Method and device for managing information exchange between a main element, for example a NFC controller, and a set of at least two auxiliary elements
10244372 ยท 2019-03-26
Assignee
Inventors
- Pierre Rizzo (Trets, FR)
- Alexandre Charles (Auriol, FR)
- Juergen Boehler (Munich, DE)
- Thierry Meziache (St Maximin la Sainte Baume, FR)
Cpc classification
H04W4/80
ELECTRICITY
G06K7/10247
PHYSICS
G06K7/0008
PHYSICS
International classification
H04L12/66
ELECTRICITY
H04B5/00
ELECTRICITY
G06K7/00
PHYSICS
G06K7/10
PHYSICS
Abstract
Device, comprising a main element (ME) and a set of at least two auxiliary elements (SEi), said main element including a master SWP interface (MINT), each auxiliary element including a slave SWP interface (SLINTi) connected to said master SWP interface of said NFC element through a controllably switchable SWP link (LK) and management means (PRM, CTLM, AMGi) configured to control said SWP link switching for selectively activating at once only one slave SWP interface on said SWP link.
Claims
1. A method of managing information to be exchanged between a main element having a master switchable single wire protocol (SWP) interface and a plurality of auxiliary elements, each auxiliary element having a slave SWP interface, the method comprising: operating an SWP switch to selectively define an SWP link between only one slave SWP interface and the master SWP interface at any given time, and activate only the one slave SWP interface at the any given time; the SWP switch comprising a first terminal coupled to the master SWP interface, and a plurality of second terminals coupled to respective ones of the plurality of slave SWP interfaces, and the SWP switch configured to electrically couple the first terminal to a respective second terminal of only the one SWP slave interface at the any given time and to simultaneously electrically decouple the first terminal from other ones of the plurality of second terminals at the any given time, wherein each of the plurality of auxiliary elements operates in a first power mode, or only one auxiliary element operates in a second power mode while each other auxiliary element is in an OFF state, or a first auxiliary element operates in the second power mode, wherein the second power mode has a power value lower than a power value of the first power mode, and wherein the SWP switch is configured to select the only one auxiliary element when the only one auxiliary element operates in the second power mode.
2. The method according to claim 1, wherein the main element comprises a contactless element configured as a near field communication (NFC) controller, and each auxiliary element is configured as a secure element containing protected information.
3. The method according to claim 1, further comprising forcing a part of the SWP link between each non-selected slave SWP interface and the SWP switch in a deactivated state.
4. The method according to claim 3, further comprising controlling switching of the SWP switch when the SWP link is in a deactivated state.
5. The method according to claim 1, wherein when the first auxiliary element operates in the second power mode, the first auxiliary element controls the SWP switch for selecting the first auxiliary element.
6. The method according to claim 5, further comprising storing in the first auxiliary element a configuration indication, with the first auxiliary element controlling the SWP switch by using the configuration indication.
7. The method according to claim 6, wherein the configuration indication is stored in the first auxiliary element when each of the plurality of auxiliary elements operates in the first power mode.
8. The method according to claim 5, wherein when the first auxiliary element operates in the second power mode, the first auxiliary element controls powering of each other auxiliary element to place each other auxiliary element in the OFF state, and controls the SWP switch for selecting the first auxiliary element when operating in the second power mode.
9. The method according to claim 5, wherein when the first auxiliary element operates in the second power mode, the first auxiliary element controls powering of a second auxiliary element configured to permit the second auxiliary element to operate in the second power mode, and the first auxiliary element controls the SWP switch for selecting the second auxiliary element operating in the second power mode.
10. The method according to claim 9, further comprising storing in the first auxiliary element a configuration indication, with the first auxiliary element controlling the SWP switch by using the configuration indication, and wherein the first auxiliary element controls the powering of the second auxiliary element based on the configuration indication.
