IP Library › Granted Patent US 12,219,347
Granted Patent B2
US 12,219,347 · App. 18/453,693 · Granted Feb 4, 2025

Secure on-demand ultra-wideband communication channels systems and methods

Inventors: Brian Sullivan (Amersham, GB); Aparna Girish (Fremont, CA); Mark Rigby (Rickmansworth, GB); Christian Aabye (Redwood City, CA); Mustafa Top (San Ramon, CA); Yuexi Chen (Foster City, CA); Dinah Sloan (San Jose, CA); Hao Ngo (San Jose, CA)
Assignee: Visa International Service Association
H04W12/03H04B1/7163H04L9/088H04L9/3073H04L9/3271H04W12/041H04W12/08H04W12/106H04W12/122H04W76/10H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,219,347
App. No.
18/453,693
Granted
Feb 4, 2025
Kind
B2
Abstract

A method includes forming a communication channel between a user device and an access device. The communication channel is then secured using a user device key pair in the user device and an access device ephemeral key pair in the access device. The access device then generates a session key using at least a private cryptographic key in the access device ephemeral key pair, and a public key in the user device key pair. The access device then uses the session key to secure an ultra-wideband communication channel between the user device and the access device.

Claims (66)

1. A method comprising:

forming a communication channel between a user device and an access device, wherein the communication channel is a primary communication channel;

securing the communication channel between the user device and the access device using a user device key pair in the user device and an access device ephemeral key pair in the access device;

generating, by the access device, a session key using at least a private cryptographic key in the access device ephemeral key pair and a public cryptographic key in the user device key pair;

using, by the access device, the session key to secure an ultra-wideband communication channel between the user device and the access device;

determining, by the access device, a distance between the access device and the user device based on the ultra-wideband communication channel;

comparing the distance and a predetermined threshold distance; and

if the distance does not exceed the predetermined threshold distance, performing further communications with the user device over the primary communication channel, the user device being a payment device.

2. The method of claim 1 , wherein the session key is used in a scrambled timestamp, secure ranging, or pulse reordering security process to secure the ultra-wideband communication channel.

3. The method of claim 1 , wherein the session key is a first session key and wherein the method further comprises:

generating a second session key using at least a cryptographic key of the access device ephemeral key pair, and using the second session key to form an ultra-wideband communication credential for the ultra-wideband communication.

4. The method of claim 1 , wherein the user device key pair and the access device ephemeral key pair are elliptic curve cryptography (ECC) key pairs.

5. The method of claim 1 , wherein the ultra-wideband communication channel is used in a relay attack prevention process, the relay attack prevention process including determining the distance between the user device and the access device.

6. The method of claim 1 , wherein the primary communication channel is a close range communication channel.

7. The method of claim 1 further comprising:

if the distance does not exceed the predetermined threshold distance, performing, by the access device, an interaction process to obtain interaction data from the user device for an interaction between a user of the user device and a resource provider of the access device;

generating, by the access device, an authorization request message comprising at least the interaction data; and

providing, by the access device, the authorization request message to an authorizing entity computer for authorization via a resource provider computer.

8. The method of claim 7 further comprising:

receiving, by the access device, an authorization response message comprising an indication of whether or not the interaction is authorized.

9. The method of claim 1 , wherein securing the communication channel between the user device and the access device further comprises:

providing, by the access device, an access device ephemeral public key of the access device ephemeral key pair to the user device;

receiving, by the access device, the public cryptographic key in the user device key pair;

generating, by the access device, a shared secret using a user device public key and the private cryptographic key of the access device ephemeral key pair; and

securing, by the access device, the communication channel using the shared secret.

10. The method of claim 1 , wherein the access device is a POS terminal.

11. An access device comprising:

a processor; and

a non-transitory computer-readable medium coupled to the processor, the non-transitory computer-readable medium comprising code executable by the processor for implementing a method comprising:

forming a communication channel between a user device and the access device, wherein the communication channel is a primary communication channel;

securing the communication channel between the user device and the access device using a user device key pair in the user device and an access device ephemeral key pair in the access device;

generating, by the access device, a session key using at least a private cryptographic key in the access device ephemeral key pair and a public cryptographic key in the user device key pair;

using the session key to secure an ultra-wideband communication channel between the user device and the access device;

determining, by the access device, a distance between the access device and the user device based on the ultra-wideband communication channel;

comparing the distance and a predetermined threshold distance; and

if the distance does not exceed the predetermined threshold distance, performing further communications with the user device over the primary communication channel, the user device being a payment device.

12. The access device of claim 11 , wherein using the session key to secure the ultra-wideband communication channel between the user device and the access device further comprises:

generating an authentication challenge;

providing the authentication challenge to the user device, wherein the authentication challenge is encrypted using the session key, and wherein the user device generates a message integrity code over the authentication challenge, and provides the message integrity code to the access device in response to the authentication challenge;

receiving the message integrity code from the user device; and

verifying the message integrity code.

13. The access device of claim 11 further comprising, on the computer-readable medium:

a primary communication channel creation module;

a communication channel securing module;

an ultra-wideband communication channel creation module; and

an interaction processing module.

