Patents by Inventor Eric Vetillard
Eric Vetillard has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 10164963Abstract: A method may include receiving, by a hardware token from a client device, a chain of certificates including a server certificate and a first root certificate authority (CA) certificate. The method may further include determining, by the hardware token, to offload validation of one or more certificates in the chain of certificates to the client device, and verifying, by a cryptography application running in a memory of the hardware token, using a trusted root CA certificate stored in the hardware token, each certificate in the chain of certificates. The method may further include authenticating, by the hardware token and based on the verification, a public key of a server certificate, encrypting, by the cryptography application, a secret message using the authenticated public key of the server certificate to obtain an encrypted secret message, and sending, by the hardware token, the encrypted secret message to the client device.Type: GrantFiled: February 26, 2016Date of Patent: December 25, 2018Assignee: ORACLE INTERNATIONAL CORPORATIONInventors: Nicolas Ponsini, Eric Vetillard
-
Patent number: 9871821Abstract: A method for enforcing secure processes between a user and a device involves determining that the user has initiated installation of a secure application, installing the RA part of the secure application, triggering a trusted UI session upon realization that the TA part of the secure application is not installed, receiving, via the trusted UI session, user credentials for authenticating the user and enforcing user-specific and device-specific security, cryptographically signing combined user credentials with a cryptographic signature to obtain an authentication object, passing the authentication object to a service provider associated with the secure application for extraction of the user credentials, and generating an authorization token permitting the installation of the TA part of the secure application upon verification of the cryptographically signed authentication object.Type: GrantFiled: November 11, 2014Date of Patent: January 16, 2018Assignee: ORACLE INTERNATIONAL CORPORATIONInventors: Nicolas Ponsini, Eric Vetillard
-
Publication number: 20170118196Abstract: A method may include receiving, by a hardware token from a client device, a chain of certificates including a server certificate and a first root certificate authority (CA) certificate. The method may further include determining, by the hardware token, to offload validation of one or more certificates in the chain of certificates to the client device, and verifying, by a cryptography application running in a memory of the hardware token, using a trusted root CA certificate stored in the hardware token, each certificate in the chain of certificates. The method may further include authenticating, by the hardware token and based on the verification, a public key of a server certificate, encrypting, by the cryptography application, a secret message using the authenticated public key of the server certificate to obtain an encrypted secret message, and sending, by the hardware token, the encrypted secret message to the client device.Type: ApplicationFiled: February 26, 2016Publication date: April 27, 2017Inventors: Nicolas Ponsini, Eric Vetillard
-
Publication number: 20160134660Abstract: A method for enforcing secure processes between a user and a device involves determining that the user has initiated installation of a secure application, installing the RA part of the secure application, triggering a trusted UI session upon realization that the TA part of the secure application is not installed, receiving, via the trusted UI session, user credentials for authenticating the user and enforcing user-specific and device-specific security, cryptographically signing combined user credentials with a cryptographic signature to obtain an authentication object, passing the authentication object to a service provider associated with the secure application for extraction of the user credentials, and generating an authorization token permitting the installation of the TA part of the secure application upon verification of the cryptographically signed authentication object.Type: ApplicationFiled: November 11, 2014Publication date: May 12, 2016Inventors: Nicolas Ponsini, Eric Vetillard
-
Patent number: 9311588Abstract: The invention relates to a secure portable object of the smart card type comprising (a) an object body and (b) a micro-module comprising a processor and at least one memory in which a first application executed by a first execution engine in a first execution space is stored. The invention is characterized in that a second application is further stored in the said at least one memory, where the said second application is executed by a second execution engine distinct from the first execution engine, in a second execution space distinct from the first execution space. The invention particularly applies to smart cards.Type: GrantFiled: November 3, 2010Date of Patent: April 12, 2016Assignee: TRUSTED LOGICInventors: Nicolas Regnault, Eric Vetillard
-
Patent number: 8935746Abstract: A distributed trusted execution environment is provided for a device, where the distributed trusted execution environment is split into two components: a trusted execution environment that is executed on a tamper-resistant secure element, and a trusted execution environment proxy that is executed on the device. The trusted execution environment proxy acts a proxy between the trusted execution environment that is executed on the secure element, and one or more hardware components or software components of the device.Type: GrantFiled: April 22, 2013Date of Patent: January 13, 2015Assignee: Oracle International CorporationInventor: Eric Vetillard
-
Publication number: 20140317686Abstract: A distributed trusted execution environment is provided for a device, where the distributed trusted execution environment is split into two components: a trusted execution environment that is executed on a tamper-resistant secure element, and a trusted execution environment proxy that is executed on the device. The trusted execution environment proxy acts a proxy between the trusted execution environment that is executed on the secure element, and one or more hardware components or software components of the device.Type: ApplicationFiled: April 22, 2013Publication date: October 23, 2014Applicant: Oracle International CorporationInventor: Eric VETILLARD
-
Publication number: 20120216276Abstract: The invention relates to a secure portable object of the smart card type comprising (a) an object body and (b) a micro-module comprising a processor and at least one memory in which a first application executed by a first execution engine in a first execution space is stored. The invention is characterised in that a second application is further stored in the said at least one memory, where the said second application is executed by a second execution engine distinct from the first execution engine, in a second execution space distinct from the first execution space. The invention particularly applies to smart cards.Type: ApplicationFiled: November 3, 2010Publication date: August 23, 2012Applicant: TRUSTED LOGICInventors: Nicolas Regnault, Eric Vetillard
