logical java card runtime environment

By hosting multiple logical partitions on the smart card and using interface switching indicators and partition firewall mechanisms, the problem of mobile handheld devices requiring multiple physical slots is solved, enabling multiple SIM/UICC cards to be active simultaneously at the same time, reducing costs and improving functionality.

CN117202413BActive Publication Date: 2025-12-12ORACLE INT CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310671265.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-06-08
Filing Date
2023-06-07
Publication Date
2025-12-12
Estimated Expiration
2043-06-07

AI Technical Summary

Technical Problem

In existing technologies, mobile handsets require physical expansion slots to support multiple SIM/UICC cards, which increases costs and does not support multiple SIM/UICC cards operating at the same time.

Method used

By hosting multiple logical partitions on a smart card, and utilizing message schedulers and partition firewall mechanisms, multiple logical interface profiles can operate simultaneously on the same physical interface. By using interface switching indicators, message streams are distributed to the corresponding logical partitions, ensuring data isolation and security.

Benefits of technology

It enables multiple SIM/UICC cards to be active simultaneously without increasing physical hardware costs, thus improving the functionality and flexibility of mobile handsets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117202413B_ABST
    Figure CN117202413B_ABST
Patent Text Reader

Abstract

This application relates to a logical Java Card runtime environment. Techniques are disclosed for generating a message stream configured to indicate the source of various messages within the message stream. In particular, an indicator identifies at which interface of a terminal (e.g., of a mobile handset) a message was received. The terminal receives messages on various interfaces and separates messages received via different interfaces within the message stream with interface switch indicators. In one embodiment, a smart card receives a message stream that includes a set of messages and interface switch indicators therein. The smart card delivers messages from the message stream to a single logical partition of the smart card until an interface switch indicator is identified in the message stream. From that point on, the smart card delivers messages from the message stream to a different logical partition of the smart card until another interface switch indicator is identified in the message stream.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to deploying a logical Java Card runtime environment on a smart card. BACKGROUND

[0002] Over the past decade, members of the mobile phone industry, including mobile handset manufacturers, subscriber identity module (SIM) card manufacturers, and mobile network operators (MNOs), have developed standards for related technologies: embedded SIM (eSIM) cards and embedded universal integrated circuit cards (eUICCs). These components, when integrated into a mobile handset, provide an interface for receiving and responding to network and handset requests. These standards define the use, format, functionality, and associated profiles of eSIM / eUICC. A secure element chip is capable of storing more than one of these profiles, but only one profile can be active at any given time, allowing the active profile to respond to network and / or terminal requests while preventing the inactive profile(s) from handling network and / or terminal requests.

[0003] Furthermore, for many years, handset manufacturers have produced handsets that include at least one (and often multiple) physical expansion slot for using multiple removable SIMs / UICCs. Integrating more than one physical slot for SIM cards is a large cost factor for handset manufacturers, whether it is an expansion slot or an embedded physical slot.

[0004] The approaches described in this section are approaches that can be taken, but need not be taken. Unless otherwise indicated, it should not be assumed that any approach described in this section needs all of the BRIEF DESCRIPTION OF DRAWINGS

[0005] Embodiments are illustrated by way of example, and not by way of limitation, in the figures of the accompanying drawings in which:

[0006] Figure 1 a block diagram illustrating an example system, in accordance with one or more embodiments is illustrated;

[0007] Figure 2 a block diagram illustrating an example system having multiple logical partitions hosted by a platform, in accordance with one or more embodiments is illustrated;

[0008] Figure 3 a use of a runtime environment for a message dispatcher, in accordance with one or more embodiments is illustrated;

[0009] Figure 4 FIGURE illustrates use of a runtime environment to a platform registry, in accordance with one or more embodiments;

[0010] Figure 5 FIGURE illustrates an example system to support logical partitioning, in accordance with one or more embodiments;

[0011] Figure 6 FIGURE illustrates an example set of operations to generate a message flow for multiple logical partitions of a smart card, in accordance with one or more embodiments;

[0012] Figure 7 FIGURE illustrates an example set of operations to process a message flow for multiple logical partitions of a smart card, in accordance with one or more embodiments;

[0013] Figure 8 FIGURE illustrates an example set of operations to apply a partition firewall to multiple logical partitions of a smart card, in accordance with one or more embodiments; and

[0014] Figure 9 shows a block diagram illustrating a computer system in accordance with one or more embodiments. DETAILED DESCRIPTION

[0015] In the following description, for the purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding. One or more embodiments can be practiced without these specific details. Features described in one embodiment can be combined with features described in a different embodiment. In some examples, well-known structures and devices are described with reference to a block diagram form in order to avoid unnecessarily obscuring the present description.

[0016] 1. OVERALL SUMMARY

[0017] 2. SYSTEM ARCHITECTURE

[0018] 3. MESSAGE SCHEDULER

[0019] 4. PLATFORM REGISTRY

[0020] 5. LOGICAL PARTITION SUPPORT

[0021] 6. EXAMPLE EMBODIMENTS

[0022] 7. COMPUTER NETWORKS AND CLOUD NETWORKS

[0023] 8. HARDWARE OVERVIEW

[0024] 9. OTHER MATTERS; EXTENSIONS

[0025] 1. OVERALL SUMMARY

[0026] A terminal can be configured to receive messages from various interfaces and forward them in the same message stream. One or more embodiments generate a message stream that is configured to indicate the source of various messages within the message stream without requiring each message to identify the source. A terminal that forwards messages received from various interfaces inserts interface switch indicators into the message stream such that the interface switch indicators are inserted between sets of messages received from different interfaces.

[0027] In one or more embodiments, a smart card (e.g., of a mobile handset) receives a message stream that includes a set of messages and interface switch indicators therein. The smart card delivers messages from the message stream to a particular logical partition of the smart card until an interface switch indicator is identified in the message stream. From that point on, the smart card delivers messages from the message stream to a different logical partition of the smart card until another interface switch indicator is identified in the message stream.

[0028] According to one or more embodiments, a smart card can host multiple logical partitions, each configured to receive messages received at a particular interface of a terminal. The smart card prevents access to data corresponding to a first logical partition from any process corresponding to a second logical partition while also preventing access to data corresponding to the second logical partition from any process corresponding to the first logical partition.

[0029] One or more embodiments described in this specification and / or recited in the claims can not be included in this general overview section.

[0030] 2. System Architecture

[0031] Mobile handset manufacturers benefit from removing the physical expansion slot from mobile handsets while still allowing the mobile handsets to host multiple enabled profiles to respond to network and terminal requests. In one or more embodiments, multiple enabled profiles can be hosted on a physical embedded secure element or smart card integrated with the mobile handset. Mobile handset manufacturers have begun to define ways to host interface profiles (e.g., eUICC profiles) on logical secure elements that communicate with the mobile handset through logical interfaces that share one physical interface. In this way, multiple enabled interface profiles can be active at any given time and able to respond to terminal and network requests of the mobile handset.

[0032] Figure 1 A block diagram of an example system 100 is illustrated in accordance with one or more embodiments. As Figure 1As shown in the figure, the system 100 includes a terminal 102 and a smart card 112. The terminal 102 is configured to generate a message stream 106 in association with receiving a message 116 (e.g., a first message 116a, a second message 116b, etc.) at the terminal 102, which is transmitted to the smart card 112. The interface 104 and the message 116 can include any type of data and information for processing by the smart card 112, such as data commands, control commands, etc.

[0033] In one embodiment, the terminal 102 can be a mobile handset (such as a mobile phone device) or some other device configured to connect to one or more data communication networks, which can include wired and / or wireless data communication networks. The terminal 102 includes a plurality of interfaces 104 (e.g., an interface 104a, an interface 104b, etc.) configured to communicate via a particular data communication network. The interfaces 104 can be configured to send and / or receive data via any data communication network. Some example data communication networks include, but are not limited to, Global System for Mobile (GSM), Code Division Multiple Access (CDMA), Universal Mobile Telecommunications System (UMTS), Long Term Evolution (LTE), General Packet Radio Service (GPRS), Universal Mobile Telecommunications System (UMTS), Broadband Global Area Network (BGAN), Wireless Local Area Network (WLAN), Ethernet, etc.

[0034] In one or more embodiments, the interface 104a can be configured to communicate using a first type of data communication network, while the interface 104b can be configured to communicate using the same type of data communication network or a different type of data communication network as the interface 104a. In one embodiment, the terminal 102 can include one or more interfaces 104 configured to communicate via a wired data communication network. In an embodiment, the terminal 102 can include one or more interfaces 104 configured to communicate via a wireless data communication network. In one embodiment, the terminal 102 can include one or more interfaces 104 configured to communicate via a satellite data communication network.