11. A device comprising: a main element comprising a master single wire protocol (SWP) interface; a plurality of auxiliary elements, each comprising a respective slave SWP interface; an SWP switch comprising a first terminal coupled to the master SWP interface, and a plurality of second terminals coupled to respective ones of the plurality of slave SWP interfaces, the SWP switch configured to electrically couple the first terminal to a respective second terminal of only one SWP slave interface at any given time and to simultaneously electrically decouple the first terminal from remaining ones of the plurality of second terminals at the any given time; and management circuitry configured to operate the SWP switch to selectively define an SWP link between the only one slave SWP interface and the master SWP interface at the any given time, and activate the only one slave SWP interface at the any given time, wherein each of the plurality of auxiliary elements operates in a first power mode, or only one auxiliary element operates in a second power mode while each other auxiliary element is in an OFF state, or a first auxiliary element operates in the second power mode, wherein the second power mode has a power value lower than a power value of the first power mode, and wherein the management circuitry is configured to operate the SWP switch to select the only one auxiliary element when the only one auxiliary element operates in the second power mode.
12. The device according to claim 11, wherein said management circuitry comprises a controller configured to control the SWP switch.
13. The device according to claim 12, wherein the controller is co-located with the main element.
14. The device according to claim 12, wherein said management circuitry comprises a processor configured to place said SWP link in a deactivated state; and wherein said controller controls said SWP switch after said processor places said SWP link in a deactivated state.
15. The device according to claim 11, further comprising first forcing circuitry configured to force a part of the SWP link coupled between each non-selected slave SWP interface and said SWP switch in a deactivated state.
16. The device according to claim 15, wherein said first forcing circuitry comprises a plurality of pull-down resistors respectively coupled between said plurality of parts of said SWP link and a reference voltage.
17. The device according to claim 15, wherein each of said plurality of auxiliary elements operates in the first power mode, or only one auxiliary element operates in the second power mode while each other auxiliary element is in the OFF state, the device further comprising a second forcing circuitry configured to force said SWP link into a configuration allowing selection of the only one auxiliary element when in the second power mode.
18. The device according to claim 17, wherein said second forcing circuitry comprises a pull-down resistor coupled between a control input of said SWP switch and a voltage reference.
19. The device according to claim 11, wherein each of said plurality of auxiliary elements operates in a first power mode, or a first auxiliary element operates in a second power mode, the device further comprising an auxiliary selector configured to control switching of said SWP switch for selecting said first auxiliary element when operating in the second power mode.
20. The device according to claim 19, wherein said auxiliary selector comprises: an auxiliary memory for storing a configuration indication; and an auxiliary controller configured to control switching of said SWP switch based on the configuration indication.
21. The device according to claim 20, wherein said auxiliary selector further comprises an auxiliary input for providing the configuration indication to said auxiliary memory when said plurality of auxiliary elements are in the first power mode.
22. The device according to claim 19, wherein said auxiliary selector controls powering OFF of each other auxiliary element when the first auxiliary element is operating in the second power mode, and selection of said first auxiliary element when operating in the second power mode.
23. The device according to claim 19, wherein said auxiliary selector controls powering of a second auxiliary element configured to permit said second auxiliary element to operate in the second power mode, and to select said second element when operating in the second power mode.
24. The device according to claim 23, wherein said auxiliary selector comprises an auxiliary power controller configured to control powering of said second auxiliary element based on the configuration indication.
25. The device according to claim 11, wherein at least one auxiliary element is co-located with said main element.
26. The device according to claim 11, wherein at least one auxiliary element is removably coupled to said main element.
27. The device according to claim 11, wherein said main element comprises a contactless element configured as a near field communication (NFC) controller, and each auxiliary element is configured as a secure element containing protected information.
