Credential extension for data transmission
By using encrypted one-time QR codes and biometric authentication between devices, combined with a sandboxed extension unit, the issues of authenticity, trustworthiness, and authorization in data transmission between devices are resolved, achieving secure and reliable data transmission and privacy protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- APPLE INC
- Filing Date
- 2022-09-23
- Publication Date
- 2026-04-21
AI Technical Summary
Existing technologies make it difficult to ensure the authenticity and reliability of data transmission and the authorization of devices or users in data transmission between devices, and information collection may raise concerns and privacy leaks in the system.
Data transmission is performed using Quick Response (QR) codes. By generating one-time-use encrypted QR codes, combined with biometric authentication and sandboxing extensions, the scope of information collection is limited, and the validity and usage time of the QR codes are verified at the service device end to prevent unauthorized data transmission.
It enables secure and reliable data transmission between devices, protects user information, prevents unauthorized access and information leakage, and improves the security and privacy protection of data transmission.
Smart Images

Figure CN115866590B_ABST
Abstract
Description
[0001] Cross-references to related applications
[0002] This application claims priority to U.S. Provisional Application 63 / 248,397, filed September 24, 2021, entitled “CREDENTIAL EXTENSION FOR DATATRANSFER,” the disclosure of which is incorporated herein by reference in its entirety for all purposes. Background Technology
[0003] For data transfers between accounts associated with a device, a concern is verifying that the data transfer is authentic and trustworthy, and / or that the device or its user is authorized to perform the data transfer. Methods used to verify data transfers include collecting information associated with the device and / or the transfer. However, collecting this information may raise concerns about entities and / or bad actors within the system who may not want them to have access to it. Furthermore, the device or its user may want to restrict the information collected. Attached Figure Description
[0004] Figure 1 A portion of an exemplary system arrangement according to some implementation schemes is shown.
[0005] Figure 2 Exemplary devices according to some implementation schemes are shown.
[0006] Figure 3 A first portion of an exemplary signal stream for configuring credentials and / or credential extensions to a device, according to some embodiments, is shown.
[0007] Figure 4 This illustrates a method for configuring credentials and / or credential extensions to a device according to some embodiments. Figure 3 The second part of the signal flow.
[0008] Figure 5 This illustrates a method for configuring credentials and / or credential extensions to a device according to some embodiments. Figure 3 The third part of the signal flow.
[0009] Figure 6 This illustrates a method for configuring credentials and / or credential extensions to a device according to some embodiments. Figure 3 The fourth part of the signal flow.
[0010] Figure 7 The first part of an exemplary signal stream for initiating data transmission based on a quick response (QR) code, according to some implementation schemes, is shown.
[0011] Figure 8This illustrates a method for initiating data transmission based on a QR code, according to some implementation schemes. Figure 7 The second part of the signal flow.
[0012] Figure 9 This illustrates a method for initiating data transmission based on a QR code, according to some implementation schemes. Figure 7 The third part of the signal flow.
[0013] Figure 10 An exemplary signal stream for displaying QR codes and fraud detection is shown according to some implementation schemes.
[0014] Figure 11 The first part of an exemplary signal stream for filling an account is shown according to some implementation schemes.
[0015] Figure 12 The following are examples of methods for filling accounts, based on some implementation schemes. Figure 11 The second part of the signal flow.
[0016] Figure 13 The first part of the signal flow for step-up authentication of data transmission is shown according to some implementation schemes.
[0017] Figure 14 An example of enhanced authentication for data transmission according to some implementation schemes is shown. Figure 13 The second part of the signal flow.
[0018] Figure 15 The first part of an exemplary process for displaying a QR code for data transmission, according to some implementation schemes, is shown.
[0019] Figure 16 This illustrates a method for displaying QR codes for data transmission according to some embodiments. Figure 15 The second part of the exemplary process.
[0020] Figure 17 The first part of another exemplary process for displaying a QR code for data transmission, according to some implementation schemes, is shown.
[0021] Figure 18 This illustrates a method for displaying QR codes for data transmission according to some embodiments. Figure 17 The second part of the exemplary process.
[0022] Figure 19 An exemplary process for displaying a QR code for data transmission, according to some implementation schemes, is shown.
[0023] Figure 20The first part of an exemplary process for performing a credentials extension on a device to collect information, according to some implementations, is shown.
[0024] Figure 21 This illustrates a method for performing a credentials extension on a device to collect information, according to some embodiments. Figure 20 The second part of the exemplary process.
[0025] Figure 22 The first part of another exemplary process for performing a credentials extension on a device to collect information, according to some implementations, is shown.
[0026] Figure 23 This illustrates a method for performing a credentials extension on a device to collect information, according to some embodiments. Figure 22 The second part of the exemplary process.
[0027] Figure 24 Another exemplary process for performing a credentials extension on a device to collect information, according to some implementation schemes, is shown.
[0028] Figure 25 Exemplary user equipment (UE) according to some implementation schemes is shown. Detailed Implementation
[0029] The following detailed description relates to the accompanying drawings. The same reference numerals may be used in different drawings to identify the same or similar elements. In the following description, specific details, such as particular structures, architectures, interfaces, technologies, etc., are set forth for illustrative and not limiting purposes to provide a thorough understanding of various aspects of the embodiments. However, it will be apparent to those skilled in the art, who benefit from this disclosure, that various aspects of the embodiments may be practiced in other examples departing from these specific details. In some cases, descriptions of well-known devices, circuits, and methods have been omitted so as not to obscure the description of the various embodiments with unnecessary detail.
[0030] The implementations described herein may include using Quick Response (QR) codes to perform data transfers and / or process between and / or by the devices. For example, a QR configuration device may generate a one-time-use QR code to be used for data transfer between accounts associated with a first device and a second device. The QR configuration device may provide the one-time-use QR code to the first device, which may store the QR code for future use.
[0031] To initiate data transmission, the user of the first device can select credentials associated with a QR code, which requests that one of the QR codes be displayed on the device's display. The first device can retrieve one of the QR codes from its memory and display that QR code on the first device's display in response to the selection of credentials.
[0032] The user of the second device can use the capture element of the second device to scan the QR code displayed on the first device. The first and second devices can communicate with one or more servers and / or other devices that maintain accounts associated with the devices. Based on the second device scanning the QR code displayed on the first device, the server and / or other device can determine whether the device is authorized to perform data transfer. If the server and / or other device determines that the first and second devices are authorized to perform data transfer, then the server and / or other device can perform data transfer between the accounts associated with the first and second devices, which may result in changes to values within the accounts.
[0033] The embodiments described herein may include a first device having a user information application for managing credentials on the device. An extension unit may operate within this user information application. The extension unit may communicate with a service device, wherein the service device may transmit information to be collected by the extension unit to determine authorization for data transmission between the first device and a second device. The extension unit may also encrypt the collected information before it is transmitted from the device to prevent malicious individuals and / or entities within the system from accessing the information.
[0034] The implementation described herein can also provide protection for QR codes to prevent malicious actors from using them to perform unauthorized data transfers. For example, each QR code can be individually encrypted, allowing the first device to decrypt a single QR code at a time for use. QR codes can also be one-time use QR codes, where the device is restricted to displaying each QR code only once. QR codes may also become outdated if they remain on the device for too long, or may become invalid if an attempt to use the QR code exceeds a threshold amount of time since it was first displayed on the first device. When a QR code is used and / or invalidated, the first device can retrieve an additional QR code from the serving device to be used to initiate a new QR code.
[0035] Figure 1 A portion of an exemplary system arrangement 100 according to some embodiments is shown. For example, system arrangement 100 may illustrate a portion of a system in which data transmission can be performed using QR codes. It should be understood that system arrangement 100 may illustrate a portion of a system in which the system may include one or more elements described throughout this disclosure.
[0036] An exemplary system arrangement 100 may include device 102. Device 102 may include UE 2500 ( Figure 25The device 102 may execute a user information application. This user information application may manage one or more credentials associated with a user of the device 102. Each credential may be associated with an account related to the user of the device 102, where the account may store the user's data. The user of the device 102 may be able to select from the credentials stored on the device 102 to perform data transfer associated with the selected credential.
[0037] One or more credentials stored on device 102 can be used to initiate data transmission using QR codes. For example, device 102 may have one or more encrypted QR codes associated with one or more credentials stored on device 102. Device 102 may perform biometric authentication (such as facial and / or fingerprint recognition) to authenticate the user. If the user is correctly authenticated, device 102 may retrieve one of the encrypted QR codes and then decrypt that QR code for display. In some embodiments, the encrypted QR codes may be encrypted individually, and device 102 may be able to decode a single QR code at a time based on the individual encryption. For example, each encrypted QR code may be encrypted with a separate key, where a single biometric authentication of the user provides access to a single key. Therefore, device 102 may retrieve the corresponding encrypted QR code and key based on biometric authentication and may decrypt a single QR code. Device 102 may display the decrypted QR code 104 on the display of device 102, where QR code 104 may be scanned by another device to initiate data transmission.
[0038] In some embodiments, QR code 104 may be a one-time QR code that can be used for a single data transmission. In some embodiments, once QR code 104 has been displayed, device 102 may remove QR code 104 from storage or store an indication of QR code 104 to prevent it from being displayed a second time. Furthermore, in some embodiments, the service device for performing the data transmission (as further described throughout this disclosure) may verify that QR code 104 is only for a single data transmission before data transmission begins. The service device may prevent any data transmission if it determines that QR code 104 has already been used once.
[0039] In some implementations, QR code 104 may be valid for a period of time after it begins to appear on the display of device 102. In some of these implementations, device 102 may determine that a period of time has elapsed since QR code 104 began to appear on the display and remove QR code 104 from the display based on the elapsed period. Furthermore, in some implementations, device 102 may capture a timestamp corresponding to the time when QR code 104 began to appear on the display of device 102. Device 102 may provide this timestamp to a service device, which may compare this timestamp with another timestamp corresponding to the time when QR code 104 has been scanned by another device to determine whether QR code 104 has been used within a certain period of time. If the service device determines that QR code 104 has not been used within a certain period of time, the service device may prevent the corresponding data transmission.
[0040] In some implementations, the displayed QR code 104 may be displayed in a manner that cannot be copied by conventional image capture devices, such as cameras. For example, the displayed QR code 104 may be an artistic representation of the QR code 104. This artistic representation may obscure the QR code 104 with additional dots and / or images within the artistic representation. A device intended to read the QR code 104 may have information that allows the device to decode the QR code 104 from the additional dots and / or images. In contrast, a device without this information may not be able to decode the QR code 104 from the additional dots and / or images.
[0041] In some embodiments, device 102 may collect information relating to the display of QR code 104. In some of these embodiments, an extension may be executed within a user information application on device 102. This extension may be an application programming interface (API) executing within the user information application. This extension may be associated with a service device that facilitates data transfer. The extension may be sandboxed within the user information application, whereby the sandbox restricts the data that the extension can collect and / or the operations that the extension can perform. The extension may collect information relating to the display of QR code 104 and may provide the collected information to the service device. The information collected by the extension may be subject to sandboxing and / or settings that may be set by the user of the device regarding information that can be shared by the device. The service device may provide one or more indications of the information to be collected by the extension, which the service device may use to determine whether the user and / or device is authorized to perform data transfer. In some embodiments, device 102 may display an indication 106 of the collected information on a display of device 102. For example, in some implementations, device 102 may display indication 106 when QR code 104 is displayed on device 102.
[0042] In some implementations, device 102 may further prevent the acquisition of screenshots of QR code 104 and / or the execution of screen recordings of the QR code. For example, when QR code 104 is displayed, device 102 may prevent the user of device 102 and / or applications on the device from performing screenshots and / or screen recordings. In other examples, the user and / or applications on the device may be able to perform screenshots and / or screen recordings when QR code 104 is displayed, but the appearance of QR code 104 in the screenshots and / or screen recordings may be prevented. In some of these implementations, an extension within the user information application may prevent QR code 104 from being captured in screenshots and / or screen recordings.
[0043] System deployment 100 may also include a QR configuration device 108. In some embodiments, the QR configuration device 108 may be implemented in a service device. Device 102 may be able to establish a wireless connection with the QR configuration device 108 to retrieve a QR code from the QR configuration device 108. The QR configuration device 108 may include a QR code generator 110. The QR code generator 110 may generate QR codes (such as QR code 104) for device 102. Specifically, the QR code generator 110 may generate QR codes associated with one or more accounts corresponding to credentials stored in a user information application on device 102. The QR code generator 110 may generate one or more QR codes in response to a request for an additional QR code received from device 102.
[0044] The QR codes generated by QR code generator 110 can be one-time use QR codes. For example, a QR code generated by QR code generator 110 may be intended for a single data transmission performed by device 102. Therefore, QR code generator 110 can generate a QR code for each data transmission performed by device 102. Device 102 and / or the service device can verify that each QR code is used for a single data transmission.
[0045] QR code generator 110 can individually encrypt each QR code generated by QR code generator 110. Individual encryption of QR codes allows for the generation of a single QR code at a time. QR code generator 110 can apply proprietary encryption to the QR code, enabling device 102 or any other device to generate a valid QR code. In some embodiments, each QR code can be encrypted by QR code generator 110 via a corresponding unique key, wherein QR configuration device 108 can configure QR code and corresponding key to device 102. Device 102 can then decrypt the corresponding encrypted QR code configured by QR configuration device 108 using the key provided by QR configuration device 108. Device 102 can perform user authentication and retrieve the key and corresponding encrypted QR code based on successful user authentication. Furthermore, QR code generator 110 can uniquely encrypt QR codes for device 102. For example, QR code generator 110 can use information related to device 102 to encrypt QR codes, wherein the QR code to be used for device 102 can be determined based on the encryption of the information.
[0046] Device 102 may request more keys based on the number of valid QR codes stored on device 102. For example, device 102 may request additional QR codes from QR configuration device 108 if the number of valid QR codes stored on device 102 is less than a threshold number of valid QR codes. QR codes may become invalid based on use and / or if a QR code remains stored on the device for a threshold period of time and is not used. For example, once a QR code has been displayed, the displayed QR code may become invalid. Furthermore, QR codes that remain stored on the device for a threshold period of time (such as 24 hours) may become invalid. Device 102 may determine the number of valid QR codes stored on device 102 and compare the number of valid QR codes to a threshold number of valid QR codes. If device 102 determines that the number of valid QR codes stored on device 102 is less than the threshold number of QR codes, device 102 may request additional QR codes from QR configuration device 108.
[0047] In some embodiments where device 102 determines that the number of valid QR codes stored on device 102 is less than a threshold number of QR codes, device 102 may also indicate the number of QR codes to be provided by QR configuration device 108. For example, device 102 may be configured with a maximum number of QR codes to be stored on device 102. Device 102 may determine the difference between the number of valid codes stored on device 102 and the maximum number of QR codes to be stored on device 102, and may request multiple QR codes from QR configuration device 108 to increase the number of valid QR codes stored on device 102 to the maximum number of QR codes. Therefore, when requesting additional QR codes from QR configuration device 108, device 102 may indicate the difference between the maximum number of QR codes and the number of valid QR codes currently stored on the device. In some embodiments, the maximum number of QR codes may be determined by device 102 based on the use of QR codes by device 102. For example, device 102 can monitor the use of QR codes by users of device 102 and set the maximum number of QR codes to be equal to or greater than the number of QR codes used by users within a threshold time period by a predetermined amount.
[0048] In some implementations, device 102 may determine whether it can establish a connection with QR configuration device 108 before requesting an additional QR code from QR configuration device 108. If device 102 determines that it can establish a connection with QR configuration device 108, it may delete an invalid QR code from memory based on whether it requests an additional QR code from QR configuration device 108 and / or receives an additional QR code from the QR configuration device. If device 102 determines that it cannot establish a connection with QR configuration device 108 at that time, it may initiate data transmission using a portion of the invalid QR code. For example, device 102 may determine to use an invalid QR code based on the fact that it has been stored on device 102 for a period longer than a threshold time period. Device 102 may indicate that it has used the invalid QR code for data transmission, or a serving device may determine this situation, wherein the serving device may determine whether to allow the data transmission based at least in part on whether device 102 is unable to retrieve the additional QR code. Device 102 may use these QR codes until it can establish a connection with QR configuration device 108 and retrieve additional QR codes from QR configuration device 108.
[0049] System arrangement 100 may also include a remote device 112 having a capture element 114. In some embodiments, remote device 112 may include a point-of-sale device. Remote device 112 may be associated with a second account that can be used for data transfer. Capture element 114 may be a device capable of reading QR codes (such as QR code 104 displayed on device 102). For example, capture element 114 may be a barcode scanner or camera capable of capturing QR codes, wherein capture element 114 may be coupled to or included in remote device 112.
[0050] To initiate data transmission, device 102 may display a QR code 104 and may be moved to a position where the capturing element 114 can scan the QR code 104 displayed on device 102. Remote device 112 may provide the service device with the QR code 104 and / or information related to the QR code 104 to initiate data transmission between an account associated with device 102 and a second account associated with remote device 112.
