IP Library Granted Patent US 12,354,092
Granted Patent B2
US 12,354,092 · App. 18/405,467 · Granted Jul 8, 2025

Establishment of a secure session between a card reader and a mobile device

Inventors: Max Joseph Guise (San Francisco, CA); Jason Waddle (Alameda, CA); Dino Dai Zovi (San Francisco, CA)
Assignee: Block, Inc.
G06Q20/3829G06Q20/202G06Q20/204G06Q20/206G06Q20/322G06Q20/3226G06Q20/3567G06Q20/4012G07F7/0886G07G1/0009G07G1/0036G07G1/14H04L9/0841G06Q2220/00H04L9/0861H04L9/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,354,092
App. No.
18/405,467
Granted
Jul 8, 2025
Kind
B2
Abstract

In some examples, a computer system receives, via a network and from a software module executable on a mobile device coupled to a card reader, security information that includes first security information associated with the card reader and second security information that is based on content of the software module and/or a software environment of the software module. The computer system determines validity of the first security information associated with the card reader based at least on information previously stored in the card reader and also accessible to the computer system. The computer system also determines the validity of the second security information. Based on determining the first and second security information are valid, the computer system sends, to the mobile device, an indication that the computer system has validated the security information, prompting the software module and the card reader to establish a secure communication session with each other.

Claims (88)

1. A system comprising:

a mobile device that includes one or more first processors;

a card reader coupled to the mobile device; and

a computer system that includes one or more second processors configured by first executable instructions to cause the computer system to perform first operations that include:

detecting an initiation of a card reader session between the mobile device and the card reader coupled to the mobile device;

in response to detecting the initiation, receiving, by the computer system, via a network, and from a software module executable on the mobile device:

first security information associated with the card reader based on information previously stored in the card reader, and

second security information based at least in part on content of at least one of the software module or a software environment of the software module;

determining, by the computer system, that the first security information associated with the card reader is valid based at least on the information previously stored in the card reader and also stored at or made accessible to the computer system;

determining, by the computer system, that the second security information is valid;

based on determining that the first security information and the second security information are valid, sending, by the computer system, to the mobile device, a success message indicating that the computer system has validated the first security information of the card reader and the second security information of the software module; and

wherein the one or more first processors are configured by second executable instructions to cause the mobile device to perform second operations comprising:

receiving the success message; and

in response to receiving the success message, establishing a secure communication session between the mobile device and the card reader.

2. The system as recited in claim 1 , wherein:

the first security information associated with the card reader comprises a digital signature of the card reader that is based on digital signature information previously stored on the card reader; and

corresponding digital signature information for the card reader is previously stored at or made accessible to the computer system.

3. The system as recited in claim 1 , wherein the second security information is derived by at least one of the software module or another software module executable on the mobile device, and is derived from at least one of:

the software module on the mobile device; or

the software environment of the software module on the mobile device.

4. The system as recited in claim 1 , wherein the first operation of determining, by the computer system, that the second security information is valid comprises:

comparing, by the computer system, the second security information with previously received security information corresponding to the software module, the previously received security information having been received from at least one of:

a provider of the software module; or

a plurality of other mobile devices executing the software module.

5. The system as recited in claim 1 , wherein the first operation of determining, by the computer system, that the second security information comprises checking the second security information for an indication of one or more of:

a jailbreaking of the mobile device;

an operation of a debugger on the mobile device;

a presence of unauthorized software on the mobile device; or

an unauthorized modification of the software module.

6. The system as recited in claim 1 , wherein the first operation of sending, by the computer system, to the mobile device, the success message comprises:

signing, by the computer system, with a digital signature of the computer system, a cryptographic key associated with the software module; and

sending the digitally signed cryptographic key to the mobile device.