[0035] The smart card 112 can be a computing device configured to securely receive and respond to commands and / or messages across various networks with the terminal 102. In one embodiment, the smart card 112 can be a UICC. In another embodiment, the smart card can be a secure element.

[0036] In one or more embodiments, the smart card 112 includes a plurality of interface profiles 114 (e.g., an interface profile 114a, an interface profile 114b, etc.). According to one approach, each of the interface profiles 114 can be an eUICC profile when the smart card 112 is a physical UICC.

[0037] WhileFigure 1 Only two interface profiles 114 are shown, but a single smart card 112 can support any number of different profiles. The maximum number of supported interface profiles 114 can be determined based on the amount of memory available to the smart card 112 and the number of interfaces 104 on the terminal 102. In some examples, the maximum number of supported profiles can be two, three, four, five, ten, etc.

[0038] The terminal 102 generates a message stream 106 based at least on the messages 116 received via the interfaces 104. In some approaches, the message stream 106 can include commands and / or responses from the smart card 112. In one or more embodiments, the various interface profiles 114 on the smart card are configured to handle messages received on a single interface (e.g., the first message 116a received via the interface 104a, the second message 116b received via the interface 104b, etc.) rather than all of the messages 116 received by the terminal 102. For the remainder of this discussion, assume that the interface profile 114a is configured to handle the first message 116a received by the interface 104a, and assume that the interface profile 114b is configured to handle the second message 116b received by the interface 104b. However, any arrangement can be used in implementing the techniques described herein, including but not limited to having more than two interface profiles 114 corresponding to more than two interfaces 104.

[0039] The message stream 106 includes a first message set 108a that can include one or more messages received via one of the interfaces (e.g., one or more first messages received via interface 104a) separated from a next message set 108b by an interface switch indicator 110a. The interface switch indicator 110a indicates that the messages included in the message stream 106 prior to the interface switch indicator 110a were received via a different interface than the messages 108b included in the message stream 106 after the interface switch indicator 110a. The next message set 108b is received via a different one of the interfaces (e.g., one or more second messages received via interface 104b). The messages 108b in the message stream 106 are followed by another switch interface indicator 110b that indicates another switch to the interface from which subsequent messages are received. The switch interface indicators 110 are located between each message set 108 in the message stream 106 in order to group the messages 108 by the interface 104 over which they are received. In other words, the message(s) 108a are selected from a first message 116a, while the message(s) 108b are selected from a second message 116b, and separated by the interface switch indicator 110 within all of the message streams 106. If additional interfaces 104 are present on the terminal 102, the interface switch indicator 110 will be configured to indicate a switch to that interface type, as well as to the interfaces 104a and 104b.

[0040] In one or more embodiments, the terminal 102 can place the messages received via the interfaces 104 into the message stream 106 in a sequential order according to when the messages are received at the terminal 102. In one approach, bursts of messages can be placed in the message stream 106 in an attempt to minimize the number of interface switch indicators 110 required to indicate a switch between interfaces 104, even if one or more messages are not placed in the message stream 106 in the order in which they were received at the interfaces 104. If a string or burst of messages is being received at a first interface (e.g., interface 104a), all of these messages 116a can be placed in the message stream 106 in order before any messages 116b received at another interface (e.g., interface 104b) until there is a break or pause in the stream of messages 116a being received at the first interface 104a. Any accumulated messages 116b received at the other interface 104b can then be placed in the message stream 106 according to the order in which they were received.

[0041] In other words, the messages 108 can be ordered in the message stream 106 in a temporal order based at least in part on the respective times at which each of the messages 116 is received at the terminal 102, and in particular at the interfaces 104 of the terminal 102.

[0042] For example, some of the messages 116a received in a first time period can be grouped into a first group of messages 108a in the message stream 106. Further, some of the messages 116b received in a second time period can be grouped into a second group of messages 108b in the message stream 106. In this example, the start time of the second time period is later than the start time of the first time period, and the first group of messages 108a is ordered before the second group of messages 108b in the message stream 106.

[0043] However, at least one message in the second group of messages 108b can have been received before at least one message in the first group of messages 108a, as the first time period can overlap the second time period, even though the second time period starts after the first time period. By generating groups of messages received at one interface within the message stream 106, the amount of switching between messages received at different interfaces 104 on the terminal 102 will be minimized as much as possible. In one embodiment, these groups can have a minimum size (e.g., 10 bits, 100 bits, 10 bytes, 100 bytes, 1 KB, etc.) or duration (1 millisecond, 10 milliseconds, 100 milliseconds, 1 second, etc.). In another embodiment, these groups or strings of messages from the same interface in the message stream 106 can have a maximum size or duration to ensure that messages are not unnecessarily delayed at the terminal 102, while still minimizing the number of interface switch indicators 110 utilized in the message stream 106.

[0044] The interface switch indicator 110 can be a short, representative string or code that corresponds to one of the various interfaces 104 present on the terminal 102 and is understood by the smart card 112, enabling the smart card 112 to determine which interface profile 114 to send the corresponding message(s) to. The interface switch indicator 110 can include a flag, a token, or some other binary mechanism that indicates a switch between interface types for the next message or set of messages on the terminal 102.

[0045] Figure 2 FIG. 1 illustrates an example system 100 in accordance with one or more embodiments. Figure 2 The various modules shown in FIG. 1 are described as being executed by a "system," but can be executed using any combination of hardware and software Figure 2 The various functions of the system 100 shown in FIG. 1.

[0046] The system 200 includes a platform environment 202 that operates a scalable set of functions. In one or more embodiments, the platform environment 202 can be a secure element, a UICC, or a smart card (such as a UICC or a secure element) that is capable of operating a set of functions that can be extended by the addition of new functions. Figure 1Implemented on the smart card 112 or some other component of the system 100, so as to provide appropriate portions of the message flow 106 from the terminal 102 to various interface profiles 114.

[0047] Refer again Figure 2 In this embodiment, platform environment 202 is configured to install, instantiate, and / or serve one or more packages to various logical partitions 204 (e.g., logical partition 204a, logical partition 204b, ..., logical partition 204n) hosted by platform environment 202. Platform environment 202 can install and / or serve any desired package(s) 232. When platform environment 202 is a JCRE, some example packages 232 that can be used include, but are not limited to, Java Card (JC) packages that provide core and extended Java Card functionality for various logical partitions 204; Global Platform (GP) packages that allow Issuer Security Domains (ISDs) to act as installers within a logical partition and act as the root of all security domains in that logical partition; and European Telecommunications Standards Institute (ETSI) packages that provide the structure, format, protocol, and communication standards for UICCs and SIM cards, etc.

[0048] In one or more embodiments, platform environment 202 can initialize and / or install any package from various packages on one of the logical partitions (e.g., logical partition 204a) to provide corresponding functionality to logical partition 204a without initializing and / or installing the same package on another logical partition (e.g., logical partition 204b). Figure 2 As shown, each of the logical partitions 204 has been provided with the same package functionality, but the system 200 is not limited to this embodiment, and any combination of package installation / provisioning across various logical partitions 204 is possible in one or more embodiments.

[0049] Platform environment 202 includes a message scheduler 230 configured to determine which logical partition among the various logical partitions 204 to send a message from a message stream received from a smart card. In one or more embodiments, message scheduler 230 may be configured to identify interface switching indicators from the message stream to determine which logical partition 204 to send the next set of messages from the message stream to. Figure 3 The message scheduler 230 is described in more detail.

[0050] Refer again Figure 2In one embodiment, the platform environment 202 provides and manages a partitioned firewall mechanism 222 that can provide firewall protection between various logical partitions 204 (e.g., partitioned firewall mechanism 222a,..., partitioned firewall mechanism 222n-1) (e.g., partitioned firewall mechanism 222a separates logical partition 204a from logical partition 204b). The platform environment 202 operates the partitioned firewall mechanism 222 to completely prevent sharing of data and objects between the various logical partitions 204.

[0051] Due to memory constraints on the secure element / smart card / UICC on which the platform environment 202 executes, the number of logical partitions 204 that can be hosted and / or resident on the platform environment 202 can be limited. However, this constraint can be effectively overcome by using a component with sufficient memory to host a large number of logical partitions 204 (e.g., greater than 10 such partitions).

