IP Library › Granted Patent US 10,084,604
Granted Patent B2
US 10,084,604 · App. 14/681,019 · Granted Sep 25, 2018

Method of programming a smart card, computer program product and programmable smart card

Inventors: Arne Burghardt (Hamburg, DE); Thomas Suwald (Hamburg, DE); Fabian Mackenthun (Hamburg, DE); Kiran G. Shekhar (Bangalore, IN)
Assignee: NXP B.V.
H04L9/3234G06F21/123G06F21/34G06F21/572G06F21/74G06F21/77H04L9/3226H04L9/3268
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,084,604
App. No.
14/681,019
Filed
Apr 7, 2015
Granted
Sep 25, 2018
Kind
B2
Art Unit
2431
USPC
726/20
Abstract

There is provided a method of programming a smart card, said smart card comprising a secure element and a microcontroller unit which is connected to said secure element, the method comprising: (a) the secure element receives a firmware image from a host device; (b) the secure element validates the firmware image; (c) the secure element forwards the firmware image to the microcontroller unit if the firmware image is valid; (d) the microcontroller unit receives the firmware image from the secure element; (e) the microcontroller unit extracts firmware from the firmware image; and (f) the microcontroller unit installs the firmware in a memory unit of said smart card. Furthermore, a corresponding computer program product and a corresponding programmable smart card are disclosed.

Claims (45)

1. A method of programming a smart card, said smart card comprising a secure element and a microcontroller unit which is connected to said secure element, the method comprising:

(a) the secure element receives a firmware image from a host device;

(b) the secure element validates the firmware image, wherein the secure element validates the firmware image by calculating a checksum of the firmware image and comparing the calculated checksum with a checksum stored in the firmware image;

(c) the secure element forwards the firmware image to the microcontroller unit only if the secure element has determined that the firmware image is valid based on the checksum comparison;

(d) the microcontroller unit receives the firmware image from the secure element;

(e) the microcontroller unit extracts firmware from the firmware image; and

(f) the microcontroller unit installs the firmware in a memory unit of said smart card, wherein the memory unit is comprised in the microcontroller unit;

wherein the firmware image comprises an update of previously installed firmware, and wherein the secure element further:

receives a firmware update request from the host device,

validates a certificate of said firmware update request, wherein the certificate is a number that is a cryptographic function of a secret key and a unique identifier (UID) of the secure element and wherein validating the certificate comprises extracting the UID from the certificate and comparing the extracted UID to a UID stored at the secure element, and

performs steps (a), (b) and (c) only if said certificate is valid and only if the extracted UID matches the UID stored at the secure element.

2. A method as claimed in claim 1 , wherein the secure element further decrypts the firmware image before calculating a checksum of the firmware image and comparing the calculated checksum with a checksum stored in the firmware image.

3. A method as claimed in claim 1 , wherein the secure element receives said firmware image from the host device through a contact-based interface unit that operates according to International Standards Organization 7816 and/or a contactless interface unit that operates according to International Standards Organization 14443.

4. A method as claimed in claim 3 , wherein the contact-based interface unit and/or contactless interface unit are controlled by the secure element.

5. A method as claimed in claim 1 , wherein the microcontroller unit enters into an In-Application Programming (IAP) mode before receiving the firmware image from the secure element.

6. A method as claimed in claim 5 , wherein the secure element instructs the microcontroller unit to enter into the IAP mode and wherein the secure element notifies the host device when the microcontroller unit is in the IAP mode, such that the host device may initiate programming of the smart card.

7. A method as claimed in claim 1 , wherein the microcontroller unit comprises a boot loader which is started automatically during start-up of the microcontroller unit.

8. A programmable smart card, said smart card comprising a secure element and a microcontroller unit which is connected to said secure element, wherein:

the secure element is connected to a contact-based interface unit that operates according to International Standards Organization 7816 and/or to a contactless interface unit that operates according to International Standards Organization 14443, wherein the contact-based interface unit and/or contactless interface unit are controlled by the secure element;

the secure element is arranged to receive a firmware image from a host device, wherein the secure element receives said firmware image from the host device through the contact-based interface unit and/or through the contactless interface unit;

the secure element is arranged to validate the firmware image, wherein the secure element validates the firmware image by calculating a checksum of the firmware image and comparing the calculated checksum with a checksum stored in the firmware image;