7. A method comprising:

detecting an initiation of a card reader session between a mobile device and a card reader coupled to the mobile device;

in response to detecting the initiation, receiving, by a computer system, via a network, and from a software module executable on the mobile device:

first security information associated with the card reader based on information previously stored in the card reader, and

second security information based at least in part on content of at least one of the software module or a software environment of the software module;

determining, by the computer system, at least one of:

the first security information associated with the card reader is invalid based at least on the information previously stored in the card reader and also stored at or made accessible to the computer system; or

the second security information is invalid;

based on determining that at least one of the first security information or the second security information are invalid, sending, by the computer system, to the mobile device, a failure message indicating that the computer system has determined that the first security information of the card reader or the second security information of the software module are invalid, wherein the failure message precludes the software module and the card reader from establishing the card reader session with each other;

receiving, at the mobile device, the failure message; and

in response to receiving the failure message, preventing, by the mobile device, the card reader session with the card reader from being established.

8. The method as recited in claim 7 , wherein:

the first security information associated with the card reader comprises a digital signature of the card reader that is based on digital signature information previously stored on the card reader; and

corresponding digital signature information for the card reader is previously stored at or made accessible to the computer system.

9. The method as recited in claim 7 , wherein the second security information comprises at least one of a checksum, a cyclic redundancy check, a sampling, or a hash of at least a portion of at least one of:

the software module on the mobile device; or

the software environment of the software module on the mobile device.

10. The method as recited in claim 7 , wherein determining, by the computer system, the second security information is invalid comprises:

comparing, by the computer system, the second security information with previously received security information corresponding to the software module, the previously received security information having been received from at least one of:

a provider of the software module; or

a plurality of other mobile devices executing the software module.

11. The method as recited in claim 7 , wherein determining, by the computer system, the second security information is invalid comprises checking the second security information for an indication of one or more of:

a jailbreaking of the mobile device;

an operation of a debugger on the mobile device;

a presence of unauthorized software on the mobile device; or

an unauthorized modification of the software module.

12. One or more non-transitory computer-readable media storing instructions executable by one or more processors of a computer system to configure the computer system to perform first operations comprising:

detecting an initiation of a card reader session between a mobile device and a card reader coupled to the mobile device;

in response to detecting the initiation, receiving, by the computer system, via a network, and from a software module executable on the mobile device:

first security information associated with the card reader based on information previously stored in the card reader, and

second security information based at least in part on content of at least one of the software module or a software environment of the software module;

determining, by the computer system, that the first security information associated with the card reader is valid based at least on the information previously stored in the card reader and also stored at or made accessible to the computer system;

determining, by the computer system, that the second security information is valid;

based on determining that the first security information and the second security information are valid, sending, by the computer system, to the mobile device, a success message indicating that the computer system has validated the first security information of the card reader and the second security information of the software module; and

the one or more non-transitory computer-readable media storing instructions executable by one or more second processors of the mobile device to configure the mobile device to perform second operations comprising:

receiving the success message; and

in response to receiving the success message, establishing a secure communication session between the mobile device and the card reader.

13. The one or more non-transitory computer-readable media as recited in claim 12 , wherein:

the first security information associated with the card reader comprises a digital signature of the card reader that is based on digital signature information previously stored on the card reader; and

corresponding digital signature information for the card reader is previously stored at or made accessible to the computer system.

14. The one or more non-transitory computer-readable media as recited in claim 12 , wherein the second security information comprises at least one of a checksum, a cyclic redundancy check, a sampling, or a hash of at least a portion of at least one of:

the software module on the mobile device; or

the software environment of the software module on the mobile device.

15. The one or more non-transitory computer-readable media as recited in claim 12 , wherein the first operation of determining, by the computer system, the second security information is valid comprises:

comparing, by the computer system, the second security information with previously received security information corresponding to the software module, the previously received security information having been received from at least one of:

a provider of the software module; or

a plurality of other mobile devices executing the software module.

16. The one or more non-transitory computer-readable media as recited in claim 12 , wherein the first operation of sending, by the computer system, to the mobile device, the success message comprises:

signing, by the computer system, with a digital signature of the computer system, a cryptographic key associated with the software module; and

sending the digitally signed cryptographic key to the mobile device.

17. The system as recited in claim 1 , wherein the first operation of determining that the second security information is valid is a precondition for the second operation of establishing the secure communication session between the mobile device and the card reader.

18. The system as recited in claim 1 , wherein the second security information associated with the software module comprises:

a public key generated by the software module and digitally signed or authenticated by the software module; and

additional security data that includes a fingerprint of the software module, wherein determining that the second security information is valid includes comparing the fingerprint to a stored fingerprint previously generated for the software module.

