IP Library › Granted Patent US 12,603,777
Granted Patent B2
US 12,603,777 · App. 18/756,159 · Granted Apr 14, 2026

Executing digital signature operations in a secure element platform runtime environment

Inventors: Sebastian Jürgen Hans (Berlin, DE); Nicolas Michel Raphaël Ponsini (Mougins, FR)
Assignee: Oracle International Corporation
H04L9/321H04L9/0861H04L9/3236H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,603,777
App. No.
18/756,159
Filed
Jun 27, 2024
Granted
Apr 14, 2026
Kind
B2
Examiner
KING, JOHN B
Art Unit
2498
USPC
713/155
Abstract

One or more embodiments initialize a signature validation object in a secure element (SE) platform runtime environment and utilize the signature validation object to perform signature validation operations. A system accesses an authentication path that includes a set of hash values corresponding to a set of nodes of a tree structure associated with a hash-based signature protocol utilized to generate a digital signature. The system computes a root hash value corresponding to a root node of the tree structure based on the set of hash values of the authentication path. The system verifies the root hash value against a root public key associated with the digital signature. The system determines that the digital signature is valid responsive at least in part to successfully verifying the root hash value against the root public key.

Claims (129)

1 . One or more non-transitory computer-readable media comprising instructions that, when executed by one or more hardware processors, cause performance of operations comprising:

initializing a signature validation object in a secure element (SE) platform runtime environment,

wherein the SE platform runtime environment is executing on at least one SE processor of a SE hardware device;

obtaining, via the signature validation object, an authentication path comprising a set of hash values corresponding to a set of nodes of a tree structure associated with a hash-based signature protocol utilized to generate a digital signature;

computing, via the signature validation object, a root hash value corresponding to a root node of the tree structure based on the set of hash values of the authentication path;

wherein computing the root hash value of the tree structure comprises:

computing a first intermediate hash value based at least in part on (a) a public key corresponding to a private key utilized to generate the digital signature and (b) a first hash value of the set of hash values;

determining that the set of hash values comprises a second hash value that has yet to be utilized in computing the root hash value;

responsive at least in part to determining that the set of hash values comprises the second hash value, computing a second intermediate hash value at least by applying a hash function to a concatenation of the first intermediate hash value and the second hash value;

wherein computing the root hash value of the tree structure further comprises:

prior to determining that the set of hash values comprises the second hash value that has yet to be utilized in computing the root hash value:

storing the first intermediate hash value in a first transient memory element of the SE hardware device;

initializing a temporary entry point object comprising a pointer to the first transient memory element;

responsive at least in part to determining that the set of hash values comprises the second hash value:

accessing the first intermediate hash value via the temporary entry point object;

computing the second intermediate hash value at least by applying the hash function to the concatenation of the first intermediate hash value and the second hash value;

verifying, via the signature validation object, the root hash value against a root public key associated with the digital signature;

determining, via the signature validation object, that the digital signature is valid responsive at least in part to successfully verifying the root hash value against the root public key.

2 . The one or more non-transitory computer-readable media of claim 1 , wherein computing the root hash value of the tree structure comprises:

determining that the set of hash values has been utilized in computing the root hash value;

responsive at least in part to determining that the set of hash values has been utilized in computing the root hash value, selecting the second intermediate hash value as the root hash value.

3 . The one or more non-transitory computer-readable media of claim 1 , wherein computing the second intermediate hash value comprises:

generating a first hash segment at least by executing the hash function on a first concatenation segment representing a first portion of the concatenation of the first intermediate hash value and the second hash value; and

generating a second hash segment at least by executing the hash function on a second concatenation segment representing a second portion of the concatenation of the first intermediate hash value and the second hash value

combining the first hash segment and the second hash segment.

4 . The one or more non-transitory computer-readable media of claim 3 , wherein computing the second intermediate hash value further comprises:

initializing a hash segment generation object in the SE platform runtime environment;

generating the first hash segment via the hash segment generation object;

directing, via a shareable interface object, the first hash segment from a first SE application, corresponding to the hash segment generation object to a second SE application corresponding to the signature validation object;

directing, via the shareable interface object, the second hash segment from the first SE application to the second SE application;

generating, via the signature validation object, the second intermediate hash value at least by combining the first hash segment and the second hash segment.

