ROUTER

DE602023015158T2Active Publication Date: 2026-04-15STMICROELECTRONICS BELGIUM +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-05-04
Publication Date
2026-04-15

AI Technical Summary

Technical Problem

Existing electronic devices face challenges in protecting internal data exchange and minimizing device size while integrating secure communications between different functionalities, particularly in complex systems like mobile phones and tablets.

Method used

Implementing a secure element and a router within the electronic device that can be put into a secure mode, requiring authentication for access to data, and managing internal and external communications, with the router adapting protocols and applying security policies.

Benefits of technology

Enhances data protection and minimizes device size by ensuring secure data exchange and authentication, adding an additional layer of security to internal and external communications.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] This description relates generally to electronic systems and devices, and more specifically to the protection of data of a user using such an electronic system or device. Previous technique

[0002] Complex electronic devices, such as mobile phones, tablets, computers, etc., are increasingly incorporating more functionalities and enabling the implementation of digital services to better integrate into daily life. To implement these functionalities, these devices may incorporate electronic components specific to these functions and adapted to exchange data with each other. This data may include private or sensitive information.

[0003] Integrating new electronic components, for example to improve security or to add new features, involves increasing the power and surface area occupied by chips used in these electronic devices.

[0004] It would be desirable to be able to improve, at least in part, certain aspects of access to and / or protection of data exchanged within the same electronic system or device, and to minimize the size of electronic devices. Summary of the invention

[0005] There is a need for electronic systems or devices in which internal data exchange is better protected, and meets certain standards.

[0006] There is a need for electronic systems or devices in which the functionalities of some of their electronic components are integrated into their main chip in order to minimize the surface area occupied by the electronic components used in these electronic systems and devices.

[0007] There is a need to establish secure communications between different parts of the same chip related to different functionalities, for example for troubleshooting purposes.

[0008] There is a need for electronic systems or devices including a router in which internal data exchange is better protected.

[0009] There is a need for electronic systems or devices that also include a secure element in which the internal exchange of data is better protected.

[0010] An embodiment overcomes all or part of the drawbacks of known electronic systems or devices.

[0011] An embodiment provides for a method of communicating, to a third module of a first electronic device, first data exchanged between a first module of the first electronic device and a second module, the third module being different from the first and second modules, the first device comprising at least one secure element and a router transmitting the first data from the first module to the second module, the router being adapted to be put into a secure mode in which, when the third module requests access to the first data, an authentication method is implemented to verify whether the third module is authorized or not to have access to the first data.

[0012] Another embodiment provides for an electronic device comprising at least: a first electronic module; a secure element; a router exchanging initial data between the first module and a second module; and a third module different from the first and second modules, the router being adapted to be put into a secure mode in which, when the third-party module requests access to the first data, an authentication process is implemented to verify whether the third-party module is authorized or not to have access to the first data.

[0013] According to one embodiment, during the implementation of the authentication process the first data is stored in the secure element or in the router.

[0014] According to one embodiment, during their storage, the initial data is at least partially visible to the third-party module.

[0015] According to one embodiment, the authentication process is implemented by the router.

[0016] According to one embodiment, in which the authentication process is implemented by the secure element.

[0017] According to one embodiment, the authentication process allows authentication, in addition to the third-party module, of the first module, the second module, or the user of the first device.

[0018] According to one embodiment, the authentication process is implemented via an external server.

[0019] According to one embodiment, the authentication process includes the implementation of several secondary rules.

[0020] According to one embodiment, the router is adapted to request permission to be in secure mode.

[0021] According to one embodiment, the router is adapted to exit secure mode upon receipt of a particular instruction.

[0022] According to one embodiment, the specific command originates from the secured element.

[0023] According to one embodiment, the router includes a series of rules concerning the security policy of communications of the first device.

[0024] According to one embodiment, the secure element transmits said series of rules to said router.

[0025] According to one embodiment, the second module is part of the first electronic device.

[0026] According to one embodiment, the second module is part of a second electronic device, different from the first electronic device.

