IP Library › Granted Patent US 12,651,241
Granted Patent B2
US 12,651,241 · App. 18/767,436 · Granted Jun 9, 2026

Point of sale device with secure connection between security meshes

Inventors: Jacob Whitaker Abrams (San Mateo, CA); Seihee Chon (Fremont, CA); Vincent Durieux (Campbell, CA); Eric David Fuhs (Sunnyvale, CA); Brian Jeremiah Murray (Mountain View, CA); Victor Pan (Fremont, CA); Sam Niansheng Qiu (Palo Alto, CA); Bambi Tsui (San Francisco, CA); Siva Raja Sekhar Reddy Yeruva (Menlo Park, CA)
Assignee: Fiserv, Inc.
G06Q20/202H04L9/0841H04L9/3247H04L9/3263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,651,241
App. No.
18/767,436
Granted
Jun 9, 2026
Kind
B2
Abstract

Systems and methods involving secure connections between security meshes are disclosed herein. One disclosed device includes a first security processor located within a first security mesh, a first casing having a connector and supporting the first security mesh and the applications processor, a second security processor located within a second security mesh, and a second casing connected to the first casing via the connector and supporting the second security mesh. The first security processor and second security processor are programmed to generate a unique pre-shared key independently on both the first security processor and the second security processor using an elliptic key exchange and establish a secure connection between the first security processor and the second security processor using the unique pre-shared key.

Claims (41)

1 . A point of sale device comprising:

a first casing housing an applications processor, a first security processor located within a first security mesh, and a first front end for receiving first information associated with a transaction;

a second casing housing a second security processor located within a second security mesh and a second front end for receiving second information associated with the transaction, wherein a secure connection is established between the first security processor and the second security processor; and

a computer readable medium housed within the first casing and accessible to the applications processor and storing instructions which, when executed by the applications processor cause the applications processor to:

in response to detecting the second security processor:

receive capabilities information from the second security processor including a secure protocol compatible with the second security processor;

adjust at least one aspect of an operating system of the applications processor based on the capabilities information;

receive a first remote procedure call (RPC) certificate signing request from the first security processor and a second RPC certificate signing request from the second security processor;

translate the first RPC certificate signing request into a first hypertext transfer protocol (HTTP) certificate signing request and the second RPC certificate signing request into a second HTTP certificate signing request;

transmit the first HTTP certificate signing request and the second HTTP certificate signing request to a certificate authority;

receive a signed first certificate from the certificate authority in response to the first certificate signing request and a signed second certificate from the certificate authority in response to the second certificate signing request; and

transmit the signed first certificate to the first security processor and the signed second certificate to the second security processor to cause the first security processor and the second security processor to each verify the signed first certificate and the signed second certificate to establish a secure connection between the first security processor and the second security processor.

2 . The point of sale device of claim 1 , wherein the first security processor and the second security processor each generate a unique pre-shared key using a key generation algorithm and information from the signed first certificate and the signed second certificate.

3 . The point of sale device of claim 1 , wherein the instructions cause the applications processor to receive the first information associated with the transaction and the second information associated with the transaction.

4 . The point of sale device of claim 2 , wherein the instructions cause the applications processor to transfer, using the secure connection, messages between the first secure processor and the second secure processor.

5 . The point of sale device of claim 4 , wherein the instructions cause the applications processor to periodically poll the second security processor for messages to the first security processor.

6 . The point of sale device of claim 4 , wherein the first security processor decrypts a message of the messages originating at the second security processor.

7 . The point of sale device of claim 6 , wherein the applications processor is unable to decrypt the message.

8 . The point of sale device of claim 7 , wherein the message includes the second information associated with the transaction received at the second front end.

9 . The point of sale device of claim 6 , wherein the first casing is capable of functioning as a separable point of sale device.

10 . The point of sale device of claim 1 , wherein the second casing includes a USB hub to facilitate a wired connection between the first security processor and the second security processor.

11 . A non-transitory, computer-readable medium housed within a first casing of a point of sale device and accessible to an applications processor of the point of sale device, the medium including storing instructions which, when executed by the applications processor cause the applications processor to:

in response to detecting a second security processor housed within a second casing of the point of sale device:

receive capabilities information from the second security processor including a secure protocol compatible with the second security processor;

adjust at least one aspect of an operating system of the applications processor based on the capabilities information;

receive a first remote procedure call (RPC) certificate signing request from the first security processor and a second RPC certificate signing request from the second security processor;

translate the first RPC certificate signing request into a first hypertext transfer protocol (HTTP) certificate signing request and the second RPC certificate signing request into a second HTTP certificate signing request;

transmit the first HTTP certificate signing request and the second HTTP certificate signing request to a certificate authority;

receive a signed first certificate from the certificate authority in response to the first certificate signing request and a signed second certificate from the certificate authority in response to the second certificate signing request;

transmit the signed first certificate to the first security processor and the signed second certificate to the second security processor to cause the first security processor and the second security processor to each verify the signed first certificate and the signed second certificate to establish a secure connection between the first security processor and the second security processor;

receive first information associated with a transaction from the first security processor; and

receive second information associated with the transaction from the second security processor.

12 . The non-transitory, computer-readable medium of claim 11 , wherein the first security processor and the second security processor each generate a unique pre-shared key using a key generation algorithm and information from the signed first certificate and the signed second certificate.

13 . The non-transitory, computer-readable medium of claim 11 , wherein the first casing houses a first front end for receiving the first information associated with the transaction, and wherein the second casing houses a second front end for receiving the second information associated with the transaction.

14 . The non-transitory, computer-readable medium of claim 12 , wherein the instructions cause the applications processor to transfer, using the secure connection, messages between the first secure processor and the second secure processor.