28. An apparatus comprising: an antenna; and a device coupled to said antenna comprising a main element comprising a master single wire protocol (SWP) interface, a plurality of auxiliary elements, each comprising a respective slave SWP interface, an SWP switch comprising a first terminal coupled to the master SWP interface, and a plurality of second terminals coupled to respective ones of the plurality of slave SWP interfaces, the SWP switch configured to electrically couple the first terminal to a respective second terminal of only one SWP slave interface at any given time and to simultaneously electrically disconnect the first terminal from other ones of the plurality of second terminals at the any given time, and management circuitry configured to operate the SWP switch to selectively define an SWP link between the only one slave SWP interface and the master SWP interface at the any given time, and activate the only one slave SWP interface at the any given time, wherein each of the plurality of auxiliary elements operates in a first power mode, or only one auxiliary element operates in a second power mode while each other auxiliary element is in an OFF state, or a first auxiliary element operates in the second power mode, wherein the second power mode has a power value lower than a power value of the first power mode, and wherein the management circuitry is configured to operate the SWP switch to select the only one auxiliary element when the only one auxiliary element operates in the second power mode.
29. The apparatus according to claim 28, wherein said management circuitry comprises a controller configured to control said SWP switch.
30. The apparatus according to claim 29, wherein the controller is co-located with the main element.
31. The apparatus according to claim 28, further comprising first forcing circuitry configured to force a part of the SWP link coupled between each non-selected slave SWP interface and said SWP switch in a deactivated state.
32. The apparatus according to claim 28, wherein at least one auxiliary element is removably coupled to said main element.
33. The apparatus according to claim 28, wherein said main element comprises a contactless element configured as a near field communication (NFC) controller, and each auxiliary element is configured as a secure element containing protected information.
34. The apparatus according to claim 28, wherein said antenna and said device are configured to operate as a wireless communications device.
Description
(1) Other advantages and features of the invention will appear on examining the detailed description of embodiments, these being no way limiting, and of the appended drawings in which:
(2)
(3)
(4)
(5)
(6)
(7)
(8)
(9)
(10) Embodiments of the invention will be now described in the technical field of contactless elements or components connected to secure elements, in particular embedded in a mobile phone, although the invention is not limited to these particulars embodiments.
(11) A contactless element is an element or a component able to exchange information through an antenna with a contactless device according to contactless communication protocol.
(12) A NFC element or component, which is a contactless element, is an element or component compliant with the NFC technology.
(13) In
(14) The device comprises also here two auxiliary elements or secure elements. Each secure element SE1 (SE2) comprises a SWP interface SLINT 1 (SLINT 2). Each SWP interface SLINTi is connected to the same SWP interface MINT of the NFC controller ME through a controllably switchable SWP link LK.
(15) A secure element is for example an element adapted to contain secure or protected information, for example banking information, information related to telephone subscription . . . .
(16) Each SWP interface SLINTi comprises auxiliary management means AMGi while the SWP interface MINT of the NFC controller ME comprises processing means PRM.
(17) The NFC controller ME is coupled to an antenna ANT1 for exchanging information with a contactless reader by using a contactless communication protocol, for example the one disclosed in ISO/IEC 14443.
(18) The Single Wire Protocol (SWP) is a bit oriented, point-to-point communication protocol between a secure element and a contactless front end, and is specified in the standard ETSI TS 102 613, for example the version V7.7.0 (2009-10) thereof. The man skilled in the art could refer if necessary to this document, the content thereof being incorporated by reference in the present patent application.
(19) More precisely, as illustrated in
(20) A SWP link is a link or line adapted to support the Single Wire Protocol (SWP)
(21) As disclosed in ETSI TS 102 613, the principle of the single wire protocol (SWP) is based on the transmission of digital information in full duplex mode. The signal S1 from ME to SE is transmitted by a digital modulation (L or H) in the voltage domain whereas the signal S2 from SE to ME is transmitted by a digital modulation (L or H) in the current domain.
(22) When the master sends S1 as state H then the slave may either draw a current (state H) or not (state L) and thus transmits S2. With pulse width modulation bit coding of S1, it is possible to transmit a transmission clock, as well as data in full duplex mode. More details can be found in ETSI TS 102 613.