[0052] In one embodiment, when the platform environment 202 is a JCRE, the logical partitions 204 are logical JCREs (L-JCREs). In this embodiment, each L-JCRE provides and / or hosts an applet space 206 (e.g., applet space 206a on L-JCRE 204a, applet space 206b on L-JCRE 204b,..., applet space 206n on L-JCRE 204n, etc.). Each applet space 206 allows for the use of one or more converted applet (CAP) files (e.g., CAP file 210, CAP file 216, CAP file 224). A CAP file can include one or more contexts in which multiple applets can be invoked and / or used. For example, CAP file 210 supports context 212 with applets 214 (e.g., applet 214a, applet 214b,..., applet 214n, etc.). Similarly, CAP file 216 supports context 218 with applets 220 (e.g., applet 220a, applet 220b,..., applet 220n, etc.). While only a single context is shown for each CAP file, in some embodiments a CAP file can include multiple contexts. In one or more embodiments, the same CAP file can be installed and / or provided to multiple different applet spaces 206.

[0053] The applets provided by the various CAP files are separated from each other within the corresponding applet spaces 206 by applet firewalls 208 (e.g., applet firewall 208a separates applet 214 provided by CAP file 210 from applet 220 provided by CAP file 216 in applet space 206a, applet firewall 208b separates applet 214 provided by CAP file 210 from applet 228 provided by CAP file 224 in applet space 206b, etc.). The applet firewalls 208 are security mechanisms that are typically implemented in the JCRE. The applet firewalls 208 each perform checks at runtime to prevent applets from accessing (reading or writing) data of other applets (i.e., applets in different security contexts). For each object, its context is recorded, and for any field or method access, the applet firewall 208 checks whether it is allowed. In other words, applets are only allowed to access data and objects in their own context, or through the use of object sharing mechanisms, while the platform environment (e.g., JCRE) has the ability to access anything within the system 200. Further, each logical partition (e.g., L-JCRE) has a context and is able to access anything in that context.

[0054] In one or more embodiments, the platform environment 202 supports a fixed number or a variable number of logical interfaces (e.g., corresponding to the number of interfaces 104 on the terminal 102). The platform environment 202 enables the same number of logical partitions 204 on a one-to-one basis with the number of interfaces 104. In one or more embodiments, the terminal 102 and / or the platform environment 202 can determine a default logical interface to open after a smart card / UICC / SIM card reset.

[0055] In one or more embodiments, the platform environment 202 manages and handles all commands and / or messages configured / defined for managing logical interfaces (e.g., opening, switching, resetting). When a logical interface is in use, all commands and / or messages in the message stream 106 will be forwarded to the logical partition 204 associated with the active logical interface (e.g., when interface 104a is in use, all messages in the message stream 106 will be forwarded to the interface profile 114a corresponding to the logical interface represented by logical partition 204a). Once delivered to the appropriate interface profile 114, the commands and / or messages will be handled according to existing rules of the packages installed on the logical partition 204 associated with the interface profile 114 (e.g., rules in the Java Card specification).

[0056] Additional embodiments and / or examples related to computer networks are described below in the section entitled "Computer Networks and Cloud Networks."

[0057] In one or more embodiments, one or more components of system 100 and / or system 200 can be implemented on one or more digital devices. The term "digital device" generally refers to any hardware device that includes a processor. A digital device can refer to a physical device that executes an application or a virtual machine. Examples of digital devices include a computer, a tablet computer, a laptop computer, a desktop computer, a netbook, a server, a web server, a network policy server, a proxy server, a general purpose machine, a function-specific hardware device, a hardware router, a hardware switch, a hardware firewall, a hardware firewall, a hardware network address translator (NAT), a hardware load balancer, a mainframe, a television, a content receiver, a set-top box, a printer, a mobile handset, a smart phone, a personal digital assistant (PDA), a wireless receiver and / or transmitter, a base station, a communication management device, a router, a switch, a controller, an access point, and / or a client device.

[0058] In one or more embodiments, system 100 and / or system 200 can include a data repository (not shown in FIGS. 1 and 2). A data repository is any type of storage unit and / or device (e.g., a file system, a database, a collection of tables, and / or any other storage mechanism) for storing data. A data repository can include multiple different storage units and / or devices. The multiple different storage units and / or devices can or can not be of the same type or located at the same physical site. A data repository can be implemented or executed in the same computing system as one or more other components shown in FIGS. 1 and 2, and / or in a separate computing system. Figure 1 and Figure 2 A data repository can be communicatively coupled to one or more other components via a direct connection or via a network. Information can be implemented across any component of a platform other than a data repository. Figure 1 and Figure 2 A data repository can be implemented or executed in the same computing system as one or more other components shown in FIGS. 1 and 2, and / or in a separate computing system. A data repository can be communicatively coupled to one or more other components via a direct connection or via a network. Information can be implemented across any component of a platform other than a data repository.

[0059] In one or more embodiments, system 100 and / or system 200 can include a user interface. A user interface refers to hardware and / or software configured to facilitate communication between a user and one or more components of system 100 and / or system 200. An interface presents user interface elements and receives input via user interface elements. Examples of interfaces include graphical user interfaces (GUIs), command line interfaces (CLIs), haptic interfaces, and voice command interfaces. Examples of user interface elements include checkboxes, radio buttons, drop-down lists, list boxes, buttons, toggles, text fields, date and time selectors, command lines, sliders, pages, and forms. Different components of an interface can be specified in different languages. For example, the behavior of a user interface element can be specified in a dynamic programming language such as JavaScript. The content of a user interface element can be specified in a markup language such as HyperText Markup Language (HTML) or XML User Interface Language (XUL). The layout of a user interface element can be specified in a style sheet language such as Cascading Style Sheets (CSS). Alternatively, an interface can be specified in one or more other languages such as Java, Python, C, or C++.

[0060] 3. Message dispatcher

[0061] Figure 3 FIG. 1 illustrates the use of a message dispatcher 230 by a platform environment 202, in accordance with one or more embodiments. The platform environment 202 operates and manages the message dispatcher 230 in order to properly direct commands and / or messages from the message stream 106 to their intended destinations, which in some embodiments is based on which logical interface 104 receives the message(s) at the terminal 102.

[0062] In one embodiment, the message dispatcher 230 analyzes the message stream 106 and directs each message, instruction, request, and / or command included in the message stream 106 to a logical partition 204 via a logical secure element interface (LSI). Each LSI logically couples the terminal 102 with one of the logical partitions 204 within the platform environment 202 that corresponds to a particular logical interface (e.g., in response to the logical interface 104a being the particular logical interface, the message is directed to the logical partition 204a). The message is sent to the particular logical interface until an interface switch indicator 110 is read from the message stream 106. Once the interface switch indicator 110 is identified, the message dispatcher 230 determines the next logical partition 204 to send the next set of messages from the message stream 106. In other words, while the previous messages are directed to the logical partition 204a that corresponds to the logical interface 104a, the next set of messages in the message stream 106 are sent to the logical partition 204b that corresponds to the logical interface 104b indicated by the interface switch indicator 110.

[0063] In one embodiment, when there are only two logical partitions 204, the interface switch indicator 110 can be a simple flag or token that indicates to switch to the other logical partition to direct messages in the message stream 106 that follow the interface switch indicator 110.

[0064] In another embodiment, when there are more than two logical interfaces 104 corresponding to more than two logical partitions 204 on the terminal 102, then the interface switch indicator 110 can specify which logical interface 104 received the message that will immediately follow and / or the associated logical partition 204 so that the subsequent message can be directed to the appropriate logical partition 204 that will handle messages for that particular logical interface 104. In one or more embodiments, the platform environment 202 and / or the message dispatcher 230 can identify and maintain the interrelationships between the interface profiles 114 in the smart card 112 corresponding to the logical partitions 204 and the logical interfaces 104 on the terminal 102. These interrelationships can be stored to a memory accessible to the platform environment 202 and / or the smart card 112.

[0065] In an embodiment, the smart card 112 can receive a message stream 106 that includes a plurality of messages 108 and interface switch indicators 110 interspersed therein. The message dispatcher 230 transmits a first subset of messages 108a from the message stream 106 to a first logical partition (e.g., logical partition 204a) of the smart card 112. Prior to receiving the message stream 106, the terminal 102 orders the first subset of messages 108a in the message stream 106 to precede a first interface switch indicator 110a to be received at the message dispatcher 230. In response to the message dispatcher 230 detecting the first interface switch indicator 110a in the message stream, the message dispatcher 230 transmits a second subset of messages 108b in the message stream 106 to a second logical partition (e.g., logical partition 204b) of the smart card 112. Prior to receiving the message stream 106, the terminal 102 orders the second subset of messages 108b in the message stream 106 to be between the first interface switch indicator 110a and a second interface switch indicator 110b. In response to the message dispatcher 230 detecting the second interface switch indicator 110b in the message stream 106, the message dispatcher 230 transmits a third subset of messages 108c in the message stream 106 to the first logical partition 204a of the smart card 112. As shown, the terminal 102 orders the third subset of messages 108c in the message stream 106 to be between the second interface switch indicator 110b and a third interface switch indicator 110c. This toggling back and forth between delivering messages to the first logical partition 204a and the second logical partition 204b will continue as the message dispatcher 230 processes through the message stream 106.

