System and method for protecting personal identification number entry privacy on consumer mobile devices and computing devices
By separating the PIN layout and PIN token design in a three-device system, the issues of PIN input security and cost are solved, enabling secure PIN input on ordinary consumer mobile devices while reducing device complexity and terminal costs.
Patent Information
- Application Number
- CN202210957696.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2017-01-12
- Filing Date
- 2017-12-27
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2037-12-27
AI Technical Summary
In existing technologies, PIN layouts and PIN tokens often appear on the same device, making it difficult to guarantee the security of PIN input. Especially on ordinary consumer mobile devices, the cost of traditional payment terminals is still too high for small merchants.
A three-device system is used, where the first device displays a random PIN layout, the second device inputs a PIN token, and the third device combines the PIN layout and PIN token to generate a verification PIN without sharing any information, ensuring that the PIN layout and PIN token are separate and avoid appearing on the same device.
By separating the PIN layout and PIN token design, the security of PIN input is improved, the complexity of device design is reduced, and the cost of traditional payment terminals is decreased, making it suitable for ordinary consumer mobile devices.
Smart Images

Figure CN115311779B_ABST
Abstract
Description
[0001] This application is a divisional application of Chinese Patent Application No. 2017800831878, filed on December 27, 2017, and entitled "SYSTEM AND METHOD FOR PROTECTING PIN ENTRY PRIVACY ON CONSUMER MOBILE DEVICES AND COMPUTING DEVICES". TECHNICAL FIELD
[0002] The present invention relates to a system and method for secure PIN entry on a device with insufficient security level, such as a mobile computing device. BACKGROUND
[0003] Electronic payments, money transfers and banking can be conducted in various ways. Typically, a transaction requires the use of a payment card, bank card or a virtual card on a mobile device. The user, card holder or account holder typically interfaces the payment card with a payment terminal or an ATM machine. The most common form of security is a PIN (personal identification number). The PIN is a short, numeric or alpha-numeric string and is entered by the user as a security measure to verify his identity. This entry is typically entered on a mechanical or touch screen keypad or keyboard on the payment terminal. The payment card is interfaced with the card reader of the payment terminal using a magnetic stripe, direct electrical contacts and by using short range wireless protocols such as RFID and NFC.
[0004] A typical payment terminal includes an interface for PIN entry, one or more card reader interfaces for interfacing with a card, a communication interface for communicating with a financial institution that processes the transaction, a payment application that processes the transaction flow and handles the human interaction with the transaction flow, and a user interface that provides means for user interaction (e.g. a screen, a keypad or a touch panel, etc.). This high cost payment terminal prevents small merchants from accepting card payments.
[0005] Recently, smart phones and tablets have become very common and most of the functionality in a traditional payment terminal can be implemented on a smart device. The payment application can run on the smart device and the smart device provides various communication methods to connect to the transaction processing entity. In this case, the functionality of the payment terminal can be reduced to two basic functions: accepting a PIN and interfacing with a card. In most applications, the PIN is accepted on the payment terminal and not on the mobile device, as it is difficult to ensure the privacy of the PIN on a mobile device that is not designed for this purpose.
[0006] By using mobile devices, the cost of payment terminals has been reduced, especially for card transactions that do not require a PIN, a simple card reader can be used with a smart device to process card transactions. However, for transactions that require a PIN, the cost of a PIN accepting terminal is still too high for smaller merchants.
[0007] To increase the security of PIN entry using a normal consumer mobile device, a number of improvements have been proposed. Many of these improvements involve protecting the PIN and encrypting the key. One improvement proposed is to use a random keypad that changes each time the PIN is entered. Another improvement is to have two devices: a first device that displays the PIN layout and a second device that enters the PIN. The PIN layout can be fixed (which is unchanging) or random (which changes each time the user is asked to enter the PIN). The second device for entering the data can display just boxes or can display a blank screen. The user observes the first device to determine the layout of the keys and enters the PIN on the second device by pressing or touching the keys. The user input on the second device is transmitted to the first device and the first device takes the PIN. The first device can then encrypt the PIN and send to the payment network. One disadvantage of these methods is that the PIN layout and the PIN keystrokes (also known as PIN tokens) appear on the same device and a single point of attack occurs.
