Credential extension for data transfer
The present application relates to devices and components including apparatus, systems, methods, and computer-readable medium to utilize a credential extension for collection of information for a data transfer. The credential extension may be sandboxed which limit the information to be collected related to the data transfer and/or provide protection for the information collected related to the data transfer.
1 . One or more non-transitory computer-readable media having instructions that, when executed by one or more processors of a device, cause the device to:
detect a selection of a credential within a user information application, the credential to be utilized for performance of a data transfer;
display a representation of the credential on a screen of the device, the representation to be scanned by a remote device to initiate the data transfer;
execute a credential extension within the user information application to collect information for authorization of the data transfer, the credential extension being sandboxed within the user information application, the sandboxing of the credential extension configured to limit privileges of the credential extension to authorized operations within the user information application;
collect, by the credential extension, the information related to the data transfer for authorization of the data transfer, the information including an indication of when the representation is displayed on the screen of the device or a location of the device when the representation is displayed on the screen of the device; and
provide, by the credential extension, a bundle with the information to a services device corresponding to the credential for authorization of the data transfer between a first account associated with the device and a second account associated with the remote device.
2 . The one or more non-transitory computer-readable media of claim 1 , wherein the instructions, when executed by the one or more processors, further cause the device to detect an indication of the information to be collected by the credential extension received from the services device, wherein the credential extension is to collect the information based at least in part on the indication of the information from the services device.
3 . The one or more non-transitory computer-readable media of claim 1 , wherein the instructions, when executed by the one or more processors, further cause the device to detect a user indication of acceptable information for collection during the data transfer, wherein the information collected by the credential extension is limited by the acceptable information.
4 . The one or more non-transitory computer-readable media of claim 1 , wherein an application of a security procedure for security of the information includes encryption of the bundle.
5 . The one or more non-transitory computer-readable media of claim 1 , wherein the instructions, when executed by the one or more processors, further cause the device to display, on the screen of the device, an indication that the credential extension is being executed to collect the information based at least in part on the execution of the credential extension.
6 . The one or more non-transitory computer-readable media of claim 1 , wherein to display the representation of the credential includes to display a quick response (QR) code, and wherein the information collected by the credential extension is related to the display of the quick response code.
7 . The one or more non-transitory computer-readable media of claim 1 , wherein the instructions, when executed by the one or more processors, further cause the device to:
detect, by the credential extension, a payload associated with the data transfer;
sign, by the credential extension, the payload with an SM 2 signature; and
provide, by the credential extension, the signed payload to the services device for authorization.
8 . The one or more non-transitory computer-readable media of claim 1 , wherein the representation includes a quick response (QR) code.
9 . The one or more non-transitory computer-readable media of claim 1 , wherein the user information application is executed on the device, and wherein the credential extension is executed within the user information application on the device.
10 . A device, comprising:
memory to store one or more credentials; and
processing circuitry coupled to the memory, the processing circuitry to:
detect a selection of a credential, of the one or more credentials, within a user information application, the credential to be utilized for performance of a data transfer;
display a representation of the credential on a screen of the device, the representation to be scanned by a remote device to initiate the data transfer;
execute a credential extension within the user information application to collect information for authorization of the data transfer, the credential extension being sandboxed within the user information application which limits privileges of the credential extension to authorized operations with the user information application;
collect, by the credential extension, the information related to the data transfer for authorization of the data transfer, the information including an indication of when the representation is displayed on the screen of the device or a location of the device when the representation is displayed on the screen of the device; and
provide, by the credential extension, a bundle with the information to a services device corresponding to the credential for authorization of the data transfer between a first account associated with the device and a second account associated with the remote device.
11 . The device of claim 10 , wherein to display the representation includes to display a quick response (QR) code on the screen of the device, and wherein the information collected by the credential extension is related to the display of the quick response code.
12 . The device of claim 11 , wherein the processing circuitry is further to prevent, by the credential extension, screenshots and screen recordings by the device while the quick response code is displayed.
13 . The device of claim 10 , wherein the processing circuitry is further to detect a user indication of acceptable information for collection during the data transfer, wherein the information collected by the credential extension is limited by the acceptable information.
14 . The device of claim 10 wherein an application of a security procedure for security of the information includes encryption of the bundle.
15 . The device of claim 10 , wherein the processing circuitry is further to detect an indication of the information to be collected by the credential extension received from the services device, wherein the credential extension is to collect the information based at least in part on the indication of the information from the services device.
16 . The device of claim 10 , wherein the processing circuitry is further to:
detect, by the credential extension, a payload associated with the data transfer;
sign, by the credential extension, the payload with an SM 2 signature; and
provide, by the credential extension, the signed payload to the services device for authorization.
17 . A method for authorization of a data transfer, comprising:
detecting, by a device, a selection of a credential within a user information application, the credential to be utilized for performance of the data transfer;
displaying, by the device, a representation of the credential on a screen of the device, the representation to be scanned by a remote device to initiate the data transfer;
executing, by the device, a credential extension within the user information application to collect information for authorization of the data transfer, the credential extension being sandboxed within the user information application which limits privileges of the credential extension to authorized operations within the user information application;
collecting, by the credential extension, the information related to the data transfer for authorization of the data transfer, the information including an indication of when the representation is displayed on the screen of the device or a location of the device when the representation is displayed on the screen of the device; and
providing, by the credential extension, a bundle with the information to a services device corresponding to the credential for authorization of the data transfer between a first account associated with the device and a second account associated with the remote device.
18 . The method of claim 17 , further comprising detecting, by the device, an indication of the information to be collected by the credential extension received from the services device, wherein the credential extension is to collect the information based at least in part on the indication of the information from the services device.
19 . The method of claim 17 , wherein displaying the representation includes displaying, by the device, a quick response (QR) code based at least in part on the selection of the credential, and wherein the information collected by the credential extension is related to the display of the quick response code.
20 . The method of claim 17 , wherein the representation includes a quick response (QR) code.