[0066] When there are more than two logical partitions 204 present on the platform environment 202, the message dispatcher 230 will analyze the various interface switch indicators 110 included in the message stream 106 to determine to which logical partition 204 to transmit the next message subset in the message stream 106 until the next interface switch indicator 110 is identified.

[0067] 4. Platform registry

[0068] Figure 4 The use of the platform registry 402 by the platform environment 202 is illustrated in accordance with one or more embodiments. In an embodiment, the platform environment 202 maintains a platform registry 402 that includes a description of all packages 232 that reside on the platform environment 202 in a format readable by the platform environment 202. Further, each package 232 installed on a logical partition 204 is included in the platform registry 402. When the platform environment 202 is a JCRE and the logical partitions are L-JCREs, the available packages 232 can include, but are not limited to, JC packages, GP packages, ETSI packages, and the like. The platform environment 202 is configured to selectively make any or all of these various packages 232 available to the various logical partitions 204.

[0069] The logical partitions 204 manifest themselves on the applet hierarchy in the applet space 206 and appear to external devices as existing platform environments (e.g., the logical partitions act and behave like platform environments). When the platform environment 202 is a JCRE, each of the logical partitions 204 is an L-JCRE that appears to other devices as its own JCRE. The platform JCRE 202 keeps track of which logical interface is active at any given time. An "active" interface means that the message dispatcher 230 is currently actively directing messages to that logical interface, as opposed to some other "inactive" logical interface. The active interface can be determined based on some default setting or based on a received message (e.g., an interface switch indicator) indicating which interface is the active interface. Further, in one or more embodiments, the platform JCRE 202 isolates the different L-JCREs 204 such that the platform JCRE 202 operating with any given L-JCRE 204 behaves like a single JCRE instance on a chip. Each L-JCRE 204 is associated with a logical interface and this connection is maintained by the platform JCRE 202.

[0070] According to one embodiment, each logical partition (e.g., L-JCRE) 204 has a dedicated logical registry 406 (e.g., logical partition 204a has logical registry 406a, logical partition 204b has logical registry 406b). In this embodiment, each logical registry view 408 (e.g., logical registry view 408a on logical partition 204a, logical registry view 408b on logical partition 204b) can be obtained as a merge between the platform registry 402 and the corresponding dedicated logical registry 406 on the logical partition. In this manner, the platform registry 402 includes packages for the platform environment 202 (e.g., P-JCRE packages), but not any packages for the logical partitions 204 (e.g., L-JCRE packages).

[0071] In one or more embodiments, the platform environment 202 (e.g., platform JCRE) has a platform registry 402 with tags indicating which entries are applicable to which logical partition 204 (e.g., L-JCRE). Each logical registry view 408 can be obtained by filtering entries from the entries in the platform registry 402 according to the tags. For example, entries tagged with an identifier corresponding to a particular logical partition 204 (e.g., L-JCRE) or tagged with an identifier assigned to the platform environment 202 (e.g., platform JCRE) can be made available and / or downloaded into the logical registry view 408. This ensures that all common registry entries assigned to the platform environment 202 and logical partition-specific entries are included in the logical registry view 408.

[0072] Each logical partition 204 relies on the local logical registry view 408 to determine which packages 232 that can be needed and / or used by the logical partition 204 to perform a certain task or operation that reside on the platform environment 202 in order to obtain the package and / or have the package installed on the logical partition 204. In one embodiment, an installer 410a on logical partition 204a is used to install all packages for logical partition 204a. The installer 410a can be an instance of the platform installer 404 and / or provided by the host platform 202 based on the platform installer 404. Similarly, in one embodiment, an installer 410b on logical partition 204b can be used to install all packages on logical partition 204b. The installer 410b can be an instance of the platform installer 404 and / or provided by the host platform 202 based on the platform installer 404.

[0073] Each L-JCRE 204 has an installer 410 that is the root of all installed packages and applet instances in that L-JCRE 204. In the case of a global platform implementation of the L-JCRE 204, it has an Issuer Security Domain (ISD) that is the installer and acts as the root of all security domains in that L-JCRE 204.

[0074] Each package 232 loaded for a particular L-JCRE 204 and applet installed in the applet space 206 is only associated with the installer 410 or ISD of that L-JCRE 204 (e.g., the installer / ISD 410 on the L-JCRE 204a). The registry of the L-JCRE 204 that the ISD can see and the applets can access is a combination of the package registry of the platform JCRE 202 and packages and the instance registry of the applets of the L-JCRE 204. In this way, there can be in the L-JCRE 204 an applet instance or package with the same applet identifier (AID) as in a second L-JCRE 204.

[0075] 5. Logical partitioning support

[0076] Figure 5 An example system 500 that supports logical partitioning is illustrated in accordance with one or more embodiments. The system 500 includes a platform environment (e.g., JCRE) 202 that supports multiple logical partitions (L-JCREs) 204a, 204b, etc. on which. Each logical partition 204 operates its own Card Application Toolkit (CAT) runtime environment (CAT-RTE) 526 (e.g., CAT RTE 526a on L-JCRE 204a, CAT RTE 526b on L-JCRE 204b, etc.) and a UICC runtime environment (UICC RTE) 518 (e.g., UICC RTE 518a on L-JCRE 204a, UICC RTE 518b on L-JCRE 204b, etc.). Above these layers, multiple packages are supported for implementation in each logical partition 204. These packages include, but are not limited to, various Java Card packages 510, a UICC.Access package 512, a UICC.Toolkit package 514, and a UICC.System package 516.

[0077] Above this layer, each logical partition 204 also operates a file system and various applications / packages. For example, in the L-JCRE 204a, a file system 522, a UICC. File package 524, and a UICC. System package 520 are supported. Figure 5Each logical partition 204 is running a UICC file system server 502 (e.g., UICC file system server 502a on L-JCRE 204a, UICC file system server 502b on L-JCRE 204b, etc.), some applications based on ETSI 102 221 (such as SIM applets, USIM applets, etc.) along with an ADF file system server 504 (e.g., ADF file system server 504a on L-JCRE 204a, ADF file system server 504b on L-JCRE 204b, etc.), some other applications 506 (not based on ETSI 102 221) (e.g., other applications 506a on L-JCRE 204a, other applications 506b on L-JCRE 204b, etc.), and toolkit applets 508 (e.g., toolkit applets 508a on L-JCRE 204a, toolkit applets 508b on L-JCRE 204b, etc.) (such as toolkit services, remote management applications, browser applications, etc.) in each logical partition 204.

[0078] If the L-JCRE 204 also implements a CAT RTE 526 according to the ETSI standard, it also maintains a logical toolkit registry 522, which is responsible for storing the terminal profile, the list of events, and all other toolkit-specific data related to the logical interface associated with this L-JCRE 204. In one or more embodiments, the combination of UICC RTE 518 and CAT RTE 526 includes the logical interface for a particular logical partition 204. For example, UICC RTE 518a and CAT RTE 526a (which includes toolkit handler 520a, toolkit registry 522a, and trigger entity 524a) includes the logical interface for logical partition (L-JCRE) 204a.

[0079] Each UICC RTE 518 stores the terminal profile it has received via the associated LSI, stores all the toolkit registry events for which applets have registered on the associated L-JCRE 204, and makes the handler available to the applets on the L-JCRE 204 in case the associated LSI is the interface that is currently open for the terminal 102. The LSI is a logical connection between an endpoint in the terminal and one logical partition 204 within the platform environment 202.

[0080] The file system of the secure element / smart card / UICC and how it is partitioned and associated with logical interfaces is exposed to the CAT-RTE 526 and corresponding file system APIs. However, in one approach, this information will not be visible to the application layer. The CAT-RTE 526, which is an extension to the platform JCRE 202, ensures that the applet on the L-JCRE 204 can only access the file system parts associated with the corresponding logical interface.

