IP Library › Granted Patent US 12,548,025
Granted Patent B2
US 12,548,025 · App. 18/223,563 · Granted Feb 10, 2026

System, device, and method of transaction verification based on challenge and response messages

Inventors: Avi Turgeman (New York, NY); Kfir Yeshayahu (Tzur Yigal, IL); Erez Zohar (Hoboken, NJ)
Assignee: IRONVEST, INC.
G06Q20/40145G06F21/40G06F21/54G06F21/64
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,548,025
App. No.
18/223,563
Granted
Feb 10, 2026
Kind
B2
Abstract

Computerized method for verification of user identity and transaction data authenticity, usable in systems having an electronic device that communicates with a remote server. The method includes: (a) receiving user interactions at a non-secure execution environment of the electronic device, reflecting transaction data entered by a user; and transmitting transaction data from the non-secure execution environment to the server; (b) locally authenticating the transaction data and user identity in a secure execution environment of the electronic device; and encrypting transaction data in that secure execution environment, by utilizing a Cryptographic Private Key of the electronic device as encryption key; and transmitting encrypted version of locally-authenticated transaction data from the electronic device to the server. Then, at the server: (c1) receiving the transaction data that was sent in step (a) from the non-secure execution environment to the server, and delaying transaction execution until arrival and verification processing of the encrypted version; (c2) receiving the encrypted version, and decrypting it by utilizing a Cryptographic Public Key of the electronic device as decryption key; (c3) checking whether or not transaction data obtained in step (c1), match transaction data obtained in step (c2); and if they do no match, then: generating a signal that voids or cancels the transaction.

Claims (70)

1 . A computerized method for verification of user identity and transaction data authenticity,

wherein the computerized method is implementable m a system that comprises an electronic device that communicates with a remote server,

wherein the electronic device comprises: a first hardware processor that is configured to execute code, and a first memory unit that is configured to store code and data;

wherein the remote server comprises: a second hardware processor that is configured to execute code, and a second memory unit that is configured to store code and data;

wherein the computerized method comprises:

(a) at the electronic device:

receiving user inputs from a user that enters transaction data;

securely authenticating said user via a biometric authentication process;

securely storing the transaction data in a secure memory unit within the electronic device;

securely storing, in said secure memory unit within the electronic device, a transaction time-stamp;

transmitting the transaction data to the remote server;

(b) at the remote server:

receiving the transaction data from the electronic device;

pseudo-randomly generating a cryptographic nonce, and storing it in the remote server as a server-side copy of the cryptographic nonce;

generating a Server-Side Challenge Message, by encrypting (i) the cryptographic nonce and (ii) the transaction data and (iii) a current time-stamp, with a Cryptographic Public Key of said electronic device as encryption key;

transmitting the Server-Side Challenge Message to the electronic device;

(c) at the electronic device:

receiving the Server-Side Challenge Message;

decrypting the Server-Side Challenge Message, by utilizing a Cryptographic Private Key of said electronic device as a decryption key, to generate a decrypted version of the Server-Side Challenge Message;

extracting from the decrypted version of the Server-Side Challenge Message: (i) the cryptographic nonce, and (ii) the time-stamp that was stored within the Server-Side Challenge Message, and (iii) the transaction data that was stored within the Server-Side Challenge Message;

locating a relevant transaction based on the time-stamp that was extracted from the decrypted version of the Server-Side Challenge Message;

(d) at the electronic device:

checking whether the transaction data, that was stored within the Server-Side Challenge Message, matches the transaction data that was locally stored in the secure memory unit within the electronic device when said transaction data was entered;

and if it does not match, then: generating a signal that voids or cancels the transaction;

(e) at the electronic device:

checking whether the time-stamp, that was stored within the Server-Side Challenge Message, matches the transaction time-stamp that was locally stored in the secure memory unit within the electronic device when said transaction data was entered;

and if it does not match, then: generating a signal that voids or cancels the transaction;

(f) at the electronic device:

generating a Client-Side Response Message, by encrypting the cryptographic nonce that was extracted in step (c) from the decrypted version of the Server-Side Challenge Message, with the Cryptographic Private Key of said electronic device as an encryption key;

transmitting the Client-Side Response Message from said electronic device to said remote server;

(g) at the remote server:

receiving the Client-Side Response Message from said electronic device;

decrypting the Client-Side Response Message from said electronic device, by utilizing the Cryptographic Public Key of said electronic device as decryption key, to generate a decrypted version of the Client-Side Response Message;

checking whether (i) a value of the cryptographic nonce that is extracted from the decrypted version of the Client-Side Response Message, matches (ii) the server-side copy of the cryptographic nonce;

and if it does not match, then: generating a signal that voids or cancels the transaction.

