Router
By incorporating a router and secure element in electronic devices, secure data exchange is facilitated within a single chip, addressing the need for enhanced protection and size reduction while ensuring secure communication.
Patent Information
- Application Number
- FR2022004563
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-05-13
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2042-05-13
AI Technical Summary
There is a need for electronic systems or devices that better protect internal data exchange, minimize device size, and ensure secure communication between different functionalities within a chip, while integrating secure elements to enhance data protection.
The implementation of a router and a secure element within an electronic device that can be put into a secure mode, requiring authentication for access to data, and enforcing communication security policies to manage and protect data exchange.
This approach adds an additional level of protection to internal and external communications, ensuring secure data exchange and minimizing device size by integrating functionalities into a single chip.
Smart Images

Figure 00000021_0000 
Figure 00000021_0001 
Figure 00000022_0000
Abstract
Description
Title of the invention: Router technical field
[0001] This description relates generally to electronic systems and devices, and more particularly to the protection of the data of a user using such an electronic system or device. Previous technique
[0002] Complex electronic devices, such as mobile phones, tablets, computers, etc., are increasingly incorporating more functionalities over time, enabling the implementation of digital services to better integrate into daily life. To implement these functionalities, these devices may incorporate electronic components specific to these functionalities and adapted to exchange data with each other. This data may include private or sensitive information.
[0003] Integrating new electronic components, for example to improve security or to add new functionalities, involves increasing the power and surface area occupied by chips used in these electronic devices.
[0004] It would be desirable to be able to improve, at least in part, certain aspects of access to and / or protection of data exchanged within the same electronic system or device, and to minimize the size of the electronic devices. Summary of the invention
[0005] There is a need for electronic systems or devices in which the internal exchange of data is better protected, and meets certain standards.
[0006] There is a need for electronic systems or devices in which the functionalities of some of their electronic components are integrated into their main chip in order to minimize the surface area occupied by the electronic components used in these electronic systems and devices.
[0007] There is a need to establish secure communications between different parts of the same chip related to different functionalities, for example for troubleshooting purposes.
[0008] There is a need for electronic systems or devices comprising a router in which the internal exchange of data is better protected.
[0009] There is a need for electronic systems or devices comprising, in addition, a secure element in which the internal exchange of data is better protected.
[0010] An embodiment overcomes all or part of the drawbacks of the systems or dis- known electronic positives.
[0011] An embodiment provides for a method of communicating, to a third module of a first electronic device, first data exchanged between a first module of the first electronic device and a second module, the third module being different from the first module and the second module, the first device comprising at least one secure element and a router transmitting the first data from the first module to the second module, the router being adapted to be put into a secure mode in which, when the third module requests access to the first data, an authentication method is implemented to verify whether the third module is authorized or not to have access to the first data.
[0012] Another embodiment provides for an electronic device comprising at least - a first electronic module; - a secure element; - a router exchanging initial data between the first module and a second module; and - a third module different from the first and second modules, the router being adapted to be put into a secure mode in which, when the third module requests access to the first data, an authentication process is implemented to verify whether the third module is authorized or not to have access to the first data.
[0013] According to one embodiment, during the implementation of the authentication process the first data is stored in the secure element or in the router.
[0014] According to one embodiment, during their storage, the first data are at least partially visible to the third-party module.
[0015] According to one embodiment, the authentication process is implemented by the router.
[0016] According to one embodiment, in which the authentication process is implemented by the secure element.
[0017] According to one embodiment, the authentication process allows authentication, in addition to the third module, of the first module, the second module, or the user of the first device.
[0018] According to one embodiment, the authentication process is implemented via an external server.
[0019] According to one embodiment, the authentication process includes the implementation of several secondary rules.
[0020] According to one embodiment, the router is adapted to request permission for be in safe mode.
[0021] According to one embodiment, the router is adapted to exit secure mode upon receipt of a particular instruction.
[0022] According to one embodiment, the particular command comes from the secure element.
[0023] According to one embodiment, the router includes a series of rules concerning the communications security policy of the first device.
[0024] According to one embodiment, the secure element transmits said series of rules to said router.
[0025] According to one embodiment, the second module is part of the first electronic device.
[0026] According to one embodiment, the second module is part of a second electronic device, different from the first electronic device.
