-
公开(公告)号:WO2023006246A1
公开(公告)日:2023-02-02
申请号:PCT/EP2022/025349
申请日:2022-07-26
Applicant: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
Inventor: RUAU, Mariano , GIFRE, Clara , GARCIA FARRÉS, Andreu , GOMEZ SOLI, Pablo Daniel
Abstract: In a first aspect, the present invention relates to a method for updating an installed software (60a), in particular an operating system, OS, (30a) in a secure element (100). The method comprises the steps of providing S1 an update agent (10) in the secure element (100); securing S3 specific data (35a; 65a) required for operating the installed software (30a; 60a) in a memory (12) of the update agent (10); loading S4a a software image (30b); (60b) into the secure element (100), the software image (30b; 60b) representing an update of the installed software (30a; 60a); and making the software image (30b; 60b) operable by the secured specific data (35b; 65b). According to further aspects, the present invention relates to a respective secure element (100), an update agent (10), and a computerprogram product in relation to other aspects of the invention.
-
公开(公告)号:WO2023006243A1
公开(公告)日:2023-02-02
申请号:PCT/EP2022/025346
申请日:2022-07-26
Applicant: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
Inventor: PATINO, David , GIFRE, Clara , RUAU, Federico
Abstract: The present invention relates to an update agent, a secure element containing the update agent, and a method for retrieving a software image to be stored onto the secure element. The update agent comprises a communication interface for providing connectivity to a storage module for downloading software images onto the SE. The update agent comprises further a first memory storing authentication data for authenticating software images, and a second memory storing credentials for personalizing software images.
-
公开(公告)号:WO2023285399A1
公开(公告)日:2023-01-19
申请号:PCT/EP2022/069350
申请日:2022-07-11
Applicant: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
Inventor: PATINO, David , GIFRE, Clara , RUAU, Federico
IPC: G06F8/65
Abstract: The present invention relates a method and a device for upgrading an Executable Load File, ELF, having dependencies, on a Secure Element, SE. The method comprises in a first step receiving a request for upgrading an ELF, the request comprising a first identifier, identifying a first ELF version loaded on the SE, a second identifier, identifying a second ELF version loaded on the SE, and an upgrade option. Upon receiving the request, dependencies of the first ELF version from other ELFs loaded or stored on the SE are determined. Subsequently, if dependencies have been determined, it is checked whether the upgrade request is allowed. If the update request is allowed, an upgrade session is started and the first ELF version is replaced with the second ELF version. The dependencies of the first ELF version are then linked to the second ELF version.
-
公开(公告)号:WO2023006247A1
公开(公告)日:2023-02-02
申请号:PCT/EP2022/025350
申请日:2022-07-26
Applicant: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
Inventor: PERARNAU, Xavier , COUTO, Marta , GIFRE, Clara , PATINO, David , RUAU, Federico
Abstract: The present invention relates a method and an apparatus for updating software loaded on a secure element, SE, which SE comprises an update agent handler, and an update agent. In a first step, a request to backup a current version of software loaded on the SE is received at the SE. The request is preferably sent from a device, external to the SE. Upon receiving the backup request, the SE performs a secure backup of the current software version, and returns the software backup to the device, to be stored thereon. In a further step, the SE performs an update process of the current software version, to obtain an updated software version. If the update process fails, a rollback is performed at the SE to restore the software backup as a new current software version on the SE.
-
公开(公告)号:WO2023274578A1
公开(公告)日:2023-01-05
申请号:PCT/EP2022/025294
申请日:2022-06-29
Applicant: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
Inventor: GIFRE, Clara , PATINO, David , RUAU, Federico
IPC: G06F21/57 , H04L9/32 , H04L9/40 , H04W12/10 , H04L9/08 , G06F21/572 , H04L63/123 , H04L9/0897 , H04L9/3247
Abstract: The present invention relates to a method, a data structure, and an update agent for implementing a scheme for downloading an operating system image onto a secure element. The update agent receives from an external device an installation package for installing an operating system onto the secure element. The update agent requests control of the secure element and loads the operating system received with the installation package into the secure element, after which control of the secure element is transferred to the operating system.