[0027] According to one embodiment, the router is integrated into a chip implementing the first module and / or the third module. Brief description of the drawings

[0028] These features and advantages, as well as others, will be described in detail in the following description of particular embodiments, given by way of non-limiting example, in relation to the attached figures, among which: there figure 1 represents, very schematically and in block form, an example of an electronic device that can implement the embodiments of figures 5 to 8 ; there figure 2 represents, very schematically and in block form, a more detailed example of a device of the figure 1 ; there figure 3 represents, very schematically and in block form, another more detailed example of a device of the figure 1 ; there figure 4 represents, very schematically and in block form, another more detailed example of a device of the figure 1 ; there figure 5 represents a block diagram illustrating a method of implementing an internal communication process within the device of the figure 1; there figure 6 represents a block diagram illustrating a method of implementing an internal communication process within the device of the figure 1 ; there figure 7 represents a block diagram illustrating another way of implementing an internal communication process within the device of the figure 1 ; and the figure 8 represents a block diagram illustrating another way of implementing an internal communication process within the device of the figure 1 . Description of the implementation methods

[0029] The same elements have been designated by the same reference numerals in the different figures. In particular, structural and / or functional elements common to the different embodiments may have the same reference numerals and may have identical structural, dimensional and material properties.

[0030] For the sake of clarity, only the steps and elements necessary for understanding the described embodiments have been shown and are detailed. In particular, the various internal communication protocols used by the different modules of an electronic device are not detailed here, as the described embodiments are designed to be implemented with standard communication protocols.

[0031] Unless otherwise specified, when referring to two connected elements, this means directly connected without any intermediate elements other than conductors, and when referring to two coupled elements, this means that these two elements can be connected or linked through one or more other elements.

[0032] In the description that follows, when referring to absolute positional qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or relative positional qualifiers, such as the terms "above", "below", "superior", "inferior", etc., or to orientational qualifiers, such as the terms "horizontal", "vertical", etc., unless otherwise specified, it refers to the orientation of the figures.

[0033] Unless otherwise specified, the expressions "approximately", "roughly", "about", and "on the order of" mean within 10%, preferably within 5%.

[0034] There figure 1 represents, very schematically and in block form, an embodiment of an electronic device 100 (DEVICE) to which the communication processes described in relation to the can be applied figures 5 to 8 .

[0035] Device 100 includes, at a minimum: a secure element 101 (SE); a router 102 (ROUTER); and at least two other electronic modules.

[0036] The secure element 101 is an electronic device suitable for processing sensitive and / or confidential data and is considered reliable. The secure element 101 itself comprises, for example, a processor, one or more memories, and encrypted data processing modules, such as a data encryption module and / or a data decryption module. The secure element 101 is adapted to communicate with the other electronic modules of device 100 via the router 102. In one embodiment, the secure element 101 may have a direct communication line with one or more other components / modules of device 100. For example, this direct communication line may be implemented using Binding Commands, a communication bus, and / or shared memory.

[0037] Router 102 is an electronic device adapted to manage all or part of the internal communications of device 100, preferably all internal communications, but which can also manage at least some of the external communications of device 100. Internal communications of device 100 are defined here as communications, that is, the exchange of data and instructions, between electronic modules that are internal to device 100. External communications of device 100 are, in this case, communications, that is, the exchange of data and / or instructions, carried out with one or more components of device 100 and one or more devices external to device 100. Router 102 can also be adapted to manage internal communications of device 100 whose data may be intended for external communications.As an example, router 102 can be adapted to perform data type conversions, such as adapting data adapted to a first protocol into data adapted to a second protocol different from the first protocol.

[0038] During internal communication, router 102's role is to receive all data and / or instructions emitted by a first electronic module of electronic device 100, and then transmit them to a second electronic module of electronic device 100. To do this, router 102 relies, for example: on information contained in the data and / or instructions to be transmitted; on data relating to transmission and / or data relating to reception provided by the first module, and, where applicable, the second module; and / or on data contained in an internal lookup table.

[0039] During external communication, router 102 has the role of receiving all data and / or instructions issued by an external device, and addressing them to one or more internal modules of device 100, or, conversely, of receiving all data and / or instructions issued by an internal device of device 100, and addressing them to a device external to device 100. For this, router 102 relies, for example, on information contained in the data and / or instructions to be transmitted, or, for example, on data provided by the external electronic device.