(23)
(24) The SWP protocol specified in ETSI TS 102 613 permits only the communication between the master SWP interface of the contactless element and a single slave SWP interface of a single secure element.
(25) According to an aspect of the invention which will be now described more in details, it will be possible to connect two or more than two auxiliary elements or secure elements SEi provided with a SWP-UICC technology to a single master SWP interface of a contactless element, for example a NFC controller.
(26) More precisely, if we refer again to
(27) Here, the processing means PRM, the control means CTLM and the auxiliary management means AMGi form management means configured to control the SWP link switching for selectively activating at once only one selected slave SWP interface on said SWP link.
(28) The management means and the control means may be realized by software module and at least partly by logic circuit.
(29) In the present embodiment, where only two auxiliary elements are used, the multiplexer/demultiplexer switch SW has a first terminal T1 coupled to said master SWP interface MINT though a first part LK1 of said SWP link LK and two second terminals T20 and T2 respectively coupled to said two slave SWP interfaces SLINT1, SLINT2 through two second parts LK20, LK21 of said SWP link.
(30) Of course, although the parts LK1, LK20 and LK21 have been represented here by wires between the terminals T1, T20, T21 and the corresponding terminals of the SWP interfaces, these parts may be reduced to the minimum if for example the terminals T1, T20, T21 respectively meet the corresponding terminals of the SWP interfaces.
(31) The switch SW further comprises a control terminal T3 connected to the control means CTLM for receiving a control signal SWCTRL for switching the first terminal T1 to either the second terminal T20 or the second terminal T21, depending on the logic value of the control signal.
(32) For example, as illustrated in
(33) As defined in ETSI TS 102 613, a SWP link may have an activated state, a suspended state and a deactivated state.
(34) More precisely, in the activated state, the master element and the selected auxiliary element are sending bits
(35) In the suspended state, the signal S1 is in state H and the signal S2 is in state L.
(36) In the deactivated state, the signal S1 is in state L and the signal S2 is in state L.
(37) As it will be explained more in details thereafter, controlling the switch SW is only performed when the SWP link LK is in its deactivated state
(38) Further, when a secure element SE1 for example, has been selected, the part of the SWP link seen by the other non selected secure element (SE2 for example), is advantageously in a deactivated state.
(39) Placing such part of the SWP link in a deactivated state is equivalent to place the C6 contact of said corresponding non selected secure element in a low state, typically at ground.
(40) Resistors R20 and R21 respectively connected between the second terminal T20 and a voltage reference, for example ground, and between second terminal T21 and the voltage reference, are pull down resistors. And, the pull down resistor R20 permits to force the part LK20 of the SWP link in a deactivated state when the secure element SE2 has been selected while pull down resistor R21 forces the part LK21 of the SWP link in its deactivated state when the secure element SE1 has been selected.
(41) Further, another pull down resistor R3 connected between the control input T3 and the voltage reference (ground, for example) permits to force the control input to the logical value 0 thereby forcing the switch in the predetermined configuration in which terminal T1 is connected to terminal T20, in the case the switch SWP is not sufficiently or not at all powered.
(42) The value of each pull down resistor is chosen to have for example a current having a very small value, for example 5 ?A or 10 ?A.
(43) We refer now more particularly to
(44) After the master element boot, the processing means PRM of the master element put the SWP link in its deactivated state (step 400) in order to select (step 401) one secure element, for example secure element SE1. In this respect, the control signal SWCTRL has the logic value 0.
(45) Since the secure element SE1 has been selected, the part LK21 of the SWP link seen by the other non selected secure element SE2 is forced to be in a deactivated state by the pull down resistor R21 (the signal S1 is pulled down to state L by the resistor R21).
(46) Of course, as explained above, forcing the part of the SWP link seen by the non selected secure element in its deactivated state is equivalent to force the potential of the C6 contact of said secure element to a low state (ground, for example).
