Systems and Methods for Connecting Safety Devices
Through the random code and personal token hashing mechanism between the portable communication device and the access device, the problems of poor user experience, insufficient security and privacy in the prior art are solved, and a safe and convenient interaction process is achieved.
Patent Information
- Application Number
- CN201880092204.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2018-04-10
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2038-04-10
AI Technical Summary
The prior art has poor user experience, insufficient security and privacy issues during the interaction between the portable communication device and the access device, especially when transactions are conducted without the need for physical operations of the user.
The first random code is generated and transmitted by the portable communication device, the access device receives and generates the second random code, and hashed it in combination with the personal token provided by the user to form a hash output. When the hash outputs at both ends are equal, a secure communication channel is established.
It realizes a safe and convenient interaction between the portable communication device and the access device, improves the user experience, ensures the security of user privacy, and reduces the user interaction needs.
Smart Images

Figure CN111954878B_ABST
Abstract
Description
[0001] Cross - reference to related applications
[0002] None. Background art
[0003] In many cases, multiple portable communication devices may be able to communicate with multiple terminals at a particular location to obtain access to a particular resource. For example, referring to Figure 1 , there may be multiple portable communication devices D1, D2, D2, and D4 that are able to interact with multiple access devices T1, T2, and T3 in location L. Each of the access devices T1, T2, and T3 can be a point - of - sale terminal, an information kiosk, a secure location input device, etc. The portable communication devices D1, D2, D3, and D4 can be mobile phones, wearable devices, etc. that are able to interact with the access devices T1, T2, and T3 (e.g., conduct a payment transaction). The portable communication devices D1, D2, D3, and D4 can communicate with any one of the access devices T1, T2, and T3 using a medium - range communication protocol such as Bluetooth. However, in order to ensure that the user of a particular portable communication device interacts correctly with the intended access device, pairing is required to securely connect the particular portable communication device and the intended access device.
[0004] There are various methods of pairing a portable communication device with an access device to perform an interaction. These include the following examples.
[0005] In a first example, the access device can air - broadcast its identifier to different portable communication devices within the location. Portable communication devices near the access device can scan and look for multiple neighboring access devices. The portable communication device asks the user to select one of the access devices to connect for the next transaction. The problem associated with this method is that the user needs to turn on the portable communication device (e.g., take out the portable communication device and unlock it) and select an access device from a list of candidate access devices. The candidate access devices can be associated with candidate access device identifiers (e.g., checkout lane number, gas pump number, etc.). This is time - consuming and not a hands - free user experience. It also requires human - readable access device identifiers.
[0006] In another example, a portable communication device may broadcast its identifier (e.g., a device name set by the user, such as "Joe’s Iphone"). An access device near the portable communication device may scan and look for neighboring portable communication devices. The access device asks the user to select one portable communication device to connect to, such that the portable communication device may perform an interaction with the access device. The problem with this process is that the portable communication device broadcasts a static identifier. This raises privacy concerns as it can be used to track the user. The portable communication device cannot use a random identifier as the user would not be able to recognize the random identifier or pick their portable communication device from a list of neighboring portable communication devices.
[0007] In yet another example, the access device may display a QR code that may include the identifier of the access device. The portable communication device scans the QR code and connects to the corresponding access device. One problem with this process is that the user needs to turn on the portable communication device (e.g., take out the portable communication device and unlock it), and then have the portable communication device perform the scan. This is not a hands-free user experience and is inconvenient. The user is also required to physically stand next to the access device.
[0008] In yet another example, the portable communication device displays a QR code that encodes the identifier of the portable communication device. The access device scans the QR code. Then, the access device connects to the corresponding portable communication device. This process also raises privacy concerns as the location of the user can be tracked.
[0009] In other additional examples, barcodes, NFC tags, sounds, or ultrasonic signals may be used instead of QR codes, but the same problems will still exist.
[0010] Accordingly, a more convenient and secure method for allowing interaction between an access device and a portable communication device is needed. Maintaining user privacy is also needed.
[0011] Embodiments of the present invention, alone and in combination, solve this and other problems. SUMMARY OF THE INVENTION
[0012] Embodiments of the present invention include secure and convenient methods for connecting a portable communication device to an access device in a wireless environment.
[0013] One embodiment of the present invention includes a method: generating, by a portable communication device, a first random code, the portable communication device including a data processor and a memory storing a personal token, the portable communication device being used by a user; transmitting, by the portable communication device, the first random code to an access device, wherein the access device receives the first random code, generates a second random code, receives the personal token from the user of the portable communication device, and hashes the first random code, the second random code, and the personal token to form a first hash output; receiving, from the access device, the first hash output and the second random code; hashing the first random code, the stored personal token, and the second random code to form a second hash output; determining, by the portable communication device, whether the first hash output and the second hash output are equal; and forming, when the first hash output and the second hash output are equal, a secure communication channel between the portable communication device and the access device. If the first hash output and the second hash output are not equal, the personal token input to the access device does not match the personal token stored in the portable communication device. In this case, the connection process will then stop and a secure communication channel will not be formed.
