IP Library Granted Patent US 10,628,817
Granted Patent B2
US 10,628,817 · App. 15/967,503 · Granted Apr 21, 2020

Processing payment transactions without a secure element

Inventor: Sarel Kobus Jooste (Novato, CA)
Assignee: Google LLC
G06Q20/202G06Q20/3278G06Q20/363G06Q20/40
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,628,817
App. No.
15/967,503
Granted
Apr 21, 2020
Kind
B2
Abstract

A user conducts a wireless payment transaction with a merchant system by transmitting payment information from a user device to a terminal reader without accessing a secure element resident on the user device. A user taps a user device in a merchant system's terminal reader's radio frequency field. The terminal reader and the user device establish a communication channel and the terminal reader transmits a signal comprising a request for a payment processing response. The signal is received by the user device and converted by a controller to a request understandable by an application host processor. The controller transmits the request to the application host processor, where the request is processed, and a response is transmitted to the controller and then to the terminal reader. The response generated by the application host processor is identifiable by the merchant system as a payment response.

Claims (45)

1. A computer-implemented method to process payment transactions without accessing secure memories, comprising:

receiving, by a mobile computing device and from a merchant system computing device, a request for payment account information to process a payment transaction;

processing, by the mobile computing device, the request for the payment account information by converting the request for the payment account information to a request understandable by a non-secure memory processor;

generating, by the non-secure memory processor of the mobile computing device, a response to the request for the payment account information that is indistinguishable from a response generated by a secure memory processor, the response comprising a payment account identifier; and

transmitting, by the mobile computing device, the response to the request for the payment account information to the merchant system computing device.

2. The computer-implemented method of claim 1 , wherein the payment account identifier is generated by the mobile computing device.

3. The computer-implemented method of claim 1 , wherein the payment account identifier is generated by an account management system and transmitted to the mobile computing device, wherein the account management system maintains an account comprising information for at least one of a credit card account, debit account, stored value account, gift card account, and bank account for a user associated with the mobile computing device.

4. The computer-implemented method of claim 1 , wherein the payment account identifier is valid for a limited number of uses.

5. The computer-implemented method of claim 1 , wherein the payment account identifier is associated with at least one of a geographic limitation and a time limitation.

6. The computer-implemented method of claim 1 , wherein the payment account identifier comprises one of a credit card account, debit account, stored value account, gift card account, and bank account number.

7. The computer-implemented method of claim 1 , wherein the payment account identifier is retrieved from a digital wallet application on the mobile computing device.

8. The computer-implemented method of claim 1 , wherein the request for a payment processing response is received using a near field communication (NFC) protocol.

9. The computer-implemented method of claim 2 , further comprising communicating, by the mobile computing device, the payment account identifier to an account management system for payment account identifier verification during processing of a payment request.

10. The computer-implemented method of claim 2 , wherein the non-secure memory processor resident on the mobile computing device generates the payment account number using a scheme that can be replicated by an account management system during processing of a payment request.

11. A computer program product, comprising:

a non-transitory computer-readable medium having computer-readable program instructions embodied thereon that when executed by a mobile computing device cause the mobile computing device to process payment transactions without accessing secure memories, the computer-readable program instructions comprising:

computer-readable program instructions to receive from a merchant computing device, a request for payment account information to process a payment transaction;

computer-readable program instructions to process the request for the payment account information by converting the request for the payment account information to a request understandable by a non-secure memory processor;

computer-readable program instructions to generate a response to the request for the payment account information that is indistinguishable from a response generated by a secure memory processor, the response comprising a payment account identifier; and

computer-readable program instructions to transmit the response to the request for the payment account information to the merchant computing device.

12. The computer program product of claim 11 , wherein the payment account identifier comprises a proxy account number generated by the mobile computing device.

13. The computer program product of claim 11 , wherein the payment account identifier comprises a proxy account number generated by an account management system and transmitted to the mobile computing device, wherein the account management system maintains an account comprising information for one of a credit card account, debit account, stored value account, gift card account, and bank account number for a user associated with the mobile computing device.

14. The computer program product of claim 11 , wherein the payment account identifier comprises a proxy account number that is valid for a limited number of uses.

15. The computer program product of claim 11 , wherein the payment account identifier comprises a proxy account number that is associated with at least one of a geographic limitation and a time limitation.

16. The computer-implemented method of claim 1 , wherein the mobile computing device converts the request for payment account information received from the merchant computing device into bytes comprising a request understandable by the non-secure memory processor.

17. A mobile computing device for processing payment transactions, comprising:

a storage device;

a controller communicatively coupled to the storage device; and

a processor communicatively coupled to the storage device and the controller, the controller of the mobile computing device executing application code instructions that are stored in the storage device to cause the mobile computing device to:

receive a request for payment account information to process a payment transaction from a merchant system computing device; and

process the request for the payment account information by converting the request for the payment account information to a request understandable by the processor; and

the processor of the mobile computing device executing application code instructions that are stored in the storage device to cause the mobile computing device to:

generate a response to the request for the payment account information that is indistinguishable from a response generated by a secure element processor, the response comprising a payment account identifier.

18. The mobile computing device of claim 17 , wherein the payment account identifier is generated by a non secure memory processor.

19. The mobile computing device of claim 17 , wherein the payment account identifier is retrieved from a digital wallet application on the mobile computing device.

20. The mobile computing device of claim 17 , wherein the processor of the mobile computing device is further configured to execute computer-executable instructions stored in the storage device to cause the mobile computing device to generate the payment account identifier using a scheme that can be replicated by an account management system during processing of a payment request.

21. The mobile computing device of claim 17 , wherein the payment account identifier is generated by an account management system and transmitted to the mobile computing device, and the account management system maintains an account comprising information for at least one of a credit card account, debit account, stored value account, gift card account, and bank account for a user associated with the mobile computing device.

22. The mobile computing device of claim 17 , wherein the payment account identifier is valid for a limited number of uses.

23. The mobile computing device of claim 17 , wherein the payment account identifier is associated with at least one of a geographic limitation and a time limitation.

24. The mobile computing device of claim 17 , wherein the processor of the mobile computing device is further configured to execute computer-executable instructions stored in the storage device to cause the mobile computing device to communicate the payment account identifier to an account management system for payment account identifier verification, the communication to the account management system comprising the response to the request for the payment account information transmitted by the mobile computing device to the merchant computing device.

25. The system of claim 17 , wherein the processor of the mobile computing device generates the payment account identifier using a scheme that can be replicated by an account management system during processing of a payment request.

26. The mobile computing device of claim 17 , wherein the controller comprises a near field communication controller.

27. The mobile computing device of claim 17 , wherein the controller comprises a Bluetooth controller.

28. The mobile computing device of claim 17 , wherein storage device comprises a secure memory other than a secure element memory.

29. The mobile computing device of claim 17 , wherein storage device comprises a combination memory with secure memory and non-secure memory portions.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2018
From: JOOSTE, SAREL KOBUS
To: GOOGLE INC.
Reel/Frame 045793/0513 →
CHANGE OF NAME Recorded May 14, 2018
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 046714/0283 →
Continuity (4)
Continuation 14918536 · Oct 20, 2015
Continuation 13859725 · Apr 9, 2013
Provisional Application 61635277 · Apr 18, 2012
Related Publication 20180247290A1 · Aug 30, 2018