Software Update in the Security Element
The update agent secures personalization data within the secure element, enabling flexible and secure software updates outside the chip manufacturer's environment, addressing the limitations of conventional secure element updates.
Patent Information
- Application Number
- JP2024503482
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-07-28
- Filing Date
- 2022-07-26
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2042-07-26
AI Technical Summary
Existing methods require secure elements to be personalized within a proven secure environment for software updates, limiting flexibility and security in updating trusted software outside the chip manufacturer's premises.
An update agent is used to secure specific data within a secure element's memory, enabling software updates outside the proven secure environment by reusing personalization data, ensuring the integrity and authenticity of the software image.
Facilitates secure and flexible software updates for secure elements, maintaining security levels while allowing updates at any point in the life cycle without the need for a proven secure environment.
Smart Images

Figure 0007710594000001 
Figure 0007710594000002 
Figure 0007710594000003
Abstract
Description
Technical Field
[0001] The present invention relates to the update of software installed in a secure element, particularly to the update of personalized trusted software of a secure element, such as an operating system.
Background Art
[0002] Background of the Invention Secure elements are widely used in various systems such as mobile phones, smart cards, payment cards, access cards, etc. to provide identity verification, authenticity proof, data storage, and application processing.
[0003] For example, in the case of a payment card, when security-critical applications and confidential data are included in a smart card, a secure element is used to store the data. The secure element is a tamper-resistant element, a TRE, which provides a secure memory and execution environment capable of securely storing and managing application code and application data. The secure element ensures that access to the data stored on the card is only possible when permitted. Such secure elements can exist in any form factor such as UICC, embedded SE, smartSD, smart microSD, eSTM, etc.
[0004] The secure element includes, for example, in the field of security, a data set such as firmware / operating system, packages, applets, applications, etc., which includes personalized data whose authenticity is proven using specific data required to operate them, such as security keys. The operating system and applications are stored in volatile and non-volatile memory modules within the secure element and executed within the secure processor of the secure element.
[0005] The specification of the Global Platform Card Technology Open Firmware Loader for Tamper resistant Elements v1.3 describes a standardized mechanism for loading firmware (i.e., use case-dependent data that may include operating system and application data) and personalization data into a secure element. In particular, the Image Trusted Loader, ITL, or update agent provided within the secure element receives the operating system image, performs security checks on the image, particularly authenticity and integrity checks, and triggers the installation of the image content into the secure element's memory using specific data required to manipulate the image, so as to configure the secure element to install an operable operating system.
[0006] Figure 1 shows a schematic diagram of a conventional process for loading firmware (e.g., operating system, OS) into a secure element. The upper part shows the entities responsible for the corresponding production stages (I, II, III, IV), and the lower part shows the content of the secure element (i.e., chip) in that specific production stage. In the first production stage I, at the chip production site (i.e., chip factory), the chip manufacturer provides a secure element 100 to be loaded with trusted software such as a secure operating system. At the chip production site, the trusted software is personalized with credentials 65a, which are specific data including keys or certificates. Once personalized, the personalized software image, e.g., the personalized operating system, OS 30a, is stored, which is called "maxiInit" in Figure 1. The trusted software or OS is personalized by specific commands, so-called APDUs, sent from an external personalization device at the chip production site to the secure element. Finally, the personalized software is loaded onto the chip.
[0007] The chip with the personalized software is then either incorporated (in stage II) into a portable card-type device such as an (e)UICC or (e)SIM at the premises of the device manufacturer, or sent to the premises of another device manufacturer and included in a final electronic device such as a smartphone, computer, automobile, measuring instrument, etc. (in stage III), and finally sold on the market (in stage IV). If at any stage of the chip's life cycle it becomes necessary to modify or update the personalized trusted software, the personalization data used to personalize the installed software to be modified or updated is lost, but note that the modified or updated versions, the respective software images, still have to be personalized. Summary of the Invention Problems to be Solved by the Invention
[0008] Therefore, there is still a need to enable the update of the trusted software installed in the secure element to overcome the aforementioned drawbacks. Means for Solving the Problems
[0009] Summary of the Invention The present invention addresses the above objectives by the subject matter encompassed by the independent claims. Preferred embodiments of the present invention are defined in the dependent claims.