[0040] Furthermore, in one embodiment, router 102 is adapted to allow certain internal modules of device 100 to access all or part of the data exchanged in an internal or external communication of which it is not a part. In other words, router 102 can allow an internal module of device 100 to become aware of data of which it is not the primary recipient. In this case, the module is said to log itself (communication log). In the following description, the internal module of device 100 that wishes to access all or part of the data of a communication of which it is not a primary party is called a third-party module. Put another way, a third-party module to a communication is a module other than the module initiating the communication and the module receiving the communication.

[0041] In one embodiment, when a third-party module seeks access to data from a communication, router 102, when in secure mode, can apply specific processing to certain communications. More specifically, router 102 can store, or have another component / module store, all or part of the data, and require the third-party module to authenticate itself before granting, or denying, access to all or part of this data. The communication can be either internal or external. The authentication of the third-party module can be implemented by router 102 itself, or, in a variant of the embodiment, by the secure element 101. Similarly, the communication data can be stored by router 102 or by the secure element 101 before the third-party module is authenticated.According to one embodiment, this secure mode can be activated by an authentication process. This secure mode is described in more detail in relation to the [reference to relevant section]. figures 5 to 8 .

[0042] In this description, a module is defined as a set of circuits and / or components related to one or more functionalities of the electronic device. Examples of these electronic modules include a Universal Integrated Circuit Card (UICC) 103 (UICC), one or more memory modules 104 (MEM), and a processor or microprocessor 105 (CPU). These modules are typical electronic modules of an electronic device and enable it to implement one or more functionalities. The device 100 is, for example, a cordless phone, a smartphone, a connected object, a tablet, etc. Alternatively, the term "module" can also refer to a software entity implemented by the electronic device.

[0043] According to one embodiment, the router 102 is a module independent of the other modules of the electronic device 100, that is to say that the router 102 is not grouped with any other module of the device 100. In other words, the router 102 can be physically isolated from the other modules, for example by being implemented by a single chip, and / or isolated by software, for example by being protected from the other software implemented by the device 100.

[0044] In another embodiment, the router 102 can be grouped with one or more modules of the device 100. In other words, the router 102 can be implemented physically and / or implemented in software in a bundled manner with other modules. As a first example, the router 102 can be implemented on the same chip as one or more other modules of the electronic device 100, or it can be integrated or embedded on a chip implementing one or more other modules of the electronic device 100. As a second example, the router 102 can be implemented using the same operating system as one or more other modules of the device 100.

[0045] THE figures 2 , 3, and 4 illustrate more detailed examples of electronic devices of the type shown in device 100. figures 5 to 8illustrate methods of implementing secure communication processes that can be implemented by device 100 or one of the devices described in relation to the figures 2 , 3, or 4 .

[0046] There figure 2 represents, very schematically and in block form, an example of the realization of an electronic device 200 of the type of the electronic device 100 described in relation to the figure 1 .

[0047] Device 200 includes: a secure element 201 (SE); a router 202 (ROUTER); and at least two electronic modules including a universal integrated circuit card 203 (UICC), and a processor 204 (APP CPU).

[0048] Secure element 201 is of the same type as secure element 101 described in relation to the figure 1For example, the secure element 201 is adapted to communicate with the router 202 via a data bus B1 suitable for Single Wire Protocol (SWP) communications or via a memory suitable for Inter-Process Call (IPC) communications. Alternatively, the secure element 201 is adapted to communicate directly with the processor 204 via a data bus B2 suitable for Inter-Integrated Circuit (I2C) or Serial Peripheral Interface (SPI) communications.

[0049] Router 202 is of the same type as router 102 described in relation to the figure 1Router 202 is particularly well-suited for managing some of the internal communications within device 200 and for handling Near Field Communication (NFC) NFC1 communications of device 300. To this end, router 202 is designed to communicate with the secure element 201 via data bus B1, with the universal integrated circuit board 203 via data bus B3, and with the processor 204 via data bus B4. Data bus B3 is suitable for SWP communications. Data bus B4 can be of the same type as bus B2.

[0050] The universal integrated circuit card 203 is, for example, a SIM (subscriber identity / identification module) card that can be considered a secure element. As an example, the 203 card is adapted to communicate directly with the processor 204 via a B5 data bus suitable for ISO7816-type communications. The universal integrated circuit card 203 can be a removable physical card or an integrated card (eUICC).

