IP Library › Granted Patent US 12,039,516
Granted Patent B2
US 12,039,516 · App. 17/864,450 · Granted Jul 16, 2024

Secure payment transactions

Inventors: Ivo Alexandrov Gueorguiev (London, GB); Diyan Stefanov Nedelchev (Burgas, BG); Antonina Ivanova Martinova (Sofia, BG)
Assignee: PHOS SERVICES LTD
G06Q20/3278G06Q20/027G06Q20/38215G06Q20/3829G06Q20/4012G06Q2220/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,039,516
App. No.
17/864,450
Granted
Jul 16, 2024
Kind
B2
Abstract

A client comprising an application for secure payment transactions is provided. The application runs on a personal mobile communication device and the client accesses a service provided by a server, which includes a payment gateway. Various security measures are included in the client-server communication related to executing payment transactions in a secure environment.

Claims (49)

1. A personal mobile communication device comprising:

a secured storage;

a communication interface; and

a processor, the processor runs a client for performing payment transactions on the personal mobile communication device, wherein the client is configured to:

store in the secured storage

a private key, wherein the private key is the private key of a private-public key pair, and

an encrypted device key from a terminal management server in response to an attestation request, wherein the encrypted device key is encrypted using a public key which is the public key of the private-public key pair,

in response to a payment transaction request, reads a contactless card related to the payment request by the communication interface;

send payment information of the payment transaction request to a payment gateway of the terminal management server for processing by a card processor, wherein the payment information comprises, among other information, payment data, contactless card data, an authorization token and a last transaction token, the last transaction token is a token generated during a previous successful transaction, the payment information is encrypted with an unencrypted device key derived from decrypting the encrypted device key using the private key,

if a rejection notification is received from the payment gateway, terminate the payment transaction,

if an approval response is received from the payment gateway when the payment transaction request is approved by the card processor for execution of the payment transaction request, continue to execute the payment transaction, and

receive a renewed last transaction token from the payment gateway, the renewed transaction token replaces the last transaction token, the renewed transaction token serves as the last transaction token for a subsequent payment transaction.

2. The personal mobile communication device of claim 1 wherein the private-public key pair is generated during initial sign-up.

3. The personal mobile communication device of claim 1 wherein the attestation request to the terminal management server comprises the public key signed with an application certificate.

4. The personal mobile communication device of claim 1 wherein the client is configured to delete the payment information after sending to the payment gateway.

5. The personal mobile communication device of claim 1 wherein the client is configured to receive a rejection response from the payment gateway if payment transaction request is rejected by the card processor.

6. The personal mobile communication device of claim 1 , wherein the attestation request further comprises a mobile communication device ID and login credentials.

7. The personal mobile communication device of claim 1 , wherein the payment information comprises payment data, contactless card data, and an authorization session token received from the management server upon logging in to the management server.

8. The personal mobile communication device of claim 6 , wherein the client is further configured to receive one or more PIN certificates from the terminal management server upon attestation and store the one or more PIN certificates in the secure storage.

9. The personal mobile communication device of claim 8 , wherein the payment information further comprises a PIN block data, when a transaction amount is beyond a predefined limit, and wherein the PIN block data comprises a PIN associated with the contactless card, the PIN encrypted with a certificate from the one or more PIN certificates respective to an issuer of the contactless card.

10. The personal mobile communication device of claim 1 , wherein the communication interface is Near Field Communication.

11. The personal mobile communication device of claim 1 , wherein the client is configured to receive an authorization session token from the terminal management server upon logging in.

12. A method for performing payment transactions on a personal mobile communication device comprising:

storing a private key in a secured storage of the personal mobile communication device, wherein the private key is the private key of a private-public key pair;

storing an encrypted device key in the secured storage of the personal mobile communication device, the encrypted device key is from a terminal management server in response to an attestation request, wherein the encrypted device key is encrypted using a public key which is the public key of the private-public key pair;

reading a contactless card used for a payment transaction request in response to the payment transaction request by a communications interface of the personal mobile communication device;

sending, by the personal mobile communication device, payment information of a payment transaction request to a payment gateway of the terminal management server for processing by a card processor, wherein the payment information comprises payment data, contactless card data, an authorization token and a last transaction token, the last transaction token is a token generated during a previous successful transaction, the payment information is encrypted with an unencrypted device key derived from decrypting the encrypted device key using the private key; and

terminating the payment transaction if a rejection notification is received from the payment gateway, or

continuing to execute the payment transaction if an approval response is received from the payment gateway when the card processor approves the payment transaction request, and

receiving a renewed last transaction token from the payment gateway, the renewed last transaction token serves as the last transaction token for a subsequent payment transaction request.

13. The method of claim 12 wherein the private-public key pair is generated during initial sign-up.

14. The method of claim 12 comprises sending of claim 1 wherein the attestation request comprises the public key signed with an application certificate.

15. The method of claim 12 comprises deleting the payment information after sending to the payment gateway.

16. The method of claim 12 comprises receiving a rejection response from the payment gateway if the payment transaction request is rejected by the card processor.

17. A method for managing secure payment transactions by a terminal management server comprising:

registering a mobile communication device ID of a personal mobile communication device comprising a client an application for secured payment transactions and login credentials associated with the mobile communication device ID;

generating a device key and sending the device key encrypted with a public key of a public/private key pair (encrypted device key) to the client upon attestation of the mobile communication device;

sending an authorization session token to the client upon logging in by the client;

receiving payment information from the client for a payment transaction request for processing, wherein the payment information comprises payment data, contactless card data, an authorization token and a last transaction token, the last transaction token is a token generated during a previous successful transaction, the payment information is encrypted with the device key after decrypting the encrypted device key using a private key of the public/private key pair;

decrypting the received payment information and checking the received payment information for the authorization session token and a last transaction token;

sending the payment information for processing to a card processor after confirming a match of the authorization session token and last transaction token; and

if receiving a rejection response rejecting the payment transaction, continue by sending the rejection response to the client with a notification to terminate the payment transaction request, or

if receiving an approval response approving the payment transaction request, continue by sending the approval response to the client with a notification to continue executing the payment transaction request, and

generating and sending a renewed last transaction token to the client, the renewed last transaction token serves as the last transaction token for a subsequent payment transaction request from the client.

18. The method of claim 17 comprises:

receiving, by the terminal management server, a rejection response from the card processor if the card processor rejects the payment transaction request; and

sending a rejection response to the client to notify the client of the rejection of the payment request.

19. The method of claim 17 wherein the terminal management server comprises a payment gateway for communicating with the client and the card processor.

20. The method of claim 17 wherein the payment information comprises payment data, contactless card data, the authorization session token and the last transaction token.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2026
From: THE PHOS SERVICES LTD
To: BANKS AND ACQUIRERS INTERNATIONAL HOLDING
Reel/Frame 074585/0612 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2022
From: GUEORGUIEV, IVO ALEXANDROV; NEDELCHEV, DIYAN STEFANOV; MARTINOVA, ANTONINA IVANOVA
To: PHOS SERVICES LTD
Reel/Frame 060512/0796 →
Continuity (3)
Continuation 16917850 · Jun 30, 2020
Continuation In Part 16491580
Related Publication 20220351183A1 · Nov 3, 2022