[0008] There is therefore a need for a PIN security solution in which the PIN layout and the PIN tokens do not appear on the same device. Furthermore, it would be advantageous if any encryption keys also do not appear on the same device as the PIN layout or the PIN tokens. SUMMARY
[0009] A first main embodiment of the invention is a system for accepting an input of a PIN, the system comprising: a first device, a second device and a third device. The first device receives a random PIN layout from a fourth device. The fourth device derives the random PIN layout and the first device displays the random PIN layout on a first display of the first device. The second device comprises an input for accepting a series of key presses to generate a PIN token indicative of each of the series of key presses. The third device is in communication with the second device. The third device derives the random PIN layout and receives the PIN token from the second device, the PIN token not being present on the first device. The third device combines the PIN layout and the PIN token to generate a PIN for authenticating a transaction.
[0010] In some embodiments of the invention, the fourth device is in communication with the third device, each of the fourth device and the third device storing a shared secret. The shared secret is used to independently derive the random PIN layout on the fourth device and the third device.
[0011] In other embodiments of the invention, the third device is remote from the first device and the second device.
[0012] In further embodiments, the first device and the second device comprise a transaction verification system, and the transaction is for verifying the veracity of a point of sale terminal. In other embodiments, the transaction verification system is for accepting a payment from a customer payment device.
[0013] In some embodiments, the first device and the fourth device are the same device.
[0014] A second primary embodiment of the invention is a system for accepting an input of a PIN. The system comprises a first device, a second device, and a third device. The first device receives a random PIN layout from a fourth device. The fourth device derives the random PIN layout. The first device displays the random PIN layout on a first display of the first device. The second device comprises an input for accepting a series of key presses to generate a PIN token. The PIN token indicates each of the series of key presses. The third device is in communication with the second device and the fourth device. The third device receives the random PIN layout from the fourth device and the PIN token from the second device, the PIN token not being present on the first device. The third device combines the PIN layout and the PIN token to generate a PIN for verifying a transaction.
[0015] A third primary embodiment of the invention is a system for accepting an input of a PIN. The system comprises a first device, a second device, and a third device. The first device receives a random PIN layout from a third device, the third device deriving the random PIN layout. The first device displays the random PIN layout on a first display of the first device. The second device comprises an input for accepting a series of key presses to generate a PIN token indicating each of the series of key presses. The third device is in communication with the second device and the fourth device. The third device receives the PIN token from the second device, the PIN token not being present on the first device. The third device combines the PIN layout and the PIN token to generate a PIN for verifying a transaction.
[0016] A fourth principal embodiment of the invention is a method for verifying a purchase on a point of sale terminal. The method includes displaying a random PIN layout on a first device. The first device receives the random PIN layout from a fourth device. The fourth device derives the random PIN layout. The first device displays the random PIN layout on a first display of the first device. A PIN token is entered on a second device. The second device includes an input for accepting a series of key presses to generate the PIN token. The PIN token indicates each of the series of key presses. A third device receives the PIN token from the second device. The PIN token is not present on the first device. The third device derives the random PIN layout and combines the PIN layout and the PIN token to generate a PIN. The PIN is used to verify a transaction. The transaction can be used to verify authenticity of a point of sale terminal. The transaction can be used to verify a payment to complete a purchase.
[0017] The above and additional aspects and embodiments of the present invention will be apparent to those of ordinary skill in the art in view of the detailed description of various embodiments and / or aspects, which is provided in connection with the accompanying drawings. BRIEF DESCRIPTION OF DRAWINGS
[0018] The above and other advantages of the invention will become apparent to those of ordinary skill in the art by reading the following detailed description, taken in conjunction with the accompanying drawings.
[0019] Figure 1 A random PIN layout display on a first device and another keypad on a second device without display of numbers is shown.
[0020] Figure 2 A sequence of positions pressed on a second device grid to enter a PIN sequence "1243" using a random PIN keypad in a first device is shown.
