IP Library › Granted Patent US 12,216,769
Granted Patent B2
US 12,216,769 · App. 17/733,562 · Granted Feb 4, 2025

Secure element enforcing a security policy for device peripherals

Inventors: Nicholas Michel Raphaël Ponsini (Mougins, FR); Patrick Van Haver (La Cadiere d+3 Azur, FR)
Assignee: Oracle International Corporation
G06F21/60G06F21/85H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,216,769
App. No.
17/733,562
Granted
Feb 4, 2025
Kind
B2
Abstract

Techniques for implementing and enforcing a security policy in a secure element are disclosed. The secure element enforces the security policy to grant and/or deny access, such as from an application processor, to configuration of the device peripheral components and access to data of the device peripheral components across one or more bus architectures, such as an I3C bus. Implementing an access control policy in a secure element allows execution of code within the isolated secure element hardware processor, preventing software attacks that may emanate from code running in the application processor. This design also benefits from hardware protections against physical attacks.

Claims (85)

1. A method, comprising:

executing a secure element (SE) application on a SE hardware processor comprised in a physical SE component, wherein: (a) the physical SE component is coupled via a first bus to a first controller comprised in a same computing device as the physical SE component, and (b) the physical SE component is coupled via a second bus to a first peripheral component comprised in the same computing device,

wherein the SE hardware processor executes one or more secure element applications within a secure execution environment, wherein the SE application is configured to perform authentication through one or more secure channels with at least one device that is remote from the SE hardware processor;

receiving, by a second controller implemented by the SE hardware processor, a first message from the first peripheral component via the first bus;

applying, by the SE hardware processor, a security policy to the first message to generate a first validated message; and

transmitting, by the second controller, the first validated message to the first controller.

2. The method as recited in claim 1 , wherein the first bus and the second bus are a same bus.

3. The method as recited in claim 1 , further comprising, transmitting, by the second controller, a second message to the first peripheral component via the first bus, wherein the first message is received subsequent to transmitting the second message.

4. The method as recited in claim 3 , further comprising:

receiving, by the second controller, a third message from the first controller prior to transmitting the second message;

applying, by the SE hardware processor, the security policy to the third message; and

subsequent to applying the security policy to the third message, generating the second message based on the third message.

5. The method as recited in claim 3 , wherein generating the second message comprises encrypting at least a portion of the third message, and wherein the second message comprises the encrypted portion of the third message.

6. The method as recited in claim 1 , further comprising:

receiving, by the second controller, a second message from the first controller prior to receiving the first message;

applying, by the SE hardware processor, the security policy to the second message;

subsequent to applying the security policy to the second message:

generating, by the SE hardware processor, a third message based on the second message;

transmitting, by the second controller, the third message to a second peripheral component via a third bus, wherein control of the second peripheral component is shared by the first controller and the second controller;

generating, by the SE hardware processor, a fourth message based on the second message; and

transmitting, by the second controller, the fourth message to the first peripheral component via the first bus, wherein the first message is received subsequent to transmitting the fourth message, and wherein the first peripheral component is exclusively controlled by the second controller.

7. The method as recited in claim 6 , further comprising:

generating, by the SE hardware processor, one or more additional messages based on the second message;

transmitting, by the second controller, the one or more additional messages to at least one additional peripheral components via the third bus;

receiving, by the second controller, at least one additional response message from the at least one additional peripheral components via the third bus; and

applying, by the SE hardware processor, the security policy to the at least one additional response message.

8. The method as recited in claim 1 , wherein access and control of the first peripheral component is shared by the first controller and the second controller.

9. The method as recited in claim 1 , wherein the first peripheral component is controlled by the second controller, and wherein access to the first peripheral component is limited by the SE hardware processor.

10. The method as recited in claim 1 , wherein the physical SE component is an integrated circuit protected from unauthorized access, wherein the physical SE component is configured to execute a limited set of applications including the SE application, and wherein the SE application provides authentication and encryption services for messages received at the physical SE component.

11. The method as recited in claim 1 , wherein information included in the first validated message is identical to information included in the first message.

12. The method as recited in claim 1 , wherein the SE hardware processor generates the first validated message based on the first message.

13. The method as recited in claim 1 , wherein the physical SE component is configured as an I3C target and comprises the second controller in accordance with I3C protocol.

14. The method as recited in claim 1 , wherein the first peripheral component is configured as an I3C target for the second controller in accordance with I3C protocol.

