IP Library Granted Patent US 12,190,304
Granted Patent B2
US 12,190,304 · App. 18/210,895 · Granted Jan 7, 2025

Embedded card reader security

Inventors: Murat Cat (Vaughan, CA); Murtaza Munaim (Fremont, CA); Gokhan Aydeniz (Mississauga, CA); Conrad Rushing (Brooklyn, NY)
Assignee: Block, Inc.
G06Q20/206G06Q20/4012
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,190,304
App. No.
18/210,895
Granted
Jan 7, 2025
Kind
B2
Abstract

Systems, devices, and methods for embedded card reader security include configuring a personal account number (PAN) application installed on a device to utilize an embedded card reader (ECR) and receiving, at the PAN application and based at least in part on an interaction between the ECR and the device, a PAN for a transaction. The PAN may be sent to a payment processing service and a personal identification number (PIN) application may render a PIN user interface. The PIN may be received at the PIN application and sent to the payment processing service. The transaction may be completed based at least in part on an indication from the payment processing service that the PAN and the PIN have been accepted.

Claims (60)

1. A device, comprising:

one or more processors; and

non-transitory computer-readable media storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

configuring a personal account number (PAN) application installed on the device to utilize an embedded card reader (ECR) of the device, wherein the PAN application is configured within a trusted execution environment (TEE) of the device, and wherein components within the TEE are isolated from components outside the TEE;

receiving, at the PAN application and based at least in part on an interaction between the ECR and the device, a PAN for a transaction;

sending, utilizing the PAN application, the PAN to a payment processing service;

in response to determining that the PAN has been received at the payment processing service, causing a personal identification number (PIN) application residing on the device to render a PIN user interface, wherein the PIN application is configured outside the TEE of the device, preventing communication between the PIN application and the PAN application;

receiving, at the PIN application and utilizing the PIN user interface, a PIN;

sending, utilizing the PIN application, the PIN to the payment processing service; and

completing the transaction based at least in part on an indication from the payment processing service that the PAN and the PIN have been accepted.

2. The device of claim 1 , the operations further comprising removing the PAN from the device in response to sending the PAN to the payment processing service.

3. The device of claim 1 , the operations further comprising:

receiving, from the payment processing service, a request for the PIN; and

removing the PAN from the device in response to receiving the request for the PIN.

4. The device of claim 1 , the operations further comprising removing the PAN from the device, wherein requesting the PIN is in response to removing the PAN from the device.

5. The device of claim 1 , the operations further comprising:

causing, after receiving the PAN, a trust routine to be performed in association with the device, the trust routine configured to determine whether the device has been tampered with;

determining that the trust routine indicates the device has not been tampered with; and

wherein requesting the PIN is in response to the trust routine indicating the device has not been tampered with.

6. The device of claim 1 , the operations further comprising:

in response to requesting the PIN, receiving an indication that user input is received that corresponds to the PIN; and

wherein completing the transaction is based at least in part on the user input corresponding to the PIN.

7. The device of claim 1 , wherein:

receiving the PAN comprises receiving encrypted first data representing the PAN from the ECR at the PAN application; and

receiving the PIN comprises receiving encrypted second data representing the PIN at the PIN application.

8. The device of claim 1 , wherein receiving the PIN comprises receiving encrypted data representing the PIN at the PIN application, and the operations further comprise:

sending the encrypted data to the payment processing service;

receiving, from the payment processing service, an indication that the PIN, as decrypted by the payment processing service, is authorized in association with the PAN; and

wherein completing the transaction is based at least in part on the PIN being authorized in association with the PAN.

9. The device of claim 1 , the operations further comprising removing, by the PAN application, the PAN from the device before requesting the PIN.

10. The device of claim 1 , wherein sending the PAN to the payment processing service further comprises sending a default PIN associated with the payment processing service.

11. A method, comprising:

configuring a personal account number (PAN) application installed on a device to utilize an embedded card reader (ECR) of the device, wherein the PAN application is configured within a trusted execution environment (TEE) of the device, and wherein components within the TEE are isolated from components outside the TEE;

receiving, at the PAN application and based at least in part on an interaction between the ECR and the device, a PAN for a transaction;

sending, utilizing the PAN application, the PAN to a payment processing service;

in response to determining that the PAN has been received at the payment processing service, causing a personal identification number (PIN) application residing on the device to render a PIN user interface, wherein the PIN application is configured outside the TEE of the device, preventing communication between the PIN application and the PAN application;

receiving, at the PIN application and utilizing the PIN user interface, a PIN;

sending, utilizing the PIN application, the PIN to the payment processing service; and

completing the transaction based at least in part on an indication from the payment processing service that the PAN and the PIN have been accepted.

