IP Library Granted Patent US 12,481,996
Granted Patent B2
US 12,481,996 · App. 18/487,723 · Granted Nov 25, 2025

Secure element having multiple CRS applets

Inventors: Herve Sibert (Le Mans, FR); Oren M. Elrad (San Francisco, CA); Jerrold V. Hauck (Windermere, FL); Onur E. Tackin (Sunnyvale, CA); Zachary A. Rosen (San Francisco, CA); Matthias Lerch (Paris, FR)
Assignee: Apple Inc.
G06Q20/40145G06F21/31G06F21/32G06Q20/204G06Q20/3278G06Q20/382G06Q20/4014H04L9/3231H04W12/065H04W12/068
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,481,996
App. No.
18/487,723
Granted
Nov 25, 2025
Kind
B2
Abstract

Techniques are disclosed relating to secure data storage. In various embodiments, a mobile device includes a wireless interface, a secure element, and a secure circuit. The secure element is configured to store confidential information associated with a plurality of users and to receive a request to communicate the confidential information associated with a particular one of the plurality of users. The secure element is further configured to communicate, via the wireless interface, the confidential information associated with the particular user in response to an authentication of the particular user. The secure circuit is configured to perform the authentication of the particular user. In some embodiments, the mobile device also includes a biosensor configured to collect biometric information from a user of the mobile device. In such an embodiment, the secure circuit is configured to store biometric information collected from the plurality of users by the biosensor.

Claims (67)

1 . A mobile device, comprising:

a contactless interface;

a secure element associated with the contactless interface,

wherein the secure element is configured to:

store a first contactless registry service (CRS) applet and a first applet within the secure element, wherein the first CRS applet is executable by the secure element to restrict communication of a first confidential information associated with the first applet via the contactless interface, wherein the first applet stores the first confidential information; and

store a second CRS applet and a second applet within the secure element, wherein the second CRS applet is executable by the secure element to restrict communication of a second confidential information associated with the second applet via the contactless interface, wherein the second applet stores the second confidential information;

wherein the mobile device further comprises:

a processor; and

a memory having program instructions stored therein that, when executed by the processor, cause the processor to:

receive a first request from a user to use the first applet;

in response to receiving the first request, select the first CRS applet, wherein selecting the first CRS applet further comprises instructing the secure element to execute the selected first CRS applet to cause communication of the first confidential information associated with the selected first CRS applet;

wherein the secure element is further configured to:

execute the first CRS applet;

execute the first applet; and

communicate the first confidential information stored in the first applet to an external system via the contactless interface for the first request.

2 . The mobile device of claim 1 , wherein receiving the first request further comprises:

receiving an indication of the user of the mobile device; and

based on the indication, selecting the first CRS applet.

3 . The mobile device of claim 1 , wherein the program instructions that, when executed by the processor, further cause the processor to:

in response to the first request, cause performance of an authentication of the user of the mobile device.

4 . The mobile device of claim 3 , further comprising:

a secure circuit coupled to the secure element,

wherein the secure circuit is configured to:

perform the authentication of the user of the mobile device; and

based on the authentication, determine whether to authorize execution of the selected first CRS applet.

5 . The mobile device of claim 3 , further comprising:

a secure circuit coupled to the secure element, wherein the secure circuit is configured to:

perform the authentication of the user of the mobile device; and

communicate a result with the executed first CRS applet.

6 . The mobile device of claim 5 , wherein the secure circuit is further configured to:

communicate securely with the executed first CRS applet using a cryptographic key.

7 . The mobile device of claim 3 , further comprising:

a biosensor configured to collect biometric information from the user of the mobile device to perform the authentication.

8 . The mobile device of claim 1 , wherein the program instructions that, when executed by the processor, further cause the processor to:

receive the first request from an interface application that presents a user interface to the user of the mobile device.

9 . The mobile device of claim 1 , wherein the first CRS applet is executable by the secure element to:

maintain a list of identifiers of applets associated with the first CRS applet.

10 . The mobile device of claim 1 , wherein the contactless interface is a near field communication interface.

11 . A non-transitory computer readable medium storing program instructions that, when executed by one or more processors of a device, cause the one or more processors to perform operations comprising:

storing, within a secure element of the device, a first contactless registry service (CRS) applet and a first applet, wherein the first CRS applet is executable by the secure element to restrict communication of a first confidential information associated with the first applet via a contactless interface of the device, wherein the first applet stores the first confidential information;

storing, within the secure element, a second CRS applet and a second applet, wherein the second CRS applet is executable by the secure element to restrict communication of second confidential information associated with the second applet via the contactless interface, wherein the second applet stores the second confidential information;

receiving a first request from a user to use the first applet;

in response to receiving the first request, selecting the first CRS applet, wherein selecting the first applet comprises instructing the secure element to execute the selected first CRS applet to cause communication of the first confidential information associated with the selected first CRS applet;

executing, via the secure element, the first CRS applet;

executing, via the secure element, the first applet; and

communicating, via the contactless interface, the first confidential information stored in the first applet to an external system via the contactless interface for the first request.

12 . The non-transitory computer readable medium of claim 11 , wherein the program instructions that, when executed by the one or more processors, further cause the one or more processors to perform additional operations comprising:

causing, via the executed first CRS applet, a verification that the user of the device has been authenticated.

13 . The non-transitory computer readable medium of claim 12 , the program instructions that, when executed by the one or more processors, further cause the one or more processors to perform additional operations comprising:

establishing, via the executed first CRS applet, a secure connection with a secure circuit configured to authenticate the user.