[0010] According to a first aspect of the present invention, there is provided a method for updating a secure element, SE, and installed software thereon, in particular an operating system, OS. The method includes, in a first step, providing an update agent to the SE. In a further step, specific data required to operate the installed software, in particular the operating system, on the SE is secured within a specific memory of the update agent. Further, a software image representing and intended to replace the update of the installed software, in particular the operating system, is loaded onto the SE. In a final step, the software image is made operational by the secured specific data and replaces the installed software, in particular the operating system, as its update.
[0011] Throughout this application, the term "software" refers to any trusted software loaded onto and executed within a secure element. Examples of such software include firmware, an operating system (OS), and any other use - case - dependent secure application. The expression "software image" (or "OS image") refers to an encompassing data format that includes the software version and cryptographic data used by an operating system or an agent of the SE, such as the update agent according to the present invention.
[0012] Preferably, the specific data is not an integral part of the installed software or the software image, yet is necessary to operate the installed software (and the installed software image) and / or to enable the software image to be installed on and executed by the secure element. That is, without the specific data, the software image cannot operate and / or be installed as an update of the installed software, nor can it replace and / or update it.
[0013] The essence of the present invention is that the update agent causes specific data associated with the installed software to be reused, i.e., "recycled", to enable the software image to operate, either to generate a new specific data set or because it is not necessary to safely obtain or handle it from an external entity within a proven secure environment. Since the update agent itself is authenticated trusted software, this can be seen as a functional replacement for a proven secure environment at the chip manufacturer's site, because thereby the specific data of the installed software can be safely reused, i.e., "recycled", at the time of its update. Thereby, the specific data is held under the control of a trusted entity, i.e., the update agent, within the secure environment of the secure element and cannot be tampered with, thus ensuring the integrity of the software image.
[0014] Regarding the present invention, the description of making a software image operable by specific data that is ensured means any process that uses that specific data to cause the software image not to operate without the specific data. Thus, making a software image operable means that the software image is correctly and operably installed in the secure element by using the specific data. That is, the presence of the specific data at a particular point in the process of installing the software image is a requirement for it to function properly as an update to the installed software. This may include the requirement to use the specific data at the time of installation of the software image or preferably at the time of personalization of the software image.
[0015] Accordingly, preferably, the specific data comprises or consists of personalization data necessary for personalizing the software image, in particular secure credentials and / or cryptographic keys. In that sense, the present invention overcomes the conventional requirement of personalizing the software image within a proven secure environment, and thus broadens the options for updating the software installed in the secure element. In other words, the present invention enables the secure update of the installed software, in particular the trusted operating system of the secure element, outside the chip manufacturer's premises and regardless of any proven secure environment. The update agent can reuse, i.e., "recycle", the personalization data of the installed software to be replaced in order to provide the necessary security level conventionally provided by the chip manufacturer's proven secure environment.
[0016] The proposed method provides an efficient and secure solution for updating trusted software regardless of the conventional security concept. The trusted software image for updating the installed software does not need to be personalized in the same way as the installed software was originally personalized, thus providing a flexible solution for personalizing the software update at any point during the life cycle of the secure element. With the proposed method for updating the installed software with an appropriate software image, it is ensured that the highly confidential personalization data remains under strictly secure conditions within the update agent and is thus protected from unauthorized changes.
[0017] Preferably, the specific or confidential data and / or personalization data is stored in a specific memory or memory structure of the update agent, for example in a dedicated secure segment of non-volatile memory that can be accessed exclusively by the update agent only.
[0018] In some embodiments of the present invention, the installed software is personalized with personalized data included in specific data, and the installed software is stored together with the specific data and / or the personalized data in a memory area of the SE where the installed and / or executable software is stored, such as the non-volatile memory of the secure element.
[0019] The update agent ensures the specific data and / or the personalized data stored together with the installed software by copying or replicating the specific data and / or the personalized data to a specific memory of the update agent for later use. The specific data and / or the personalized data are protected from being deleted or degraded during the update process, for example, by deleting the installed software together with their respective specific data and / or the personalized data. Once the specific data and / or the personalized data are secured in and / or copied to the specific memory of the update agent, the installed software can be updated, as this enables, for the first time, the software image representing the update of the installed software to be made operable. Finally, the installed software is updated by using the personalized data to personalize the software image and / or by using the specific data stored in the specific memory of the update agent to make the software image operable.
