IP Library Granted Patent US 12,632,869
Granted Patent B2
US 12,632,869 · App. 18/973,196 · Granted May 19, 2026

System and method to prevent unauthorized usage of card readers and modular electronic funds transfer point of sale device

Inventors: Hwai Sian Tsai (Hong Kong, HK); Chi Wah Lo (Hong Kong, HK)
Assignee: Stripe, LLC
G06Q20/409G06K7/06G06K7/10009G06K7/10405G06Q20/34G06Q20/352G07F7/0893
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,632,869
App. No.
18/973,196
Granted
May 19, 2026
Kind
B2
Abstract

A contactless card reader comprises a contactless card reader front-end coupled to a processor. A communications module is coupled to the processor and a set of sensors is coupled to the processor. The set of sensors determines parameters related to the location, orientation and motion of the card reader. The processor receives the parameters from the set of sensors and utilizes the parameters and scenario configuration data to evaluate a rule. The result of the evaluation of the rule results in a limitation on the operation of the card reader. The communications module is configured to intermittently receive the scenario configuration data from external sources.

Claims (38)

1 . A terminal device certified to process card-based requests, the terminal device comprising:

a first subsystem that processes a first card data in a card-based request received by the terminal device, the first subsystem certified against a first standard and against a second standard that is different from the first standard;

a second subsystem, communicatively coupled with the first subsystem, that processes a second card data during the card-based request, the second subsystem certified against the first standard and the second standard, wherein certification of the terminal device to process card-based requests is based at least in part on both the first subsystem and the second subsystem being certified against the first standard and the second standard; and

a new subsystem that replaces one of the first subsystem or the second subsystem, wherein only the new subsystem is recertified against the first standard and the second standard, without recertifying the terminal device as a whole, and without recertifying the first subsystem when the second subsystem is replaced or the second subsystem when the first subsystem is replaced, thereby maintaining certification of the terminal device to process new card-based requests.

2 . The terminal device of claim 1 , wherein the first subsystem comprises a card reading interface subsystem, and the first standard comprises an account data security standard.

3 . The terminal device of claim 2 , wherein the second subsystem comprises a card holder authentication subsystem, and the second standard comprises one of a card holder authentication security standard.

4 . The terminal device of claim 2 , wherein the processing the card-based requests comprises:

obtaining parameters corresponding to a location, an orientation, or a motion of the terminal device;

evaluating a rule based on the parameters; and

limiting an operation of the card reading interface subsystem based at least on the evaluation of the rule.

5 . The terminal device of claim 1 , further comprising:

the first subsystem reads card data from a card used in making the card-based request and transmits the card data to the second subsystem, the first card data comprising the card data read by the first subsystem; and

the second subsystem receives the card data from the first subsystem, and authenticates the card-based request at least in part based on the card data, the second card data comprising the card data received from the first subsystem.

6 . The terminal device of claim 5 , wherein the first subsystem encrypts the card data prior to transmission of the card data to the second subsystem.

7 . The terminal device of claim 5 , wherein the second subsystem receives user authentication information and performs an offline authentication with the card used in the card-based request.

8 . The terminal device of claim 7 , wherein the user authentication information comprises a personal identification number (PIN).

9 . The terminal device of claim 5 , wherein the second subsystem receives user authentication information, encrypts the user authentication information, and transmits the encrypted user authentication information to a remote server for approval of the card-based request.

10 . The terminal device of claim 1 , wherein the first subsystem and the second subsystem are comprised in separate, independent devices of the terminal device.

11 . The terminal device of claim 1 , wherein cards associated with the card-based requests include one or more of magnetic stripe cards, chip cards, contactless cards, or device emulated cards.

12 . A method of operating a terminal device certified to process card-based requests, the method comprising:

configuring a first subsystem for processing a first card data in a card-based request received by the terminal device against a first standard and against a second standard that is different from the first standard;

configuring a second subsystem for processing a second card data during the card-based request, the second subsystem communicatively coupled with the first subsystem, against the second standard and against the first standard, wherein certification of the terminal device to process the card-based requests is based on both certification of the first subsystem and the second subsystem against the first standard and the second standard; and

in response to replacing one of the first subsystem or the second subsystem with a new subsystem, recertifying only the new subsystem against the first standard and the second standard, without recertifying the terminal device as a whole, and without recertifying the first subsystem when the second subsystem is replaced or the second subsystem when the first subsystem is replaced, thereby maintaining certification of the terminal device to process new card-based requests.

13 . The method of claim 12 , further comprising:

reading, by the first subsystem, card data from a card used in making the card-based request, and transmitting the card data to the second subsystem, the first card data comprising the card data read by the first subsystem; and

receiving, by the second subsystem, the card data from the first subsystem, and authenticating the card-based request at least in part based on the card data, the second card data comprising the card data received from the first subsystem.