[0027] According to one embodiment, the router is integrated into a chip implementing the first module and / or the third module. Brief description of the drawings
[0028] These features and advantages, as well as others, will be described in detail in the following description of particular embodiments, given by way of non-limiting example, in relation to the accompanying figures, among which:
[0029] [Fig.1] represents, very schematically and in block form, an example of an electronic device that can implement the embodiments of figures 5 to 8;
[0030] [Fig.2] represents, very schematically and in block form, a more detailed example of a device of [Fig.1];
[0031] [Fig.3] represents, very schematically and in block form, another more detailed example of a device of [Fig.1];
[0032] [Fig.4] represents, very schematically and in block form, another more detailed example of a device of [Fig.1];
[0033] [Fig.5] represents a block diagram illustrating a method of implementing an internal communication process in the device of [Fig.1];
[0034] [Fig.6] represents a block diagram illustrating a method of implementing an internal communication process in the device of [Fig.1];
[0035] [Fig. 7] represents a block diagram illustrating another way of implementing an internal communication process in the device of [Fig. 1]; and
[0036] [Fig.8] represents a block diagram illustrating another way of implementing an internal communication process in the device of [Fig.1]. Description of the implementation methods
[0037] The same elements have been designated by the same reference numerals in the different figures. In particular, the structural and / or functional elements common to the different embodiments may have the same reference numerals and may have identical structural, dimensional and material properties.
[0038] For the sake of clarity, only the steps and elements useful for understanding the described embodiments have been shown and are detailed. In particular, the various internal communication protocols used by the different modules of an electronic device are not detailed here, as the described embodiments are adapted to be implemented with standard communication protocols.
[0039] Unless otherwise specified, when referring to two elements connected together, this means directly connected without intermediate elements other than conductors, and when referring to two elements connected (in English "coupled") together, this means that these two elements can be connected or linked through one or more other elements.
[0040] In the following description, when reference is made to absolute position qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or relative position qualifiers, such as the terms "above", "below", "superior", "inferior", etc., or to orientation qualifiers, such as the terms "horizontal", "vertical", etc., reference is made, unless otherwise specified, to the orientation of the figures.
[0041] Unless otherwise specified, the expressions "approximately", "roughly", and "in the order of" mean within 10%, preferably within 5%.
[0042] Fig. 1 represents, very schematically and in block form, an embodiment of an electronic device 100 (DEVICE) to which the communication methods described in relation to Figures 5 to 8 can be applied.
[0043] Device 100 comprises, at least: - a secure element 101 (SE); - a 102 router (ROUTER); and - at least two other electronic modules.
[0044] The secure element 101 is an electronic device adapted to handle sensitive and / or secret data and is considered reliable. The secure element 101 itself comprises, for example, a processor, one or more memories, and encrypted data processing modules, such as, for example, a data encryption module and / or a data decryption module. The secure element 101 is adapted to communicate with the other electronic modules of the device 100 via the router 102. In one embodiment, the secure element 101 may have a direct communication line with one or more other components / modules of the device 100. In one example, this direct communication line may be implemented by binding commands. Command), via a communication bus and / or via shared memory.
[0045] The router 102 is an electronic device adapted to manage all or part of the internal communications of the device 100, preferably all internal communications, but which can also manage at least part of the external communications of the device 100. Here, internal communications of the device 100 are defined as communications, that is, the exchange of data and instructions, between electronic modules that are internal to the device 100. External communications of the device 100 are, in this case, communications, that is, the exchange of data and / or instructions, carried out with one or more components of the device 100 and one or more devices external to the device 100. The router 102 can, moreover, be adapted to manage internal communications of the device 100 whose data may be intended for external communications.As an example, router 102 can be adapted to perform data type conversions, such as adapting data adapted to a first protocol into data adapted to a second protocol different from the first protocol.
[0046] During internal communication, the router 102 is responsible for receiving all data and / or instructions emitted by a first electronic module of the electronic device 100, and then transmitting them to a second electronic module of the electronic device 100. To do this, the router 102 relies, for example: - on information contained in the data and / or instructions to be transmitted; - on transmission and / or reception data provided by the first module, and, where applicable, the second module; and / or - on data contained in an internal lookup table.
[0047] During external communication, the router 102 has the role of receiving all the data and / or instructions emitted by an external device, and addressing them to one or more internal modules of the device 100, or, conversely, of receiving all the data and / or instructions emitted by an internal device of the device 100, and addressing them to a device external to the device 100. For this, the router 102 relies, for example, on information contained in the data and / or instructions to be transmitted, or, for example, on data provided by the external electronic device.
