IP Library Granted Patent US 10,050,790
Granted Patent B2
US 10,050,790 · App. 15/111,895 · Granted Aug 14, 2018

Method for authorizing a transaction

Inventors: Florian Gawlas (München, DE); Jan Eichholz (München, DE)
Assignee: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
H04L9/3226G06F21/41G06Q20/325G06Q20/327G06Q20/3276G06Q20/385G06Q20/401H04L63/061H04L63/083H04L63/0838H04W12/04H04W12/06H04L63/18H04L2209/56H04L2209/80H04L2463/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,050,790
App. No.
15/111,895
Granted
Aug 14, 2018
Kind
B2
Abstract

A method for authorizing a transaction has the following steps: inputting transaction data on a first mobile device, transmitting the transaction data from the first device to a background system by means of a first over-the-air interface, transmitting in encrypted manner at least a password to a second mobile device through the intermediary of the first mobile device, and authorizing the transaction by inputting the password displayed on the second device on the first device.

Claims (13)

1. A method for authorizing a transaction, having the following steps:

inputting transaction data on a first mobile device;

transmitting the transaction data from the first device to a background system by means of a first over-the-air interface;

requesting the input of a password on the first device in order to authorize the transaction;

transmitting in encrypted manner at least the password from the background system to a second mobile device, wherein the data employed for the transmission of the password are transferred between the background system and the second mobile device in encrypted manner through the intermediary of the first mobile device, and authorizing the transaction by inputting the password displayed on the second device on the first device;

wherein the second mobile device is not connected directly with the background system, and the second mobile device receives a cryptographic key through the intermediary of the first device; and

wherein the second device and the background system exchange the cryptographic key, of which the first device has no knowledge, before the step of the encrypted transmission.

2. The method according to claim 1 , wherein the first mobile device is a mobile phone and/or a tablet PC.

3. The method according to claim 1 , wherein the second mobile device is a second device being in connection with the first mobile device via a second over-the-air interface.

4. The method according claim 1 , wherein the second device is data glasses, a smartwatch and/or a body-wearable display device.

5. The method according to claim 1 , wherein the second device and the background system set up a secure end-to-end-encrypted channel, wherein the first device has no knowledge of the key required for the encryption of the channel.

6. The method according to claim 1 , wherein together with the password at least a part of the inputted transaction data are transmitted to the second mobile device.

7. The method according to claim 1 , wherein the password is a one-time password.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2017
From: GIESECKE & DEVRIENT GMBH
To: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
Reel/Frame 043230/0485 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2016
From: GAWLAS, FLORIAN; EICHHOLZ, JAN
To: GIESECKE & DEVRIENT GMBH
Reel/Frame 039360/0209 →
Priority Claims (1)
DE 10 2014 000 644 · Jan 17, 2014 · national
Continuity (1)
Related Publication 20160337126A1 · Nov 17, 2016