12. The method of claim 11 , further comprising removing the PAN from the device in response to sending the PAN to the payment processing service.

13. The method of claim 11 , further comprising:

receiving, from the payment processing service, a request for the PIN; and

removing the PAN from the device in response to receiving the request for the PIN.

14. The method of claim 11 , further comprising removing the PAN from the device, wherein requesting the PIN is in response to removing the PAN from the device.

15. The method of claim 11 , further comprising:

causing, after receiving the PAN, a trust routine to be performed in association with the device, the trust routine configured to determine whether the device has been tampered with;

determining that the trust routine indicates the device has not been tampered with; and

wherein requesting the PIN is in response to the trust routine indicating the device has not been tampered with.

16. The method of claim 11 , further comprising:

in response to requesting the PIN, receiving an indication that user input is received that corresponds to the PIN; and

wherein completing the transaction is based at least in part on the user input corresponding to the PIN.

17. The method of claim 11 , wherein:

receiving the PAN comprises receiving encrypted first data representing the PAN from the ECR at the PAN application; and

receiving the PIN comprises receiving encrypted second data representing the PIN at the PIN application.

18. The method of claim 11 , wherein receiving the PIN comprises receiving encrypted data representing the PIN at the PIN application, and the method further comprises:

sending the encrypted data to the payment processing service;

receiving, from the payment processing service, an indication that the PIN, as decrypted by the payment processing service, is authorized in association with the PAN; and

wherein completing the transaction is based at least in part on the PIN being authorized in association with the PAN.

19. The method of claim 11 , further comprising removing, by the PAN application, the PAN from the device before requesting the PIN.

20. The method of claim 11 , wherein sending the PAN to the payment processing further comprises sending a default PIN associated with the payment processing service.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2023
From: CAT, MURAT; MUNAIM, MURTAZA; AYDENIZ, GOKHAN; RUSHING, CONRAD
To: SQUARE, INC.
Reel/Frame 064858/0181 →
CHANGE OF NAME Recorded Sep 11, 2023
From: SQUARE, INC.
To: BLOCK, INC.
Reel/Frame 064860/0699 →
Continuity (2)
Continuation 17183149 · Feb 23, 2021
Related Publication 20230410076A1 · Dec 21, 2023
References Cited (28)
US 20030061170A1 · Uzo et al. · 2003 [cited by applicant]
US 20030173401A1 · Yamagami · 2003 [cited by applicant]
US 20040203384A1 · Sugikawa et al. · 2004 [cited by applicant]
US 20060111081A1 · Whittington et al. · 2006 [cited by applicant]
US 20080040274A1 · Uzo et al. · 2008 [cited by applicant]
US 20080189214A1 · Mueller et al. · 2008 [cited by applicant]
US 20080294766A1 · Wang et al. · 2008 [cited by applicant]
US 20100049655A1 · Nilsson et al. · 2010 [cited by applicant]
US 20110246315A1 · Spies et al. · 2011 [cited by applicant]
US 20120185398A1 · Weis et al. · 2012 [cited by applicant]
US 20130144792A1 · Nilsson · 2013 [cited by examiner]
US 20140114855A1 · Bajaj et al. · 2014 [cited by applicant]
US 20200160347A1 · Quiroga et al. · 2020 [cited by applicant]
US 20200242588A1 · Rule et al. · 2020 [cited by applicant]
US 20220270064A1 · Cat et al. · 2022 [cited by applicant]
US 20220270069A1 · Cat et al. · 2022 [cited by applicant]
EP 1553518A1 · 2005 [cited by applicant]
GB 2508015A · 2014 [cited by applicant]
JP 2002163450A · 2002 [cited by applicant]
JP 2015114737A · 2015 [cited by applicant]
JP 2016133832A · 2016 [cited by applicant]
JP 2018125876A · 2018 [cited by applicant]
WO 2008144555A1 · 2008 [cited by applicant]
WO 2018126283A1 · 2018 [cited by applicant]
WO 2020214113A1 · 2020 [cited by applicant]
WO 2022182639A1 · 2022 [cited by applicant]
Ahmad et al., “Enhancing the Security of Mobile Applications by Using TEE and (U)SIM”, 2013 IEEE 10th International Conference on Ubiquitous Intelligence and Computing and 2013 Ieee 10th International Conference on Auto… [cited by applicant]
Ahmad et al., “Enhancing the Security of Mobile Applications by Using TEE and (U)SIM”, 2013 IEEE 10th International Conference on Ubiquitous Intelligence and Computing and 2013 IEEE 10th International Conference on Auto… [cited by applicant]