[0051] In some implementations, the remote device 112 may also collect information related to the reading of the QR code 104 and provide this information to the service device. For example, the remote device 112 may collect a timestamp corresponding to the time when the capturing element 114 scans the QR code 104. The remote device 112 may provide this timestamp to the service device. The service device may compare the timestamp corresponding to when the QR code 104 begins to be displayed with the timestamp corresponding to when the QR code 104 is scanned to determine whether data transmission should be performed. For example, if the timestamp corresponding to when the QR code 104 begins to be displayed and the timestamp corresponding to when the QR code 104 is scanned are within a threshold time period, the service device may determine that data transmission is permitted. If the timestamp corresponding to when the QR code 104 begins to be displayed and the timestamp corresponding to when the QR code 104 is scanned are not within the threshold time period, the service device may determine that data transmission is not permitted.
[0052] Remote device 112 can also define a value for data transmission corresponding to the scanning of QR code 104. For example, remote device 112 can display the value of the data transmission, and device 102 can be moved to a position where QR code 104 can be scanned by capture element 114 to indicate that the user of device 102 has approved the data transmission with that value. Device 102 can indicate the value to a service device, which can facilitate the data transmission with that value between the account associated with device 102 and the account associated with remote device 112.
[0053] Figure 2 An exemplary device 200 according to some embodiments is shown. According to embodiments herein, device 200 can be used for data transmission. For example, device 102 ( Figure 1 It may include one or more features of device 200.
[0054] Device 200 may include a user information application 202. User information application 202 may include multiple instructions that, when executed by device 200, cause device 200 to perform one or more operations. User information application 202 may manage one or more credentials that can be used for data transfer as described herein. User information application 202 may cause the device to display instructions on the credentials managed by user information application 202, allowing a user of device 200 to select the credentials to be used for data transfer. User information application 202 may facilitate data transfer between an account associated with the credentials and an account associated with another device (such as a point-of-sale device).
[0055] User information application 202 may include a credential extension 204. Credential extension 204 may include multiple instructions that, when executed by device 200, cause one or more operations to be performed within user information application 202. In some embodiments, device 200 may also include one or more credential applications, such as credential application 206. Credential application 206 may be associated with credentials managed by user information application 202. Credential application 206 may be used to install credential extension 204 within user information application 202. In some cases, credential application 206 may be removed from device 200, while credential extension may remain within user information application 202.
[0056] Credential extension 204 can be sandboxed within user information application 202. Specifically, sandboxing credential extension 204 can limit the data and / or operations that credential extension 204 can utilize within user information application 202. Credential extension 204 can collect information from user information application 202, such as information related to data transmission performed using user information application 202. Sandboxing credential extension 204 can limit the information that credential extension 204 can collect from user information application 202. For example, credential extension can be limited to collecting information about QR codes (such as QR code 104). Figure 1 Information on when to display on device 200, the location of device 200, and other information related to QR codes or data transmissions associated with user information application 202, or some combination thereof. In some embodiments, the user of device 200 may define which data and / or operations are available to credential extension 204, and which data and / or operations are not available to credential extension 204.
[0057] Credential extension 204 can communicate with the service device associated with the credential. The service device can communicate with credential extension 204 to define what information credential extension 204 intends to collect. For example, the service device can instruct credential extension 204 on the information it intends to collect. Because sandboxing of credential extension 204 restricts the information that can be collected by credential extension 204, credential extension 204 can collect all information indicated by the service device, or portions of the information indicated by the service device that are not prevented from being collected by sandboxing of credential extension 204. Credential extension 204 can provide the indicated information to the service device. For example, once a QR code has been displayed and / or data transmission has been initiated based on the QR code, credential extension 204 can provide the indicated information to the service device. The service device can use this information to determine whether the data transmission associated with the QR code is authorized.
[0058] Credential extension unit 204 and / or credential application 206 can facilitate the acquisition of additional QR codes by device 200. For example, credential extension unit 204 and / or credential application 206 can monitor the number of valid QR codes stored on device 200. Credential extension unit 204 and / or credential application 206 can compare the number of QR codes stored on device 200 with a threshold number of QR codes. When the number of QR codes stored on device 200 is less than the threshold number of QR codes, credential extension unit 204 and / or credential application 206 can enable device 200 to retrieve QR codes from a QR configuration device (such as QR configuration device 108). Figure 1 )) Request an additional QR code. In addition, the credential extension unit 204 and / or credential application 206 can facilitate the configuration of the additional QR code to the device 200.
[0059] Device 200 may also include memory 208. Memory 208 may store one or more QR codes 210 on the device. Specifically, QR codes received from QR configuration device 108 may be stored in the memory of device 200. QR codes stored in memory 208 may be encrypted, for example, to prevent unauthorized access to the QR codes. User information application 202 and / or credential extension unit 204 may retrieve the encrypted QR codes from memory 208 and then decrypt the QR codes for use.
[0060] Device 200 may also include a security element 212. Security element 212 may be an electronic component (such as a processor and / or memory device) configured to restrict entities (such as applications and / or other devices) that can utilize security element 212 and / or access data stored on security element 212. Security element 212 may be programmed with entities that can utilize and / or access security element 212 in an implementation as a final product (e.g., device 200), wherein once security element 212 is implemented in the final product, the entities cannot be redefined.
[0061] Device 200 may store one or more keys 214 within a secure element 212. Each key 214 may correspond to a corresponding QR code stored in memory 208 of device 200. Device 200 may allow a user to perform an authentication procedure (such as biometric (facial and / or fingerprint) recognition) to allow access to the key 214 within secure element 212. Secure element 212 may allow retrieval of a single key from key 214 according to each authentication procedure. For example, user information application 202 and / or credential extension 204 may request a key from secure element 212 to decrypt a corresponding QR code retrieved from memory 208. In response to this request, device 200 may cause the user of device 200 to perform an authentication procedure to authenticate that the user who caused the request is the user authorized to access key 214. If the user is correctly authenticated, secure element 212 may allow user information application 202 and / or credential extension 204 to retrieve a key corresponding to the QR code to be decrypted. Each key may have a single corresponding QR code, such that a single key can be used to decrypt a single QR code. The key 214 can be received from the QR configuration device together with the corresponding QR code 210.
[0062] In other embodiments, the security element 212 may store a key that can be used to decrypt a plurality of QR codes 210 stored in the memory 208. In these embodiments, the user information application 202 and / or the credential extension 204 may limit the number of QR codes that can be decrypted at one time. For example, the user information application 202 and / or the credential extension 204 may retrieve the key from the security element based on the authentication of the user of device 200. The user information application 202 and / or the credential extension 204 may limit the number of QR codes that can be decrypted by the key at this time. The user information application 202 and / or the credential extension 204 may limit the number of QR codes that the key must decrypt based on the user's correct authentication.
[0063] Figure 3 A first portion of an exemplary signal flow 300 for configuring credentials and / or credential extensions to a device, according to some embodiments, is shown. For example, signal flow 300 illustrates a method for configuring credentials and / or credential extensions (such as credential extension 204) to a device. Figure 2 Add to devices (such as device 200) Figure 2 User information applications (such as User Information Application 202) on the platform. Figure 2 An exemplary process is shown for configuring a QR code (such as QR code 104) to a device. Signal stream 300 also illustrates this process. Figure 1 ) and / or QR code 210 ( Figure 2The exemplary process is as shown in the diagram. It should be understood that one or more of the operations described in signal flow 300 may be performed simultaneously and / or in a different order than that shown. Additionally, one or more of these operations may be omitted in other embodiments.
[0064] Signal flow 300 can occur between multiple entities. For example, an entity may include credential application 302. Credential application 302 may include credential application 206. Figure 2 One or more of the characteristics of ). Credential application 302 may reside on the device and may be executed by the device. Credential application 302 may be associated with credentials to be configured to the device.
[0065] The entity may also include user information application 304. User information application 304 may include user information application 202 ( Figure 2 The user information application 304 may reside on and be executed by the device. The user information application 304 may manage one or more credentials stored on the device. For example, the user information application 304 may allow a user of the device to select from credentials stored on the device and initiate data transfer with the account associated with the credentials. The user information application 304 may also cause the device to display a QR code associated with the credentials for initiating data transfer with the account associated with the credentials.
[0066] The entity may also include an account server 306. The account server 306 may be decoupled from the device and may manage user accounts associated with the user information application 304. The account server 306 may store information associated with the device, the device's users, credentials stored on the device, or some combination thereof. For example, the account server 306 may maintain user accounts for the user information application 304 (such as usernames and / or passwords that allow access to user accounts corresponding to credentials). The account server 306 may facilitate the transmission of data associated with credentials of the user information application 202 and / or facilitate the reception of QR codes associated with credentials of the user information application 202.
[0067] The entity may also include service device 308. Service device 308 may be decoupled from the device and may manage accounts associated with credentials of the user information application. For example, service device 308 may maintain one or more accounts associated with one or more credentials of user information application 202. Service device 308 may perform data transfer between one or more accounts stored on service device 308, and / or data transfer between accounts stored on service device 308 and accounts stored on another device.
[0068] In 310, a request to add credentials may be provided to user information application 304. For example, credential application 302 may generate a request to add credentials to credentials maintained by user information application 304 and transmit the request to user information application 304. A user of the device may instruct in credential application 302 to add credentials associated with credential application 302 to user information application 304. Credential application 302 may provide the request in 310 to user information application 304 based on the user's instruction to add credentials to user information application 304.
[0069] In step 312, a request for a certificate and / or a nonce (a one-time-use random number) may be made to the account server 306. Specifically, the user information application 304 may generate and transmit a request for one or more certificates and / or nonces from the account server 306. The requested certificate and / or nonce may be related to credentials to be configured into the user information application 304.
[0070] In step 314, account server 306 may provide the one or more certificates and / or nonces to user information application 304. Specifically, account server 306 may transmit the certificate and / or nonce requested in step 312 to user information application 304.
[0071] In step 316, the user information application 304 may provide the one or more certificates, nonces, and / or signed nonces to the credentials application 302. For example, the user information application 304 may sign a nonce received from the account server 306 to generate a signed nonce. The signed nonce verifies that the nonce has been tampered with. The user information application 304 may transmit the certificates, nonces, and / or signed nonces to the credentials application 302.
[0072] In 318, the credential application 302 may provide a configuration package preparation request to the service device 308. The configuration package preparation request may request the service device 308 to generate a configuration package for configuring credentials and / or credential extensions to the user information application 304. The configuration package preparation request may include the certificate received in 316.
[0073] In step 320, the service device 308 may provide the credential application 302 with an identifier (which may be referred to as a "package identifier") for an encrypted configuration package. Specifically, the service device 308 may generate a configuration package based on a configuration package preparation request received in step 318. The configuration package may be used to configure credentials and / or credential extensions to the user information application 304. The service device 308 may also encrypt the configuration package. The service device 308 may generate a package identifier indicating the encrypted configuration package. The package identifier may be used by the service device 308 to identify the encrypted configuration package. The service device 308 may transmit the package identifier of the encrypted configuration package to the credential application 302, which may use the package identifier to refer to the encrypted configuration package.
[0074] In step 322, the credentials application 302 may provide the user information application 304 with a package identifier, a nonce, and / or a signed nonce. The package identifier indicates the content being configured and provides a link to the account on the service device corresponding to the configuration package. The nonce can be used to verify that the configuration occurred once. The signed nonce can be used to verify that the nonce has not been tampered with. The credentials application 302 may transmit the package identifier, nonce, and / or signed nonce to the user information application 304.
[0075] In step 324, the user information application 304 may provide a credential verification request to the account server 306. The credential verification request may request the account server 306 to verify that credentials have been authorized for addition to the user information application 304. The credential verification request may include a package identifier indicating a configuration package. The user information application 304 may transmit the credential verification request to the account server 306.
[0076] In 326, account server 306 may provide terms to user information application 304. For example, account server 306 may generate terms indicating the configuration and / or features to be provided for credentials. Account server 306 may transmit the terms to user information application 304.
[0077] In step 328, the user information application 304 may provide an enable credentials request to the account server 306. For example, the user information application 304 may generate a credential identifier that refers to credentials stored in the user information application 304. The enable credentials request may request that credentials be enabled within the user information application 304. The user information application 304 may transmit the enable credentials request to the account server 306.
[0078] In 330, account server 306 may provide a request for a configuration package to service device 308. The request for the configuration package may request service device 308 to provide account server 306 with a configuration package associated with a package identifier. The request for the configuration package may include a package identifier and / or an encrypted certificate chain. The encrypted certificate chain may be generated based on a certificate received by the user information application in 314. Account server 306 may transmit the request for the configuration package to service device 308.
[0079] In 332, the service device 308 may provide a configuration package to the account server 306. The configuration package provided by the service device 308 may be an encrypted configuration package encrypted by the service device. The encrypted configuration package may include encrypted data containing content to be configured into the user information application 304. The encrypted configuration package may also indicate which files the service device 308 expects to be included in the credentials. The service device 308 may transmit the configuration package to the account server 306.
[0080] In section 334, account server 306 may transmit a credential Uniform Resource Locator (URL) to user information application 304. The credential URL indicates the location that the user information application can use to access the configuration suite. User information application 304 may use the credential URL to download data that can be used to indicate credentials in user information application 304.
[0081] Figure 4 A second portion of a signal flow 300 for configuring credentials and / or credential extensions to a device, according to some embodiments, is shown. Specifically, the signal flow 300 may proceed from 334 to 402.
[0082] In step 402, account server 306 can tokenize the bundle identifier. For example, account server 306 can generate a Device Master Account (DPAN) associated with the bundle identifier. The DPAN or bundle identifier can later be used to perform certain data transfers, such as when a QR code is not used for data transfer. The DPAN or bundle identifier can be sent to user information application 304, which can use the DPAN or bundle identifier to perform data transfers. User information application 304 can detoxify the DPAN into a bundle ID and provide the DPAN to a credentials application to perform data transfers.
[0083] In 404, account server 306 may store one or more pending commands. For example, account server 306 may use the put command to store pending commands. Pending commands may be related to user information application 304 and the configuration of credentials and / or credential extensions onto user information application 304.
[0084] In position 406, the user information application 304 may request a pending command stored in position 404. For example, the user information application 304 may transmit a get command to the account server 306 for a pending command stored in position 404. The pending command can...
[0085] In step 408, account server 306 may provide a configuration success notification to service device 308. The configuration success notification may include an event notification indicating that configuration has been successful. For example, the configuration success notification may indicate that credentials and / or credential extensions have been successfully configured to the user information application. Account server 306 may transmit the configuration success notification to service device 308 based on the successful configuration of credentials and / or credential extensions to user information application 304.
[0086] In 410, the service device 308 can activate credentials. Specifically, the service device 308 can activate credentials based on an indication that credentials and / or credential extensions have been successfully configured in 408. Activation of credentials allows data transfer to be performed using the account associated with the credential extensions.
[0087] In 412, service device 308 may provide account server 306 with a message indicating that credentials have been activated. For example, service device 308 may provide account server 306 with a 200 type message to indicate that credentials have been activated.
[0088] In 414, the user information application 304 may generate one or more key pairs. For example, in some embodiments, the user information application 304 may generate encryption key pairs and / or signature key pairs.
[0089] In step 416, the user information application 304 may perform auxiliary registration to the account server 306. For example, the user information application 304 may provide the account server 306 with information for auxiliary registration. The auxiliary registration message provided by the user information application 304 to the account server 306 may include a package identifier, a device signature corresponding to the device on which the user information application 304 executes, a barcode encryption certificate signing request (CSR), a device signing CSR, an indication of a requested certificate, or some combination thereof. The user information application 304 may provide the account server 306 with a barcode encryption CSR and / or a device signing CSR to allow the account server 306 to issue a certificate. The user information application 304 may transmit auxiliary registration messages to the account server 306.
[0090] In section 418, account server 306 may issue one or more certificates. For example, account server 306 may issue one or more certificates based on the auxiliary registration in section 416. Certificates issued by account server 306 may include barcode encryption certificates and / or device signing certificates.
[0091] In 420, account server 306 may establish functionality with service device 308. For example, account server 306 may request the issuance of a certificate from service device 308. The certificate issued by service device 308 may be used by service device 308 to encrypt a QR code to a device executing user information application 304 and credentials application 302. Once encrypted, only the device executing user information application 304 and credentials application 302 can decrypt the code. Requests for certificate issuance may include a packet identifier, a barcode encryption certificate, a device signature certificate, an indication of the requested certificate, an account server signature, fraudulent data, or some combination thereof. Account server 306 may transmit a request to service device 308 to issue a certificate.
[0092] Figure 5 A third portion of a signal flow 300 for configuring credentials and / or credential extensions to a device is shown according to some embodiments. Specifically, the signal flow 300 may proceed from 420 to 502.
