IP Library Granted Patent US 10,839,380
Granted Patent B2
US 10,839,380 · App. 15/513,781 · Granted Nov 17, 2020

Transaction process

Inventor: Caroline Grosser (Anzing, DE)
Assignee: Giesecke+Devrient Mobile Security GmbH
G06Q20/382G06Q20/0855G06Q20/322G06Q20/385G06Q30/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,839,380
App. No.
15/513,781
Granted
Nov 17, 2020
Kind
B2
Abstract

A method for anonymously carrying out a transaction, wherein one-time passwords encrypted by means of a one-way function are sent by an authentication server to a service device. The non-encrypted one-time passwords are sent by the authentication server to a secure element of a mobile device. In order for a transaction to be effected, the secure element sends the one-time passwords to the service device.

Claims (31)

1. A method for anonymously carrying out a transaction, the method comprising:

establishing a first connection between a secure element and an authentication server,

establishing a second connection between the authentication server and a payment device,

transferring an amount of money from the secure element to the payment device via the authentication server,

producing at least one one-time password, wherein the number of one-time passwords corresponds to the transferred amount of money, and

sending the produced one-time passwords to a service device via a third connection, wherein the at least one one-time password is sent only after its encryption with a one-way function.

2. The method according to claim 1 , wherein the one-way function is a hash function.

3. The method according to claim 2 , wherein the one-time password is supplied with a randomly chosen character sequence prior to encryption.

4. The method according to claim 1 , wherein the payment device confirms receipt of the amount of money to the authentication server.

5. The method according to claim 1 , wherein the authentication server sends the at least one one-time password to the secure element, wherein the sending is effected preferably in encrypted fashion.

6. The method according to claim 1 , wherein the authentication server produces the at least one one-time password.

7. The method according to claim 1 , wherein the authentication server has a list of the one-time passwords and of the one-time passwords encrypted with the one-way function.

8. The method according to claim 1 , wherein the authentication server sends the at least one one-time password to the service device via the third connection.

9. The method according to claim 1 , wherein the number of the one-time passwords corresponds to the sum of the amount of money.

10. The method according to claim 1 , wherein the service device has a list of the one-time passwords that have been encrypted with the one-way function and have not yet been employed.

11. The method according to claim 1 , wherein for concluding a transaction the secure element of a mobile device sends at least one one-time password not encrypted with the one-time function to the service device.

12. The method according to claim 11 , wherein the service device applies the one-way function to the sent one-time passwords.

13. The method according to claim 11 , wherein the number of sent one-time passwords corresponds to an amount of money payable to the service device.

14. The method according to claim 1 , wherein the secure element is storage unit in a mobile device in which data can be stored securely.

15. The method according to claim 14 , wherein the mobile device is a mobile phone or a tablet PC that is equipped with a contactless interface.

16. The method according to claim 1 , wherein the secure element is a chip firmly incorporated in a mobile device, is a SIM card, or is a micro SD card.

17. The method according to claim 1 , wherein the service device and the payment device are independent of each other.

18. The method according to claim 1 , wherein the number of sent one-time passwords corresponds to an amount of money payable to the service device, and money is subsequently transferred to the service device.

19. The method according to claim 1 , further comprising

establishing a fourth connection between the secure element and the service device,

the secure element transferring one of the passwords previously transferred to the service device via the fourth connection.

20. The method according to claim 1 , further comprising

establishing a fourth connection between the secure element and the service device,

the secure element sending a one-time password to the service device,

the service device applying the one-way function to the one-time password sent by the secure element, and

the service device checking whether a one-time password encrypted with the one-way function has been deposited with it matches the password encrypted with the one-way function.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2017
From: GIESECKE & DEVRIENT GMBH
To: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
Reel/Frame 043230/0485 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 23, 2017
From: GROSSER, CAROLINE
To: GIESECKE & DEVRIENT GMBH
Reel/Frame 042081/0723 →
Priority Claims (1)
DE 10 2014 014 109 · Sep 24, 2014 · national
Continuity (1)
Related Publication 20180232727A1 · Aug 16, 2018