19. The method as recited in claim 7 , further comprising, in response to determining that the first security information is invalid, maintaining an indication of the determination of invalidity of the first security information on the computer system to use in validation of the card reader in one or more subsequent initiations of card reader sessions with the card reader.

20. The one or more non-transitory computer-readable media as recited in claim 12 , wherein the first operation of determining that the second security information is valid is a precondition for the second operation of establishing the secure communication session between the mobile device and the card reader.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2024
From: GUISE, MAX JOSEPH; WADDLE, JASON; DAI ZOVI, DINO
To: SQUARE, INC.
Reel/Frame 066177/0315 →
CHANGE OF NAME Recorded Jan 19, 2024
From: SQUARE, INC.
To: BLOCK, INC.
Reel/Frame 066355/0929 →
Continuity (5)
Continuation 17854468 · Jun 30, 2022
Division 15497388 · Apr 26, 2017
Division 14614350 · Feb 4, 2015
Continuation 14273447 · May 8, 2014
Related Publication 20240144259A1 · May 2, 2024
References Cited (85)
US 5204902A · Reeds et al. · 1993 [cited by applicant]
US 5241599A · Bellovin et al. · 1993 [cited by applicant]
US 5903652A · Mital · 1999 [cited by applicant]
US 6148404A · Yatsukawa · 2000 [cited by applicant]
US 6772331B1 · Hind et al. · 2004 [cited by applicant]
US 7302564B2 · Berlin · 2007 [cited by applicant]
US 7788491B1 · Dawson · 2010 [cited by applicant]
US 7929702B2 · Brown et al. · 2011 [cited by applicant]
US 8127345B2 · Gregg et al. · 2012 [cited by applicant]
US 8254579B1 · Morgan et al. · 2012 [cited by applicant]
US 8281998B2 · Tang et al. · 2012 [cited by applicant]
US 8472629B2 · Hamachi · 2013 [cited by applicant]
US 8494165B1 · Monica et al. · 2013 [cited by applicant]
US 8788825B1 · Le et al. · 2014 [cited by applicant]
US 8874913B1 · Monica et al. · 2014 [cited by applicant]
US 8880881B2 · Morel et al. · 2014 [cited by applicant]
US 8978975B2 · Barnett · 2015 [cited by applicant]
US 8990121B1 · Guise et al. · 2015 [cited by applicant]
US 9141977B2 · Davis et al. · 2015 [cited by applicant]
US 9665867B2 · Guise et al. · 2017 [cited by applicant]
US 11893580B2 · Guise et al. · 2024 [cited by applicant]
US 20020035695A1 · Riches et al. · 2002 [cited by applicant]
US 20020188870A1 · Gong et al. · 2002 [cited by applicant]
US 20030018878A1 · Dorward et al. · 2003 [cited by applicant]
US 20030177353A1 · Hiltgen · 2003 [cited by applicant]
US 20040094624A1 · Fernandes et al. · 2004 [cited by applicant]
US 20040104268A1 · Bailey · 2004 [cited by examiner]
US 20040153644A1 · McCorkendale et al. · 2004 [cited by applicant]
US 20060083187A1 · Dekel · 2006 [cited by applicant]
US 20060224892A1 · Brown et al. · 2006 [cited by applicant]
US 20070067643A1 · Zhuk et al. · 2007 [cited by applicant]
US 20070141984A1 · Kuehnel et al. · 2007 [cited by applicant]
US 20080016537A1 · Little et al. · 2008 [cited by applicant]
US 20080017711A1 · Adams · 2008 [cited by examiner]
US 20080244714A1 · Kulakowski et al. · 2008 [cited by applicant]
US 20090198618A1 · Chan et al. · 2009 [cited by applicant]
US 20100017602A1 · Bussard et al. · 2010 [cited by applicant]
US 20100260069A1 · Sakamoto et al. · 2010 [cited by applicant]
US 20100325735A1 · Etchegoyen · 2010 [cited by applicant]
US 20110030040A1 · Ronchi et al. · 2011 [cited by applicant]
