IP Library › Granted Patent US 10,009,177
Granted Patent B2
US 10,009,177 · App. 15/070,446 · Granted Jun 26, 2018

Integration of verification tokens with mobile communication devices

Inventor: Ayman Hammad (Pleasanton, CA)
Assignee: Visa International Service Association
H04L9/10G06F21/34G06Q20/12G06Q20/341G06Q20/352G06Q20/385G06Q20/40G06Q20/4018G06Q20/42G06Q20/425H04L9/14H04L9/3231H04L9/3234H04L63/0853H04L63/126G06F2221/2129H04L2209/12H04L2209/24H04L2209/805
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,009,177
App. No.
15/070,446
Granted
Jun 26, 2018
Kind
B2
Abstract

Apparatuses, methods, and systems pertaining to the verification of portable consumer devices are disclosed. In one implementation, a verification token is communicatively coupled to a computer by a USB connection so as to use the computer's networking facilities. The verification token reads identification information from a user's portable consumer device (e.g., credit card) and sends the information to a validation entry over a communications network using the computer's networking facilities. The validation entity applies one or more validation tests to the information that it receives from the verification token. If a selected number of tests are passed, the validation entity sends a device verification value to the verification token, and optionally to a payment processing network. The verification token may enter the device verification value into a CVV field of a web page appearing on the computer's display, or may display the value to the user using the computer's display.

Claims (26)

1. A mobile communication device comprising:

a housing;

a first processor disposed within the housing;

a first memory unit disposed within the housing;

an input-output controller coupled to the first processor; and

a verification token disposed within the housing and communicatively coupled to the input-output controller, the verification token comprising a second processor separate from the first processor, and a second memory unit that is separate from the first memory unit and stores an encryption key that is used by the second processor for encrypting or signing data sent from the verification token to a validation entity that validates the encrypted or signed data and then provides a dynamic account number to the verification token, and wherein the verification token stores the dynamic account number from the validation entity.

2. The mobile communication device of claim 1 , wherein the encryption key is a symmetric encryption key.

3. The mobile communication device of claim 1 wherein the mobile communication device is a mobile phone.

4. The mobile communication device of claim 1 wherein the verification token is protected from attacks from hackers.

5. The mobile communication device of claim 1 wherein the second memory unit is a security module.

6. The mobile communication device of claim 1 wherein the verification token stores a uniform resource identifier for the validation entity.

7. The mobile communication device of claim 1 wherein the validation entity provides a device verification value to the verification token.

8. The mobile communication device of claim 7 wherein the verification token stores the device verification value.

9. A method comprising:

receiving identification information at a verification token in a mobile communication device, the mobile communication device comprising (a) a housing, (b) a first processor disposed within the housing, (c) a first memory unit disposed within the housing, (d) an input-output controller coupled to the first processor, and (e) the verification token communicatively coupled to the input-output controller, the verification token comprising a second processor separate from the first processor, a second memory unit separate from the first memory unit and storing an encryption key:

encrypting or signing, the identification information using the second processor and the encryption key;

transmitting, the encrypted identification information to a validation entity, wherein the validation entity validating the encrypted or signed identification information, and then transmits a dynamic account number to the verification token in response to the validating; and

receiving, the dynamic account number at the verification token.

10. The method of claim 9 , wherein the encryption key is a symmetric key.

11. The method of claim 9 wherein the encryption key is a first encryption key, and the validation entity holds a second encryption key, the first encryption key and the second encryption key being a symmetric key pair.

12. The method of claim 9 wherein the second memory unit is a security module.

13. The method of claim 9 wherein the verification token stores a uniform resource identifier for the validation entity.

14. The method of claim 9 further comprising:

receiving, by the mobile communication device, a device verification value from the validation entity.

15. The method of claim 14 further comprising:

storing, by the mobile communication device, the device verification value received from the validation entity.

Continuity (7)
Continuation 13963538 · Aug 9, 2013
Continuation 13250918 · Sep 30, 2011
Continuation In Part 12780657 · May 14, 2010
Continuation In Part 12712148 · Feb 24, 2010
Provisional Application 61178636 · May 15, 2009
Provisional Application 61407423 · Oct 27, 2010
Related Publication 20160197725A1 · Jul 7, 2016
Cited By (5)
US 12,450,590 US 12,518,263 US 12,646,045 US 12,675,795 US 12,694,390