IP Library Granted Patent US 12,361,400
Granted Patent B2
US 12,361,400 · App. 17/361,629 · Granted Jul 15, 2025

Validation of merchant-associated devices during mobile transactions

Inventor: Max Edward Metral (Brookline, MA)
Assignee: PAYPAL, INC.
G06Q20/322G06Q20/02G06Q20/3224G06Q20/3278G06Q20/3829G06Q20/4014G06Q30/01G06Q2220/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,361,400
App. No.
17/361,629
Granted
Jul 15, 2025
Kind
B2
Abstract

Methods, systems, and computer program products for providing enhanced mobile transactions and payments are disclosed. A computer-implemented method may include providing a registry of public keys to allow users to securely exchange mobile payment data with respective trusted merchants, sending a request from a computing device of a user to validate a merchant, storing a public key for the merchant from the registry, receiving a merchant identifier from a terminal during a mobile transaction indicating that the terminal is associated with the merchant, receiving a request for information from the terminal as part of the mobile transaction, determining whether the terminal requesting the information is trusted, providing the requested information encrypted using the public key to the terminal when the terminal is trusted, and providing decoy response information to the terminal when the terminal is determined to be untrusted.

Claims (59)

1. A computer-implemented method, comprising:

establishing, by a user device with a second device associated with a merchant, a first wireless connection, the user device being associated with purchaser information for a user of the user device;

receiving, by the user device and from the second device associated with the merchant, a request for processing of a transaction via the first wireless connection between the user device and the second device, the request comprising a merchant identifier of the merchant and instructions indicating how to process at least a portion of the transaction on the user device;

responsive to receiving the request, initiating, at the user device, a processing of the transaction with the second device based on the purchaser information;

sending, by the user device to a server over a network, a validation request to validate that the second device is associated with the merchant;

receiving, by the user device and from the server over the network based on the validation request, a validation and a public key, wherein the validation indicates that the second device is authorized to receive the purchaser information, and wherein the public key is usable for encrypting data exchanged during a second wireless connection;

determining, by the user device, data for the merchant and corresponding to the at least the portion of the transaction and the purchaser information, wherein the data is responsive to the instructions;

encrypting, by the user device, the purchaser information and the data using the public key, wherein the purchaser information and the data are encrypted by the public key that causes the encrypted purchaser information and the data to appear differently in one or more communications from the first device;

establishing, by the user device with the second device, the second wireless connection based at least in part on the merchant identifier; and

communicating, by the user device via the second wireless connection, the encrypted purchaser information.

2. The method of claim 1 , further comprising:

receiving, by the user device, a confirmation of the processing of the transaction by the second device.

3. The method of claim 1 , further comprising, prior to the receiving the request, determining that the user device has performed a check-in with the merchant.

4. The method of claim 1 , wherein the establishing the first wireless connection comprises:

populating, by the user device, a request for the purchaser information from the second device as part of the transaction.

5. The method of claim 1 , wherein the merchant identifier indicates to the user device that the second device of the merchant is authenticated for facilitating transactions with the merchant.

6. The method of claim 1 , wherein the validation indicates that the second device of the merchant has processed one or more previous transactions with the server.

7. The method of claim 1 , wherein the public key is received from the server based on data stored by a registry of keys associated with the server.

8. The method of claim 1 , wherein the encrypting the purchaser information is performed in response to the validation of the second device of the merchant by the server.

9. The method of claim 1 , wherein the encrypting the purchaser information comprises:

encrypting, by the user device, payment card information using the public key in response to the validation of the second device; and wherein the method further comprises:

transmitting, by the user device, the encrypted payment card information to the second device for the processing of the transaction.

10. A device, comprising:

a non-transitory memory storing instructions; and

a processor executing the instructions, the instructions, when executed, causing the processor of the device to perform operations comprising:

establishing, with a second device associated with a merchant, a first wireless connection;

initiating a transaction with the second device, the transaction for a purchase of an item or a service from the merchant;

receiving, from the second device and in response to the initiating the transaction, a request for processing the transaction via the first wireless connection between the device and the second device, the request comprising a merchant identifier of the merchant and merchant data indicating how to process at least a portion of the transaction on the device;

responsive to receiving the request, sending, over a network to a server, a validation request that the second device is associated with the merchant;

receiving, from the server over the network based on the validation request, a validation and a public key, wherein the validation indicates that the second device is authorized to receive purchaser information for a user of the device, and wherein the public key is usable for encrypting data exchanged during a second wireless connection;

determining data for the merchant and corresponding to the at least the portion of the transaction and the purchaser information;

encrypting the purchaser information and the data for the merchant using the public key, wherein the purchaser information and the data for the merchant are encrypted by the public key that causes the encrypted purchaser information and the data for the merchant to appear differently in one or more communications from the device;

establishing the second wireless connection based at least in part on the merchant identifier; and

communicating, by the device via the second wireless connection, the encrypted purchaser information.

