IP Library Granted Patent US 11,132,665
Granted Patent B2
US 11,132,665 · App. 14/261,763 · Granted Sep 28, 2021

Method and device for conducting a secured financial transaction on a device

Inventors: Luc Dolcino (Laval, CA); Sebastien Fontaine (Montreal, CA); Xavier Alberti (Montreal, CA); Benjamin Du Hays (Hampstead, CA); Maxime De Nanclas (Montreal, CA)
Assignee: Apple Inc.
G06Q20/3227G06Q20/20G06Q20/32G06Q20/322G06Q20/327G06Q20/3229G06Q20/3278G06Q20/34G06Q20/353G06Q20/388G06Q20/3825G06Q20/3829G06Q20/409G06Q20/4012
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,132,665
App. No.
14/261,763
Filed
Apr 25, 2014
Granted
Sep 28, 2021
Kind
B2
Examiner
RAZA, ZEHRA
Art Unit
3685
USPC
705/65
Abstract

A device, an add-on and a secure element for conducting a secured financial transaction are disclosed. The device comprises a central processing unit; a communication interface for establishing a communication between the device and a financial institution related to a financial account; an interface for acquiring data relating to the financial account; the secure element for processing at least a portion of the data relating to the financial account acquired by the interface; and control logic for acquiring a purchase amount to be debited from the financial account and for obtaining a transaction authorization from the financial institution related to the financial account, the transaction authorization being based, at least partially, on data processed solely by the secure element independently of data processed by the central processing unit. A method of conducting the secured financial transaction, and a computer program product for execution by the secure element are also disclosed.

Claims (51)

1. A method of conducting a secured financial transaction on a device used as a payment terminal, the device running a point of sale (POS) application, the device comprising a central processing unit, a wireless interface, a communication interface and a secure element, the POS application comprising a payment control application, the payment control application running on the central processing unit and comprising control instructions to control the secure element, the secure element storing a merchant identifier, the method comprising:

receiving, by the POS application, user input comprising a payment amount for the secured financial transaction;

sending, by the payment control application and to the secure element, a request to conduct the secured financial transaction;

after receiving the request to conduct the secured financial transaction, activating, by the secure element, the wireless interface of the device;

receiving, via the wireless interface of the device and from a payment apparatus, an indication of one or more payment applications supported by the payment apparatus;

selecting, by the secure element, and based on the one or more payment applications supported by the payment apparatus, a payment application amongst a plurality of payment applications available to the secure element;

acquiring, by the secure element, via the wireless interface of the device, and from the payment apparatus, data relating to a financial account;

encrypting, by the secure element, at least a portion of the data relating to the financial account;

establishing a secured communication channel between the secure element and a server through the communication interface of the device;

transmitting, by the secure element and to the server, the encrypted data and the merchant identifier;

obtaining, by the secure element, a transaction authorization for conducting the secured financial transaction from the server; and

displaying, by the device, an indication of the transaction authorization.

2. The method of claim 1 , wherein acquiring the data relating to the financial account comprises contactlessly reading data from one of a payment card or a mobile device.

3. The method of claim 1 , wherein the secure element comprises at least one microcontroller, memory, or a cryptographic accelerator.

4. The method of claim 1 , wherein encrypting the at least the portion of the data relating to the financial account is performed in accordance with Europay, MasterCard, or Visa (EMV) specifications.

5. A device to be used as a payment terminal and configured to run a point of sale (POS) application for conducting a secured financial transaction, the device comprising a central processing unit, a secure element storing a merchant identifier, a wireless interface and a memory comprising computer-executable instructions for execution by the device, the instructions, upon being executed by the device, causing the device to perform operations comprising:

running the point of sale (POS) application, the POS application comprising a payment control application, the payment control application running on the central processing unit and comprising control instructions to control the secure element;

receiving, by the POS application, user input comprising a payment amount for the secured financial transaction;

sending, by the payment control application and to the secure element, a request to conduct the secured financial transaction;

after receiving the request to conduct the secured financial transaction, activating, by the secure element, the wireless interface of the device;

receiving, via the wireless interface of the device and from a payment apparatus, an indication of one or more payment applications supported by the payment apparatus;

selecting, by the secure element, and based on the one or more payment applications supported by the payment apparatus, a payment application amongst a plurality of payment applications available to the secure element;

acquiring, by the secure element, via the wireless interface of the device, and from the payment apparatus, data relating to a financial account;

encrypting, by the secure element, at least a portion of the data relating to the financial account;

establishing a secured communication channel between the secure element and a server through a communication interface of the device;

transmitting, by the secure element and to the server, the encrypted data and the merchant identifier;

obtaining, by the secure element, a transaction authorization for conducting the secured financial transaction from the server; and

displaying, by the device, an indication of the transaction authorization.