[0051] The 204 processor is a processor suitable for running one or more applications, for example two applications 2041 (App1) and 2042 (App2) in the example shown in figure 2To this end, the 204 processor is designed to implement several software programs that serve as interfaces between applications 2041 and 2042 and the other modules of device 300. These interface programs include, for example, low-level software 2043 and API conversion software 2044. The interface programs are designed to translate commands sent by the applications into commands understandable by the other modules of device 300. For example, API conversion software 2044 translates a command from an application into several commands, each destined for a module of device 300. Similarly, API conversion software 2043 converts commands intended for a module of device 300 into a command understandable by that module. Other architectures are possible, and the example described here is not exhaustive.The B2, B4 and B5 data buses are suitable for communicating with interface software, for example low-level software 2043, of processor 204.

[0052] There figure 3 represents, very schematically and in block form, an embodiment of an electronic device 300 (DEVICE) of the type of the electronic device 100 described in relation to the figure 1 .

[0053] Device 300 includes: a 301 router (VNP ROUTER); a 302 modem (MODEM); a first host software 303 (HOST 1) implementing at least one 3031 application (App1); and a second host software 304 (HOST 2) implementing at least one 3032 application (App2).

[0054] Router 301 is a router that manages all internal communications of device 300, and also at least some of the external communications of device 300. As an example, router 301 allows wired or wireless communication with an external device 310 (OTHER DEVICE).

[0055] The 302 modem, for example, is a module that allows the 300 device to connect to a communication network, such as the telephone network or the internet. The 302 modem includes a security component, such as a universal integrated circuit card, that allows it to obtain connection authorizations from that communication network.

[0056] The first and second host software 303 and 304 are, for example, processors or parts of processors dedicated to one or more application or groups of applications. figure 3 , each host software 303, 304 is dedicated to one application.

[0057] There figure 4represents, very schematically and in block form, an embodiment of an electronic device 350 (DEVICE) of the type of the electronic device 100 described in relation to the figure 1 .

[0058] Device 350 includes: a router 351 (ROUTER); a resistive element 352 (TRE) (Tamper Resistant Element) implementing at least one application 3521 (VPP App); a first host software 353 (HOST 1) implementing at least one application 3531 (App1); a second host software 354 (HOST 2) implementing at least one application 3532 (App2); one or more other electronic components 356 (OTHER).

[0059] Router 351 is a router that manages all internal communications of device 350 to or from the resistive element 352. Router 351 can also manage communications to or from other electronic components 356.

[0060] The 352 hard drive element is a secure component suitable for implementing applications, such as application 3521. The 352 hard drive element can be formed on a separate chip from the router or be directly integrated with the router 351. When the 352 hard drive element is integrated with the router 351, communication between these two components can be implemented via one or more buses and / or one or more internal memories of the router 351. As an example, the 352 hard drive element can be integrated into another component of the device 350, such as a processor; in this case, all communication to and from the 352 hard drive element will use the router 351.

[0061] The 352 resilient element, for example, includes its own memory (one or more), and the 3521 application can be stored in one of its memories. The 352 resilient element is also capable of implementing multiple applications of the 3521 type (VPP App). Several implementations are possible; one of them may be based on storing application data in internal memory or in memories external to the 352 resilient element. In the case of external storage, the data stored in one or more external memories can be protected by the resilient element, for example, using an encryption algorithm. Another implementation may involve using both internal and external memory storage.

[0062] The first and second host software programs 354 and 355, and the applications 3541 and 3551 are of the type of host software and applications described in relation to the figure 3 .

[0063] There figure 5 is a block diagram illustrating a method of implementing a secure communication process, during which a third-party module attempts to access data from a communication. The communication process implements a router 401 (ROUTER) and a secure element 402 (SE) of the same electronic device 403. The device 403 is of the type of device 100 described in relation to the figure 1 , and thus router 401 and secure element 402 are of the type of router 102 and secure element 101.

[0064] At step 404 (block "Log ON"), the 401 router enters secure mode, in which authentication is requested from any third-party module seeking access to communication data. For example, secure mode is activated upon receiving a command from the secured element or following a specific event, such as the entire device switching to a particular operating mode, like a test mode.

