IP Library Granted Patent US 12,505,197
Granted Patent B2
US 12,505,197 · App. 18/391,287 · Granted Dec 23, 2025

Protection of an electronic device

Inventors: Olivier Van Nieuwenhuyze (Wezembeek-Oppem, BE); Alexandre Charles (Auriol, FR)
Assignees: STMICROELECTRONICS (ROUSSET) SAS; STMICROELECTRONICS BELGIUM
G06F21/44
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,505,197
App. No.
18/391,287
Granted
Dec 23, 2025
Kind
B2
Abstract

An electronic device includes a processor and one or more secure elements. The processor executes a first high-level operating system and a first application. The one or more secure elements execute a first low-level operating system to verify a reliability, an authenticity, or a reliability and an authenticity of the first high-level operating system, and execute a second low-level operating system to execute a second application and to perform wireless communication with the first application. At each booting of the electronic device, the first low-level operating system performs a verification of the reliability, of the authenticity, or of the reliability and the authenticity of the first high-level operating system. In response to a request from the first application to the second application, the second low-level operating system requests a result of the verification from the first low-level operating system, and transmits the result to the second application.

Claims (55)

1 . An electronic device comprising:

a processor, which, in operation, executes a first high-level operating system and a first application; and

one or more secure elements, which, in operation,

execute a first low-level operating system to verify a reliability, an authenticity, or a reliability and an authenticity of the first high-level operating system, and

execute a second low-level operating system to execute a second application and to perform wireless communication with the first application, wherein:

at each booting of the electronic device, the first low-level operating system, in operation, performs a verification of the reliability, of the authenticity, or of the reliability and the authenticity of the first high-level operating system, and

in response to a request from the first application to the second application, the second low-level operating system, in operation, requests a result of the verification from the first low-level operating system, and transmits the result to the second application.

2 . The electronic device according to claim 1 , wherein in response to the result indicating that the first high-level operating system is reliable or authentic, the second application accepts the request from the first application.

3 . The electronic device according to claim 1 , wherein in response to the result indicating that the first operating system is not reliable or authentic, the second application refuses, partially accepts, or fully accepts the request from the first application.

4 . The electronic device according to claim 1 , wherein the second application refuses, partially accepts, or fully accepts the request from the first application based on a list of rules of access authorization associated with the first application.

5 . The electronic device according to claim 1 , wherein when the first low-level operating system verifies the reliability of the first high-level operating system, the first low-level operating system stores the result of the verification of the reliability of the first high-level operating system.

6 . The electronic device according to claim 1 , wherein the second low-level operating system transmits the result to the second application via a first application programming interface.

7 . The electronic device according to claim 1 , wherein the first high-level operating system is a trust platform module.

8 . The electronic device according to claim 1 , wherein the second low-level operating system is a program compliant with:

a Global Platform standard;

a Java Card Virtual Machine; or

a Global Platform standard and a Java Card Virtual Machine.

9 . The electronic device according to claim 1 , wherein the first and second low-level operating systems, in operation, communicate via a dedicated communication channel.

10 . The electronic device according to claim 1 , wherein the one or more secure elements comprise a first chip, which, in operation, executes the first low-level operating system, and a second chip, different from the first chip, which, in operation, executes the second low-level operating system.

11 . The electronic device according to claim 10 , wherein the first chip is a first secure element, and the second chip is a second secure element of the one or more secure elements.

12 . The electronic device according to claim 6 , wherein the one or more secure elements, in operation, execute a second application programming interface, which, in operation, verifies whether a command received by the second application has been reliably sent.

13 . The electronic device according to claim 12 , wherein the second application programming interface, in operation, applies a plurality of verification tests.

14 . The device according to claim 12 , wherein the second application programming interface, in operation, verifies whether a sender of the command is reliable.

15 . A method, comprising:

executing, using a processor of an electronic device, a first high-level operating system and a first application;

executing, using one or more secure elements of the electronic device,

a first low-level operating system to verify a reliability, an authenticity, or a reliability and an authenticity of the first high-level operating system, and

a second low-level operating system to execute a second application and to perform wireless communication with the first application, wherein the method includes:

at each booting of the electronic device, performing, using the first low-level operating system, a verification of the reliability, of the authenticity, or of the reliability and the authenticity of the first high-level operating system; and

in response to a request from the first application to the second application, the second low-level operating system requests a result of the verification from the first low-level operating system, and transmits the result to the second application.

16 . The method according to claim 15 , wherein in response to the result indicating that the first high-level operating system is reliable or authentic, the second application accepts the request from the first application.

17 . The method according to claim 15 , wherein in response to the result indicating that the first operating system is not reliable or authentic, the second application refuses, partially accepts, or fully accepts the request from the first application.