15 . The non-transitory, computer-readable medium of claim 14 , wherein the instructions cause the applications processor to periodically poll the second security processor for messages to the first security processor.

16 . The non-transitory, computer-readable medium of claim 14 , wherein the first security processor decrypts a message of the messages originating at the second security processor.

17 . The non-transitory, computer-readable medium of claim 16 , wherein the applications processor is unable to decrypt the message.

18 . The non-transitory, computer-readable medium of claim 17 , wherein the message includes the second information associated with the transaction.

19 . The non-transitory, computer-readable medium of claim 16 , wherein the first casing is capable of functioning as a separable point of sale device.

20 . The non-transitory, computer-readable medium of claim 11 , wherein the second casing includes a USB hub to facilitate a wired connection between the first security processor and the second security processor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2024
From: ABRAMS, JACOB WHITAKER; CHON, SEIHEE; DURIEUX, VINCENT; FUHS, ERIC DAVID; MURRAY, BRIAN JEREMIAH; PAN, VICTOR; QIU, SAM NIANSHENG; TSUI, BAMBI; YERUVA, SIVA RAJA SEKHAR REDDY
To: FISERV, INC.
Reel/Frame 068368/0915 →
Continuity (2)
Continuation 16811760 · Mar 6, 2020
Related Publication 20240362604A1 · Oct 31, 2024
References Cited (35)
US 10326797B1 · Murray et al. · 2019 [cited by applicant]
US 20140241523A1 · Kobres et al. · 2014 [cited by applicant]
US 20150324781A1 · Saitoh · 2015 [cited by applicant]
US 20150324793A1 · Guise et al. · 2015 [cited by applicant]
US 20160117659A1 · Bedier et al. · 2016 [cited by applicant]
US 20180005230A1 · Zovi et al. · 2018 [cited by applicant]
US 20180033255A1 · Beatty · 2018 [cited by examiner]
US 20190066103A1 · Murray · 2019 [cited by applicant]
US 20190172036A1 · Bedier et al. · 2019 [cited by applicant]
US 20190207953A1 · Klawe et al. · 2019 [cited by applicant]
US 20190295060A1 · Patwardhan · 2019 [cited by examiner]
US 20190325437A1 · Murray · 2019 [cited by examiner]
CN 107274185 · 2017 [cited by applicant]
CN 110832518 · 2020 [cited by applicant]
TW 201723946 · 2018 [cited by applicant]
Wang, Xiaosheng et al. A Secure Dual-Core Processor Design for Embedded Terminal Device. 2018 IEEE 3rd Advanced Information Technology, Electronic and Automation Control Conference (IAEAC), 2018. (Year: 2018). [cited by examiner]
Office Action issued in connection with Taiwan Appl. No. 109146262 dated Oct. 28, 2024. [cited by applicant]
Credential Management for Internet of Things Devices, Technical Disclosure, published Dec. 2017, Internet Protocol for Smart Objects (IPSO) Alliance, available at hllps://www.omaspecworks.org/wp-content/uploads/2018/03/… [cited by applicant]
ECC Certificate Signing Request (CSR) Generation Instructions for Apache SSL, Technical Disclosure, published Apr. 19, 2019, DigiCert., available at hllps://knowledge.digicert.com/generalinformation/INFO1909.html, (Acce… [cited by applicant]
ECDSA: The digital signature algorithm of a better internet, Technical Disclosure, published Mar. 10, 2014, Nick Sullivan, Cloudflare, available at hllps://blog.cloudflare.com/ecdsa-the-digital-signature-algorithm--0f-a… [cited by applicant]
Extended European Search Report issued in connection with EP Appl. No. 21765072.0 dated Dec. 14, 2023. [cited by applicant]
Final Office Action on U.S. Appl. No. 16/811,760 dtd Jan. 29, 2024. [cited by applicant]
Final Office Action on U.S. Appl. No. 16/811,760 dtd Jul. 26, 2023. [cited by applicant]
Final Office Action on U.S. Appl. No. 16/811,760 dtd Aug. 10, 2022. [cited by applicant]
Foreign Action other than Search Report on PCT dtd Sep. 15, 2022. [cited by applicant]
Foreign Search Report on PCT PCT/US2021/018209 dtd Apr. 28, 2021. [cited by applicant]
International Search Report and Written Opinion dated Apr. 28, 2021 from International Application No. PCT/US2021/018209m, 17 pages. [cited by applicant]
Jiang et al., “A Blockchain-Based Authentication Protocol for WLAN Mesh Security Access”, CMC, 2019, vol. 58, No. 1, pp. 45-59. [cited by applicant]
Kisialiova, Liudmila. Payment Terminal Emulator. Universidade do Porto (Portugal) ProQuest Dissertations Publishing, 2020. (Year: 2020). [cited by applicant]
Non-Final Office Action on U.S. Appl. No. 16/811,760 dtd Mar. 20, 2023. [cited by applicant]
Non-Final Office Action on U.S. Appl. No. 16/811,760 dtd Oct. 23, 2023. [cited by applicant]
Notice of Allowance on U.S. Appl. No. 16/811,760 dtd Apr. 10, 2024. [cited by applicant]
NXP Introduces New Innovative “Plug and Trust” Approach to IoT Security Using NXP A71CH Trust Anchor, Technical Disclosure and Publicly Available Product, published Feb. 27, 2018, NXP, available at https://www.globenews… [cited by applicant]
Tonesi et al., “Smart PSK Provisioning: a Key-Management and Authentication Scheme for Wireless LANs”, IEEE, J005, pp. 119-124. [cited by applicant]
US Office Action on U.S. Appl. No. 16/811,760 dtd Dec. 7, 2021. [cited by applicant]