[0020] In some embodiments of the present invention, before installing a software image, including making it operational and / or personalizing it, the entire installed software, i.e., together with the specific data and / or personalization data used to make it operational, is canceled. This includes canceling any memory or memory area in the secure element where the installed software resides or a part of it exists. For example, if the installed software to be updated is the operating system of the secure element, canceling the entire operating system also includes canceling all personalization data, OS-specific data, certificates, cryptographic keys, credentials, etc.
[0021] When a software image or an operating system image is loaded into the secure element to provide an update to the canceled software, within the update agent, the specific data and / or personalization data by which security is thereby ensured are required to make the loaded software image operational and / or to personalize it.
[0022] First, since the installed software, e.g., the trusted operating system of the SE, is made operational by specific data or personalized by personalization data during the first production stage of the SE, the specific data and / or personalization data are secured by the update agent at the chip manufacturer's site during this initial production stage. Thus, the update agent, which is itself trusted software, is loaded into the SE and is made operational / personalized by that data / personalization data during the first production stage of the SE within the environment where the security of the chip manufacturer is also proven. This makes it possible to already secure the specific data / personalization data of the installed software, e.g., the trusted operating system, by the update agent at this early production stage.
[0023] According to some embodiments of the present invention, the update agent secures specific data and / or personalized data of the installed software of the SE in a specific memory if the specific data and / or the personalized data are changed or adjusted during the installation process. This subset of the installed software of the SE may include only the operating system of the SE, and may include any software or application that is installed on the SE and may potentially be updated during the life cycle of the SE.
[0024] After the specific data and / or the personalized data are secured by the update agent during the first production stage I of the SE, it is preferable that the software image is loaded onto the SE at a stage after the first production stage of the SE. Thereby, while the flexibility and versatility of the use of the secure element and its applications within the electronic device are increased, the security level required for the personalization of the software is still provided, because such a software image can then be made operable and / or personalized outside the environment where the chip manufacturer's security has been proven.
[0025] Preferably, to ensure that the specific data and / or the personalized data are secured in a reliable state, the securing of the personal data and / or the personalized data is stopped when the secure element progresses from the first production stage to subsequent stages of the manufacturing process. Thereby, when the installed software is updated, it is ensured that the respective specific data and / or the personalized data have not been tampered with.
[0026] According to a second aspect of the present invention, a secure element including installed software, in particular an operating system, and an update agent are provided. The update agent includes or can access a specific memory or memory structure in which specific data required to operate the installed software can be secured or is secured.
[0027] When the secure element is shipped from the chip factory, the specific data necessary to operate the installed software is secured for the subsequent update process by the update agent.
[0028] In a stage after the chip production stage (stages II, III or IV in Figure 1), the software image is loaded onto the secure element at some point, thereby updating the installed software. The update agent is configured to complete the update of the installed software by making the loaded software image operable using the secured specific data.
[0029] Preferably, the specific data secured within the memory structure of the update agent includes the personalized data of the installed software, in particular the secure credentials and / or cryptographic keys by which the installed software is personalized. That is, the specific or personalized data secured therein by the update agent is a copy of or at least includes the personalized data used for the personalization of the installed software. In this sense, the update agent is configured to update the installed software in that the loaded software image is personalized using the secured personalized data.
[0030] In some embodiments, the secure element includes a processor and a memory coupled to the processor and storing program modules executed by the processor. The program modules may include instructions regarding at least some of the aforementioned operations performed by the secure element, for example those of the update agent according to the present invention.
[0031] According to a third aspect of the present invention, an update agent for use in a secure element is provided. As already detailed with respect to the first and second aspects, the update agent includes a memory, secures specific data necessary to operate software installed in the secure element, and is configured to make an uploaded software image operable by the secured specific data representing an update of the installed software. The update agent is preferably designed as software installed in and thereby executed by a secure element according to the present invention to enable updating of the software installed in the secure element.
[0032] In some embodiments of the present invention according to any of the above aspects, the update agent is configured to authenticate a software image using authentication data stored in the memory of the update agent upon loading of the software image. Preferably, the secure element, in particular the update agent, authenticates the software image by verifying a digital signature that can be associated with the vendor of the secure element or the provider of the electronic device in which the secure element is incorporated. For example, the update agent may verify the integrity of the software image using a cryptographic key associated with a specific vendor or device. The update agent may also be able to decrypt the software image using the authentication data stored in the memory of the update agent when the software image is loaded into the secure element.
