IP Library › Granted Patent US 12,309,259
Granted Patent B2
US 12,309,259 · App. 17/952,094 · Granted May 20, 2025

Data transfer using a virtual terminal

Inventors: Raphael Hudon-Voyer (Montreal, CA); Frank Andries van den Berg (San Jose, CA); Sebastien Fontaine (Montreal, CA); Frederic Arnaud (Montreal, CA); Neilson Proulx-Marcil (Montreal, CA); Pradeepa Krishnamoorthy (Llie-Perrot, CA); Guilherme Bicalho de Padua (Montreal, CA); Varun A. Vora (Campbell, CA); Jin W. Lee (South Barrington, IL)
Assignee: Apple Inc.
H04L9/0822G06F9/45558H04L9/0825H04L9/14H04L9/3213H04L9/3234H04L67/06G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,309,259
App. No.
17/952,094
Granted
May 20, 2025
Kind
B2
Abstract

Techniques for using a virtual terminal on a device to process a data transfer are described herein. These techniques provide the configuring of a virtual terminal for transfer of data, encryption of the data, and rewrapping the data. A server transmits virtual terminal kernel configuration data to the virtual terminal, configuring the terminal with a first public encryption key used to encrypt a second encryption key only known by the terminal. The second encryption key is used to encrypt data for data transfer. The server device is able to decrypt the second encryption key by using a third private encryption key that corresponds to the first public encryption key.

Claims (55)

1. A method, comprising:

transmitting, by a first server device and to a secure element of a user device, virtual terminal kernel configuration data, the virtual terminal kernel configuration data used to configure a virtual terminal with a first public encryption key, the virtual terminal associated with the secure element, the first public encryption key used to generate an encrypted second encryption key by encrypting a second encryption key, and the second encryption key used to generate an encrypted data payload by encrypting a data payload;

receiving, by the first server device and from a second server device, a request for the data payload, the request including an encrypted data payload and the encrypted second encryption key;

decrypting, by the first server device, the encrypted second encryption key using a third private encryption key corresponding to the first public encryption key;

generating, by the first server device, a rewrapped second encryption key by encrypting the second encryption key using a fourth encryption key which corresponds to a fifth encryption key associated with the second server device; and

transmitting, by the first server device and to the second server device, the rewrapped second encryption key and the encrypted data payload.

2. The method of claim 1 , wherein the fourth encryption key and the fifth encryption key are associated symmetric encryption keys.

3. The method of claim 1 , wherein decrypting the encrypted second encryption key using a third private encryption key is done on a hardware secure module.

4. The method of claim 3 , wherein the hardware secure module is configured to be physically secured from electronic and physical interference.

5. The method of claim 1 , wherein the second encryption key is generated by the virtual terminal on the user device.

6. The method of claim 1 , further comprising receiving, from the user device, a kernel token, the kernel token indicative that the second server device has authorized the user device to generate one or more data payloads.

7. The method of claim 6 , further comprising:

receiving a reader token from the user device, the reader token including a first data associated with the device and a second data associated with the second server device;

determining the reader token is valid by checking the first data and second data;

generating the kernel token based at least in part one or more of the first data and the second data; and

sending the kernel token to the user device.

8. The method of claim 1 , further comprising:

sending, to the user device, a session token, the session token indicative that the second server device has authorized the user device to generate the data payload, the data payload to be processed by the second server device; and

validating the session token, the request for the data payload from the second server device further including the session token.

9. A computing device, comprising:

one or more memories; and

one or more processors in communication with the one or more memories and configured to execute instructions stored in the one or more memories to cause the computing device to:

transmit, by a first server device and to a secure element of a user device, virtual terminal kernel configuration data, the virtual terminal kernel configuration data used to configure a virtual terminal with a first public encryption key, the virtual terminal associated with the secure element, the first public encryption key used to generate an encrypted second encryption key by encrypting a second encryption key, and the second encryption key used to generate an encrypted data payload by encrypting a data payload;

receive, by the first server device and from a second server device, a request for the data payload, the request including an encrypted data payload and the encrypted second encryption key;

decrypt, by the first server device, the encrypted second encryption key using a third private encryption key corresponding to the first public encryption key;

generate, by the first server device, a rewrapped second encryption key by encrypting the second encryption key using a fourth encryption key which corresponds to a fifth encryption key associated with the second server device; and

transmit, by the first server device and to the second server device, the rewrapped second encryption key and the encrypted data payload.

10. The computing device of claim 9 , wherein the fourth encryption key and the fifth encryption key are associated symmetric encryption keys.

11. The computing device of claim 9 , wherein decrypting the encrypted second encryption key using a third private encryption key is done on a hardware secure module.

12. The computing device of claim 11 , wherein the hardware secure module is configured to be physically secured from electronic and physical interference.

13. The computing device of claim 9 , wherein the second encryption key is generated by the virtual terminal on the user device.

14. The computing device of claim 9 , wherein the one or more processors are further configured to receive, from the user device, a kernel token, the kernel token indicative that the second server device has authorized the user device to generate one or more data payloads.