[0081] On the UICC, the specific extension of each L-JCRE 204 and its CAT-RTE 526 will ensure that the FileView object can only access files associated by the UICC operating system to the same logical interface the L-JCRE 204 is associated with. Global objects and so-called “JCRE entry point objects” (like File View, handlers, APDU buffers) are only visible in the context of the L-JCRE 204 they are associated with. Thus, in one embodiment, the platform JCRE 202 keeps track of which applet from which L-JCRE 204 is accessing a specific object and ensures that these specific objects are allocated on the platform JCRE hierarchy.

[0082] In another embodiment, specific objects are created for the L-JCRE 204 and only under the control of the L-JCRE 204, freeing the platform JCRE 202 from the need to keep track of such interactions. This is equally true for applet created and persistently stored objects (e.g., cryptographic keys, blockchain keys, encryption keys, etc.). The platform JCRE 202, such as by leveraging a partition firewall, ensures that only applets from the same L-JCRE 204 can access this sensitive data.

[0083] During any time interval where no communication occurs on the logical interface (the message flow 106 is empty, the connection is interrupted, etc.), the L-JCRE 204 will behave like a card waiting for the next command. The L-JCRE 204 stores the context of the L-JCRE 204 at the time it has sent the last response APDU, which applets are selected, the status of the PIN, etc. The context of the file view and the state of the toolkit registry are also saved during LSI switching.

[0084] 5. Example Embodiments

[0085] For the sake of clarity, detailed examples are described below. The components and / or operations described below should be understood as one particular example that can not apply to certain embodiments. Thus, the components and / or operations described below should not be interpreted as limiting the scope of any claims.

[0086] Figure 6FIGURE illustrates an example set of operations 600 for generating a message flow for multiple logical partitions of a smart card, in accordance with one or more embodiments. Figure 6 One or more of the operations shown in FIGURE 6 can be modified, rearranged, or omitted. Thus, for example, Figure 6 The particular sequences of operations shown in FIGURE 6 should not be construed as limiting the scope of one or more embodiments. Although the operations are described as being performed by a system, in one or more embodiments the set of operations 600 can be performed by any hardware, software, or combination thereof. Figure 6

[0087] In operations 602 and 604, the system receives a plurality of messages at a terminal. In operation 602, the system receives, at the terminal via a first interface, a first subset of the plurality of messages destined for a first logical partition of a smart card. The logical partition of the smart card can be an L-JCRE, as described herein in various embodiments. Further, the smart card can be a UICC, a secure element, or some other communication chip device.

[0088] In operation 604, the system receives, at the terminal via a second interface, a second subset of the plurality of messages destined for a second logical partition of the smart card. In various embodiments, the first interface and the second interface can be a wireless interface, a wired interface, or a direct connection with another component of the system.

[0089] In one or more embodiments, the first logical partition can correspond to a first subscriber identity module (SIM) card profile and the second logical partition can correspond to a second SIM card profile.

[0090] According to some embodiments, the first logical partition can correspond to a first application executing on the smart card and the second logical partition can correspond to a second application executing on the smart card.

[0091] In one way, the first and second partitions can correspond to a mix of different entities on the smart card, including a SIM card profile, an application, a UICC profile, a secure element profile, an L-JCRE, and the like.

[0092] In one or more embodiments, the smart card can be a UICC, an integrated smart card for a mobile handset, a removable smart card for a mobile handset, or some other suitable device described herein.

[0093] ​In operations 606 and 608, the system generates a message stream comprising a plurality of messages. In operation 606, the system orders the plurality of messages within the message stream in a temporal order based at least in part on respective times at which each message of the plurality of messages was received at the terminal. While messages are not required to be strictly in temporal order within the message stream, it is one of the considerations in determining the order of messages in the message stream. Other considerations include minimizing the number of interface switch indicators, reducing resource usage for generating and / or processing the message stream, etc.

[0094] In operation 608, the system inserts, in the message stream, an interface switch indicator corresponding to each switch between (a) a message from a first subset of the plurality of messages and (b) a message from a second subset of the plurality of messages. In this way, an interface switch indicator is inserted in the message stream each time the destination of a message in the message stream changes, to make the receiving device aware of the change.

[0095] According to one or more embodiments, the system can order the plurality of messages within the message stream in a temporal order by: grouping messages from a first subset of the plurality of messages received in a first time period into a first group of messages; grouping messages from a second subset of the plurality of messages received in a second time period into a second group of messages, wherein a start time of the second time period is later than a start time of the first time period; ordering the first group of messages before the second group of messages in the message stream, wherein at least one message in the second group of messages is received before at least one message in the first group of messages.

[0096] To avoid including too many back-and-forth and / or too many interface switch indicators in the message stream, some grouping can be performed instead of strict temporal ordering of messages. In one embodiment, the system can group messages together in a set of reception times from one of the interfaces of the terminal even when the reception times of different interfaces overlap.

[0097] For example, all messages received from 10ms to 20ms on a first interface can be added to a first subset of messages and sent to the smart card before all messages received from 15ms to 25ms on a second interface that are to be added to a second subset of messages. In this example, a message received at 15ms in the second subset is sent later than a message received at 17ms in the first subset, but it prevents adding a large number of interface switch indicators to the message stream to switch all messages received from 15ms to 20ms across the two interfaces.

[0098] In operation 610, the system transmits, by the terminal to the smart card, the message stream comprising the ordered plurality of messages with the inserted interface switch indicators.

[0099] The operations 600 can also include, once the message stream is generated and transmitted to the smart card, performing any of the following: the smart card receiving the message stream including the ordered plurality of messages with the inserted interface switch indicator; transmitting a first group of the first subset of messages to the first logical partition, the first group of the first subset of messages ordered in the message stream before the first interface switch indicator; in response to detecting the first interface switch indicator in the message stream: transmitting a first group of the second subset of messages to the second logical partition, the first group of the second subset of messages ordered in the message stream between the first interface switch indicator and the second interface switch indicator; and in response to detecting the second interface switch indicator in the message stream: transmitting a second group of the first subset of messages to the first logical partition, the second group of the first subset of messages ordered in the message stream between the second interface switch indicator and the third interface switch indicator.

[0100] Figure 7 FIGURE 13 illustrates an example set of operations 1300 for processing a message stream for multiple logical partitions of a smart card, in accordance with one or more embodiments. Figure 7 One or more of the operations shown in FIGURE 13 can be modified, rearranged, or omitted. Thus, the particular sequence of operations illustrated in FIGURE 13 should not be construed as limiting the scope of one or more embodiments. Figure 7 The particular sequence of operations shown in FIGURE 13 should not be construed as limiting the scope of one or more embodiments. Although the operations are described as being performed by a system, in one or more embodiments the set of operations 1300 can be performed using any hardware, software, or combination thereof. Figure 7 The particular sequence of operations shown in FIGURE 13 should not be construed as limiting the scope of one or more embodiments. Although the operations are described as being performed by a system, in one or more embodiments the set of operations 1300 can be performed using any hardware, software, or combination thereof.

[0101] In operation 702, the system receives a message stream including a plurality of messages and interface switch indicators. In one embodiment, the message stream can be generated by a terminal of a mobile handset. Each interface switch indicator in the message stream indicates a change in which interface receives subsequent messages in the message stream.

[0102] In operation 704, the system transmits a first subset of messages of the plurality of messages to a first logical partition of the smart card, the first subset of messages ordered in the message stream before a first interface switch indicator.

[0103] In operation 706, the system identifies the first interface switch indicator in the message stream. If no interface switch indicator is identified in the message stream, the messages continue to be transmitted to the first logical partition of the smart card. In response to detecting the first interface switch indicator in the message stream, in operation 708, the system transmits a second subset of messages of the plurality of messages to a second logical partition of the smart card. The second subset of messages is ordered in the message stream between the first interface switch indicator and a second interface switch indicator.

[0104] In operation 708, the system identifies a second interface switch indicator in the message stream. If no interface switch indicator is identified in the message stream after the first interface switch indicator, the messages will continue to be transmitted to the second logical partition of the smart card. In response to detecting the second interface switch indicator in the message stream, in operation 710, the system transmits a third subset of messages of the plurality of messages to the first logical partition of the smart card. The third subset of messages is ordered in the message stream between the second interface switch indicator and a third interface switch indicator.

[0105] According to one or more embodiments, the first logical partition can correspond to a first SIM card profile and the second logical partition can correspond to a second SIM card profile.

[0106] According to some embodiments, the first logical partition can correspond to a first application executing on the smart card and the second logical partition can correspond to a second application executing on the smart card.

[0107] In one approach, the first and second partitions can correspond to a mix of different entities on the smart card, including SIM card profiles, applications, UICC profiles, secure element profiles, L-JCREs, etc.