[0021] Figure 3 Input of a PIN in a system with first, second, and third devices, where the first and third devices have a shared secret, is shown.
[0022] Figure 4 Input of a PIN in a system with first, second, third, and fourth devices, where the third and fourth devices have a shared secret, is shown.
[0023] Figure 5 Input of a PIN in a system with first, second, third, and fourth devices, where the fourth device generates a PIN pad layout for the first and third devices, is shown.
[0024] Figure 6 Input of a PIN in a system having first, second, and third devices is shown, where the third device generates a PIN keyboard layout for the first device.
[0025] Figure 7 Input of a PIN in a system having first, second, and third devices is shown, where the first device generates a PIN keyboard layout for the third device.
[0026] Figure 8 A process of system initialization is shown.
[0027] Figure 9 A process of the system for processing a payment transaction is shown.
[0028] While the application is susceptible to various modifications and alternative forms, specific embodiments or implementations have been shown by way of example in the drawings and will be described in detail herein. It should be understood however that the application is not limited to the particular forms disclosed. Rather, the disclosure covers all modifications, equivalents, and alternatives falling within the spirit and scope of the application as defined by the appended claims. DETAILED DESCRIPTION
[0029] In exemplary embodiments of the application, systems and methods are included that display a random PIN layout on a first device and accept input (PIN token) from a cardholder or account holder on a second device in a manner that the PIN layout and PIN token do not exist on the same device. Embodiments of the application can be used to verify a merchant's card reader device by a financial service provider, or to approve a financial transaction by a customer.
[0030] Figure 1 A separate PIN layout and PIN token are shown. A first device 100 includes a display 101 that displays a PIN layout 102. The first device can be a dedicated device for displaying a PIN layout, or a card reader that can display a PIN layout, or any device (including a mobile device) that has the appropriate means (e.g. a special application) to display a PIN layout. The first device can belong to a merchant or an account holder. A second device 200 can be a smart phone or mobile device that belongs to a merchant or an account holder.
[0031] In some embodiments of the application, the first device 100 and the second device 200 can be coupled together by a wired or wireless connection and communicate with each other over the connection, thereby synchronizing the state between the devices. For example, if each key press can change the PIN keypad layout, the first and second devices must be synchronized to ensure that the PIN keypad is fixed for each input. In other embodiments of the application, the first and second devices do not need to communicate directly with each other. The first device 100 displays a PIN layout 101 on the screen as a conventional numeric input keypad. The arrangement 102 of the digits 0 through 9 can be fixed, but preferably is generated randomly for each transaction or after each key press. The first device 100 can also have multiple predefined layouts, selecting one for each transaction. The first device can also generate a pseudo-random layout based on a secret value, or receive the layout from another device in the system. The second device 200 displays a grid 201 of blank keys 202, and can also display other non-numeric characters, thereby controlling the PIN input, such as OK and cancel buttons 203. In use, the user observes the PIN layout 102 of the first device, which enables the user to know which squares 202 to press on the second device to enter their PIN. The first device 100 displays the PIN layout, and the second device 200 accepts the PIN token. As is conventional, when the PIN input is complete, the user can press the OK button, or the cancel button to abort the PIN input. In embodiments of the application, the PIN layout and the PIN token are never present on the same device. This separation adds another layer of security to the PIN input process, and helps to reduce the complexity of the design of the application on both the mobile second device 200 and the peripheral first device 100.
[0032] Figure 2 A step-by-step process of entering a PIN token on the second device 200 based on the PIN layout displayed on the first device 100 is shown. In this example, the PIN 1234 is entered. In this example, the PIN layout 102 does not shuffle the positions after each key press. However, in other examples, the PIN layout 102 randomizes the positions of the displayed digits after each key press. It can be seen that the PIN token entry on the second device 200 indicates which key or virtual key was pressed for each position in the PIN. The PIN layout displayed on the first device 100 indicates the value of each position, key or virtual key at that point in time. By combining the PIN layout and the PIN token, the PIN can be determined.