18 . The method according to claim 15 , wherein the second application refuses, partially accepts, or fully accepts the request from the first application based on a list of rules of access authorization associated with the first application.

19 . The method according to claim 15 , comprising, storing, by the first low-level operating system, a result of the verification of the reliability of the first high-level operating system.

20 . The method according to claim 15 , comprising transmitting, by the second low-level operating system, the result to the second application via a first application programming interface.

21 . The method according to claim 20 , comprising executing, by the one or more secure elements, a second application programming interface to verify whether a command received by the second application has been reliably sent.

22 . A system, comprising:

a memory;

a processor coupled to the memory, wherein the processor, in operation and using the memory, executes a first high-level operating system and a first application; and

one or more secure elements, which, in operation,

execute a first low-level operating system to verify a reliability, an authenticity, or a reliability and an authenticity of the first high-level operating system, and

execute a second low-level operating system to execute a second application and to perform wireless communication with the first application, wherein

at each booting of the system, the first low-level operating system, in operation, performs a verification of the reliability, of the authenticity, or of the reliability and the authenticity of the first high-level operating system, and

in response to a request from the first application to the second application, the second low-level operating system, in operation, requests a result of the verification from the first low-level operating system, and transmits the result to the second application.

23 . The system according to claim 22 , wherein in response to the result indicating that the first high-level operating system is reliable or authentic, the second application accepts the request from the first application.

24 . The system of claim 22 , comprising a dedicated communication channel, wherein the first and second low-level operating systems, in operation, communicate via the dedicated communication channel.

25 . The system according to claim 22 , wherein the one or more secure elements comprise a first chip, which, in operation, executes the first low-level operating system, and a second chip, different from the first chip, which, in operation, executes the second low-level operating system.

26 . A non-transitory computer-readable medium having contents which configure an electronic device to perform a method, the method comprising:

executing, using a processor of the electronic device, a first high-level operating system and a first application;

executing, using one or more secure elements of the electronic device,

a first low-level operating system to verify a reliability, an authenticity, or a reliability and an authenticity of the first high-level operating system, and

a second low-level operating system to execute a second application and to perform wireless communication with the first application, wherein the method includes:

at each booting of the electronic device, performing, using the first low-level operating system, a verification of the reliability, of the authenticity, or of the reliability and the authenticity of the first high-level operating system; and

in response to a request from the first application to the second application, the second low-level operating system requests a result of the verification from the first low-level operating system, and transmits the result to the second application.

27 . The non-transitory computer-readable medium of claim 26 , wherein the contents comprise instructions executable by the electronic device.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2024
From: VAN NIEUWENHUYZE, OLIVIER
To: PROTON WORLD INTERNATIONAL N.V.
Reel/Frame 069014/0610 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2024
From: CHARLES, ALEXANDRE
To: STMICROELECTRONICS (ROUSSET) SAS
Reel/Frame 069014/0620 →
CHANGE OF NAME Recorded Sep 26, 2024
From: PROTON WORLD INTERNATIONAL
To: STMICROELECTRONICS BELGIUM
Reel/Frame 069057/0620 →
Priority Claims (1)
FR 2214230 · Dec 22, 2022 · national
Continuity (1)
Related Publication 20240211579A1 · Jun 27, 2024
References Cited (18)
US 9154479B1 · Sethi · 2015 [cited by applicant]
US 11356845B1 · Nelson · 2022 [cited by examiner]
US 20060015748A1 · Goto et al. · 2006 [cited by applicant]
US 20070283327A1 · Mathew et al. · 2007 [cited by applicant]
US 20100064142A1 · Matsuzaki · 2010 [cited by applicant]
US 20130176980A1 · Kneckt et al. · 2013 [cited by applicant]
US 20150150127A1 · Ning et al. · 2015 [cited by applicant]
US 20160345376A1 · Yang et al. · 2016 [cited by applicant]
US 20170195327A1 · Lee et al. · 2017 [cited by applicant]
US 20190036688A1 · Wasily et al. · 2019 [cited by applicant]
US 20190163910A1 · Moon et al. · 2019 [cited by applicant]
US 20210011871A1 · Blanco et al. · 2021 [cited by applicant]
US 20210042207A1 · Joyce et al. · 2021 [cited by applicant]
US 20210058774A1 · Yang · 2021 [cited by examiner]
US 20220245253A1 · Van Nieuwenhuyze · 2022 [cited by examiner]
US 20240211578A1 · Van Nieuwenhuyze et al. · 2024 [cited by applicant]
CN 104318182A · 2015 [cited by applicant]
WO WO2018162040A1 · 2018 [cited by applicant]