2 . The computerized method of claim 1 ,

wherein step (a) comprises:

at said electronic device, securely authenticating said user via a biometric authentication process that includes at least capturing a video segment of the user while the user enters the transaction data into said electronic device, and utilizing one or more signals or data-items extracted from said video segment to authenticate said user.

3 . A computerized system for verification of user identity and transaction data authenticity,

wherein the computerized system comprises an electronic device that communicates with a remote server;

wherein the electronic device comprises: a first hardware processor that is configured to execute code, and a first memory unit that is configured to store code and data;

wherein the remote server comprises: a second hardware processor that is configured to execute code, and a second memory unit that is configured to store code and data;

wherein the computerized system is configured to perform a process comprising:

(a) at the electronic device:

receiving user inputs from a user that enters transaction data;

securely authenticating said user via a biometric authentication process;

securely storing the transaction data in a secure memory unit within the electronic device;

securely storing, in said secure memory unit within the electronic device, a transaction time-stamp;

transmitting the transaction data to the remote server;

(b) at the remote server:

receiving the transaction data from the electronic device;

pseudo-randomly generating a cryptographic nonce, and storing it in the remote server as a server-side copy of the cryptographic nonce;

generating a Server-Side Challenge Message, by encrypting (i) the cryptographic nonce and (ii) the transaction data and (iii) a current time-stamp, with a Cryptographic Public Key of said electronic device as encryption key;

transmitting the Server-Side Challenge Message to the electronic device;

(c) at the electronic device:

receiving the Server-Side Challenge Message;

decrypting the Server-Side Challenge Message, by utilizing a Cryptographic Private Key of said electronic device as a decryption key, to generate a decrypted version of the Server-Side Challenge Message;

extracting from the decrypted version of the Server-Side Challenge Message: (i) the cryptographic nonce, and (ii) the time-stamp that was stored within the Server-Side Challenge Message, and (iii) the transaction data that was stored within the Server-Side Challenge Message;

locating a relevant transaction based on the time-stamp that was extracted from the decrypted version of the Server-Side Challenge Message;

(d) at the electronic device:

checking whether the transaction data, that was stored within the Server-Side Challenge Message, matches the transaction data that was locally stored in the secure memory unit within the electronic device when said transaction data was entered; and if it does not match, then: generating a signal that voids or cancels the transaction;

(e) at the electronic device:

checking whether the time-stamp, that was stored within the Server-Side Challenge Message, matches the transaction time-stamp that was locally stored in the secure memory unit within the electronic device when said transaction data was entered; and if it does not match, then: generating a signal that voids or cancels the transaction;

(f) at the electronic device:

generating a Client-Side Response Message, by encrypting the cryptographic nonce that was extracted in step (c) from the decrypted version of the Server-Side Challenge Message, with the Cryptographic Private Key of said electronic device as an encryption key;

transmitting the Client-Side Response Message from said electronic device to said remote server;

(g) at the remote server:

receiving the Client-Side Response Message from said electronic device; decrypting the Client-Side Response Message from said electronic device, by utilizing the Cryptographic Public Key of said electronic device as decryption key, to generate a decrypted version of the Client-Side Response Message;

checking whether (i) a value of the cryptographic nonce that is extracted from the decrypted version of the Client-Side Response Message, matches (ii) the server-side copy of the cryptographic nonce;

and if it does not match, then: generating a signal that voids or cancels the transaction.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2023
From: TURGEMAN, AVI; YESHAYAHU, KFIR; ZOHAR, EREZ
To: IRONVEST, INC.
Reel/Frame 064563/0108 →
Continuity (5)
Continuation In Part 18219677 · Jul 9, 2023
Continuation 17114579 · Dec 8, 2020
Provisional Application 63369597 · Jul 27, 2022
Provisional Application 62957236 · Jan 5, 2020
Related Publication 20230368206A1 · Nov 16, 2023
References Cited (15)
US 7801569B1 · Zellner · 2010 [cited by examiner]
US 8112629B2 · Schneider · 2012 [cited by examiner]
US 10372894B2 · Kim · 2019 [cited by examiner]
US 11714170B2 · Smits · 2023 [cited by examiner]
US 20090138405A1 · Blessing · 2009 [cited by examiner]
US 20120246079A1 · Wilson · 2012 [cited by examiner]
US 20120306632A1 · Fleizach · 2012 [cited by examiner]
US 20160212079A1 · Oliver · 2016 [cited by examiner]
US 20170186011A1 · Lieberman · 2017 [cited by examiner]
US 20190289463A1 · Glouche · 2019 [cited by examiner]
US 20190303551A1 · Tussy · 2019 [cited by examiner]
US 20200195639A1 · Chien · 2020 [cited by examiner]
US 20200280750A1 · Nakamura · 2020 [cited by examiner]
US 20200311449A1 · Parupati · 2020 [cited by examiner]
US 20210097260A1 · Verma · 2021 [cited by examiner]