METHOD TO PROTECT A SET OF SENSITIVE DATA ASSOCIATED TO PUBLIC DATA IN A SECURED CONTAINER
    51.
    发明申请
    METHOD TO PROTECT A SET OF SENSITIVE DATA ASSOCIATED TO PUBLIC DATA IN A SECURED CONTAINER 审中-公开
    保护一组与安全容器中的公共数据相关的敏感数据的方法

    公开(公告)号:US20160294791A1

    公开(公告)日:2016-10-06

    申请号:US15036171

    申请日:2014-10-31

    Applicant: GEMALTO SA

    CPC classification number: H04L63/0435 G06F21/6209 H04L63/0428 H04L63/061

    Abstract: The present invention relates to a method to protect, in a secured container using an encryption key, a set of mixed sensitive and public data to be transferred to an entity. The method includes the steps of: generating a random key, ciphering the set of mixed sensitive and public data using said random key to obtain a ciphered set of data, generating an initialization value, and defining configuration information for the secured container. The initialization value, the configuration information and random key form a preamble. The preamble and the ciphered set of data are encrypted. The initialization value renders the resulting encrypted data variable from a secured container to another even in case of repetitive configuration information in the preamble.

    Abstract translation: 本发明涉及一种在使用加密密钥的安全容器中保护要传送到实体的一组混合敏感和公共数据的方法。 该方法包括以下步骤:产生随机密钥,使用所述随机密钥对混合敏感和公共数据集进行加密,以获得加密数据集,生成初始化值并定义安全容器的配置信息。 初始化值,配置信息和随机密钥形成前导码。 前导码和加密的数据集被加密。 即使在前序部分中重复配置信息的情况下,初始化值也将生成的加密数据变量从安全的容器转换到另一个容器。

    Method and system for accessing a service
    53.
    发明授权
    Method and system for accessing a service 有权
    访问服务的方法和系统

    公开(公告)号:US09444815B2

    公开(公告)日:2016-09-13

    申请号:US14647269

    申请日:2013-11-27

    Applicant: GEMALTO SA

    CPC classification number: H04L63/0853 H04L63/0815 H04L63/0884 H04L63/18

    Abstract: To access a service, each user device stores one first key. The user device is connected to a first server. A terminal sends to a second server a connection request. The second server responds with first data relating to a transaction identifier and an associated challenge. The terminal determines a first result depending upon the first data and the first key. The terminal sends to the first server the first result and user device data. The first server identifies a user device based upon the user device data and sends to the device the first result. The device determines the challenge and the transaction identifier based upon the first result and the first key and sends to the second server the challenge and the transaction identifier. The second server verifies whether the data received from the device matches the first data and, if so, authorizes the terminal to connect.

    Abstract translation: 为了访问服务,每个用户设备存储一个第一密钥。 用户设备连接到第一服务器。 终端向第二台服务器发送连接请求。 第二服务器响应与事务标识符和相关联的挑战相关的第一数据。 终端根据第一数据和第一密钥确定第一结果。 终端向第一台服务器发送第一个结果和用户设备数据。 第一服务器基于用户设备数据识别用户设备,并向设备发送第一个结果。 设备基于第一结果和第一密钥来确定挑战和交易标识符,并向第二服务器发送质询和交易标识符。 第二服务器验证从设备接收的数据是否与第一数据匹配,如果是,则授权终端连接。

    Secure element comprising separated containers and corresponding method
    55.
    发明授权
    Secure element comprising separated containers and corresponding method 有权
    安全元件包括分离的容器和相应的方法

    公开(公告)号:US09361470B2

    公开(公告)日:2016-06-07

    申请号:US14349047

    申请日:2012-09-18

    Applicant: GEMALTO SA

    Abstract: The invention is a secure element comprising a virtual machine able to work in admin mode and in runtime mode. The secure element comprises two enhanced containers. Each of said enhanced containers can be either in an activated state or in a disabled state. Only one of the enhanced containers can be in activated state at any given time. The virtual machine is adapted to access each of the enhanced containers when working in admin mode. The virtual machine cannot access an enhanced container which is in disabled state when working in runtime mode.

