IP Library › Granted Patent US 12,632,537
Granted Patent B2
US 12,632,537 · App. 18/535,432 · Granted May 19, 2026

Executing cryptographic operations in a secure element platform runtime environment

Inventors: Nicolas Michel Raphaël Ponsini (Mougins, FR); Sebastian Jürgen Hans (Berlin, DE)
Assignee: Oracle International Corporation
G06F21/53H04L9/0618H04L9/0825H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,632,537
App. No.
18/535,432
Granted
May 19, 2026
Kind
B2
Abstract

A system performs a set of cryptographic operations at least by utilizing an API to cause execution of a set of one or more secure element (SE) applications within the SE platform runtime environment of a first computing entity. The set of cryptographic operations include generating a first shared secret, generating a ciphertext at least by encapsulating the first shared secret with a first public key associated with a second computing entity in accordance with an encapsulation algorithm, and transmitting the ciphertext from the first computing entity to the second computing entity. The second computing entity derives the first shared secret by decapsulating the ciphertext with a private key corresponding to the first public key. The first computing entity and the second computing entity then exchange at least one encrypted message, encrypted with an encryption key that includes, or is based at least in part on, the first shared secret.

Claims (121)

1 . A method, comprising:

executing a secure element (SE) platform runtime environment on at least one SE hardware processor comprised in a first computing entity, wherein the SE platform runtime environment comprises instructions, which when executed by the at least one SE hardware processor, cause performance of operations, comprising:

receiving a request from a device host hardware element of the first computing entity via a SE interface for transferring messages from the device host hardware element to the at least one SE hardware processor;

responsive at least in part to the request, performing a set of cryptographic operations at least by executing a set of SE applications within the SE platform runtime environment, wherein the set of SE applications are isolated, within the SE platform runtime environment, from the device host hardware element, wherein the set of cryptographic operations comprises:

executing a first SE application, of the set of SE applications, wherein executing the first SE application comprises:

generating, by the first SE application, a first shared secret;

generating, by the first SE application, a ciphertext at least by encapsulating the first shared secret with a first key encapsulation mechanism (KEM) public key associated with a second computing entity in accordance with an encapsulation algorithm;

executing a second SE application, of the set of SE applications, wherein executing the second SE application comprises:

obtaining, by the second SE application, the first shared secret from the first SE application for securely accessing data from the first SE application, and

generating, by the second SE application, an encryption key based at least in part on the first shared secret, wherein the second SE application is different from the first SE application;

directing, from the at least one SE hardware processor to the device host hardware element via the SE interface, a response to the request, the response comprising the ciphertext; and

transmitting the ciphertext from the first computing entity to the second computing entity,

wherein subsequent to transmitting the ciphertext to the second computing entity:

the second computing entity (a) derives the first shared secret by decapsulating the ciphertext with a KEM private key corresponding to the first KEM public key and (b) generates a decryption key based at least in part on the first shared secret, and

the first computing entity and the second computing entity exchange at least one encrypted message,

wherein the first computing entity encrypts the at least one encrypted message with the encryption key and wherein the second computing entity decrypts the at least one encrypted message with the decryption key.

2 . The method of claim 1 , wherein the encapsulation algorithm comprises at least one of: a legacy cryptographic algorithm, or a quantum-resistant cryptographic algorithm.

3 . The method of claim 1 , wherein the set of SE applications comprises a key encapsulation mechanism module; and

wherein executing the set of SE applications within the SE platform runtime environment comprises:

encapsulating the first shared secret with the first KEM public key in accordance with the encapsulation algorithm at least by executing the key encapsulation mechanism module,

wherein an output of the key encapsulation mechanism module comprises the ciphertext.