-
公开(公告)号:WO2023006242A1
公开(公告)日:2023-02-02
申请号:PCT/EP2022/025345
申请日:2022-07-26
Applicant: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
Inventor: PATINO, David , GIFRE, Clara , RUAU, Federico , KORNEFALK, Björn
Abstract: The present invention relates to an update agent, a secure element containing the update agent, and a method for loading and personalizing a software in the secure element. In a first step, an update agent is loaded into the secure element. In a further step, software personalization data is loaded into the secure element, and stored in the update agent. Subsequently, the software is loaded into the secure element and personalized using the software personalization data stored in the update agent.
-
公开(公告)号:WO2022038192A1
公开(公告)日:2022-02-24
申请号:PCT/EP2021/072956
申请日:2021-08-18
Applicant: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
Inventor: AMOROS, Luis, Miguel , BRAVO, Hector , DE ANTONIO, Pablo , GIFRE, Clara , PATINO, David
IPC: G06F8/60
Abstract: The present invention is directed towards a method for making sure that a piece of software to be installed on an end device is compatible with an existing software and especially the underlying hardware structure of the end device. Consequently, it is an advantage of the present invention that new software components can be evaluated before installing them, thus preventing incompatible software components from being installed on an end device which would harm or destroy the same. Furthermore, the present invention is directed towards a system arrangement implemented in accordance with the suggested method along with a computer program product comprising control instructions for implementing the suggested method.
-
公开(公告)号:WO2023006245A1
公开(公告)日:2023-02-02
申请号:PCT/EP2022/025348
申请日:2022-07-26
Applicant: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
Inventor: GIFRE, Clara , PATINO, David , RUAU, Federico , GOMEZ JIMENEZ , Ruben
Abstract: A method for personalizing a software, in particular an operating system OS, in a secure element, SE, (100) comprises the steps of loading S2 a software image (30; 30a, 30b) into the memory (20) of the SE (100); loading S3 a software personalization record 40 comprising personalization data (41) into the memory (20) of the SE (100); and personalizing S7, S8 the loaded software image (30; 30a, 30b) using the software personalization data (41). According to the invention, personalization of the software image (30; 30a, 30b) is initiated S5 by an internal agent (10) of the SE (100). Preferably, initiation S5 personalization of the software image (30; 30a, 30b) by the internal agent (10) is triggered by a trigger event (200) that is detected S4 by the internal agent (10), the trigger event (200) being unrelated to software personalization.
-
公开(公告)号:WO2023006244A1
公开(公告)日:2023-02-02
申请号:PCT/EP2022/025347
申请日:2022-07-26
Applicant: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
Inventor: PATINO, David , GIFRE, Clara , RUAU, Federico , GOMEZ JIMENEZ , Ruben
Abstract: The present invention relates to a method for updating an operating system, OS, (30) administering a file system (32) in a secure element, SE, (100). The method comprises the steps of providing SI an update agent (10) in the SE (100); assuming control S3 of the SE (100) by the update agent (10) from the operating system (30); loading S4 an OS image (31) into the SE (100), the OS image (31) representing an update of the operating system (30); providing S5a an updated operating system (30) by installing the OS image (31); and handing over control S6 of the SE (100) by the update agent (10) to the updated operating system (30). Within this update process, the update agent (10) provides Sla a provisional file system (12) in the SE (100) and administers S5a the provisional file system (12) as long as the update agent (10) is in control of the SE (100). The present invention also relates to a respective secure element (100), a respective update agent (10), and to a respective computer-program product.
-
公开(公告)号:WO2023274579A1
公开(公告)日:2023-01-05
申请号:PCT/EP2022/025295
申请日:2022-06-29
Applicant: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
Inventor: GIFRE, Clara , PATINO, David , RUAU, Federico
IPC: G06F21/57 , H04L9/06 , H04L9/40 , H04W12/40 , H04L9/08 , H04L9/32 , G06F21/572 , H04L2209/80 , H04L63/0442 , H04L9/0637 , H04L9/0897 , H04L9/3242
Abstract: The present invention relates to methods, apparatus and systems for implementing an encryption scheme for providing a software image to a secure element. The software image is converted into a sequence of ciphered blocks, which is protected with an authentication tag to obtain a sequence of protected blocks, which are then transmitted to an update agent on the secure element. The steps of converting the software image into a sequence of ciphered blocks and protecting the sequence of ciphered blocks with an authentication tag are implemented by an authenticated encryption function using a same block cipher.
-
-
-
-
-
-
-
-
-