[0108] In one or more embodiments, the smart card can be a UICC, an integrated smart card for a mobile handset, a removable smart card for a mobile handset, or some other suitable device described herein.

[0109] In one or more embodiments, a system can receive a plurality of messages at a terminal (e.g., of a mobile handset), including receiving a first set of the plurality of messages destined for a first logical partition of a smart card via a first interface and receiving a second set of the plurality of messages destined for a second logical partition of the smart card via a second interface. The system can generate a message stream including the plurality of messages by ordering the plurality of messages in a temporal order within the message stream based at least in part on respective times at which each message of the plurality of messages is received at the terminal and inserting an interface switch indicator in the message stream corresponding to each switch between (a) messages from the first set of the plurality of messages and (b) messages from the second set of the plurality of messages. Thereafter, the system can transmit the message stream including the ordered plurality of messages with the inserted interface switch indicators to the smart card by the terminal.

[0110] Figure 8 FIG. 8 illustrates an example set of operations 800 for applying a partitioned firewall to a plurality of logical partitions of a smart card, according to one or more embodiments. Figure 8 One or more of the operations shown in FIG. 8 can be modified, rearranged, or omitted. Thus, for example, Figure 8The specific operations sequences described in connection with the embodiments are not to be interpreted as limiting the scope of one or more embodiments. To the contrary, it is contemplated that operations might be combined or otherwise re-ordered, and / or various aspects of the embodiments could be altered or supplemented. Figure 8 The set of operations 800 might be performed using any hardware, software, or combinations thereof in one or more embodiments.

[0111] In operation 802, the system hosts a smart card's first logical partition configured to receive messages received at a first wireless interface (e.g., of a terminal of a mobile handset).

[0112] In operation 804, the system hosts a smart card's second logical partition configured to receive messages received at a second wireless interface.

[0113] In operation 806, the system prevents access from any processes corresponding to the second logical partition to data and processes corresponding to the first logical partition, e.g., applying a partition firewall between the first and second logical partitions. Additional partition firewalls can be applied between all other logical partitions of the smart card.

[0114] In operation 808, the system prevents access from any processes corresponding to the first logical partition to data corresponding to the second logical partition.

[0115] In one or more embodiments, the system can also maintain a registry of platform packages (e.g., for Java Card, GlobalPlatform, ETSI, etc.) for the JCRE. Further, the system can selectively perform operations corresponding to at least one first platform package and / or install at least one first platform package on the first logical partition for execution by the first logical partition in accordance with the registry of platform packages for the first logical partition. Further, the system can selectively perform operations corresponding to at least one second platform package and / or install at least one second platform package on the second logical partition for execution by the second logical partition in accordance with the registry of platform packages for the second logical partition. In one or more embodiments, the first and second packages can be the same platform package or different platform packages.

[0116] In one embodiment, the system can perform operations corresponding to at least one platform package in accordance with the registry of platform packages for the first and second logical partitions.

[0117] 6. Computer networks and cloud networks

[0118] In one or more embodiments, a computer network provides connectivity between a set of nodes. The nodes can be local to each other and / or remote from each other. The nodes are connected by a set of links. Examples of links include coaxial cable, unshielded twisted cable, copper wire, optical fiber, and virtual links.

[0119] A subset of nodes implement the computer network. Examples of such nodes include switches, routers, firewalls, and network address translators (NATs). Another subset of nodes use the computer network. Such nodes (also referred to as “hosts”) can execute client processes and / or server processes. Client processes make requests for computational services, such as execution of a particular application and / or storage of a particular quantity of data. Server processes respond by executing the requested services and / or returning the corresponding data.

[0120] A computer network can be a physical network, including physical nodes connected by physical links. A physical node is any digital device. A physical node can be a function-specific hardware device, such as a hardware switch, a hardware router, a hardware firewall, and a hardware NAT. Additionally or alternatively, a physical node can be a general-purpose machine configured to execute various virtual machines and / or applications that perform the respective functions. A physical link is a physical medium connecting two or more physical nodes. Examples of links include coaxial cable, unshielded twisted cable, copper cable, and optical fiber.

[0121] A computer network can be an overlay network. An overlay network is a logical network implemented on top of another network, such as a physical network. Each node in an overlay network corresponds to a respective node in the underlying network. Thus, each node in an overlay network is associated with both an overlay address (used to address to the overlay node) and an underlay address (used to address the underlay node that implements the overlay node). An overlay node can be a digital device and / or a software process, such as a virtual machine, an application instance, or a thread. A link connecting overlay nodes is implemented as a tunnel through the underlying network. Overlay nodes at either end of a tunnel treat the underlying multi-hop path between them as a single logical link. Tunneling is performed by encapsulation and decapsulation.

[0122] In embodiments, a client can be local to and / or remote from a computer network. A client can access a computer network through other computer networks, such as a private network or the Internet. A client can transmit requests to a computer network using a communication protocol, such as the Hypertext Transfer Protocol (HTTP). Requests are transmitted through an interface, such as a client interface (such as a web browser), a programmatic interface, or an application programming interface (API).

[0123] In embodiments, a computer network provides connectivity between clients and network resources. Network resources include hardware and / or software configured to execute server processes. Examples of network resources include processors, data storage devices, virtual machines, containers, and / or software applications. Network resources are shared among multiple clients. Clients independently request computing services from the computer network. Network resources are dynamically allocated to requests and / or clients on an on-demand basis. Network resources allocated to each request and / or client can scale up or down based on, for example, (a) the computing services requested by a particular client, (b) the aggregate computing services requested by a particular tenant, and / or (c) the requested aggregate computing services of the computer network. Such computer networks can be referred to as “cloud networks.”

[0124] In embodiments, a service provider provides a cloud network to one or more end users. The cloud network can implement various service models, including but not limited to software as a service (SaaS), platform as a service (PaaS), and infrastructure as a service (IaaS). In SaaS, the service provider provides end users with the ability to use applications executing on network resources of the service provider. In PaaS, the service provider provides end users with the ability to deploy custom applications onto network resources. The custom applications can be created using programming languages, libraries, services, and tools supported by the service provider. In IaaS, the service provider provides end users with the ability to provision processing, storage, networking, and other basic computing resources provided by network resources. Any arbitrary applications, including operating systems, can be deployed on the network resources.

[0125] In embodiments, a computer network can implement various deployment models, including but not limited to private cloud, public cloud, and hybrid cloud. In a private cloud, network resources are provisioned for the exclusive use of a particular group of one or more entities (as the term “entity” is used herein to refer to a company, organization, person, or other entity). The network resources can be local to the premises of the particular group of entities and / or remote from the premises of the particular group of entities. In a public cloud, cloud resources are provisioned for multiple entities (also referred to as “tenants” or “customers”) independently of one another. The computer network and its network resources are accessed by clients corresponding to different tenants. Such computer networks can be referred to as “multi-tenant computer networks.” Several tenants can use the same particular network resources at different times and / or at the same time. The network resources can be local to the premises of the tenants and / or remote from the premises of the tenants. In a hybrid cloud, a computer network includes a private cloud and a public cloud. An interface between the private cloud and the public cloud allows for portability of data and applications. Data stored at the private cloud and data stored at the public cloud can be exchanged through the interface. Applications implemented at the private cloud and applications implemented at the public cloud can have dependencies on one another. Calls from an application at the private cloud to an application at the public cloud (and vice versa) can be performed through the interface.

[0126] In embodiments, tenants of a multi-tenant computer network are independent of each other. For example, a tenant's business or operations can be separate from another tenant's business or operations. Different tenants can require different network requirements for the computer network. Examples of network requirements include processing speed, amount of data storage, security requirements, performance requirements, throughput requirements, latency requirements, resiliency requirements, Quality of Service (QoS) requirements, tenant isolation, and / or consistency. The same computer network can need to implement different network requirements required by different tenants.

[0127] In one or more embodiments, in a multi-tenant computer network, tenant isolation is implemented to ensure that applications and / or data of different tenants are not shared with each other. Various tenant isolation methods can be used.

[0128] In embodiments, each tenant is associated with a tenant ID. Each network resource of the multi-tenant computer network is tagged with a tenant ID. A tenant is only allowed to access a particular network resource if the tenant and the particular network resource are associated with the same tenant ID.

[0129] In embodiments, each tenant is associated with a tenant ID. Each application implemented by the computer network is tagged with a tenant ID. Additionally or alternatively, each data structure and / or data set stored by the computer network is tagged with a tenant ID. A tenant is only allowed to access a particular application, data structure, and / or data set if the tenant and the particular application, data structure, and / or data set are associated with the same tenant ID.