(47) Once the secure element SE1 has been selected, the management means (processing means and auxiliary management means) perform an initial SWP activation (step 402) of the corresponding slave SWP interface, as defined in ETSI TS 102 613.
(48) Activating a slave SWP interface leads to place said slave SWP interface in an activated state. For example, activating a slave SWP interface comprises performing an activation phase during which control data are exchanged between the master interface and the slave interface. At the end of the activation phase, the master and the slave have been mutually recognized and the slave is ready to exchange payload information related to a particular contactless application with the contactless element. The slave interface is thus activated (or in an activated state).
(49) Once initial SWP activation sequence is finished, the processing means of the main element ME put the SWP link into its suspended state, and wait for communication from the activated slave interface of the secure element.
(50) If the conditions are fulfilled to deactivate the secure element, the processing means of the main element put the SWP link in its deactivated state (step 404). Such conditions are for example those detailed in point 8.3 of ETSI TS 102 613.
(51) Now, the main element ME is able to switch the SWP link between the secure element SE1 and the secure element SE2 (step 406).
(52) In this respect, the switch control SWCTRL takes the logic value 1
(53) An initial SW activation (step 402) is performed for the secure element SE2, while the part LK20 of SWP link seen by the non selected secure element SE1 is forced in its deactivated state by the pull-down resistor R20 (step 407).
(54) For example, an event which can lead to an initial SWP activation of secure element SE2, which is for example a UICC, is the reception of a signal from the main processor.
(55) Once initial SWP activation sequence is finished for the secure element SE2, the processing means of the main element ME put SWP link into its suspended state to wait for SWP communication from secure element SE2. If no activity is required on this interface, the processing means of the main element put the SWP link in its deactivated state (step 404).
(56) If other secure element SE is to be activated, thus a new selection is performed followed by an initial activation of this new selected secure element (step 402).
(57) If no other secure element is to be activated (step 405), the SWP link remains in its deactivated state.
(58) At this stage, if a SWP communication with a secure element SEi is required (step 501) (upon, for example, reception of an external event coming from the application supported by this secure element), this secure element SEi is selected (step 502).
(59) Of course, if the switch SWP is already in the configuration for selecting this secure element, no change is performed on the switch.
(60) Then, a subsequent activation (step 504), as defined in ETSI TS 102 613, is performed for this secure element SEi, while the part of SWP link seen by each non selected secure element SEj (contact C6 of each non selected secure element SEj) is in its deactivated state (step 503)
(61) Once the selected slave interface SLINTi of the secure element SEi has been activated (step 505), a SWP communication between the main element ME and this secure element SEi may be performed (step 506) until the conditions are fulfilled allowing to deactivate the SWP link as for example described within chapter 8.3 of ETSI TS 102 613, for example, until the reception of a signal named EVT_HCI_END_OF_OPERATION in ETSI TS 102 622 (step 507).
(62) Such signal indicates the end of a communication with the secure element SEi.
(63) After the conditions are fulfilled, the SWP link is put again in its deactivated state (step 508) by the processing means PRM of the main element SE.
(64) If a new SW communication is required with the previously selected secure element SEi, thus, the control signal SWCTRL is not modified (step 510) and a subsequent activation (step 511) is performed for activating the slave interface SLINTi of this secure element SEi (step 512) permitting thus the SWP communication with this secure element (Step 513).
(65) If a SWP communication is required with a secure element SEj, different from the previously selected secure element SEi, then, this new secure element SEj is selected (step 514) by modifying the value of the control signal SWCTRL.
(66) A subsequent activation (step 516) is performed for this new selected secure element SEj, while maintaining the contact C6 of each other non selected secure element in a low state (step 515).
(67) Once the slave interface SLINTj of this secure element SEj has been activated (step 517), a SWP communication between the main element ME and the secure element SEj may be performed (step 518).
(68) An initial activation and a subsequent activation of a slave interface are disclosed in ETSI TS 102 613.
