IP Library › Granted Patent US 12,614,172
Granted Patent B2
US 12,614,172 · App. 18/241,844 · Granted Apr 28, 2026

Multi-path communication of electronic device secure element data for online payments

Inventors: Manoj K. Thulaseedharan Pillai (Cupertino, CA); Ahmer A. Khan (Cupertino, CA); Thomas Elliott (Cupertino, CA); Timothy S. Hurley (Cupertino, CA); Jennifer J. Bailey (Cupertino, CA); David E. Brudnicki (Cupertino, CA)
Assignee: Apple Inc.
G06Q20/3829G06Q20/12G06Q20/3227G06Q20/325G06Q20/3278G06Q20/382G06Q20/3823G06Q20/40H04L9/0861G06Q2220/00H04L2209/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,614,172
App. No.
18/241,844
Granted
Apr 28, 2026
Kind
B2
Abstract

Systems, methods, and computer-readable media for communicating electronic device secure element data over multiple paths for online payments are provided. In one example embodiment, a method includes, inter alia, at a commercial entity subsystem, receiving, from an electronic device, device transaction data that includes credential data indicative of a payment credential on the electronic device for funding a transaction with a merchant subsystem, accessing a transaction identifier, deriving a transaction key based on transaction key data that includes the accessed transaction identifier, transmitting, to one of the merchant subsystem and the electronic device, merchant payment data that includes a first portion of the credential data and the accessed transaction identifier, and sharing, with a financial institution subsystem using the transaction key, commercial payment data that includes a second portion of the credential data that is different than the first portion of the credential data. Additional embodiments are also provided.

Claims (56)

1 . A device comprising:

a memory; and

at least one processor configured to:

receive, from a first subsystem via an online resource, potential transaction data corresponding to a transaction between the device and the first subsystem;

generate, on a secure element of the device, secure cryptographic data using at least a portion of token data and a shared secret between the device and a second subsystem;

transmit, to a third subsystem, device transaction data that comprises the secure cryptographic data;

receive, from the third subsystem, first subsystem data that comprises a transaction identifier associated with the device transaction data; and

transmit, to the first subsystem via the online resource, another first subsystem data that comprises the transaction identifier and the token data to perform the transaction.

2 . The device of claim 1 , wherein:

the device transaction data further comprises a portion of the potential transaction data; and

the portion of the potential transaction data comprises at least one of:

an identifier of the first subsystem; and

a currency of a transaction to be funded.

3 . The device of claim 1 , wherein the token data comprises:

a primary account number; and

an expiry date of the primary account number.

4 . The device of claim 1 , wherein the online resource comprises at least one of a web page or an application.

5 . The device of claim 1 , wherein the token data is stored on the secure element.

6 . The device of claim 1 , wherein the secure cryptographic data is generated on the secure element of the device.

7 . The device of claim 1 , further comprising:

the secure element separate from the memory and the at least one processor.

8 . A method comprising:

receiving, by a device and from a first subsystem via an online resource, potential transaction data;

generating, on a secure element of the device, secure cryptographic data using at least a portion of token data and a shared secret between the device and a second subsystem;

transmitting, to a third subsystem, device transaction data that comprises the secure cryptographic data;

receiving, from the third subsystem, first subsystem data that comprises a transaction identifier associated with the device transaction data; and

transmitting, to the first subsystem via the online resource, second another first subsystem data that comprises the transaction identifier and the token data.

9 . The method of claim 8 , wherein:

the device transaction data further comprises a portion of the potential transaction data; and

the portion of the potential transaction data comprises at least one of:

an identifier of the first subsystem; and

a currency of a transaction to be funded.

10 . The method of claim 8 , wherein the token data comprises:

a primary account number; and

an expiry date of the primary account number.

11 . The method of claim 8 , wherein the online resource comprises at least one of a web page or an application.

12 . The method of claim 8 , wherein the token data is stored on the secure element.

13 . The method of claim 8 , wherein the secure cryptographic data is generated on the secure element of the device.

14 . The method of claim 8 , wherein the transmitting, to the third subsystem, the device transaction data bypasses the first subsystem.

15 . A non-transitory machine-readable medium comprising instructions that, when executed by one or more processors of a device, cause the one or more processors to perform operations comprising:

receiving, by the device and from a first subsystem via an online resource, potential transaction data;

generating, on a secure element of the device, secure cryptographic data using at least a portion of token data and a shared secret between the device and a second subsystem;

transmitting, to a third subsystem, device transaction data that comprises the secure cryptographic data;

receiving, from the third subsystem, first subsystem data that comprises a transaction identifier associated with the device transaction data; and

transmitting, to the first subsystem via the online resource, another first subsystem data that comprises the transaction identifier and the token data.