4 . The method of claim 1 , wherein the set of cryptographic operations further comprise:

generating a first key agreement (KA) private key;

generating a second shared secret at least by combining the first KA private key with a first KA public key associated with the second computing entity in accordance with a KA algorithm;

generating a combined shared secret at least by combining, in accordance with a combination function, the first shared secret, the second shared secret, and a combination parameter associated with the combination function;

wherein the second computing entity derives the second shared secret at least by:

generating a second KA private key, and

combining the second KA private key with a second KA public key associated with the first computing entity in accordance with the KA algorithm;

wherein the second computing entity derives the combined shared secret at least by combining, in accordance with the combination function, the first shared secret, the second shared secret, and the combination parameter associated with the combination function;

wherein the encryption key comprises, or is based at least in part on, the combined shared secret.

5 . The method of claim 4 , wherein the operations further comprise:

selecting the combination function from a set of combination functions.

6 . The method of claim 4 , wherein the operations further comprise:

receiving the first KEM public key and the first KA public key from the second computing entity;

validating the first KEM public key and the first KA public key;

responsive to validating the first KEM public key and the first KA public key, performing the set of cryptographic operations; and

transmitting a first encrypted message to the second computing entity, wherein the first encrypted message is encrypted with the encryption key.

7 . The method of claim 1 , further comprising:

initializing the SE platform runtime environment at least in part via an electromagnetic field generated by a near-field communication element associated with the second computing entity; and

receiving the first KEM public key from the second computing entity subsequent to initializing the SE platform runtime environment.

8 . The method of claim 1 , wherein the first computing entity and the second computing entity are communicatively coupled via a wired or wireless network.

9 . The method of claim 1 , wherein the operations further comprise:

initiating a cryptography module within the SE platform runtime environment; and

selecting, via the cryptography module, the set of SE applications for execution within the SE platform runtime environment.

10 . The method of claim 1 , wherein the operations further comprise:

selecting the encapsulation algorithm from a set of encapsulation algorithms using an application programming interface.

11 . The method of claim 1 , wherein an application programming interface is utilized to perform at least one of: generating, configuring, or selecting, the set of SE applications.

12 . The method of claim 1 , wherein the operations further comprise:

configuring one or more parameters associated with the set of cryptographic operations based on one or more user inputs,

wherein the one or more parameters comprises at least one of: the first KEM public key, or a selection of the encapsulation algorithm,

wherein at least one of the one or more parameters is provided as a byte array.

13 . One or more non-transitory computer-readable media comprising instructions, which when executed by one or more hardware processors associated with a first computing entity, cause performance of operations comprising:

initiating a cryptography module within a secure element (SE) platform runtime environment, wherein the one or more hardware processors comprise at least one SE hardware processor, and wherein the SE platform runtime environment is executed on the at least one SE hardware processor;

receiving a request from a device host hardware element of the first computing entity via a SE interface for transferring messages from the device host hardware element to the at least one SE hardware processor;

responsive at least in part to the request, performing a set of cryptographic operations at least by executing a set of SE applications within the SE platform runtime environment, wherein the set of SE applications are isolated, within the SE platform runtime environment, from the device host hardware element, wherein the set of cryptographic operations comprises:

executing a first SE application, of the set of SE applications, wherein executing the first SE application comprises:

generating, by the first SE application, a first shared secret;

generating, by the first SE application, a ciphertext at least by encapsulating the first shared secret with a first key encapsulation mechanism (KEM) public key associated with a second computing entity in accordance with an encapsulation algorithm;

executing a second SE application, of the set of SE applications, wherein executing the second SE application comprises:

obtaining, by the second SE application, the first shared secret from the first SE application for securely accessing data from the first SE application, and

generating, by the second SE application, an encryption key based at least in part on the first shared secret, wherein the second SE application is different from the first SE application;

directing, from the at least one SE hardware processor to the device host hardware element via the SE interface, a response to the request, the response comprising the ciphertext; and

transmitting the ciphertext from the first computing entity to the second computing entity,

wherein subsequent to transmitting the ciphertext to the second computing entity:

the second computing entity (a) derives the first shared secret by decapsulating the ciphertext with a KEM private key corresponding to the first KEM public key and (b) generates a decryption key based at least in part on the first shared secret, and

the first computing entity and the second computing entity exchange at least one encrypted message,

wherein the first computing entity encrypts the at least one encrypted message with the encryption key and wherein the second computing entity decrypts the at least one encrypted message with the decryption key.

