Method and system to enhance an executable load file (ELF) upgrade
The method and system enhance ELF upgrades in Secure Elements by using version tags to ensure compatibility and prevent downgrade or multiple upgrades, addressing security risks and configuration disruptions.
Patent Information
- Application Number
- PCT/EP2024/088435
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-29
- Filing Date
- 2024-12-24
- Publication Date
- 2025-07-03
AI Technical Summary
Existing methods for upgrading executable load files (ELFs) in Secure Elements do not adequately address version compatibility checks, leading to potential security risks and configuration disruptions during multiple upgrades.
A method and system that utilize a tag in the upgrade request to compare the new and current ELF versions, allowing for informed decisions on whether to proceed with the upgrade, saving data instances of the current ELF, and generating new instances based on these, ensuring compatibility and preventing downgrade or multiple upgrades.
Ensures secure and efficient ELF upgrades by maintaining configuration integrity and preventing downgrade or multiple upgrades, thereby reducing security risks and reconfiguration needs.
Smart Images

Figure EP2024088435_03072025_PF_FP_ABST
Abstract
Description
[0001] METHOD AND SYSTEM TO ENHANCE AN EXECUTABLE LOAD FILE (ELF)
[0002] UPGRADE
[0003] The invention relates to a system and a method to enhance an upgrade of executable load files (ELF) .
[0004] The ELFs are packages required for the installation and upgrade of applications on Secure Elements , where an ELF may contain one or more executable modules .
[0005] To install an application on the Secure Element , the ELF, which must have at least one executable module for the application, must first be loaded into the Secure Element and stored in it . An executable module is also referred to as an applet , which can be instantiated to one or more application instances .
[0006] The upgrade of a new ELF in the Secure Element is speci fied in the "GlobalPlat f orm Technology Executable Load File Upgrade Version 1 . 1" of the "Card Speci fication v2 . 3 - Amendment H" ( GP CS v2 . 3 - Amd H) .
[0007] SUMMARY
[0008] A method to enhance the ELF upgrade is provided, comprising the following steps : receiving a request for the ELF upgrade ; identi fying a tag in the request , the tag indicating a new ELF version intended to be loaded; determining that the new ELF version is newer, equal or lower than a current ELF version; take a decision based on the indicated new ELF version whether to continue with the upgrade process or stop the process i f for instance ELF downgrade ; saving data instances of a current ELF, the data instances corresponding to the ELF upgrade ; in response to saving the data instances of the current ELF, loading the ELF upgrade ; and in response to loading the ELF upgrade , generating data instances for the ELF upgrade , based at least in part on the saved data instances .
[0009] According to the invention, the tag in the request can be used to recogni ze and determine whether the upgrade should be carried out or not . The tag comprises the version of the new ELF to be loaded and can be compared with the current ELF in the Secure Element .
[0010] The decision as to whether the upgrade is carried out or not is made before the save phase , load phase and restore phase in accordance with GP CS v2 . 3 - Amd H .
[0011] According to an advantageous embodiment of the method according to the invention, it may be provided that the saving comprises : storing, in persistent memory, the data instances of the current ELF corresponding to the ELF upgrade , the data instances being configured to be restorable ; performing a cleanup operation to facilitate a deletion of the current ELF; and deleting the current ELF . Preferably, the persistent memory is persistent memory of a chip module .
[0012] Optionally advantageous according to the invention, it may be provided that the data instances include personali zed user information . The personali zed user information can be payment information of the card user . I f these are restored from the new and then current ELF after the upgrade , the personal user information and / or payment information of the payment card does not have to be reconfigured . In general , sensitive data can therefore be saved and restored . For example , the payment card can be used again quickly and without additional configuration after the ELF upgrade .
[0013] According to a particularly advantageous embodiment of the method according to the invention, it may be provided that the request comprises a byte configuration, the byte configuration comprising the tag indicating the new ELF version . Preferably, the byte configuration is in the MANAGE ELF UPGRADE command according to GP CS v2 . 3 - Amd H .
