IP Library › Granted Patent US 12,395,319
Granted Patent B2
US 12,395,319 · App. 17/952,100 · Granted Aug 19, 2025

Data transfer using a virtual terminal

Inventors: Raphael Hudon-Voyer (Montreal, CA); Frank Andries van den Berg (San Jose, CA); Sebastien Fontaine (Montreal, CA); Frederic Arnaud (Montreal, CA); Neilson Proulx-Marcil (Montreal, CA); Pradeepa Krishnamoorthy (Llie-Perrot, CA); Guilherme Bicalho de Padua (Montreal, CA); Varun A. Vora (Campbell, CA); Jin W. Lee (South Barrington, IL)
Assignee: Apple Inc.
H04L9/0822G06F9/45558H04L9/0825H04L9/14H04L9/3213H04L9/3234H04L67/06G06F2009/45595G06Q20/36G06Q20/3674G06Q20/3821G06Q20/3829H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,395,319
App. No.
17/952,100
Filed
Sep 23, 2022
Granted
Aug 19, 2025
Kind
B2
Art Unit
2457
USPC
713/171
Abstract

Techniques for using a virtual terminal on a device to process a data transfer are described herein. These techniques provide the use of a virtual terminal for transfer of data, encryption of the data, and rewrapping the data. A virtual terminal receives virtual terminal kernel configuration data, configuring the terminal with a first public encryption key. The virtual terminal generates a second encryption key only known by the virtual terminal. The virtual terminal encrypts the second encryption key with the first public encryption key. The second encryption key is used to encrypt data for data transfer. The virtual terminal is associated with a secure element of a device that is outside the normal processor of the device. The secure element is designed for encryption.

Claims (61)

1. A method, comprising:

receiving, by a user device and from a first server device, virtual terminal kernel configuration data, the virtual terminal kernel configuration data used to configure a virtual terminal of the user device with a first public encryption key, and the virtual terminal associated with a secure element of the user device;

generating, by the user device, a data payload, the data payload associated with a request for a data transfer;

generating, by the user device, a second encryption key;

generating, by the user device, an encrypted data payload by encrypting the data payload with the second encryption key;

generating, by the user device, an encrypted second encryption key by encrypting the second encryption key with the first public encryption key;

requesting, by the user device, and from a second server device, authorization for the request for data transfer, the request for data transfer including the encrypted data payload and the encrypted second encryption key; and

receiving, by the user device, and from the second server device, authorization for the request for data transfer, the second server device evaluating the data payload after the first server device decrypts the encrypted data payload and the encrypted second encryption key.

2. The method of claim 1 , wherein the secure element is a part of the user device, wherein the secure element is a separate hardware module configured for security and cryptography, and wherein the secure element is separate from an application processor on the user device.

3. The method of claim 2 , wherein generating the second encryption key and generating the encrypted data payload are performed by the secure element.

4. The method of claim 1 , further comprising sending, to the first server device, a kernel token, the kernel token indicative that the second server device has authorized the user device to generate one or more data payloads.

5. The method of claim 4 , further comprising:

sending, to the first server device, a reader token, the reader token including a first data associated with the user device and a second data associated with the second server device;

receiving, from the first server device, the kernel token, the kernel token indicative that the reader token is valid; and

sending, to the first server device, a request for the virtual terminal kernel configuration data, the request including the kernel token.

6. The method of claim 1 , further comprising:

receiving, from the first server device, a session token, the session token indicative that the first server device has authorized the user device to generate the data payload, the data payload to be processed by the second server device; and

validating the session token, and

wherein the request for the data transfer from the server device further includes the session token.

7. The method of claim 1 , wherein the second encryption key is only known by the secure element.

8. A computing device, comprising:

one or more memories; and

one or more processors in communication with the one or more memories and configured to execute instructions stored in the one or more memories to cause the computing device to:

receive, by a user device and from a first server device, virtual terminal kernel configuration data, the virtual terminal kernel configuration data used to configure a virtual terminal of the user device with a first public encryption key, and the virtual terminal associated with a secure element of the user device;

generate, by the user device, a data payload, the data payload associated with a request for a data transfer;

generate, by the user device, a second encryption key;

generate, by the user device, an encrypted data payload by encrypting the data payload with the second encryption key;

generate, by the user device, an encrypted second encryption key by encrypting the second encryption key with the first public encryption key;

request, by the user device, and from a second server device, authorization for the request for data transfer, the request for data transfer including the encrypted data payload and the encrypted second encryption key; and

receive, by the user device, and from the second server device, authorization for the request for data transfer, the second server device evaluating the data payload after the first server device decrypts the encrypted data payload and the encrypted second encryption key.

9. The computing device of claim 8 , wherein the secure element is a part of the user device, wherein the secure element is a separate hardware module configured for security and cryptography, and wherein the secure element is separate from an application processor on the user device.

10. The computing device of claim 9 , wherein generating the second encryption key and generating the encrypted data payload are performed by the secure element.

11. The computing device of claim 8 , wherein the one or more processors are further configured to send, to the first server device, a kernel token, the kernel token indicative that the second server device has authorized the user device to generate one or more data payloads.

12. The computing device of claim 11 , wherein the one or more processors are further configured to:

send, to the first server device, a reader token, the reader token including a first data associated with the user device and a second data associated with the second server device;

receive, from the first server device, the kernel token, the kernel token indicative that the reader token is valid; and

send, to the first server device, a request for the virtual terminal kernel configuration data, the request including the kernel token.