[0048] Furthermore, according to one embodiment, the router 102 is adapted to allow certain internal modules of the device 100 to access all or part of the data exchanged in an internal or external communication of which it is not a part. In other words, the router 102 can allow an internal module of the device 100 to become aware of data of which it is not the primary recipient. In this case, the module is said to log itself (communication log). In the following description, the internal module of the device 100 wishing to have access to all or part of the data in a communication of which it is not a primary participant. In other words, a third-party module in a communication is a module that is different from both the module initiating the communication and the module receiving the communication.
[0049] According to one embodiment, when a third-party module seeks access to data in a communication, router 102, when in secure mode, can apply specific processing to certain communications. More specifically, router 102 can store, or have another component / module store, all or part of the data, and require the third-party module to authenticate itself before granting, or denying, it access to all or part of this data. The communication can be either internal or external. The authentication of the third-party module can be implemented by router 102 itself, or, according to another embodiment, by the secure element 101. Similarly, the communication data can be stored by router 102 or by the secure element 101 before the authentication of the third-party module is performed.According to one embodiment, this secure mode can be activated by an authentication process. This secure mode is described in more detail with reference to Figures 5 to 8.
[0050] In this description, a module is defined as a set of circuits and / or components related to one or more functionalities of the electronic device. These one or more other electronic modules of the device are, for example, a Universal Integrated Circuit Card (UICC) 103 (UICC), one or more memories 104 (MEM), and a processor or microprocessor 105 (CPU). These modules are conventional electronic modules of an electronic device and enable it to implement one or more functionalities. The device 100 is, for example, a cordless phone, a smartphone, a connected object, a tablet, etc. In one variant, the term "module" can also refer to a software entity implemented by the electronic device.
[0051] According to one embodiment, the router 102 is a module independent of the other modules of the electronic device 100, that is to say that the router 102 is not grouped with any other module of the device 100. In other words, the router 102 can be physically isolated from the other modules, for example by being implemented by a single chip, and / or isolated by software, for example by being protected from the other software implemented by the device 100.
[0052] According to another embodiment, the router 102 can be grouped with one or more modules of the device 100. In other words, the router 102 can be implemented physically and / or implemented in software in a grouped manner with other modules. According to a first example, the router 102 can be implemented by the same chip as one or more other modules of the electronic device 100 or can be integrated or embedded in a chip implementing one or more other modules of the electronic device 100. According to a second example, the router 102 can be implemented by the same operating system as one or more other modules of the device 100.
[0053] Figures 2, 3, and 4 illustrate more detailed examples of electronic devices of the type of device 100. Figures 5 to 8 illustrate implementation methods of secure communication processes that can be implemented by device 100 or one of the devices described in relation to Figures 2, 3, or 4.
[0054] [Fig.2] represents, very schematically and in block form, an example of the realization of an electronic device 200 of the type of the electronic device 100 described in relation to [Fig.1].
[0055] Device 200 comprises: - a secure element 201 (SE); - a 202 router (ROUTER); and - at least two electronic modules including a universal integrated circuit board 203 (UICC), and a processor 204 (APP CPU).
[0056] The secure element 201 is of the same type as the secure element 101 described in relation to [Fig. 1]. For example, the secure element 201 is adapted to communicate with the router 202 via a data bus B1 adapted for Single Wire Protocol (SWP) communications or via a memory adapted for Inter-Process Call (IPC) communications. For example, the secure element 201 is adapted to communicate directly with the processor 204 via a data bus B2 adapted for Inter-Integrated Circuit (I2C) or Serial Peripheral Interface (SPI) communications.
[0057] Router 202 is of the same type as router 102 described in relation to [Fig. 1]. Router 202 is particularly suited to managing some of the internal communications of device 200 and to managing Near Field Communication (NFC) NFC1 of device 300. For this purpose, router 202 is adapted to communicate with the secure element 201 via data bus B1, with the universal integrated circuit board 203 via data bus B3, and with the processor 204 via data bus B4. Data bus B3 is suitable for SWP-type communications. Data bus B4 can be of the same type as bus B2.
[0058] The universal integrated circuit card 203 is, for example, a SIM (subscriber identity / identification module) card that can be considered a secure element. According to one example, the card 203 is adapted to communicate directly with the processor 204 via a B5 data bus adapted for ISO7816 type communications. The universal integrated circuit card 203 can be a removable physical card or an integrated card (eUICC).