[0065] In one embodiment, router 401 can request authorization to enter secure mode. This authorization can originate from the secure element 401, the user of device 403, or an external server. In another example, the authorization can originate from an authentication process that recognizes the user of electronic device 403; this authentication process could, for example, require a password or biometric authentication. The authorization obtained by router 401 can, in one example, be verified by router 401 or by the secure element 402.

[0066] At step 405 (the "Comm START" block), following step 404, communication begins. This communication can be internal to the 403 device or external between the 403 device and another electronic device. In practice, the 401 router begins receiving DATA4 data from a communication between a first module and a second module. The first module is part of the 403 electronic device, and the second module can be internal to the 403 electronic device or external to the 403 device. For example, the communication could be between two modules of the 403 device, between a module of the 403 device and a device external to the 403 device, or even between the 402 secure element and another module of the 403 device or an external device.

[0067] Furthermore, at step 405, a third module, that is to say a module different from the first and second modules, requests access to all or part of the DATA4 communication data.

[0068] Router 401 performs its function and transfers the DATA4 data from the first module to the second module. However, since router 401 is in secure mode and a third-party module requests access to the DATA4 data, the DATA4 data is also copied and transferred to the secure 402 element.

[0069] At step 406 (block "HIDE DATA"), the secure element 402 receives the DATA4 data and stores it securely. The DATA4 data is therefore not made accessible to the third-party module by the router 401. In one embodiment, the DATA4 data is stored securely by the router 401 itself. For example, if the storage capacity of the secure element 402, or of the router 401 if applicable, becomes full, the router 401 can be adapted to detect this and emit an error signal.

[0070] At a 407 step (block "AUT?"), the secure element starts an authentication process of the third-party module to check if the DATA4 data can be transmitted to it by the element storing it, i.e. the router 401 or the secure element 402.

[0071] According to a first example, the authentication process is intended to directly authenticate the third-party module, but also the first module and / or the second module.

[0072] According to a second example, the authentication process is intended to authenticate the third-party module by authenticating the user of the 403 device, for example by requesting a PIN code.

[0073] According to a third example, the authentication process is carried out via a service using an external server that might want to have access to the DATA4 data.

[0074] According to a fourth example, the authentication process includes the implementation of several secondary rules. A secondary rule could be the implementation of an authentication process requested by a module of the 403 device or by software or an application implemented by the 403 device.

[0075] Furthermore, and depending on the variant, the DATA4 data may be fully or partially visible to the third-party module during the authentication process. In one example, the DATA4 data is fully visible to the third-party module during authentication. In another example, only a portion of the DATA4 data is visible to the third-party module, for example, the DATA4 data headers. In a third example, only the form, or configuration, of the DATA4 data is visible to the third-party module, for example, to recognize whether the DATA4 data relates to sensitive communication, i.e., communication whose data is sensitive and must be protected, such as a bank transaction or user identification for SIM card use (subscriber identity / identification module).For example, if a user submits their PIN to start using a SIM card, the information related to that PIN is anonymized.

[0076] If the authentication result is correct (output Y of the "AUT?" block), the next step is a 408 step ("Continue" block), otherwise (output N of the "AUT?" block), the next step is a 409 step ("Error" block).

[0077] At step 408, the third-party module is authorized to access all or part of the DATA4 data. To do this, the DATA4 data is returned to the router. Alternatively, if the DATA4 data is stored by router 401, then at this step, the DATA4 data is made accessible to the third-party module.

[0078] At step 409, communication is not authorized by the secure element 402. In this case, the DATA4 data can be erased so that the third-party module never has access to it. In one embodiment, an error counter can be implemented to give the third-party module, or the user, multiple attempts to authenticate. For example, the counter can count the number of attempts, and if this number exceeds a limit, the ability to authenticate is disabled for a predetermined period. In another example, if the counter reaches a limit, the DATA4 data is erased, but as long as the counter value is below the limit, the DATA4 data is retained.

[0079] At step 410 (the "EXECUTE Log" block), following step 408, router 401 transmits the DATA4 data to the third-party module. For example, authentication performed by the secure element 402 grants authorization to make all or part of the DATA4 data accessible. Alternatively, router 401 may periodically request authentication during the communication process.

[0080] At step 411 (the "Log OFF" block), following step 410, router 401 exits its secure mode. For example, router 401 might exit this mode upon receiving a command from the secure element or following a specific event, such as device 403 switching to a different operating mode.