11. The device of claim 10 , wherein the initiating of the transaction is based on the device being in a physical proximity to the second device of the merchant.

12. The device of claim 10 , wherein the operations further comprise:

encrypting payment card information using the public key in response to the validation of the second device; and

communicating the encrypted payment card information to the second device of the merchant during processing of the transaction.

13. The device of claim 10 , wherein the operations further comprise prior to the receiving the request, determining that the device has performed a check-in with the merchant, and wherein initiating the transaction is a separate process from the check-in.

14. The device of claim 10 , wherein the establishing the first wireless connection comprises:

populating, by the device, a request for the purchaser information from the second device as part of the transaction.

15. The device of claim 10 , wherein the encrypting the purchaser information is performed in response to the validation of the second device of the merchant by the server.

16. A non-transitory machine-readable medium having stored thereon machine-readable instructions, the machine-readable instructions when executed by a processor of a user device, cause the processor to perform operations comprising:

establishing, by the user device with a second device associated with a merchant, a first wireless connection;

initiating a transaction with the second device, the transaction for a purchase of an item or a service from the merchant;

receiving, by the user device from the second device and in response to the initiating the transaction, a request for processing the transaction via the first wireless connection between the user device and the second device, the request comprising a merchant identifier of the merchant and merchant data indicating how to process at least a portion of the transaction on the user device;

responsive to receiving the communication session request, sending a validation request to a server that the second device is associated with the merchant for the transaction indicated by the communication session request;

receiving, by the user device and from the server over the network based on the validation request, a validation and a public key, wherein the validation indicates that the second device is authorized to receive purchaser information for a user of the user device, and wherein the public key is usable for encrypting data exchanged during a second wireless connection;

determining data for the merchant and corresponding to the at least the portion of the transaction and the purchaser information;

encrypting the purchaser information and the data for the merchant using the public, wherein the purchaser information and the data for the merchant are encrypted by the public key that causes the encrypted purchaser information and the data for the merchant to appear differently in one or more communications from the user device;

establishing the second wireless connection between the user device and the second device based at least in part on the merchant identifier; and

communicating, by the user device via the second wireless connection, the encrypted purchaser information.

17. The non-transitory machine-readable medium of claim 16 , wherein the initiating of the transaction is based on the user device being in a physical proximity to the second device of the merchant.

18. The non-transitory machine-readable medium of claim 16 , wherein the operations further comprise:

encrypting payment card information using the encryption key in response to the validation of the second device; and

communicating the encrypted payment card information to the second device of the merchant during processing of the transaction.

19. The non-transitory machine-readable medium of claim 16 , wherein the establishing the first wireless connection comprises, prior to the receiving the request, determining that the user device has performed a check-in with the merchant, and wherein the initiating the transaction is a separate process from the check-in.