[0093] In section 502, service device 308 may store the information provided in section 420. For example, service device 308 may store a package identifier, a barcode encryption certificate, a device signing certificate, or some combination thereof. The service device may store the barcode encryption certificate and / or the device signing certificate for the package identifier, such that the certificates can be used for the package identifier in the future.
[0094] In step 504, service device 308 may provide account server 306 with an indication that the certificate has been stored in step 502. For example, service device 308 may transmit an OKAY message to account server 306, indicating that the certificate has been stored by service device 308.
[0095] In step 506, account server 306 may provide a certificate to user information application 304. For example, account server 306 may transmit a device signing certificate, barcode encryption certificate, device encryption certificate, or a combination thereof to user information application 304. User information application 304 may use the certificate to request a QR code from service device 308.
[0096] In step 508, the user information application 304 may request a QR code to be retrieved. Specifically, the user information application 304 may indicate to the account server 306 and / or service device 308 that it is requesting an additional QR code. The user information application 304 may transmit a retrieval request to the account server 306 to request that an additional QR code be provided to the user information application 304. The retrieval request may include a packet identifier, the number of QR codes that the user information application 304 is requesting and expects to receive, a last used credential identifier, a barcode encryption certificate, a device signature, or some combination thereof.
[0097] In 510, account server 306 may provide a credential retrieval request to service device 308. For example, account server 306 may indicate that user information application 304 has requested an additional QR code. The credential retrieval request may include a packet identifier, a credential type indicator, a last used credential identifier, the number of QR codes that user information application 304 is requesting and expects to receive, a barcode encryption certificate, an account server signature, fraudulent data, or some combination thereof. Account server 306 may transmit the credential retrieval request to service device 308 based on the retrieval request from 508.
[0098] In section 512, service device 308 can locate the encryption certificate. Specifically, service device 308 will locate the encryption certificate based on the packet identifier. For example, service device 308 can locate the barcode encryption certificate from section 502.
[0099] In 514, the service device 308 can generate one or more QR codes for use in a user information application. For example, the service device 308 can generate one or more QR codes and encrypt them. The service device 308 can generate a number of QR codes equal to the number of QR codes that the user information application 304 is requesting and expects to receive. The algorithm used to encrypt the QR codes can be proprietary to the service device 308. The service device 308 can encrypt each QR code individually.
[0100] In step 516, service device 308 may provide a QR code to account server 306. For example, service device 308 may transmit the encrypted QR code generated in step 514 to account server 306. Service device 308 may provide account server 306 with a credential type indication, expiration time / date, package identifier, value, or some combination thereof along with the QR code.
[0101] In 518, account server 306 can verify that the QR code has been individually encrypted. Specifically, account server 306 can verify that the QR code has been individually encrypted in 514. In some implementations, account server 306 can verify that the QR code has been individually encrypted based on the credential type indicated in 516.
[0102] Figure 6 A fourth portion of a signal flow 300 for configuring credentials and / or credential extensions to a device is shown according to some embodiments. Specifically, the signal flow 300 may proceed from 518 to 602.
[0103] In step 602, account server 306 may provide a QR code to user information application 304. For example, account server 306 may transmit an encrypted QR code to user information application 304. Account server 306 may provide user information application 304 with an expiration time / date indication, a package identifier, and / or a value. User information application 304 may use the expiration time / date to determine when the QR code becomes invalid if it is stored by the device but not used.
[0104] In 604, the user information application 304 may store a QR code. For example, the user information application 304 may store an encrypted QR code associated with credentials and / or a user associated with credentials.
[0105] Figure 7 A first portion of an exemplary signal stream 700 for initiating data transmission based on a QR code, according to some embodiments, is shown. Signal stream 700 may also show QR code supplements according to some embodiments. For example, signal stream 700 shows a method for initiating data transmission in a device (such as device 102). Figure 1 The display shows a QR code (such as QR code 104). Figure 1 )) and based on remote devices (such as remote device 112 ( Figure 1 An exemplary process of initiating data transmission by scanning a QR code. Signal stream 700 also illustrates a QR code stored on the device (such as one stored on device 200). Figure 2 ) memory 208 ( Figure 2 The QR code 210 in ) Figure 2 This is a supplement to the above. It should be understood that one or more of the operations described in signal flow 700 may be performed simultaneously and / or in a different order than that shown. Additionally, one or more of these operations may be omitted in other embodiments.
[0106] Signal flow 700 can occur between multiple entities. For example, in the illustrated embodiment, signal flow 700 can occur between a secure area processor (SEP) 702, a user information application 704, an account server 706, and a service device 708. SEP 702 may include a dedicated security subsystem isolated from the device's main processor to provide an additional layer of security and maintain the security of sensitive user data. SEP 702 may be dedicated only to certain defined purposes, such as secure area purposes. User information application 704 may include user information application 304 (… Figure 3 Account server 706 may include one or more of the features of account server 306. Figure 3 Service device 708 may include one or more of the features of service device 308. Figure 3 One or more of the features of ).
[0107] In 710, the user information application 704 can perform biometric authentication. For example, a user can select credentials from the user information application 704 to be used for data transfer utilizing a QR code. These credentials can be associated with an account maintained by the service device, and the account can be identified based on these credentials. Based on the user's selection of these credentials, the user information application 704 can perform biometric authentication (such as facial recognition and / or fingerprint recognition) to authenticate the user. The user information application 704 can perform biometric authentication to determine that the user of the device is authorized to perform the data transfer associated with these credentials.
[0108] In 712, the user information application 704 can request information from SEP 702 for decrypting the QR code. For example, the user information application 704 can provide an indication of an encrypted QR code stored on the device executing the user information application 704, and a request for information for decrypting the QR code.
[0109] In 714, SEP 702 analyzes the biometric authentication identified in 710 to determine whether the user is authorized to use the QR code. If SEP 702 determines that the user is not authorized to use the QR code, the signaling flow 700 may terminate. If SEP 702 determines that the user is authorized to use the QR code, the signaling flow 700 may continue.
[0110] In 716, SEP 702 executes a key protocol process to determine the key to be used to decode the QR code. The key protocol process may be based on a Private Basic Proof Authority (BAA) key and / or a public temporary key. The BAA key provides a digital signature that can be used to verify that a device with SEP 702 is a trusted device.
[0111] In 718, SEP 702 can perform a Key Derivation Function (KDF) to generate a key for decrypting the QR code. The KDF can be performed using ShS. ShS's KDF can generate a key for decrypting the QR code.
[0112] In 720, SEP 702 can provide the exported key generated in 718 to the user information application 704. For example, SEP 702 can transfer the exported key to the user information application 704.
[0113] In 722, the user information application 704 can use the export key received in 720 to export the QR code. For example, the user information application 704 can use the key to decrypt the encrypted QR code indicated in the request from 712. The user information application 704 can generate a decrypted QR code by decrypting the encrypted QR code.
[0114] In 724, the user information application 704 can display the QR code on the device's display. For example, the user information application 704 can display the decrypted QR code on the device running the user information application 704.
[0115] In 726, the user information application 704 can sign a timestamp and a last-used credential identifier. For example, the user information application 704 can identify a timestamp corresponding to the time when the QR code begins to appear on the device. Furthermore, the user information application 704 can identify an identifier associated with the credential utilizing the QR code, which can be used as the last-used credential identifier. The user information application 704 can generate a device signature based on the timestamp and / or the last-used credential identifier.
[0116] Figure 8 A second portion of a signal stream 700 for initiating data transmission based on a QR code, according to some embodiments, is shown. Specifically, the signal stream 700 may proceed from 726 to 802.
[0117] In 802, the user information application 704 may provide timestamp information to the service device 708. For example, the user information application 704 may provide the service device 708 with information related to the timestamp identified in 726. This timestamp information may include a timestamp, a device signature, a last used credential identifier, or some combination thereof. The service device 708 may use the timestamp to determine whether the QR code was scanned within an allowed time period (e.g., three minutes) from the start of the QR code's display, to determine whether data transmission is permitted.
[0118] In step 804, the service device 708 can verify the device signature. Specifically, the service device 708 can verify the validity of the device signature received from the user information application 704 in step 802. Verifying the device signature helps the service device 708 identify the account associated with the credentials and / or verify that the device is authorized to perform data transfers with the account.
[0119] In 806, the service device 708 may provide the user information application 704 with an indication that the device signature has been verified. For example, the service device 708 may transmit an OK message to the user information application 704 to indicate that the device signature has been verified.
[0120] In step 808, the user information application 704 may determine supplementary QR codes stored on the device. For example, the user information application 704 may determine that the number of valid QR codes stored on the device is less than a threshold number of QR codes to be stored on the device. Whether a QR code is valid or invalid may be determined based on methods described throughout this disclosure, such as whether the QR code has been used for data transmission, the amount of time the QR code has been stored on the device, or some combination thereof. Based on the user information application 704 determining that the number of valid QR codes stored on the device is less than the threshold number of QR codes to be stored on the device, the user information application may determine supplementary QR codes.
[0121] In 810, the user information application 704 may provide a request to the account server 706 to retrieve an additional QR code. The request to retrieve the additional QR code may include credentials corresponding to the retrieval of the additional QR code and / or a DPAN identifier corresponding to the device. The user information application 704 may transmit the request to retrieve the additional QR code to the account server 706.
[0122] In 812, account server 706 can parse the configuration package identifier (which may be referred to as the package identifier). For example, account server 706 can determine the package identifier associated with the DPAN identifier received in 810. For example, account server 706 can identify the package identifier associated with the credentials based on the DPAN identifier.
[0123] In 814, account server 706 may provide service device 708 with a request to retrieve a QR code used for credentials. This request may include an indication of the credential type, a bundle identifier, an indication of the number of QR codes requested by user information application 704, and an account signature, or some combination thereof. Account server 706 may transmit a request to service device 708 to retrieve a QR code based on a request to retrieve additional QR codes received from user information application 704 in 810.
[0124] In 816, the service device 708 can locate the encryption certificate. For example, the service device 708 can locate the encryption certificate based on the packet identifier received in 814.
[0125] In 818, service device 710 can verify account signatures. For example, service device 708 can verify account signatures received in 814.
[0126] Figure 9 A third portion of a signal stream 700 for initiating data transmission based on a QR code, according to some embodiments, is shown. Specifically, the signal stream 700 may proceed from 818 to 902.
[0127] In 902, service device 708 can generate one or more QR codes. Service device 708 can generate QR codes based on the verification of the account signature in 818. Service device 708 can generate a number of QR codes equal to the number of QR codes indicated in 814.
[0128] In 904, service device 708 can encrypt these QR codes. For example, service device 708 can encrypt the QR codes generated in 902. Service device 708 can apply proprietary algorithms to these QR codes to encrypt them to produce encrypted QR codes.
[0129] In 906, service device 708 can provide an encrypted QR code to account server 706. For example, service device 708 can transmit an encrypted QR code encrypted in 904 to account server 706.
[0130] In 908, account server 706 may provide an encrypted QR code to user information application 704. For example, account server 706 may transmit an encrypted QR code received in 906 to user information application 704.
[0131] In 910, the user information application 704 can store an encrypted QR code. For example, the user information application 704 can store an encrypted QR code received in 908. The user information application 704 can store the encrypted QR code in the device's memory, such as memory 208. Figure 2 The user information application 704 can store encrypted QR codes for use in association with future data transfers.
[0132] Figure 10 An exemplary signal stream 1000 for displaying QR codes and fraud detection is shown according to some embodiments. For example, signal stream 1000 shows a method for displaying QR codes (such as QR code 104). Figure 1This is an exemplary process of providing information to the service device to determine whether the requested data transmission is fraudulent. It should be understood that one or more of the operations described in signal flow 1000 may be performed simultaneously and / or in a different order than shown. Additionally, one or more of these operations may be omitted in other embodiments.
[0133] Signal flow 1000 can occur between multiple entities. For example, in the illustrated embodiment, entities may include user information application 1002, credential extension unit 1004, and service device 1006. User information application 1002 may include user information application 202 (… Figure 2 ), User Information Application 304 ( Figure 3 ) and / or User Information Application 704 ( Figure 7 The credential extension 1004 may include one or more of the features of the credential extension 204. Figure 2 Service device 1006 may include one or more of the features of service device 308. Figure 3 ) and / or service equipment 708 ( Figure 7 One or more of the features of ).
[0134] In 1008, the user information application 1002 may display a QR code. For example, the user information application 1002 may display a QR code on the display of the device running the user information application 1002.
[0135] In 1010, user information application 1002 may initiate metadata collection. For example, user information application 1002 may initiate conditional event metadata collection based on a QR code displayed on the device's display. The user information application may collect data associated with the QR code. In some embodiments, the data collected by user information application 1002 may include data to be collected requested by credential extension 1004. The data to be collected may be defined via service device 1006, which may communicate with credential extension 1004 to indicate the data to be collected and / or receive the collected data from credential extension 1004.
[0136] In 1012, the user information application 1002 can provide the collected data to the credential extension unit 1004. For example, the user information application 1002 can transmit the data collected in 1010 to the credential extension unit 1004. The user information application 1002 can provide an indication of the QR code identifier (which may be referred to as the last used barcode identifier) corresponding to the QR code being displayed.
[0137] In step 1014, the credential extension unit 1004 can determine a portion of the received data to be provided to the service device for determining whether to perform data transmission associated with the barcode. The credential extension unit can encrypt this portion of the data and provide the encrypted data to the service device 1006. In other embodiments, the user information application 1002 can provide the encrypted data to the service device 1006. Encryption of this portion of the data prevents malicious individuals and / or any entity that transmits encrypted data to the service device 1006 through it from accessing the data.
[0138] In step 1016, the credential extension unit 1004 may provide the user information application 1002 with an indication that the credential extension unit 1004 has received the data to be provided to the service device 1006. For example, the credential extension unit 1004 may transmit an OK message indicating that the event metadata has been received from the user information application.
[0139] In some implementations, 1012 to 1016 may be omitted. For example, when a credentials application (such as credentials application 302) Figure 3 If 1012 to 1016 are not installed on the device or if the credential extension section 1004 has not yet been implemented in the user information application 1002, then 1012 to 1016 can be omitted.
[0140] In step 1018, the user information application 1002 may stop collecting metadata. For example, the user information application 1002 may terminate the collection of conditional event metadata corresponding to the display of a QR code.
[0141] In 1020, the user information application 1002 can generate a signature. For example, the user information application 1002 can recognize a timestamp, a QR code identifier (which may be referred to as a barcode identifier), an authentication type, a device account identifier, a biometric change indicator, conditional event metadata from metadata collection, or some combination thereof. The user information application 1002 can generate a signature based on a timestamp, a QR code identifier, an authentication type, a device account identifier, a biometric change indicator, conditional event metadata, or some combination thereof.
[0142] In 1022, the user information application 1002 may provide timestamp information to the service device 1006. The timestamp information may include a timestamp, QR code identifier, authentication type, device account identifier, biometric change indication, conditional event metadata, and / or a signature from 1020. The user information application 1002 may transmit the timestamp information to the service device 1006.
[0143] In 1024, service device 1006 may provide user information application 1002 with an indication that data transmission corresponding to a QR code can be performed. For example, service device 1006 may determine, at least in part, that the data transmission is authorized to be performed based on timestamp information received in 1022. Service device 1006 may transmit to user information application 1002 an indication that the data transmission can be performed based on the authorization for the data transmission.
[0144] Figure 11 A first portion of an exemplary signal flow 1100 for topping up an account, according to some embodiments, is shown. For example, signal flow 1100 may illustrate a process for adding a value to an account associated with credentials stored in a user information application. For example, credentials may be associated with an account having a value that may decrease with each use of the credentials. If the value of a credential reaches zero, or if decreasing the value would result in a value less than zero, the credential may no longer be utilized. Topping up an account may include adding a value to the account to allow the use of the credentials. It should be understood that one or more of the operations described in signal flow 1100 may be performed simultaneously and / or in a different order than shown. Additionally, one or more of these operations may be omitted in other embodiments.
[0145] Signal flow 1100 can occur between multiple entities. For example, entities may include applet 1102, secure element 1104, user information application 1106, credential service 1108, agent 1110, token service provider (TSP) 1112, service device 1114, and remote device 1116. Applet 1102 may include credential application 302 (… Figure 3 Safety element 1104 may include one or more of the features of safety element 212. Figure 2 ) and / or SEP 702 ( Figure 7 User information application 1106 may include one or more of the features of user information application 202. Figure 2 ), User Information Application 304 ( Figure 3 User Information Application 704 Figure 7 ) and / or User Information Application 1002 ( Figure 10 Service device 1114 may include one or more of the features of service device 308. Figure 3 ), Service Equipment 708 ( Figure 7 ) and / or service equipment 1006 ( Figure 10 One or more of the features of ).