14. The access device of claim 11 , wherein the method further comprises:

performing an interaction process to obtain interaction data from the user device for an interaction;

generating, by the access device, an authorization request message comprising at least the interaction data; and

providing, by the access device, the authorization request message to an authorizing entity computer for authorization.

15. The access device of claim 11 , wherein the access device is a first mobile device, and wherein the user device is a second mobile device.

16. The access device of claim 11 , wherein the session key is a first session key and wherein the method further comprises:

generating a second session key using at least a cryptographic key of the access device ephemeral key pair, and using the second session key to form an ultra-wideband communication credential for the ultra-wideband communication.

17. A method comprising:

forming a communication channel between a user device and an access device;

securing the communication channel between the user device and the access device using a user device key pair in the user device and an access device ephemeral key pair in the access device;

generating, by the user device, a session key using at least a private cryptographic key in the user device key pair and a public cryptographic key in the access device ephemeral key pair;

using, by the user device, the session key to secure an ultra-wideband communication channel between the user device and the access device

determining a distance between the access device and the user device based on the ultra-wideband communication channel;

comparing the distance and a predetermined threshold distance; and

if the distance does not exceed the predetermined threshold distance, performing an interaction process to provide interaction data to the access device for an interaction over the communication channel, the user device being a payment device.

18. The method of claim 17 ,

wherein the access device generates an authorization request message comprising at least the interaction data, provides the authorization request message to an authorizing entity computer for authorization, receives an authorization response message comprising an indication of whether or not the interaction is authorized, and provides the indication of whether or not the interaction is authorized to the user device.

19. The method of claim 17 further comprising:

providing the session key to the access device.

20. The method of claim 17 , wherein the access device is a POS terminal.

Continuity (2)
Continuation 17491402 · Sep 30, 2021
Related Publication 20230396998A1 · Dec 7, 2023
References Cited (32)
US 8552903B2 · Julian et al. · 2013 [cited by applicant]
US 9647832B2 · Le Saint · 2017 [cited by examiner]
US 10759389B2 · Ledvina et al. · 2020 [cited by applicant]
US 20090313472A1 · Guccione et al. · 2009 [cited by applicant]
US 20110019587A1 · Wang · 2011 [cited by examiner]
US 20150200774A1 · Le Saint · 2015 [cited by applicant]
US 20150237461A1 · Goyal · 2015 [cited by examiner]
US 20190114605A1 · Valencia · 2019 [cited by applicant]
US 20190215154A1 · Simplicio, Jr. · 2019 [cited by examiner]
US 20200168017A1 · Prostko · 2020 [cited by examiner]
US 20210027130A1 · Ette · 2021 [cited by examiner]
US 20210058259A1 · Le Saint · 2021 [cited by examiner]
US 20210266303A1 · Pollutro · 2021 [cited by examiner]
US 20210360395A1 · Lemsitzer · 2021 [cited by examiner]
US 20210402955A1 · Ahmed · 2021 [cited by examiner]
US 20220078609A1 · Appietto · 2022 [cited by examiner]
US 20220256338A1 · Parthasarathi · 2022 [cited by examiner]
EP 3273635A1 · 2018 [cited by applicant]
EP 3748900A1 · 2020 [cited by applicant]
KR 20050092989A · 2005 [cited by applicant]
KR 202000028820A · 2020 [cited by applicant]
KR 20200112559A · 2020 [cited by applicant]
WO 2020197221A1 · 2000 [cited by applicant]
U.S. Appl. No. 17/491,402, “Non-Final Office Action”, Feb. 16, 2023, 40 pages. [cited by applicant]
U.S. Appl. No. 17/491,402, “Notice of Allowance”, May 26, 2023, 16 pages. [cited by applicant]
Brzuska et al., “An Analysis of the EMV Channel Establishment Protocol”, School of Computer Science, School of Engineering, Available Online at: https://eprint.iacr.org/2013/031.pdf, Nov. 2013, 30 pages. [cited by applicant]
PCT/US2022/043649 , “International Search Report and the Written Opinion”, Jan. 2, 2023, 12 pages. [cited by applicant]
PIRC , “UWB Explained: What Secure Ranging Means for the IoT and Beyond”, NXP Semiconductors,, Aug. 4, 2021, 7 pages. [cited by applicant]
Singh et al., “UWB with Pulse Reordering: Securing Ranging against Relay and Physical-Layer Attacks”, Network and Distributed Systems Security (NOSS) Symposium 2019, Available Online at: https://eprint.iacr.org/2017/124… [cited by applicant]
Stocker et al., “Towards Secure and Scalable UWB-Based Positioning Systems”, Institute of Technical Informatics, 2020, 9 pages. [cited by applicant]
YANG , “Security Enhanced EMV-Based Mobile Payment Protocol”, Hindawi Publishing Corporation, the Scientific World Journal, vol. 2014, Article Id 864571, Sep. 15, 2014, 19 pages. [cited by applicant]
EP22877122.6 , “Extended European Search Report”, Dec. 12, 2024, 12 pages. [cited by applicant]