-
Patent number: 7865724Abstract: The invention relates to a user interface-equipped computing device comprising means for implementing a series of applications, said means including two execution spaces. According to the invention, the applications of the second execution space (100, P1, 200, P2) have a level of security specifically higher than that of the applications of the first execution space (100, P1, 200, P2), said two execution spaces being hosted by a physical processing means which is designed such that it cannot be separated into two parts without destroying the physical processing means.Type: GrantFiled: December 17, 2004Date of Patent: January 4, 2011Assignees: France Telecom, Trusted LogicInventors: Cuihtlauac Alvarado, Jean-Bernard Blanchet, Laurent Frerebeau, Alexandre Frey, Eric Vetillard, Geoffroy Montel, Matthieu Maupetit
-
Patent number: 7827534Abstract: The inventive method for determining operational characteristics of a program includes a verification procedure involving the following stages: the first stage for expressing the operational characteristics of the program in the form of functions related to events producible during possible executions of the program, a second stage for simultaneously estimating, by program analysis, the program structure, the possible ways of execution and values used at different program points and the third stage for determining said characteristics by calculating associated functions by means of information extracted with the aid of the analysis.Type: GrantFiled: December 27, 2004Date of Patent: November 2, 2010Assignee: Trusted LogicInventors: Eric Vetillard, Renaud Marlet
-
Publication number: 20080032668Abstract: The inventLion relates to a user interface-equppedi computing device comprising mneans for implementing a series of applicatiorm, said means including two execution spaces. According to the invention. the applications of the second execution space (100, P1, 200, P2) have a level of security specifically htigher than that of the applications of the first execution space (100, P1, 200, P2), said two execution spaces beino hosted by a physical processing means which is designed such that it carnnot be separated into two parts without destroying the physical processing means.Type: ApplicationFiled: December 17, 2004Publication date: February 7, 2008Inventors: Cuihtlauac Alvarado, Jean-Bernard Blanchet, Laurent Frerebeau, Alexandre Frey, Eric Vetillard, Geoffroy Montel, Matthieu Maupetit
-
Publication number: 20070277168Abstract: The invention relates to a method for enabling a new version of an application to be loaded onto a computer processing device. According to said method, information on the correspondence (I1, I3, I4, I6) between the classes (A to D) of the old version of the application and the classes (A to F) of the new version of the application, and information about correspondence between the static fields of the old version of the application and static fields of the new version of the application, is calculated prior to the loading. Said correspondence information is then associated in order to modify the objects in such a way that they point towards classes of the new version and use the new identifiers of the static fields of the new version of the application.Type: ApplicationFiled: December 22, 2004Publication date: November 29, 2007Applicant: Trusted LogicInventor: Eric Vetillard
-
Patent number: 7275681Abstract: The customization or initialization of the application, for example in a programmable smart card, uses minimum integrated code. A device for preparing customizing or initializing data to be transmitted to the card creates a concatenation of information elements in respective adjacent data blocks in accordance with a convention recognized by a communication device, without explicit field specification. On reception of a data sequence, the card code identifies the information elements according to their size and their position in the flow.Type: GrantFiled: July 2, 2002Date of Patent: October 2, 2007Assignee: GemplusInventors: Jean-Jacques Vandewalle, Eric Vetillard
-
Publication number: 20070168987Abstract: The inventive method for determining operational characteristics of a program includes a verification procedure involving the following stages: the first stage for expressing the operational characteristics of the program in the form of functions related to events producible during possible executions of the program, a second stage for simultaneously estimating, by program analysis, the program structure, the possible ways of execution and values used at different program points and the third stage for determining said characteristics by calculating associated functions by means of information extracted with the aid of the analysis.Type: ApplicationFiled: December 27, 2004Publication date: July 19, 2007Inventors: Eric Vetillard, Renaud Marlet
-
Publication number: 20050107069Abstract: In order to secure messages that are exchanged in a data transmission network between a server (1) and a client (2), a control device that is decentralized or represents the authority (3) is permanently inserted into the network between the server (1) and the user (2) during the secured exchange of messages. The representative of the authority (3) translated the transmitted messages and carries out the message verifications that have been decided by the authority. The representative of the authority (3) can be a specific microprocessor card, for example, which is permanently inserted between the server (1) and the client (2), so that the authority does not need to be directly involved in the transactions and no permanent connection with the authority is required.Type: ApplicationFiled: January 31, 2003Publication date: May 19, 2005Inventor: Eric Vetillard
-
Publication number: 20040245331Abstract: The invention enables the customization or the initialization of an application for example in a programmable smart card (1) using minimum integrated code. Therefor, a device for preparing customizing or initializing data to be transmitted to the card comprises means (44, 46) designed to create concatenation (26) of information elements (Vi) in respective adjacent data blocks (Bi) scheduled in accordance with a convention recognised by said communication device, without explicit field specification. On reception of said data sequence, the card code identifies the information elements according to their size and their position in the flow.Type: ApplicationFiled: July 1, 2004Publication date: December 9, 2004Inventors: Jean-Jacques Vandewalle, Eric Vetillard
-
Publication number: 20040154027Abstract: A method for managing communications between local and remote objects in an object oriented client server system in which a client application invokes a focal object as a proxy for a remote object on the server.Type: ApplicationFiled: September 15, 2003Publication date: August 5, 2004Inventors: Jean-Jacques Vandewalle, Eric Vetillard, Patrick George