5 . The one or more non-transitory computer-readable media of claim 4 , wherein computing the second intermediate hash value further comprises:

prior to generating the second hash segment:

storing the first hash segment in the first transient memory element of the SE hardware device;

initializing the temporary entry point object comprising the pointer to the first transient memory element;

subsequent to generating the second hash segment:

accessing the first hash segment via the temporary entry point object;

combining the first hash segment and the second hash segment.

6 . The one or more non-transitory computer-readable media of claim 3 , wherein computing the second intermediate hash value further comprises:

prior to generating the first hash segment and the second hash segment:

determining, based at least in part on the hash function, a hash length corresponding to the second intermediate hash value;

determining, based at least in part on the hash length, a hash segment length representing a portion of the hash length;

determining at least one of:

(a) the first concatenation segment based at least in part on the hash segment length, wherein the first concatenation segment comprises a first concatenation segment length corresponding to the hash segment length, or

(b) the second concatenation segment based at least in part on the hash segment length, wherein the second concatenation segment comprises a second concatenation segment length corresponding to the hash segment length.

7 . The one or more non-transitory computer-readable media of claim 6 , wherein computing the second intermediate hash value comprises:

determining a combined length corresponding to a combination of the first hash segment and the second hash segment;

determining that the combined length matches the hash length;

determining, based at least in part on the combined length matching the hash length, that computing the second intermediate hash value is complete.

8 . The one or more non-transitory computer-readable media of claim 1 , wherein computing the root hash value of the tree structure comprises:

determining, based on an index value accompanying the authentication path, the public key corresponding to the private key utilized to generate the digital signature, wherein the index value corresponds to a key pair index that identifies a first leaf node of the tree structure;

computing the first hash value based at least in part on the public key;

determining, from the authentication path, the second hash value corresponding to an intermediate node of the tree structure;

computing the root hash value of the tree structure at least by applying the hash function to a first combination of the first hash value and the second hash value.

9 . The one or more non-transitory computer-readable media of claim 8 , wherein computing the first hash value based at least in part on the public key comprises:

determining, from the index value accompanying the authentication path, a leaf hash value corresponding to a second leaf node of the tree structure, wherein the public key is associated with the first leaf node of the tree structure, and wherein the second leaf node is a sibling node of the first leaf node;

computing the first intermediate hash value at least by applying the hash function to a second combination of the public key and the leaf hash value;

computing the first hash value based at least in part on the first intermediate hash value.

10 . The one or more non-transitory computer-readable media of claim 1 , wherein computing the root hash value of the tree structure comprises:

determining, based on an index value accompanying the authentication path, the public key corresponding to the private key utilized to generate the digital signature, wherein the index value corresponds to a key pair index that identifies a key pair comprising the public key, wherein the public key is associated with a first leaf node of the tree structure;

determining, from the authentication path, the first hash value associated with a second leaf node of the tree structure, wherein the first leaf node is a first sibling node of the second leaf node;

generating the second hash value, for a first parent node of the first leaf node and the second leaf node, at least by applying the hash function to a first concatenation of the public key and the first hash value, wherein the first parent node is a first intermediate node of the tree structure;

computing the root hash value of the tree structure based at least in part on the second hash value.

11 . The one or more non-transitory computer-readable media of claim 10 , wherein computing the root hash value of the tree structure based at least in part on the second hash value comprises:

determining, from the authentication path, a third hash value associated with a second intermediate node of the tree structure, wherein the second intermediate node is a second sibling node of the first intermediate node;

generating a fourth hash value, for a second parent node of the first intermediate node and the second intermediate node, at least by applying the hash function to a second concatenation of the second hash value and the third hash value;

computing the root hash value of the tree structure based at least in part on the fourth hash value.

12 . The one or more non-transitory computer-readable media of claim 11 , wherein computing the root hash value of the tree structure based at least in part on the fourth hash value comprises:

generating a fifth hash value based at least in part on (a) the fourth hash value and (b) one or more additional hash values determined from the authentication path;

determining that the fifth hash value is the root hash value of the tree structure.

13 . The one or more non-transitory computer-readable media of claim 1 , wherein the operations further comprise at least one of:

executing, in the SE platform runtime environment, at least one operation on a message associated with the digital signature responsive at least in part to determining that the digital signature is valid; or

outputting, from the SE platform runtime environment to a hardware device, a signature validation indicator comprising an indication that the digital signature is valid responsive at least in part to determining that the digital signature is valid.