14 . The one or more non-transitory computer-readable media of claim 13 , wherein the set of SE applications comprises a key encapsulation mechanism module; and

wherein executing the set of SE applications within the SE platform runtime environment comprises:

encapsulating the first shared secret with the first KEM public key in accordance with the encapsulation algorithm at least by executing the key encapsulation mechanism module,

wherein an output of the key encapsulation mechanism module comprises the ciphertext.

15 . The one or more non-transitory computer-readable media of claim 13 , wherein the set of cryptographic operations further comprise:

generating a first key agreement (KA) private key;

generating a second shared secret at least by combining the first KA private key with a first KA public key associated with the second computing entity in accordance with a KA algorithm;

generating a combined shared secret at least by combining, in accordance with a combination function, the first shared secret, the second shared secret, and a combination parameter associated with the combination function;

wherein the second computing entity derives the second shared secret at least by:

generating a second KA private key, and

combining the second KA private key with a second KA public key associated with the first computing entity in accordance with the KA algorithm;

wherein the second computing entity derives the combined shared secret at least by combining, in accordance with the combination function, the first shared secret, the second shared secret, and the combination parameter associated with the combination function;

wherein the encryption key comprises, or is based at least in part on, the combined shared secret.

16 . The one or more non-transitory computer-readable media of claim 15 , wherein the operations further comprise:

receiving the first KEM public key and the first KA public key from the second computing entity;

validating the first KEM public key and the first KA public key;

responsive to validating the first KEM public key and the first KA public key, performing the set of cryptographic operations; and

transmitting a first encrypted message to the second computing entity, wherein the first encrypted message is encrypted with the encryption key.

17 . The one or more non-transitory computer-readable media of claim 13 , wherein the operations further comprise:

initializing the SE platform runtime environment at least in part via an electromagnetic field generated by a near-field communication element associated with the second computing entity; and

receiving the first KEM public key from the second computing entity subsequent to initializing the SE platform runtime environment.

18 . The one or more non-transitory computer-readable media of claim 13 , wherein the operations further comprise:

initiating a cryptography module within the SE platform runtime environment; and

selecting, via the cryptography module, the set of SE applications for execution within the SE platform runtime environment.

19 . The one or more non-transitory computer-readable media of claim 13 , wherein the operations further comprise:

configuring one or more parameters associated with the set of cryptographic operations based on one or more user inputs,

wherein the one or more parameters comprises at least one of: the first KEM public key, or a selection of the encapsulation algorithm,

wherein at least one of the one or more parameters is provided as a byte array.

20 . A system, comprising:

at least one secure element (SE) hardware processor associated with a first computing entity;

an SE platform runtime environment executable on the at least one SE hardware processor;

wherein the SE platform runtime environment is configured to execute operations, using the at least one SE hardware processor, the operations comprising:

receiving a request from a device host hardware element of the first computing entity via a SE interface for transferring messages from the device host hardware element to the at least one SE hardware processor;

responsive at least in part to the request, performing a set of cryptographic operations at least by executing a set of SE applications within the SE platform runtime environment, wherein the set of SE applications are isolated, within the SE platform runtime environment, from the device host hardware element, wherein the set of cryptographic operations comprises: executing a first SE application, of the set of SE applications, wherein executing the first SE application comprises:

generating, by the first SE application, a first shared secret;

generating, by the first SE application, a ciphertext at least by encapsulating the first shared secret with a first key encapsulation mechanism (KEM) public key associated with a second computing entity in accordance with an encapsulation algorithm;

executing a second SE application, of the set of SE applications, wherein executing the second SE application comprises:

obtaining, by the second SE application, the first shared secret from the first SE application for securely accessing data from the first SE application, and