[0059] The processor 204 is a processor adapted to implement one or more applications, for example, two applications 2041 (Appl) and 2042 (App2) in the example illustrated in [Fig. 2]. To this end, the processor 204 is adapted to implement several software programs that serve as interfaces between applications 2041 and 2042 and the other modules of the device 300. These interface software programs include, for example, low-level software 2043 and conversion software 2044 (API). The interface software programs are adapted to translate the commands sent by the applications into commands understandable by the other modules of the device 300. For example, the conversion software 2044 programs are programs that translate a command from an application into several commands, each intended for a module of the device 300.As an example, the 2043 low-level software is designed to convert commands intended for a module of the 300 device into a command understandable by that module. Other architectures are possible here, and the example described is not exhaustive. The B2, B4, and B5 data buses are designed to communicate with interface software, for example, the 2043 low-level software, of the 204 processor.
[0060] Fig. 3 represents, very schematically and in block form, an embodiment of an electronic device 300 (DEVICE) of the type of the electronic device 100 described in relation to Fig. 1.
[0061] Device 300 comprises: - a 301 router (VNP ROUTER); - a 302 modem (MODEM); - a first host software 303 (HOST 1) implementing at least one application 3031 (Appl); and - a second 304 host software (HOST 2) implementing at least one 3032 application (App2).
[0062] The router 301 is a router which manages all internal communications of the device 300, and also at least part of the external communications of the device 300. According to an example, the router 301 allows communication, wired or wireless, with an external device 310 (OTHER DEVICE).
[0063] The 302 modem is, for example, a module enabling the connection of the 300 device to a communication network, for example, the telephone network or the internet. The 302 modem includes a security element, for example, a universal integrated circuit card, enabling it to obtain connection authorizations to said communication network.
[0064] The first and second host software 303 and 304 are, for example, processors or parts of processors dedicated to one or more application or groups of applications. In [Fig. 3], each host software 303, 304 is dedicated to one application.
[0065] [Fig.4] represents, very schematically and in block form, an embodiment of an electronic device 350 (DEVICE) of the type of the electronic device 100 described in relation to [Fig.1].
[0066] Device 350 comprises: - a 351 router (ROUTER); - a 352 (TRE) (Tamper Resistant Element) implementing at least one 3521 (VPP App); - a first host software 353 (HOST 1) implementing at least one application 3531 (Appl); - a second host software 354 (HOST 2) implementing at least one application 3532 (App2); - one or more other electronic components 356 (OTHER).
[0067] The router 351 is a router that manages all internal communications of the device 350 to or from the resistive element 352. The router 351 can, in addition, manage communications to or from other electronic components 356.
[0068] The resistant element 352 is a secure element suitable for implementing applications, such as application 3521. The resistant element 352 can be formed on a chip separate from that of the router or be directly integrated with the router 351. In the case where the resistant element 352 is integrated into the router 351, communications between these two elements can be implemented by one or more buses and / or one or more internal memories of the router 351. By way of example, the resistant element 352 can be integrated into another component of the device 350, such as a processor; in this case, all communications to or from the resistant element 352 will use the router 351 to be implemented.
[0069] The resilient element 352 includes, for example, its own memory (one or more), and the application 3521 can be stored in one of its memories. The resilient element 352 is also capable of implementing several applications of the type of application 3521 (VPP App). Several implementations are possible; one of them may be based on storing application data in internal memory or in memories external to the resilient element 352. In the case of external storage, the data stored in one or more external memories can be protected by the resilient element, for example, using an encryption algorithm. Another implementation may include using both internal and external memory storage.
[0070] The first and second host software 354 and 355, and the applications 3541 and 3551 are of the type of host software and applications described in relation to [Fig.3].
[0071] Figure 5 is a block diagram illustrating an implementation of a secure communication method, during which a third-party module seeks access to data from a communication. The communication method implements a router 401 (ROUTER) and a secure element 402 (SE) of the same electronic device 403. The device 403 is of the type of device 100 described in relation to Figure 1, and thus the router 401 and the secure element 402 are of the type of router 102 and secure element 101.
[0072] At a 404 step (block "Log ON"), router 401 activates secure mode in which authentication is requested from a third-party module seeking access to communication data. For example, secure mode is activated upon receipt of a command from the secured element or following a specific event, such as the complete device switching to a particular operating mode, for example, a test mode.