[0146] Credentials service 1108 may include a device or server that facilitates the transfer of one or more credentials stored within user information application 1106. For example, credentials service 1108 may facilitate the filling of one or more accounts associated with one or more credentials stored within user information application 1106.
[0147] Agent 1110 may include a device or server that can help configure credentials for the device. In some implementations, agent 1110 may be omitted.
[0148] TSP 1112 may include an entity that can map the QR codes described herein to corresponding accounts. For example, TSP 1112 may maintain a mapping that can be used to map QR codes to corresponding accounts. TSP 1112 may be able to identify the corresponding account based on the receipt of the QR code or information related to the QR code.
[0149] Remote device 1116 may include remote device 112 ( Figure 1 One or more of the characteristics of the remote device 1116. The remote device 1116 may be associated with a topped-off credential. Credentials on the user information application 1106 can be used to perform data transfers with the account associated with the remote device. The account associated with the credential may have a stored value. The user information application 1106 may perform data transfers with the remote device 1116, which results in a decrease in the value of the account associated with the credential. The account associated with the credential may be terminated to prevent the account value from becoming negative, wherein the credential may not perform the data transfer if performing data transfers with the account associated with the remote device 1116 would result in a negative value for the account associated with the credential.
[0150] In 1118, the user information application 1106 can recognize a fill request. For example, a user of the device executing the user information application 1106 can perform a user interaction indicating that an account associated with credentials will be filled. The user information application 1106 can detect the user interaction indicating that the account will be filled and can initiate the account fill based on that user interaction.
[0151] In 1120, the user information application 1106 can perform an authentication process. For example, the user information application 1106 can perform biometric authentication (such as facial recognition and / or fingerprint recognition) on the user of the device. Performing biometric authentication may include capturing the user's biometric information, such as an image of the user's face and / or an image of the user's fingerprint. The user information application 1106 may also provide the biometric information to the secure element 1104 for the purpose of performing user authentication.
[0152] In 1122, security element 1104 can analyze the biometric information provided by user information application 1106 in 1120. For example, security element 1104 can compare the biometric information with stored biometric information corresponding to a user associated with credentials to authenticate that the user is authorized to terminate the account.
[0153] In 1124, the secure element 1104 can provide a host password to the user information application 1106. The host password may include binary data, which may be a digital signature or a Message Authentication Code (MAC). The host password can serve as input for decrypting a single QR code.
[0154] In 1126, the user information application 1106 can provide a transmission data transfer instruction to the applet 1102. The data transfer instruction can indicate the amount to be added to or terminated from the account. The data transfer instruction may also include the host password. The user information application 1106 can transmit the transmission data transfer instruction to the applet 1102.
[0155] In 1128, applet 1102 can provide the DPAN and password to user information application 1106. For example, applet 1102 can generate the DPAN based on a transmission data transmission instruction received from user information application 1106. Applet 1102 can store the DPAN in secure element 1104. The DPAN can correspond to credentials within user information application 1106 that will terminate the corresponding account.
[0156] In 1130, the user information application 1106 may provide an execution data transfer request to the credential service 1108. The execution data transfer request may instruct the execution of data transfer to increment a value in an account to terminate the account. The execution data transfer request may include a DPAN and a password. The user information application 1106 may transmit the execution data transfer request to the credential service 1108 based on the DPAN and password being received by the credential service 1108.
[0157] In 1132, Credentials Service 1108 may request authorized data transfer and / or detoxification of the DPAN by TSP 1112. This request may include the DPAN, password, and / or values to be added to the account to achieve termination. Credentials Service 1108 may transmit the request for authorized data transfer and / or detoxification of the DPAN to TSP 1112.
[0158] In 1134, TSP 1112 can detoxify the DPAN. For example, the DPAN may have a certain size and format. The size and format of the DPAN may not be desirable for some operations, such as for a configuration package identifier. By detoxifying the DPAN, these size and / or format constraints may not apply to the result of detoxification. TSP 1112 can generate a configuration package identifier (which may be referred to as a package identifier) based on the detoxification of the DPAN. For example, a DPAN can be issued for a package identifier, where the package identifier may not have the same size and / or format constraints as the DPAN. TSP 1112 can transmit the package identifier to credential service 1108.
[0159] In 1136, credential service 1108 may provide a retrieval authorization token request to service device 1114. The retrieval authorization token request may request service device 1114 to generate an authorization token corresponding to the account to be terminated. The retrieval authorization token request may include a package identifier, credential signature, amount to be added to the account, data transfer notification identifier, or some combination thereof. Credential service 1108 may transmit the retrieval authorization token request to service device 1114.
[0160] In 1138, service device 1114 can generate remote device authorization tokens. The remote device authorization token can be a one-time token. The remote device authorization token can be used to authorize data transfer between the account associated with the credentials and the account associated with the remote device 1116. Service device 1114 can store the remote device authorization token.
[0161] Figure 12 A second portion of a signal flow 1100 for filling an account is shown according to some embodiments. Specifically, the signal flow 1100 may proceed from 1138 to 1202.
[0162] In 1202, service device 1114 may provide a remote device authorization token to credential service 1108. For example, service device 1114 may transmit the remote device authorization token generated in 1138 to credential service 1108.
[0163] In step 1204, credential service 1108 may provide a data transfer request to remote device 1116. The data transfer request may request data transfer between the account associated with the credentials and the account associated with remote device 1116. The data transfer request may include a remote device authorization token. Credential service 1108 may transmit the data transfer request to remote device 1116.
[0164] In 1206, remote device 1116 can perform data transfer with service device 1114. For example, remote device 1116 can transmit a request to perform data transfer between an account associated with credentials (which may be maintained by service device 1114) and an account associated with remote device 1116. This instruction may include data transfer information for the data transfer to be performed. The data transfer information may indicate the amount to be transferred between accounts, the format of the value of the account associated with remote device 1116, a remote device authorization token, or some combination thereof. Remote device 1116 may transmit the request to service device 1114 to perform the data transfer.
[0165] In 1208, service device 1114 can perform a lookup of the authorization token. For example, service device 1114 can look up the authorization token to verify that data transmission is authorized to be performed.
[0166] In 1210, service device 1114 can verify the quantity to be transmitted in the data transfer. For example, service device 1114 can compare the quantity received in 1136 with the quantity received in 1206 to determine whether the two quantities match. In some embodiments, service device 1114 can determine whether the two quantities match, and if the values match, signal flow 1100 can continue, or if the values do not match, signal flow 1100 can be terminated. Service device 1114 can perform data transfer with the account corresponding to the credentials based on the determination that the two quantities match. For example, service device 1114 can decrease the value of the account associated with the credentials.
[0167] In 1212, service device 1114 may provide remote device 1116 with an indication that data transmission will be performed. For example, service device 1114 may transmit an OK message to remote device 1116 to indicate that data transmission will be performed. Based on the indication from service device 1114, the remote device may increase the value of the account associated with remote device 1116 by that amount.
[0168] In 1214, remote device 1116 may provide an indication to credential service 1108 that data transmission has been performed. For example, remote device 1116 may transmit an OK message to credential service 1108, indicating that data transmission has been performed.
[0169] In 1216, the credential service 1108 can provide the user information application 1106 with an indication that data transmission has been performed. For example, the credential service 1108 can transmit an OK message to the user information application 1106, indicating that data transmission has been performed.
[0170] In 1218, service device 1114 may provide data transmission notification information to user information application 1106. For example, the data transmission notification information may notify user information application 1106 of information associated with data transmission. The data transmission notification information may include a data transmission notification identifier corresponding to the data transmission, the amount transmitted, or a value obtained from an account associated with credentials, or some combination thereof.
[0171] Figure 13 A first portion of a signal flow 1300 for enhanced authentication of data transmission according to some embodiments is shown. For example, signal flow 1300 may be performed based on the failure of other authentication processes associated with data transmission to provide sufficient authentication of the data transmission. Enhanced authentication may be used, for example, when an expired QR code has been used for data transmission, such as when a device is unable to establish a connection with a QR configuration server or service device to retrieve an additional QR code. Enhanced authentication can be used to authenticate data transmission to verify that data transmission will be performed. It should be understood that one or more of the operations described in signal flow 1300 may be performed simultaneously and / or in a different order than shown. Additionally, one or more of these operations may be omitted in other embodiments.
[0172] Signal flow 1300 can occur between multiple entities. For example, in an illustrated embodiment, entities may include user information application 1302, credential extension unit 1304, push server 1306, and service device 1308. User information application 1302 may include user information application 202 (… Figure 2 ), User Information Application 304 ( Figure 3 User Information Application 704 Figure 7 User Information Application 1002 Figure 10 ) and / or user information application 1106 ( Figure 11 The credential extension 1304 may include one or more of the features of the credential extension 204. Figure 2 ) and / or credential extension section 1004 ( Figure 10 Service device 1308 may include one or more of the features of service device 308. Figure 3 ), Service Equipment 708 ( Figure 7 ), service equipment 1006 ( Figure 10 ) and / or service equipment 1114 ( Figure 11 One or more of the features of ).
[0173] Push server 1306 may include a server that can cause one or more devices (e.g., devices executing user information application 1302 and credential extension unit 1304) to perform push notifications. For example, push server 1306 may send push notifications to one or more devices, which, in response to receiving a push notification from push server 1306, cause the devices to display messages and / or images on their displays. In other cases, push notifications transmitted by push server 1306 may cause one or more devices to perform one or more operations associated with the push notification.
[0174] In 1310, service device 1308 can receive requests for data transmission. For example, service device 1308 can receive requests to perform data transmission with an account maintained by service device 1308.
[0175] In 1312, the service device 1308 may transmit a push notification request to the push server 1306. The push notification request may guide the push server 1306 to retrieve information for data transmission that can be used to perform enhanced authentication procedures for it.
[0176] In 1314, push server 1306 can transmit push notifications to user information application 1302. The push notifications allow user information application 1302 to retrieve information used for data transmission.
[0177] In step 1316, the user information application 1302 may transmit a request to the service device 1308 to retrieve data transmission information. The request to retrieve data transmission information may include an authentication token associated with the data transmission. The request to retrieve data transmission information may also request data transmission details from the service device 1308.
[0178] In 1318, the service device 1308 may transmit a message including data transmission details to the user information application 1302. Data transmission details may include data transmission status, a pending QR code identifier, verification details, or some combination thereof.
[0179] In 1320, the user information application 1302 may initiate an enhanced authentication operation. For example, the user information application 1302 may initiate an enhanced authentication operation based on an instruction from the service device 1308 to use further authentication for data transmission.
[0180] In 1322, the user information application 1302 may collect a personal identification number (PIN) of the user of the device. For example, the user information application 1302 may cause a user interface to be displayed on the display of the device executing the user information application 1302, wherein the user interface requests the user to enter a PIN. The user information application 1302 may recognize the PIN entered by the user.
[0181] In 1324, the user information application 1302 can encrypt the PIN. For example, the user information application 1302 can encrypt the PIN identified in 1322. The user information application 1302 can encrypt the PIN based on the device encryption certificate and / or a temporary public key.
[0182] In step 1326, the user information application 1302 may transmit an SM2 collection request to the credential extension unit 1304. The SM2 collection request may request the credential extension unit 1304 to provide an SM2 signature corresponding to the data transmission. The SM2 collection request may include details of the data transmission received in step 1318.
[0183] In 1328, the credential extension unit 1304 can generate an SM2 signature. For example, the credential extension unit 1304 can generate an SM2 signature for data transmission based on data transmission details. An SM2 signature can be issued based on the data transmission details.
[0184] Figure 14 A second portion of a signal flow 1300 for enhanced authentication of data transmission is shown according to some embodiments. Specifically, the signal flow 1300 may proceed from 1328 to 1402.
[0185] In step 1402, the credential extension unit 1304 can provide an SM2 signature to the user information application 1302. For example, the credential extension unit 1304 can transmit the SM2 signature generated in step 1328 to the user information application 1302. The SM2 signature can be issued at the data transmission details.
[0186] In step 1404, the user information application 1302 may submit authentication result information to the service device 1308. The submitted authentication result information may include a data transmission identifier corresponding to the data transmission and / or an authentication result. The authentication result may include an encrypted PIN and / or an SM2 signature on the data transmission details. The user information application 1302 may transmit the authentication result information to the service device 1308.
[0187] In 1406, the serving device 1308 can verify the SM2 signature. For example, the serving device 1308 can verify the SM2 signature received in 1404. The serving device 1308 can compare the SM2 signature received in 1404 with a stored SM2 signature corresponding to user-authorized data transmission to determine that data transmission is authorized.
[0188] In 1408, service device 1308 can verify the PIN. For example, service device 1308 can verify the PIN received in 1404. Service device 1308 can decrypt the encrypted PIN received in 1404. Service device 1308 can compare the PIN with a stored PIN corresponding to a user authorized to perform data transmission to determine that the data transmission is authorized.
[0189] If both the SM2 signature verification at 1406 and the PIN verification at 1408 are successful, the service device 1308 may transmit an indication to the user information application 1302 indicating that the data transmission is authorized. If either the SM2 signature verification at 1406 or the PIN verification at 1408 fails, the signaling flow 1300 may perform additional authentication operations and / or transmit an indication to the user information application indicating that the data transmission is unauthorized. In the illustrated embodiment, PIN verification has failed, and additional authentication operations are performed for the PIN.
[0190] In 1410, service device 1308 may transmit an authentication mechanism retry request to the user information application. The authentication mechanism retry request may include the authentication mechanism to be performed and / or the reason for performing the authentication mechanism. In an illustrated embodiment, the authentication mechanism to be performed may be PIN collection, and the reason provided may be that the PIN verification performed in 1408 has failed.
[0191] In 1412, the user information application 1302 may collect the PIN of the device's user. For example, the user information application 1302 may cause a user interface to be displayed on the display of the device executing the user information application 1302, wherein the user interface requests the user to enter a PIN. The user information application 1302 may recognize the PIN entered by the user.
[0192] In 1414, the user information application 1302 can encrypt the PIN. For example, the user information application 1302 can encrypt the PIN identified in 1412. The user information application 1302 can encrypt the PIN based on the device encryption certificate and / or a temporary public key.
[0193] In step 1416, the user information application 1302 may submit authentication result information to the service device 1308. The submitted authentication result information may include a data transmission identifier corresponding to the data transmission and / or authentication result. The authentication result may include an encrypted PIN. The user information application 1302 may transmit the authentication result information to the service device 1308.
[0194] In step 1418, service device 1308 can verify the PIN. For example, service device 1308 can verify the PIN received in step 1416. Service device 1308 can decrypt the encrypted PIN received in step 1416. Service device 1308 can compare the PIN with a stored PIN corresponding to a user authorized to perform data transmission to determine that the data transmission is authorized. In the illustrated embodiment, service device 1308 can determine that the PIN verification was successful.
[0195] In 1420, service device 1308 may transmit an instruction to user information application 1302 indicating that data transmission will be performed. For example, service device 1308 may transmit an instruction indicating that data transmission will be performed based on successful SM2 signature verification in 1406 and successful PIN verification in 1416. Although SM2 signature verification and PIN verification are shown for enhanced authentication, it should be understood that SM2 signature verification or PIN verification may be implemented separately in other embodiments. Furthermore, different authentication methods may be utilized in other embodiments, such as requesting user confirmation of data transmission and / or redirecting the user to a credentials application (such as credentials application 206). Figure 2 ) and / or credentials application 302 ( Figure 3 )).
[0196] Figure 15 The first part of an exemplary process 1500 for displaying a QR code for data transmission, according to some embodiments, is shown. Process 1500 can be performed by a device, such as device 102 ( Figure 1 ) and / or equipment 200 ( Figure 2 The order of operations described in process 1500 (or any process described herein) is not intended to be construed as limiting, and any number of the operations may be performed in any order and / or in parallel combination to implement the process.
[0197] In 1502, the device can determine that the QR code has been stored for a time longer than a time threshold. For example, the device can determine one or more QR codes stored on the device (such as those stored in memory 208). Figure 2 The QR code 210 in ) Figure 2 The time period longer than the time threshold has already been stored. The time threshold can be predefined, such as the time threshold described throughout this disclosure. In some embodiments, 1502 may be omitted.
[0198] In step 1504, the device can remove the QR code. For example, the device can remove one or more QR codes identified in step 1502 from the device. The device can remove the one or more QR codes at least in part based on the fact that the one or more QR codes have been stored for a period longer than a time threshold. In some implementations, step 1504 can be omitted.
[0199] In step 1506, the device may determine that the number of QR codes is less than a threshold. For example, the device may determine that the number of QR codes stored on the device is less than a threshold number of QR codes. The threshold number of QR codes may define a minimum number of QR codes to be stored on the device. The threshold number of QR codes may be determined according to the methods described throughout this disclosure for determining the threshold number of QR codes. In some embodiments, step 1506 may be omitted.