[0033] The update agent is thus a stand-alone entity that is loaded onto the secure element in the factory, enabling the operating system and / or other trusted software images to be loaded onto the secure element or the device in which the secure element is incorporated, even if the device has already been deployed in the field at any given time. Thus, the update agent enables the software image or operating system to be loaded directly in the field, i.e., outside a proven secure environment, to update the software installed in the secure element.
[0034] According to yet another aspect of the invention, there is provided a computer program for use within an electronic device in which a secure element according to the second aspect is incorporated or into which it can be incorporated. The computer program product includes a non-transitory computer-readable storage medium for loading a software image onto the secure element within the electronic device and a computer program mechanism incorporated therein. The computer program mechanism includes instructions for securing in memory specific data necessary for operating the software installed in the secure element, the specific data being personalization data, including instructions for personalizing the installed software using the personalization data, instructions for receiving a software image to be loaded onto the secure element, the software image representing an update of the installed software, and instructions for making the software image operable by the secured specific data and / or for personalizing the software image with the personalization data included in the specific data.
[0035] It should be noted that all the devices, elements, units, and means described in this application can be implemented by software or hardware elements or combinations thereof. All steps executed by various entities described in this application and the described functions are meant that each entity is adapted or configured to execute its respective steps and functions.
[0036] Other aspects, features, and advantages of the present invention will become apparent to those skilled in the art by reading the following detailed description of the preferred embodiments and variations of the present invention together with the accompanying drawings.
[0037] Brief Description of the Drawings Here, refer to the following attached drawings.
Brief Description of the Drawings
[0038]
Figure 1
Figure 2a
Figure 2b
Figure 3
Modes for Carrying Out the Invention
[0039] Detailed Description Hereinafter, a detailed description of the present invention will be made with reference to the accompanying drawings showing specific embodiments of the present invention. These embodiments are described in sufficient detail so that those skilled in the art can practice the present invention. It should be understood that the various embodiments of the present invention, although different, are not necessarily mutually exclusive. For example, a particular feature, structure, or characteristic described in connection with one embodiment herein may be implemented in other embodiments without departing from the scope of the present invention. In addition, it should be understood that the position or arrangement of the individual elements of each disclosed embodiment may be changed without departing from the scope of the present disclosure. Therefore, the following detailed description should not be construed in a limiting sense, and the scope of the present invention is defined only by the full scope of the appended claims and the equivalents that the claims may have. In the drawings, like numerals refer to the same or similar functions throughout the several views.
[0040] Figures 2a and 2b show in more detail the structure of a secure element, SE 100, according to two preferred embodiments. Figure 3 shows the steps of the method according to the present invention with respect to Figures 2a and 2b.
[0041] The SE 100 shown in FIG. 2a is a tamper-resistant element and includes an update agent 10, an operating system, OS 30, and a processor, CPU 40. Both the update agent 10 and the OS 30 can be stored in a memory within the SE 100, for example, a non-volatile memory 50. The OS 30 and the update agent 10 are independent entities and can communicate with each other through a suitable interface, for example, an application programming interface, API. The memory 50 is the non-volatile memory of the SE 100, which includes a memory area 55 where software that is installed on the SE 100 and executable by the CPU 40 is stored. Such installed software can be an executable application or program that provides specific functions to the secure element identified by reference numeral 60a in FIG. 2a, or it can be the operating system of the secure element 100 identified by reference numeral 30a in FIG. 2b, which is also installed software that may need to be updated at a specific point in the life cycle of the SE 100 with respect to this application. Both the OS 35a in FIG. 2b and the OS 30 in FIG. 2a are, for example, the standard operating systems of secure elements or smart cards based on the Java Card platform. They are equivalent, and the difference between FIGS. 2a and 2b is that the OS 30 in FIG. 2a is the target of software updates according to the present invention in FIG. 2b. The personalized OS 30a in FIG. 2a is shown as "maxInit" in FIG. 1.
