IP Library › Granted Patent US 8,997,188
Granted Patent B2
US 8,997,188 · App. 14/053,373 · Granted Mar 31, 2015

System for enabling a smart device to securely accept unsolicited transactions

Inventors: Jerome Svigals (Redwood City, CA); Howard M. Svigals (Gig Harbor, WA); Geoff Ingalls (Sarasota, FL); John D. Hipsley (Sunnyvale, CA)
G06F21/606G06F21/31G06F21/44H04L9/3228H04L9/3231H04L9/3234
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,997,188
App. No.
14/053,373
Granted
Mar 31, 2015
Kind
B2
Abstract

A Smart Device ( 102 ) securely validates an incoming message emanating from an external source ( 906 ). A method embodiment comprises the steps of a SPARC Internet Security Corporation (SISC 900 ) verifying ( 912 ) that the incoming message contains a pre-stored validity identifier ( 901 ). When the incoming message contains the correct validity identifier ( 901 ), SSC ( 900 ) appends ( 914 ) a SSD Unsolicited Transaction Identifier (SSD UT ID) to the message. The SSD UT ID comprises a unique security device ( 104 ) identifier and an optional message count. SISC ( 900 ) then sends ( 915 ) the message and the SSD UT ID to the Smart Device 102 . The invention does not require encryption, PINs, or passwords. In an embodiment of the invention, Smart Device ( 102 ) is not allowed to communicate directly with external networks ( 506 ), but rather must do so via SSD ( 104 ). This removes the security burden from Smart Device ( 102 ), speeding and simplifying transactions.

Claims (25)

1. A method for a smart device to securely validate an incoming unsolicited message emanating from an external source, said method comprising the steps of a security communication module automatically:

verifying that the incoming message contains a validity identifier that is pre-stored within the security communication module;

when the incoming message contains the pre-stored validity identifier, appending a SSD Unsolicited Transaction Identifier (SSD UT ID) to the message, wherein the SSD UT ID comprises a unique security device identifier associated with a security device having a pre-established security arrangement with the smart device; and

sending the message and the SSD UT ID to the smart device; wherein

the security device is a device separate and apart from the smart device, is not in direct communication with the security communication module, and works in conjunction with the smart device to securely process smart device transactions; and

the security communication module is not under the control of a user of the smart device.

2. The method of claim 1 wherein the security coordination module is separate and apart from the smart device and from the security device.

3. The method of claim 1 wherein the steps are executed securely without using encryption, a PIN, or a password.

4. The method of claim 1 wherein the smart device checks the unique security device identifier after receiving the message and the SSD UT ID; and

when the smart device determines that the unique security device identifier portion of the SSD UT ID is valid, the smart device accepts and processes the message.

5. The method of claim 1 wherein the smart device checks the unique security device identifier after receiving the message and the SSD UT ID; and

when the smart device determines that the unique security device identifier portion of the SSD UT ID is invalid, the smart device destroys the message.

6. The method of claim l wherein the SSD UT ID appended by the security communication further comprises a message count indicating the number of incoming messages, regardless of source, that have been sent to the smart device from external sources.

7. The method of claim 6 wherein the message count is changed, but not incremented by 1, by the security communication module for each successive message.

8. The method of claim 1 wherein, when the verifying step determines that the incoming message does not contain the pre-stored validity identifier, the message is deemed by the security communication module to be contaminated, but the smart device is given a chance to accept the message anyway.

9. The method of claim 8 wherein a user of the smart device is given a preselected period of time to accept the message received from the security communication module; and

when the preselected period of time expires without the user having accepted the message, the message is destroyed by the security communication module.

10. The method of claim 1 further comprising the step of the security communication module retrieving a new validity identifier upon interruption of message flow from the external source, and replacing the pre-stored validity identifier with the new validity identifier.

11. At least one non-transitory computer-readable medium containing computer program instructions for enabling a security communication module to automatically perform the steps of;

verifying that an incoming unsolicited message addressed to a smart device contains a pre-stored validity identifier;

when the incoming message contains the pre-stored validity identifier, appending a SSD Unsolicited Transaction Identifier (SSD UT ID) to the message, wherein the SSD UT ID comprises a unique security device identifier associated with a security device having a pre-established security arrangement with the smart device; and

sending the message and the SSD UT ID to the smart device; wherein

the security device is a device separate and apart from the smart device, is not in communication with the security communication module and works in conjunction with the smart device to securely process smart device transactions; and

the security communication module is not controlled by a user of the smart devise.

12. The at least one non-transitory computer-readable medium of claim 11 wherein the steps are executed securely without using encryption, a PIN, or a password.

Priority Claims (1)
WO PCT/US2013/003603 · Apr 10, 2013 · international
Continuity (4)
Continuation In Part 13895155 · May 15, 2013
Continuation In Part 13444551 · Apr 11, 2012
Provisional Application 61795190 · Oct 12, 2012
Related Publication 20140068729A1 · Mar 6, 2014