[0033] Figure 3A first embodiment of the invention for securely receiving PIN entry is shown. The system comprises a first device 100 for generating and displaying a PIN layout, a second device 200 for obtaining a PIN token 302 from a user, and a third device 300 for receiving the PIN token and reconstructing the PIN 303 required to validate a transaction.
[0034] The first device 100 can be associated with a merchant, a bank or financial institution, or a card holder, and can be a card reader, a cash register, a self-checkout kiosk, or a mobile device such as a smartphone, or a dedicated device for this purpose. If the first device is a smartphone device, it will run a payment application that can be provided by the smartphone manufacturer, a financial institution, a financial card company, or other third party. The first device can also have dedicated hardware or software to support encryption and decryption of sensitive data such as the PIN layout map 101. The first device can also have a dongle or card reader interface that allows it to read secure or non-secure data from a card. The first device generates a PIN layout, which can be random or can include a limited number of layouts from which the first device selects. Typically a new PIN layout 101 is generated for each new transaction. The first device has a display on which to display the PIN layout for a transaction. The first device can include a wired or wireless communication interface to communicate with the second device or the third device 300. The first device stores a shared secret 301 that is also stored by the third device. It uses this shared secret as a seed to generate the PIN layout 101. The shared secret need not be shared during a transaction. The shared secret can be defined during initial setup of the device, or exchanged periodically. The shared secret can be manually entered, or loaded or hard-coded into the device during manufacture.
[0035] The second device 200 can also be associated with a merchant, bank, or financial institution involved in a financial transaction. It is typically a mobile or handheld electronic device (e.g., a smartphone or tablet) with an LCD display that accepts touch input, or a point of sale (POS) terminal, or a computer system with a display and hardware to accept PIN input. The second device runs a payment application that can be provided by the smartphone manufacturer, the financial institution, the financial card company, or other third party. The second device can also have specialized hardware or software to support encryption and decryption of sensitive data, such as the PIN token 302. The second device can also have a dongle that allows it to read data from the card. The second device displays a keypad 201 on which the user can enter their PIN code. The keypad 201 can be blank, have unmarked rectangles, contain images, contain a dummy keypad, or any other display that allows the user to press buttons 202 or areas on the screen 201. The user refers to the PIN display 101 on the first device to determine where to press the keys, buttons, or screen 201 of the second device to enter their PIN. The key presses are used to generate a PIN token 302 that indicates which keys or areas of the screen 201 were pressed. The second device also includes a wired or wireless communication interface to communicate with the third device. The second device sends the PIN token to the third device 300 in either plain text or encrypted form, without going through the first device 100. Furthermore, the random PIN layout 101 does not exist in the second device 200 and is never transmitted in any form (plain or encrypted) to or through the second device. Thus, the random PIN layout 101 and the PIN token 302 exist only in two separate devices and not in the other. Compromise of either device does not compromise the privacy of the PIN.
[0036] The third device 300 is a secure device or a device in a secure location, such as a back-end server located in a secure location or off site. The third device 300 can be a dedicated device or computer server running a payment application that can be provided by the smartphone manufacturer, a financial institution, a financial card company, or other third party. The third device 300 stores the same shared secret 301 as the first device 100 and uses the shared secret 301 as a seed to generate the same PIN layout 101 as the first device. In this way, the PIN layout 101 is never transmitted between devices. The third device receives the PIN token 302 from the second device 200 and combines the PIN token 302 with the PIN layout 101, which was generated using the shared secret 301, to obtain the PIN 303. The PIN is obtained by using the PIN token, determining which key was pressed based on the location, key, or virtual key encoded in the PIN token. This is matched to the PIN layout to determine the value of the key. This process is repeated for each number or character in the PIN 303. The PIN 303 can then be encrypted. The PIN or encrypted PIN is then used to verify a transaction.