[0042] The update agent 10 can be a functional part of the operating system 30 or the loader entity or be implemented as its function, enabling the provisioning of software (e.g., use case-dependent firmware) within the SE 100. Such a loader entity is also referred to in the art as an Image Trusted Loader, ITL. The update agent is the main entity responsible for loading software or software images into the secure element and all other related procedures, such as updates, restorations, rollbacks, etc. In FIGS. 2a and 2b, the software images loaded into the SE 100 are indicated by a reference number 60b identifying any software image and 30b identifying the operating system image, respectively. The update agent 10 is loaded into the SE 100 during production in the factory (see step S1 in FIG. 3), regardless of whether it is implemented as an independent entity or as a functional part of the operating system 30, because it reflects a security-critical entity of the SE 100 (FIG. 1, stage I).
[0043] The update agent 10 may include its own reserved memory space in the form of a memory structure 12, where confidential data, such as personal data and / or authentication data, is stored, and the latter is used to authenticate and / or decrypt the software images 30b, 60b before their personalization. Thus, at any point in the personalization process, the memory structure 12 of the update agent 10 may include personalization data 35b, 65b, and the operating system 30 may be able to access at least a part of the memory structure 12.
[0044] According to FIG. 2a, the executable software 60a is personalized and installed in the SE 100. The installed software 60a is thus the personalized data 65a associated therewith, such as secure credentials and / or encryption keys, whereby it is ensured that the installed software is authenticated and trustworthy, non-tampered software. The installed software 60a and the personalized data 65a are stored together in the memory area 55 of the SE 100. Within the memory area 55, the installed software 60a and its personalized data 65a can be stored intertwined, which is because at the time of installation, the software 60a is provided or supplemented with the personalized data 65a in various ways. The software 60a is personalized during the production in the factory of the SE 100 and installed on the SE 100 (see step S2 in FIG. 3), which is because personalization is a security-critical operation that is conventionally performed in an environment where the security of the production site of the manufacturer of the SE 100 is proven.
[0045] FIG. 2b is different from FIG. 2a in that the installed software is actually the operating system 30a itself of the SE 100, to which the individual personalized data 35a is attached. For the reasons described above, the operating system 30a is personalized during the production in the factory of the SE 100 and installed in the SE 100 (see step S2 in FIG. 3).
[0046] The SE 100 in the state shown in FIGS. 2a and 2b has left the environment where the safety of the chip manufacturer has been proven after the first chip production (stage I in FIG. 1). In this situation, copies 65b, 35b of the personalized data 65a, 35a are stored in the memory structure 12 of the update agent 10, and the software images 60b, 30b are provided by the external server 200 and loaded into the secure element 100 to update and replace the installed software 60a, 30b. The software images 60b, 30b represent software updates of the installed software 60a or the operating system 30a, respectively. The external server 200 may represent an entity that communicates with the SE 100. This can be an LPA (Local Profile Assistant), a terminal, or any device to which the SE can be connected. In particular, the external server 200 is or includes an image delivery server and provides the software image 60b or the operating system image 30b to the SE through a custom interface during subsequent production stages (stages II, III, IV in FIG. 1).
[0047] FIG. 3 shows a flowchart of the main steps of a method for updating the installed software 60a (see FIG. 2a) in the secure element 100, for example, the operating system, OS 30a (see FIG. 2b). The steps of the method are described in detail with respect to the SE shown in FIGS. 2a and 2b.
[0048] The method according to the present invention is not limited to a specific type of software or software image, as will be explained below. In fact, any secure software or software image that can be installed in and executed by the secure element 100 can be the subject of the update method disclosed in this application, which can be, for example, the firmware or OS of the SE 100 or an applet / application.
[0049] Steps S1 to S3 are executed in an environment where safety has been proven during the production stage at the factory of SE 100, thereby ensuring the security and authenticity of its software components and data. Steps S4 and S5 represent a software update process, which can be executed outside the environment where the chip manufacturer's safety has been proven in subsequent stage II or III and further thereafter (see FIG. 1).
[0050] Regarding FIG. 3, in the first step S1 executed in the first chip production stage I, the update agent 10 is loaded into SE 100. The update agent 10 reflects the security-critical entities of SE 100 that are loaded into SE 100 during production at the factory.
[0051] In the second step S2, software is installed into SE 100, which is, for example, an application of other software 60a or the operating system 30a of SE 100. When installing the software 60a or the operating system 30a, they are each personalized by their respective personalized data 65a, 35b. This includes loading both personalized data 65a, 35a, which particularly includes security credentials and cryptographic keys, and the software 60a or the operating system 30a to be installed into SE 100. By using the credentials and keys 65a, 35a, the loaded software 60a or the operating system 60a is finally personalized so that the executable software 60a, 65a or the operating system 30a, 35a is installed on SE 100, which is shown as "maxInit" in FIG. 1.