14 . The one or more non-transitory computer-readable media of claim 1 , wherein the hash-based signature protocol comprises at least one of: a stateful hash-based signature protocol, a stateless hash-based signature protocol, or a one-time hash-based signature protocol.

15 . The one or more non-transitory computer-readable media of claim 1 , wherein the operations further comprise:

receiving, by a first SE application from a second SE application via a shareable interface object, a signature validation request for the first SE application to execute a signature validation process for validating the digital signature;

wherein, responsive at least in part to receiving the signature validation request, the first SE application initializes the signature validation object for executing at least a portion of the signature validation process.

16 . The one or more non-transitory computer-readable media of claim 1 , wherein the operations further comprise:

obtaining, via the signature validation object, the digital signature and the public key corresponding to the private key utilized to generate the digital signature;

computing, via the signature validation object, a verification value at least by applying a verification protocol to the digital signature and the public key;

computing, via the signature validation object, a message digest at least by applying the hash function to a message associated with the digital signature;

verifying, via the signature validation object, the verification value against the message digest;

determining, via the signature validation object, that the digital signature is valid further responsive at least in part to successfully verifying the verification value against the message digest.

17 . A method, comprising:

initializing a signature validation object in a secure element (SE) platform runtime environment, wherein the SE platform runtime environment is executing on at least one SE processor of a SE hardware device;

accessing, via the signature validation object, an authentication path comprising a set of hash values corresponding to a set of nodes of a tree structure associated with a hash-based signature protocol utilized to generate a digital signature;

computing, via the signature validation object, a root hash value corresponding to a root node of the tree structure based on the set of hash values of the authentication path;

wherein computing the root hash value of the tree structure comprises:

computing a first intermediate hash value based at least in part on (a) a public key corresponding to a private key utilized to generate the digital signature and (b) a first hash value of the set of hash values;

determining that the set of hash values comprises a second hash value that has yet to be utilized in computing the root hash value;

responsive at least in part to determining that the set of hash values comprises the second hash value, computing a second intermediate hash value at least by applying a hash function to a concatenation of the first intermediate hash value and the second hash value;

wherein computing the root hash value of the tree structure further comprises:

prior to determining that the set of hash values comprises the second hash value that has yet to be utilized in computing the root hash value:

storing the first intermediate hash value in a first transient memory element of the SE hardware device;

initializing a temporary entry point object comprising a pointer to the first transient memory element;

responsive at least in part to determining that the set of hash values comprises the second hash value:

accessing the first intermediate hash value via the temporary entry point object;

computing the second intermediate hash value at least by applying the hash function to the concatenation of the first intermediate hash value and the second hash value;

verifying, via the signature validation object, the root hash value against a root public key associated with the digital signature;

determining, via the signature validation object, that the digital signature is valid responsive at least in part to successfully verifying the root hash value against the root public key.

18 . A system comprising:

at least one secure element (SE) hardware processor;

the system being configured to perform operations comprising:

initializing a signature validation object in a secure element (SE) platform runtime environment,

wherein the SE platform runtime environment is executing on at least one SE processor of a SE hardware device;

accessing, via the signature validation object, an authentication path comprising a set of hash values corresponding to a set of nodes of a tree structure associated with a hash-based signature protocol utilized to generate a digital signature;

computing, via the signature validation object, a root hash value corresponding to a root node of the tree structure based on the set of hash values of the authentication path;

wherein computing the root hash value of the tree structure comprises:

computing a first intermediate hash value based at least in part on (a) a public key corresponding to a private key utilized to generate the digital signature and (b) a first hash value of the set of hash values;

determining that the set of hash values comprises a second hash value that has yet to be utilized in computing the root hash value;

responsive at least in part to determining that the set of hash values comprises the second hash value, computing a second intermediate hash value at least by applying a hash function to a concatenation of the first intermediate hash value and the second hash value;

wherein computing the root hash value of the tree structure further comprises:

prior to determining that the set of hash values comprises the second hash value that has yet to be utilized in computing the root hash value:

storing the first intermediate hash value in a first transient memory element of the SE hardware device;

initializing a temporary entry point object comprising a pointer to the first transient memory element;

responsive at least in part to determining that the set of hash values comprises the second hash value:

accessing the first intermediate hash value via the temporary entry point object;

computing the second intermediate hash value at least by applying the hash function to the concatenation of the first intermediate hash value and the second hash value;

verifying, via the signature validation object, the root hash value against a root public key associated with the digital signature;

determining, via the signature validation object, that the digital signature is valid responsive at least in part to successfully verifying the root hash value against the root public key.