[0014] Preferably, according to a particular aspect of the method according to the invention, it can be provided that the tag is a C2 tag, as per ISO / IEC 7816-4 standards it has consideration of private class .
[0015] A system to enhance the ELF upgrade is provided, wherein the system comprises : a first processing component associated with a computing device ; a second processing component associated with a chip module ; and a memory storing instructions that , when executed by at least one of the first processing component or the second processing component , cause the system to perform a set of operation, the set of operations comprising : transmitting, via the first processing component , a request for the ELF upgrade ; receiving, at the second processing component , the request ; identi fying, via the second processing component , a tag in the request , the tag indicating a new ELF version intended to be loaded; determining, via the second processing component , that the new ELF version is newer than a current ELF version; saving, via the second processing component , data instances of a current ELF, the data instances corresponding to the ELF upgrade ; in response to saving the data instances of the current ELF, loading the ELF upgrade , from the computing device to the chip module ; in response to loading the ELF upgrade , generating, via the second processing component , data instances of the ELF upgrade , based at least in part on the saved data instances .
[0016] According to the invention, the system can use the identified tag to determine whether the actual upgrade should be carried out . The decision can be used to determine whether the current ELF should be replaced with the newer ELF .
[0017] According to an advantageous embodiment of the system according to the invention, it may be provided that the memory comprises persistent memory associated with the chip module , and wherein the saving comprises : storing, in the persistent memory, the data instances of the current ELF corresponding to the ELF upgrade , the data instances being configured to be restorable ; performing a cleanup operation to facilitate a deletion of the current ELF; and deleting the current ELF, from the memory .
[0018] According to an advantageous aspect of the system according to the invention, it may be provided that the request comprises a byte configuration, the byte configuration comprising the tag indicating the new ELF version . Preferably, the request corresponds to the MANAGE ELF UPGRADE command according to GP CS v2 . 3 - Amd H, wherein the tag is a C2 tag, per ISO / IEC 7816-4 standards .
[0019] DETAILED DESCRIPTION
[0020] The disclosed method and system, in accordance with one or more various embodiments , is described with reference to the following figures . The figures are provided for purposes of illustration only and merely depict examples of some embodiments of the disclosed method and system . These figures are provided to facilitate the reader ' s understanding of the disclosed method and system :
[0021] Fig . 1 is an illustration of a system with a first and a second processing component .
[0022] Fig . 2 is an illustration of a table according to GP CS v2 . 3 - Amd H .
[0023] The figures are not intended to be exhaustive or to limit the claimed invention to the precise form disclosed . It should be understood that the disclosed method and system can be practiced with modi fication and alteration, and that the invention should be limited only by the claims and the equivalents thereof .
[0024] Fig . 1 shows a system 1 with a first processing component 2 , which has a computing device 3 , and a second processing component 4 with a chip module 5 . Both are connected by means of a communication channel and can exchange data 6 with each other by means of a set of operations 7 , 8 , 9 , 10 , 11 .
[0025] For example , i f a smart card has security-critical applications and sensitive data, as is the case with payment cards , a Secure Element is used to store the sensitive data . The Secure Element is a tamper-proof chip module 5 that has a secure storage and execution environment (virtual machine ) with which application code and application data can be securely stored, managed and executed . The Secure Element allows access to the sensitive data stored on the card only when access is authori zed .
[0026] In a first operation 7 , the first processing component 2 transmits a request for an ELF upgrade to the second processing component 4 . A MANAGE ELF UPGRADE command is transmitted in accordance with GP CS v2 . 3 - Amd H, which has a tag that the second processing component 4 can use to check a version of a new ELF that the first processing component 2 intends to transmit by means of the ELF upgrade .
[0027] Based on the tag in the MANAGE ELF UPGRADE command and the version of the new ELF it contains , the second processing component 4 can determine in a second operation 8 whether the ELF upgrade should be carried out . I f the version of the new ELF is less than or equal to a version of the current ELF that is stored in the chip module 5 of the second processing component 4 , the second processing component 4 rej ects the requested ELF update .