14 . The method of claim 13 , wherein the first subsystem encrypts the card data prior to transmission of the card data to the second subsystem.

15 . The method of claim 13 , wherein the second subsystem receives user authentication information and performs an offline authentication with the card used in the card-based request.

16 . The method of claim 13 , wherein the second subsystem receives user authentication information, encrypts the user authentication information, and transmits the encrypted user authentication information to a remote server for approval of the card-based request.

17 . The method of claim 12 , wherein the first subsystem and the second subsystem are comprised in separate, independent devices of the terminal device.

18 . A non-transitory machine readable storage medium storing instructions, which when executed by a terminal device, causes the terminal device to perform operations for operating the terminal device certified to process card-based requests, the operations comprising:

configuring a first subsystem for processing a first card data in a card-based request received by the terminal device against a first standard and against a second standard that is different from the first standard;

configuring a second subsystem for processing a second card data during the card-based request, the second subsystem communicatively coupled with the first subsystem, against the second standard and against the first standard, wherein certification of the terminal device to process the card-based requests is based on both certification of the first subsystem and the second subsystem against the first standard and the second standard; and

in response to replacing one of the first subsystem or the second subsystem with a new subsystem, recertifying only the new subsystem against the first standard and the second standard, without recertifying the terminal device as a whole, and without recertifying the first subsystem when the second subsystem is replaced or the second subsystem when the first subsystem is replaced, thereby maintaining certification of the terminal device to process new card-based requests.

19 . The non-transitory machine readable medium of claim 18 , the operations further comprising:

reading, by the first subsystem, card data from a card used in making the card-based request, and transmitting the card data to the second subsystem, the first card data comprising the card data read by the first subsystem; and

receiving, by the second subsystem, the card data from the first subsystem, and authenticating the card-based request at least in part based on the card data, the second card data comprising the card data received from the first subsystem.

20 . The non-transitory machine readable medium of claim 19 , wherein the second subsystem receives user authentication information, encrypts the user authentication information, and transmits the encrypted user authentication information to a remote server for approval of the card-based request.