[0200] In 1508, the device can determine that it does not have connectivity. For example, the device can determine that it does not have connectivity with QR-enabled devices (such as QR-enabled device 108). Figure 1 Connectivity. Because the device lacks connectivity to QR-enabled devices, it may be unable to request an additional QR code. In some implementations, step 1508 may be omitted.
[0201] In step 1510, the device may store a QR code. For example, the device may store one or more QR codes as determined in step 1502. The device may store one or more QR codes at least in part based on the determination in step 1508 that the device does not have connectivity with a QR configuration device. The device may store the one or more QR codes at least until the device has connectivity with a QR configuration device. Once the device establishes a connection with a QR configuration device, the device may request an additional QR code from the QR configuration device and / or remove the one or more QR codes. In some embodiments, step 1510 may be omitted.
[0202] In 1512, the device may request multiple QR codes. For example, the device may request multiple QR codes provided by a QR configuration device. The QR configuration device may provide the multiple QR codes at least in part based on the fact that multiple QR response codes are being requested. In some embodiments, the device may request the multiple QR codes at least in part based on the fact that one or more QR codes have been stored for a time longer than a time threshold (which can be determined in 1502). In some embodiments, 1512 may be omitted.
[0203] In 1514, the device may indicate the amount of the QR code. For example, the device may indicate the amount of the QR code to be included in a plurality of QR codes to be provided by the QR configuration device. The amount of the QR code to be provided by the QR configuration device may be determined according to any of the methods for determining the amount of QR code to be provided described throughout this disclosure. In some embodiments, 1514 may be omitted.
[0204] In 1516, the device can receive the plurality of QR codes. For example, the device can receive a plurality of QR codes associated with an account. The device can receive the plurality of QR codes from a QR configuration device. Each of the plurality of QR response codes can be individually encrypted as described throughout this disclosure, such that each of the plurality of QR codes is configured to be decrypted once.
[0205] In 1518, the device can receive a request to display a QR code. For example, the device can receive a request to display one of a plurality of QR codes. The display of the QR code can be configured to enable data transmission.
[0206] In 1520, the device can perform authorization operations. For example, the device can perform authorization operations for authorizing an account based at least in part on a request to display a QR code. Authorization operations may include authenticating a user of the device according to methods for performing authentication operations (such as via biometric information) as described throughout this disclosure in some embodiments. Authentication operations can verify that the user is authorized to perform data transfers with the account.
[0207] Figure 16 The second part of an exemplary process 1500 for displaying a QR code for data transmission, according to some embodiments, is shown. Process 1500 can be obtained from... Figure 15 The indicated 1522 advances to Figure 16 1522 shown.
[0208] In step 1602, the device can determine whether authorization has been performed. For example, the device can determine whether authorization has been performed for an account. The device can determine whether authorization has been performed based on the authorization operation in step 1520. In some implementations, step 1602 can be omitted, such as when the authorization operation in step 1520 fails.
[0209] In 1604, the device can determine whether to decrypt the QR code. For example, the device can determine whether to decrypt the QR code based at least in part on the authorization of the account from 1602.
[0210] In 1606, the device can decrypt the QR code. For example, the device can determine to decrypt the QR code based at least in part on authorization implemented for the account. In some implementations, a key stored on the device's secure element (such as one stored on secure element 212) can be utilized. Figure 2 The key 214 on ) Figure 2 The QR code is decrypted using a 1606 cipher. These multiple QR codes can be stored separately from the secure element. In some implementations, 1606 can be omitted.
[0211] In 1608, the device can determine whether to display the QR code. For example, the device can determine whether to display the QR code on the device's display based at least in part on whether it is determined that the quick response code needs to be decrypted.
[0212] In 1610, the device can display a QR code. For example, the device can display a QR code (such as QR code 104) on the device's display. Figure 1 The device may display a QR code, at least in part, based on the determination in 1608 that a QR code should be displayed. A remote device may be configured to scan the QR code and initiate data transmission. In some implementations, 1610 may be omitted, such as when it is determined in 1608 that a QR code should not be displayed.
[0213] In step 1612, the device may determine a first timestamp. For example, the device may determine a first timestamp indicating the first time the QR code was first displayed on the device's display. In some embodiments, step 1612 may be omitted.
[0214] In section 1614, the device may provide a first timestamp to the service device. For example, the device may transmit the first timestamp to the service device, which is configured to compare the first timestamp with a second timestamp indicating a second time when the QR code was scanned to determine whether the QR code has been used within an allowed time period. In some embodiments, section 1614 may be omitted.
[0215] In 1616, the device may receive an authorization request. For example, the device may receive an authorization request for further authorization operations for data transmission received from the serving device. In some embodiments, the further authorization operations may include enhanced authentication as described throughout this disclosure. In some embodiments, 1616 may be omitted.
[0216] In step 1618, the device can identify data used for further authorization operations. In some embodiments, the data to be identified may be defined by the service device. In some embodiments, step 1618 may be omitted.
[0217] In section 1620, the device may provide this data to the service device. For example, the device may provide the service device with data for further authorization, wherein the data for further authorization operations can be configured to determine the permissions required to complete the data transfer. In some implementations, section 1620 may be omitted.
[0218] Figure 17 The first part of another exemplary process 1700 for displaying a QR code for data transmission, according to some embodiments, is shown. Process 1700 can be performed by a device, such as device 102 ( Figure 1 ) and / or equipment 200 ( Figure 2The order of operations described in process 1700 (or any process described herein) is not intended to be construed as limiting, and any number of the operations may be performed in any order and / or in parallel combination to implement the process.
[0219] In 1702, the device may determine that the number of QR codes is less than a threshold number. For example, the device may determine that the number of QR codes stored in memory is less than a threshold number of QR codes. The threshold number of QR codes may be a minimum number of QR codes to be stored in memory. The threshold number of QR codes may be defined according to the methods described throughout this disclosure for limiting the threshold number of QR codes. In some embodiments, 1702 may be omitted.
[0220] In section 1704, the device may provide a request. For example, the device may provide a request to a quick-response configuration device associated with multiple QR codes, the request being based at least in part on the premise that the number of QR codes is less than a threshold number of QR codes to provide additional QR codes. In some implementations, section 1704 may be omitted.
[0221] In 1706, the device may indicate the number of additional QR codes. For example, the device may indicate the number of additional QR codes to be provided by a QR configuration device. In some embodiments, 1706 may be omitted.
[0222] In step 1708, the device can determine that a portion of the QR code has been stored for a time longer than a time threshold. For example, the device can determine that a portion of the plurality of QR codes has been stored for a time longer than the time threshold. The time threshold can be defined according to any method described throughout this disclosure for defining the time threshold. In some embodiments, step 1708 can be omitted.
[0223] In 1710, the device may remove that portion of the QR code. For example, the device may remove that portion of the plurality of QR codes from memory based at least in part on determining that the portion of the plurality of QR codes has been stored for a period longer than a time threshold. In some embodiments, 1710 may be omitted.
[0224] In 1712, the device can receive authorization requests. For example, the device can receive an authorization request to display one of the multiple QR codes. The display of the QR codes can be configured to enable data transfer associated with an account.
[0225] In 1714, the device can perform authorization operations. For example, the device can perform authorization operations for authorizing an account. In some embodiments, the authorization operation may include performing authentication (such as biometric authentication) to verify that the user of the device is the user authorized to perform data transfers with that account. The authorization operation may also include determining, based on the authentication of the user of the device, that the user is authorized to perform data transfers.
[0226] In 1716, the device can decrypt the QR code. For example, the device can decrypt the QR code at least partially based on authorization implemented for the account in 1714. Authorization can be implemented by determining that the user is authorized to perform data transfer. The device can be limited to decrypting a single QR code at a time, at least partially based on the fact that the multiple QR codes are individually encrypted. In some embodiments, QR code decryption may include utilizing a key stored on the device's secure element (such as one stored on secure element 212). Figure 2 The key 214 on ) Figure 2 To decrypt the QR codes, the multiple QR codes are stored separately from the secure element.
[0227] In version 1718, the device can display a decrypted QR code. For example, the device can display a decrypted QR code from version 1716 on its display. This QR code can be configured to be scanned by a remote device to initiate data transmission.
[0228] Figure 18 The second part of an exemplary process 1700 for displaying a QR code for data transmission, according to some embodiments, is shown. Process 1700 can be obtained from... Figure 17 The 1720 shown advances to Figure 18 1720 shown.
[0229] In step 1802, the device may determine a first timestamp. For example, the device may determine a first timestamp at the first moment when a QR response indicative of decryption begins to be displayed on the device's display, such as the display of the QR code in step 1718. In some embodiments, step 1802 may be omitted.
[0230] In step 1804, the device may provide a first timestamp to the service device. For example, the device may provide the first timestamp to the service device associated with the plurality of QR codes. The service device may be configured to compare the first timestamp with a second timestamp indicating a second time when the QR code was scanned to determine whether the QR code has been used within an allowed time period. The allowed time period may be defined according to any method described throughout this disclosure for defining the allowed time period. In some embodiments, the allowed time period may be three minutes. In some embodiments, step 1804 may be omitted.
[0231] In step 1806, the device may receive a request for further authorization operations. For example, the device may receive a request for further authorization operations for data transmission received from a service device associated with the plurality of QR codes. In some embodiments, the further authorization operations may include enhanced authentication as described throughout this disclosure. In some embodiments, step 1806 may be omitted.
[0232] In step 1808, the device can identify data for further authorization operations. In some implementations, the data to be identified may be defined by the service device. In some implementations, step 1808 may be omitted.
[0233] In step 1810, the device may provide this data to the service device. For example, the device may provide the service device with the data identified in step 1808 for further authorization operations. The data used for further authorization operations may be configured to determine the permissions required to complete the data transfer. In some implementations, step 1810 may be omitted.
[0234] Figure 19 An exemplary process 1900 for displaying a QR code for data transmission, according to some embodiments, is shown. Process 1900 can be performed by a device, such as device 102 (…). Figure 1 ) and / or equipment 200 ( Figure 2 The order of operations described in process 1900 (or any process described herein) is not intended to be construed as limiting, and any number of the operations may be performed in any order and / or in parallel combination to implement the process.
[0235] In 1902, the device can receive a request to display a QR code. For example, the device can receive a request to display a QR code to initiate data transmission.
[0236] In 1904, the device can perform authorization operations. For example, the device can perform authorization operations to authorize the use of a QR code. Authorization operations may include performing authentication operations (such as biometric authentication) to determine that the user of the device is an authorized user of the QR code.
[0237] In 1906, the device can decrypt QR codes. For example, the device can decrypt a QR code among multiple QR codes stored on the device, at least partially based on an authorized operation. Because these multiple QR codes are individually encrypted, the device cannot decrypt other QR codes among these multiple QR codes, at least partially based on an authorized operation.
[0238] In 1908, the device could display a QR code. For example, the device could display a QR code (such as QR code 104) on its display. Figure 1 You can scan this QR code to initiate data transmission.
[0239] In step 1910, the device can prevent the QR code from being displayed again. For example, the device can prevent the QR code from being displayed again on the device's display. Specifically, the QR code can be a one-time QR code, wherein the device can prevent the QR code from being displayed again after it has been displayed for the first time. In some embodiments, step 1910 can be omitted.
[0240] In section 1912, the device may determine that the number of valid QR codes is less than a threshold number. For example, the device may determine that the number of valid QR codes among a plurality of QR codes stored on the device is less than a threshold number of QR codes. Whether a QR code is valid or invalid can be determined according to the methods for determining validity as described throughout this disclosure. Furthermore, the threshold number of QR codes may be the minimum number of QR codes to be stored by the device, and the threshold number of QR codes can be defined according to any method for defining the threshold number of QR codes as described throughout this disclosure. In some embodiments, section 1912 may be omitted.
[0241] In step 1914, the device may request an additional QR code. For example, the device may request an additional QR code from the QR configuration device based at least in part on the fact that the number of valid QR codes is less than a threshold number of QR codes. In some implementations, step 1914 may be omitted.
[0242] In 1916, the device can determine that the QR code has been stored for a time longer than a time threshold. For example, the device can determine that one or more of the plurality of QR codes have been stored on the device for a time longer than the time threshold. The time threshold can be defined according to any method described throughout this disclosure for defining the time threshold. In some embodiments, 1916 may be omitted.
[0243] In step 1918, the device may remove these QR codes from the storage device. For example, the device may remove one or more of these QR codes from the storage device, at least in part, based on the determination that one or more of the QR codes identified in step 1916 have been stored on the device for a period longer than a time threshold. In some embodiments, step 1918 may be omitted.
[0244] Figure 20 The first part of an exemplary process 2000 for performing a credential extension on a device to collect information, according to some embodiments, is shown. Process 2000 can be executed by a device, such as device 102 (…). Figure 1 ) and / or equipment 200 ( Figure 2 The credential extension executed on the device may include credential extension 204. Figure 2 ) and / or credential extension section 1004 ( Figure 10 One or more of the features of the process. The order of operations describing process 2000 (or any process described herein) is not intended to be construed as limiting, and any number of the operations may be performed in any order and / or in parallel combination to implement the process.
[0245] In 2002, the device can detect an indication of information to be collected. For example, the device can detect an indication received from a service device of information to be collected by the Credential Extension Unit. The Credential Extension Unit can collect information based at least in part on this indication from the service device. In some embodiments, 2002 may be omitted.
[0246] In section 2004, the device can detect user indications for acceptable information. For example, the device can detect user indications for acceptable information collected during data transmission. The information collected by the credential extension may be limited by the acceptable information. In some embodiments, section 2004 may be omitted.
[0247] In section 2006, the device can detect instructions for security procedures. For example, the device can detect instructions for security procedures received from a service device for the security of information collected by the Credentials Extension Unit. In some implementations, section 2006 may be omitted.
[0248] In 2008, the device can detect the selection of credentials. For example, the device can detect the selection of credentials within a user information application running on the device. These credentials can be used to perform data transfer. The user of the device can select the credentials to use to perform the data transfer.
[0249] In version 2010, the device can display a QR code. For example, the device can display the QR code on its display. This QR code can be scanned by a remote device to initiate data transmission. Information collected by the credential extension unit may be related to the display of the QR code. In some implementations, version 2010 may be omitted.
[0250] In 2012, the device can execute a Credential Extension. For example, the device can execute the Credential Extension within a user information application running on the device. The Credential Extension can collect authorization information for data transmission. The Credential Extension can be sandboxed within the user information application, wherein the sandboxing of the Credential Extension can be configured to restrict the privileges of the Credential Extension to authorized operations within the user information application.
[0251] In 2014, the device may display an indication that a credential extension is being performed. For example, the device may display an indication on its display that a credential extension is being performed to collect information, at least in part based on the execution of the credential extension. In some embodiments, this indication may include an indication that information collection is in progress, such as indication 106 (…). Figure 1 In some implementations, 2014 may be omitted.
[0252] In 2016, the device can collect information related to data transmission. For example, a credential extension unit running on the device can collect information related to data transmission for authorizing data transmission. The information collected by the credential extension unit can be defined based on instructions detected in 2002 and / or user instructions detected in 2004.
[0253] In 2018, the device can generate a bundle. For example, a Credential Extensions (CLE) function running on the device can generate a bundle containing information collected by the CLE in 2016 by applying a security procedure indicated in 2006. The security procedure prevents the data within the bundle from being accessed by user information applications. In some embodiments, the application of the security procedure may include encryption of the bundle. In some embodiments, 2018 may be omitted.
[0254] In 2020, the device can provide this information to the service device. For example, a credential extension unit running on the device can provide the service device corresponding to the credential with information collected by the credential extension unit for authorized data transfer.
[0255] Figure 21 The second part of an exemplary process 2000 for performing a credential extension on a device to collect information, according to some embodiments, is shown. Process 2000 can be accessed from... Figure 20 The 2022 progress shown Figure 21 2022 shown.
[0256] In 2102, the device can detect the payload. For example, a credential extension executed on the device can detect the payload associated with data transmission. The payload may include information collected for a step-by-step authorization procedure according to some of the methods described throughout this disclosure. In some embodiments, 2102 may be omitted.
[0257] In step 2104, the device may use SM2 signature to sign the payload. For example, a credential extension unit executing on the device may use SM2 signature to sign the payload detected in step 2102. In some embodiments, step 2104 may be omitted.
[0258] In 2106, the device may provide a signed payload to the service device. For example, a credential extension executed on the device may provide a signed payload to the service device for authorization. In some embodiments, 2106 may be omitted.
[0259] Figure 22 The first part of another exemplary process 2200 for performing a credential extension on a device to collect information, according to some embodiments, is shown. Process 2200 can be executed by a device, such as device 102 ( Figure 1 ) and / or equipment 200 ( Figure 2 The credential extension executed on the device may include credential extension 204. Figure 2 ) and / or credential extension section 1004 ( Figure 10 One or more of the features of ). The order of operations describing process 2200 (or any process described herein) is not intended to be construed as limiting, and any number of said operations may be performed in any order and / or in parallel combination to implement said process.
