IP Library Granted Patent US 10,269,011
Granted Patent B2
US 10,269,011 · App. 15/274,951 · Granted Apr 23, 2019

Configuring a plurality of security isolated wallet containers on a single mobile device

Inventors: Mehul Desai (Oak Brook, IL); Satyan G. Pitroda (Oak Brook, IL); Nehal Maniar (Oak Brook, IL)
Assignee: MASTERCARD MOBILE TRANSACTIONS SOLUTIONS, INC.
G06Q20/3829G06F8/65G06Q20/08G06Q20/105G06Q20/322G06Q20/36G06Q20/3674G06Q20/382G06Q20/40G06Q30/06G06Q30/0641
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,269,011
App. No.
15/274,951
Granted
Apr 23, 2019
Kind
B2
Abstract

Configuring a plurality of security isolated wallet containers on a single mobile device includes configuring at least one mobile transaction platform-specific application programming interface for facilitating access to secure mobile transaction platform resources by a wallet container executing on a mobile device; disposing a plurality of distinct wallet containers in a memory of the mobile device, wherein each wallet container interfaces with secure mobile transaction platform resources via the at least one application programming interface; disposing at least one service provider-specific wallet in each of the plurality of distinct wallet containers; and enforcing service-provider specific wallet security by a distinct wallet container accessing a portion of the secure mobile transaction platform resources via the at least one application programming interface.

Claims (30)

1. A high security mobile electronic transaction device for ensuring isolated access to a plurality of distinct service-provider specific electronic wallets disposed in a non-transient memory of the device comprising:

a non-transient memory accessible by a processor of the mobile device;

at least one mobile transaction platform-specific application programming interface stored in the memory and configured to facilitate access to secure mobile transaction platform resources by a wallet container executing on the mobile device;

a wallet container disposed in the memory of the mobile device and executable by the processor, wherein the wallet container interfaces with secure mobile transaction platform resources via the at least one application programming interface, the wallet container comprising:

an access controller that ensures a wallet disposed in the at least one of the plurality of distinct wallet containers only has access to mobile device resources to which the disposed wallet has permissions by limiting access to the at least one application programming interface;

at least one service provider-specific wallet disposed in the wallet container, wherein service provider-specific wallet security is enforced by the wallet container accessing a portion of the secure mobile transaction platform resources via the at least one application programming interface; and

at least one wallet companion applet, for each of the at least one service provider-specific wallets, stored in a particular non-volatile service provider-specific security domain of a plurality of non-volatile service provider-specific security domains of a secure element, wherein the particular security domain comprises the at least one wallet companion applet and at least one other applet, the security domain and all applets disposed therein being accessible as a group by the mobile transaction platform when using unique, security through use of domain-specific security keys when accessing the secure element.

2. The mobile device of claim 1 , wherein a mobile transaction platform with which the mobile transaction platform-specific application programming interface is associated comprises an enabling tier, a service tier, and a personalization tier.

3. The mobile device of claim 1 , wherein the application programming interface is mobile device-independent.

4. The mobile device of claim 1 , wherein the application programming interface is mobile device operating environment-specific.

5. The mobile device of claim 1 , wherein the wallet container cannot impact access to secure mobile transaction platform resources of a second wallet container.

6. The mobile device of claim 1 , wherein a mobile transaction platform with which the mobile transaction platform-specific application programming interface is associated supports multiple independent wallet containers operating on a single mobile device.

7. The mobile device of claim 1 , wherein service-provider specific wallet security is enabled to facilitate keeping service provider-specific information separate and confidential from other service providers with which the at least one wallet interacts via the mobile device.

8. The mobile device of claim 1 , wherein a wallet container executing on the mobile device comprises a run-time environment for interpreting at least one of the wallet and an applet.

9. The mobile device of claim 1 , wherein the wallet container facilitates security of transactions between external service provider resources and at least one wallet by isolating access of service provider resources from unauthorized wallets.

10. The mobile device of claim 1 , wherein the wallet container provides defined transaction patterns for implementing complex security for mobile transactions among wallets and service providers.

11. A high security mobile electronic transaction device for ensuring isolated access to a plurality of distinct service-provider specific security domains disposed in a non-transient memory of the device comprising:

a non-transient memory accessible by a processor of the mobile device;

at least one mobile transaction platform-specific application programming interface stored in the memory and configured to facilitate access to secure mobile transaction platform resources by a wallet container executing on the mobile device;

a distinct wallet container disposed in the memory of the mobile device and executable by the processor, wherein the wallet container ensures a wallet disposed in the distinct wallet container only has access to mobile device resources to which the disposed wallet has permissions by limiting access to the at least one application programming interface; and

at least one wallet companion applet, for the wallet, stored in a non-volatile service provider-specific security domain of a non-volatile secure element comprising the at least one wallet companion applet and at least one other applet, the security domain and all applets disposed therein being accessible as a group through use of domain-specific security keys when accessing the secure element.

12. The mobile device of claim 11 , wherein a mobile transaction platform with which the mobile transaction platform-specific application programming interface is associated comprises an enabling tier, a service tier, and a personalization tier.

13. The mobile device of claim 11 , wherein the application programming interface is mobile device-independent.

14. The mobile device of claim 11 , wherein the application programming interface is mobile device operating environment-specific.

15. The mobile device of claim 11 , wherein the wallet container cannot impact access to secure mobile transaction platform resources of a second wallet container.

16. The mobile device of claim 11 , wherein a mobile transaction platform with which the mobile transaction platform-specific application programming interface is associated supports multiple independent wallet containers operating on a single mobile device.

17. The mobile device of claim 11 , wherein the wallet container facilitates keeping service provider-specific information separate and confidential from other service providers with which the at least one wallet interacts via the mobile device.

18. The mobile device of claim 11 , wherein a wallet container executing on the mobile device comprises a run-time environment for interpreting at least one of the wallet and an applet.

19. The mobile device of claim 11 , wherein the wallet container facilitates security of transactions between external service provider resources and at least one wallet by isolating access of service provider resources from unauthorized wallets.

20. The mobile device of claim 11 , wherein the wallet container provides defined transaction patterns for implementing complex security for mobile transactions among wallets and service providers.

Assignments (2)
CHANGE OF NAME Recorded Sep 23, 2016
From: C-SAM, INC.
To: MASTERCARD MOBILE TRANSACTIONS SOLUTIONS, INC.
Reel/Frame 040144/0217 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2016
From: DESAI, MEHUL; PITRODA, SATYAN G.; MANIAR, NEHAL
To: C-SAM, INC.
Reel/Frame 039848/0534 →
Continuity (8)
Continuation 14154620 · Jan 14, 2014
Continuation 13909262 · Jun 4, 2013
Continuation 13651028 · Oct 12, 2012
Continuation In Part 11539024 · Oct 5, 2006
Provisional Application 60724066 · Oct 6, 2005
Provisional Application 61546084 · Oct 12, 2011
Provisional Application 61619751 · Apr 3, 2012
Related Publication 20170011396A1 · Jan 12, 2017
Cited By (2)
US 12,217,244 US 12,626,239