13. The computing device of claim 8 , wherein the one or more processors are further configured to:

receive, from the first server device, a session token, the session token indicative that the first server device has authorized the user device to generate the data payload, the data payload to be processed by the second server device; and

validate the session token, and

wherein the request for the data transfer from the server device further includes the session token.

14. The computing device of claim 8 , wherein the second encryption key is only known by the secure element.

15. A non-transitory computer-readable storage medium having stored thereon program instructions that, when executed by one or more processors of a user device, cause the user device to perform operations comprising:

receiving, from a first server device, virtual terminal kernel configuration data, the virtual terminal kernel configuration data used to configure a virtual terminal of the user device with a first public encryption key, and the virtual terminal associated with a secure element of the user device;

generating a data payload, the data payload associated with a request for a data transfer;

generating a second encryption key;

generating an encrypted data payload by encrypting the data payload with the second encryption key;

generating an encrypted second encryption key by encrypting the second encryption key with the first public encryption key; and

requesting, from a second server device, authorization for the request for data transfer, the request for data transfer including the encrypted data payload and the encrypted second encryption key;

receiving, from the second server device, authorization for the request for data transfer, the second server device evaluating the data payload after the first server device decrypts the encrypted data payload and the encrypted second encryption key.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the secure element is a part of the user device, wherein the secure element is a separate hardware module configured for security and cryptography, and wherein the secure element is separate from an application processor on the user device.

17. The non-transitory computer-readable storage medium of claim 16 , wherein generating the second encryption key and generating the encrypted data payload are performed by the secure element.

18. The non-transitory computer-readable storage medium of claim 15 , wherein operations further comprise sending, to the first server device, a kernel token, the kernel token indicative that the second server device has authorized the user device to generate one or more data payloads.

19. The non-transitory computer-readable storage medium of claim 18 , wherein operations further comprise:

sending, to the first server device, a reader token, the reader token including a first data associated with the user device and a second data associated with the second server device;

receiving, from the first server device, the kernel token, the kernel token indicative that the reader token is valid; and

sending, to the first server device, a request for the virtual terminal kernel configuration data, the request including the kernel token.

20. The non-transitory computer-readable storage medium of claim 15 , wherein operations further comprise:

receiving, from the first server device, a session token, the session token indicative that the first server device has authorized the user device to generate the data payload, the data payload to be processed by the second server device; and

validating the session token, and

wherein the request for the data transfer from the server device further includes the session token.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2022
From: HUDON-VOYER, RAPHAEL; VAN DEN BERG, FRANK ANDRIES; FONTAINE, SEBASTIEN; ARNAUD, FREDERIC; PROULX-MARCIL, NEILSON; KRISHNAMOORTHY, PRADEEPA; BICALHO DE PADUA, GUILHERME; VORA, VARUN A.; LEE, JIN W.
To: APPLE INC.
Reel/Frame 061981/0404 →
Continuity (2)
Provisional Application 63307626 · Feb 7, 2022
Related Publication 20230254123A1 · Aug 10, 2023
References Cited (26)
US 5978840A · Nguyen et al. · 1999 [cited by applicant]
US 11290257B2 · Tanimoto · 2022 [cited by examiner]
US 11537421B1 · Brooker · 2022 [cited by examiner]
US 11673058B2 · Schouviller · 2023 [cited by examiner]
US 11823161B2 · Shanmugam · 2023 [cited by examiner]
US 11948146B2 · Prokop et al. · 2024 [cited by applicant]
US 20040177260A1 · Gilfix et al. · 2004 [cited by applicant]
US 20100208889A1 · Humphrey et al. · 2010 [cited by applicant]
US 20110093883A1 · Sun · 2011 [cited by applicant]
US 20150006894A1 · Bandyopadhyay · 2015 [cited by examiner]
US 20150154595A1 · Collinge · 2015 [cited by examiner]
US 20150287031A1 · Radu et al. · 2015 [cited by applicant]
US 20150332262A1 · Lingappa · 2015 [cited by examiner]
US 20150339664A1 · Wong · 2015 [cited by examiner]
US 20160359832A1 · Bao et al. · 2016 [cited by applicant]
US 20170004496A1 · Pujari · 2017 [cited by applicant]
US 20170061419A1 · Kim · 2017 [cited by examiner]
US 20200065803A1 · Abouelenin · 2020 [cited by examiner]
US 20200279258A1 · Agrawal · 2020 [cited by examiner]
US 20210252409A1 · Lee · 2021 [cited by applicant]
US 20230368190A1 · Baruvoori et al. · 2023 [cited by applicant]
WO 2021230835A1 · 2021 [cited by applicant]
WO WO2022093218A1 · 2022 [cited by examiner]
International Search Report and Written Opinion of the International Searching Authority mailed May 25, 2023 in International Patent Application No. PCT/US2023/012432. 13 pages. [cited by applicant]
International Patent Application No. PCT/US2023/012432 , “International Preliminary Report on Patentability”, Aug. 22, 2024, 8 pages. [cited by applicant]
U.S. Appl. No. 17/952,094 , Notice of Allowance, Mailed On Jan. 16, 2025, 13 pages. [cited by applicant]
Cited By (1)
US 12,603,762