IP Library Granted Patent US 11,757,885
Granted Patent B2
US 11,757,885 · App. 17/158,870 · Granted Sep 12, 2023

Transaction security systems and methods

Inventor: Shlomo Touboul (Kefar Haim, IL)
Assignee: CUPP Computing AS
H04L63/10G06F21/34G06F21/53G06F21/606H04L63/0236H04L63/18H04L63/20H04L63/0853H04L63/0861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,757,885
App. No.
17/158,870
Filed
Jan 26, 2021
Granted
Sep 12, 2023
Kind
B2
Art Unit
2433
USPC
726/1
Abstract

Outbound traffic of a host application may be received from a host device having a host processor. The secure resource may be configured to provide a secure transaction based on the outbound network traffic. Using a second processor different than the host processor, it may be determined whether the host application is authorized to provide the outbound network traffic to the secure resource. The outbound network traffic may be allowed to be forwarded to the secure resource if the host application is authorized. The outbound network traffic may be disallowed to be forwarded to the secure resource if the host application is not authorized.

Claims (40)

1. A method comprising:

establishing, by a secure transaction device having a secure transaction device processor, redirection protocols in a host device having a host device processor different than the secure transaction device processor, the host device having a host device network connection, the secure transaction device having a secure transaction device network connection different than the host device network connection, the redirection protocols causing the host device to redirect all network traffic to the secure transaction device when the secure transaction device is coupled to the host device and not to redirect all network traffic to the secure transaction device when the secure transaction device is not coupled to the host device, the secure transaction device network connection configured to use network configuration details of the host device network connection to mimic the host device network connection to render the secure transaction device transparent to a remote network resource;

when the secure transaction device is coupled to the host device,

receiving, by the secure transaction device from the host device, outbound network traffic originated by a host application on the host device, the outbound network traffic directed to the remote network resource, the remote network resource being remote from the secure transaction device and from the host device;

establishing, by the secure transaction device, a secure tunnel between the host device via the secure transaction device network connection to the remote network resource; and

transmitting the outbound network traffic from the host application via the secure tunnel to the remote network resource; and

the host device being configured to, when the secure transaction device is not coupled to the host device, transmit the outbound network traffic from the host application via the host device network connection to the remote network resource.

2. The method of claim 1 , wherein the host application comprises a stand-alone application resident on the host device, or an interface resident on the host device that cooperates with a server application resident on at least one server.

3. The method of claim 1 , further comprising determining whether the host application is authorized to access the remote network resource.

4. The method of claim 3 , wherein the determining whether the host application is authorized to access the remote network resource comprises looking up permissions of the host application on the security policy.

5. The method of claim 1 , further comprising determining whether a user of the host application has permission to access sensitive information on the remote network resource.

6. The method of claim 1 , wherein the secure transaction device is a device coupled externally to the host device.

7. The method of claim 1 , wherein the secure transaction device is a device coupled internally to the host device.

8. The method of claim 1 , wherein the establishing redirection protocols in the host device includes injecting redirection code into an operating system of the host device.

9. The method of claim 1 , wherein the network configuration details include network protocols and network addresses.

10. A secure transaction device comprising:

a secure transaction device processor;

a secure transaction device network connection; and

memory storing computer code that, when processed by the secure transaction device processor, is configured to cause the secure transaction device to perform:

establishing redirection protocols in a host device having a host device processor different than the secure transaction device processor, the host device having a host device network connection different than the secure transaction device network connection different than the host device network connection, the redirection protocols causing the host device to redirect all network traffic to the secure transaction device when the secure transaction device is coupled to the host device and not to redirect all network traffic to the secure transaction device when the secure transaction device is not coupled to the host device, the secure transaction device network connection configured to use network configuration details of the host device network connection to mimic the host device network connection to render the secure transaction device transparent to a remote network resource;

when the secure transaction device is coupled to the host device,

receiving, by the secure transaction device from the host device, outbound network traffic originated by a host application on the host device, the outbound network traffic directed to the remote network resource, the remote network resource being remote from the secure transaction device and from the host device:

establishing a secure tunnel between the host device via the secure transaction device network connection to the remote network resource; and

transmitting the outbound network traffic from the host application via the secure tunnel to the remote network resource; and

the host device being configured to, when the secure transaction device is not coupled to the host device, transmit the outbound network traffic from the host application via the host device network connection to the remote network resource.

11. The secure transaction device of claim 10 , wherein the host application comprises a stand-alone application resident on the host device, or an interface resident on the host device that cooperates with a server application resident on at least one server.

12. The secure transaction device of claim 10 , wherein the computer code is further configured to cause the secure transaction device to perform determining whether the host application is authorized to access the remote network resource.

13. The secure transaction device of claim 12 , wherein the computer code configured to cause the secure transaction device to perform determining whether the host application is authorized to access the remote network resource comprises computer code configured to cause the secure transaction device to perform looking up permissions of the host application on the security policy.

14. The secure transaction device of claim 10 , wherein the computer code is further configured to cause the secure transaction device to perform determining whether a user of the host application has permission to access sensitive information on the remote network resource.

15. The secure transaction device of claim 10 , wherein the secure transaction device is a device coupled externally to the host device.

16. The secure transaction device of claim 10 , wherein the secure transaction device is a device coupled internally to the host device.

17. The secure transaction device of claim 10 , wherein the computer code configured to cause the secure transaction device to perform establishing redirection protocols in the host device comprises computer code configured to cause the secure transaction device to perform injecting redirection code into an operating system of the host device.

18. The secure transaction device of claim 10 , wherein the network configuration details include network protocols and network addresses.

19. A non-transitory computer-readable medium comprising computer code configured to instruct one or more processors to perform:

establishing, by a secure transaction device having a secure transaction device processor, redirection protocols in a host device having a host device processor different than the secure transaction device processor, the host device having a host device network connection, the secure transaction device having a secure transaction device network connection different than the host device network connection, the redirection protocols causing the host device to redirect all network traffic to the secure transaction device when the secure transaction device is coupled to the host device and not to redirect all network traffic to the secure transaction device when the secure transaction device is not coupled to the host device, the secure transaction device network connection configured to use network configuration details of the host device network connection to mimic the host device network connection to render the secure transaction device transparent to a remote network resource;

when the secure transaction device is coupled to the host device,

receiving, by the secure transaction device from the host device, outbound network traffic originated by a host application on the host device, the outbound network traffic directed to the remote network resource, the remote network resource being remote from the secure transaction device and from the host device;

establishing, by the secure transaction device, a secure tunnel between the host device via the secure transaction device network connection to the remote network resource; and

transmitting the outbound network traffic from the host application via the secure tunnel to the remote network resource; and

the host device being configured to, when the secure transaction device is not coupled to the host device, transmit the outbound network traffic from the host application via the host device network connection to the remote network resource.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE ADDRESS PREVIOUSLY RECORDED AT REEL: 056107 FRAME: 0056. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded May 25, 2021
From: TOUBOUL, SHLOMO
To: CUPP COMPUTING AS
Reel/Frame 056366/0169 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 3, 2021
From: TOUBOUL, SHLOMO
To: CUPP COMPUTING AS
Reel/Frame 056107/0056 →