[0014] Another embodiment of the present invention includes a portable communication device, the portable communication device including: a processor; and a computer-readable medium coupled to the processor, the computer-readable medium including code executable by the processor to implement a method, the method including: generating, by a portable communication device, a first random code, the portable communication device including a data processor and a memory storing a personal token, the portable communication device being used by a user; transmitting, by the portable communication device, the first random code to an access device, wherein the access device receives the first random code, generates a second random code, receives the personal token from the user of the portable communication device, and hashes the first random code, the second random code, and the personal token to form a first hash output; receiving, from the access device, the first hash output and the second random code; hashing the first random code, the stored personal token, and the second random code to form a second hash output; determining, by the portable communication device, whether the first hash output and the second hash output are equal; and forming, when the first hash output and the second hash output are equal, a secure communication channel between the portable communication device and the access device.
[0015] Another embodiment of the present invention relates to a method, the method comprising: receiving, by the access device, a first random code from a portable communication device; generating, by the access device, a second random code; generating, by the access device, a first hash output of the first random code, the second random code, and the personal token; transmitting, by the access device, the second random code and the first hash output to a portable communication device near the access device, wherein the portable communication device generates a second hash output from the personal token, a first random value, and a second random value, and determines whether the first hash output and the second hash output are equal; and forming a secure communication channel between the access device and the portable communication device when the first hash output and the second hash output match.
[0016] Another embodiment of the present invention relates to an access device, comprising: a data processor; and a computer-readable medium including code executable by the processor to perform methods such as the method described above.
[0017] In some embodiments, the access device may receive a plurality of first random codes from a plurality of portable communication devices near the access device. The access device may generate a first hash output for each of the plurality of communication devices and transmit the first hash output to the plurality of communication devices for evaluation.
[0018] In some embodiments, the portable communication device may receive a plurality of first hash outputs from a plurality of access devices near the portable communication device. The portable communication device may calculate a plurality of second hash outputs until one matches the received first hash output. If there is a match, the secure communication channel between the portable communication device and the access device provides the matching first hash output. If there is no second hash output that matches the received first hash output, the connection process may stop.
[0019] These and other embodiments of the present invention are described in further detail below. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 A diagram showing a plurality of portable communication devices and a plurality of access devices within a specified location.
[0021] Figure 2 A block diagram showing an access device according to an embodiment of the present invention.
[0022] Figure 3 A block diagram showing an exemplary portable communication device according to an embodiment of the present invention.
[0023] Figure 4 An exemplary flowchart showing a method according to an embodiment of the present invention.
[0024] Figure 5 A block diagram showing a transaction processing system according to an embodiment of the present invention.
[0025] Figure 6 A block diagram showing a secure location access system according to an embodiment of the present invention. Detailed Description
[0026] A portable communication device (e.g., a mobile phone, a wearable device, an IoT device) can communicate using a medium-range communication protocol such as Bluetooth and WiFi. New access devices (e.g., a smart POS device, a mobile POS device) can also communicate using a medium-range communication protocol. The portable communication device can interact with the access device using such a medium-range communication protocol.
[0027] The medium-range communication protocol has the following advantages. First, the user can use the portable communication device to conduct transactions with the access device hands-free, without having to slide, insert, or tap the portable communication device against the access device. In addition, although OR codes have been used, it is difficult to implement them in two-way communication between the access device and the portable communication device. Second, a user with a portable communication device can also conduct a transaction without being physically close to the access device, thus reducing the waiting time for conducting a transaction (e.g., waiting in a checkout lane). Third, when there is no checkout lane, for example, a resource provider of a merchant can process transactions faster. Fourth, an employee of the resource provider can interact with the user during the transaction, regardless of the location of the user or the employee within the store.
[0028] Before discussing specific embodiments and examples, some descriptions of the terms used herein are provided below.
[0029] A "portable communication device" can be a portable device that can be transported and operated by a user and can include one or more electronic components (e.g., integrated chips, etc.). The portable communication device according to an embodiment of the present invention can take any suitable form, including but not limited to, a mobile phone (e.g., a smart phone, a cellular phone, etc.), a tablet computer, a portable media player, a personal digital assistant device (PDA), a wearable communication device (e.g., a watch, a bracelet, glasses, etc.), an e-reader device, a laptop computer, a netbook, a ultrabook, etc. The portable communication device can also take the form of a vehicle (e.g., a car) equipped with communication capabilities.
[0030] A portable communication device according to an embodiment of the present invention may be configured to communicate with an external entity, such as a telecommunications gateway, via telecommunications technologies and protocols. The portable communication device may also be configured to communicate with an external entity, such as an access device, using any suitable short-range or medium-range communication technology, including Bluetooth (classic and BLE - Bluetooth Low Energy), Wi-Fi, etc.
[0031] A "portable transaction device" may be a portable communication device that can be used to conduct transactions. The portable transaction device may include storage technologies (e.g., electronic memory, magnetic stripe, etc.) for storing credentials or tokens associated with a user account. The portable transaction device may take any form described above for the portable communication device, or may take the form of a card (e.g., integrated chip card, magnetic stripe card) or a keychain, etc. In some embodiments, the portable transaction device and the portable communication device may be the same device and do not need to be separate devices. Specific examples of the portable transaction device may include, for example, mobile phones such as smart phones, wearable devices, payment cards such as credit cards, debit cards, and prepaid cards, vehicles with telecommunications capabilities, etc.
[0032] A "server computer" may include a powerful computer or a computer cluster. For example, the server computer may be a mainframe, a small computer cluster, or a group of servers acting as a unit. In one example, the server computer may be a database server connected to a web server. The server computer may include one or more computing devices and may use any of a variety of computing architectures, arrangements, and compilations to service requests from one or more client computers.
