IP Library Granted Patent US 8,346,672
Granted Patent B1
US 8,346,672 · App. 13/442,861 · Granted Jan 1, 2013

System and method for secure transaction process via mobile device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,346,672
App. No.
13/442,861
Granted
Jan 1, 2013
Kind
B1
Abstract

A system providing enhanced security for device based transactions, constituted of: a server associated with a network address; a first device associated with a user, the first device in communication with the server over a first communication channel responsive to an obtained server network address; a second device associated with the user arranged to obtain the server network address from the first device; and a mobile device server in communication with the second device over a second communication channel, the mobile device server in communication with the server via a third communication channel, the mobile device server arranged to: obtain the server network address from the second device over the second communication channel; obtain the server network address from a trusted source; and authorize to the server over third communication channel a transaction only in the event that the server network addresses are consonant.

Claims (67)

1. A system providing enhanced security for device based transactions, the system comprising:

a server comprising a processor and a memory associated with a network address;

a first device comprising a first device processor and having an associated first device memory, said first device associated with a user, the first device memory storing instructions which when executed by the first device processor causes the first device processor to perform the steps of:

communicating with said server over a first communication channel, requesting a transaction via said server, and

obtaining the server associated network address,

wherein said first communication channel is established responsive to the obtained server associated network address;

a second device comprising a second device processor and having an associated second device memory, said second device associated with the user, the second device memory storing instructions which when executed by the second device processor causes the second device processor to perform the steps of communicating with said first device and receiving from said first device the obtained server associated network address; and

a mobile device server comprising a mobile device server processor and a mobile device server memory, the mobile device server memory storing instructions which when executed by the mobile device server processor causes the mobile device server processor to perform the steps of:

communicating with said second device over a second communication channel,

communicating with said server over a third communication channel,

inputting said received obtained server associated network address from said second device over said second communication channel,

obtaining the server associated network address from a trusted source, and

authorizing a transaction only in the event that said input received obtained server associated network address is consonant with the server associated network address obtained from the trusted source.

2. The system of claim 1 , wherein said trusted source is said server, wherein the server associated network address is obtained from the server over the third communication channel.

3. The system of claim 1 , wherein said trusted source is a database in communication with said mobile device server.

4. The system of claim 1 , wherein said first communication channel is different from said second communication channel.

5. The system of claim 1 , wherein said first device and said second device are a single device.

6. The system of claim 1 , wherein one of said first device and said second device is a user mobile device.

7. The system of claim 1 , wherein one of said first device and second device said user device is a computer.

8. The system of claim 1 , wherein said first device is a computer and said second device is a user mobile device.

9. The system of claim 1 , wherein said communicating of said second device with said first device is over a fourth communication channel, the fourth communication channel different from any of the first, second and third communication channels.

10. The system of claim 9 , wherein said fourth communication channel is one of radio frequency identification and near field communication.

11. The system of claim 1 , wherein said third communication channel is a secured communication channel different from any of the first and second communication channels.

12. The system of claim 1 , further comprising a secured element arranged to be in communication with said second device, said secured element arranged to provide an encrypted pass code to said second device responsive to a user gesture, the second device memory further storing instructions which when executed by the second device processor causes the second device process to transmit said provided encrypted pass code to said mobile device server over said second communication channel.

13. The system of claim 12 , further comprising a data entry device in communication with said secured element, said pass code provided to said secured element by said user gesture via said data entry device.

14. The system of claim 13 , wherein said data entry device is a dedicated data entry device.

15. The system of claim 13 , further comprising a contactless element, said secured element comprised within said contactless element, said communication between said secured element and said second device responsive to said contactless element.

16. The system of claim 1 , further comprising a notification server comprising a notification server processor and having an associated notification server memory, said notification server in communication with said mobile device server, the notification server memory storing instructions which when executed causes the notification server processor to perform the step of transmitting a message to said second device;

said second device memory storing application instructions which when executed by the second device processor responsive to the transmitted message from said notification server further causes the second device processor to perform the step of providing a network address of the first device and the received obtained server associated network address to said mobile device server thus enabling said inputting over said second communication channel of said received obtained server associated network address.

17. The system of claim 1 , further comprising an additional server comprising an additional server processor and having an associated additional server memory, the additional server memory storing instructions which when executed by the additional server processor causes the additional server processor to perform the steps of: communicating with said mobile device server; and authorizing an additional transaction with said first device responsive to the authorization of the transaction between the first device and the server.