[0037] In some embodiments of the application, the first device 100 can be the cardholder's device, and the second device 200 can be the merchant's smartphone, terminal, or device. In this case, the PIN layout 101 is displayed on the cardholder's device 100, and the PIN token 302 is entered into the merchant's device 200. In other embodiments of the application, the first device 100 can be the merchant's device, and the second device 200 can be the cardholder's or account holder's device. In further embodiments of the application, the first device 100 and the second device 200 are both the cardholder's devices. In other embodiments of the application, the first device 100 and the second device 200 are both owned by the merchant. These embodiments replace the current payment system in which the PIN would exist or be stored in a terminal that combines the functionality of the first and second devices.
[0038] In embodiments of the application, the first device 100 displaying the PIN layout and the second device 200 entering the PIN must be in close proximity to each other so that the person entering the PIN can manipulate the second device while viewing the first device. There is no restriction on the location of the third device 300 and the fourth device 400. Either or both of the third and fourth devices can be located at the same location as the first and second devices, in a separate room, or at a remote location.
[0039] Figure 4A second embodiment of the application for securely receiving PIN input is shown. In this embodiment, the first device 100 has a simplified function to display a PIN layout 101 received through a communication interface from a fourth device 400. The random PIN layout 101 is generated by the fourth device 400 using a shared secret 301 that is common with the third device 300. This allows the third and fourth devices to generate or derive the same pseudo-random keyboard layout 101 without transmitting the PIN layout between them. The second device is the same as the device mentioned in the first embodiment. As before, the PIN tokens from the second device never pass through the first device in clear or encrypted form.
[0040] Figure 5 A third embodiment of the application for securely receiving PIN input is shown. This embodiment is similar to the second embodiment shown in Figure 4 However, there is no shared secret 301 associated with generating the PIN layout 101 that is shared between the third device 300 and the fourth device 400. Instead, the fourth device is responsible for generating the random PIN layout 101 and generating it independently. It then transmits the PIN layout to the third device 300 through a wired or wireless communication interface. The PIN layout can be encrypted before transmission through the fourth device. The third device receives the encrypted PIN keyboard layout from the fourth device and decrypts it. The third device also receives the PIN tokens 302 from the second device and uses them to construct the PIN 303.
[0041] Figure 6 A fourth embodiment of the application for securely receiving PIN input is shown. This embodiment is a variation of the first embodiment shown in Figure 3 In this embodiment, the first device 100 and the third device 300 do not share a secret. Instead, the third device is responsible for generating the random PIN layout 101 and generating it independently. The third device then transmits the PIN layout to the first device 100 through a wired or wireless communication interface. The PIN layout can be encrypted before transmission through the third device 300. The first device receives the encrypted PIN keyboard layout 101 from the third device and decrypts it.
[0042] Figure 7 A fifth embodiment of the application for securely receiving PIN input is shown. This embodiment is a variation of the first embodiment shown in Figure 3Another variation of the first embodiment is shown. In this embodiment, the first device 100 and the third device 300 do not share a secret. Instead, the first device is responsible for generating a random PIN layout 101 and generating it independently. It then transmits the PIN layout to the third device 100 through a wired or wireless communication interface. The PIN layout can be encrypted before transmission through the first device 300. The third device receives the encrypted PIN keyboard layout 101 from the first device and decrypts it.
[0043] There are many possible variations that are not exhaustively listed for embodiments of the present invention. However, in embodiments of the present invention, the PIN layout 101 is not displayed on the device that enters the PIN token 302. Furthermore, the PIN layout 101 and the PIN token 302 are never present on the first device 100 or the second device 200 at the same time, which is typically the device used at the location where the transaction is taking place. Both the PIN layout 101 and the PIN token 302 are only present on the third device 300, which is a remote or secure server or device. In this way, compromising the device that displays the PIN layout or the device that displays the PIN token alone, an intruder will not be able to determine the PIN 303 for the smart card, or the card holder or the account holder's mobile device.