[0033] An "access device" may be any suitable device for providing access to an external computer system. The access device may take any suitable form. Some examples of the access device include point-of-sale (POS) devices, cellular phones, PDAs, personal computers (PCs), tablet PCs, handheld dedicated readers, set-top boxes, electronic cash registers (ECRs), automated teller machines (ATMs), virtual cash registers (VCRs), information kiosks, security systems, access systems, websites, etc. The access device may use any suitable contact or non-contact operating mode to send or receive data from or associated with the portable communication device. In some embodiments where the access device may include a POS terminal, any suitable POS terminal may be used and it may include a reader, a processor, and a computer-readable medium. The reader may include any suitable contact or non-contact operating mode. For example, an exemplary card reader may include a radio frequency (RF) antenna, an optical scanner, a barcode reader, or a magnetic stripe reader that interacts with the portable communication device.
[0034] An "authorization request message" can be an electronic message sent to an entity to perform an authorization process. In some cases, an authorization request message can be sent to a processor server computer associated with a processing network and / or an authorization computer associated with an authorization entity to request authorization for an access request. According to some embodiments, the authorization request message can comply with ISO 8583 (International Organization for Standardization), which is a standard for systems that exchange electronic transaction information associated with payments made by users using payment devices or payment accounts. The authorization request message can include an account identifier that can be associated with a device or an account. The authorization request message can also include additional data elements corresponding to "identification information", including (by way of example only): service code, CVV (Card Verification Value), dCVV (dynamic Card Verification Value), expiration date, etc. The authorization request message can also include "access request information", such as any information associated with the current access request, such as access request amount, resource provider identifier, resource provider location, etc., and any other information that can be used to determine whether to identify and / or authorize the access request.
[0035] An "authorization response message" can be an electronic message reply to an authorization request message for an authorization process. In some embodiments, the authorization response message can be generated by a processor server computer associated with a processing network and / or an authorization computer associated with an authorization entity. By way of example only, the authorization response message can include one or more of the following status indicators: Approved - the transaction is approved; Declined - the transaction is not approved; or Call Center - more information is pending for the response and the resource provider must call a toll-free authorization phone number. The authorization response message can also include an authorization code, which can be a code returned by a credit card issuing bank to an access device of a resource provider (e.g., a POS device) in response to an authorization request message in an electronic message (either directly or through a processing network) indicating that the transaction is approved. The code can be used as evidence of authorization. As noted above, in some embodiments, the processing network can generate or forward an authorization response message to a resource provider.
[0036] A "token" can include an alternative identifier for some information. For example, a token can include a string of alphanumeric characters that can be used as an alternative to the original account identifier. In some cases, the token can be a payment token, which can include an identifier of a payment account, which is an alternative to the actual account identifier, such as the primary account number (PAN). For example, the token "4900 0000 0000 0001" can be used in place of the PAN "4147 0900 0000 1234". In some embodiments, the token can be "in a reserved format" and can have a numeric format that conforms to the account identifiers used in existing processing networks (e.g., the ISO 8583 financial transaction message format). In some embodiments, the token can be used in place of the PAN to initiate, authorize, settle, or resolve a payment transaction. In other systems that typically provide the original credentials, the token can also be used to represent the original credentials. In some embodiments, a token value can be generated such that it may not be possible to computationally recover the original PAN or other account identifier from the token value.
[0037] "Access data" can include account information, or any other suitable type of data that can be used to access resources such as data, goods, services, locations, etc. Access data can be specifically associated with a user or a group of users and can be in any suitable form. Access data can include account information, access tokens, and the like.
[0038] "Account information" can refer to any information associated with a user account. Such information can be directly related to the account or can be derived from information related to the account. Examples of account information can include account identifiers, user names, passwords, user information (e.g., name, age, email address, shipping address, etc.). In some cases, account information can also be referred to as payment account information, card account information, etc., and can be associated with a payment device (e.g., a payment card). For example, account information can include the PAN (primary account number or "account number"), user name, expiration date, CVV (card verification value), dCVV (dynamic card verification value), CVV2 (card verification value 2), CVC3 card verification value, etc. CVV2 is generally understood to be a static verification value associated with a payment device. The CVV2 value is generally visible to the user (e.g., the user), while the CVV and dCVV values are generally embedded in memory or authorization request messages and are not easily known to the user (but they are known to the issuer and the payment processor).
[0039] A "resource providing entity" can be an entity that makes resources available to users. A resource providing entity can also be referred to as a resource provider. Examples of resource providing entities include resource providers, suppliers, vendors, owners, traders, wallet providers, service providers, etc. In some embodiments, such an entity can be an individual person, a group of individuals, or a larger group of individuals (such as a company). A resource providing entity can be associated with one or more physical locations (such as a supermarket, a mall, a store, etc.) and online platforms (such as an e-commerce website, an online company, etc.). In some embodiments, a resource providing entity can make physical items (such as goods, products, etc.) available to users. In other embodiments, a resource providing entity can make digital resources (such as electronic documents, electronic files, etc.) available to users. In other embodiments, a resource providing entity can manage user access to certain resources. In some embodiments, a resource can be a service (such as a digital wallet service).
[0040] An "access request" can refer to a request to access a resource. The resource can be a physical resource (such as a good), a digital resource (such as an electronic document, electronic data, etc.), or a service. In some cases, an access request can be submitted by transmitting an access request message that includes access request data. Generally, a device associated with the requester can transmit the access request message to a device associated with the resource provider.