[0073] In one embodiment, router 401 may request authorization to enter secure mode. This authorization may originate from the secure element 401, the user of device 403, or an external server. In another example, the authorization may originate from an authentication process that recognizes the user of electronic device 403; this authentication process may, for example, require a password or biometric authentication. The authorization obtained by router 401 may, in one example, be verified by router 401 or by the secure element 402.
[0074] At a step 405 (block "Comm START"), following step 404, communication begins. The communication may be internal to the device 403 or external between the device 403 and another electronic device. In practice, the router 401 begins receiving DATA4 data from a communication between a first module and a second module. The first module is part of the electronic device 403, and the second module may be internal to the electronic device 403 or external to the device 403. By way of example, the communication may be between two modules of the device 403, between a module of the device 403 and a device external to the device 403, or even between the secure element 402 and another module of the device 403 or an external device.
[0075] In addition, at step 405, a third module, that is to say a module different from the first and second modules, requests access to all or part of the DATA4 data of the communication.
[0076] Router 401 plays its role and transfers the DATA4 data from the first module to second module. But in addition, since router 401 is in secure mode and a third module requests access to DATA4 data, the DATA4 data is, furthermore, copied and transferred to the secure element 402.
[0077] At step 406 (block "HIDE DATA"), the secure element 402 receives the DATA4 data and stores it securely. The DATA4 data is therefore not made accessible to the third-party module by the router 401. In one embodiment, the DATA4 data is stored securely by the router 401 itself. For example, if the storage capacity of the secure element 402, or of the router 401 as the case may be, becomes full, the router 401 can be adapted to detect this and emit an error signal.
[0078] At a step 407 (block "AUT?"), the secure element starts an authentication process of the third-party module to check if the DATA4 data can be transmitted to it by the element storing it, i.e. router 401 or secure element 402.
[0079] According to a first example, the authentication process is intended to directly authenticate the third module, but also the first module and / or the second module.
[0080] According to a second example, the authentication process is intended to authenticate the third-party module by authenticating the user of the 403 device, for example by requesting a PIN code.
[0081] According to a third example, the authentication process is carried out via a service using an external server which might want to have access to the DAT A4 data.
[0082] According to a fourth example, the authentication process includes the implementation of several secondary rules. A secondary rule may be the implementation of an authentication process requested by a module of the 403 device or by software or an application implemented by the 403 device.
[0083] Furthermore, and according to one variant, the DATA4 data may be visible or partially visible to the third-party module during the implementation of the authentication process. In a first example, the DAT A4 data is fully visible to the third-party module during authentication. In a second example, only a portion of the DATA4 data is visible to the third-party module, for example, the headers of the DAT A4 data. In a third example, only the form, or configuration, of the DATA4 data is visible to the third-party module, so as, for example, to recognize whether the DAT A4 data relates to sensitive communication, that is, communication whose data is sensitive and must be protected, such as a bank transaction or the identification of a user for the use of a SIM card (subscriber identity / identification module).For example, if a user submits their PIN to start using a . SIM card, the information relating to this PIN code is anonymized.
[0084] If the authentication result is correct (output Y of the "AUT?" block), the next step is a 408 step (block "Continue"), otherwise (output N of the "AUT?" block), the next step is a 409 step (block "Error").
[0085] At step 408, the third-party module is authorized to access all or part of the DATA4 data. For this purpose, the DATA4 data is returned to the router. According to one variant, if the DATA4 data is stored by router 401, then at this step, the DATA4 data is made accessible to the third-party module.
[0086] At step 409, communication is not authorized by the secure element 402. In this case, the DATA4 data can be erased so that the third-party module never has access to it. According to one embodiment, an error counter can be implemented to give the third-party module, or the user, several attempts to authenticate. In one example, the counter can count the attempts, and if this number of attempts exceeds a limit, then the possibility of authentication is disabled for a predetermined period. In another example, if the counter value reaches a limit, then the DATA4 data is erased, but as long as the counter value is less than the limit, then the DATA4 data is retained.
[0087] At step 410 (the "EXECUTE Log" block), following step 408, router 401 transmits the DATA4 data to the third-party module. For example, authentication performed by the secure element 402 authorizes access to all or part of the DATA4 data. In another example, router 401 may periodically request authentication during the communication process.
