Nova Patents
CA2870503C

Secure zone for secure purchases

Abstract

An apparatus according to the present disclosure may comprise a secure zone configured to execute a task having a subtask. The task and subtask may have respective executable code and may be digitally signed by respective code providers. The secure zone may be further configured to apply respective sets of permissions while the respective executable code of the task and subtask are executed. The respective set of permissions for the task may be based on at least one of information associated with the signed task and information in a digital certificate of the respective code provider for the task. The respective set of permissions for the subtask may be based on at least one of information associated with the signed subtask and information in a digital certificate of the respective code provider for the subtask.

CA2870503C, drawing sheet 1
Sheet 1 of 6

Term

6.6 yearsleft in the term

Expires 20 April 2033.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

20 claims: 3 independent, 17 dependent

  1. 1
    The embodiments of the present invention for which an exclusive property or privilege is claimed are defined as follows:1. An apparatus, comprising: a secure zone comprising an interface to a non-secure zone, the secure zone further configured to: execute a task having one or more subtasks, wherein the task and the subtasks have respective executable code for one or more secure transactions, the task and the subtasks are digitally signed by respective code providers, and execution is switched between the task and the subtasks;and apply respective sets of permissions describing access to certain portions of the secure zone while the respective executable code of the task and the subtasks are executed, wherein the respective set of permissions for the task are based on at least one of information associated with the signed task and information in a digital certificate of the respective code provider for the task, and wherein the respective set of permissions for the subtasks are based on at least one of information associated with the signed subtasks and information in a digital certificate of the respective code provider for the subtasks.
  2. 11
    12. The apparatus of claim 11, further comprising a second indicator wherein the first and second indicators are configured to be both activated when the subtask is being executed by the secure zone.
  3. 12
    13. The apparatus of daim 1, further comprising a non-secure zone, wherein the secure zone is configured to use network capabilities of the non-secure zone to connect to a network.
  4. 14
    15. The apparatus of claim 14, wherein the temporary storage is further configured to store a secure hash of the data memory area used by the task when switching to execute the subtask. Date Reçue/Date Received 2020-05-15
  5. 17
    18. A method, comprising:executing, within a secure zone comprising an interface to a non-secure zone, a task having one or more subtasks, wherein the task and the subtasks have respective executable code for one or more secure transactions, the task and the subtasks are digitally signed by respective code providers, and execution is switched between the task and the subtasks;and applying respective sets of permissions describing access to certain portions of the secure zone while the respective executable code of the task and the subtasks are executed, wherein the respective set of permissions for the task are based on at least one of information associated with the signed task and information in a digital certificate of the respective code provider for the task, and wherein the respective set of permissions for the subtasks are based on at least one of infonnation associated with the signed subtasks and information in a digital certificate of the respective code provider for the subtasks. Date Reçue/Date Received 2020-05-15
  6. 18
    19. The method of claim 18, wherein the respective sets of permissions are contained inside respective digital certificates signed by respective certificate authorities.