6. The device of claim 5 , wherein the acquiring of the data relating to the financial account comprises reading data, by a contactless interface, from one of a payment card or a mobile device.

7. The device of claim 5 , wherein the operations further comprise: transmitting encrypted data to the server to generate the transaction authorization.

8. The device of claim 5 , wherein the secure element comprises at least one microcontroller, memory, or a cryptographic accelerator.

9. The device of claim 5 , wherein the encrypting of the at least the portion of the data relating to the financial account comprises the encrypting of the at least the portion of the data in accordance with Europay, MasterCard, or Visa (EMV) specifications.

10. A non-transitory computer readable storage medium comprising computer-executable instructions for execution by a device, the device to be used as a payment terminal and configured to run a point of sale (POS) application for conducting a secured financial transaction, the device comprising a central processing unit, a wireless interface and a secure element storing a merchant identifier, the instructions, upon being executed by the device, causing the device to perform a method comprising:

receiving, by the POS application, user input comprising a payment amount for the secured financial transaction;

running the POS application, the POS application comprising a payment control application, the payment control application running on the central processing unit and comprising control instructions to control the secure element;

sending, by the payment control application and to the secure element, a request to conduct the secured financial transaction;

after receiving the request to conduct the secured financial transaction, activating, by the secure element, the wireless interface of the device;

receiving, via the wireless interface of the device and from a payment apparatus, an indication of one or more payment applications supported by the payment apparatus;

selecting, by the secure element, and based on the one or more payment applications supported by the payment apparatus, a payment application amongst a plurality of payment applications available to the secure element;

acquiring, by the secure element, via the wireless interface of the device, and from the payment apparatus, data relating to a financial account;

encrypting, by the secure element, at least a portion of the data relating to the financial account;

establishing a secured communication channel between the secure element and a server through a communication interface of the device;

transmitting, by the secure element and to the server, the encrypted data and the merchant identifier;

obtaining, by the secure element, a transaction authorization for conducting the secured financial transaction from the server; and

displaying, by the device, an indication of the transaction authorization.

11. The method of claim 1 , wherein the payment control application and the secure element are certified, and where the secure element is certified at a higher level of security than the payment control application is certified.

12. The method of claim 1 , wherein the secure element is provided on a separate chipset, and wherein the secure element is Europay, MasterCard or Visa (EMV) transaction certified independently of the device.

13. The device of claim 5 , wherein the payment control application and the secure element were certified, and where the secure element was certified at a higher level of security than the payment control application was certified.

14. The device of claim 5 , wherein the secure element is Europay, MasterCard or Visa (EMV) transaction certified independently of the device.

15. The method of claim 1 , wherein the secure element comprises software elements.

16. The device of claim 5 , wherein the secure element comprises software elements.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2021
From: MOBEEWAVE SYSTEMS ULC
To: APPLE INC.
Reel/Frame 055813/0031 →
CHANGE OF NAME Recorded Jul 22, 2020
From: 1251008 B.C. UNLIMITED LIABILITY COMPANY
To: MOBEEWAVE SYSTEMS ULC
Reel/Frame 053280/0732 →
MERGER AND CHANGE OF NAME Recorded Jul 21, 2020
From: MOBEEWAVE SYSTEMS ULC; 1251008 B.C. UNLIMITED LIABILITY COMPANY
To: 1251008 B.C. UNLIMITED LIABILITY COMPANY
Reel/Frame 053265/0272 →
CHANGE OF NAME Recorded Jul 20, 2020
From: MOBEEWAVE SYSTEMS INC.
To: MOBEEWAVE SYSTEMS ULC
Reel/Frame 053251/0488 →
CHANGE OF NAME Recorded Jul 15, 2020
From: MOBEEWAVE, INC.
To: MOBEEWAVE SYSTEMS INC.
Reel/Frame 053223/0069 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 15, 2014
From: DOLCINO, LUC; FONTAINE, SEBASTIEN; ALBERTI, XAVIER; DU HAYS, BENJAMIN; DE NANCLAS, MAXIME
To: MOBEEWAVE, INC.
Reel/Frame 032899/0141 →
Continuity (3)
Continuation In Part PCTCA2013000185 · Feb 28, 2013
Provisional Application 61604613 · Feb 29, 2012
Related Publication 20140324698A1 · Oct 30, 2014