    Abstract translation: 本发明是一种安全元件,包括能够以管理模式和运行时模式工作的虚拟机。 安全元件包括两个增强的容器。 所述增强容器中的每一个可以处于激活状态或处于禁用状态。 在任何给定的时间,只有一个增强的容器可以处于激活状态。 虚拟机适用于在管理模式下工作时访问每个增强型容器。 虚拟机无法访问在运行时模式下处于禁用状态的增强型容器。

    METHOD FOR MAKING AN ANTI-CRACK ELECTRONIC DEVICE
    56.
    发明申请
    METHOD FOR MAKING AN ANTI-CRACK ELECTRONIC DEVICE 审中-公开
    制造抗裂电子器件的方法

    公开(公告)号:US20160125284A1

    公开(公告)日:2016-05-05

    申请号:US14896094

    申请日:2014-06-03

    Applicant: GEMALTO SA

    Abstract: A method for making an intermediate electronic device, wherein said device is coated or is to be coated with a cover sheet or layer, the method comprising the step of forming a carrier-body comprising: a cavity provided in the carrier-body; an electric circuit comprising at least one electric interconnection area inside the cavity; an electronic module comprising at least one connection pad connecting said interconnection area and arranged in the cavity; a space or gap provided at the interface between the module and the carrier-body, substantially perpendicular to a main surface of the carrier-body, in communication with the surface of the carrier-body, and intended to be covered with a cover sheet or layer; the method is characterized in that a flexible or elastic material is arranged in the device so as to fill the space or gap between the module and the body-carrier or at least partially cover same.

    Abstract translation: 一种制造中间电子器件的方法,其中所述器件被涂覆或将被覆盖片或层,该方法包括形成载体的步骤,包括:设置在载体中的腔体; 电路,其包括所述腔内的至少一个电互连区域; 电子模块,包括连接所述互连区域并布置在空腔中的至少一个连接焊盘; 设置在模块和载体之间的界面处的空间或间隙,其基本上垂直于载体主体的主表面,与载体主体的表面连通,并且旨在被覆盖片或 层; 该方法的特征在于,在装置中布置柔性或弹性材料,以便填充模块和身体载体之间的空间或间隙,或至少部分地覆盖其上。

    Method for mutual authentication between a terminal and a remote server by means of a third-party portal
    57.
    发明授权
    Method for mutual authentication between a terminal and a remote server by means of a third-party portal 有权
    通过第三方门户在终端和远程服务器之间进行相互认证的方法

    公开(公告)号:US09319882B2

    公开(公告)日:2016-04-19

    申请号:US14439167

    申请日:2013-10-25

    Applicant: GEMALTO SA

    CPC classification number: H04W12/06 H04L63/0853 H04L63/0869 H04W4/60

    Abstract: Mutual authentication between: (i) a user terminal cooperating with a security element and an application for registering with a service, and (ii) a remote server that provides the service, by means of a third-party portal, includes: i) transmitting, to the remote server by means of the portal, signed information R enabling the security element to be authenticated in the remote server; ii) authenticating the security element in the remote server; iii) transmitting a value R′ signed by the remote server to the application by means of the portal; iv) transmitting a request for verification of the signed value R′ from the application to the security element; v) verifying, in the security element, the signature of the remote server and whether the requested service has been granted by the remote server; vi) establishing a secure connection with the remote server using the security element, and requesting that the service be executed.

