IP Library › Granted Patent US 11,625,725
Granted Patent B1
US 11,625,725 · App. 16/181,160 · Granted Apr 11, 2023

Stateless secure payment system

Inventors: Jordan Tyler Williams (Seattle, WA); Sarath Geethakumar (Bellevue, WA); Aneeta Bhattacharyya (Seattle, WA); Tamer Avci (Seattle, WA); Venkatraman Srinivasan (Redmond, WA); Sanjay Kumar Dash (Mercer Island, WA)
Assignee: AMAZON TECHNOLOGIES, INC.
G06Q20/409G06Q20/352G06Q20/3825G06Q20/3829G06Q20/40145H04L9/3231H04L63/0861G06Q2220/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,625,725
App. No.
16/181,160
Granted
Apr 11, 2023
Kind
B1
Abstract

A biometric input device is used to obtain biometric data from a user. The biometric data is used to determine host card emulation (HCE) parameters that are associated with the user and are used to access a payment account. An interface device that is associated with the biometric input device receives the HCE parameters. The interface device includes a secure execution environment (SEE). A processor in the SEE decrypts and stores the HCE parameters in the memory of the SEE and executes an HCE instance. The HCE instance uses a communication interface to interact with a payment terminal using a contactless communication protocol. The interaction provides payment data to the payment terminal, which is then sent along a payment channel for processing. The HCE instance is then erased, and the SEE is then available for use by another user for another transaction using a different payment account.

Claims (115)

1. A device comprising:

a first communication interface;

a biometric input device;

a first memory storing first computer-executable instructions;

a first hardware processor to execute the first computer-executable instructions to:

determine, using the biometric input device, biometric data;

send the biometric data using the first communication interface, wherein the biometric data is used to determine encrypted data; and

receive, using the first communication interface, the encrypted data; and

a secure execution environment comprising:

a second communication interface;

a second memory storing second computer-executable instructions and a private key; and

a second hardware processor to execute the second computer-executable instructions to:

receive an encrypted installation file comprising one or more instructions;

access the private key that is stored in the second memory;

decrypt the encrypted installation file using the private key to produce a decrypted installation file;

instantiate a contactless payment application using the decrypted installation file;

access the encrypted data;

decrypt, using the private key, the encrypted data to provide one or more host card emulation (HCE) parameters;

configure the contactless payment application based at least in part on the one or more HCE parameters;

perform, using the second communication interface and the contactless payment application, a transaction with a payment terminal; and

erase the encrypted data and the one or more HCE parameters.

2. The device of claim 1 , wherein the biometric input device comprising one or more of:

a camera,

a fingerprint sensor, or

a microphone.

3. The device of claim 1 , wherein the private key is unique to the secure execution environment.

4. The device of claim 1 , wherein the second hardware processor to further execute the second computer-executable instructions to:

send to the payment terminal one or more application protocol data unit commands that are compliant with at least a portion of the ISO/IEC 7816 standard as promulgated by the International Organization for Standardization (ISO).

5. A method comprising:

instantiating an application within a secure execution environment;

acquiring biometric data using one or more biometric input devices;

sending at least a portion of the biometric data to a first device, wherein the biometric data is used to determine encrypted data;

receiving the encrypted data from the first device;

decrypting, within the secure execution environment, the encrypted data to provide one or more host card emulation (HCE) parameters;

configuring the application based at least in part on the one or more HCE parameters;

performing, using the application executing in the secure execution environment, a transaction with a second device; and

erasing the encrypted data and the one or more HCE parameters after the transaction is complete.

6. The method of claim 5 , wherein the one or more HCE parameters comprise data indicative of one or more of:

an application primary account number,

a cardholder name,

an application expiration date, or

an application primary account number sequence number.

7. The method of claim 5 , further comprising:

receiving an installation file comprising one or more instructions;

determining a digital signature of the installation file is valid; and

wherein the instantiating the application uses the installation file.

8. The method of claim 5 , further comprising:

receiving an encrypted installation file comprising one or more instructions;

accessing, within the secure execution environment, a private key that is stored in the secure execution environment;

decrypting the encrypted installation file using the private key to produce a decrypted installation file; and

wherein the instantiating the application uses the decrypted installation file.

9. The method of claim 5 , further comprising:

accessing, within the secure execution environment, a private key that is stored in the secure execution environment; and

wherein the decrypting the encrypted data uses the private key.

10. The method of claim 5 , wherein the application is compliant with at least a portion of the ISO/IEC 14443 standard as promulgated by the International Organization for Standardization (ISO).