[0044] Figure 8 An exemplary process for initializing a system according to embodiments of the present invention is shown. To initialize the system 700, the device must have any proprietary software installed, a user account established, a configuration completed, and will be authenticated using a payment processor, financial institution, corporate server, or any other authentication or security device. For embodiments that require a shared secret 702, whether it is a secret that will be used to derive a PIN layout or a secret that will be used to encrypt and decrypt other data, this must be configured. The merchant will then authenticate the merchant's card reader device with the payment processor, financial institution, or corporate server as necessary 703 to ensure that the device is not compromised and is being used in a non-fraudulent manner. The merchant can use embodiments of the present invention to enter a PIN on their device to generate a separate PIN layout 702 and PIN token 704 on a separate device. The PIN is generated on the third device 707 and used to enable the card reader or point of sale terminal to allow it to process financial transactions 708.
[0045] In Figure 9, when a customer selects a set of products or services and wishes to pay for them, a transaction 800 begins. The merchant will calculate the price of the products and enter the amount in a cash register or similar device 801. The customer indicates that they wish to use an electronic payment method (e.g. a bank card or mobile wallet) to make the payment. The merchant then begins to generate a PIN layout on a first device. The first device generates the PIN layout using the shared secret and displays the PIN layout on its display 802. The PIN layout is random for each transaction. The user's physical card, virtual card or wallet will then be swiped, tapped or inserted 803 and then the PIN entry process will begin on a second device. This will cause the blank keypad to be displayed on the second device along with control keys (e.g. OK, Cancel and Space keys). The user will then observe the display on the first device to know the value of the blank keys of the keypad on the second device and enter the PIN by pressing the correct blank keys on the second device 804. The second device takes the position of the keys pressed to generate a PIN token 805. Once the PIN has been entered, the second device will transmit the PIN token to a third device, optionally encrypting the PIN token before transmission. The third device is a dedicated hardware device or server at a secure or off-site location that receives the PIN token and decrypts it if necessary. The third device also generates a local copy of the PIN layout using the shared secret 806. It then combines the local PIN layout with the PIN token to generate the PIN 807. The PIN token provides the position of the keys pressed to indicate which keys were pressed. The PIN layout is used to determine the value of the PIN. The PIN is then used to validate the transaction 808.
[0046] While specific implementations and applications of the present application have been illustrated and described, it is to be understood that the application is not limited to the specific examples of electronic payment and point of sale terminal validation. Many other applications involving the secure entry of a PIN, or other entries involving position information, tokens, and layouts involving numbers, characters, symbols, pictures or other similar indicators, can benefit from the improved security provided by embodiments of the present application.
Claims
1. A plurality of devices that enable a user to enter a PIN to validate a transaction, wherein the plurality of devices includes a first device, a second device, a third device, and a fourth device, and the first device and the second device validate authenticity of a point-of-sale terminal based on the transaction; wherein the first device receives a random PIN layout from the fourth device, the fourth device derives the random PIN layout, the first device displays the random PIN layout on a first display of the first device to enable the user to enter a series of key presses on the second device; wherein the second device includes an input to accept the series of key presses from the user to generate a PIN token, the PIN token indicating each of the series of key presses; wherein the third device is in communication with the second device, the third device derives the random PIN layout and receives the PIN token from the second device, the PIN token not being present on the first device, the third device combines the PIN layout and the PIN token to generate a PIN; and wherein, prior to the PIN token being transmitted to the third device, the PIN token is encrypted by the second device. the fourth device is in communication with the third device, each of the fourth device and the third device stores a shared secret.
2. The plurality of devices of claim 1, wherein, the shared secret is used to independently derive the random PIN layout on the fourth device and the third device.
3. The plurality of devices of claim 2, wherein, the third device is remote from the first device and the second device.
4. The plurality of devices of claim 1, wherein, the first device and the second device are used to accept payment from a customer payment device.
5. The plurality of devices of claim 4, wherein, 6. The plurality of devices of claim 1, wherein: the third device is communicatively coupled to the fourth device, and the fourth device transmits the random PIN layout to the third device. the random PIN layout is encrypted prior to transmission by the fourth device.
7. The plurality of devices of claim 6, wherein, 8. The plurality of devices of claim 7, wherein: the third device receives the encrypted random PIN layout; and the third device decrypts the received encrypted random PIN layout. the PIN token is based on a position corresponding to the series of key presses.