15. The method as recited in claim 1 , wherein the second bus is configured in accordance with I3C protocol.

16. A method, comprising:

executing a secure element (SE) application on a SE hardware processor comprised in a physical SE component, wherein: (a) the physical SE component is coupled via a first bus to a first controller comprised in a same computing device as the physical SE component, and (b) the physical SE component is coupled via a second bus to a first peripheral component comprised in the same computing device,

wherein the SE hardware processor executes one or more secure element applications within a secure execution environment, wherein the SE application is configured to perform authentication through one or more secure channels with at least one device that is remote from the SE hardware processor;

receiving, by a second controller implemented by the SE hardware processor, a first message from the first controller via the first bus;

applying, by the SE hardware processor, a security policy to the first message to generate a first validated message; and

transmitting, by the second controller, the first validated message to the first peripheral component via the second bus.

17. The method as recited in claim 16 , wherein the first bus and the second bus are a same bus.

18. The method as recited in claim 16 , wherein the first peripheral component is controlled by the second controller, and wherein access to components along the second bus including the first peripheral component is limited by the SE hardware processor.

19. The method as recited in claim 16 , wherein the physical SE component is an integrated circuit protected from unauthorized access, wherein the physical SE component is configured to execute a limited set of applications including the SE application, and wherein the SE application provides authentication and encryption services for messages received at the physical SE component.

20. The method as recited in claim 16 , wherein generating the first validated message comprises encrypting at least a portion of the first message, and wherein the first validated message comprises the encrypted portion of the first message.

21. The method as recited in claim 16 , further comprising:

receiving, by the second controller, a second message from the first peripheral component via the second bus;

applying, by the SE hardware processor, the security policy to the second message to generate a second validated message; and

transmitting, by the second controller, the second validated message to the first controller via the first bus.

22. The method as recited in claim 16 , wherein information included in the first validated message is identical to information included in the first message.

23. The method as recited in claim 16 , wherein the SE hardware processor generates the first validated message based on the first message.

24. The method as recited in claim 16 , wherein the physical SE component is configured as an I3C target and comprises the second controller in accordance with I3C protocol.

25. The method as recited in claim 16 , wherein the first peripheral component is configured as an I3C target for the second controller in accordance with I3C protocol.

26. The method as recited in claim 16 , wherein the second bus is configured in accordance with I3C protocol.

27. The method as recited in claim 16 , wherein the first peripheral component is controlled by the second controller, wherein access to components along the second bus including the first peripheral component is limited by the SE hardware processor, wherein the physical SE component is an integrated circuit protected from unauthorized access, wherein the physical SE component is configured to execute a limited set of applications including the SE application, wherein generating the first validated message comprises encrypting at least a portion of the first message, wherein the first validated message comprises the encrypted portion of the first message, wherein the physical SE component is configured as an I3C target and comprises the second controller in accordance with I3C protocol, wherein the first peripheral component is configured as an I3C target for the second controller in accordance with I3C protocol, wherein the second bus is configured in accordance with I3C protocol, and wherein the method further comprises:

receiving, by the second controller, a second message from the first peripheral component via the second bus;

applying, by the SE hardware processor, the security policy to the second message to generate a second validated message; and

transmitting, by the second controller, the second validated message to the first controller via the first bus.

28. One or more non-transitory computer-readable media comprising instructions that, when executed by one or more hardware processors, cause performance of operations comprising:

executing a secure element (SE) application on a SE hardware processor comprised in a physical SE component, wherein: (a) the physical SE component is coupled via a first bus to a first controller comprised in a same computing device as the physical SE component, and (b) the physical SE component is coupled via a second bus to a first peripheral component comprised in the same computing device,

wherein the SE hardware processor executes one or more secure element applications within a secure execution environment, wherein the SE application is configured to perform authentication through one or more secure channels with at least one device that is remote from the SE hardware processor;

receiving, by a second controller implemented by the SE hardware processor, a first message from the first peripheral component via the first bus;

applying, by the SE hardware processor, a security policy to the first message to generate a first validated message; and

transmitting, by the second controller, the first validated message to the first controller.

29. One or more non-transitory computer-readable media comprising instructions that, when executed by one or more hardware processors, cause performance of operations comprising:

executing a secure element (SE) application on a SE hardware processor comprised in a physical SE component, wherein: (a) the physical SE component is coupled via a first bus to a first controller comprised in a same computing device as the physical SE component, and (b) the physical SE component is coupled via a second bus to a first peripheral component comprised in the same computing device,

wherein the SE hardware processor executes one or more secure element applications within a secure execution environment, wherein the SE application is configured to perform authentication through one or more secure channels with at least one device that is remote from the SE hardware processor;

receiving, by a second controller implemented by the SE hardware processor, a first message from the first controller via the first bus;

applying, by the SE hardware processor, a security policy to the first message to generate a first validated message; and

transmitting, by the second controller, the first validated message to the first peripheral component via the second bus.