15. The computing device of claim 14 , wherein the one or more processors are further configured to:

receive a reader token from the user device, the reader token including a first data associated with the device and a second data associated with the second server device;

determine the reader token is valid by checking the first data and second data;

generate the kernel token based at least in part one or more of the first data and the second data; and

send the kernel token to the user device.

16. The computing device of claim 9 , wherein the one or more processors are further configured to:

sending, to the user device, a session token, the session token indicative that the second server device has authorized the user device to generate the data payload, the data payload to be processed by the second server device; and

validating the session token, the request for the data payload from the second server device further including the session token.

17. A non-transitory computer-readable storage medium having stored thereon program instructions that, when executed by one or more processors of a first controller device, cause the first controller device to perform operations comprising:

transmitting, by a first server device and to a secure element of a user device, virtual terminal kernel configuration data, the virtual terminal kernel configuration data used to configure a virtual terminal with a first public encryption key, the virtual terminal associated with the secure element, the first public encryption key used to generate an encrypted second encryption key by encrypting a second encryption key, and the second encryption key used to generate an encrypted data payload by encrypting a data payload;

receiving, by the first server device and from a second server device, a request for the data payload, the request including an encrypted data payload and the encrypted second encryption key;

decrypting, by the first server device, the encrypted second encryption key using a third private encryption key corresponding to the first public encryption key;

generating, by the first server device, a rewrapped second encryption key by encrypting the second encryption key using a fourth encryption key which corresponds to a fifth encryption key associated with the second server device; and

transmitting, by the first server device and to the second server device, the rewrapped second encryption key and the encrypted data payload.

18. The non-transitory computer-readable storage medium of claim 17 , wherein operations further comprise receiving, from the user device, a kernel token, the kernel token indicative that the second server device has authorized the user device to generate one or more data payloads.

19. The non-transitory computer-readable storage medium of claim 18 , wherein operations further comprise:

receiving a reader token from the user device, the reader token including a first data associated with the device and a second data associated with the second server device;

determining the reader token is valid by checking the first data and second data;

generating the kernel token based at least in part one or more of the first data and the second data; and

sending the kernel token to the user device.

20. The non-transitory computer-readable storage medium of claim 17 , wherein operations further comprise:

sending, to the user device, a session token, the session token indicative that the second server device has authorized the user device to generate the data payload, the data payload to be processed by the second server device; and

validating the session token, the request for the data payload from the second server device further including the session token.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2022
From: HUDON-VOYER, RAPHAEL; VAN DEN BERG, FRANK ANDRIES; FONTAINE, SEBASTIEN; ARNAUD, FREDERIC; PROULX-MARCIL, NEILSON; KRISHNAMOORTHY, PRADEEPA; BICALHO DE PADUA, GUILHERME; VORA, VARUN A.; LEE, JIN W.
To: APPLE INC.
Reel/Frame 061896/0421 →
Continuity (2)
Provisional Application 63307626 · Feb 7, 2022
Related Publication 20230254141A1 · Aug 10, 2023
References Cited (24)
US 5978840A · Nguyen et al. · 1999 [cited by applicant]
US 11673058B2 · Schouviller et al. · 2023 [cited by applicant]
US 11823161B2 · Shanmugam · 2023 [cited by applicant]
US 11948146B2 · Prokop · 2024 [cited by examiner]
US 20040177260A1 · Gilfix · 2004 [cited by examiner]
US 20100208889A1 · Humphrey · 2010 [cited by examiner]
US 20110093883A1 · Sun · 2011 [cited by examiner]
US 20150006894A1 · Bandyopadhyay et al. · 2015 [cited by applicant]
US 20150154595A1 · Collinge et al. · 2015 [cited by applicant]
US 20150287031A1 · Radu et al. · 2015 [cited by applicant]
US 20150332262A1 · Lingappa · 2015 [cited by applicant]
US 20150339664A1 · Wong et al. · 2015 [cited by applicant]
US 20160359832A1 · Bao · 2016 [cited by examiner]
US 20170004496A1 · Pujari · 2017 [cited by examiner]
US 20170061419A1 · Kim et al. · 2017 [cited by applicant]
US 20200065803A1 · Abouelenin · 2020 [cited by applicant]
US 20200279258A1 · Agrawal et al. · 2020 [cited by applicant]
US 20210252409A1 · Lee · 2021 [cited by examiner]
US 20230368190A1 · Baruvoori · 2023 [cited by examiner]
WO 2021230835A1 · 2021 [cited by applicant]
WO 2022093218A1 · 2022 [cited by applicant]
International Search Report and Written Opinion of the International Searching Authority mailed May 25, 2023 in International Patent Application No. PCT/US2023/012432. 13 pages. [cited by applicant]
U.S. Appl. No. 17/952,100 , “Non-Final Office Action”, Aug. 15, 2024, 10 pages. [cited by applicant]
International Patent Application No. PCT/US2023/012432 , “International Preliminary Report on Patentability”, Aug. 22, 2024, 8 pages. [cited by applicant]
Cited By (1)
US 12,603,762