[0260] In 2202, the device can detect user indications for acceptable information. For example, the device can detect user indications for acceptable information collected during data transmission. The information collected by the credential extension unit during data transmission may be limited by the acceptable information. In some embodiments, 2202 may be omitted.
[0261] In 2204, the device may detect an indication of information to be collected. For example, the device may detect an indication of information to be collected by the Credential Extension Unit. This indication may be received from the service device. The Credential Extension Unit may collect information based at least in part on this indication from the service device. In some embodiments, 2204 may be omitted.
[0262] In 2206, the device can detect instructions for security procedures. For example, the device can detect instructions for security procedures received from a service device for the security of information collected by the credential extension unit. In some embodiments, 2206 may be omitted.
[0263] In 2208, the device can detect the selection of credentials. For example, the device can detect the selection of a credential from one or more credentials within a user information application. This credential can be used to perform data transfer. For example, a user of the device can select a credential from one or more credentials maintained by a user information application executed by the device.
[0264] In 2210, the device can display QR codes. For example, the device can display QR codes (such as QR code 104). Figure 1 The QR code is displayed on the device's screen. It can be scanned by a remote device to initiate data transmission. In some embodiments, information collected by the credential extension unit may be related to the display of the QR code. In some embodiments, 2210 may be omitted.
[0265] In 2212, the device can execute a credential extension. For example, the device can execute the credential extension within a user information application running on the device. The credential extension can collect information for authorizing data transfer. The credential extension can be sandboxed within the user information application, which restricts the privileges of the credential extension to authorized operations within the user information application.
[0266] In 2214, the device may collect information relating to data transmission. For example, a credential extension unit performed by the device may collect information relating to data transmission for authorizing data transmission. In some embodiments, the information collected by the credential extension unit may be defined based on the user's indication of the information to be collected in 2204 and / or the acceptable information in 2202.
[0267] In 2216, the device can prevent screenshots and screen recording. For example, a credential extension performed by the device can prevent screenshots and screen recording when a QR code is displayed. In some embodiments, 2216 can be omitted.
[0268] In 2218, the device may generate a bundle. For example, a credential extension unit executed by the device may generate a bundle containing information collected by the credential extension unit by applying a security program (such as the security program indicated in 2206). The security program may prevent the data within the bundle from being accessed by a user information application executed by the device. In some embodiments, the application of the security program may include encryption of the bundle. In some embodiments, 2218 may be omitted.
[0269] In 2220, the device may provide this information to the service device. For example, the credential extension unit performed by the device may provide the service device corresponding to the credential selected in 2208 with the information collected by the credential extension unit for authorized data transmission.
[0270] Figure 23 The second part of an exemplary process 2200 for performing a credential extension on a device to collect information, according to some embodiments, is shown. The process 2200 can be accessed from... Figure 22 The 2222 shown advances to Figure 23 2222 shown.
[0271] In 2302, the device may detect a payload. For example, a credential extension executed on the device may detect a payload associated with data transmission. The payload may include information collected for a step-by-step authorization procedure according to some of the methods described throughout this disclosure. In some embodiments, 2302 may be omitted.
[0272] In 2304, the device may use SM2 signature to sign the payload. For example, a credential extension unit executing on the device may use SM2 signature to sign the payload detected in 2302. In some embodiments, 2304 may be omitted.
[0273] In section 2306, the device may provide a signed payload to the service device. For example, a credential extension executed on the device may provide a signed payload to the service device for authorization. In some embodiments, section 2306 may be omitted.
[0274] Figure 24 Another exemplary process 2400 for performing a credential extension on a device to collect information, according to some embodiments, is shown. Process 2400 can be executed by a device, such as device 102 ( Figure 1 ) and / or equipment 200 ( Figure 2 The credential extension executed on the device may include credential extension 204. Figure 2 ) and / or credential extension section 1004 ( Figure 10 One or more of the features of ). The order of operations describing process 2400 (or any process described herein) is not intended to be construed as limiting, and any number of said operations may be performed in any order and / or in parallel combination to implement said process.
[0275] In 2402, the device can detect an indication of information to be collected. For example, the device can detect an indication of information to be collected by the Credential Extension Unit. This indication can be received from the service device. The Credential Extension Unit can collect information based at least in part on this indication from the service device. In some embodiments, 2402 can be omitted.
[0276] In section 2404, the device may detect an instruction for a security procedure. For example, the device may detect an instruction for a security procedure received from a service device for the security of information. In some implementations, section 2404 may be omitted.
[0277] In 2406, the device can detect the selection of credentials. For example, the device can detect the selection of credentials within a user information application executed by the device. These credentials can be used to perform data transfer. The user of the device can select credentials from one or more credentials managed by the user information application.
[0278] In 2408, the device can execute a credential extension. For example, the device can execute the credential extension within a user information application to collect information for data transmission. The credential extension can be sandboxed within the user information application, which restricts the privileges of the credential extension to authorized operations within the user information application.
[0279] In 2410, the device may display a QR code. For example, the device may display the QR code based at least in part on the selection of credentials in 2406. This QR code can be scanned by a remote device to initiate data transmission. Information collected by the credential extension unit may be related to the display of the QR code. In some embodiments, 2410 may be omitted.
[0280] In 2412, the device may collect information related to data transmission. For example, a credential extension unit performed by the device may collect information related to data transmission for authorizing data transmission. In some embodiments, the information collected by the credential extension unit may be defined by an indication of information to be collected detected in 2402.
[0281] In 2414, the device can generate a bundle. For example, the device can generate a bundle containing information collected by the credential extension unit by applying the security procedure indicated in 2404. The security procedure prevents the data within the bundle from being accessed by a user information application executed by the device. In some embodiments, 2414 may be omitted.
[0282] In 2416, the device can provide this information to the service device. For example, a credential extension unit executed by the device can provide the service device corresponding to the credential with the information collected by the credential extension unit.
[0283] Figure 25 An exemplary UE 2500 according to some implementations is shown. The UE 2500 can be any mobile or non-mobile computing device, such as a mobile phone, computer, tablet, industrial wireless sensors (e.g., microphones, carbon dioxide sensors, pressure sensors, humidity sensors, thermometers, motion sensors, accelerometers, laser scanners, fluid level sensors, inventory sensors, voltmeters / ammeters, actuators, etc.), video surveillance / monitoring devices (e.g., cameras, camcorders, etc.), wearable devices (e.g., smartwatches), and loosely coupled IoT devices. In some implementations, the UE 2500 can be a RedCap UE or an NR-Light UE.
[0284] The UE 2500 may include a processor 2504, an RF interface circuit 2508, a memory / storage device 2512, a user interface 2516, a sensor 2520, a drive circuit 2522, a power management integrated circuit (PMIC) 2524, an antenna structure 2526, and a battery 2528. The components of the UE 2500 may be implemented as integrated circuits (ICs), portions of integrated circuits, discrete electronic devices or other modules, logic components, hardware, software, firmware, or combinations thereof. Figure 25 The block diagram is intended to show a high-level view of some of the components of the UE 2500. However, some of the components shown may be omitted, additional components may be present, and different arrangements of the components shown may occur in other specific implementations.
[0285] The components of UE 2500 can be coupled to various other components via one or more interconnects 2532, which can represent any type of interface, input / output, bus (local, system, or extension), transmission line, trace, optical connector, etc., allowing various circuit components (on common or different chips or chipsets) to interact with each other.
[0286] Processor 2504 may include processor circuitry such as baseband processor circuitry (BB) 2504A, central processing unit circuitry (CPU) 2504B, and graphics processing unit circuitry (GPU) 2504C. Processor 2504 may include any type of circuitry or processor circuitry that executes or otherwise operates computer-executable instructions (such as program code, software modules, or functional processes from memory / storage device 2512) to cause UE 2500 to perform the operations described herein.
[0287] In some implementations, the baseband processor circuit 2504A can access the communication protocol stack 2536 in the memory / storage device 2512 to communicate over a 3GPP-compliant network. Generally, the baseband processor circuit 2504A can access the communication protocol stack to perform the following operations: user plane functions at the PHY, MAC, RLC, PDCP, SDAP, and PDU layers; and control plane functions at the PHY, MAC, RLC, PDCP, RRC, and non-access layers. In some implementations, PHY layer operations may, in addition to / optionally, be performed by components of the RF interface circuit 2508.
[0288] The baseband processor circuit 2504A can generate or process baseband signals or waveforms carrying information in a 3GPP-compliant network. In some implementations, the waveforms used for NR can be based on cyclic prefix OFDM (CP-OFDM) in the uplink or downlink, and Discrete Fourier Transform Extended OFDM (DFT-S-OFDM) in the uplink.
[0289] Memory / storage device 2512 may include one or more non-transitory computer-readable media, including instructions (e.g., communication protocol stack 2536) that can be executed by one or more processors in processor 2504 to cause UE 2500 to perform the various operations described herein. Memory / storage device 2512 includes any type of volatile or non-volatile memory that can be distributed throughout UE 2500. In some embodiments, some memory / storage devices 2512 may be located on processor 2504 itself (e.g., L1 cache and L2 cache), while other memory / storage devices 2512 may be located external to processor 2504 but accessible via a memory interface. Memory / storage device 2512 may include any suitable volatile or non-volatile memory, such as, but not limited to, dynamic random access memory (DRAM), static random access memory (SRAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, solid-state memory, or any other type of memory device technology.
[0290] The RF interface circuitry 2508 may include transceiver circuitry and a radio frequency front-end module (RFEM), which allows the UE 2500 to communicate with other devices via a radio access network. The RF interface circuitry 2508 may include various components arranged in the transmit or receive path. These components may include, for example, switches, mixers, amplifiers, filters, synthesizer circuitry, control circuitry, etc.
[0291] In the receiving path, the RFEM can receive the radiated signal from the air interface via antenna structure 2526 and continue to filter and amplify the signal (using a low-noise amplifier). This signal can be provided to the receiver of the transceiver, which downconverts the RF signal into a baseband signal that is provided to the baseband processor of processor 2504.
[0292] In the transmission path, the transceiver's transmitter upconverts the baseband signal received from the baseband processor and provides the RF signal to the RFEM. The RFEM amplifies the RF signal using a power amplifier before it is radiated across the air interface via antenna 2526.
[0293] In various implementations, the RF interface circuit 2508 can be configured to transmit / receive signals in a manner compatible with NR access technology.
[0294] Antenna 2526 may include antenna elements to convert electrical signals into radio waves for propagation through the air and to convert received radio waves back into electrical signals. These antenna elements may be arranged in one or more antenna panels. Antenna 2526 may have omnidirectional, directional, or combinations thereof antenna panels to enable beamforming and multiple-input / multiple-output communication. Antenna 2526 may include microstrip antennas, printed antennas fabricated on the surface of one or more printed circuit boards, patch antennas, phased array antennas, etc. Antenna 2526 may have one or more panels designed for a specific frequency band included in FR1 or FR2.
[0295] User interface circuitry 2516 includes various input / output (I / O) devices designed to enable users to interact with UE 2500. User interface circuitry 2516 includes input device circuitry and output device circuitry. Input device circuitry includes any physical or virtual means for accepting input, particularly including one or more physical or virtual buttons (e.g., a reset button), a physical keyboard, a keypad, a mouse, a touchpad, a touchscreen, a microphone, a scanner, a headset, etc. Output device circuitry includes any physical or virtual means for displaying information or otherwise conveying information (such as sensor readings, actuator positions, or other similar information). Output device circuitry may include any number or combination of audio or visual displays, particularly including one or more simple visual outputs / indicators (e.g., binary status indicators, such as light-emitting diodes "LEDs") and multi-character visual outputs, or more complex outputs, such as display devices or touchscreens (e.g., liquid crystal displays (LCDs), LED displays, quantum dot displays, projectors, etc.), wherein the output of characters, graphics, multimedia objects, etc., is generated or produced by the operation of UE 2500.
[0296] Sensor 2520 may include devices, modules, or subsystems designed to detect events or changes in their environment and transmit information about the detected events (sensor data) to other devices, modules, subsystems, etc. Examples of such sensors include, in particular: inertial measurement units including accelerometers, gyroscopes, or magnetometers; microelectromechanical systems (MEMS) or nanoelectromechanical systems (NEMS) including triaxial accelerometers, triaxial gyroscopes, or magnetometers; level sensors; flow sensors; temperature sensors (e.g., thermistors); pressure sensors; barometric pressure sensors; gravimeters; altimeters; image capture devices (e.g., cameras or lensless aperture sensors); light detection and ranging sensors; proximity sensors (e.g., infrared radiation detectors, etc.); depth sensors; ambient light sensors; ultrasonic transceivers; microphones or other similar audio capture devices; etc.
[0297] The driving circuitry 2522 may include software and hardware elements for controlling specific devices embedded in, attached to, or otherwise communicatively coupled to the UE 2500. The driving circuitry 2522 may include various drivers that allow other components to interact with or control various input / output (I / O) devices that may exist within or be connected to the UE 2500. For example, the driving circuitry 2522 may include: a display driver for controlling and allowing access to a display device; a touchscreen driver for controlling and allowing access to a touchscreen interface; a sensor driver for obtaining sensor readings from the sensor circuitry 2520 and controlling and allowing access to the sensor circuitry 2520; a driver for obtaining actuator positions of electromechanical components or controlling and allowing access to electromechanical components; a camera driver for controlling and allowing access to an embedded image capture device; and an audio driver for controlling and allowing access to one or more audio devices.
[0298] The PMIC 2524 manages the power supplied to various components of the UE 2500. Specifically, relative to the processor 2504, the PMIC 2524 controls power selection, voltage scaling, battery charging, or DC-DC conversion.
[0299] In some implementations, the PMIC 2524 can control or otherwise become part of various power-saving mechanisms of the UE 2500. For example, if the platform UE is in the RRC_Connected state, where it remains connected to the RAN node as it anticipates receiving traffic soon, it can enter a state known as Discontinuous Receive Mode (DRX) after a period of inactivity. During this state, the UE 2500 can power down for short intervals to conserve power. If there is no data traffic activity over a longer period, the UE 2500 can transition to the RRC_Idle state, where it is disconnected from the network and does not perform operations such as channel quality feedback or handover. The UE 2500 enters a very low-power state and performs paging, in which it periodically wakes up again to listen to the network before powering down again. The UE 2500 may not receive data in this state; to receive data, it may need to transition back to the RRC_Connected state. Additional power-saving modes can prevent the device from using the network for longer than the paging interval (ranging from a few seconds to several hours). During this period, the device is completely unable to connect to the network and can be completely powered off. Any data sent during this time will result in significant latency, which is assumed to be acceptable.
[0300] Battery 2528 can power UE 2500, but in some examples, UE 2500 may be mounted in a fixed location and may have a power source coupled to the mains. Battery 2528 may be a lithium-ion battery, a metal-air battery such as a zinc-air battery, an aluminum-air battery, a lithium-air battery, etc. In some specific implementations, such as in vehicle-based applications, battery 2528 may be a typical lead-acid automotive battery.
[0301] As is widely recognized, the use of personally identifiable information should comply with privacy policies and practices that are generally accepted to meet or exceed industry or governmental requirements for protecting user privacy. Specifically, personally identifiable information data should be managed and processed to minimize the risk of unintentional or unauthorized access or use, and the nature of authorized use should be clearly explained to users.
[0302] For one or more embodiments, at least one of the components shown in one or more of the foregoing figures may be configured to perform one or more operations, techniques, processes, or methods as described in the Examples section below. For example, the baseband circuitry described above in conjunction with one or more of the foregoing figures may be configured to operate according to one or more of the examples below. Similarly, circuitry associated with the UE, base station, network element, etc., described above in conjunction with one or more of the foregoing figures may be configured to operate according to one or more of the examples shown in the Examples section below.
[0303] In some implementations, an application running on a user's device may be used to perform some or all of the operations described herein. Circuits, logic modules, processors, and / or other components may be configured to perform the various operations described herein. Those skilled in the art will understand that, depending on the specific implementation, such configuration can be accomplished through the design, setup, interconnection, and / or programming of particular components, and again, depending on the specific implementation, the configured components may be reconfigurable or not reconfigurable for different operations. For example, a programmable processor can be configured by providing appropriate executable code; a dedicated logic circuit can be configured by appropriately connecting logic gates and other circuit elements; and so on.
[0304] As described above, one aspect of the present invention is the collection, sharing, and use of data, including authentication tags and data from which those tags are derived. This disclosure contemplates that, in some instances, the collected data may include personal information data that uniquely identifies or can be used to contact or locate specific individuals. Such personal information data may include demographic data, location-based data, telephone numbers, email addresses, Twitter IDs, home addresses, data or records related to a user's health or fitness level (e.g., vital sign measurements, medication information, exercise information), date of birth, or any other identifying information or personal information.