[0130] As an example, each database implemented by the multi-tenant computer network can be tagged with a tenant ID. Only a tenant associated with a corresponding tenant ID can access data of a particular database. As another example, each entry in a database implemented by the multi-tenant computer network can be tagged with a tenant ID. Only a tenant associated with a corresponding tenant ID can access data of a particular entry. However, the database can be shared by multiple tenants.

[0131] In embodiments, a subscription list indicates which tenants have authorization to access which applications. For each application, a list of tenant IDs of tenants authorized to access the application is stored. A tenant is only allowed to access a particular application if the tenant's tenant ID is included in the subscription list corresponding to the particular application.

[0132] In embodiments, network resources corresponding to different tenants, such as digital devices, virtual machines, application instances, and threads, are isolated to tenant-specific overlay networks maintained by the multi-tenant computer network. As an example, packets from any source device in a tenant overlay network can only be transmitted to other devices within the same tenant overlay network. Any transmissions from a source device on a tenant overlay network to devices in other tenant overlay networks are prohibited using encapsulation tunnels. Specifically, a packet received from a source device is encapsulated within an outer packet. The outer packet is transmitted from a first encapsulation tunnel endpoint (in communication with the source device in the tenant overlay network) to a second encapsulation tunnel endpoint (in communication with a destination device in the tenant overlay network). The second encapsulation tunnel endpoint decapsulates the outer packet to obtain the original packet transmitted by the source device. The original packet is transmitted from the second encapsulation tunnel endpoint to the destination device in the same specific overlay network.

[0133] 7. Hardware Overview

[0134] According to one embodiment, the technology described herein is implemented by one or more special-purpose computing devices. The special-purpose computing devices can be hardwired to perform the present technology, or can include digital electronic devices such as one or more application-specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or network processing units (NPUs) that are persistently programmed to perform the present technology, or can include one or more general purpose hardware processors programmed to perform the present technology pursuant to program instructions in firmware, memory, other storage, or a combination. Such special-purpose computing devices can also combine custom hard-wired logic, ASICs, FPGAs, or NPUs with custom programming to accomplish the present technology. The special-purpose computing devices can be a desktop computer system, a portable computer system, a handheld device, a networking device or any other device that incorporates hard-wired and / or program logic to implement the present technology.

[0135] For example, Figure 9 is a block diagram that illustrates a computer system 900 upon which an embodiment of the application can be implemented. Computer system 900 includes a bus 902 or other communication mechanism for communicating information, and a hardware processor 904 coupled with bus 902 for processing information. Hardware processor 904 can be one or more general

[0136] The computer system 900 also includes a main memory 906, such as a random access memory (RAM) or other dynamic storage device, coupled to bus 902 for storing information and instructions to be executed by processor 904. Main memory 906 also can be used for storing temporary variables or other intermediate information during execution of instructions to be executed by processor 904. Such instructions can be stored or implemented in non-transitory storage media accessible by processing system 900, such as storage device 910, hard disk, or other memory storage.

[0137] The computer system 900 further includes a read only memory (ROM) 908 or other static storage device coupled to bus 902 for storing static information and instructions for processor 904. A storage device 910, such as a magnetic disk or optical disk, is provided and coupled to bus 902 for storing information and instructions.

[0138] Computer system 900 can be coupled via bus 902 to a display 912, such as a cathode ray tube (CRT), for displaying information to a computer user. An input device 914, including alphanumeric and other keys, is coupled to bus 902 for communicating information and command selections to processor 904. Another type of user input device is cursor control 916, such as a mouse, a trackball, or cursor direction keys for communicating direction information and command selections to processor 904 and for controlling cursor movement on display 912. This input device typically has two degrees of freedom in two axes, a first axis (e.g., x) and a second axis (e.g., y), that allows the device to specify positions in a plane.

[0139] Computer system 900 can implement the techniques described herein using customized hard-wired logic, one or more ASICs or FPGAs, firmware and / or program logic which in combination with the computer system causes or programs computer system 900 to be a special-purpose machine. According to one embodiment, the techniques herein are performed by computer system 900 in response to processor 904 executing one or more sequences of one or more instructions contained in main memory 906. Such instructions can be read into main memory 906 from another storage medium, such as storage device 910. Execution of the sequences of instructions contained in main memory 906 causes processor 904 to perform the process steps described herein. In alternative embodiments, hard-wired circuitry can be used in place of or in combination with software instructions.

[0140] The term“storage media” as used herein refers to any non-transitory media that store data and / or instructions that cause a machine to operate in a specific fashion. Such storage media can comprise non-volatile media and / or volatile media. Non-volatile media includes, for example, optical disks or magnetic disks, such as storage device 910. Volatile media includes dynamic memory, such as main memory 906. Common forms of storage media include, for example, a floppy disk, a flexible disk, a hard disk, a solid state drive, a magnetic tape, or any other magnetic data storage medium, a CD-ROM, any other optical data storage medium, any physical medium with patterns of holes, a RAM, a PROM, and EPROM, a FLASH-EPROM, NVRAM, any other memory chip or cartridge, content addressable memory (CAM), and ternary content addressable memory (TCAM).

[0141] Storage media are tangible and non-transitory. Storage media has physical properties, such as shape, surface texture, and / or color, that differ based on the information encoded in the storage media. Storage media excludes signals per se. Storage media excludes a modulated data signal carrier wave per se. Storage media excludes a non-tangible, transitory signal per se. Storage media excludes a signal per se that can be carried by a carrier wave or other transitory signals.

[0142] Carrying one or more sequences of instructions to the processor 904 for execution can involve various forms of media. For example, initially, the instructions can be carried on a magnetic disk or solid state drive of a remote computer. The remote computer can load the instructions into its dynamic memory and send the instructions over a telephone line using a modem. A modem local to the computer system 900 can receive the data on the telephone line and use an infra-red transmitter to convert the data to an infra-red signal. An infra-red detector can receive the infra-red signal and appropriate circuitry of the computer system 900 can place the data carried in the infra-red signal in bus 902. Bus 902 carries the data to main memory 906, from which processor 904 retrieves and executes the instructions. The instructions received by main memory 906 can optionally be stored on storage device 910 either before or after execution by processor 904.

[0143] Computer system 900 also includes a communication interface 918 coupled to bus 902. Communication interface 918 provides a two-way data communication coupling to a network link 920 that is connected to a local network 922. For example, communication interface 918 can be an integrated services digital network (ISDN) card, cable modem, satellite modem, or a modem to provide a data communication connection to a corresponding type of telephone line. As another example, communication interface 918 can be a local area network (LAN) card to provide a data communication connection to a compatible LAN. Wireless links can also be implemented. In any such implementation, communication interface 918 sends and receives electrical, electromagnetic or optical signals that carry digital data streams representing various types of information.

[0144] Network link 920 typically provides data communication through one or more networks to other data devices. For example, network link 920 can provide a connection through local network 922 to a host computer 924 or to data equipment operated by an Internet Service Provider (ISP) 926. ISP 926 in turn provides data communication services through the world wide packet data communication network now commonly referred to as the "Internet" 928. Local network 922 and Internet 928 both use electrical, electromagnetic or optical signals that carry digital data streams. The signals through the various networks and the signals on network link 920 and through communication interface 918, which carry the digital data to and from computer system 900, are example forms of transmission media for digital data.

[0145] Computer system 900 can send messages and receive data, including program code, through the network(s), network link 920 and communication interface 918. In the Internet example, a server 930 might transmit a requested code for an application program through Internet 928, ISP 926, local network 922 and communication interface 918.

[0146] The received code can be executed by processor 904 as it is received, and / or stored in storage device 910, or other non-volatile storage for later execution.

[0147] 8. Other Matters; Extensions

[0148] Embodiments relate to a system having one or more devices comprising a hardware processor and configured to perform any of the operations described herein and / or recited in any of the claims below.

[0149] In an embodiment, a non-transitory computer-readable storage medium comprises instructions that, when executed by one or more hardware processors, cause performance of any of the operations described herein and / or recited in any of the claims.

[0150] Any combination of the features and functionality described herein can be used in accordance with one or more embodiments. In the foregoing specification, embodiments have been described with reference to numerous specific details that can vary from implementation to implementation. Thus, the specification and drawings should be regarded as illustrative rather than restrictive. The sole and exclusive indicator of the scope of the application, and what is intended by the inventors to be the scope of the application, is the literal and equivalent scope of the claims that issue from this application, in whatever form they can be expressed, including any subsequent amendments, revisions, equivalents, rulers, or substitutions.