[0041] "Access request data" can refer to any information about or related to an access request. Access request data can include access data. Access request data can include information that can be used to process and / or verify an access request. For example, access request data can include details associated with entities (such as a resource provider computer, a processor server computer, an authorization computer, etc.) involved in processing the access request, such as entity identifiers (such as names, etc.), location information associated with the entity, and information indicating the type of the entity (such as a category code). Exemplary access request data can include information indicating the volume of the access request, the location of the access request, the received resource (such as a product, a document, etc.), information about the received resource (such as size, volume, type, etc.), resource providing entity data (such as resource provider data, document owner data, etc.), user data, the date and time of the access request, the method used to make the access request (such as contactless, non-contactless, etc.), and other relevant information. Access request data can also be referred to as access request information, transaction data, transaction information, etc.
[0042] Figure 2A block diagram of an access device 200 according to an embodiment of the present invention is shown. The access device 200 may include a processor 202 and a memory element 204, and the memory element includes a computer-readable medium coupled to the processor 202. A reader 208, a display 210, a speaker 212, an input element 206, and a network interface 214 may be electronically coupled to the processor 202. Exemplary device readers may include an RF (radio frequency) antenna, a magnetic stripe reader, etc., that can interact with a portable communication device. Exemplary computer-readable media may include one or more memory chips, disk drives, etc.
[0043] The exemplary processor may be a central processing unit (CPU). As used herein, a processor may include a single-core processor, multiple single-core processors, multi-core processors, multiple multi-core processors, or any other suitable combination of hardware configured to perform arithmetic operations, logical operations, and / or input / output operations of a computing device.
[0044] The network interface 214 may be any suitable combination of hardware and software that enables data to be transmitted to and from an external computer. The network interface 214 may enable the processor server computer to transmit data to and receive data from another device (e.g., a resource provider computer, an authorization computer, etc.). Some examples of the network interface 214 may include a modem, a physical network interface (e.g., an Ethernet card or other network interface card (NIC)), a virtual network interface, a communication port, a Personal Computer Memory Card International Association (PCMCIA) slot and card, etc. Wireless protocols enabled by the network interface 214 may include Wi-Fi TM .
[0045] Data transmitted via the network interface 214 may be in the form of a signal, which may be an electrical, electromagnetic, optical, or any other signal (collectively referred to as an "electronic signal" or "electronic message") that can be received by an external communication interface. These electronic messages, which may include data or instructions, may be provided between the network interface 214 and other devices via a communication path or channel. As described above, any suitable communication path or channel may be used, such as wires or cables, optical fibers, telephone lines, cellular links, radio frequency (RF) links, WAN or LAN networks, the Internet, or any other suitable medium.
[0046] The memory element 204 may include a computer-readable medium that may store code or instructions to cause the access device 200 to perform the functions described herein. For example, the memory element 204 may include a random code generator 204A, an authorization module 204B, a hashing module 204C, and a personal token 204D.
[0047] The random code generator 204A may include code or instructions, and / or hardware for causing the access device 200 to generate a random code such as a random number. The random code generator may be a random number generator. Exemplary random number generators may include a pseudo-random number generator (PRNG), a true random number generator (TRNG), and a quasi-random number generator.
[0048] The authorization module 204B may include code or instructions for causing the access device 200 to generate and format an authorization request message, send the authorization request message to the issuer for approval, and receive an authorization response message.
[0049] The hashing module 204C may include code executable by the processor 202 to create a hash of one or more data inputs. The hashing module 204C may include a hash function such as SHA-1, SHA-2, SHA-256, etc.
[0050] The personal token 204D may be a data segment created by a user of the portable communication device and input into the temporary memory of the access device 200. The temporary memory may have code or logic for causing the memory element 204 to delete the personal token and any other received personal tokens after a predetermined amount of time (e.g., every hour, every two hours, every day, etc.). Examples of personal tokens may include passwords, personal identification numbers (PINs), biometric samples, and templates, etc.
[0051] In some embodiments, the computer-readable medium in the memory element 204 may include code executable by a processor in the access device to perform a method. The method may include: receiving, by the access device, a personal token from a user;; receiving, by the access device, a first random code from the portable communication device; generating, by the access device, a second random code; generating, by the access device, a first hash output of the first random code, the second random code, and the personal token; transmitting, by the access device, the second random code and the first hash output to the portable communication device near the access device, wherein the portable communication device generates a second hash output from the personal token, the first random code, and the second random code, and determines whether the first hash output and the second hash output are equal; and forming, when the first hash output and the second hash output are the same, a secure communication channel between the access device and the portable communication device.
[0052] Figure 3 A block diagram showing an exemplary portable communication device according to an embodiment of the present invention.
[0053] The portable communication device 300 may include a processor 302 (e.g., a microprocessor) for processing the functions of the portable communication device 300. One example function enabled by the processor 302 includes the processing function of the display 314 to allow a user to see information (e.g., an interface, contact information, messages, etc.).
[0054] The portable communication device 300 may include a security element 310. The security element 310 may be a secure memory on the portable communication device 300 such that the data contained on the security element 310 cannot be easily attacked, cracked, or obtained by unauthorized entities. The security element 310 may be used by the portable communication device 300 to host and store data and applications that may require a high level of security. The security element 310 may be embedded in the handset of the portable communication device 300 or in a subscriber identity module (SIM) card that can be detached from the portable communication device 300. The security element 310 may also be included in an additional device such as a micro secure digital (micro-SD) card or other portable storage device.