(69) The man skilled in the art may refer to this standard if necessary.
(70) Some details about these activations are now briefly described with reference to
(71) According to ETSI TS 102 613, particular control frames, called ACT frames, are exchanged between the NFC controller ME and a secure element SE during an activation phase.
(72) Such ACT frame, referenced CFR, is diagrammatically illustrated in
(73) More precisely, the first three bits of byte 1 of the frame CFR declare the SWP frame as an ACT frame. The FR bit indicates an eventually corrupted previously received ACT frame (only used by the NCF controller ME). The INF bit indicates that the last payload byte contains ACT_INFORMATION field and the ACT_CTRL bits b1 b2 b3 define the meaning of the ACT frame. After byte 1, 0-3 payload bytes follow, the content thereof depending of the content of ACT_CTRL and FR fields.
(74) More precisely, when the bits b 1 b2 b3 have respectively the binary values 000, the corresponding frame CFR1 is a so-called ACT_READY frame indicating that the secure element has been activated and is ready for exchanging information with the contactless element (
(75) When the bits b1, b2, b3 have respectively the binary values 001, the corresponding frame CFR2 is a so-called ACT_SYNC frame sent by a secure element and containing the identification SYNC_ID of this secure element (
(76) When the bits b1 b2 b3 have respectively the binary values 010, the corresponding frame CFR3 (
(77)
(78) First, the SWIO signal (see
(79) In ETSI TS 102 613 a secure element which detects such state H on its contact C6 has a predetermined duration (700 ?s) for resuming the SWP link.
(80) The auxiliary management means of the slave interface of the secure element SE, which is the selected secure element, sends, after having resumed the SWP link, an ACT_SYNC frame CFR2 (step 83).
(81) Then, the activation process continues depending on the power mode (step 85)
(82) More precisely, the NFC controller ME sends an ACT_POWER_MODE frame CFR3 (step 86) in the case of a full power mode.
(83) Upon receipt of this frame CFR3, the auxiliary management means of the selected secure element SE send an ACT_READY frame CFR1 (step 87).
(84) The SWP interface of the secure element SEn is thus considered as being activated.
(85) If the power mode is a low power mode, the interface of the selected secure element SE is considered as being activated after step 83.
(86)
(87) In step 91, the auxiliary management means of the secure element SE send on the link LK the ACT_SYNC frame.
(88) The slave SWP interface of the secure element SE is thus considered to be subsequently activated.
(89)
(90) In this embodiment, the switch SW is a passive switch. It comprises, for example, two NMOS transistors TRA and TRB. The input control T3 of the switch SW is connected to the gate of transistor TRA and to the gate of transistor TRB through an inversor INV.
(91) The terminal T20 of the switch SW is connected to one electrode (the drain, for example) of the transistor TRA, while the terminal T21 of the switch SW is connected to the electrode (the drain, for example) of transistor TRB.
(92) The other electrode (the source, for example) of each transistor TRA and TRB are both connected to the terminal T1 of the switch SW
(93) It is also possible to use an active multiplexer/demultiplexer switch as for example the one available at the company STMicroelectronics under the reference STG5123
(94) Such an active multiplexer/demultiplexer switch which is a high-speed CMOS low voltage single analog SPDT (Single-Pole Double Throw) switch or 2:1 multiplexer/demultiplexer switch, has a lower resistivity and a lower input capacity.
(95) As illustrated in
(96) The NFC controller ME is connected to the main processor through another bus, for example an I.sup.2C bus.
(97) The secure element SE2 is for example used for banking operations.
(98) The secure element SE2 is here totally embedded in an integrated circuit containing the NFC controller ME and is for example packed with said NFC controller in a single package SPCK.
(99) While the secure element SE2 is thus permanently fixed within the apparatus WP, the secure element SE1 (UICC) is removably lodged within the apparatus WP and removably connected to the NFC controller.
(100) The NFC controller is powered by the voltage VPS_main coming from a power management unit PMU connected to a battery. The NFC controller is also directly connected to the battery.