generating, by the second SE application, an encryption key based at least in part on the first shared secret, wherein the second SE application is different from the first SE application;

directing, from the at least one SE hardware processor to the device host hardware element via the SE interface, a response to the request, the response comprising the ciphertext; and

transmitting the ciphertext from the first computing entity to the second computing entity,

wherein subsequent to transmitting the ciphertext to the second computing entity:

the second computing entity (a) derives the first shared secret by decapsulating the ciphertext with a KEM private key corresponding to the first KEM public key and (b) generates a decryption key based at least in part on the first shared secret, and

the first computing entity and the second computing entity exchange at least one encrypted message,

wherein the first computing entity encrypts the at least one encrypted message with the encryption key and wherein the second computing entity decrypts the at least one encrypted message with the decryption key.

21 . The system of claim 20 , wherein obtaining the first shared secret from the first SE application comprises:

generating a shareable interface object, and

utilizing the shareable interface object to obtain the first shared secret from the first SE application.

22 . The system of claim 20 ,

wherein executing the first SE application further comprises:

storing the first shared secret in a transient memory element, and

generating a transient object handle comprising a reference to the first shared secret in the transient memory element;

wherein obtaining the first shared secret from the first SE application comprises:

utilizing the transient object handle to access the first shared secret from the transient memory.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2024
From: HANS, SEBASTIAN JÜRGEN
To: ORACLE DEUTSCHLAND B.V. & CO. KG
Reel/Frame 067440/0507 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2024
From: ORACLE DEUTSCHLAND B.V. & CO. KG
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 067440/0578 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2023
From: PONSINI, NICOLAS MICHEL RAPHAËL
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 065830/0044 →
Continuity (2)
Provisional Application 63595907 · Nov 3, 2023
Related Publication 20250148071A1 · May 8, 2025
References Cited (45)
US 20100262829A1 · Brown · 2010 [cited by examiner]
US 20150288514A1 · Pahl · 2015 [cited by examiner]
US 20160286391A1 · Khan · 2016 [cited by examiner]
US 20180082065A1 · Liu · 2018 [cited by examiner]
US 20190164156A1 · Lindemann · 2019 [cited by examiner]
US 20190319802A1 · Misoczki et al. · 2019 [cited by applicant]
US 20200235929A1 · Jacobs · 2020 [cited by examiner]
US 20210226782A1 · Florit · 2021 [cited by examiner]
US 20220231843A1 · Garcia Morchon · 2022 [cited by examiner]
US 20220278833A1 · Nix · 2022 [cited by examiner]
US 20220345298A1 · Cap · 2022 [cited by examiner]
US 20230336334A1 · Scheible · 2023 [cited by examiner]
US 20230353349A1 · Cap · 2023 [cited by examiner]
US 20240275599A1 · Albert · 2024 [cited by examiner]
EP 3758290A1 · 2020 [cited by applicant]
EP 4040716A1 · 2022 [cited by examiner]
WO 2019071026A1 · 2019 [cited by applicant]
WO 2021062517A1 · 2021 [cited by applicant]
WO WO2024175953A1 · 2024 [cited by examiner]
“Comments Requested on Three Draft FIPS for Post-Quantum Cryptography,” CSRC, Aug. 24, 2023, pp. 3., Feb. 14, 2024. [cited by applicant]
“Cyber; Quantum-safe Hybrid Key Exchanges,” TS 103 744 V1.1.1, Dec. 2020, pp. 42. [cited by applicant]