[0081] One advantage of this embodiment is that it allows for an additional level of protection to be added to the internal and external communications of an electronic device.

[0082] There figure 6 is a block diagram illustrating another way of implementing a secure communication process using a router 401 (ROUTER) and a secure element 402 (SE) of the same electronic device 403 of the figure 5 .

[0083] The implementation method of the secure communication process described in relation to the figure 5 share common elements with the secure communication process described in relation to the figure 5 In particular, in the process of the figure 6 , third-party module authentication is implemented by router 401, and not by secure element 402.

[0084] Thus, the process of figure 6 includes steps common to the process of the figure 5 These common steps are not described again here. These common steps are: step 404 (block "Log ON"); step 405 (block "Comm Start"); step 406 (block "HIDE DATA"); step 408 (block "Continue"); step 409 (block "Error"); step 410 (block "EXECUTE Log"); and step 411 (block "Log Off").

[0085] As in figure 5 The process begins with step 404, which is followed by step 405.

[0086] Step 405 is followed by step 501 (the "Auth?" block) during which router 401 initiates an authentication process to authenticate the third-party module. In one example, the authentication process directly authenticates the third-party module, as well as the first and / or second module. In another example, the authentication process directly authenticates the user of device 403, for example, by requesting a PIN. In a third example, the authentication process authenticates the third-party module via a service using an external server.

[0087] The AUT5 information regarding the success, or failure, of the authentication process is sent to the secure element 402, if it is indeed the one storing the DATA4 data.

[0088] At step 502 (block "Result Aut?"), the secure element 402 receives the AUT5 information and deduces whether authentication was successful or not. If the AUT5 information indicates that authentication is correct (output Y of the block "Result Aut?"), the next step is step 408; otherwise (output N of the block "Result Aut?"), the next step is step 409 (block "Error").

[0089] Step 408 is then followed by step 410, and then by step 411.

[0090] There figure 7 is a block diagram illustrating another implementation method of a secure communication process, during which a third-party module seeks access to data from a communication. The communication process implements a router 601 (ROUTER) and a secure element 602 (SE) of the same electronic device 603 of the figure 7 Device 603 is of the type of device 100 described in relation to the figure 1, and thus router 601 and secure element 602 are, respectively, of the type of router 102 and secure element 101.

[0091] At a 604 step (block "POLICY"), the secure element 602 has at its disposal a series of POL6 rules concerning a policy for protecting internal communications, and optionally external communications, of device 101. This series of POL6 rules is intended to be implemented by router 601 when a third-party module requests access to data from a communication.

[0092] Here, a rule is an instruction that the router must implement in a specific situation.

[0093] The POL6 rule set can include different types of rules. For example, a rule in the POL6 rule set might prohibit a particular third-party module, or any third-party module, from accessing the data of a specific communication, such as a communication of a certain type. Another rule in the POL6 rule set might allow only the transmission of all or part of the data of a specific communication to a third-party module. A third rule in the POL6 rule set might require the third-party module to authenticate itself in various ways to access all or part of the data of a communication. Other rules are described below, and still more rules can be devised by a person skilled in the art without demonstrating inventiveness.

[0094] The secure element 601 can obtain the POL6 rule set in several ways. In one example, the secure element 601 can create the POL6 rule set from instructions provided by the manufacturer of the device 603, by the user of the device 603, via an external server (which could authorize communication directly or through another authentication system), and / or by the software and applications implemented by the device 603. In this case, the secure element 602 can update the rule set with each new instruction received. In a second example, the POL6 rule set is stored in the secure element 601 without the latter being able to modify it.

[0095] In one embodiment, when applications implemented by device 603 generate rules within the rule series, different rules may be applied depending on which application is started or running. These rules may be supplemented by rules provided by the operating system of device 603 and / or by rules provided by protection or security software for device 603. Protection or security software may, for example, provide rules preventing the implementation of rules from a specific application that it deems untrustworthy, or forcing the concealment of certain sensitive data.

[0096] In another embodiment, the POL6 rules can themselves be protected by the 602 secure element to guarantee their integrity. To this end, the 602 secure element can apply a signature process to the POL6 rules.

