发明名称 METHOD OF ENFORCING CONTROL OF ACCESS BY A DEVICE TO A SECURE ELEMENT, AND CORRESPONDING SECURE ELEMENT
摘要 A method of enforcing control of access by a hosting device to a secure element, and a secure element are described. The method includes steps performed by the secure element: receiving a request for retrieving at least one access rule controlling access to at least one application of the secure element, from access rules stored in the secure element; outputting at least one access rule retrieved from the stored access rules, wherein an access rule controlling access to an application of the secure element is retrieved by searching only in access rules stored in a security domain to which the application belongs in the secure element, or an access rule controlling access to an application of the secure element is stored only in a security domain to which the application belongs in the secure element.
申请公布号 US2015026759(A1) 申请公布日期 2015.01.22
申请号 US201414331321 申请日期 2014.07.15
申请人 KRISNA Balamurali;LESTARI Dewi;SETIAWAN Eric 发明人 KRISNA Balamurali;LESTARI Dewi;SETIAWAN Eric
分类号 G06F21/53 主分类号 G06F21/53
代理机构 代理人
主权项 1. A method of enforcing control of access by a device to a secure element hosted in the device, the secure element comprising a master security domain and at least one other security domain, each security domain storing one or more access rules, each access rule identifying at least one application of the secure element to control access to the application, the method comprising the following steps performed by an access rule application of the master security domain of the secure element: receiving a request from the hosting device, for retrieving at least one access rule controlling access to at least one application of the secure element, from access rules stored in the secure element, the request including an identifier identifying the at least one application; outputting, to the hosting device, at least one access rule retrieved from the stored access rules, wherein the method further comprises enforcing the output access rule by an access control enforcer of the hosting device; characterized in that the method further comprises the following steps performed by the access rule application of the master security domain of the secure element, upon receiving the request: first determining, based on the identifier identifying the application in the request, a security domain to which the application belongs in the secure element from amongst the security domains of the secure element, and then, requesting only the determined security domain to search for an access rule identifying the application to control access to the application, only in the access rules stored in the determined security domain.
地址 South Jakarta Selatan ID