[0088] At a step 411 (block "Log OFF"), following step 410, router 401 exits its secure mode. For example, router 401 may exit this mode upon receiving a command from the secure element or following a specific event, such as device 403 switching to another specific operating mode.
[0089] One advantage of this embodiment is that it allows an additional level of protection to be added to the internal and external communications of an electronic device.
[0090] Fig. 6 is a block diagram illustrating another implementation method of a secure communication process implementing a router 401 (ROUTER) and a secure element 402 (SE) of the same electronic device 403 of Fig. 5.
[0091] The implementation method of the secure communication process described in relation to [Fig. 5] has common elements with the secure communication process described in relation to [Fig. 5]. In particular, in the method of [Fig. 6], the authentication of the third-party module is implemented by router 401, and not by the secure element 402.
[0092] Thus, the process of [Fig. 6] includes steps common to the process of [Fig. 5], these common steps are not described again here. These common steps are: - step 404 (block "Log ON"); - step 405 (block "Comm Start"); - step 406 (block "HIDE DATA"); - step 408 (block "Continue"); - step 409 (block "Error"); - step 410 (block "EXECUTE Log"); and - step 411 (block "Log Off").
[0093] As in [Fig.5], the process begins with step 404, which is followed by step 405.
[0094] Step 405 is followed by step 501 (block "Auth?") during which router 401 initiates an authentication process to authenticate the third-party module. In one example, the authentication process is designed to directly authenticate the third-party module, as well as the first and / or second module. In another example, the authentication process is designed to directly authenticate the user of device 403, for example, by requesting a PIN. In a third example, the authentication process is designed to authenticate the third-party module via a service using an external server.
[0095] The AUT5 information concerning the success, or failure, of the authentication process is sent to the secure element 402, if it is indeed the one that stores the DATA4 data.
[0096] At a step 502 (block "Resuit Aut?"), the secure element 402 receives the AUT5 information and deduces whether the authentication was successful or not. If the AUT5 information indicates that the authentication is correct (output Y of the block "Resuit Aut?"), the next step is step 408; otherwise (output N of the block "Resuit Aut?"), the next step is step 409 (block "Error").
[0097] Step 408 is then followed by step 410, and then by step 411.
[0098] Figure 7 is a block diagram illustrating another implementation of a secure communication method, during which a third-party module seeks access to data in a communication. The communication method implements a router 601 (ROUTER) and a secure element 602 (SE) of the same electronic device 603 of Figure 7. The device 603 is of the type of device 100 described in relation to Figure 1, and thus the router 601 and the secure element 602 are, respectively, of the type of router 102 and secure element 101.
[0099] At step 604 (block "POLICY"), secure element 602 has at its disposal a series of POL6 rules concerning a policy for protecting internal communications, and Optionally, external communications from device 101. This series of POL6 rules is intended to be implemented by router 601 when a third-party module requests access to data from a communication.
[0100] Here, a rule is an instruction that the router must implement in a specific situation.
[0101] The POL6 rule set can include different types of rules. As a first example, a rule in the POL6 rule set can prohibit a particular third-party module, or any third-party module, from accessing the data of a specific communication, for example, a communication of a certain type. As a second example, another rule in the POL6 rule set can only allow the transmission of all or part of the data of a specific communication to a third-party module. As a third example, another rule in the POL6 rule set can require the third-party module to authenticate itself in various ways to access all or part of the data of a communication. Other rules are described below, and still other rules can be devised by a person skilled in the art without demonstrating inventive step.
[0102] The secure element 601 can obtain the POL6 rule set in several ways. According to a first example, the secure element 601 can create the POL6 rule set from instructions provided by the manufacturer of the device 603, by the user of the device 603, via an external server (which could authorize communication directly or through another authentication system), and / or by the software and applications implemented by the device 603. In this case, the secure element 602 can update the rule set with each new instruction received. According to a second example, the POL6 rule set is stored in the secure element 601 without the latter being able to modify it.
[0103] According to one embodiment, when applications implemented by device 603 generate rules in the rule series, different rules may be applied depending on which application is started or running. These rules may be supplemented by rules provided by the operating system of device 603 and / or by rules provided by protection or security software for device 603. Protection or security software may, for example, provide rules preventing the implementation of rules from a specific application that it deems untrustworthy, or forcing the concealment of certain sensitive data.
[0104] According to another embodiment, the POL6 rules can themselves be protected by the secure element 602 to guarantee their integrity. For this purpose, the secure element 602 can apply a signature process to the POL6 rules.