11. The method of claim 5 , wherein the performing the transaction comprises:

sending, to the second device, one or more application protocol data unit commands that are compliant with at least a portion of the ISO/IEC 7816 standard as promulgated by the International Organization for Standardization (ISO).

12. The method of claim 5 , further comprising:

determining data indicative of physical or electronic tampering; and

erasing contents stored in the secure execution environment.

13. A system comprising:

a first communication interface;

a second communication interface;

a first memory storing first computer-executable instructions;

a first hardware processor to execute the first computer-executable instructions to:

determine, using a biometric input device, biometric data that is indicative of one or more of one or more features of a user;

send the biometric data using the first communication interface, and wherein the biometric data is used to determine encrypted data;

receive, using the first communication interface, the encrypted data;

send, using the second communication interface, the encrypted data to a secure execution environment; and

the secure execution environment comprising:

a third communication interface that is in communication with the second communication interface;

a fourth communication interface;

a second memory storing second computer-executable instructions and a private key;

a second hardware processor to execute the second computer-executable instructions to:

access the encrypted data;

decrypt, using the private key, the encrypted data to provide one or more host card emulation (HCE) parameters;

instantiate an instance of an application using the one or more HCE parameters;

perform, using the fourth communication interface and the instance of the application, a transaction with an external device; and

erase the instance of the application, the encrypted data, and the one or more HCE parameters.

14. The system of claim 13 , further comprising:

the biometric input device comprising one or more of:

a camera, a fingerprint sensor, or a microphone; and

a controller to generate biometric data.

15. The system of claim 13 , wherein the one or more HCE parameters comprise data indicative of one or more of:

an application primary account number,

a cardholder name,

an application expiration date, or

an application primary account number sequence number.

16. The system of claim 13 , wherein the application comprises a contactless payment application that is compliant with at least a portion of the ISO/IEC 14443 standard as promulgated by the International Organization for Standardization (ISO).

17. The system of claim 13 , wherein the second hardware processor to further execute the second computer-executable instructions to:

receive an installation file comprising one or more instructions;

determine a digital signature of the installation file is valid; and

wherein the instantiation of the instance of the application uses the installation file.

18. The system of claim 13 , wherein the second hardware processor to further execute the second computer-executable instructions to:

receive encrypted installation data comprising one or more instructions;

decrypt the encrypted installation data using the private key to produce decrypted installation data; and

wherein the instantiation of the instance of the application uses the decrypted installation data.

19. The system of claim 13 , wherein the private key is unique to the secure execution environment.

20. The system of claim 13 , wherein the secure execution environment further comprises:

one or more tamper detection devices; and

the second hardware processor to execute the second computer-executable instructions to:

responsive to output from the one or more tamper detection devices:

disable the third communication interface,

disable the fourth communication interface,

erase contents of the second memory, or

disable the second hardware processor.

21. A method comprising:

instantiating, at a first device, an application within a secure execution environment of the first device;

acquiring, at a biometric input device, biometric data;

sending, from the biometric input device, the biometric data to a second device, wherein the biometric data is used to determine encrypted data;

receiving, at the first device, the determined encrypted data from the second device;

decrypting, within the secure execution environment of the first device, the encrypted data to provide one or more host card emulation (HCE) parameters;

configuring, at the first device, the application based at least in part on the one or more HCE parameters;

performing, using the application executing in the secure execution environment of the first device, a transaction with a third device; and

erasing, at the first device, the encrypted data and the one or more HCE parameters after the transaction is complete.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVAL OF ASSIGNOR'S MIDDLE NAME, FOR TAMER AVCI, I AS THE MIDDLE NAME IS INCORRECT PREVIOUSLY RECORDED AT REEL: 047415 FRAME: 0587. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 6, 2022
From: WILLIAMS, JORDAN TYLER; GEETHAKUMAR, SARATH; BHATTACHARYYA, ANEETA; AVCI, TAMER; SRINIVASAN, VENKATRAMAN; DASH, SANJAY KUMAR
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 058650/0646 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 5, 2018
From: WILLIAMS, JORDAN TYLER; GEETHAKUMAR, SARATH; BHATTACHARYYA, ANEETA; AVCI, TAMER I; SRINIVASAN, VENKATRAMAN; DASH, SANJAY KUMAR
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 047415/0587 →
Continuity (1)
Provisional Application 62716573 · Aug 9, 2018
Cited By (2)
US 12,231,555 US 12,619,626