[0028] Disclosed is also an aspect , wherein the request for the ELF upgrade is received from a computing device 3 comprising a processor and memory, and wherein the ELF upgrade is loaded from the memory of the computing device 3 , via the processor of the ELF upgrade .
[0029] I f an upgrade is to be carried out , the version of the new ELF must be higher than that of the current ELF, which corresponds to the ELF upgrade . I f a downgrade is to be carried out , the version of the new ELF must be lower . This includes saving personali zed data from the current ELF that corresponds to the ELF upgrade and creating data instances for the ELF upgrade before the cleanup . At least partially, the configuration prior to the upgrade can be restored based on the saved data instances after loading the ELF upgrade .
[0030] In addition, an upgrade can be prevented i f the version of the new ELF and the current ELF that is still loaded in the Secure Element match . Multiple upgrades are not possible according to the invention, so that a targeted disruption of the upgrade by multiple upgrade processes in succession can no longer lead to security risks .
[0031] On the one hand, constellations may occur during the upgrade in which the current ELF has already been deleted in the Secure Element , but the new ELF could not be loaded into the Secure Element in a fully executable manner ; on the other hand, GP CS v2 . 3 - Amd H does not speci fy how a multiple upgrade of the new ELF can be prevented . Constellations of the above-mentioned type can lead to di f ficulties in restoring the original configuration before the upgrade and to security risks .
[0032] I f the version in the tag of the first ELF is greater than the version of the current ELF, the second processing component 4 initiates the saving of data instances of the current ELF in a third operation 9 . The data instances correspond to the requested ELF upgrade and are stored in a permanent memory of the two processing components 2 , 4 .
[0033] Saving the data instances of the current ELF enables the new ELF to load and adopt the data instances of the current ELF . This means that the configurations and data of the current ELF are not also deleted after the ELF upgrade , so that the Secure Element does not have to be reconfigured after the ELF upgrade .
[0034] The two processing components 2 , 4 then trans fer the ELF upgrade in a fourth operation 10 , whereby the first ELF is trans ferred to the second processing component 4 and the current ELF is deleted in the second processing component 4 . Deletion can happen j ust after the save phase , there are two possibilities :
[0035] - First option, i f the new ELF has a di f ferent AID than the current ELF, deletion occurs after installing the new ELF . This requires extra memory to have both ELF loaded at the same time . - Second option, the new ELF and current ELF have the same AIDs , deletion occurs right after current ELF saves its data .
[0036] In a fourth operation 11 , the data of the ELF upgrade is restored based on the data instances of the new ELF and the first ELF . After the current ELF has been deleted - which can also happen in save phase - , instances of the new ELF can be recreated using the data instances of the current ELF in the permanent memory according to the ELF upgrade . A configuration of the current ELF can be restored and does not have to be reconfigured in the new ELF . Preferably, it can be provided that the data instances include personali zed user information .
[0037] Fig . 2 shows that the MANAGE ELF UPGRADE command 12 comprises an Al tag 12 in the data field, which prompts the second processing component 4 to upgrade the current ELF by means of an AID . According to the invention, the second processing component 4 can check the version of the new ELF based on a C2 tag 14 according to the ISO / IEC 7816-4 standard, which is inserted immediately after an 81 tag 15 of the Al tag 13 and determine whether the ELF upgrade is to be carried out .
[0038] The C2 tag 14 lends itsel f for this purpose as a proprietary tag, whereby this is inserted in the MANAGE ELF UPGRADE command in accordance with GP CS v2 . 3 Amd H in the Al tag 13 directly or indirectly after the 81 tag 15 . Accordingly, i f the Secure Element can receive a C2 tag 14 during and / or at the beginning of the upgrade process after the 81 tag 15 of the Al tag 13 , it is possible to determine and compare the versions of the new ELF and the current ELF corresponding to the ELF upgrade .