20. The non-transitory machine-readable medium of claim 16 , wherein the operations further comprise:

populating, by the user device, a request for the purchaser information from the second device as part of the transaction.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2021
From: METRAL, MAX EDWARD
To: PAYPAL, INC.
Reel/Frame 056702/0099 →
Continuity (3)
Continuation 14984968 · Dec 30, 2015
Provisional Application 62131462 · Mar 11, 2015
Related Publication 20220012709A1 · Jan 13, 2022
References Cited (115)
US 6065120A · Laursen et al. · 2000 [cited by applicant]
US 6671716B1 · Diedrichsen et al. · 2003 [cited by applicant]
US 7418596B1 · Carroll et al. · 2008 [cited by applicant]
US 8020763B1 · Kowalchyk et al. · 2011 [cited by applicant]
US 8229852B2 · Carlson · 2012 [cited by applicant]
US 8700729B2 · Dua · 2014 [cited by examiner]
US 9135612B1 · Proctor, Jr. et al. · 2015 [cited by applicant]
US 9715689B1 · Ellis et al. · 2017 [cited by applicant]
US 10134202B2 · Schleicher · 2018 [cited by examiner]
US 10504179B1 · McGuire et al. · 2019 [cited by applicant]
US 11127001B2 · Tang · 2021 [cited by examiner]
US 11334865B1 · Bergantz · 2022 [cited by examiner]
US 11392934B1 · Gupta · 2022 [cited by examiner]
US 11397971B2 · Lakes · 2022 [cited by examiner]
US 12118612B2 · Brown · 2024 [cited by applicant]
US 20030093667A1 · Dutta · 2003 [cited by examiner]
US 20040199475A1 · Rivest et al. · 2004 [cited by applicant]
US 20050204128A1 · Aday et al. · 2005 [cited by applicant]
US 20080091614A1 · Bas Bayod · 2008 [cited by examiner]
US 20080103972A1 · Anc · 2008 [cited by applicant]
US 20080133351A1 · White et al. · 2008 [cited by applicant]
US 20080234047A1 · Nguyen · 2008 [cited by examiner]
US 20090125429A1 · Takayama · 2009 [cited by examiner]
US 20090327825A1 · Natsuno et al. · 2009 [cited by applicant]
US 20100327054A1 · Hammad · 2010 [cited by examiner]
US 20110137797A1 · Stals et al. · 2011 [cited by applicant]
US 20110276496A1 · Neville et al. · 2011 [cited by applicant]
US 20120016731A1 · Smith et al. · 2012 [cited by applicant]
US 20120179587A1 · Hill · 2012 [cited by examiner]
US 20120203701A1 · Ayuso De Paul · 2012 [cited by applicant]
US 20130080276A1 · Granbery · 2013 [cited by applicant]
US 20130191232A1 · Calman et al. · 2013 [cited by applicant]
US 20130191290A1 · Glendenning · 2013 [cited by examiner]
US 20130275222A1 · Amaro et al. · 2013 [cited by applicant]
US 20140025461A1 · Knowles et al. · 2014 [cited by applicant]
US 20140025958A1 · Calman · 2014 [cited by applicant]
US 20140040145A1 · Ozvat et al. · 2014 [cited by applicant]
US 20140040146A1 · Fiske · 2014 [cited by applicant]
US 20140040147A1 · Varadarajan et al. · 2014 [cited by applicant]
US 20140058951A1 · Kuppuswamy · 2014 [cited by examiner]
US 20140067690A1 · Pitroda · 2014 [cited by examiner]
US 20140074637A1 · Hammad · 2014 [cited by applicant]
US 20140108260A1 · Poole et al. · 2014 [cited by applicant]
US 20140129358A1 · Mathison · 2014 [cited by applicant]
US 20140249945A1 · Gauthier et al. · 2014 [cited by applicant]
US 20140279552A1 · Ortiz · 2014 [cited by examiner]
US 20150012425A1 · Mathew · 2015 [cited by applicant]
US 20150019443A1 · Sheets · 2015 [cited by examiner]
US 20150032627A1 · Dill et al. · 2015 [cited by applicant]
US 20150046338A1 · Laxminarayanan et al. · 2015 [cited by applicant]
US 20150052063A1 · Feraud · 2015 [cited by applicant]
US 20150058145A1 · Luciani · 2015 [cited by applicant]
US 20150081462A1 · Ozvat et al. · 2015 [cited by applicant]
US 20150088756A1 · Makhotin et al. · 2015 [cited by applicant]
US 20150095219A1 · Hurley · 2015 [cited by examiner]
US 20150127478A1 · Westby et al. · 2015 [cited by applicant]
US 20150127529A1 · Makhotin et al. · 2015 [cited by applicant]
US 20150200774A1 · Le Saint · 2015 [cited by examiner]
US 20160005009A1 · Li et al. · 2016 [cited by applicant]
US 20160012420A1 · Chitilian · 2016 [cited by examiner]
US 20160048836A1 · Sabatier · 2016 [cited by examiner]
US 20160055474A1 · Syed · 2016 [cited by applicant]
US 20160132873A1 · Elbaum et al. · 2016 [cited by applicant]