14 . The non-transitory computer readable medium of claim 11 , the program instructions that, when executed by the one or more processors, further cause the one or more processors to perform additional operations comprising:

storing, via the selected first CRS applet, a list of applets associated with authorized to communicate confidential information via the contactless interface.

15 . The non-transitory computer readable medium of claim 11 , the program instructions that, when executed by the one or more processors, further cause the one or more processors to perform additional operations comprising:

receiving the first request from an interface application that receives a menu selection from the user of the device.

16 . A method, comprising:

storing, by a mobile device and within a secure element of the mobile device, a first applet and a first contactless registry service (CRS) applet, wherein the first CRS applet is executable by the secure element to restrict communication of a first confidential information associated with the first applet via a contactless interface of the device, wherein the first applet stores the first confidential information;

storing, by the mobile device and within the secure element, a second applet and a second CRS applet, wherein the second CRS applet is executable by the secure element to restrict communication of second confidential information associated with the second applet via the contactless interface, wherein the second applet stores the second confidential information;

receiving, by the mobile device, a first request from a user to use the first applet;

in response to the first request, selecting, by the mobile device, the first CRS applet, wherein the selecting comprises instructing, by the mobile device, the secure element to execute the selected first CRS applet to cause communication of first confidential information of the first applet associated with the selected first CRS applet;

executing, by the mobile device via the secure element, the first CRS applet;

executing, by the mobile device via the secure element, the first applet; and

communicating, via a contactless interface of the mobile device, the first confidential information stored in the first applet to an external system via the contactless interface for the first request.

17 . The method of claim 16 , further comprising:

prior to communicating of the first confidential information of the first applet via the contactless interface, performing, by the mobile device, an authentication of the user of the mobile device.

18 . The method of claim 17 , wherein the performing the authentication comprises using a biosensor that collects biometric information from the user of the mobile device.

19 . The method of claim 18 , wherein the performing the authentication further comprises comparing, by the mobile device via a secure circuit of the mobile device, the collected biometric information with biometric information of an authorized user.

20 . The method of claim 18 , wherein the biosensor includes an infrared (IR) emitter and an IR camera configured to capture images of a biometric.

Continuity (4)
Continuation 17384488 · Jul 23, 2021
Continuation 15709925 · Sep 20, 2017
Provisional Application 62399297 · Sep 23, 2016
Related Publication 20240185245A1 · Jun 6, 2024
References Cited (36)
US 8196131B1 · von Behren · 2012 [cited by applicant]
US 8775757B2 · Polzin et al. · 2014 [cited by applicant]
US 8832465B2 · Gulati et al. · 2014 [cited by applicant]
US 9503894B2 · Shanmugam · 2016 [cited by examiner]
US 9547778B1 · Paaske et al. · 2017 [cited by applicant]
US 20060213982A1 · Cannon et al. · 2006 [cited by applicant]
US 20130174266A1 · Smrz · 2013 [cited by examiner]
US 20140058937A1 · Watson · 2014 [cited by examiner]
US 20140143826A1 · Sharp · 2014 [cited by examiner]
US 20140298484A1 · Sung · 2014 [cited by examiner]
US 20150078550A1 · Ferguson et al. · 2015 [cited by applicant]
US 20150095238A1 · Khan · 2015 [cited by examiner]
US 20150127549A1 · Khan · 2015 [cited by examiner]
US 20150257004A1 · Shanmugam et al. · 2015 [cited by applicant]
US 20150348008A1 · Khan · 2015 [cited by applicant]
US 20160171192A1 · Holz · 2016 [cited by examiner]
US 20170262267A1 · Hans · 2017 [cited by examiner]
CN 105474224A · 2016 [cited by applicant]
CN 105684009A · 2016 [cited by applicant]
CN 105794244A · 2016 [cited by applicant]
JP 2015207217A · 2015 [cited by applicant]
KR 20150016369A · 2015 [cited by examiner]
WO 9219078 · 1992 [cited by applicant]
WO 2012042262 · 2012 [cited by applicant]
WO 2014031183A1 · 2014 [cited by applicant]
GlobalPlatform Card Contactless Services Card Specification v2.2-Amendment C Version 1.1, Apr. 2013 (Year: 2013). [cited by examiner]
IOS Security—White Paper, Apple Inc., Mar. 2017, pp. 1-68. [cited by applicant]
Invitation to pay additional fees & partial International Search in Application No. PCT/US2017/053107 mailed Dec. 8, 2017, 15 pages. [cited by applicant]
Contactless Services: Card Specification v2. 2—Amendment C, Version 1.1.1, GlobalPlatform Card Technology, Jul. 31, 2014, XP055189214, 126 pages. [cited by applicant]
International Search Report & Written Opinion in in Application No. PCT/US2017/053107 mailed Mar. 29, 2018, 24 pages. [cited by applicant]
Written Opinion of the International Preliminary Examining Authority in Appl. No. PCT/US2017/053107, mailed Aug. 20, 2018, 13 pages. [cited by applicant]
International Preliminary Report on Patentability in PCT Appl. No. PCT/US2017/053107 mailed Jan. 7, 2019, 16 pages. [cited by applicant]
Examination Report in Australian Appl. No. 2017330439 mailed Feb. 14, 2020, 3 pages. [cited by applicant]
GlobalPlatform, Inc., The Introduction to Secure Elements, May 2018, 9 pages. [cited by applicant]
Examination Report No. 3 in Australian Appl. No. 2017330439 mailed Oct. 16, 2020, 8 pages. [cited by applicant]
Office Action in Chinese Appl. No. 201780053136.0 mailed Oct. 12, 2022, 8 pages. [cited by applicant]