[0052] Update agent 10 may facilitate or further execute step S2 in that it loads personalized data 65a, 35a into memory structure 12 and uses the loaded personalized data 65a, 35a to personalize software 60a or operating system 30a. In fact, the installed software includes the operational software 60a and its specific personalization / configuration 65a including credentials. Similarly, with respect to FIG. 2b, the operating system includes the operational system 30a and its specific personalization / configuration 35a.
[0053] Steps S1 and S2 may be executed sequentially, i.e., in two or more load commands (e.g., APDU commands) or in one step where update agent 10 is loaded into secure element 100 together with software 60a / operating system 30a and / or personalized data 65a, 35a.
[0054] To enable the update of the software 60a or the operating system 30a installed in an environment where the safety of the chip maker according to the present invention has been proven, in step S3, the update agent 30 secures specific confidential data of the installed software 60a or operating system 30a, such as the personalization data 65a, 35a, in the memory structure 12. Regarding the software 60a, 30a installed in the secure element 100, such secured specific data 65b, 35b is not an integral part of the installed software 60a or operating system 30a itself, but is separately loaded and characterized by being necessary to operate the installed software 60a or operating system 60a. Regarding the present invention, the secured specific data 65b, 35b is also necessary to enable or operate any software image 60b or operating system image 30b loaded in the SE 100 as an update that replaces it with the installed software 60a or operating system 60a. In particular, the personalization data 65a, 35a is specific data in the above-mentioned sense and is secured as the personalization data 65b, 35b replicated by the update agent 10 in step S3.
[0055] The step S3 of securing the specific and / or personalization data 65b, 35b can be a continuous process within the chip production stage I, in which the specific and / or personalization data 65b, 35b is secured each time the specific and / or personalization data 65a, 35a is modified during the installation of the software 60a or the operating system 30a.
[0056] Personalized data 65b, 35b and the secure element 100 and / or other confidential data necessary to operate it, specific to the installed software 60a, such as the operating system 30a, are secured by the update agent 10 at step S3, because such data may be lost during subsequent updates of a particular kind, for example when a particular data area is updated or a particular part of the memory area 55 is overwritten.
[0057] In order to be able to update the installed software 60a, such as the operating system 30a, outside the environment where the security of the chip manufacturer has been proven without impairing the personalization and thus the operability of the software 60a, 30a, such specific data 65b, 35b is secured thereby within the update agent 10, so that it can be retrieved later and the software image 60b or the operating system image 30b can be updated and installed to make it operable.
[0058] According to the invention, step S3 is performed only during the production phase of the secure element 100, i.e., while the secure element 100 is still within the environment where the security of the chip manufacturer has been confirmed. When the secure element 100 proceeds to its subsequent production phases II, III or IV according to FIG. 1, the secured data 35b, 65b are retained in the state when the SE 100 completed production phase I. Thus, the update agent 10 stops securing the specific and / or personalized data 65b, 35b at this point in the production cycle.
[0059] Steps S4 and S5 indicate the actual update by the software image 60b or the operating system image 30b of the installed software 60a or the installed operating system 30a in subsequent production phase II or III or later (see FIG. 1).
[0060] As part of step S4, the software image 60b or the operating system image 30b is loaded from the external image server 200 into the memory area 55 of the SE 100 (step S4a). Before the image upload or essentially during any part of the image upload process, the installed software 60a or the installed operating system 30a is completely deleted from the memory area 55, together with all of the related or associated specific and personalized data 65a, 35a. This deletion, sometimes called a "full flash", is required during software updates because the ROM cannot be updated. During a full flash, the memory area 55 is erased, i.e., the entire installed software 60a or the entire installed operating system 30a is deleted together with its personalized data 65a, 35a, such as private credentials and cryptographic keys, and any specific data necessary to operate the installed software 60a or operating system 30a.
[0061] In step S4a, the update agent 10 loads the updated software version or operating system version in the form of the software image 60b or the operating system image 30b provided by the image server 200 into the memory area 55. Due to the full flash, when the software image 60b or the operating system image 30b is loaded into the memory area 55 of the SE 100, no specific or personalized data 65a, 35a is available. At this point, the secure element 1000 has conventionally been rendered useless because there is no need to personalize any software image 60b or operating system image 30b, which has conventionally been impossible outside of the environment where the security of production stage I has been proven.
