IP Library Granted Patent US 11,974,126
Granted Patent B2
US 11,974,126 · App. 17/294,885 · Granted Apr 30, 2024

Method, first and second device and system for connecting to at least one chip

Inventors: Danny Tabak (Gemenos, FR); Johan Josefsson (Gemenos, FR)
Assignee: THALES DIS FRANCE SAS
H04W12/06G06F21/35G06F21/44H04L63/0492H04L63/0853H04W12/63
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,974,126
App. No.
17/294,885
Granted
Apr 30, 2024
Kind
B2
Abstract

A method comprises: Sending, by a first Chip Interface Device (CID), to a second CID, using a CID type protocol, a request for establishing a secure channel over a wireless protocol. Sending, by the second CID, to a Personal Computer Smart Card (PCSC), a first request for establishing a connection to the chip. Establishing, by the PCSC, a connection to the chip. Establishing, by the PCSC, a connection to the second CID. Establishing, by the second CID, a secure session with the first CID by using a session key. And sending, by the second CID, to the first CID, while using the CID type protocol, a secure CID channel establishment success that allows sending or receiving APDU(s) via the established secure channel over the wireless protocol. The second CID renders apparent to the first CID the chip as being connected.

Claims (33)

1. A method for connecting to at least one chip,

via a first device including a first Chip Interface Device type interface (CID), and a second device including a second CID, the second device including a Personal Computer/Smart Card (PCSC) type interface, wherein the method comprises the following steps:

a) sending, by the first CID, to the second CID, while using a CID type protocol, a request for establishing a secure CID channel over a wireless protocol, as a secure CID channel establishment request;

b) sending, by the second CID, to the PCSC, a first request for establishing a connection to the chip;

c) establishing, by the PCSC, a connection to the chip;

d) establishing, by the PCSC, a connection to the second CID, as a response to the first request;

e) establishing, by the second CID, a secure session with the first CID by using a session key; and

f) sending, by the second CID, to the first CID, while using the CID type protocol, a message relating to a secure CID channel establishment success, as a response to the secure CID channel establishment request, the secure CID channel establishment success allowing to send or receive at least one Application Protocol Data Unit or APDU via the established secure CID channel over the wireless protocol, the second CID rendering apparent to the first CID the chip as being connected, the second CID managing, through the PCSC, in a native manner, at least one connection to or at least one disconnection from the at least one chip.

2. Method according to claim 1 , wherein the first CID and the second CID generate both the session key, by using an on-the-fly generated session key seed and a predetermined long term key shared between the first CID and the second CID.

3. Method according to claim 1 , wherein the first CID and the second CID determine or generate both the session key by using either an on-the-fly generated session key or an on-the-fly generated session key seed, the first CID having securely sent, along with the secure CID channel establishment request, either the session key or the session key seed.

4. Method according to claim 1 , wherein the first CID and the second CID generate both the session key by using a Diffie-Hellman based session key establishment, the session key being a shared secret key.

5. Method according to claim 1 , wherein, prior to step a), the method further comprises a step in which the first CID pairs with the second CID by establishing a long term key, the long term key being previously shared only between the first CID and the second CID.

6. Method according to claim 1 , wherein, the first device including an application for cooperating with the chip, the method further comprises, prior to step a):

a chip cooperation application launches, during a chip cooperation application execution, by the first device, at least one operation; and

the chip cooperation application sends, to the first CID, a request for connecting to the second device; and

after step f), the first CID sends, to the chip cooperation application, a message relating to a connection success with the second device, as a response to the second device connection request.

7. Method according to claim 1 , wherein, the chip cooperates with a third device, to carry out step c), and the method includes the following steps:

sending, based on the first chip connection establishment request, by the PCSC, to the third device, a second request for establishing a connection to the chip;

sending, based on the second chip connection establishment request, by the third device, to the chip, a third request for establishing a connection to the chip;

sending, by the chip, to the third device, a message relating to a third connection success with the third device; and

sending, by the third device, to the PCSC, a message relating to a second connection success with the PCSC.

8. A second device for connecting to at least one chip,

wherein the second device includes a second Chip Interface Device type interface (CID), the second device including a Personal Computer/Smart Card type interface (PCSC), the second CID is configured to:

receive, from a first CID, while using a CID type protocol, a request for establishing a secure channel over a wireless protocol; and

send, to the PCSC, a first request for establishing a connection to the chip;

wherein the PCSC is configured to:

establish a connection to the chip; and

establish a connection to the second CID, as a response to the first request;

and wherein the second CID is configured to:

establish a secure session with the first CID by using a session key; and

send, to the first CID, while using the CID type protocol, a message relating to a secure CID channel establishment success, as a response to the secure CID channel establishment request, the secure CID channel establishment success allowing to send or receive at least one Application Protocol Data Unit or APDU via the established secure channel over the wireless protocol, the second CID rendering apparent to the first CID the chip as being connected, the second CID managing, through the PCSC, in a native manner, at least one connection to or at least one disconnection from the at least one chip.

9. A system for connecting to at least one chip, the system comprising a first device, a second device and the at least one chip,

wherein the system is configured to carry out the steps of claim 1 .

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2023
From: THALES DIS FRANCE SA
To: THALES DIS FRANCE SAS
Reel/Frame 064870/0162 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2022
From: THALES DIS FRANCE SA
To: THALES DIS FRANCE SAS
Reel/Frame 062165/0876 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2022
From: TABAK, DANNY
To: THALES DIS ISRAEL LTD
Reel/Frame 059342/0183 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2022
From: JOSEFSSON, JOHAN
To: THALES DIS SWEDEN AB
Reel/Frame 059342/0208 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2022
From: THALES DIS ISRAEL LTD
To: THALES DIS FRANCE SA
Reel/Frame 059342/0800 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2022
From: THALES DIS SWEDEN AB
To: THALES DIS FRANCE SA
Reel/Frame 059342/0828 →