(101) At last, an antenna ANT1 permitting an NFC communication with a contactless device is coupled to the NFC controller.
(102) Information related to two different applications may be thus exchange between the secure elements SE1 or SE2 through the NFC controller and the antenna ANT1.
(103) In both embodiments disclosed in
(104) However in the embodiment disclosed in
(105) As a matter of fact, the secure element SE1 is connected to terminal T20 of the switch SW and, in a low power mode, the switch SW is forced by the pull down resistor R3 to be in a configuration where terminal T1 is connected to terminal T20.
(106) As indicated above, the power Vcc of the secure element SE1 is delivered by the NFC controller.
(107) In order to be compliant with ETSI TS 102 221 which requires the same power value between the main processor and the ETSI TS 102 221 interface of the secure element SE1, an additional signal Vref indicating the voltage value of the main processor is delivered to the NFC controller.
(108) In the embodiment disclosed in
(109) In this respect, as in a low power mode, switch SW is forced by pull down resistor R3 into a configuration in which terminal T1 is connected to terminal T20, the secure element SE2 is connected to terminal 20 while secure element SE1 is connected to terminal T21 of the switch SW
(110)
(111) As for the embodiments illustrated in
(112) As it will be explained now more in details the device illustrated in
(113) Thus the device comprises auxiliary selection means at least partly incorporated in said secure element SE2 and configured, when said device is in its second state, to control said SWP link switching for selecting only one auxiliary element operating in a second operation mode, here the secure element SE2.
(114) More precisely, the secure element SE2 is powered by Vcc1 provided by the NFC controller ME.
(115) The contact C1 of the secure element SE1 is connected to the voltage Vcc provided by the main processor in the full power mode, and to the voltage Vcc1 through a PMOS transistor TRP. The gate of this transistor TRP is connected to Vcc1 through a pull-up resistor R4.
(116) The gate of the transistor TRP is also connected to an input/output port I/O2 of the secure element SE2.
(117) This port I/O2 is also connected to a first input of a EXNOR gate LGT.
(118) The second input of the EXNOR gate LGT is connected to the NFC controller for receiving the control signal SWCTRL in the first operation mode, and to the pull down resistor R3 to be forced to the logical value 0 in the second operation mode
(119) The output of the EXNOR gate LGT is connected to the control input of the switch SW.
(120) Both EXNOR gate LGT and switch SW are powered by Vcc1, which is still available in the second operation mode.
(121) The output terminal T20 of the switch is connected to the contact C6 of the secure element SE1, and the input terminal T1 of the switch is switched to the terminal T20 when the signal present at the control input of the switch has the logical value 1.
(122) The output terminal T21 of the switch is connected to the SWP interface of the secure element SE2, and the input terminal T1 of the switch is switched to the terminal T21 when the signal present at the control input of the switch has the logical value 0.
(123) The secure element comprises also auxiliary processing means PRA connected to auxiliary memory means MMA, to the port I/O2 and to another input/output port I/O1. The auxiliary processing means may be realized by logic circuit and/or by software.
(124) The main processor is also configured to receive from an user interface an indication designating the auxiliary element which is chosen to be able to cooperate with the main element (NFC controller) in the low power mode. This indication is processed by the main processor and sent to the NFC controller through the I.sup.2C bus, and then to the secure element SE2 during a SWP transaction in the full power mode. The auxiliary processing means PRA of the secure element are thus configured to store in the auxiliary memory means MMA a corresponding configuration indication CFI.
(125) The main processor comprises also detection means configured to detect the passage from the first state of the device (full power operation mode) to the second state (low power operation mode) and to deliver a corresponding detection signal SDT to the port I/O1. For example this signal SDT is representative of the state ON or OFF of the main processor. For example, when the processor is ON, it sets the signal SDT to the logical value 1, whereas the signal SDT is forced to the logical value 0 by a pull-down resistor R5 when the processor is OFF.