    Abstract translation: (i)与安全元件协作的用户终端和与服务注册的应用相互认证,以及(ii)通过第三方门户提供服务的远程服务器包括:i)发送 通过门户到远程服务器,使得能够在远程服务器中验证安全元素的签名信息R; ii)验证远程服务器中的安全元素; iii)通过门户传输由远程服务器签名的值R'到应用程序; iv)从所述应用向所述安全元件发送对所述签名值R'的验证请求; v)在安全元素中验证远程服务器的签名以及所请求的服务是否已被远程服务器许可; vi)使用安全元件与远程服务器建立安全连接,并请求执行该服务。

    METHOD OF AUTHENTICATING A DEVICE
    58.
    发明申请
    METHOD OF AUTHENTICATING A DEVICE 有权
    认证设备的方法

    公开(公告)号:US20150304114A1

    公开(公告)日:2015-10-22

    申请号:US14372799

    申请日:2013-01-21

    Applicant: GEMALTO SA

    Abstract: The invention is a method for authenticating a device which comprises a chip and a body carrying the chip. The body comprises a graphical security feature. The method comprises the steps of: running a first physical unclonable function for generating a first response representative of the chip, extracting a first reference from the graphical security feature, authenticating the device by checking that said first response and first reference are linked by a preset mathematical function. The extracting step and the authenticating step are carried out by a machine distinct from the device.

    Abstract translation: 本发明是一种认证装置的方法,该装置包括一个芯片和一个承载芯片的机体。 身体包括图形安全功能。 该方法包括以下步骤:运行用于生成表示芯片的第一响应的第一物理不可克隆功能,从图形安全特征提取第一参考,通过检查所述第一响应和第一参考是否被预设链接来认证该设备 数学函数。 提取步骤和认证步骤由与装置不同的机器进行。

    METHOD FOR AUTHENTICATING A USER
    59.
    发明申请
    METHOD FOR AUTHENTICATING A USER 审中-公开
    用于认证用户的方法

    公开(公告)号:US20150286811A1

    公开(公告)日:2015-10-08

    申请号:US14438217

    申请日:2013-10-18

    Applicant: GEMALTO SA

    Abstract: The invention relates to a method for authenticating a user when accessing to an application securely stored on a secure element of a portable device, said method comprising a step of authenticating the user via two authentication factors. The method comprises requesting a further authentication factor to said user, in a form of challenge-response based on a randomised request associated to a biometric data of said user.

    Abstract translation: 本发明涉及一种用于在访问安全地存储在便携式设备的安全元件上的应用时认证用户的方法,所述方法包括通过两个认证因素认证用户的步骤。 该方法包括基于与所述用户的生物特征数据相关联的随机化请求,以询问 - 响应的形式向所述用户请求另外的认证因子。

    Contactless electronic communication device with optional auxiliary power source
    60.
    发明授权
    Contactless electronic communication device with optional auxiliary power source 有权
    非接触式电子通信设备,带可选辅助电源

    公开(公告)号:US09152906B2

    公开(公告)日:2015-10-06

    申请号:US14483286

    申请日:2014-09-11

    Applicant: Gemalto SA

    Abstract: A device having a card (40) and a support (PC). The card has (a) no internal battery, (b) a single antenna (10) that receives electromagnetically data and power, (c) a data processor, (d) rectifying and filtering circuitry receiving the electromagnetic input and supplying at output terminals (A, B) a voltage to the processor. and (e) two terminals (36, 38) on an external surface of the card which are connected to the output terminals (A, B). The support is mechanically and electrically connectable to the card. It has (a) a power source that may be a battery, (b) surface terminals that mate with the card's external terminals, (c) a switch for connecting the power source to the surface terminals, and (d) a mechanism for holding together the card and support with the card's and the support terminal's electrically engaged to one another.

    Abstract translation: 具有卡(40)和支撑(PC)的装置。 该卡具有(a)没有内部电池,(b)接收电磁数据和电力的单个天线(10),(c)数据处理器,(d)整流和滤波接收电磁输入的电路并在输出端提供 A,B)处理器的电压。 和(e)在卡的外表面上连接到输出端(A,B)的两个端子(36,38)。 支架机械和电连接到卡上。 它具有(a)可以是电池的电源,(b)与卡的外部端子配合的表面端子,(c)用于将电源连接到表面端子的开关,以及(d) 将卡片和支架与卡片和支撑终端电连接在一起。

Patent Agency Ranking