IP Library Granted Patent US 9,607,298
Granted Patent B2
US 9,607,298 · App. 14/293,688 · Granted Mar 28, 2017

System and method for providing secure data communication functionality to a variety of applications on a portable communication device

Inventors: David Brudnicki (Duvall, WA); Michael K Craft (Carlsbad, CA); Hans Reisgies (San Jose, CA); Andrew Weinstein (San Francisco, CA)
Assignee: Sequent Software Inc.
G06Q20/3226G06F21/34G06F21/74G06Q20/3574H04L63/0807H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,607,298
App. No.
14/293,688
Granted
Mar 28, 2017
Kind
B2
Abstract

A system for providing an application associated with a portable communication device the ability to communicate via a secure element. The system has a digital identifier and digital token operably associated with the application; a card services module that provides an application programming interface to the secure element; and a secure data table associated with the card services module. The secure data table includes a list of trusted applications each identifiable by paired digital identifier and token. The card services module [includes] compares the identifier and the token with each of the identifier-token pairs in the table until a match indicates the application is trusted. The card services module issues commands to the secure element based on an action requested by a trusted application in conjunction with the presentation of the digital token. A method of providing an application with the ability to communicate via secure element is also disclosed.

Claims (26)

1. A system comprising:

a secure data table including a list of one or more trusted applications each being identifiable by a paired set of digital identifier and digital token:

a card services module configured to confirm that a first application is trusted based on determining that a first digital identifier and a first digital token associated with the first application match one of the digital identifier and digital token pairs; and

a token generator configured to generate a second digital token that is a function of the first digital token in response to confirming that the first application is trusted and to store the second digital token in the secure data table in association with the first application and in place of the first digital token, wherein the card services module issues one or more commands in response to receipt of a first action in association with the presentation of the second digital token by the first application, wherein the first digital token is presented during an initial launch of the first application and in subsequent launches the second digital token is presented instead of the first digital token.

2. The system according to claim 1 further comprising means for determining that the first application is signed using a known issuer identifier.

3. The system according to claim 1 further comprising means for receiving data associated with the one or more trusted applications at periodic time intervals.

4. The system according to claim 1 wherein the first digital token is a constant associated with the first application.

5. The system according to claim 4 wherein the constant is a global constant.

6. The system according to claim 1 wherein the token generator is a pseudo-random number generator.

7. The system according to claim 6 wherein the pseudo-random number generator is associated with a secure element.

8. The system according to claim 1 wherein the token generator generates the second token based on a seed.

9. The system according to claim 8 wherein the seed is selected from the group consisting of the first digital token, the first digital identifier, an issuer of the first application, and combinations thereof.

10. The system according to claim 1 , wherein the secure data table is stored in a secure memory and encrypted.

11. A computer-implemented method comprising:

storing, by a secure data table, a list of one or more trusted applications each being identifiable by a paired set of digital identifier and digital token;

confirming, by a card services module, that a first application is trusted based on determining that a first digital identifier and a first digital token associated with the first application match one of the digital identifier and digital token pairs; and

generating, by a token generator, a second digital token that is a function of the first digital token in response to confirming that the first application is trusted and storing the second digital token in the secure data table in association with the first application and in place of the first digital token, wherein the card services module issues one or more commands in response to receipt of a first action in association with the presentation of the second digital token by the first application, wherein the first digital token is presented during an initial launch of the first application and in subsequent launches the second digital token is presented instead of the first digital token.

12. The method according to claim 11 further comprising receiving data associated with the one or more trusted applications at periodic time intervals.

13. The method according to claim 11 further comprising determining that the first application is signed using a known issuer identifier.

14. The method according to claim 11 wherein the first digital token is a constant associated with the first application.

15. The method according to claim 14 wherein the constant is a global constant.

16. The method according to claim 11 wherein the token generator is a pseudo-random number generator.

17. The method according to claim 16 wherein the pseudo-random number generator is associated with a secure element.

18. The method according to claim 11 further comprising generating, by the token generator, the second token based on a seed.

19. The method according to claim 18 further comprising selecting the seed from the group consisting of the first digital token, the first digital identifier, an issuer of the first application, and combinations thereof.

20. The method according to claim 11 , further comprising storing the secure data table in a secure memory, wherein the secure data table is encrypted.

Assignments (7)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2023
From: SEQUENT SOFTWARE, INC.
To: TIS INC.
Reel/Frame 064105/0348 →
SECURITY INTEREST Recorded Dec 22, 2022
From: SEQUENT SOFTWARE INC.
To: TIS INC.
Reel/Frame 062179/0639 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 16, 2020
From: GFA WORLDWIDE, INC.
To: SEQUENT SOFTWARE, INC.
Reel/Frame 051533/0808 →
SECURITY INTEREST Recorded Jun 27, 2019
From: SEQUENT SOFTWARE INC.; GFA WORLDWIDE, INC.
To: TIS INC.
Reel/Frame 049623/0638 →
RELEASE OF SECURITY INTEREST Recorded Jun 11, 2019
From: COMERICA BANK
To: SEQUENT SOFTWARE INC.
Reel/Frame 049437/0802 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 19, 2017
From: SEQUENT SOFTWARE, INC.
To: GFA WORLDWIDE, INC.
Reel/Frame 044432/0366 →
SECURITY INTEREST Recorded Dec 11, 2014
From: SEQUENT SOFTWARE LLC
To: COMERICA BANK
Reel/Frame 034477/0111 →
Continuity (3)
Continuation 13279184 · Oct 21, 2011
Provisional Application 61414847 · Nov 17, 2010
Related Publication 20140289119A1 · Sep 25, 2014