Claims

1. One or more non-transitory machine-readable media storing instructions that, when executed by one or more processors, cause: receiving, at a terminal, a plurality of messages, the receiving comprising: receiving, at the terminal via a first interface, a first subset of the plurality of messages to a first logical partition of a smart card; receiving, at the terminal via a second interface, a second subset of the plurality of messages to a second logical partition of the smart card; generating a message stream comprising the plurality of messages, the generating comprising: ordering the plurality of messages within the message stream in a temporal order based at least in part on respective times at which each of the plurality of messages was received at the terminal; and inserting, in the message stream, an interface switch indicator corresponding to each switch between (a) a message from the first subset of the plurality of messages and (b) a message from the second subset of the plurality of messages; and transmitting, by the terminal to the smart card, the message stream comprising the ordered plurality of messages with the inserted interface switch indicators.

2. The one or more non-transitory machine-readable media of claim 1, wherein the first logical partition corresponds to a first subscriber identity module (SIM) card profile and the second logical partition corresponds to a second SIM card profile.

3. The one or more non-transitory machine-readable media of claim 1, wherein the first logical partition corresponds to a first application executing on the smart card and the second logical partition corresponds to a second application executing on the smart card.

4. The one or more non-transitory machine-readable media of claim 1, wherein the smart card is a universal integrated circuit card (UICC).

5. The one or more non-transitory machine-readable media of claim 1, wherein the smart card is an integrated smart card or a removable smart card for a mobile handset.

6. The one or more non-transitory machine-readable media of claim 1, wherein ordering the plurality of messages within the message stream in a temporal order based at least in part on respective times at which each of the plurality of messages was received at the terminal comprises: grouping messages from the first subset of the plurality of messages received in a first time period into a first group of messages; grouping messages from the second subset of the plurality of messages received in a second time period into a second group of messages, wherein a start time of the second time period is later than a start time of the first time period; ordering the first group of messages before the second group of messages in the message stream, wherein at least one message in the second group of messages is received before at least one message in the first group of messages.

7. The one or more non-transitory machine-readable media of claim 1, wherein the instructions, when executed by the one or more processors, further cause: receiving, at the smart card, the message stream comprising the ordered plurality of messages with the inserted interface switch indicators; transmitting a first group of the first subset of the plurality of messages to the first logical partition, the first group of the first subset of messages being ordered in the message stream before a first interface switch indicator; in response to detecting the first interface switch indicator in the message stream: transmitting a first group of a second subset of messages of the plurality of messages to the second logical partition, the first group of the second subset of messages ordered in the message stream between the first interface switch indicator and the second interface switch indicator; and in response to detecting the second interface switch indicator in the message stream: transmitting a second group of a third subset of messages of the plurality of messages to the first logical partition, the second group of the third subset of messages ordered in the message stream between the second interface switch indicator and a third interface switch indicator.

8. One or more non-transitory machine-readable media storing instructions that, when executed by one or more processors, cause: receiving a message stream comprising a plurality of messages and interface switch indicators; transmitting a first subset of messages of the plurality of messages to a first logical partition of a smart card, the first subset of messages ordered in the message stream before a first interface switch indicator; in response to detecting the first interface switch indicator in the message stream: transmitting a second subset of messages of the plurality of messages to a second logical partition of the smart card, the second subset of messages ordered in the message stream between the first interface switch indicator and a second interface switch indicator; and in response to detecting the second interface switch indicator in the message stream: transmitting a third subset of messages of the plurality of messages to the first logical partition of the smart card, the third subset of messages ordered in the message stream between the second interface switch indicator and a third interface switch indicator.

9. The one or more non-transitory machine-readable media of claim 8, wherein the first logical partition corresponds to a first subscriber identity module (SIM) card profile and the second logical partition corresponds to a second SIM card profile.

10. The one or more non-transitory machine-readable media of claim 8, wherein the first logical partition corresponds to a first application executing on the smart card and the second logical partition corresponds to a second application executing on the smart card.

11. The one or more non-transitory machine-readable media of claim 8, wherein the smart card is a universal integrated circuit card (UICC).

12. The one or more non-transitory machine-readable media of claim 8, wherein the smart card is an integrated smart card or a removable smart card for a mobile handset.

13. The one or more non-transitory machine-readable media of claim 8, wherein the message stream is received from a terminal, wherein the plurality of messages are ordered in a temporal order within the message stream based at least in part on respective times at which each message of the plurality of messages is received at the terminal, and wherein at least one message of the second subset of messages is received at the terminal before at least one message of the first subset of messages.

14. The one or more non-transitory machine-readable media of claim 8, wherein the instructions, when executed by the one or more processors, further cause: receiving the plurality of messages at a terminal, the receiving operation comprising: receiving, at the terminal, a first set of the plurality of messages destined for a first logical partition of the smart card via a first interface; receiving, at the terminal, a second set of the plurality of messages destined for a second logical partition of the smart card via a second interface; generating a message stream comprising the plurality of messages, the generating comprising: ordering the plurality of messages within the message stream in a temporal order based at least in part on respective times at which each of the plurality of messages was received at the terminal; and inserting, in the message stream, an interface switch indicator corresponding to each switch between (a) a message from the first set of the plurality of messages and (b) a message from the second set of the plurality of messages; and transmitting, by the terminal to the smart card, the message stream comprising the ordered plurality of messages with the inserted interface switch indicators.

15. A system comprising: at least one device comprising a hardware processor; the system configured to perform operations comprising receiving a plurality of messages at a terminal, the receiving comprising: receiving, at the terminal, a first subset of the plurality of messages destined for a first logical partition of the smart card via a first interface; receiving, at the terminal, a second subset of the plurality of messages destined for a second logical partition of the smart card via a second interface; generating a message stream comprising the plurality of messages, the generating comprising: ordering the plurality of messages within the message stream in a temporal order based at least in part on respective times at which each of the plurality of messages was received at the terminal; and inserting, in the message stream, an interface switch indicator corresponding to each switch between (a) a message from the first subset of the plurality of messages and (b) a message from the second subset of the plurality of messages; and transmitting, by the terminal to the smart card, the message stream comprising the ordered plurality of messages with the inserted interface switch indicators.

16. A method comprising: receiving a plurality of messages at a terminal, the receiving comprising: receiving, at the terminal, a first subset of the plurality of messages destined for a first logical partition of the smart card via a first interface; receiving, at the terminal, a second subset of the plurality of messages destined for a second logical partition of the smart card via a second interface; generating a message stream comprising the plurality of messages, the generating comprising: ordering the plurality of messages within the message stream in a temporal order based at least in part on respective times at which each of the plurality of messages was received at the terminal; and inserting, in the message stream, an interface switch indicator corresponding to each switch between (a) a message from the first subset of the plurality of messages and (b) a message from the second subset of the plurality of messages; and transmitting, by the terminal to the smart card, the message stream comprising the ordered plurality of messages with the inserted interface switch indicators.

17. A system comprising: at least one device comprising a hardware processor; the system configured to perform operations comprising: receiving a message stream comprising a plurality of messages and interface switch indicators; transmitting a first subset of messages of the plurality of messages to a first logical partition of a smart card, the first subset of messages ordered in the message stream before a first interface switch indicator; in response to detecting the first interface switch indicator in the message stream: transmitting a second subset of messages of the plurality of messages to the second logical partition of the smart card, the second subset of messages ordered in the message stream between the first interface switch indicator and a second interface switch indicator; and in response to detecting the second interface switch indicator in the message stream: transmitting a third subset of messages of the plurality of messages to the first logical partition of the smart card, the third subset of messages ordered in the message stream between the second interface switch indicator and a third interface switch indicator.

18. A method comprising: receiving a message stream comprising a plurality of messages and interface switch indicators; transmitting a first subset of messages of the plurality of messages to a first logical partition of a smart card, the first subset of messages ordered in the message stream before a first interface switch indicator; in response to detecting the first interface switch indicator in the message stream: transmitting a second subset of messages of the plurality of messages to a second logical partition of the smart card, the second subset of messages ordered in the message stream between the first interface switch indicator and a second interface switch indicator; and in response to detecting the second interface switch indicator in the message stream: transmitting a third subset of messages of the plurality of messages to the first logical partition of the smart card, the third subset of messages ordered in the message stream between the second interface switch indicator and a third interface switch indicator.

Citation Information

Patent Citations

  • Number switching method and system as well as intelligent card

    CN101977372A

  • Intelligent card adaptor, intelligent card detection system and intelligent card detection method

    CN103049362A