16 . The non-transitory machine-readable medium of claim 15 , wherein:

the device transaction data further comprises a portion of the potential transaction data; and

the portion of the potential transaction data comprises at least one of:

an identifier of the first subsystem; and

a currency of a transaction to be funded.

17 . The non-transitory machine-readable medium of claim 15 , wherein the token data comprises:

a primary account number; and

an expiry date of the primary account number.

18 . The non-transitory machine-readable medium of claim 15 , wherein the online resource comprises at least one of a web page or an application.

19 . The non-transitory machine-readable medium of claim 15 , wherein the token data is stored on the secure element.

20 . The device of claim 1 , wherein the secure cryptographic data is communicated to the second subsystem via the third subsystem without being communicated through the first subsystem.

Continuity (9)
Division 15274841 · Sep 23, 2016
Continuation In Part 14481526 · Sep 9, 2014
Provisional Application 62348956 · Jun 12, 2016
Provisional Application 62234929 · Sep 30, 2015
Provisional Application 62004182 · May 28, 2014
Provisional Application 62002721 · May 23, 2014
Provisional Application 61989107 · May 6, 2014
Provisional Application 61884926 · Sep 30, 2013
Related Publication 20230419310A1 · Dec 28, 2023
References Cited (50)
US 6760711B1 · Gillett · 2004 [cited by applicant]
US 7333615B1 · Jarboe · 2008 [cited by examiner]
US 7376629B1 · McIsaac et al. · 2008 [cited by applicant]
US 7908216B1 · Davis · 2011 [cited by applicant]
US 8214298B2 · McCown · 2012 [cited by applicant]
US 8571995B2 · Spies · 2013 [cited by applicant]
US 10817875B2 · Makhotin · 2020 [cited by examiner]
US 10878414B2 · Pillai · 2020 [cited by applicant]
US 20050256806A1 · Tien · 2005 [cited by applicant]
US 20060112271A1 · Soumiya · 2006 [cited by applicant]
US 20080319914A1 · Carrott · 2008 [cited by applicant]
US 20100250390A1 · Song et al. · 2010 [cited by applicant]
US 20100318468A1 · Carr · 2010 [cited by applicant]
US 20110161671A1 · Whitehouse · 2011 [cited by examiner]
US 20120124378A1 · Chang · 2012 [cited by applicant]
US 20120130839A1 · Koh et al. · 2012 [cited by applicant]
US 20120143770A1 · Pauker et al. · 2012 [cited by applicant]
US 20120197807A1 · Schlesser · 2012 [cited by examiner]
US 20120215693A1 · Faith et al. · 2012 [cited by applicant]
US 20120284187A1 · Hammand et al. · 2012 [cited by applicant]
US 20120290376A1 · Dryer · 2012 [cited by examiner]
US 20120300932A1 · Cambridge et al. · 2012 [cited by applicant]
US 20130054473A1 · Jan et al. · 2013 [cited by applicant]
US 20130212026A1 · Powell · 2013 [cited by applicant]
US 20130263215A1 · Ekdhal · 2013 [cited by applicant]
US 20140019367A1 · Khan et al. · 2014 [cited by applicant]
US 20140052553A1 · Uzo · 2014 [cited by applicant]
US 20140108172A1 · Weber · 2014 [cited by examiner]
US 20140310183A1 · Weber · 2014 [cited by applicant]
US 20150019418A1 · Hotard · 2015 [cited by examiner]
US 20150019443A1 · Sheets · 2015 [cited by applicant]
US 20160019536A1 · Ortiz · 2016 [cited by examiner]
US 20180322602A1 · Song · 2018 [cited by examiner]
CN 101295384 · 2008 [cited by applicant]
CN 102057386 · 2011 [cited by applicant]
CN 102609837 · 2012 [cited by applicant]
CN 103123708 · 2013 [cited by applicant]
KR 1020040091063 · 2004 [cited by applicant]
KR 20110083193 · 2011 [cited by applicant]
KR 1020120108599 · 2012 [cited by applicant]
KR 1020130082656 · 2013 [cited by applicant]
KR 1020130100872 · 2013 [cited by applicant]
TW M418352 · 2011 [cited by applicant]
TW 201227557 · 2012 [cited by applicant]
TW 201241769 · 2012 [cited by applicant]
WO WO0079367 · 2000 [cited by applicant]
WO WO0159731 · 2001 [cited by applicant]
WO WO2013067521 · 2013 [cited by applicant]
Chinese Office Action from Chinese Patent Application No. 201480049141.0, dated Sep. 25, 2019, 22 pages including English language translation. [cited by applicant]
Korean Office Action from Korean Patent Application No. 2018-7003517, dated Nov. 20, 2019, 13 pages including English language translation. [cited by applicant]