[0055] The security element 310 may store any suitable sensitive information. For example, the security element 310 may store access data associated with the user (e.g., account information, token information, etc.). For example, the security element 310 may store an access identifier 310A, such as an access code, account number, payment token, etc. Other information that may be stored in the security element 310 may include user information or user data (e.g., name, date of birth, contact information, etc.).
[0056] The portable communication device 300 may include a memory element 304 that includes a computer-readable medium. The computer-readable medium is coupled to a processor 302 and may include code executable by the processor 302 to implement a method. The method may include: generating, by the portable communication device, a first random code, the portable communication device including a data processor and a memory storing a personal token, the portable communication device being used by a user; transmitting, by the portable communication device, the first random code to an access device, wherein the access device receives the first random code, generates a second random code, receives a personal token from the user of the portable communication device, and hashes the first random code, the second random code, and the personal token to form a first hash output; receiving, from the access device, the first hash output and the second random code; hashing the first random code, the stored personal token, and the second random code to form a second hash output; determining, by the portable communication device, whether the first hash output and the second hash output are equal; and forming, when the first hash output and the second hash output are equal, a secure communication channel between the portable communication device and the access device.
[0057] The memory element 304 may be present within the body of the portable communication device 300 or may be detachable from the body of the portable communication device 300. The body of the portable communication device 300 may be in the form of a plastic substrate, housing, or other structure. The memory element 304 may store data (e.g., applications, etc.) and may be in any suitable form (e.g., magnetic strip, memory chip, etc.).
[0058] The memory element 304 may include a random code generator 304A, a hashing module 304B, an access application 304C such as a mobile payment application, and a personal token 304D. The personal token 304D may be the same as the personal token 204D of the access device 200 input into Figure 2 . The hashing module 304B and the personal token 304D may be similar to Figure 2 the hashing module 204C and the personal token 204D in , and their descriptions need not be repeated here.
[0059] The access application 304C may be computer code or data stored on a computer-readable medium (e.g., the memory element 304), and the computer code or data may be executed by the processor 302 to complete tasks (e.g., providing services). The access application 304C may be an application that operates on the portable communication device 300 and may provide a user interface for user interaction (e.g., to input and view information). Examples of access applications may include payment applications, digital wallet applications, transportation applications, secure location access applications (e.g., hotel room applications), etc.
[0060] The portable communication device 300 may further include a non-contact element 308, which may generally be implemented in the form of a semiconductor chip (or other electronic data storage element) of an associated wireless transfer (e.g., data transmission) element such as a short-range antenna. The non-contact element 308 may be associated with the portable communication device 300 (e.g., embedded within the portable communication device). Data or control instructions transmitted to another entity (e.g., a device) may be applied to the non-contact element 308 via a non-contact element interface (not shown).
[0061] The non-contact element 308 may be capable of transmitting and receiving data. The portable communication device 300 may use an ISO 14443-based EMV contactless communication protocol (EMV-CCP) to support contactless transactions in order to interact with an access device (e.g., a reader device). This capability may be met by using Bluetooth ® , BLE (Bluetooth Low Energy), or other data transfer capabilities that may be used to exchange data between the portable communication device 300 and an interrogation device in the access device.
[0062] The portable communication device 300 may further include an antenna 316 for wireless data transfer (e.g., data transmission). The antenna 316 may be used by the portable communication device 300 to send and receive wireless communications via a telecommunications network. The antenna 316 may facilitate connection to the Internet or other communication networks and enable data transfer functions. The antenna 316 may enable SMS, USSD, and other types of cellular communications, such as voice calls and data communications.
[0063] The portable communication device 300 may include a display 314 that can display information to the user. The display 314 may be any suitable screen and may enable touch functionality. In some embodiments, the display 314 of the portable communication device 300 may display a user interface (e.g., of a mobile application or website) that may allow the user to select and interact with objects presented on the display 314. Objects may include, but are not limited to, menus, text boxes, icons, and keys / inputs on a virtual keyboard.
[0064] The portable communication device 300 may include a speaker 312, which may be any suitable device that can produce sound in response to an electrical audio signal. The speaker 312 may play recorded sounds and pre-recorded messages to communicate with the user. In some cases, the user may be able to receive instructions via voice communications played by the speaker 312, to which the user may respond (e.g., by returning a voice command, activating an input element, etc.).
[0065] The portable communication device 300 may further include input elements 306 to allow the user to input information into the device. Example input elements 306 include hardware and software buttons, audio detection devices (e.g., microphones), biometric readers, touchscreens, etc. The user may activate one or more of the input elements 306, which may transfer user information to the portable communication device 300. In some cases, one or more of the input elements 306 may be used to navigate between various screens of the access application 304C.
[0066] In some embodiments where the portable communication device 300 is a phone or other similar computing device, the portable communication device 300 may include a browser stored in the memory element 304 and may be configured to retrieve, present, and send data over a communication network (e.g., the Internet). In such embodiments, the portable communication device 300 may be configured to send data as part of an access request. In some embodiments, the portable communication device 300 may provide data in response to a request from another entity (e.g., an access device).
[0067] Figure 4An exemplary flowchart illustrating a method according to an embodiment of the present invention is shown. Figure 4 A plurality of portable communication devices 460, 470, 480 are shown in the vicinity, just like the access device 490. The portable communication devices 460, 470, 480 can communicate with the access device 490 via a short-range communication protocol such as Bluetooth, Bluetooth Low Energy (BLE), Wi-Fi, etc.
