IP Library › Granted Patent US 11,374,949
Granted Patent B2
US 11,374,949 · App. 16/848,727 · Granted Jun 28, 2022

Logical validation of devices against fraud and tampering

Inventors: Janek Klawe (New York, NY); Richard Neal Harris (Mountain View, CA)
Assignee: Block, Inc.
H04L63/1416G06F21/57G06Q20/202G06Q20/206G06Q20/3567G06Q20/382G07F7/088H04L63/1483H04L63/308
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,374,949
App. No.
16/848,727
Granted
Jun 28, 2022
Kind
B2
Abstract

Disclosed herein is a method and system to determine whether a payment terminal has been tampered with based on a comparison of attestation data received from the payment terminal, for example in an offline mode when an otherwise secure remote server cannot be reached. If the determination yields that the request has been approved, the terminal generates an attestation ticket having one or more validity conditions, wherein the validity conditions include expiration time that indicates the time after which the attestation ticket becomes invalid. The attestation ticket can be used as long as it is valid or until another trigger causes the ticket to be invalidated or regenerated.

Claims (52)

1. A computer-implemented method for determining whether a payment terminal is secure, the method comprising:

sending, from the payment terminal and to a payment server, a first state of the payment terminal while the payment terminal is in a first mode;

obtaining, by the payment terminal and from the payment server, an indication that the payment terminal is secure;

sending, from the payment terminal and to a payment reader, a second state of the payment terminal while the payment terminal is in a second mode;

obtaining, by the payment terminal and from the payment reader, another indication that the payment terminal is secure; and

switching between the first mode and the second mode based on a type or level of network connection.

2. The computer-implemented method of claim 1 , wherein the first state and the second state include attestation data indicative of fraud or tampering of the payment terminal.

3. The computer-implemented method of claim 2 , wherein the indication or the other indication that the payment terminal is secure is based on a comparison of the attestation data with known behavior.

4. The computer-implemented method of claim 1 , further comprising:

determining that the payment terminal has a network connection to the payment server; and

determining whether the payment terminal is secure via the first mode.

5. The computer-implemented method of claim 1 , further comprising:

determining that the payment terminal lacks a network connection to the payment server; and

determining whether the payment terminal is secure via the second mode.

6. The computer-implemented method of claim 1 , wherein sending the first state or sending the second state comprises sending security data in response to one or more instructions received directly or indirectly from the payment server.

7. The computer-implemented method of claim 1 , further comprising:

determining an occurrence of an attestation trigger; and

sending the first state or the second state based at least in part on determining the occurrence of the attestation trigger.

8. The computer-implemented method of claim 7 , wherein the attestation trigger includes at least one of:

connecting the payment terminal to the payment reader using a wired connection;

connecting the payment terminal to the payment reader via a short range communication protocol;

pairing the payment terminal to the payment reader;

installing a new payment application on the payment terminal;

detecting re-location of the payment reader or the payment terminal;

detecting insertion of a payment object from a known fraudulent user;

detecting a known fraudulent payment object; or

detecting entry of a known fraudulent device within an established geo-fence.

9. The computer-implemented method of claim 1 , wherein based at least in part on determining that the payment terminal is secure, attesting the payment terminal to allow the payment terminal to perform a secure operation.

10. The computer-implemented method of claim 1 , wherein the payment terminal is a point-of-sale device configured to accept one or more Europay Mastercard Visa (EMV) payments through a payment application and the payment server is remotely located from the payment terminal and (i) hosts the payment application and (ii) stores data pertaining to the one or more EMV payments.

11. A system for determining whether a payment terminal is secure, the system comprising:

one or more processors; and

non-transitory computer-readable media storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

sending, from the payment terminal and to a payment server, a first state of the payment terminal while the payment terminal is in a first mode;

obtaining, by the payment terminal and from the payment server, an indication that the payment terminal is secure;

sending, from the payment terminal and to a payment reader, a second state of the payment terminal while the payment terminal is in a second mode;

obtaining, by the payment terminal and from the payment reader, another indication that the payment terminal is secure; and

switching between the first mode and the second mode based on a type or level of network connection.

12. The system of claim 11 , wherein the first state and the second state include attestation data indicative of fraud or tampering of the payment terminal.

13. The system of claim 12 , wherein the indication or the other indication that the payment terminal is secure is based on a comparison of the attestation data with known behavior.

14. The system of claim 11 , the operations further comprising:

determining that the payment terminal has a network connection to the payment server; and

determining whether the payment terminal is secure via the first mode.

15. The system of claim 11 , the operations further comprising:

determining that the payment terminal lacks a network connection to the payment server; and

determining whether the payment terminal is secure via the second mode.

16. The system of claim 11 , wherein sending the first state or sending the second state comprises sending security data in response to one or more instructions received directly or indirectly from the payment server.

17. The system of claim 11 , the operations further comprising:

determining an occurrence of an attestation trigger; and

sending the first state or the second state based at least in part on determining the occurrence of the attestation trigger.

18. The system of claim 11 , wherein the payment terminal is a point-of-sale device configured to accept one or more Europay Mastercard Visa (EMV) payments through a payment application and the payment server is remotely located from the payment terminal and (i) hosts the payment application and (ii) stores data pertaining to the one or more EMV payments.

19. The computer-implemented method of claim 1 , wherein the first mode comprises an online mode and the second mode comprises an offline mode.

20. The system of claim 11 , wherein the first mode comprises an online mode and the second mode comprises an offline mode.

Assignments (2)
CHANGE OF NAME Recorded Jan 5, 2022
From: SQUARE, INC.
To: BLOCK, INC.
Reel/Frame 058646/0154 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 14, 2020
From: KLAWE, JANEK; HARRIS, RICHARD NEAL
To: SQUARE, INC.
Reel/Frame 052396/0319 →
Continuity (2)
Continuation 15858050 · Dec 29, 2017
Related Publication 20200244681A1 · Jul 30, 2020