19 . The method of claim 17 , wherein computing the second intermediate hash value comprises:

generating a first hash segment at least by executing the hash function on a first concatenation segment representing a first portion of the concatenation of the first intermediate hash value and the second hash value; and

generating a second hash segment at least by executing the hash function on a second concatenation segment representing a second portion of the concatenation of the first intermediate hash value and the second hash value

combining the first hash segment and the second hash segment.

20 . The method of claim 17 , wherein computing the root hash value of the tree structure comprises:

determining, based on an index value accompanying the authentication path, the public key corresponding to the private key utilized to generate the digital signature, wherein the index value corresponds to a key pair index that identifies a first leaf node of the tree structure;

computing the first hash value based at least in part on the public key;

determining, from the authentication path, the second hash value corresponding to an intermediate node of the tree structure;

computing the root hash value of the tree structure at least by applying the hash function to a first combination of the first hash value and the second hash value.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2024
From: ORACLE DEUTSCHLAND B.V. & CO. KG
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 068957/0209 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 3, 2024
From: HANS, SEBASTIAN JÜRGEN
To: ORACLE DEUTSCHLAND B.V. & CO. KG
Reel/Frame 067907/0859 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2024
From: PONSINI, NICOLAS MICHEL RAPHAËL
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 067873/0185 →
Continuity (2)
Provisional Application 63595907 · Nov 3, 2023
Related Publication 20260058812A1 · Feb 26, 2026
References Cited (55)
US 10218511B2 · Campagna · 2019 [cited by examiner]
US 10880278B1 · de Quehen · 2020 [cited by examiner]
US 12063313B2 · De Santis · 2024 [cited by examiner]
US 12445303B2 · van Vredendaal · 2025 [cited by examiner]
US 20040221158A1 · Olkin · 2004 [cited by examiner]
US 20100042842A1 · Huang · 2010 [cited by examiner]
US 20160266943A1 · Hans · 2016 [cited by examiner]
US 20190171849A1 · Assenmacher · 2019 [cited by examiner]
US 20190319801A1 · Sastry · 2019 [cited by examiner]
US 20190319802A1 · Misoczki et al. · 2019 [cited by applicant]
US 20210073647A1 · Hunter · 2021 [cited by examiner]
US 20210099309A1 · Winarski · 2021 [cited by examiner]
US 20220086009A1 · Vacek · 2022 [cited by examiner]
US 20220131707A1 · Chen · 2022 [cited by examiner]
US 20220191037A1 · Hassanzadeh Nazarabadi · 2022 [cited by examiner]
US 20220255735A1 · Masny et al. · 2022 [cited by applicant]
US 20220263663A1 · Chen · 2022 [cited by examiner]
US 20220278859A1 · Mackay · 2022 [cited by examiner]
US 20240080204A1 · Van Vredendaal · 2024 [cited by examiner]
US 20240356736A1 · Relyea · 2024 [cited by examiner]
US 20250148071A1 · Ponsini · 2025 [cited by examiner]
US 20250150282A1 · Hans · 2025 [cited by examiner]
EP 3758290A1 · 2020 [cited by applicant]
EP 4440036A1 · 2024 [cited by examiner]
WO 2019071026A1 · 2019 [cited by applicant]
WO 2021062517A1 · 2021 [cited by applicant]
WO WO2025096254A1 · 2025 [cited by examiner]
WO WO2025096266A1 · 2025 [cited by examiner]
WO WO2025096268A1 · 2025 [cited by examiner]
Ando, M., et al., “Hash-based TPM signatures for the quantum world.”, International Conference on Applied Cryptography and Network Security, Jun. 9, 2016, pp. 77-94. [cited by applicant]