18. A system providing enhanced security for device based transactions, the system comprising:

a server associated with a network address, said server comprising a server processor and an associated server memory;

a first device comprising a first device processor and having an associated first device memory, said first device associated with a user, wherein the first device memory storing instructions which when executed by the first device processor causes the first device processor to perform the steps of:

communicating with said server over a first communication channel,

requesting a transaction via said server, and

obtaining the server associated network address,

wherein the communication over the first communication channel is established responsive to the obtained server associated network address;

a second device comprising a second device processor and having an associated second device memory, said second device associated with the user, the second device memory storing instructions which when executed by the second device processor causes the second device processor to perform the steps of: communicating with said first device and receiving from said first device the obtained server associated network address; and

a mobile device server comprising a mobile device server processor and a mobile device server memory, the mobile device server memory storing instructions which when executed by the mobile device server processor causes the mobile device server processor to perform the steps of:

communicating with said second device over a second communication channel, and communicating with said server via a third communication channel,

at least one of said server associated memory and said mobile device server associated memory storing instructions which when executed by the respective one of the server processor and the mobile device server processor causes the respective one of the server processor and the mobile device server processor to perform the steps of:

obtaining the server associated network address from a trusted source;

inputting said received obtained server associated network address from said second device over said second communication channel; and

authorizing a transaction only in the event that the input received obtained server associated network address is consonant with the server associated network address obtained from the trusted source.

19. A method of providing enhanced security for device based transactions, the method comprising:

providing a first user device;

obtaining by the first user device a server associated network address;

establishing communication between the first user device and the server responsive to the obtained server associated network address over a first communication channel;

receiving by a mobile device server the obtained server associated network address from the first user device over a second communication channel,

inputting by the mobile device server the obtained server associated network address over the second communication channel,

obtaining by the mobile device server said server associated network address from a trusted source;

comparing by the mobile device server the server associated network address obtained from the trusted source with the input obtained server associated network address;

determining by the mobile device server that the server associated network address input over the said second communication channel is consonant with the server associated network address from the trusted source; and

based on the determination, authorizing by the mobile device server a transaction associated with the server.

20. The method of claim 19 , wherein the first communication channel is different from the second communication channel.

21. The method of claim 19 , where the trusted source comprises one of a third communication channel different from the first and second communication channels and a secure database.

22. The method of claim 19 , further comprising:

providing a second user device, said provided second user device received said obtained server associated network address from the first user device, wherein said input obtained server associated network address is communicated by said provided second user device over the second communication channel.

23. The method of claim 22 , wherein said provided second user device receives said obtained server associated network address from the first user device via a contactless element.

24. The method of claim 19 , further comprising:

encrypting a pass code; and

transmitting said encrypted pass code over the second communication channel to said mobile device server.

25. The method of claim 24 , further comprising:

providing an entry device associated with said provided second user device, said pass code received responsive to a user gesture via said entry device.

26. The method of claim 19 , further comprising:

providing an additional server;

authorizing an additional transaction associated with said provided additional server responsive to the authorization of the transaction associated with the server.

Assignments (13)
RELEASE OF SECURITY INTEREST AT R/F 61703/0988 Recorded Nov 14, 2025
From: BLUE OWL CAPITAL CORPORATION
To: PING IDENTITY CORPORATION
Reel/Frame 073570/0777 →
SECURITY INTEREST Recorded Nov 13, 2025
From: PING IDENTITY CORPORATION; PING IDENTITY INTERNATIONAL, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 073557/0093 →
RELEASE OF SECURITY INTEREST Recorded Oct 19, 2022
From: BANK OF AMERICA, N.A.
To: PING IDENTITY CORPORATION
Reel/Frame 061709/0527 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Oct 18, 2022
From: PING IDENTITY CORPORATION
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 061703/0988 →
RELEASE OF SECURITY INTEREST Recorded Nov 23, 2021
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: PING IDENTITY CORPORATION
Reel/Frame 058195/0557 →
SECURITY INTEREST Recorded Nov 23, 2021
From: PING IDENTITY CORPORATION
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 058944/0687 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL/FRAME NO. 44725/0443 Recorded Dec 12, 2019
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: PING IDENTITY CORPORATION
Reel/Frame 051265/0873 →
PATENT SECURITY AGREEMENT Recorded Dec 12, 2019
From: PING IDENTITY CORPORATION
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 051271/0247 →
SECURITY INTEREST Recorded Jan 25, 2018
From: PING IDENTITY CORPORATION
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 044725/0443 →
RELEASE OF SECURITY INTEREST Recorded Jan 25, 2018
From: GUGGENHEIM CORPORATE FUNDING, LLC
To: PING IDENTITY CORPORATION
Reel/Frame 044729/0597 →
SECURITY INTEREST Recorded Jun 30, 2016
From: PING IDENTITY CORPORATION
To: GUGGENHEIM CORPORATE FUNDING, LLC
Reel/Frame 039055/0274 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2014
From: ACCELLS TECHNOLOGIES (2009), LTD.
To: PING IDENTITY CORPORATION
Reel/Frame 032179/0405 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2012
From: WEINER, AVISH JACOB; NE'MAN, RAN
To: ACCELLS TECHNOLOGIES (2009), LTD.
Reel/Frame 028525/0882 →