[0305] This disclosure recognizes that the use of such personal information data in the techniques of this invention can be beneficial to users. For example, personal information data can be used to authenticate another device and vice versa to control which device ranging operations can be performed. Furthermore, this disclosure also contemplates other uses of personal information data that are beneficial to users. For example, health and fitness data can be shared to provide insights into a user's overall health status or can be used as positive feedback for individuals using technology to pursue health goals.
[0306] This disclosure assumes that entities responsible for collecting, analyzing, disclosing, transmitting, storing, or otherwise using such personal information data will comply with established privacy policies and / or privacy practices. Specifically, such entities should implement and adhere to privacy policies and practices that are generally recognized as meeting or exceeding industry or governmental requirements for maintaining the privacy and security of personal information data. Such policies should be easily accessible to users and should be updated as data collection and / or use change. Personal information from users should be collected for the entity's lawful and reasonable purposes and not shared or sold outside of these lawful uses. Furthermore, such collection / sharing should be conducted only after obtaining informed consent from users. In addition, such entities should consider taking any necessary steps to protect and safeguard access to such personal information data and ensure that others with access to such personal information data comply with their privacy policies and processes. Additionally, such entities may be subject to third-party evaluations to demonstrate their compliance with widely accepted privacy policies and practices. Furthermore, policies and practices should be adapted to the specific types of personal information data collected and / or accessed, and to applicable laws and standards, including specific considerations regarding jurisdiction. For example, in the United States, the collection or acquisition of certain health data may be governed by federal and / or state laws, such as the Health Insurance Portability and Accountability Act (HIPAA); while in other countries, health data may be subject to other regulations and policies and should be handled accordingly. Therefore, different privacy practices should be maintained for different types of personal data in each country.
[0307] Regardless of the foregoing, this disclosure also contemplates implementation schemes for users to selectively block the use or access to personal information data. That is, this disclosure contemplates providing hardware and / or software components to prevent or block access to such personal information data. For example, with regard to sharing content and performing ranging, the inventive technology can be configured to allow users to opt-in or opt-out at any time during or after registering for the service to participate in the collection of personal information data. In addition to providing opt-in and opt-out options, this disclosure envisions providing notifications related to access to or use of personal information. For example, users may be notified when downloading an application that their personal information data will be accessed, and then reminded again just before the application accesses the personal information data.
[0308] Furthermore, the purpose of this disclosure is to manage and process personal information data to minimize the risk of unintentional or unauthorized access or use. Once data is no longer needed, this risk can be minimized by limiting data collection and deleting data. Additionally, and where applicable, including in certain health-related applications, data deidentification can be used to protect user privacy. Where appropriate, deidentification can be facilitated by removing specific identifiers (e.g., date of birth, etc.), controlling the amount or characteristics of stored data (e.g., collecting location data at the city level rather than address level), controlling how data is stored (e.g., aggregating data among users), and / or other methods.
[0309] Therefore, while this disclosure broadly covers the use of personal information data to implement one or more of the various disclosed embodiments, it is also contemplated that various embodiments can be implemented without access to such personal information data. That is, various embodiments of the present invention will not be rendered inoperable due to the absence of all or part of such personal information data.
[0310] In some examples, "circuit" may refer to, be part of, or include the following: hardware components such as electronic circuits, logic circuits, processors (shared, dedicated, or grouped) or memories (shared, dedicated, or grouped) configured to provide the said functions, application-specific integrated circuits (ASICs), field-programmable devices (FPDs) (e.g., field-programmable gate arrays (FPGAs), programmable logic devices (PLDs), complex PLDs (CPLDs), high-capacity PLDs (HCPLDs), structured ASICs, or programmable system-on-chips (SoCs)), digital signal processors (DSPs), etc. In some embodiments, the circuit may execute one or more software or firmware programs to provide at least some of the said functions. The term "circuit" may also refer to a combination of one or more hardware elements and program code for performing the functions (or a combination of circuits used in an electrical or electronic system). In these embodiments, the combination of hardware elements and program code may be referred to as a particular type of circuit.
[0311] As used herein, the term "processor circuit" means, is part of, or includes the following: a circuit capable of sequentially and automatically performing a series of arithmetic or logical operations or recording, storing, or transmitting digital data. The term "processor circuit" may also refer to an application processor, baseband processor, central processing unit (CPU), graphics processing unit, single-core processor, dual-core processor, triple-core processor, quad-core processor, or any other device capable of executing or otherwise operating computer-executable instructions (such as program code, software modules, and / or functional procedures).
[0312] As used herein, the term "interface circuit" refers to, is part of, or includes a circuit that enables the exchange of information between two or more components or devices. The term "interface circuit" can refer to one or more hardware interfaces, such as buses, I / O interfaces, peripheral component interfaces, network interface cards, etc.
[0313] As used herein, the term "user equipment" or "UE" refers to equipment of a remote user that has radio communication capabilities and can describe network resources in a communication network. Furthermore, the term "user equipment" or "UE" can be considered synonymous and can be referred to as a client, mobile phone, mobile device, mobile terminal, user terminal, mobile unit, mobile station, mobile user, subscriber, user, remote station, access agent, user agent, receiver, radio equipment, reconfigurable radio equipment, reconfigurable mobile device, etc. Additionally, the term "user equipment" or "UE" can include any type of wireless / wired equipment or any computing device that includes a wireless communication interface.
[0314] As used herein, the term "computer system" means any type of interconnected electronic device, computer device, or component thereof. Additionally, the term "computer system" or "system" may refer to the various components of a computer that are communicatively coupled to each other. Furthermore, the term "computer system" or "system" may refer to multiple computer devices or multiple computing systems that are communicatively coupled to each other and configured to share computing resources or network resources.
[0315] As used herein, the term "resource" refers to physical or virtual devices, physical or virtual components within a computing environment, or physical or virtual components within a specific device, such as computer equipment, mechanical equipment, memory space, processor / CPU time, processor / CPU utilization, processor and accelerator load, hardware time or utilization, power supply, input / output operations, port or network sockets, channel / link allocation, throughput, memory utilization, storage, network, databases and applications, units of workload, etc. "Hardware resource" can refer to computing, storage, or networking resources provided by physical hardware components. "Virtualized resource" can refer to computing, storage, or networking resources provided by virtualization infrastructure to applications, devices, systems, etc. The terms "network resource" or "communication resource" can refer to resources that computer equipment / systems can access via a communication network. The term "system resource" can refer to any kind of shared entity providing services and can include computing or network resources. System resources can be considered as a coherent set of functions, network data objects, or services accessible through a server, wherein such system resources reside on a single host or multiple hosts and are clearly identifiable.
[0316] As used herein, the term "channel" refers to any tangible or intangible transmission medium used for transmitting data or data streams. The term "channel" may be synonymous or equivalent with "communication channel," "data communication channel," "transmission channel," "data transmission channel," "access channel," "data access channel," "link," "data link," "carrier," "radio frequency carrier," or any other similar term indicating a path or medium through which data is transmitted. Additionally, as used herein, the term "link" refers to a connection between two devices used for transmitting and receiving information.
[0317] As used in this article, the terms "instantiate" and "instantiate" refer to the creation of an instance. "Instance" also refers to the concrete occurrence of an object, which may occur, for example, during the execution of program code.
[0318] The term "connection" can mean that two or more elements at a common communication protocol layer have an established signaling relationship with each other through a communication channel, link, interface, or reference point.
[0319] As used herein, the term "network element" refers to physical or virtualized equipment or infrastructure used to provide wired or wireless communication network services. The term "network element" may be considered synonymous with or referred to as networked computers, network hardware, network equipment, network nodes, virtualized network functions, etc.
[0320] The term "information element" refers to a structural element that contains one or more fields. The term "field" refers to the individual content of an information element, or the data element that contains that content. An information element may include one or more additional information elements.
[0321] Although this disclosure has been described with respect to specific embodiments, it should be understood that this disclosure is intended to cover all modifications and equivalents within the scope of the following claims.
[0322] For all purposes, all patents, patent applications, publications, and specifications mentioned herein are incorporated herein by reference in their entirety. No document is acknowledged as prior art.
[0323] Accordingly, the specification and drawings should be considered illustrative rather than restrictive. However, it will be apparent that various modifications and changes may be made thereto without departing from the broader spirit and scope of this disclosure as set forth in the claims.
[0324] Other variations are within the scope of this disclosure. Therefore, although the disclosed technology is susceptible to various modifications and alternative constructions, certain exemplary embodiments are shown in the accompanying drawings and have been described in detail above. However, it should be understood that this disclosure is not intended to be limited to the specific forms disclosed, but rather is intended to cover all modifications, alternative constructions, and equivalents falling within the scope and spirit of this disclosure as defined by the appended claims.
[0325] In the context of describing the disclosed embodiments (particularly in the context of the claims below), the terms “a,” “an,” and “the,” as well as similar indicator words, shall be construed to cover both singular and plural forms, unless otherwise stated or clearly contradicted by the context. Unless otherwise stated, the terms “comprising,” “having,” “including,” and “containing” shall be construed as open-ended terms (i.e., meaning “including but not limited to”). The term “connected” is construed as including, attaching, or joining together, even if there is interference. The phrase “based on” shall be understood as open-ended and not in any way limiting, and is intended to be construed or otherwise understood as “at least partially based on” where appropriate. Unless otherwise stated herein, the description of numerical ranges herein is intended merely as a simple way of referring separately to each individual value falling within that range, and each individual value is incorporated into the specification as if separately referenced herein. All methods described herein can be performed in any suitable order, unless otherwise stated or clearly contradicted by the context. Unless otherwise stated, all examples or exemplary language (e.g., "such as") used herein are intended merely to better illustrate embodiments of this disclosure and do not limit the scope of this disclosure. No language in the specification should be construed as indicating that any unstated element is essential to the practice of this disclosure. Unless expressly indicated to the contrary, the use of "or" is intended to mean "inclusive or" rather than "exclusive or". Referring to a "first" component does not necessarily require the provision of a second component. Furthermore, unless expressly stated otherwise, referring to a "first" or "second" component does not limit the referenced component to a particular location. The term "based on" is intended to mean "at least partially based on".
[0326] Unless otherwise specifically stated, parse languages such as the phrase "at least one of X, Y, or Z" are understood in context to generally refer to items, terms, etc., which can be X, Y, or Z, or any combination thereof (e.g., X, Y, and / or Z). Therefore, such parse languages are generally not intended and should not imply that certain embodiments require the existence of at least one of X, at least one of Y, or at least one of Z. Additionally, unless otherwise specifically stated, union languages such as the phrase "at least one of X, Y, and Z" should also be understood to mean X, Y, Z, or any combination thereof, including "X, Y, and / or Z".
[0327] This document describes preferred embodiments of the present disclosure, including the best modes known to the inventors for carrying out the present disclosure. Variations of those preferred embodiments will become apparent to those skilled in the art after reading the foregoing description. The inventors expect those skilled in the art to appropriately employ such variations, and the inventors intend to practice the present disclosure in ways different from those specifically described herein. Therefore, this disclosure includes all modifications and equivalents of the subject matter recited in the appended claims, as permitted by applicable law. Furthermore, unless otherwise indicated herein or clearly contradicted by the context, this disclosure encompasses any combination of all possible variations of the foregoing elements.
[0328] All references cited in this article, including publications, patent applications and patents, are incorporated herein by reference, as each reference is individually and specifically indicated to be incorporated by reference and elaborated in the entire text.
[0329] The specific details of a particular implementation may be combined in any suitable manner or differ from those shown and described herein without departing from the spirit and scope of the implementation of the technology.
[0330] The above description of exemplary embodiments of the technology is provided for illustrative and descriptive purposes. It is not intended to be exhaustive, nor is it intended to limit the technology to the precise form described, and many modifications and variations are possible in accordance with the above teachings. This embodiment has been chosen and described to fully illustrate the principles of the technology and its practical application, thereby enabling others skilled in the art to fully utilize the technology in various embodiments and with various modifications suitable for the particular intended use.
[0331] All publications, patents and patent applications cited in this article are incorporated herein by reference in their entirety for all purposes.
[0332] Example
[0333] Further exemplary implementations are provided in the following sections.
[0334] Example 1 may include one or more non-transitory computer-readable media having instructions that, when executed by one or more processors of a device, cause the device to: receive a plurality of quick response (QR) codes associated with an account received from a quick response configuration device, each of the plurality of quick response codes being individually encrypted such that each of the plurality of quick response codes is configured to be decrypted once; receive a request to display one of the plurality of quick response codes, the display of the quick response codes being configured to enable data transmission; perform an authorization operation for authorizing the account based at least in part on the request to display the quick response codes; determine whether to decrypt the quick response codes based at least in part on the authorization of the account; and determine whether to display the quick response codes on a display of the device based at least in part on whether the quick response codes are determined to be decrypted.
[0335] Example 2 may include one or more non-transitory computer-readable media as described in Example 1, wherein the instructions, when executed by the one or more processors, further cause the device to: determine that the authorization has been implemented for the account; decrypt the quick response code based at least in part on the implementation of the authorization for the account; and display the quick response code on the display of the device, wherein a remote device is configured to scan the quick response code and initiate the data transmission.
[0336] Example 3 may include one or more non-transitory computer-readable media as described in Example 2, wherein the instructions, when executed by the one or more processors, further cause the device to: determine a first timestamp indicating a first time when the fast response code is first displayed on the device's display; and provide the first timestamp to a service device, wherein the service device is configured to compare the first timestamp with a second timestamp indicating a second time when the fast response code is scanned to determine whether the fast response code has been used within an allowed time period.
[0337] Example 4 may include one or more non-transitory computer-readable media as described in Example 2, wherein the instructions, when executed by the one or more processors, further cause the device to: receive an authorization request for further authorization operations for the data transmission received from the service device; identify data for the further authorization operations; and provide the service device with the data for the further authorization operations, the data for the further authorization operations being configured to determine permissions for completing the data transmission.
[0338] Example 5 may include one or more non-transitory computer-readable media as described in Example 2, wherein decrypting the fast response code includes decrypting the fast response code using a key stored on a secure element of the device, and wherein the plurality of fast response codes are stored separately from the secure element.
[0339] Example 6 may include one or more non-transitory computer-readable media as described in Example 1, wherein the instructions, when executed by the one or more processors, further cause the device to: determine that the number of fast response codes stored on the device is less than a threshold number of fast response codes; and request that the plurality of fast response codes be provided by the fast response configuration device, wherein the fast response configuration device provides the plurality of fast response codes at least in part based on the fact that the plurality of fast response codes are being requested.
[0340] Example 7 may include one or more non-transitory computer-readable media as described in Example 6, wherein the instructions, when executed by the one or more processors, further cause the device to indicate an amount of fast response codes to be included in the plurality of fast response codes provided by the fast response configuration device.
[0341] Example 8 may include one or more non-transitory computer-readable media as described in Example 1, wherein the instructions, when executed by the one or more processors, further cause the device to: determine that one or more fast response codes stored on the device have been stored for a time longer than a time threshold; remove the one or more fast response codes from the device at least in part based on the time that the one or more fast response codes have been stored for a time longer than the time threshold; and request the plurality of fast response codes at least in part based on the time that the one or more fast response codes have been stored for a time longer than the time threshold.
[0342] Example 9 may include one or more non-transitory computer-readable media as described in Example 1, wherein the instructions, when executed by the one or more processors, further cause the device to: determine that one or more of the plurality of fast response codes have been stored on the device for a time longer than a time threshold; determine that the device does not have connectivity with the fast response configuration device; and maintain the storage of the one or more fast response codes at least in part based on the determination that the device does not have connectivity with the fast response configuration device, at least until the device has connectivity with the fast response configuration device.
[0343] Example 10 may include a device comprising: a memory for storing a plurality of quick response (QR) codes associated with an account, wherein each quick response code is individually encrypted; and processing circuitry coupled to the memory, the processing circuitry comprising: receiving an authorization request to display a quick response code from the plurality of quick response codes, the display of the quick response code being configured to enable data transmission associated with the account; performing an authorization operation for authorizing the account; decrypting the quick response code at least in part based on the authorization being performed for the account, the device being limited to decrypting a single quick response code at a time at least in part based on the individual encryption of the plurality of quick response codes; and displaying the decrypted quick response code on a display of the device, the quick response code being configured to be scanned by a remote device for initiating the data transmission.
[0344] Example 11 may include the device described in Example 10, wherein the processing circuitry further: determines a first timestamp indicating a first time when a decrypted fast response code begins to be displayed on the display of the device; and provides the first timestamp to a service device associated with the plurality of fast response codes, the service device being configured to compare the first timestamp with a second timestamp indicating a second time when the fast response code is scanned, to determine whether the fast response code has been used within an allowed time period.
[0345] Example 12 may include the device described in Example 10, wherein the processing circuitry further: receives a request for a further authorization operation for the data transmission received from a service device associated with a plurality of fast response codes; identifies data for the further authorization operation; and provides the data for the further authorization operation to the service device, the data for the further authorization operation being configured to determine permissions for completing the data transmission.
