Update of an operating system in a security element
A method is for updating an operating system, OS, administering a file system in a secure element, SE. The method includes the steps of providing an update agent in the SE; assuming control of the SE by the update agent from the operating system; loading an OS image into the SE, the OS image representing an update of the operating system; providing an updated operating system by installing the OS image; and handing over control of the SE by the update agent to the updated operating system. Within this update process, the update agent provides a provisional file system in the SE and administers the provisional file system as long as the update agent is in control of the SE. A respective secure element, a respective update agent, and to a respective computer-program product employ the method.
1 . A method for updating an operating system, OS, administering a file system in a secure element, SE, the method comprising:
providing an update agent in the SE;
assuming control of the SE by the update agent from the operating system;
loading an OS image into the SE, the OS image representing an update of the operating system;
providing an updated operating system by installing the OS image; and
handing over control of the SE by the update agent to the updated operating system;
wherein the update agent provides a provisional file system in the SE and administers the provisional file system as long as the update agent is in control of the SE,
wherein the update agent provides the provisional file system so that it is transparent to an external terminal that the operating system and/or the file system is not available as long as the update agent is in control of the SE.
2 . The method according to claim 1 , wherein the update agent provides the provisional file system so that it contains the minimum functionality required to process commands of an external terminal.
3 . The method according to claim 1 , wherein the update agent provides the provisional file system so that the SE is not deactivated and/or disconnected by an external terminal in reaction to a command sent to the SE.
4 . The method according to claim 1 , wherein the update agent provides the provisional file system in a memory structure of the update agent.
5 . The method according to claim 1 , wherein the update agent provides the provisional file system as a data grouping with a data grouping identifier, DGI, and in a TLV format keeping parent/child file relationships of the file system.
6 . The method according to claim 1 , wherein the update agent keeps a pointer to a selected file of the provisional file system, for example in reaction to a file-related command received from an external terminal, and/or responds a status byte in reaction to a file-unrelated command received from an external terminal.
7 . The method according to claim 1 , wherein the update agent is provided by loading the update agent into the SE during a production phase of the SE, while the OS image is loaded into and installed on the SE in a subsequent phase after a production phase of the SE.
8 . The method according to claim 1 , wherein the provisional file system is provided as a part of the update agent, comprised in personalization data of the update agent, and/or upon loading the update agent into the SE during a production phase of the SE.
9 . A secure element, SE, comprising a non-transitory computer-readable storage medium with an update agent and an operating system, OS, embedded therein, the OS administering a file system and the update agent being configured to:
assume control of the SE from the operating system;
load an OS image into the SE, the OS image representing an update of the operating system;
provide an updated operating system by installing the OS image; and
hand over control of the SE by the update agent to the updated operating system;
wherein the update agent is further configured to provide a provisional file system in the SE and to administer the provisional file system as long as the update agent is in control of the SE,
wherein the update agent is configured to provide the provisional file system so that it is transparent to an external terminal that the operating system and/or the file system is not available as long as the update agent is in control of the SE.
10 . The secure element according to claim 9 , wherein the update agent is further configured to conduct a method for updating an operating system, OS, administering a file system in a secure element, SE, when it is executed by a processor of the secure element, the method comprising:
providing an update agent in the SE;
assuming control of the SE by the update agent from the operating system;
loading an OS image into the SE, the OS image representing an update of the operating system;
providing an updated operating system by installing the OS image; and
handing over control of the SE by the update agent to the updated operating system;
wherein the update agent provides a provisional file system in the SE and administers the provisional file system as long as the update agent is in control of the SE.
11 . An update agent embedded in a non-transitory computer-readable storage medium for use in a secure element, SE, the update agent being configured to:
assume control of the SE from an operating system;
load an OS image into the SE, the OS image representing an update of the operating system;
provide an updated operating system by installing the OS image; and
hand over control of the SE by the update agent to the updated operating system;
wherein the update agent is further configured to provide a provisional file system in the SE and to administer the provisional file system as long as the update agent is in control of the SE,
wherein the update agent is configured to provide the provisional file system so that it is transparent to an external terminal that the operating system and/or the file system is not available as long as the update agent is in control of the SE.
12 . The update agent according to claim 11 , wherein the update agent is further configured to conduct a method for updating an operating system, OS, administering a file system in a secure element, SE, when it is executed by a processor of the secure element, the method comprising:
providing an update agent in the SE;
assuming control of the SE by the update agent from the operating system;
loading an OS image into the SE, the OS image representing an update of the operating system;
providing an updated operating system by installing the OS image; and
handing over control of the SE by the update agent to the updated operating system;
wherein the update agent provides a provisional file system in the SE and administers the provisional file system as long as the update agent is in control of the SE;
and/or is realized as an executable software product configured to be installed on a security element and to be executed by a processor of the security element, the secure element comprising an operating system, OS, administering a file system and an update agent configured to:
assume control of the SE from the operating system;
load an OS image into the SE, the OS image representing an update of the operating system;
provide an updated operating system by installing the OS image; and
hand over control of the SE by the update agent to the updated operating system;
wherein the update agent is further configured to provide a provisional file system in the SE and to administer the provisional file system as long as the update agent is in control of the SE.
13 . The secure element according to claim 9 , or an update agent for use in a secure element, the update agent being configured to:
assume control of the SE from the operating system;
load an OS image into the SE, the OS image representing an update of the operating system;
provide an updated operating system by installing the OS image; and
hand over control of the SE by the update agent to the updated operating system;
wherein the update agent is further configured to provide a provisional file system in the SE and to administer the provisional file system as long as the update agent is in control of the SE;
wherein the update agent is configured:
to provide the provisional file system so that it contains the minimum functionality required to process commands of an external terminal and/or so that the SE is not deactivated and/or disconnected by an external terminal in reaction to a command sent to the SE and/or so that it is transparent to an external terminal that the operating system and/or the file system is not available as long as the update agent is in control of the SE, and
to provide the provisional file system in a memory structure of the update agent, as a data grouping with a data grouping identifier, DGI, in a TLV format keeping parent/child file relationships of the file system.
14 . A computer-program product for use in conjunction with a secure element, SE, in an electronic device, the computer-program product comprising a non-transitory computer-readable storage medium and a computer-program mechanism embedded therein, to load a software into the secure element in the electronic device, the computer-program mechanism including:
instructions for assuming control of the SE from an operating system;
loading an OS image into the SE, the OS image representing an update of the operating system;
providing an updated operating system by installing the OS image; and
handing over control of the SE by the computer-program mechanism to the updated operating system;
wherein the computer-program mechanism further includes instructions for providing a provisional file system in the SE and for administering the provisional file system as long as the computer-program mechanism is in control of the SE so that it is transparent to an external terminal that the operating system and/or the file system is not available as long as the computer-program mechanism is in control of the SE.