30. A system comprising:

at least one device including a hardware processor;

the system being configured to perform operations comprising:

executing a secure element (SE) application on a SE hardware processor comprised in a physical SE component, wherein: (a) the physical SE component is coupled via a first bus to a first controller comprised in a same computing device as the physical SE component, and (b) the physical SE component is coupled via a second bus to a first peripheral component comprised in the same computing device,

wherein the SE hardware processor executes one or more secure element applications within a secure execution environment, wherein the SE application is configured to perform authentication through one or more secure channels with at least one device that is remote from the SE hardware processor;

receiving, by a second controller implemented by the SE hardware processor, a first message from the first peripheral component via the first bus;

applying, by the SE hardware processor, a security policy to the first message to generate a first validated message; and

transmitting, by the second controller, the first validated message to the first controller.

31. A system comprising:

at least one device including a hardware processor

the system being configured to perform operations comprising:

executing a secure element (SE) application on a SE hardware processor comprised in a physical SE component, wherein: (a) the physical SE component is coupled via a first bus to a first controller comprised in a same computing device as the physical SE component, and (b) the physical SE component is coupled via a second bus to a first peripheral component comprised in the same computing device,

wherein the SE hardware processor executes one or more secure element applications within a secure execution environment, wherein the SE application is configured to perform authentication through one or more secure channels with at least one device that is remote from the SE hardware processor;

receiving, by a second controller implemented by the SE hardware processor, a first message from the first controller via the first bus;

applying, by the SE hardware processor, a security policy to the first message to generate a first validated message; and

transmitting, by the second controller, the first validated message to the first peripheral component via the second bus.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2022
From: PONSINI, NICOLAS MICHEL RAPHAËL; VAN HAVER, PATRICK
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 059801/0534 →
Continuity (1)
Related Publication 20230351028A1 · Nov 2, 2023
References Cited (33)
US 6112987A · Lambert et al. · 2000 [cited by applicant]
US 10063375B2 · Thom · 2018 [cited by examiner]
US 10084604B2 · Burghardt et al. · 2018 [cited by applicant]
US 20060085848A1 · Aissi et al. · 2006 [cited by applicant]
US 20070207798A1 · Talozi et al. · 2007 [cited by applicant]
US 20080147508A1 · Liu et al. · 2008 [cited by applicant]
US 20080230609A1 · Singh et al. · 2008 [cited by applicant]
US 20120108206A1 · Haggerty · 2012 [cited by applicant]
US 20120190354A1 · Merrien et al. · 2012 [cited by applicant]
US 20140123209A1 · Rajakarunanayake · 2014 [cited by examiner]
US 20140188713A1 · Alimi · 2014 [cited by applicant]
US 20140245272A1 · Wilkinson et al. · 2014 [cited by applicant]
US 20150127529A1 · Makhotin et al. · 2015 [cited by applicant]
US 20150134958A1 · Merrien et al. · 2015 [cited by applicant]
US 20150288686A1 · Pepin et al. · 2015 [cited by applicant]
US 20160088464A1 · Hans · 2016 [cited by applicant]
US 20160173493A1 · Wane · 2016 [cited by applicant]
US 20180026963A1 · Ning · 2018 [cited by examiner]
US 20180144137A1 · Rhelimi et al. · 2018 [cited by applicant]
US 20220124481A1 · Kang et al. · 2022 [cited by applicant]
US 20220159448A1 · Kang et al. · 2022 [cited by applicant]
US 20230217356A1 · Cogan et al. · 2023 [cited by applicant]
EP 1566941A1 · 2005 [cited by applicant]
GB 2328042A · 1999 [cited by applicant]
WO 2010089401A2 · 2010 [cited by applicant]
WO 2015179198A1 · 2015 [cited by applicant]
WO 2016030893A2 · 2016 [cited by applicant]
WO 2016108096A1 · 2016 [cited by applicant]
WO 2018162117A1 · 2018 [cited by applicant]
Samsung R&D Institute UK, “DRAFT Reply LS from ETSI TC SCP about the multiple logical interfaces support”, ETSI DRAFT; SCP(21)000112, European Telecommunications Standards Institute, Jul. 8, 2021. [cited by applicant]
“Baseline Security Recommendations for IoT”, Retrieved at https://www.enisa.europa.eu/publications/baseline-security-recommendations-for-iot, Nov. 20, 2017, 3 Pages. [cited by applicant]
“MIPI I3C and I3C Basic”, Retrieved at https://www.mipi.org/specifications/i3c-sensor-specification, Retrieved on May 2022, 8 Pages. [cited by applicant]
“NIST Releases Draft Guidance on Internet of Things Device Cybersecurity”, Retrieved at https://www.nist.gov/news-events/news/2020/12/nist-releases-draft-guidance-internet-things-device-cybersecurity, Retrieved on May 2… [cited by applicant]
Cited By (1)
US 12,468,825