[0062] In step S5, the update agent 10 personalizes the loaded software image 60b or operating system image 30b with the specific and personalized data 65b, 35b already reserved in the memory structure 12 in step S3. Since the specific and personalized data 65b, 35b represent copies of the specific and personalized data 65a, 35a deleted during the full flash process in step S4, the update agent 10 restores the specific and personalized data 65b, 35b reserved in step S5. As an effect of data restoration, the uploaded software image 60b or operating system image 30b is made operable by the reserved specific and personalized data 65b, 35b, for example, in that the uploaded software image 60b or operating system image 30b is personalized using the personalized data 65b, 35b. Therefore, in step S5, the update agent 10 converts the loaded software 60b or operating system image 30b into a new updated operable software or operating system to be installed on the SE 100.
[0063] At the end of this process, the software image 60a or operating system image 30a is personalized by the personalized data 65b, 35b respectively. When updating the operating system 30a with the operating system image 30b, the personalized operating system image is called "maxiInit" in FIG. 1. This means that it includes its specific personalization / configuration including the operable system and credentials.
[0064] Since this update process may be repeated multiple times during the life cycle of the SE 100, each time the installed software 60a or the installed operating system 30a is updated, the update agent 10 performs a full flash followed by the recovery of the specific and personalized data 65b, 35b secured during the chip production stage I of the SE 100. By this process, the software image 60b or the operating system image 30b uploaded to the SE 100 at a stage after the chip production stage I can still operate and be personalized equally securely as if it had been personalized in the conventional manner during the production stage I of the secure element 100.
[0065] The methods and apparatuses described through the above embodiments provide an efficient and secure solution for personalizing a trusted software image outside a proven secure environment at the chip manufacturer's site. Since the software image can be personalized outside the chip manufacturer's environment at a later stage, a flexible solution is provided that allows software to be personalized at any point during the life cycle of the secure element.
[0066] In the foregoing specification, the invention has been described with reference to specific embodiments thereof. However, it will be apparent that various modifications and variations can be made to them without departing from the broader scope of the invention. For example, the process flow described above has been described with respect to a particular order of process operations. However, many of the orders of the described process operations can be changed without affecting the scope or operation of the invention. The specification and drawings are, therefore, to be regarded in an illustrative rather than a limiting sense.
Claims
1. A method for a processor included in a secure element SE (100) to update software (60a) installed in the SE (100), particularly an operating system, OS (30a), comprising: - providing an update agent (10) to the SE (100) (S1); - securing specific data (35a, 65a) necessary for operating the installed software (30a, 60a) in a memory (12) of the update agent (10), which is a dedicated secure segment to which the update agent (10) has exclusive access (S3); - after the specific data (35a, 65a) is secured in the memory (12), making the installed software (30a, 60a) updatable and loading a software image (30b, 60b) into the SE (100) (S4a), wherein the software image (30b, 60b) represents an update of the installed software (30a, 60a), the loading (S4a); - making the software image (30b, 60b) operable with the secured specific data (35b, 65b) (S5). A method comprising the above steps.
2. The method according to claim 1, wherein in the securing step (S3), specific data (35a, 65a) including personalized data of the installed software (30a, 60a), particularly secure credentials and / or cryptographic keys, is secured.
3. The installed software (30a, 60a) is personalized with the personalized data (35a, 65a), and the installed software (30a, 60a) is updated (S4, S5) in that the software image (30b, 60b) is made operable by personalizing the software image (30b, 60b) using the personalized data (35b, 65b) (S5). The method according to claim 2.
4. The installed software (30a, 60a) is stored in the memory area (55) of the SE (100) together with the specific data (35a, 65a), and the specific data (35a, 65a) re - uses the specific data (35b, 65b) from the memory area (55) of the SE (100) and / or secures it by copying it to the memory (12) of the update agent (10) (S3), the method according to any one of claims 1 to 3.
5. The installed software (60a, 30a) is deleted together with the specific data (35a, 65a) by deleting the memory area (55) of the SE (100) before loading the software image (30b, 60b) (S4a) or as a result of loading the software image (30b, 60b) into the memory area (55) (S4a), the method according to claim 4.