Barnes. R. et al., “RFC 9180_ Hybrid Public Key Encryption,” Feb. 2022, pp. 85. [cited by applicant]
Ounsworth. M. et al., “Combiner function for hybrid key encapsulation mechanisms (Hybrid KEMs),” Jan. 9, 2024, pp. 13. [cited by applicant]
Wood C., “HPKE: Standardizing public-key encryption (finally!),” Feb. 24, 2022, pp. 15. [cited by applicant]
“Java Card Platform Specification Release Notes”, Version 3.2, Jan. 2023, pp. 1-18. [cited by applicant]
“Java Card™ Platform, Application Programming Interface, Classic Edition Version 3.2”, Retrieved from https://docs.oracle.com/en/java/javacard/3.2/jcapi/api_classic/index.html, Retrieved on Jul. 25, 2024, pp. 1-5. [cited by applicant]
“Runtime Environment Specification, Classic Edition”, Version 3.2, Java Card™ Platform, Jan. 2023, pp. 1-136. [cited by applicant]
“Virtual Machine Specification, Classic Edition”, Version 3.2, Java Card™ Platform, Jan. 2023, pp. 1-274. [cited by applicant]
Cooper et al., “Recommendation for Stateful Hash-Based Signature Schemes”, NIST SP 800-208, Oct. 2020, pp. 59. [cited by applicant]
Fluhrer et al., “Additional Parameter sets for HSS/LMS Hash-Based Signatures”, Sep. 18, 2023, pp. 20. [cited by applicant]
Huelsing et al., “XMSS: eXtended Merkle Signature Scheme”, Retrieved from https://datatracker.ietf.org/doc/html/rfc8391, May 2018, pp. 1-74. [cited by applicant]
Mcgrew et al., “Leighton-Micah Hash-Based Signatures”, Apr. 2019, pp. 1-61. [cited by applicant]
National Institute of Standards and Technology, “Stateless Hash-Based Digital Signature Standard”, FIPS 205 (Draft), Aug. 24, 2023, pp. 58. [cited by applicant]
“Document Search”, Retrieved from https://datatracker.ietf.org/doc/search?name=draft-ietf-lamps-pq-composit&rfcs=on&activedrafts=on&olddrafts=on, Retrieved on Mar. 4, 2025, p. 1. [cited by applicant]
“Falcon: Fast-Fourier Lattice-based Compact Signatures over NTRU”, Specification v1.2, Jan. 10, 2020, pp. 1-67. [cited by applicant]
“Information technology—Open Systems Interconnection—The Directory: Public-key and attribute certificate frameworks”, Recommendation ITU-T X.509, Oct. 2019, pp. 236. [cited by applicant]
“ITU-T Recommendations”, Retrieved from https://handle.itu.int/11.1002/1000/14033, Oct. 14, 2019, pp. 1-2. [cited by applicant]
“Module-Lattice-Based Digital Signature Standard”, Federal Information Processing Standards Publication, Aug. 13, 2024, pp. 65. [cited by applicant]
Ounsworth et al., “Composite ML-DSA for use in Internet PKI”, Mar. 4, 2024, 34 Pages. [cited by applicant]
Ounsworth et al., “Composite ML-DSA for use in X.509 Public Key Infrastructure and CMS”, Mar. 3, 2025, pp. 65. [cited by applicant]
Ando, M., et al., “Hash-based TPM signatures for the quantum world.”, International Conference on Applied Cryptography and Network Security, Jun. 9, 2016, pp. 77-94. [cited by applicant]
Banerjee T et al., “Post-Quantum Cryptography for Engineers”, draft-ietfpquip-pqc-engineers-00; draft-ietf-pquip-pqc-engineers-00.txt, Internet-draft: Pquip, Internet Engineering Task Force, Ietf, Standardworkingdraft, … [cited by applicant]
Chalkias, K., et al., “Blockchained post-quantum signatures.”, International Conference on Internet of Things, Jul. 30, 2018, pp. 1196-1203. [cited by applicant]
Iftikhar, Z., et al., “Quantum safe cloud computing using hash-based digital signatures.”, International Conference on Automation and Computing, Sep. 2, 2021, pp. 1-6. [cited by applicant]
Ulitzsch V.Q., et al., “A Post-Quantum Secure Subscription Concealed Identifier for 6G”, Proceedings of the Twelveth Acm Conference on Data and Application Security and Privacy, Acmpub27, May 16-19, 2022, pp. 157-168 (1… [cited by applicant]