SECURE LOADING OF SECRET DATA TO NON-PROTECTED HARDWARE REGISTERS

    公开(公告)号:US20190311154A1

    公开(公告)日:2019-10-10

    申请号:US16315105

    申请日:2017-06-14

    Applicant: GEMALTO SA

    Abstract: The present invention relates to a method to securely load set of sensitive data hardware registers with sensitive data on a chip supporting hardware cryptography operations, said method comprising the following steps monitored by software instructions, at each run of a software: select a set of available hardware registers listed in a predefined list listing, in the chip architecture, the unused hardware registers and other relevant hardware registers not handling sensitive data and not disrupting chip functionality when loaded, establish an indexible register list of the address of the sensitive data hardware registers and of the hardware registers in the set of available hardware registers, in a loop, write each hardware register in this register list with random data, a random number of times, in random order except the last writing in each of the sensitive data hardware registers where a part of the sensitive data is written.

    METHOD, FIRST DEVICE AND SYSTEM FOR AUTHENTICATING TO A SECOND DEVICE

    公开(公告)号:US20190311110A1

    公开(公告)日:2019-10-10

    申请号:US16464709

    申请日:2017-11-23

    Applicant: GEMALTO SA

    Abstract: The invention relates to a method for authenticating to a second device. A first device shares with the second device at least one session key. The first device sends to at least one third device at least one first session key. The at least one third device connects directly to the second device by using the at least one first session key. According to the invention, the method further comprises the following steps. The first device sends to the at least one third device a command for disconnecting from or switching to a non-connected mode with the second device. And the at least one third device disconnects from or switches to a non-connected mode with the second device based upon the received command. The invention also pertains to corresponding first device and system for authenticating to a second device.

    Method of privacy preserving during an access to a restricted service

    公开(公告)号:US10402583B2

    公开(公告)日:2019-09-03

    申请号:US14903036

    申请日:2014-07-04

    Applicant: GEMALTO SA

    Inventor: Mourad Faher

    Abstract: The present invention relates to a method of privacy-preserving during an access to a restricted e-service requiring user private data from a smart card. The invention relates more particularly to the field of methods implemented so that the user has the guarantee that only the private data needed to access to the e-service are extracted from the smart card. It is to guarantee that the user has a perfect knowledge of his private data provided by his smart card to a requester. With the invention a message notifying to the user the very nature of the identity assertion is displayed on the screen of the smart card. By doing so, the card ensure 100% security with regard to user consent: the data read out of his card cannot differ comparing to the data requested by the service provider through the terminal.

    METHOD FOR PROVISIONING A FIRST COMMUNICATION DEVICE BY USING A SECOND COMMUNICATION DEVICE

    公开(公告)号:US20190238324A1

    公开(公告)日:2019-08-01

    申请号:US16320291

    申请日:2017-03-30

    Applicant: GEMALTO SA

    Abstract: This invention related to a method for provisioning a first communication device with a set of at least one credential required for accessing to a wireless network by using a second communication device provisioned with a cryptographic key K also known by the wireless network, the first communication device being associated with a certificate comprising a public key PK, said certificate being stored with an associated private key PrK in said first communication device, the method comprising the following steps: receiving by the second communication device a registration request from the first communication device in order to be provisioned with the set of at least one credential; transmitting to the wireless network by the second communication device the registration request to generate a set of at least one credential associated to the first communication device comprising at least a cryptographic key K″, the wireless network being adapted to generate a first random number R1 and a second random number R2; receiving by the second communication device a response from the wireless network comprising R1 and R2; generating K′ by the second communication device using R1 and K; transmitting by the second communication device to the first communication device K′ and R2 to generate K″ using R2 and K′.

    METHOD FOR PROVISIONING AN APPLET WITH CREDENTIALS OF A TERMINAL APPLICATION PROVIDED BY AN APPLICATION SERVER AND CORRESPONDING OTA PLATFORM

    公开(公告)号:US20190158996A1

    公开(公告)日:2019-05-23

    申请号:US16301762

    申请日:2017-05-15

    Applicant: GEMALTO SA

    Abstract: A method for provisioning an applet in a security element with credentials of a terminal application provided by an application server comprises: Sending a request to provision the applet with credentials from the terminal application to the applet; Sending an SMS message containing an identifier of the applet from the applet to an OTA platform; Adding the MSISDN of the security element by an SMSC located in front of the OTA platform in the header of the SMS; Requesting the credentials from the OTA platform to the application server; Sending from the application server to the OTA platform the credentials to be associated with the MSISDN; Sending from the OTA platform to the applet the credentials associated with the MSISDN; and Sending from the applet to the terminal application a message that it has been provisioned with credentials of the terminal application.

    MOBILE COMMUNICATION DEVICE WITH SUBSCRIBER IDENTITY MODULE

    公开(公告)号:US20190149985A1

    公开(公告)日:2019-05-16

    申请号:US16097411

    申请日:2017-04-24

    Abstract: The present invention relates to a mobile communication device for communicating with a cellular network by means of a serving base node, the mobile communication device further being connected to a subscriber identity module, the mobile communication device being configured to operate in a power optimization mode wherein the power optimization mode comprises extended paging periods, and the mobile communication device is further configured to set up a communication context with the base node using authentication means of the subscriber identity module, wherein the mobile communication device is further configured, in case of detection of a removal of the subscriber identity module and when the power optimization mode is activated: to send an removal alert message to the serving base node by means of said communication context, afterwards to terminate the communication context.

    Method for producing a single-sided electronic module including interconnection zones

    公开(公告)号:US10282652B2

    公开(公告)日:2019-05-07

    申请号:US15531159

    申请日:2016-02-09

    Applicant: GEMALTO SA

    Abstract: The invention relates to a method for producing a module having an electronic chip including metallizations which are accessible from a first side of the metallizations and an integrated circuit chip which is arranged on the second side of the metallizations, opposite the first side. The method comprises the step of forming electrical interconnection elements which are separate from the metallizations, directly connecting the chip, and are arranged on the second side of the metallizations. The invention also relates to a module corresponding to the method and to a device comprising said module.

    Automated examination and processing of biometric data

    公开(公告)号:US10235582B2

    公开(公告)日:2019-03-19

    申请号:US15502759

    申请日:2015-07-31

    Applicant: GEMALTO SA

    Abstract: The present disclosure describes systems and methods for assessing biometric data and determining the type of additional processing required to conclude analysis. In one example, the disclosure describes a computer-implemented method comprising providing biometric data, defining one or more performance parameters, assessing the biometric data for quality of one or more features, wherein the quality includes at least a quantity and correlation between the one or more features, assessing the rarity of the one or more features, and processing the performance parameter, quality, and rarity to guide a determination of a type of additional processing.

Patent Agency Ranking