[0068] The method can be described with respect to a user who operates the portable communication device 460 and wishes to interact with the access device 490. The users of the other portable communication devices 470, 480 have not expressed an intention to interact with the access device 490. The access device 490 is capable of communicating with each of the portable communication devices 460, 470, 480. Therefore, the access device 490 needs to specifically pair with the portable communication device 460 and form a secure communication channel.
[0069] Before entering the location or otherwise interacting with the access device 490, the user inputs a personal token into the portable communication device 460 and the personal token can be stored in the portable communication device 460. Such a personal token can be any suitable information selected by the user. For example, the personal token can be a 2- to 4-digit number (e.g., birth month and date, the last 4 digits of a phone number, etc.), a pattern (e.g., similar to the Android™ unlock pattern), an emoji / icon, biometrics, etc. For illustrative purposes, the personal token associated with the portable communication device 460 can be the last four digits of the user's phone number, such as "5549".
[0070] At a certain point in time, the user can carry the portable communication device 460 to the location. The portable communication device may be in the user's pocket, bag (e.g., wallet), etc. If the portable communication device is a smart wearable device, it can be worn by the user. For example, the user can enter a store and can express an intention to pay for an item purchased by interacting with the access device 490, which can be a POS (point of sale) terminal.
[0071] In steps S402A, S402B, and S402C, each of the portable communication devices 460, 470, 480 can store a unique personal token and can generate a first random code using a random code generator module. This random code (e.g., a random number) can be temporarily stored in a memory device in the portable communication device 460. For example, in step S404A, the portable communication device 460 can generate a first random number RN1 and broadcast RN1. RN1 is refreshed at periodic intervals (e.g., 60 seconds) to enhance security, thereby preventing replay attacks. For example, a new random number can be generated every 5 minutes, 10 minutes, 60 minutes, or longer. In step S404B, the portable communication device 470 can similarly generate and broadcast a second random number RN2. In step S404C, the portable communication device 480 can similarly generate and broadcast a third random number RN3. The access device 490 can scan for neighboring portable communication devices and can receive the first random number RN1, the second random number RN2, and the third random number RN3. The access device 490 can also receive a device identifier or address for each of the portable communication devices 460, 470, 480.
[0072] In step S406, the access device 490 receives the first digital RN1 from the portable communication device 460 and generates a fourth random number RN4 using its random number generation module. Then, the user of the portable communication device 460 can interact with the access device 490 by entering the personal token (e.g., "5549") into the access device 490. The access device 490 then uses its hashing module to hash the first random number RN1, the fourth random number RN4, and the personal token "5549" to form a first hash output H1 for the portable communication device 460 (H1 = F(RN1, 5549, RN4), where F() is a hash function. The access device 490 also generates another hash output H2 for the portable communication device 470 by hashing the second random number, the fourth random number, and the personal token (H2 = (RN2, 5549, RN4)). The access device also generates another hash output H3 for the portable communication device 480 by hashing the third random number, the fourth random number, and the personal token (H3 = (RN3, 5549, RN4)).
[0073] For illustrative purposes, the personal tokens associated with and stored in the portable communication device 470 and the portable communication device 480 can be 9444 and 0000, respectively. Since the users of the portable communication devices 470, 480 did not express an intention to interact with the access device 490, these numbers were not entered into the access device 490.
[0074] In some embodiments, the inputs to the hash function can be combined prior to hashing, or padding values can be included in or between the inputs prior to hashing. For example, input values such as RN1, RN4, and "5549" can be concatenated together and then hashed to form a first hash output H1.
[0075] In step 408A, access device 490 transmits the first hash output H1 and the fourth random number RN4 to portable communication device 460. In steps S408B and S408C, access device 490 also transmits the hash outputs H2 and H3 and the fourth random number RN4 to portable communication devices 470 and 480, respectively.
[0076] In step 410A, portable communication device 460 hashes the previously generated first random number RN1, the stored personal token "5549", and the fourth random number RN4 received from access device 490 to form a second hash output H4 (i.e., H4 = F(RN1, 5549, RN4) where F() is the hash function). Then, portable communication device 460 determines whether the first hash output H1 received from access device 490 and the second hash output H4 are equal.
[0077] If the first hash output H1 and the second hash output H4 are equal, then in step S412, a secure communication channel is formed between portable communication device 460 and access device 490. The secure communication channel can be formed in any suitable manner. A session key and other known security protocols such as the Diffie-Hellman protocol can be established between portable communication device 460 and access device 490 so that data between the two devices is encrypted and secure. Such secure communication channels are used in Bluetooth and BLE type wireless connections. If the first hash output H1 and the second hash output H4 are not equal, then no secure communication is established because the stored personal identifier and the personal identifier received at access device 490 do not match.
[0078] It should be noted that portable communication device 470 will compute a different hash output from the hash output H2 received from access device 490 (which is F(RN2, 5549, RN4)) (e.g., H5 = F(RN2, 9444, RN4)), so access device 490 will not form a secure communication channel with portable communication device 470. Similarly, portable communication device 480 will compute a different hash output from the hash output H3 received from access device 490 (which is F(RN3, 5549, RN4)) (e.g., H6 = F(RN3, 0000, RN4)), so access device 490 will not form a secure communication channel with portable communication device 480.