[0105] At step 605 (block "Store Policy"), following step 604, router 601 receives The P0L6 rule set from the secure element 602 is stored. Since router 601 has this rule set in memory, it can implement it when it receives data for internal or external communication from device 603.
[0106] At a step 606 (block "Comm Start"), following step 605, communication begins. The communication may be internal to device 603 or external between device 603 and another electronic device. In practice, the router 601 begins receiving data from a first module with the instruction to forward it to a second module. In one example, the first module is an internal module of electronic device 603, and the second module is either an internal module of the electronic device or an external electronic device.
[0107] In addition, at step 606, a third-party module requests access to the data exchanged during the communication.
[0108] At a step 607 (block "Policy Check"), router 601 consults the POL6 rule series to determine if a rule should be implemented. If no rule is to be applied (output Y of the "Policy check" block), the next step is a step 608 (block "EXECUTE Comm"), otherwise (output N of the "Policy check" block) the next step is a step 609 (block "Action").
[0109] At step 608, following step 607, router 601 transmits the data to the third-party module without any further action being taken.
[0110] In step 609, following step 607, a rule from the POL6 rule series corresponds to the communication situation. Router 601 then executes the rule.
[0111] As an example, a rule may require that the transfer of data to a third-party module from a communication originating from a specific module of the 603 device or from a device external to the 603 device be preceded by an authentication process, for example, performed by the 601 router or by the 602 secure element. As another example, a rule may prohibit the transmission to a third-party module of any data from a communication originating from a specific module of the 603 device or from a device external to the 603 device. As yet another example, a rule may require that all data of a certain type, for example, data having a specific format or header, be encrypted.
[0112] In the event that some of the rules are provided by applications implemented by device 603, the rules provided by these applications may relate to the type of authentication process used to grant or deny communication.
[0113] Furthermore, if the rules followed for a given communication are provided by first and second running applications, then the rules provided by both applications can be used in parallel. According to a practical example, if If application A requires a password to authorize the transmission of DATA-A, which is part of the DATA of a communication, and application B requires password authentication via an external server to authorize the transmission of DATA-B, which is also part of the DATA, a user who only provides the password will only see the transmission of DATA-A implemented, and not the transmission of DATA-B. If the 603 device is equipped with a screen, the user could, for example, see which rule was implemented and which rule could not be implemented.
[0114] The implementation method of [Fig.7] can be combined with the implementation methods of Figures 5 and 6. This is described in relation to [Fig.8].
[0115] Figure 8 is a block diagram illustrating another implementation of a secure communication method using a router and a secure element of the same electronic device. The device is of the type of device 100 described in relation to Figure 1, and thus the router and the secure element are, respectively, of the type of router 102 and secure element 101.
[0116] The router described here includes a set of rules of the type of the POL6 rule set described in relation to [Fig. 7]. The secure element provided this rule set to the router as described in relation to [Fig. 7].
[0117] At step 701 (block "Router Log ON"), the router is put into a secure operating mode. This step is identical to step 404 described in relation to [Fig. 5].
[0118] At a step 702 (block "Comm Start"), following step 701, communication begins. The communication may be internal to the device or external between the device and another electronic device. In practice, the router begins receiving data with the instruction to transmit it to a module of the device or to another electronic device external to the device.
[0119] In addition, at step 702, a third-party module requests access to all or part of the communication data.
[0120] At step 703 (block "Auth & Policy Check"), following step 702, the data and the communication instruction are subjected to the series of rules stored in the router and to the authentication process that can be implemented by the router's secure mode. According to a first example, the router first implements the series of rules as described in relation to [Fig. 7], then implements authentication according to one of the variants presented in relation to [Fig. 5] or [Fig. 6]. According to a second example, the router first implements authentication according to one of the variants presented in relation to [Fig. 5] or [Fig. 6]. [Fig.6], then implements the series of rules as described in relation to [Fig.7].
[0121] If the third-party module is allowed to have access to the communication data (output Y of the "Auth & Policy Check" block) the next step is a 704 step (block "EXECUTE Comm"), otherwise (output N of the "Auth & Policy check" block) the next step is a 705 step (block "Action").
[0122] At step 704, following step 703, the router transmits the data to the third-party module without any further action being taken.
[0123] At step 705, following step 703, the instruction that the router is trying to implement falls under one of the rules in the rule series, and / or the authentication process did not produce a successful response. The router then executes the rule and / or blocks the communication.