[0097] At step 605 (the "Store Policy" block), following step 604, router 601 receives the POL6 rule set from the secure element 602 and stores it. With this rule set in memory, router 601 can implement it when it receives data for internal or external communication from device 603.

[0098] At step 606 (the "Comm Start" block), following step 605, communication begins. This communication can be internal to device 603 or external between device 603 and another electronic device. In practice, router 601 begins receiving data from a first module with the instruction to forward it to a second module. For example, the first module is an internal module of electronic device 603, and the second module can be either an internal module of the electronic device or an external electronic device.

[0099] Furthermore, at step 606, a third-party module requests access to the data exchanged during the communication.

[0100] At step 607 (the "Policy Check" block), router 601 consults the POL6 rule series to determine if a rule should be implemented. If no rule is to be applied (output Y of the "Policy Check" block), the next step is step 608 (the "EXECUTE Comm" block); otherwise (output N of the "Policy Check" block), the next step is step 609 (the "Action" block).

[0101] At step 608, following step 607, router 601 transmits the data to the third-party module without any further action being taken.

[0102] In step 609, following step 607, a rule from the POL6 rule series corresponds to the communication situation. Router 601 then executes the rule.

[0103] For example, a rule might require that the transfer of data to a third-party module from a communication originating from a specific module of the 603 device or from a device external to the 603 device be preceded by an authentication process, for example, performed by the 601 router or the 602 secure element. For example, a rule might prohibit the transmission to a third-party module of any data from a communication originating from a specific module of the 603 device or from a device external to the 603 device. For example, a rule might require that all data of a certain type, for example, data with a specific format or header, be encrypted.

[0104] In cases where some of the rules are provided by applications implemented by device 603, the rules provided by these applications may relate to the type of authentication process used to grant or deny communication.

[0105] Furthermore, if the rules followed for a given communication are provided by first and second running applications, then the rules provided by both applications can be used in parallel. As a practical example, if first application A requires the presentation of a password to authorize the transmission of DATA-A, which is part of the DATA data in a communication, and application B requires password authentication via an external server to authorize the transmission of DATA-B, which is also part of the DATA data, a user providing only the password will only see the transmission of DATA-A implemented, and not the transmission of DATA-B. If the 603 device is equipped with a screen, the user could, for example, see which rule was implemented and which rule could not be implemented.

[0106] The method of implementation of the figure 7 can be combined with the implementation methods of Figures 5 And 6 This is described in relation to the figure 8 .

[0107] There figure 8 is a block diagram illustrating another implementation method for a secure communication process using a router and a secure element of the same electronic device. The device is of the type of device 100 described in relation to the figure 1 , and thus the router and the secure element are, respectively, of type router 102 and secure element 101.

[0108] The router described here includes a set of rules of the type of the POL6 rule set described in relation to the figure 7 The secure element provided this set of rules to the router as described in relation to the figure 7 .

[0109] At step 701 (block "Router Log ON"), the router is put into a secure operating mode. This step is identical to step 404 described in relation to the figure 5 .

[0110] At step 702 (the "Comm Start" block), following step 701, communication begins. This communication can be internal to the device or external between the device and another electronic device. In practice, the router begins receiving data with instructions to forward it to a module within the device or to another electronic device external to the device.

[0111] Furthermore, at step 702, a third-party module requests access to all or part of the communication data.

[0112] At step 703 (the "Auth & Policy Check" block), following step 702, the data and communication instructions are subjected to the series of rules stored in the router and to the authentication process that can be implemented by the router's secure mode. In a first example, the router initially implements the series of rules as described in relation to the figure 7 , then implements authentication according to one of the variants presented in relation to the figure 5 or the figure 6 According to a second example, the router first implements authentication according to one of the variants presented in relation to the figure 5 or the figure 6 , then implements the series of rules as described in relation to the figure 7 .

[0113] If the third-party module is allowed to have access to the communication data (output Y of the "Auth & Policy Check" block) the next step is a 704 step (block "EXECUTE Comm"), otherwise (output N of the "Auth & Policy check" block) the next step is a 705 step (block "Action").

[0114] At step 704, following step 703, the router transmits the data to the third-party module without any further action being taken.

[0115] At step 705, following step 703, the instruction that the router is trying to implement falls under one of the rules in the rule series, and / or the authentication process failed. The router then executes the rule and / or blocks the communication.