Banerjee T. et al., “Post-Quantum Cryptography for Engineers”, draft-ietfpquip-pqc-engineers-00; draft-ietf-pquip-pqc-engineers-00.txt, Internet-draft: Pquip, Internet Engineering Task Force, Ietf, Standardworkingdraft,… [cited by applicant]
Chalkias, K., et al., “Blockchained post-quantum signatures.”, International Conference on Internet of Things, Jul. 30, 2018, pp. 1196-1203. [cited by applicant]
Iftikhar, Z., et al., “Quantum safe cloud computing using hash-based digital signatures.”, International Conference on Automation and Computing, Sep. 2, 2021, pp. 1-6. [cited by applicant]
Ulitzsch V.Q., et al., “A Post-Quantum Secure Subscription Concealed Identifier for 6G”, Proceedings of the Twelveth Acm Conference On Data and Application Security and Privacy, Acmpub27, May 16-19, 2022, pp. 157-168 (1… [cited by applicant]
“Comments Requested on Three Draft FIPS for Post-Quantum Cryptography,” CSRC, Aug. 24, 2023, pp. 3., Feb. 14, 2024. [cited by applicant]
“CYBER; Quantum-safe Hybrid Key Exchanges,” TS 103 744 V1.1.1, Dec. 2020, pp. 42. [cited by applicant]
“Java Card Platform Specification Release Notes”, Version 3.2, Jan. 2023, pp. 1-18. [cited by applicant]
“Java Card™ Platform, Application Programming Interface, Classic Edition Version 3.2”, Retrieved from https://docs.oracle.com/en/java/javacard/3.2/jcapi/api_classic/index.html, Retrieved on Jul. 25, 2024, pp. 1-5. [cited by applicant]
“Runtime Environment Specification, Classic Edition”, Version 3.2, Java Card™ Platform, Jan. 2023, pp. 1-136. [cited by applicant]
“Virtual Machine Specification, Classic Edition”, Version 3.2, Java Card™ Platform, Jan. 2023, pp. 1-274. [cited by applicant]
Barnes. R. et al., “RFC 9180_Hybrid Public Key Encryption,” Feb. 2022, pp. 85. [cited by applicant]
Cooper et al., “Recommendation for Stateful Hash-Based Signature Schemes”, NIST SP 800-208, Oct. 2020, pp. 59. [cited by applicant]
Fluhrer et al., “Additional Parameter sets for HSS/LMS Hash-Based Signatures”, Sep. 18, 2023, pp. 20. [cited by applicant]
Huelsing et al., “XMSS: extended Merkle Signature Scheme”, Retrieved from https://datatracker.ietf.org/doc/html/rfc8391, May 2018, pp. 1-74. [cited by applicant]
McGrew et al., “Leighton-Micali Hash-Based Signatures”, Apr. 2019, pp. 1-61. [cited by applicant]
National Institute of Standards and Technology, “Stateless Hash-Based Digital Signature Standard”, FIPS 205 (Draft), Aug. 24, 2023, pp. 58. [cited by applicant]
Ounsworth. M. et al., “Combiner function for hybrid key encapsulation mechanisms (Hybrid KEMs),” Jan. 9, 2024, pp. 13. [cited by applicant]
Wood C., “HPKE: Standardizing public-key encryption (finally!),” Feb. 24, 2022, pp. 15. [cited by applicant]
“Document Search”, Retrieved from https://datatracker.ietf.org/doc/search?name=draft-ietf-lamps-pq-composit&rfcs=on&activedrafts=on&olddrafts=on, Retrieved on Mar. 4, 2025, p. 1. [cited by applicant]
“Falcon: Fast-Fourier Lattice-based Compact Signatures over NTRU”, Specification v1.2, Jan. 10, 2020, pp. 1-67. [cited by applicant]
“Information technology—Open Systems Interconnection—The Directory: Public-key and attribute certificate frameworks”, Recommendation ITU-T X.509, Oct. 2019, pp. 236. [cited by applicant]
“ITU-T Recommendations”, Retrieved from https://handle.itu.int/11.1002/1000/14033, Oct. 14, 2019, pp. 1-2. [cited by applicant]
“Module-Lattice-Based Digital Signature Standard”, Federal Information Processing Standards Publication, Aug. 13, 2024, pp. 65. [cited by applicant]
Ounsworth et al., “Composite ML-DSA for use in Internet PKI”, Mar. 4, 2024, 34 Pages. [cited by applicant]
Ounsworth et al., “Composite ML-DSA for use in X.509 Public Key Infrastructure and CMS”, Mar. 3, 2025, pp. 65. [cited by applicant]