[0079] Embodiments of the present invention have several advantages. For example, a user's personal token is not passed between the portable communication device and the access device to which it will connect. Thus, the security of the personal token remains intact. Additionally, the random code used is dynamic and protects user privacy as there is no need to broadcast device identifiers between the portable communication device and the access device to which it will connect. Further still, the portable communication device decides whether to connect to the access device by checking the hashed result, thereby providing higher security. Moreover, no user interaction is required, so pairing is a hands-free experience. Additionally, a personal code can be selected for the user in embodiments of the present invention, and embodiments of the present invention are user-friendly.
[0080] The connection protocol described above can be used in a number of different systems, including payment transaction processing systems and secure location access systems (e.g., a hotel with room security doors). Examples of such systems are shown in Figure 5 and 6 .
[0081] Figure 5 A block diagram of a transaction processing system that can use a portable communication device having access data (e.g., an access token) is shown. Figure 5 A user 506 who can operate a portable communication device 510 is shown. The user 506 can use the portable communication device 510 to pay for goods or services from a merchant. The merchant can operate a resource provider computer 530 and / or an access device 520. The merchant can communicate with an authorization computer 560 (e.g., an issuer computer) via a transmission computer 540 (e.g., an acquirer computer) and a processing computer 550 (e.g., a computer in a payment processing network).
[0082] The payment processing network can include data processing subsystems, networks, and operations for supporting and delivering authorization services, exception file services, and clearing and settlement services. An exemplary payment processing network can include VisaNet™. Payment processing networks such as VisaNet™ are capable of processing credit card transactions, debit card transactions, and other types of commercial transactions. VisaNet™ specifically includes the VIP system (Visa Integrated Payment system) that processes authorization requests, and the Base II system that performs clearing and settlement services. The payment processing network can use any suitable wired or wireless network, including the Internet.
[0083] The following may describe a typical payment transaction flow using the portable communication device 510 at the access device 520 (e.g., a POS terminal). As described above, after a secure communication channel is formed between the access device and the portable communication device 510, the user 506 presents their portable communication device 510 to the access device 520 to pay for goods or services. The portable communication device 510 and the access device 520 interact such that one or more access data (e.g., PAN, payment token, authentication value, expiration date, etc.) from the portable communication device 510 are received by the access device 520 (e.g., via a contact or non-contact interface). The resource provider computer 530 may then generate an authorization request message that includes the information received from the access device 520 (i.e., the information corresponding to the portable communication device 510) and additional transaction information (e.g., transaction amount, merchant-specific information, etc.), and electronically transmit this information to the transmission computer 540 (e.g., an acquirer computer). The transmission computer 540 may then receive, process, and forward the authorization request message to the authorization computer 560 via the processing computer 550 (e.g., an issuer computer) for authorization. The authorization computer 560 may respond with an authorization response message. The authorization response message may be transmitted from the authorization computer 560 to the access device 520 via the resource provider computer 530, the transmission computer 540, and the processing computer 550.
[0084] A clearing and settlement process may be performed later between the transmission computer 450, the processing computer 550, and the authorization computer 560.
[0085] Figure 6 A block diagram of a secure location access system is shown. Figure 6 A portable communication device 610 operated by the user 606 is shown. As described above, the portable communication device 610 already has access data. As described above, after a secure communication channel is formed between the portable communication device 610 and the access device 620, the portable communication device 610 may interact with the access device 620 and pass or transmit the access data to the access device 620. The access device 620 may locally verify the received access data, or it may communicate with a remotely located authentication server computer (not shown). The remotely located authentication server computer may verify that the access data is trustworthy and may transmit a signal indicating this back to the access device 620. The access device 620 may then continue to allow the user 606 to enter the secure location 630.
[0086] A computer system can be used to implement any of the entities or components described above. The subsystems of the computer system can be interconnected via a system bus. Additional subsystems can include a printer, a keyboard, a fixed disk (or other memory including computer-readable media), a monitor coupled to a display adapter, and other devices. Peripheral devices and I / O devices coupled to an input / output (I / O) controller (which can be a processor or other suitable controller) can be connected to the computer system by any number of means known in the art (e.g., via a serial port). For example, a serial port or an external interface can be used to connect a computer device to a wide area network such as the Internet, a mouse input device, or a scanner. The interconnection via the system bus allows the central processor to communicate with each subsystem and control the execution of instructions from the system memory or the fixed disk and the exchange of information between subsystems. The system memory and / or the fixed disk can embody computer-readable media. In some embodiments, the monitor can be a touch-sensitive display screen.
[0087] Specific details regarding some aspects described above are provided above. Without departing from the spirit and scope of the embodiments of the present technology, the specific details of the specific aspects can be combined in any suitable manner. For example, in some embodiments of the present technology, back-end processing, data analysis, data collection, and other access requests can be combined in their entirety. However, other embodiments of the present technology can relate to specific embodiments associated with each individual aspect, or specific combinations of these individual aspects.
[0088] It should be understood that the present technology described above can be implemented in the form of control logic using computer software (stored on a tangible physical medium) in a modular or integrated manner. Although the present invention has been described using a specific combination of hardware and software in the form of control logic and programming code and instructions, it should be recognized that other combinations of hardware and software are also within the scope of the present invention. Based on the disclosures and teachings provided herein, those of ordinary skill in the art will know and understand other ways and / or methods of implementing the present technology using hardware and combinations of hardware and software.