[0116] Various embodiments and variations have been described. A person skilled in the art will understand that some features of these various embodiments and variations could be combined, and other variations will become apparent to a person skilled in the art.

[0117] In particular, different methods of implementing DATA4 data storage can be considered.

[0118] In one example, the module storing the DATA4 data—that is, the router or the secure element—can use limited memory. If the memory is full, an alert message is sent, and the module decides to free up space. Alternatively, the memory can be circular, meaning that once it is full, it deletes the oldest data to free up space. The module can also store only DATA4 data of a certain type, sorting the DATA4 data to store only the relevant data and avoid double storage. This type of storage is called aggregated storage.

[0119] According to a second example, the module storing the DATA4 data can decide to store this data in another module of the device, having previously applied the series of rules, if applicable.

[0120] Finally, the practical implementation of the described methods and variants is within the reach of the person in the trade, based on the functional indications given above.

Claims

1. Method of communication, to a third party module of a first electronic device, of first data (DATA4) exchanged between a first module of the first electronic device (100; 200; 300) and a second module, the third party module being different from the first module and from the second module, the first device comprising at least a secure element (101; 201; 402) and a router (102; 202; 401) transmitting the first data (DATA4) from the first module to the second module, the router (102; 202; 401) being adapted to being set to a secure mode in which, when the third party module requests access to the first data (DATA4), an authentication method is implemented to verify whether or not the third party module is authorized access to the first data (DATA4).

2. Electronic device comprising at least: - a first electronic module; - a secure element; - a router (102; 202; 401; 601) exchanging first data (DATA4) between the first module and a second module; and - a third party module different from the first module and from the second module, the router (102; 202; 401; 601) being adapted to being set to a secure mode in which, when the third party module requests access to the first data (DATA4), an authentication method is implemented to verify whether or not the third party module is authorized access to the first data (DATA4).

3. Method according to claim 1, or device according to claim 2, wherein during the implementation of the authentication method, the first data (DATA4) are stored in the secure element (101; 201; 402) or in the router (102; 202; 401).

4. Method or device according to claim 3, wherein during their storage, the first data (DATA4) are at least partially visible by the third party module.

5. Method according to any of claims 1, 3 or 4, or device according to any of claims 2 to 4, wherein the authentication method is implemented by the router (102; 202; 401).

6. Method according to any of claims 1, 3 or 4, or device according to any of claims 2 to 4, wherein the authentication method is implemented by the secure element.

7. Method according to any of claims 1, 3 to 6, or device according to any of claims 2 to 6, wherein the authentication method enables to authenticate, in addition to the third party module, the first module, the second module, or the user of the first device.

8. Method according to any of claims 1, 3 to 7, or device according to any of claims 2 to 7, wherein the authentication method is implemented via an external server.

9. Method according to any of claims 1, 3 to 8, or device according to any of claims 2 to 8, wherein the authentication method comprises the implementation of a plurality of secondary rules.

10. Method according to claims 1, 3 to 9, or device according to any of claims 2 to 9, wherein the router (102, 202; 401) is adapted to requesting authorization to be in the secure mode (101; 201; 402).

11. Method according to any of claims 1, 3 to 10, or device according to any of claims 2 to 10, wherein the router (102; 202; 401; 601) is adapted to leaving the secure mode on reception of a specific instruction.

12. Method or device according to claim 11, wherein the specific instruction originates from the secure element.

13. Method according to any of claims 1, 3 to 12 or device according to any of claims 3 to 12, wherein the router (102; 202; 401; 601) comprises a series of rules concerning the communications security policy of the first device.

14. Method or device according to claim 13, wherein the secure element (101; 201; 402; 602) transmits said series of rules to said router (102; 202; 401; 601).

15. Method according to any of claims 1, 3 to 14, or device according to any of claims 2 to 14, wherein the second module forms part of the first electronic device.

16. Method according to any of claims 1, 3 to 14, or device according to any of claims 2 to 14, wherein the second module forms part of a second electronic device, different from the first electronic device.

17. Method according to any of claims 1, 3 to 16, or device according to any of claims 2 to 16, wherein the router (102; 202; 401; 601) is incorporated in a chip implementing the first module (100; 200; 300) and / or the third party module.