Assignments (1)
CHANGE OF NAME Recorded Jan 30, 2026
From: STRIPE, INC.
To: STRIPE, LLC
Reel/Frame 074572/0182 →
Continuity (8)
Continuation 17339058 · Jun 4, 2021
Continuation In Part 17091051 · Nov 6, 2020
Continuation 16394213 · Apr 25, 2019
Continuation 16046573 · Jul 26, 2018
Continuation In Part 16046521 · Jul 26, 2018
Continuation 15343917 · Nov 4, 2016
Provisional Application 62538285 · Jul 28, 2017
Related Publication 20250104084A1 · Mar 27, 2025
References Cited (76)
US 20050156029A1 · Hopkins · 2005 [cited by applicant]
US 20060214845A1 · Jendbro et al. · 2006 [cited by applicant]
US 20070270128A1 · Kakiuchi · 2007 [cited by applicant]
US 20080189214A1 · Mueller et al. · 2008 [cited by applicant]
US 20100207730A1 · Boursier et al. · 2010 [cited by applicant]
US 20100299265A1 · Walters · 2010 [cited by examiner]
US 20110251958A1 · Aubin et al. · 2011 [cited by applicant]
US 20120047564A1 · Liu · 2012 [cited by applicant]
US 20130144731A1 · Baldwin et al. · 2013 [cited by applicant]
US 20140085089A1 · Rasband et al. · 2014 [cited by applicant]
US 20140164154A1 · Ramaci · 2014 [cited by applicant]
US 20140263625A1 · Smets et al. · 2014 [cited by applicant]
US 20140289129A1 · Savolainen et al. · 2014 [cited by applicant]
US 20140365366A1 · Spinella · 2014 [cited by applicant]
US 20150006407A1 · Lunn et al. · 2015 [cited by applicant]
US 20150295920A1 · Van et al. · 2015 [cited by applicant]
US 20150310410A1 · Chai et al. · 2015 [cited by applicant]
US 20160027006A1 · Billett, Jr. · 2016 [cited by applicant]
US 20160027284A1 · Kamp et al. · 2016 [cited by applicant]
US 20160171361A1 · Chatterton et al. · 2016 [cited by applicant]
US 20160203480A1 · Dravenstott et al. · 2016 [cited by applicant]
US 20160316367A1 · Rose et al. · 2016 [cited by applicant]
US 20180082297A1 · Bacastow · 2018 [cited by applicant]
US 20180096329A1 · Hamilton et al. · 2018 [cited by applicant]
US 20220391903A1 · Tsai et al. · 2022 [cited by applicant]
CN 2257046Y · 1997 [cited by applicant]
CN 2515713Y · 2002 [cited by applicant]
CN 101039183A · 2007 [cited by applicant]
CN 201007824Y · 2008 [cited by applicant]
CN 201035502Y · 2008 [cited by applicant]
CN 101329399A · 2008 [cited by applicant]
CN 101836223A · 2010 [cited by applicant]
CN 101872454A · 2010 [cited by applicant]
CN 102013001A · 2011 [cited by applicant]
CN 102184499A · 2011 [cited by applicant]
CN 102422302A · 2012 [cited by applicant]
CN 102811276A · 2012 [cited by applicant]
CN 202662098U · 2013 [cited by applicant]
CN 102956069A · 2013 [cited by applicant]
CN 102956077A · 2013 [cited by applicant]
CN 103186809A · 2013 [cited by applicant]
CN 103377517A · 2013 [cited by applicant]
CN 103413218A · 2013 [cited by applicant]
CN 103425944A · 2013 [cited by applicant]
CN 103700192A · 2014 [cited by applicant]
CN 104054098A · 2014 [cited by applicant]
CN 104951938A · 2015 [cited by applicant]
CN 105388820A · 2016 [cited by applicant]
CN 106415611A · 2017 [cited by applicant]
CN 106709382A · 2017 [cited by applicant]
CN 106980801A · 2017 [cited by applicant]
CN 106991306A · 2017 [cited by applicant]
CN 110291567A · 2019 [cited by applicant]
GB 2524946A · 2015 [cited by applicant]
WO 2010012129A1 · 2010 [cited by applicant]
WO 2012163256A1 · 2012 [cited by applicant]
WO 2015132559A1 · 2015 [cited by applicant]
Non-Final Office Action received for U.S. Appl. No. 18/914,534, mailed on Jun. 17, 2025, 13 pages. [cited by applicant]
Final Office Action received for U.S. Appl. No. 17/339,058, mailed on Jul. 3, 2024, 23 pages. [cited by applicant]
International Preliminary Report on Patentability received for PCT Patent Application No. PCT/CN2018/097361, mailed on Feb. 6, 2020, 06 pages. [cited by applicant]
International Preliminary Report on Patentability received for PCT Patent Application No. PCT/IB2017/001764, mailed on May 16, 2019, 6 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/CN2018/097361, mailed on Oct. 30, 2018, 07 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/IB2017/001764, mailed on Aug. 15, 2018, 9 pages. [cited by applicant]
Non-Final Office Action received for U.S. Appl. No. 17/339,058, mailed on Jan. 19, 2024, 12 pages. [cited by applicant]
Notice of Allowance received for Chinese Patent Application No. 201780082209.9, mailed on Mar. 22, 2021, 3 pages (2 pages of English Translation and 1 pages of Original Document). [cited by applicant]
Notice of Allowance received for U.S. Appl. No. 17/339,058, mailed on Aug. 5, 2024, 9 pages. [cited by applicant]
Notice of Allowance received for U.S. Appl. No. 18/143,219, mailed on Jun. 26, 2024, 12 pages. [cited by applicant]
Notification to Grant Patent Right for Invention received for Chinese Patent Application No. 202110620168.2, mailed on Mar. 22, 2024, 3 pages (2 pages of English Translation and 1 page of Original Document). [cited by applicant]
Notification to grant right for invention received for Chinese Patent Application No. 201880048317.9, mailed on Jun. 8, 2023, 3 pages (2 pages of English Translation and 1 pages of Original Document). [cited by applicant]
Office Action received for Chinese Patent Application No. 201780082209.9, mailed on Feb. 21, 2020, 24 pages (13 pages of English Translation and 11 pages of Original Document). [cited by applicant]
Office Action received for Chinese Patent Application No. 201880048317.9, mailed on Jan. 5, 2023, 15 pages. (9 pages of English Translation and 6 pages of Original Document). [cited by applicant]
Office Action received for Chinese Patent Application No. 202110620168.2, mailed on Oct. 31, 2023, 9 pages (4 pages of English Translation and 5 pages of Original Document). [cited by applicant]
Patent Cooperation Treaty: International Search Report and Written Opinion of PCT/CN2018/097361, Oct. 30, 2018, 7 pages. [cited by applicant]
Payment Card Industry (PCI) PIN Transaction Security (PTS) Hardware Security Module (HSM): Modular Security Requirements version 3.0 Jun. 2016, retrieved from https://www.pcisecuritystandards. org/documents/PCI_HSM_Secu… [cited by applicant]
PCT International Preliminary Report on Patentability for PCT/CN2018/097361, issued Jan. 28, 2020, mailed Feb. 6, 2020, 6 pages. [cited by applicant]
The Second Office Action received for Chinese Patent Application No. 201780082209.9, mailed on Nov. 4, 2020, 8 pages (5 pages of English Translation and 3 pages of Original Document). [cited by applicant]