Patents by Inventor Eric Vetillard

Eric Vetillard has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 10164963
    Abstract: A method may include receiving, by a hardware token from a client device, a chain of certificates including a server certificate and a first root certificate authority (CA) certificate. The method may further include determining, by the hardware token, to offload validation of one or more certificates in the chain of certificates to the client device, and verifying, by a cryptography application running in a memory of the hardware token, using a trusted root CA certificate stored in the hardware token, each certificate in the chain of certificates. The method may further include authenticating, by the hardware token and based on the verification, a public key of a server certificate, encrypting, by the cryptography application, a secret message using the authenticated public key of the server certificate to obtain an encrypted secret message, and sending, by the hardware token, the encrypted secret message to the client device.
    Type: Grant
    Filed: February 26, 2016
    Date of Patent: December 25, 2018
    Assignee: ORACLE INTERNATIONAL CORPORATION
    Inventors: Nicolas Ponsini, Eric Vetillard
  • Patent number: 9871821
    Abstract: A method for enforcing secure processes between a user and a device involves determining that the user has initiated installation of a secure application, installing the RA part of the secure application, triggering a trusted UI session upon realization that the TA part of the secure application is not installed, receiving, via the trusted UI session, user credentials for authenticating the user and enforcing user-specific and device-specific security, cryptographically signing combined user credentials with a cryptographic signature to obtain an authentication object, passing the authentication object to a service provider associated with the secure application for extraction of the user credentials, and generating an authorization token permitting the installation of the TA part of the secure application upon verification of the cryptographically signed authentication object.
    Type: Grant
    Filed: November 11, 2014
    Date of Patent: January 16, 2018
    Assignee: ORACLE INTERNATIONAL CORPORATION
    Inventors: Nicolas Ponsini, Eric Vetillard
  • Publication number: 20170118196
    Abstract: A method may include receiving, by a hardware token from a client device, a chain of certificates including a server certificate and a first root certificate authority (CA) certificate. The method may further include determining, by the hardware token, to offload validation of one or more certificates in the chain of certificates to the client device, and verifying, by a cryptography application running in a memory of the hardware token, using a trusted root CA certificate stored in the hardware token, each certificate in the chain of certificates. The method may further include authenticating, by the hardware token and based on the verification, a public key of a server certificate, encrypting, by the cryptography application, a secret message using the authenticated public key of the server certificate to obtain an encrypted secret message, and sending, by the hardware token, the encrypted secret message to the client device.
    Type: Application
    Filed: February 26, 2016
    Publication date: April 27, 2017
    Inventors: Nicolas Ponsini, Eric Vetillard
  • Publication number: 20160134660
    Abstract: A method for enforcing secure processes between a user and a device involves determining that the user has initiated installation of a secure application, installing the RA part of the secure application, triggering a trusted UI session upon realization that the TA part of the secure application is not installed, receiving, via the trusted UI session, user credentials for authenticating the user and enforcing user-specific and device-specific security, cryptographically signing combined user credentials with a cryptographic signature to obtain an authentication object, passing the authentication object to a service provider associated with the secure application for extraction of the user credentials, and generating an authorization token permitting the installation of the TA part of the secure application upon verification of the cryptographically signed authentication object.
    Type: Application
    Filed: November 11, 2014
    Publication date: May 12, 2016
    Inventors: Nicolas Ponsini, Eric Vetillard
  • Patent number: 9311588
    Abstract: The invention relates to a secure portable object of the smart card type comprising (a) an object body and (b) a micro-module comprising a processor and at least one memory in which a first application executed by a first execution engine in a first execution space is stored. The invention is characterized in that a second application is further stored in the said at least one memory, where the said second application is executed by a second execution engine distinct from the first execution engine, in a second execution space distinct from the first execution space. The invention particularly applies to smart cards.
    Type: Grant
    Filed: November 3, 2010
    Date of Patent: April 12, 2016
    Assignee: TRUSTED LOGIC
    Inventors: Nicolas Regnault, Eric Vetillard
  • Patent number: 8935746
    Abstract: A distributed trusted execution environment is provided for a device, where the distributed trusted execution environment is split into two components: a trusted execution environment that is executed on a tamper-resistant secure element, and a trusted execution environment proxy that is executed on the device. The trusted execution environment proxy acts a proxy between the trusted execution environment that is executed on the secure element, and one or more hardware components or software components of the device.
    Type: Grant
    Filed: April 22, 2013
    Date of Patent: January 13, 2015
    Assignee: Oracle International Corporation
    Inventor: Eric Vetillard
  • Publication number: 20140317686
    Abstract: A distributed trusted execution environment is provided for a device, where the distributed trusted execution environment is split into two components: a trusted execution environment that is executed on a tamper-resistant secure element, and a trusted execution environment proxy that is executed on the device. The trusted execution environment proxy acts a proxy between the trusted execution environment that is executed on the secure element, and one or more hardware components or software components of the device.
    Type: Application
    Filed: April 22, 2013
    Publication date: October 23, 2014
    Applicant: Oracle International Corporation
    Inventor: Eric VETILLARD
  • Publication number: 20120216276
    Abstract: The invention relates to a secure portable object of the smart card type comprising (a) an object body and (b) a micro-module comprising a processor and at least one memory in which a first application executed by a first execution engine in a first execution space is stored. The invention is characterised in that a second application is further stored in the said at least one memory, where the said second application is executed by a second execution engine distinct from the first execution engine, in a second execution space distinct from the first execution space. The invention particularly applies to smart cards.