6. The specific data (35a, 65a) is secured during the production stage (I) of the SE (100) (S3), and the software image (30b, 60b) is loaded (S4a) and made operable (S5) in subsequent stages (II, III, IV) after the production stage (I) of the SE (100), the method according to claim 1.
7. The specific data (35a, 65a) is secured by the update agent (10) when the specific data (35a, 65a) is changed during the production stage (I) of the SE (100) (S3), and the update agent (10) stops securing the specific data (35a, 65a) when the SE (100) proceeds to subsequent stages (II, III, IV) after the production stage (I) of the SE (100), the method according to claim 1.
8. The update agent (10) is provided by loading the update agent (10) into the SE (100) during the production stage (I) of the SE (100) (S1), the method according to claim 1.
9. A secure element (100) including installed software (60a), in particular an operating system (30a) and an update agent, The update agent (10) includes a memory (12) which is a dedicated secure segment that can be exclusively accessed by the update agent (10), and in which specific data (35b, 65b) necessary for operating the installed software (30a, 60a) is secured, and the software images (30b, 60b) are configured to be operable by the secured specific data (65b, 35b). After the specific data (35b, 65b) is secured in the memory (12), the installed software (30a, 60a) can be updated, and the software images (30b, 60b) are loaded into the secure element (100), and the secure element (100) represents an update of the installed software (30a, 60a).
10. The secured specific data (35b, 65b) includes personalization data of the installed software (30a, 60a), in particular secure credentials and / or cryptographic keys, and the installed software (30a, 60a) is personalized with the personalization data (35a, 65a), while the update agent (10) is configured to update the installed software (30a, 60a) in that the loaded software images (30b, 60b) are made operable by personalizing them using the secured personalization data (35b, 65b). The secure element (100) according to claim 9.
11. The specific data (35b, 65b) secured in the memory (12) of the update agent (10) is a reuse and / or copy of the specific data (35a, 65a) stored in the memory area (55) of the secure element (100) together with the installed software (30a, 60a). The secure element (100) according to claim 9 or 10.
12. An update agent (10) which is a program for use in a secure element (100), including a memory (12), and - Ensuring specific data (35a, 65a) necessary for operating software (30a, 60a) installed in the secure element (100) within the memory area (55) of the secure element (100); - Making software images (30b, 60b) operable by the secured specific data (35b, 65b), where the software images (30b, 60b) are loaded into the secure element (100) and represent an update of the installed software (30a, 60a), and making them operable; An update agent (10) configured to perform the above.
13. Personalized data, thereby securing specific data (35a, 65a) including personalized data, particularly secure credentials and / or cryptographic keys, by which the installed software (30a, 60a) is personalized, and using the secured personalized data (35b, 65b) to personalize the loaded software images (30b, 60b) to update the installed software (30a, 60a). While the specific data (35a, 65a) is secured during the production stage (I) of the SE (100), and the installed software (30a, 60a) is updated in subsequent stages (II, III, IV) after the production stage (I) of the SE (100). The update agent (10) according to claim 12.
14. The update agent (10) according to any one of claims 12 to 13, realized as an executable software product configured to implement the method according to claim 1 and / or installed in the secure element (100) according to claim 9 and configured to be executed by a processor (40) of the secure element (100).
15. A computer program product for use with a secure element (100) within an electronic device, Including a computer program mechanism for loading software into the secure element (100) within the electronic device, The computer program mechanism is - Instructions for securing specific data (35a, 65a) necessary for operating software (30a, 60a) installed in the secure element (100) within a memory area (55) that is a dedicated secure segment exclusively accessible by the computer program product, wherein the specific data (35a, 65a) is personalization data, and including instructions for personalization data with which the installed software (30a, 60a) is personalized. - Instructions for making the installed software (30a, 60a) updatable and receiving software images (30b, 60b) loaded into the secure element (100) after the specific data (35a, 65a) is secured in the memory area (55), wherein the software images (30b, 60b) represent updates to the installed software (30a, 60a). - Instructions for making the software image (30b, 60b) operable by the secured specific data (35b, 65b) and / or personalizing the software image (30b, 60b) with the personalization data included in the specific data (35a, 65a). A computer program product comprising the above.
Citation Information
Patent Citations
Preserving trust data during operating system updates of a secure element of an electronic device
US20180089434A1