(126) The means PRA, MMA, DTM, TRP, LGT, R4 form here said auxiliary selection means.
(127) The operation of the device in the first state (full power mode) is now described with reference to
(128) In this state, all the element are fully powered by the battery.
(129) The auxiliary control signal CTRLA, provided at the first input of the EXNOR gate LGT, has the logical value 1 due to the pull up resistor R4.
(130) The transistor TRP is off and the secure element SE1 is powered by the Vcc voltage delivered by the main processor.
(131) The NFC controller ME may, in this full power operation mode, either select the secure element SE1 or the secure element SE2 through the switch SW for performing a SWP communication with selected secure element.
(132) As a matter of fact, because the signal CTRLA has the logical value 1 the logical value of the control signal SWCTRL delivered by the NFC controller will be the logical value of the signal fed at the control input of the switch SW.
(133) Further, as explained above, during this full power operation mode, the configuration indication CFI may be delivered to secure element SE2 and stored by the auxiliary processing means PRA in the auxiliary memory means MMA.
(134) Reference is now made to
(135) In the low power mode, the secure element SE2 is powered by the voltage Vcc1 provided by the NFC controller. As in the embodiments illustrated in
(136) ANT1 during a NFC communication with a contactless device.
(137) Upon receipt of the detection signal SDT having the logical value 0, the auxiliary processing means PRA read the configuration indication CFI stored in the auxiliary memory means and deliver the control signal CTRLA having here the logical value 1.
(138) Further the control signal SWCTRL is forced to the logical value 0 by the pull down resistor R3.
(139) Consequently, the EXNOR gate LGT powered by Vcc1, delivers a logical value 0 to the control input of the switch SW also powered by Vcc1, allowing the selection of the secure element SE2.
(140) It should be noted here that, in this non limitative particular embodiment, the transistor TRP is off and thus the secure element SE1 is not powered.
(141) Reference is now made to
(142) In the low power mode, the secure element SE2 is powered by the voltage Vcc1 provided by the NFC controller.
(143) Upon receipt of the detection signal SDT having the logical value 0, the auxiliary processing means PRA read the configuration indication CFI stored in the auxiliary memory means and deliver the control signal CTRLA having here the logical value 0.
(144) Consequently the transistor TRP is ON and the secure element SE1 is also powered by the voltage Vcc1.
(145) Since the control signal SWCTRL is forced to the logical value 0 by the pull down resistor R3, the EXNOR gate LGT powered by Vcc1, delivers a logical value 1 to the control input of the switch SW also powered by Vcc1, allowing the selection of the secure element SE1.
(146) It should be noted here that the secure element SE1 is powered before being selected by the switch SW due to the delay introduced by the EXNOR gate LGT.
(147) The means PRA, MMA, TRP, R4 form also auxiliary power control means configured to control the powering of secure element SE1 and SE2 from said configuration indication.
(148) Of course, as both secure elements SE1, SE2 are powered in the low power operation mode, the part LK21 of SWP link seen by the non selected secure element SE2 is forced in its deactivated state by the pull-down resistor R21.
(149) According to an aspect of the invention, it is thus possible to exchange information between a main element and two auxiliary elements through a controllable multiplexer/demultiplexer switch without modifying the operating system of the secure element. Further, only a small modification of the operating system of the NFC controller is needed for controlling the analogue multiplexer/demultiplexer switch SW.
(150) Although different embodiments of the invention have been disclosed with two secure elements, other embodiments including more than two secure elements connected to the master SWP interface through a multiplexer/demultiplexer switch SW are also possible.
(151) Further although the analogue switch SW has been located outside the main element and the slave elements, it would be possible to integrate the switch (and eventually the EXNOR gate) within the single package SPCK or directly within the main element. In such a case the outputs of the main element would be for example the terminals T20 and T21 of the switch, and terminal T1 of the switch would be connected to the processing means of the master interface within said main element.