[0346] Example 13 may include the device described in Example 10, wherein the processing circuitry further: determines that the number of fast response codes stored in the memory is less than a threshold number of fast response codes; and provides a request to a fast response configuration device associated with the plurality of fast response codes, the request being at least in part based on the fact that the number of fast response codes is less than the threshold number of fast response codes to provide additional fast response codes.
[0347] Example 14 may include the device described in Example 13, wherein the processing circuitry further indicates the number of additional fast response codes to be provided by the fast response configuration device.
[0348] Example 15 may include the device described in Example 10, wherein the processing circuitry further: determines that a portion of the plurality of fast response codes has been stored for a time longer than a time threshold; and removes the portion of the plurality of fast response codes from the memory based at least in part on the determination that the portion of the plurality of fast response codes has been stored for a time longer than the time threshold.
[0349] Example 16 may include the device described in Example 10, wherein decrypting the fast response code includes decrypting the fast response code using a key stored on a secure element of the device, and wherein the plurality of fast response codes are stored separately from the secure element.
[0350] Example 17 may include a method for performing data transmission, the method comprising: receiving, by a device, a request to display a Quick Response (QR) code to initiate data transmission; performing, by the device, an authorization operation to authorize the use of the Quick Response code; decrypting, by the device, from a plurality of Quick Response codes stored on the device, at least in part based on the authorization operation, wherein, since the plurality of Quick Response codes are individually encrypted, the device cannot decrypt other Quick Response codes from the plurality of Quick Response codes at least in part based on the authorization operation; and displaying, by the device, the Quick Response code on a display of the device, the Quick Response code being scanned to initiate the data transmission.
[0351] Example 18 may include the method described in Example 17, and further includes preventing the fast response code from being displayed again on the display of the device.
[0352] Example 19 may include the method of Example 17, further comprising: determining by the device that the number of valid fast response codes among the plurality of fast response codes stored on the device is less than a threshold number of fast response codes; and requesting additional fast response codes from the fast response configuration device by the device based at least in part on the fact that the number of valid fast response codes is less than the threshold number of fast response codes.
[0353] Example 20 may include the method of Example 17, further comprising: determining by the device that one or more of the plurality of fast response codes have been stored on the device for a time longer than a time threshold; and removing the one or more fast response codes from the storage device based at least in part on the determination that the one or more of the plurality of fast response codes have been stored on the device for a time longer than the time threshold.
[0354] Example 21 may include one or more non-transitory computer-readable media having instructions that, when executed by one or more processors of a device, cause the device to: detect the selection of credentials within a user information application, the credentials being used to perform data transmission; execute a credential extension within the user information application to collect information for authorizing the data transmission, the credential extension being sandboxed within the user information application, the sandboxing of the credential extension being configured to restrict the privileges of the credential extension to authorization operations within the user information application; collect information relating to the data transmission by the credential extension for authorizing the data transmission; and provide the information by the credential extension to a service device corresponding to the credentials for authorizing the data transmission.
[0355] Example 22 may include one or more non-transitory computer-readable media as described in Example 21, wherein the instructions, when executed by the one or more processors, further cause the device to detect an instruction received from the service device for information to be collected by the credential extension unit, wherein the credential extension unit will collect the information based at least in part on the instruction from the service device.
[0356] Example 23 may include one or more non-transitory computer-readable media as described in Example 21, wherein the instructions, when executed by the one or more processors, further cause the device to detect a user instruction for collecting acceptable information during the data transmission, wherein the information collected by the credential extension is limited by the acceptable information.
[0357] Example 24 may include one or more non-transitory computer-readable media as described in Example 21, wherein the instructions, when executed by the one or more processors, further cause the device to detect an instruction from the service device for a security program to secure the information, and the credential extension unit to generate a bundle containing the information by applying the security program, the security program causing the data within the bundle to be inaccessible by the user information application.
[0358] Example 25 may include one or more non-transitory computer-readable media as described in Example 24, wherein the application of the security program includes encryption of the package.
[0359] Example 26 may include one or more non-transitory computer-readable media as described in Example 21, wherein the instructions, when executed by the one or more processors, also cause the device to display an indication on the device's display, at least in part, based on the execution of the credential extension, the indication indicating that the credential extension is performing to collect the information.
[0360] Example 27 may include one or more non-transitory computer-readable media as described in Example 21, wherein the instructions, when executed by the one or more processors, further cause the device to display a Quick Response (QR) code, which will be scanned by a remote device to initiate the data transmission, wherein the information collected by the credential extension is related to the display of the Quick Response code.
[0361] Example 28 may include one or more non-transitory computer-readable media as described in Example 21, wherein the instructions, when executed by the one or more processors, further cause the device to: detect a payload associated with the data transmission by the credential extension; sign the payload using an SM2 signature by the credential extension; and provide the signed payload to the service device for authorization by the credential extension.
[0362] Example 29 may include a device comprising: a memory for storing one or more credentials; and processing circuitry coupled to the memory, the processing circuitry: detecting, within a user information application, a selection of one or more credentials to be used for data transmission; executing a credential extension within the user information application to collect information for authorizing the data transmission, the credential extension being sandboxed within the user information application, the sandboxing restricting the privileges of the credential extension to authorization operations within the user information application; collecting information related to the data transmission by the credential extension for authorizing the data transmission; and providing the information by the credential extension to a service device corresponding to the credential for authorizing the data transmission.
[0363] Example 30 may include the device described in Example 29, wherein the processing circuitry further causes a Quick Response (QR) code to be displayed on the device’s display, the QR code being scanned by a remote device to initiate the data transmission, wherein the information collected by the credential extension unit is related to the display of the QR code.
[0364] Example 31 may include the device described in Example 30, wherein the processing circuitry further: prevents the device from taking screenshots and recording screens when the fast response code is displayed by the credential extension unit.
[0365] Example 32 may include the device described in Example 29, wherein the processing circuitry further detects user indications for collecting acceptable information during the data transmission, wherein the information collected by the credential extension is limited by the acceptable information.
[0366] Example 33 may include the device described in Example 29, wherein the processing circuitry further: detects an instruction from the service device for a security procedure to secure the information, and generates a bundle containing the information by the credential extension unit by applying the security procedure, the security procedure causing the data within the bundle to be inaccessible by the user information application.
[0367] Example 34 may include the device described in Example 33, wherein the application of the security program includes encryption of the package.
[0368] Example 35 may include the device described in Example 29, wherein the processing circuitry further detects an indication received from the service device for information to be collected by the credential extension unit, wherein the credential extension unit will collect the information based at least in part on the indication from the service device.
[0369] Example 36 may include the device described in Example 29, wherein the processing circuitry further: detects a payload associated with the data transmission by the credential extension unit; signs the payload using an SM2 signature by the credential extension unit; and provides the signed payload to the service device for authorization by the credential extension unit.
[0370] Example 37 may include a method for authorizing data transmission, the method comprising: a device detecting the selection of credentials within a user information application, the credentials being used to perform data transmission; the device executing a credential extension within the user information application to collect information for authorizing the data transmission, the credential extension being sandboxed within the user information application, the sandboxing restricting the privileges of the credential extension to authorization operations within the user information application; the credential extension collecting information related to the data transmission for authorizing the data transmission; and the credential extension providing the information to a service device corresponding to the credentials.
[0371] Example 38 may include the method of Example 37, and further includes the device detecting an indication received from the service device for information to be collected by the credential extension unit, wherein the credential extension unit will collect the information based at least in part on the indication from the service device.
[0372] Example 39 may include the method of Example 37, further comprising: the device detecting an instruction for a security procedure received from the service device for the security of the information, and the device generating a bundle containing the information by applying the security procedure, the security procedure causing the data within the bundle to be inaccessible by the user information application.
[0373] Example 40 may include the method of Example 37, further comprising displaying a quick response (QR) code by the device at least in part based on the selection of the credential, the quick response code being scanned by a remote device to initiate the data transmission, wherein the information collected by the credential extension is related to the display of the quick response code.
[0374] Example 41 may include an apparatus comprising one or more elements for performing the method described or associated with any of Examples 1-40 or any other method or process described herein.
[0375] Example 42 may include one or more non-transitory computer-readable media, the one or more non-transitory computer-readable media including instructions that, when executed by one or more processors of an electronic device, cause the electronic device to perform one or more elements described or associated with any of Examples 1 to 40, or any other methods or processes described herein.
[0376] Example 43 may include an apparatus comprising logic components, modules, or circuitry for performing one or more elements of or related to any of Examples 1 to 40 or any other method or process described herein.
[0377] Example 44 may include a method, technique, or process, or a part or component thereof, as described or associated with any of Examples 1-40.
[0378] Example 45 may include an apparatus comprising one or more processors and one or more computer-readable media, the one or more computer-readable media including instructions that, when executed by the one or more processors, cause the one or more processors to perform the methods, techniques, or processes or portions thereof described or associated with any of Examples 1 to 40.
[0379] Example 46 may include a signal, or a portion thereof, as described or associated with any of Examples 1-40.
[0380] Example 47 may include a datagram, information element, packet, frame, segment, PDU or message, or a portion or component thereof, as described or associated with any of Examples 1 to 40, or otherwise described in this disclosure.
[0381] Example 48 may include a signal encoded with data according to or associated with any of Examples 1 to 40, or a portion or component thereof, or otherwise described in this disclosure.
[0382] Example 49 may include a signal, or a portion or component thereof, encoded as a datagram, IE, packet, frame, segment, PDU, or message, as described or associated with any of Examples 1 to 40, or otherwise described in this disclosure.
[0383] Example 50 may include an electromagnetic signal carrying computer-readable instructions, wherein execution of the computer-readable instructions by one or more processors will cause the one or more processors to perform a method, technique, or process, or a portion thereof, as described or associated with any of Examples 1 to 40.
[0384] Example 51 may include a computer program comprising instructions, wherein execution of the program by a processing element will cause the processing element to perform a method, technique, or process, or a portion thereof, as described or associated with any one of Examples 1 to 40.
[0385] Example 52 may include signals in a wireless network as shown and described herein.
[0386] Example 53 may include methods for communicating in a wireless network as shown and described herein.
[0387] Example 54 may include a system for providing wireless communication as shown and described herein.
[0388] Example 55 may include a device for providing wireless communication as shown and described herein.
[0389] Unless otherwise expressly stated, any of the examples above may be combined with any other example (or combination of examples). The foregoing description of one or more specific embodiments provides illustration and description, but is not intended to be exhaustive or to limit the scope of the embodiments to the precise form disclosed. In light of the teachings above, modifications and variations are possible, or modifications and variations may be derived from practice of various embodiments.
[0390] Although the above embodiments have been described in considerable detail, many variations and modifications will become apparent to those skilled in the art once the disclosure is fully understood. This disclosure is intended to render the following claims as encompassing all such variations and modifications.
Claims
1. One or more computer-readable media having instructions that, when executed by one or more processors of the device, cause the device to: The selection of credentials is detected within the user information application; these credentials will be used to perform data transmission. The device displays a representation of the credentials on its screen, the representation to be scanned by a remote device to initiate the data transmission; The Credential Extensions section within the User Information application is executed to collect information for authorizing the data transmission. The Credential Extensions section is sandboxed within the User Information application, and the sandboxing of the Credential Extensions section is configured to restrict the permissions of the Credential Extensions section to authorized operations within the User Information application. The credential extension unit collects information related to the data transmission for authorizing the data transmission, including an indication of when the data is displayed on the device's screen or the device's location when the indication is displayed on the device's screen; as well as The credential extension unit provides the information to the service device corresponding to the credential to authorize the data transfer between a first account associated with the device and a second account associated with the remote device.
2. The computer-readable medium of claim 1, wherein the instructions, when executed by the one or more processors, further cause the device to detect an instruction received from the service device for information to be collected by the credential extension unit, wherein the credential extension unit will collect the information based at least in part on the instruction from the service device.
3. The computer-readable medium of claim 1 or 2, wherein the instructions, when executed by the one or more processors, further cause the device to detect a user instruction for collecting acceptable information during the data transmission, wherein the information collected by the credential extension is limited by the acceptable information.
4. The computer-readable medium of claim 1 or 2, wherein the instructions, when executed by the one or more processors, further cause the device to: Detecting instructions received from the service device regarding security procedures for the security of the information; and The credential extension unit generates a bundle containing the information by applying the security program, which prevents the data within the bundle from being accessed by the user information application.
5. The one or more computer-readable media of claim 4, wherein the application of the security program includes encryption of the package.
6. The computer-readable medium of claim 1 or 2, wherein the instructions, when executed by the one or more processors, further cause the device to display, at least in part, an instruction on the display of the device indicating that the credential extension is performing to collect the information, based on the execution of the credential extension.
7. The computer-readable medium of claim 1 or 2, wherein the instructions, when executed by the one or more processors, further cause the device to display a quick response code (QR code), the quick response code to be scanned by a remote device to initiate the data transmission, wherein the information collected by the credential extension is related to the display of the quick response code.
8. The computer-readable medium of claim 1 or 2, wherein the instructions, when executed by the one or more processors, further cause the device to: The payload associated with the data transmission is detected by the credential extension unit; The payload is signed by the credential extension unit using SM2 signature; and The credential extension unit provides a signed payload to the service device for authorization.
9. An apparatus for authorized data transmission, comprising: A memory for storing one or more credentials; and A processing circuit coupled to the memory, the processing circuit: Within the user information application, the selection of a credential from one or more of the credentials will be used to perform data transmission; The device displays a representation of the credentials on its screen, the representation to be scanned by a remote device to initiate the data transmission; The credential extension within the user information application is executed to collect information for authorizing the data transmission. The credential extension is sandboxed within the user information application, and the sandboxing restricts the permissions of the credential extension to authorized operations using the user information application. The information related to the data transmission, which is authorized by the credential extension unit, includes an indication of when the data is displayed on the screen of the device or the location of the device when the indication is displayed on the screen of the device; as well as The credential extension unit provides the information to the service device corresponding to the credential to authorize the data transfer between a first account associated with the device and a second account associated with the remote device.
10. The device of claim 9, wherein the processing circuitry further causes a quick response code (QR code) to be displayed on a display of the device, the quick response code being scanned by a remote device to initiate the data transmission, wherein the information collected by the credential extension unit relates to the display of the quick response code.
11. The device of claim 10, wherein the processing circuitry further prevents the device from taking screenshots and recording screens by the credential extension unit when the fast response code is displayed.
12. The device according to any one of claims 9 to 11, wherein the processing circuitry further detects a user indication for collecting acceptable information during the data transmission, wherein the information collected by the credential extension is limited by the acceptable information.
13. The device according to any one of claims 9 to 11, wherein the processing circuit further comprises: Detecting instructions received from the service device regarding security procedures for the security of the information; and The credential extension unit generates a bundle containing the information by applying the security program, which prevents the data within the bundle from being accessed by the user information application.
14. The device of claim 13, wherein the application of the security program includes encryption of the package.
15. The device according to any one of claims 9 to 11, wherein the processing circuitry further detects an indication received from the service device for information to be collected by the credential extension unit, wherein the credential extension unit will collect the information based at least in part on the indication from the service device.
16. The device according to any one of claims 9 to 11, wherein the processing circuit further comprises: The payload associated with the data transmission is detected by the credential extension unit; The payload is signed by the credential extension unit using SM2 signature; as well as The credential extension unit provides a signed payload to the service device for authorization.
17. A method for authorizing data transmission, comprising: The device detects the selection of credentials within the user information application; these credentials will be used to perform the data transmission. The device displays a representation of the credentials on its screen, the representation to be scanned by a remote device to initiate the data transmission; The device executes a credential extension within the user information application to collect information for authorizing the data transmission. The credential extension is sandboxed within the user information application, and the sandboxing restricts the permissions of the credential extension to authorized operations within the user information application. The credential extension unit collects information related to the data transmission for authorizing the data transmission, including an indication of when the indication is displayed on the device's screen or the device's location when the indication is displayed on the device's screen; as well as The credential extension unit provides the information to the service device corresponding to the credential to authorize the data transfer between a first account associated with the device and a second account associated with the remote device.
18. The method of claim 17, further comprising the device detecting an indication received from the service device for information to be collected by the credential extension unit, wherein the credential extension unit will collect the information based at least in part on the indication from the service device.
19. The method according to claim 17 or 18, further comprising: The device detects an instruction from the service device regarding a security procedure for the security of the information. as well as The device generates a bundle containing the information by applying the security program, which prevents the data within the bundle from being accessed by the user information application.
20. The method of claim 17 or 18, further comprising displaying, by the device, a quick response code (QR code) based at least in part on the selection of the credential, the quick response code to be scanned by a remote device to initiate the data transfer, wherein the information collected by the credential extension is related to the display of the quick response code.
Citation Information
Patent Citations
Device security utilizing continually changing QR codes
US20150244715A1
Multiple device credential sharing
US20190034621A1