US 20110035604A1 · Habraken · 2011 [cited by applicant]
US 20120124375A1 · Truskovsky et al. · 2012 [cited by applicant]
US 20130023240A1 · Weiner · 2013 [cited by applicant]
US 20130119130A1 · Braams · 2013 [cited by applicant]
US 20130144792A1 · Nilsson et al. · 2013 [cited by applicant]
US 20130173475A1 · Lund · 2013 [cited by applicant]
US 20130227647A1 · Thomas et al. · 2013 [cited by applicant]
US 20130268443A1 · Petrov et al. · 2013 [cited by applicant]
US 20130328801A1 · Quigley et al. · 2013 [cited by applicant]
US 20130332367A1 · Quigley et al. · 2013 [cited by applicant]
US 20140032415A1 · Lee et al. · 2014 [cited by applicant]
US 20140075522A1 · Paris et al. · 2014 [cited by applicant]
US 20140237545A1 · Mylavarapu et al. · 2014 [cited by applicant]
US 20140241523A1 · Kobres et al. · 2014 [cited by applicant]
US 20150324792A1 · Guise et al. · 2015 [cited by applicant]
US 20210192507A1 · Guise et al. · 2021 [cited by applicant]
AU 2020210294A1 · 2020 [cited by applicant]
CA 2766038A1 · 2008 [cited by examiner]
CA 2860757A1 · 2013 [cited by applicant]
CA 2948481A1 · 2015 [cited by applicant]
EP 0739105B1 · 2004 [cited by applicant]
EP 3866092A1 · 2021 [cited by applicant]
GB 2491731A · 2012 [cited by examiner]
JP 2002259866A · 2002 [cited by applicant]
JP 2003500923A · 2003 [cited by applicant]
JP 2004153711A · 2004 [cited by applicant]
JP 2006293747A · 2006 [cited by applicant]
JP 2009140275A · 2009 [cited by applicant]
JP 2015201091A · 2015 [cited by applicant]
JP 6313520B2 · 2018 [cited by applicant]
JP 2018125876A · 2018 [cited by applicant]
WO 2009107349A1 · 2009 [cited by applicant]
WO 2013109370A2 · 2013 [cited by applicant]
WO 2015171939A1 · 2015 [cited by applicant]
Foreign Ref Included (Year: 2011). [cited by examiner]
Foreign Ref Included (Year: 2014). [cited by examiner]
Menezes, A.J., et al., “Handbook of Applied Cyptography, Motivation for Use of Session Keys, Key Transport Based on Public-Key Encryption, Hybrid Key Transport Protocols Using PK Encryption,” Handbook of Applied Cryptog… [cited by applicant]
“Wi-Fi Certified Wi-Fi Direct,” Wi-Fi Alliance, published Oct. 2010, Retrieved from the Internet URL: http://www.wi-fi.org/knowledge-center/white-papers/wi-fi-certified-wi-fi%C2#AEconnect-devices, on Oct. 16, 2012, pp. … [cited by applicant]
Toegl et al., “An approach to introducing locality in remote attestation using near field communications”,The Journal of Supercomputing, Kluwer Academic Publishers, BO, vol. 55, No. 2, Mar. 19, 2010, pp. 207-227. [cited by applicant]
Denning, E.D., “Field Encryption and Authentication”, Advances in Cryptology: Proceedings of Crypto, pp. 1-17 (1983). [cited by applicant]
Denning, R.E.D., “Cryptography and Data Security,” Purdue University (1982), pp. 1-199 [Part-1]. [cited by applicant]
Denning, R.E.D., “Cryptography and Data Security,” Purdue University (1982), pp. 200-209 [Part-2]. [cited by applicant]
Koch, H.S., et al., “The application of cryptography for data base security,” AFIPS National Computer Conference, dated Jun. 7-10, 1976, pp. 97-107. [cited by applicant]
“Security Requirements for Cryptographic Modules,” National Institute of Standards and Technology, FIPS Pub 140-1, on Jan. 11, 1994, pp. 1-69. [cited by applicant]
Schneier B., “Applied Cryptography, Second Edition: Protocols, Algorithms, and Source Code in C (cloth)”, published on Jan. 1, 1996, retreived from URL: https://mrajacse.files.wordpress.com/2012/01/applied-cryptography-… [cited by applicant]