US 20160183033A1 · Pogorelik et al. · 2016 [cited by applicant]
US 20160189157A1 · Bavirisetty et al. · 2016 [cited by applicant]
US 20160196545A1 · Kwak · 2016 [cited by applicant]
US 20160196559A1 · Einhorn · 2016 [cited by examiner]
US 20160232534A1 · Lacey · 2016 [cited by examiner]
US 20160260116A1 · Xie et al. · 2016 [cited by applicant]
US 20160300237A1 · Khan · 2016 [cited by examiner]
US 20160323259A1 · Carlson · 2016 [cited by examiner]
US 20160364723A1 · Reese et al. · 2016 [cited by applicant]
US 20170103388A1 · Pillai · 2017 [cited by examiner]
US 20170148018A1 · Levin · 2017 [cited by applicant]
US 20170221055A1 · Carlsson · 2017 [cited by examiner]
US 20180047011A1 · Pedersoli · 2018 [cited by examiner]
US 20200082402A1 · Patel · 2020 [cited by examiner]
US 20200104822A1 · Govindarajan · 2020 [cited by examiner]
US 20200126061A1 · Chen · 2020 [cited by examiner]
US 20200382480A1 · Isaacson · 2020 [cited by examiner]
US 20200387887A1 · Rathod · 2020 [cited by examiner]
US 20230222507A1 · Patel · 2023 [cited by examiner]
US 20240013205A1 · Perito · 2024 [cited by examiner]
AU 2014290143A1 · 2016 [cited by examiner]
CA 2873695A1 · 2013 [cited by examiner]
CA 2911637A1 · 2014 [cited by examiner]
CN 1455894A · 2003 [cited by examiner]
CN 100377027C · 2008 [cited by examiner]
CN 102629921A · 2012 [cited by examiner]
CN 103067401A · 2013 [cited by examiner]
CN 103329154A · 2013 [cited by examiner]
CN 103067401B · 2015 [cited by examiner]
CN 102859543B · 2017 [cited by examiner]
EP 2733654A1 · 2014 [cited by examiner]
EP 2652694A4 · 2014 [cited by applicant]
GB 2424804A · 2006 [cited by examiner]
GB 2536044A · 2016 [cited by examiner]
JP 5791128B2 · 2015 [cited by applicant]
KR 20140114511A · 2014 [cited by examiner]
KR 20160098756A · 2016 [cited by examiner]
WO WO2013150333A1 · 2013 [cited by examiner]
WO WO2014049136A1 · 2014 [cited by examiner]
WO WO2014105226A1 · 2014 [cited by examiner]
WO WO2014107977A1 · 2014 [cited by examiner]
WO WO2015023999A1 · 2015 [cited by examiner]
Smart Card Alliance. Technologies for Payment Fraud Prevention: EMV, Encryption and Tokenization. https://www.emv-connection.com/downloads/2014/10/EMV-Tokenization-Encryption-WP-FINAL.pdf (Year: 2014). [cited by examiner]
R. Abdellaoui and M. Pasquet, “Secure Communication for Internet Payment in Heterogeneous Networks,” 2010 24th IEEE International Conference on Advanced Information Networking and Applications, Perth, WA, Australia, 201… [cited by examiner]
Dodson et al., Secure, Consumer-Friendly Web Authentication and Payments with a Phone. Computer Science Department Stanford University, Stanford, CA. 2012. https://eudl.eu/pdf/10.1007/978-3-642-29336-8_2 (Year: 2012). [cited by examiner]
Marforio et al., Smartphones as Practical and Secure Location Verification Tokens for Payments. https://ethz.ch/content/dam/ethz/special-interest/infk/inst-infsec/system-security-group-dam/research/publications/pub2014/… [cited by examiner]
J. Gao, V. Kulkarni, H. Ranavat, L. Chang and H. Mei, “A 2D Barcode-Based Mobile Payment System,” 2009 Third International Conference on Multimedia and Ubiquitous Engineering, Qingdao, China. https://ieeexplore.ieee.org… [cited by examiner]
P. Urien, “EMV-TLS, a secure payment protocol for NFC enabled mobiles, ” 2014 International Conference on Collaboration Technologies and Systems (CTS), Minneapolis, MN, USA, 2014, pp. 203-210. https://ieeexplore.ieee.or… [cited by examiner]
International Preliminary Report on Patentability for Application No. PCT/US2016/031325 mailed on Sep. 21, 2017, 6 pages. [cited by applicant]
International Appl. No. PCT/US2015/063452, International Search Report and Written Opinion mailed Feb. 1, 2016, 9 pages. [cited by applicant]
International Appl. No. PCT/US2016/031325, International Search Report and Written Opinion dated Aug. 5, 2016, 6 pages. [cited by applicant]
Pauralji A., “The Presentation of an Ideal Safe SMS Based Model in Mobile Electronic Commerce Using Encryption Hybrid Algorithms AES and ECC”, https://ieeexplore.ieee.org/stamp/stamp.jsptp=&arnumber=6836761, Apr. 2014, … [cited by applicant]