9. The plurality of devices of claim 1, wherein, 10. A plurality of devices that enable a user to enter a PIN to validate a transaction, wherein the plurality of devices includes a first device, a second device, a third device, and a fourth device, and the first device and the second device validate authenticity of a point-of-sale terminal based on the transaction; wherein the first device receives a random PIN layout from the fourth device, the fourth device derives the random PIN layout, and the first device displays the random PIN layout on a first display of the first device to enable the user to enter a series of key presses on the second device; the second device includes an input to accept the series of key presses from the user to generate a PIN token, the PIN token indicating each of the series of key presses; the third device is in communication with the second device and the fourth device, the third device receives the random PIN layout from the fourth device and the PIN token from the second device, the PIN token is not present on the first device, the third device combines the PIN layout and the PIN token to generate a PIN; and wherein the PIN token is encrypted by the second device prior to transmission to the third device.
11. The plurality of devices of claim 10, wherein, the third device is remote from the first device and the second device.
12. The plurality of devices of claim 10, wherein, the first device and the second device are configured to accept payment from a customer payment device.
13. A plurality of devices that enable a user to enter a PIN to authenticate a transaction, wherein the plurality of devices comprises a first device, a second device and a third device, and the first device and the second device are configured to verify authenticity of a point of sale terminal based on the transaction; wherein the first device receives a random PIN layout from the third device, the third device derives the random PIN layout, and the first device displays the random PIN layout on a first display of the first device to enable the user to enter a series of key presses on the second device; wherein the second device comprises an input configured to accept the series of key presses from the user to generate a PIN token, the PIN token indicating each of the series of key presses; the third device is in communication with the second device, the third device receives the PIN token from the second device, the PIN token is not present on the first device, the third device combines the PIN layout and the PIN token to generate a PIN; and wherein the PIN token is encrypted by the second device prior to transmission to the third device.
14. The plurality of devices of claim 13, wherein, the third device is remote from the first device and the second device.
15. The plurality of devices of claim 13, wherein, the first device and the second device are configured to accept payment from a customer payment device.
16. A method for authenticating a transaction using a plurality of devices, the devices comprising a first device, a second device, a third device and a fourth device, the method comprising: displaying a random PIN layout on the first device, the first device receiving the random PIN layout from the fourth device, the fourth device deriving the random PIN layout, the first device displaying the random PIN layout on a first display of the first device to enable a user to enter a series of key presses on the second device; accepting a series of key presses at an input of the second device; generating, by the second device, a PIN token based on the accepted series of key presses, the PIN token indicating each of the series of key presses; receiving the PIN token at the third device from the second device, the PIN token not being present on the first device, the third device deriving the random PIN layout, the third device combining the PIN layout and the PIN token to generate a PIN, and the PIN being used to validate a transaction and based on the transaction validating authenticity of a point of sale terminal; and wherein the PIN token is encrypted by the second device prior to transmission to the third device.
17. The method of claim 16, wherein, the fourth device is in communication with the third device, each of the fourth device and the third device storing a shared secret.
18. The method of claim 17, wherein, the shared secret is used to independently derive the random PIN layout on the fourth device and the third device.
19. The method of claim 16, wherein, the third device is remote from the first device and the second device.
20. The method of claim 16, wherein, the first device and the second device are used to accept payment from a customer payment device.
21. The method of claim 16, further comprising: transmitting the random PIN layout by the fourth device to the third device.
22. The method of claim 16, further comprising: the random PIN layout is encrypted prior to transmission to the third device.
23. The method of claim 22, further comprising: receiving, by the third device, the encrypted random PIN layout; and decrypting, by the third device, the received encrypted random PIN layout.
24. The method of claim 16, further comprising: the PIN token is encrypted by the second device prior to transmission to the third device.
25. The method of claim 16, wherein, the PIN token is based on a location corresponding to the series of key presses.
Citation Information
Patent Citations
System and method to protect privacy of personal- identification-number entry on consumer mobile device and computing apparatus
CN110178347A