[0089] Any software component or function described in this application can be implemented as software code executed by a processor using, for example, conventional or object-oriented techniques and using any suitable computer language (e.g., Java, C++, or Perl). The software code can be stored as a series of instructions or commands on a computer-readable medium such as random access memory (RAM), read-only memory (ROM), a magnetic medium such as a hard disk drive or a floppy disk, or an optical medium such as a CD-ROM. Any such computer-readable medium can reside on a single computing device or within a single computing device, and can be present on or within different computing devices in a system or network.
[0090] The above description is illustrative and not restrictive. Many variations of the technology will become apparent to those skilled in the art after reviewing this disclosure. Accordingly, the scope of the technology should not be determined with reference to the above description, but instead should be determined with reference to the pending claims and their full scope or equivalents.
[0091] In some embodiments, any entity described herein may be embodied by a computer performing any or all of the disclosed functions and steps.
[0092] Without departing from the scope of the technology, one or more features from any embodiment may be combined with one or more features of any other embodiment.
[0093] The recitation of "a," "an," or "the" is intended to mean "one or more" unless expressly indicated to the contrary.
[0094] All patents, patent applications, publications, and descriptions mentioned above are incorporated by reference in their entirety for all purposes. It is not admitted that they are prior art.
Claims
1. A method for connecting a security device, the method comprising: generating, by a portable communication device, a first random code, the portable communication device including a data processor and a memory storing a personal token, the portable communication device being used by a user in a payment transaction; transmitting, by the portable communication device, the first random code to an access device near the portable communication device, wherein the access device is a POS terminal and receives the first random code, generates a second random code, receives the personal token from the user of the portable communication device by the user inputting the personal token into the access device, and hashes the first random code, the second random code, and the personal token to form a first hash output; receiving, from the access device, the first hash output and the second random code; hashing the first random code, the stored personal token, and the second random code to form a second hash output; determining, by the portable communication device, whether the first hash output and the second hash output are equal; and when the first hash output and the second hash output are equal, forming a secure communication channel between the portable communication device and the access device.
2. The method according to claim 1, wherein the access device includes an input element, a data processor, and a memory, wherein the user inputs the personal token into the access device via the input element, and the memory is configured to store the personal token and then delete the personal token.
3. The method according to claim 1, wherein if the first hash output and the second hash output are not equal, the secure communication channel is not formed between the access device and the portable communication device.
4. The method according to claim 1, wherein the secure communication channel utilizes Bluetooth.
5. The method according to claim 1, wherein the portable communication device is a mobile phone.
6. The method according to claim 1, wherein the method further comprises, after forming the secure communication channel: transmitting access data from the portable communication device to the access device.
7. The method according to claim 6, wherein the access data includes an access token.
8. A portable communication device, comprising: a processor; and a computer-readable medium coupled to the processor, the computer-readable medium including code executable by the processor to implement a method, the method comprising: generating, by a portable communication device, a first random code, the portable communication device including a data processor and a memory storing a personal token, the portable communication device being used by a user in a payment transaction, The portable communication device transmits the first random code to an access device near the portable communication device, where the access device is a POS terminal and receives the first random code, generates a second random code, receives the personal token from the user of the portable communication device by the user inputting the personal token into the access device, and hashes the first random code, the second random code, and the personal token to form a first hash output. Receive the first hash output and the second random code from the access device. Hash the first random code, the stored personal token, and the second random code to form a second hash output. The portable communication device determines whether the first hash output and the second hash output are equal, and When the first hash output and the second hash output are equal, a secure communication channel is formed between the portable communication device and the access device.
9. The portable communication device according to claim 8, wherein the secure communication channel is a secure wireless communication channel.
10. The portable communication device according to claim 9, wherein the secure wireless communication channel utilizes Bluetooth.
11. The portable communication device according to claim 8, wherein the portable communication device is a mobile phone.
12. The portable communication device according to claim 8, wherein the method further comprises, after forming the secure communication channel: Transmit access data from the portable communication device to the access device.
13. The portable communication device according to claim 12, wherein the access data is an access token.
14. A method for secure device connection, the method comprising: The access device receives the personal token from the user by the user inputting the personal token of the user into the access device during a payment transaction, where the access device is a POS terminal; The access device receives a first random code from a portable communication device; The access device generates a second random code; The access device generates a first hash output of the first random code, the second random code, and the personal token; The access device transmits the second random code and the first hash output to the portable communication device near the access device, where the portable communication device generates a second hash output by hashing the personal token, the first random code, and the second random code, and determines whether the first hash output and the second hash output are equal; And When the first hash output and the second hash output are the same, a secure communication channel is formed between the access device and the portable communication device.
15. The method according to claim 14, wherein the portable communication device is a mobile phone.
16. The method according to claim 14, wherein the method further comprises, after forming the secure communication channel: Receive access data from the portable communication device; Generate an authorization request message including the access data; and Transmit the authorization request message to an authorization computer.
17. The method according to claim 14, wherein the access device permits or does not permit access to a secure location.
18. The method according to claim 14, further comprising: Transmitting, by the access device, at least the second random code to a plurality of additional portable communication devices that do not store the personal token and do not form a secure communication channel with the access device.
19. An access device, comprising: A data processor; And A computer-readable medium comprising code executable by the processor to perform the method according to any one of claims 14 to 18.
20. A system comprising the access device according to claim 19 and the portable communication device.
Citation Information
Patent Citations
System, method and computer program product for authenticating a data agreement between network entities
CN101273572A