[0124] Various embodiments and variations have been described. A person skilled in the art will understand that certain features of these various embodiments and variations could be combined, and other variations will become apparent to a person skilled in the art.
[0125] In particular, different methods of implementing DATA4 data storage can be envisaged.
[0126] According to a first example, the module storing the DATA4 data, i.e., the router or the secure element, can use a limited amount of memory. If the memory is full, an alert message is sent, and the module decides to free up space. According to another variation, the memory can be circular, i.e., memory that, once full, erases the oldest data to free up space. The module can also store only DATA4 data of a certain type, i.e., it can filter the DATA4 data to store only the useful data and avoid double storage; such a storage method is called aggregation storage.
[0127] According to a second example, the module storing the DATA4 data can decide to store this data in another module of the device, having previously applied the series of rules, if applicable.
[0128] Finally, the practical implementation of the embodiments and variants described is within the reach of a person skilled in the art, based on the functional indications given above.
Claims
Demands
1. A method of communicating, to a third module of a first electronic device, first data (DATA4) exchanged between a first module of the first electronic device (100; 200; 300) and a second module, the third module being different from the first module and the second module, the first device comprising at least one secure element (101; 201; 402) and a router (102; 202; 401) transmitting the first data (DATA4) from the first module to the second module, the router (102; 202; 401) being adapted to be put into a secure mode in which, when the third module requests access to the first data (DATA4), an authentication method is implemented to verify whether the third module is authorized or not to have access to the first data (DATA4).
2. Electronic device comprising at least: - a first electronic module; - a secure element; - a router (102; 202; 401; 601) exchanging first data (DATA4) between the first module and a second module; and - a third module different from the first and second modules, the router (102; 202; 401; 601) being adapted to be put into a secure mode in which, when the third module requests access to the first data (DATA4), an authentication process is implemented to verify whether the third module is authorized or not to have access to the first data (DATA4).
3. Method according to claim 1, or device according to claim 2, wherein during the implementation of the authentication method the first data (DATA4) are stored in the secure element (101; 201; 402) or in the router (102; 202; 401).
4. Method or device according to claim 3, wherein during their storage, the first data (DATA4) are at least partially visible by the third-party module.
5. Method according to any one of claims 1, 3 or 4, or device according to any one of claims 2 to 4, wherein the authentication method is implemented by the router (102; 202; 401).
6. A method according to any one of claims 1, 3 or 4, or a device according to any one of claims 2 to 4, wherein the The authentication process is implemented by the secure element.
7. A method according to any one of claims 1, 3 to 6, or a device according to any one of claims 2 to 6, wherein the authentication method allows authentication, in addition to the third module, of the first module, the second module, or the user of the first device.
8. A method according to any one of claims 1, 3 to 7, or a device according to any one of claims 2 to 7, wherein the authentication method is implemented via an external server.
9. A method according to any one of claims 1, 3 to 8, or a device according to any one of claims 2 to 8, wherein the authentication method comprises the implementation of several secondary rules.
10. Method according to any one of claims 1, 3 to 9, or device according to any one of claims 2 to 9, wherein the router (102; 202; 401) is adapted to request permission to be in secure mode (101; 201; 402).
11. A method according to any one of claims 1, 3 to 10, or a device according to any one of claims 2 to 10, wherein the router (102; 202; 401; 601) is adapted to exit safe mode upon receipt of a particular instruction.
12. Method or device according to claim 11, wherein the particular control originates from the secured element.
13. A method according to any one of claims 1, 3 to 12, or a device according to any one of claims 3 to 12, wherein the router (102; 202; 401; 601) includes a series of rules concerning the communications security policy of the first device.
14. Method or device according to claim 13, wherein the secure element (101; 201; 402; 602) transmits said series of rules to said router (102; 202; 401; 601).
15. A method according to any one of claims 1, 3 to 14, or a device according to any one of claims 2 to 14, wherein the second module is part of the first electronic device.
16. A method according to any one of claims 1, 3 to 14, or a device according to any one of claims 2 to 14, wherein the second module is part of a second electronic device, different from the first electronic device.
17. Method according to any one of claims 1, 3 to 16, or device according to any one of claims 2 to 16, wherein the router (102; 202; 401; 601) is integrated into a chip implementing the first module (100; 200; 300) and / or the third module.