the secure element forwards the firmware image to the microcontroller unit only if the secure element has determined that the firmware image is valid based on the checksum comparison;

the microcontroller unit is arranged to receive the firmware image from the secure element;

the microcontroller unit is arranged to extract firmware from the firmware image; and

the microcontroller unit is arranged to install the firmware in a memory unit of said smart card, wherein the memory unit is comprised in the microcontroller unit;

wherein the firmware image comprises an update of previously installed firmware, and wherein the secure element further:

receives a firmware update request from the host device,

validates a certificate of said firmware update request, wherein the certificate is a number that is a cryptographic function of a secret key and a unique identifier (UID) of the secure element and wherein validating the certificate comprises extracting the UID from the certificate and comparing the extracted UID to a UID stored at the secure element, and

forwards the firmware image to the microcontroller unit only if the secure element determines that said certificate is valid and only if the extracted UID matches the UID stored at the secure element.

9. A smart card as claimed in claim 8 , being an electronic identification card, a payment card or an access card.

10. A method of programming a smart card, said smart card comprising a secure element and a microcontroller unit which is connected to said secure element, the method comprising:

(a) the secure element receives a firmware image from a host device, wherein the secure element receives said firmware image from the host device through a contact-based interface unit that operates according to International Standards Organization 7816 and/or a contactless interface unit that operates according to International Standards Organization 14443, wherein the secure element is connected between the contact-based interface unit and the microcontroller and/or the secure element is connected between contactless interface unit and the microcontroller and wherein the contact-based interface unit and/or contactless interface unit are controlled by the secure element;

(b) the secure element validates the firmware image, wherein the secure element validates the firmware image by calculating a checksum of the firmware image and comparing the calculated checksum with a checksum stored in the firmware image;

(c) the secure element forwards the firmware image to the microcontroller unit only if the secure element has determined that the firmware image is valid based on the checksum comparison;

(d) the microcontroller unit receives the firmware image from the secure element;

(e) the microcontroller unit extracts firmware from the firmware image; and

(f) the microcontroller unit installs the firmware in a memory unit of said smart card wherein the memory unit is comprised in the microcontroller unit;

wherein the firmware image comprises an update of previously installed firmware, and wherein the secure element further:

receives a firmware update request from the host device,

validates a certificate of said firmware update request, wherein the certificate is a number that is a cryptographic function of a secret key and a unique identifier (UID) of the secure element and wherein validating the certificate comprises extracting the UID from the certificate and comparing the extracted UID to a UID stored at the secure element, and

performs steps (a), (b) and (c) only if said certificate is valid and only if the extracted UID matches the UID stored at the secure element.

11. A method as claimed in claim 10 , wherein the secure element further decrypts the firmware image before calculating a checksum of the firmware image and comparing the calculated checksum with a checksum stored in the firmware image.

12. A method as claimed in claim 10 , wherein the microcontroller unit enters into an TAP mode before receiving the firmware image from the secure element.

13. A method as claimed in claim 12 , wherein the secure element instructs the microcontroller unit to enter into the TAP mode and wherein the secure element notifies the host device when the microcontroller unit is in the TAP mode, such that the host device may initiate programming of the smart card.

14. A method as claimed in claim 10 , wherein the microcontroller unit comprises a boot loader which is started automatically during start-up of the microcontroller unit.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 042985 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051029/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 039361 FRAME 0212. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051029/0387 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051030/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 042762 FRAME 0145. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051145/0184 →
RELEASE OF SECURITY INTEREST Recorded Sep 10, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 050745/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12681366 PREVIOUSLY RECORDED ON REEL 039361 FRAME 0212. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded May 9, 2017
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 042762/0145 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12681366 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded May 9, 2017
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 042985/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12092129 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Jul 14, 2016
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 039361/0212 →
SECURITY AGREEMENT SUPPLEMENT Recorded Mar 7, 2016
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 038017/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2015
From: BURGHARDT, ARNE; SUWALD, THOMAS; MACKENTHUN, FABIAN; SHEKHAR, KIRAN G.
To: NXP B.V.
Reel/Frame 035352/0558 →
Priority Claims (1)
EP 14163732 · Apr 7, 2014 · regional
Continuity (1)
Related Publication 20150288523A1 · Oct 8, 2015
Cited By (4)
US 12,197,974 US 12,216,769 US 12,538,130 US 12,608,185