[0039] Preferably, the C2 tag 14 can be inserted directly and indirectly after the 81 tag 15 of the Al tag 13 of the MANAGE ELF UPGRADE command, so that the second processing component 4 can determine whether the ELF upgrade is to be carried out before the current ELF is replaced with the new ELF . Since the 81 tag is optional , it is also conceivable i f the C2 tag follows the last mandatory field (AID of old ELF version) . It is only essential that it is located in the Al field i f it is present . For this purpose , the C2 tag can have the version of the new ELF, which can be compared with the version of the current ELF .
Claims
Claims1 . A method to enhance executable load file upgrade , the method comprising : receiving a request for the ELF upgrade ; identi fying a tag in the request , the tag indicating a new ELF version intended to be loaded; determining that the new ELF version is newer, equal or lower than a current ELF version; take a decision based on the indicated new ELF version whether to continue with the upgrade process or stop the process i f for instance ELF downgrade ; saving data instances of a current ELF, the data instances corresponding to the ELF upgrade ; in response to saving the data instances of the current ELF, loading the ELF upgrade ; and in response to loading the ELF upgrade , generating data instances for the ELF upgrade , based at least in part on the saved data instances .2 . A method according to claim 1 , wherein the saving comprises : storing, in persistent memory, the data instances of the current ELF corresponding to the ELF to be upgraded, the data instances being configured to be restorable ; performing a cleanup operation ( 9 ) to facilitate a deletion of the current ELF; and deleting the current ELF .3 . A method according to claim 2 , wherein the persistent memory is persistent memory of a chip module ( 5 ) .
4. A method according to one of the claims 1 to 3, wherein the data instances include personalized information .
5. A method according to one of the preceding claims, wherein the request comprises a byte configuration (13) , the byte configuration (13) comprising the tag indicating the new ELF version.
6. A method according to one of the preceding claims, wherein the tag is a C2 tag (14) , as per ISO / IEC 7816-4 standards it has consideration of private class.
7. A method according to one of the preceding claims, wherein the request for the ELF upgrade is received from a computing device comprising a processor and memory, and wherein the ELF upgrade is loaded from the memory of the computing device, via the processor of the ELF upgrade.
8. A system (1) to enhance an executable load file upgrade, the system (1) comprising: a first processing component (2) associated with a computing device (3) ; a second processing component (4) associated with a chip module (5) ; and a memory storing instructions that, when executed by at least one of the first processing component (2) or the second processing component (4) , cause the system (1) to perform a set of operation (7, 8, 9, 10, 11) , the set of operations (7, 8, 9, 10, 11) comprising: transmitting, via the first processing component (2) , a request for the ELF upgrade;receiving, at the second processing component( 4 ) , the request ; identifying, via the second processing component (4) , a tag in the request, the tag indicating a new ELF version intended to be loaded; determining, via the second processing component (4) , that the new ELF version is newer than a current ELF version; saving, via the second processing component (4) , data instances of a current ELF, the data instances corresponding to the ELF upgrade; in response to saving the data instances of the current ELF, loading the ELF upgrade, from the computing device (3) to the chip module (5; in response to loading the ELF upgrade, generating, via the second processing component (4) , data instances of the ELF upgrade, based at least in part on the saved data instances.
9. A system (1) according to claim 8, wherein the memory comprises persistent memory associated with the chip module (5) , and wherein the saving comprises: storing, in the persistent memory, the data instances of the current ELF corresponding to the ELF upgrade, the data instances being configured to be restorable; performing a cleanup operation (9) to facilitate a deletion of the current ELF; and deleting the current ELF, from the memory.
10. A system (1) according to one of the claims 8 to 9, wherein the data instances include personalized information .
11. A system (1) according to one of the claims 8 to 10, wherein the request comprises a byte configuration (13) , the byte configuration (13) comprising the tag indicating the new ELF version.
12. A system (1) according to one of the claims 8 to 11, wherein the tag is a C2 tag (14) , per ISO / IEC 7816-4 standards .
Citation Information
Patent Citations
Replacement of executable load files in secure elements
WO2023285399A1