    Type: Application
    Filed: November 3, 2010
    Publication date: August 23, 2012
    Applicant: TRUSTED LOGIC
    Inventors: Nicolas Regnault, Eric Vetillard
  • Patent number: 7865724
    Abstract: The invention relates to a user interface-equipped computing device comprising means for implementing a series of applications, said means including two execution spaces. According to the invention, the applications of the second execution space (100, P1, 200, P2) have a level of security specifically higher than that of the applications of the first execution space (100, P1, 200, P2), said two execution spaces being hosted by a physical processing means which is designed such that it cannot be separated into two parts without destroying the physical processing means.
    Type: Grant
    Filed: December 17, 2004
    Date of Patent: January 4, 2011
    Assignees: France Telecom, Trusted Logic
    Inventors: Cuihtlauac Alvarado, Jean-Bernard Blanchet, Laurent Frerebeau, Alexandre Frey, Eric Vetillard, Geoffroy Montel, Matthieu Maupetit
  • Patent number: 7827534
    Abstract: The inventive method for determining operational characteristics of a program includes a verification procedure involving the following stages: the first stage for expressing the operational characteristics of the program in the form of functions related to events producible during possible executions of the program, a second stage for simultaneously estimating, by program analysis, the program structure, the possible ways of execution and values used at different program points and the third stage for determining said characteristics by calculating associated functions by means of information extracted with the aid of the analysis.
    Type: Grant
    Filed: December 27, 2004
    Date of Patent: November 2, 2010
    Assignee: Trusted Logic
    Inventors: Eric Vetillard, Renaud Marlet
  • Publication number: 20080032668
    Abstract: The inventLion relates to a user interface-equppedi computing device comprising mneans for implementing a series of applicatiorm, said means including two execution spaces. According to the invention. the applications of the second execution space (100, P1, 200, P2) have a level of security specifically htigher than that of the applications of the first execution space (100, P1, 200, P2), said two execution spaces beino hosted by a physical processing means which is designed such that it carnnot be separated into two parts without destroying the physical processing means.
    Type: Application
    Filed: December 17, 2004
    Publication date: February 7, 2008
    Inventors: Cuihtlauac Alvarado, Jean-Bernard Blanchet, Laurent Frerebeau, Alexandre Frey, Eric Vetillard, Geoffroy Montel, Matthieu Maupetit
  • Publication number: 20070277168
    Abstract: The invention relates to a method for enabling a new version of an application to be loaded onto a computer processing device. According to said method, information on the correspondence (I1, I3, I4, I6) between the classes (A to D) of the old version of the application and the classes (A to F) of the new version of the application, and information about correspondence between the static fields of the old version of the application and static fields of the new version of the application, is calculated prior to the loading. Said correspondence information is then associated in order to modify the objects in such a way that they point towards classes of the new version and use the new identifiers of the static fields of the new version of the application.
    Type: Application
    Filed: December 22, 2004
    Publication date: November 29, 2007
    Applicant: Trusted Logic
    Inventor: Eric Vetillard
  • Patent number: 7275681
    Abstract: The customization or initialization of the application, for example in a programmable smart card, uses minimum integrated code. A device for preparing customizing or initializing data to be transmitted to the card creates a concatenation of information elements in respective adjacent data blocks in accordance with a convention recognized by a communication device, without explicit field specification. On reception of a data sequence, the card code identifies the information elements according to their size and their position in the flow.
    Type: Grant
    Filed: July 2, 2002
    Date of Patent: October 2, 2007
    Assignee: Gemplus
    Inventors: Jean-Jacques Vandewalle, Eric Vetillard
  • Publication number: 20070168987
    Abstract: The inventive method for determining operational characteristics of a program includes a verification procedure involving the following stages: the first stage for expressing the operational characteristics of the program in the form of functions related to events producible during possible executions of the program, a second stage for simultaneously estimating, by program analysis, the program structure, the possible ways of execution and values used at different program points and the third stage for determining said characteristics by calculating associated functions by means of information extracted with the aid of the analysis.
    Type: Application
    Filed: December 27, 2004
    Publication date: July 19, 2007
    Inventors: Eric Vetillard, Renaud Marlet
  • Publication number: 20050107069
    Abstract: In order to secure messages that are exchanged in a data transmission network between a server (1) and a client (2), a control device that is decentralized or represents the authority (3) is permanently inserted into the network between the server (1) and the user (2) during the secured exchange of messages. The representative of the authority (3) translated the transmitted messages and carries out the message verifications that have been decided by the authority. The representative of the authority (3) can be a specific microprocessor card, for example, which is permanently inserted between the server (1) and the client (2), so that the authority does not need to be directly involved in the transactions and no permanent connection with the authority is required.
    Type: Application
    Filed: January 31, 2003
    Publication date: May 19, 2005
    Inventor: Eric Vetillard
  • Publication number: 20040245331
    Abstract: The invention enables the customization or the initialization of an application for example in a programmable smart card (1) using minimum integrated code. Therefor, a device for preparing customizing or initializing data to be transmitted to the card comprises means (44, 46) designed to create concatenation (26) of information elements (Vi) in respective adjacent data blocks (Bi) scheduled in accordance with a convention recognised by said communication device, without explicit field specification. On reception of said data sequence, the card code identifies the information elements according to their size and their position in the flow.
    Type: Application
    Filed: July 1, 2004
    Publication date: December 9, 2004
    Inventors: Jean-Jacques Vandewalle, Eric Vetillard
  • Publication number: 20040154027
    Abstract: A method for managing communications between local and remote objects in an object oriented client server system in which a client application invokes a focal object as a proxy for a remote object on the server.
    Type: Application
    Filed: September 15, 2003
    Publication date: August 5, 2004
    Inventors: Jean-Jacques Vandewalle, Eric Vetillard, Patrick George