Method and system for secure deferred transfer of information to a mobile application

EP4674149A4Pending Publication Date: 2026-07-29PHONESTAMP APS
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
PHONESTAMP APS
Filing Date
2024-02-29
Publication Date
2026-07-29

AI Technical Summary

Technical Problem

Existing methods for transferring loyalty information to mobile devices require the digital loyalty mobile application to be installed first, which is an additional burden for customers, and there is a need for a secure method to do so without using Personal Identifiable Information (PII) due to privacy concerns.

Method used

A method and system for secure deferred transfer of information using reusable tokens, where one-time tokens are created on a remote server and embedded in a deferred deep-link, allowing information to be transferred to a mobile application even if it's not yet installed, ensuring security by exposing reusable tokens only to the device and not to users or intermediate components.

Benefits of technology

Facilitates frictionless and fast transfer of digital loyalty information, such as loyalty points or rewards, by allowing information to be onboarded and transferred without manual steps, benefiting merchants with busy hours or limited staff, while ensuring security through one-time tokens.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure DK2024050039_06092024_PF_FP
    Figure DK2024050039_06092024_PF_FP
Patent Text Reader

Abstract

A method and system for secure deferred transfer of information to a mobile application. The method and system provides a secure mechanism for transfer of information to a mobile application using one or more reusable tokens on a mobile communication device where the mobile application is not installed. One or more reusable tokens are provided on a computer readable medium for a mobile application and the one or more reusable tokens are read from the computer readable medium by a mobile communication device where the mobile application is not installed. The mobile communication device sends to a remote server the read one or more reusable tokens, where one or more one-time tokens are created in the remote server as a function of the received one or more reusable tokens. The created one or more one-time tokens are embedded in the remote server into a deferred deep-link targeting the mobile application and from the remote server the deferred deep-link is sent to the mobile communication device. The received deferred deep-link is executed on the mobile communication device. The mobile application sends to the remote server the embedded one or more one-time tokens and the remote server returns to the mobile application information associated with the received one or more one-time tokens.
Need to check novelty before this filing date? Find Prior Art

Description

Method and system for secure deferred transfer of information to a mobile applicationField of the invention

[0001] The present invention relates generally to mobile applications, and more specifically to methods and systems for secure transfer of information to a mobile application after it has been installed on a mobile communication device.Background of the invention

[0002] Physical loyalty cards have for centuries been used by merchants to increase retention of customers and ensure that they return to buy more goods or services.

[0003] With the increased popularity of mobile communication devices the physical loyalty cards are being replaced by loyalty information in digital solutions on mobile communication devices that, compared to their physical counterparts, can help customers to keep track of their earned loyalty and increase merchants' insights into the use of their loyalty programs. Exemplary digital loyalty information include loyalty points, rewards, coupons, stamps, lotteries and tickets. This exemplary digital loyalty information can be acquired after, for example, a sale of a good or service, and can be used or redeemed immediately or at a later point in time.

[0004] With the increased focus on Personal Identifiable Information (PII), for example due to the European General Data Protection Regulation (GDPR), it may not be desirable to track customer loyalty on mobile communication devices through PII, for example, telephone numbers or email addresses. Thus alternative methods for transferring loyalty information to mobile communication devices are needed.

[0005] Known methods for transferring loyalty information to mobile communication devices without using PII include embedding one or more re-usable tokens into computer readable mediums such as near field communication (NFC) tags or quick response (QR) codes, which can be read or scanned, respectively, by a mobile communication device and used to authorize access to digital loyalty information through an installed digital loyalty mobile application running on the same mobile communication device.

[0006] These methods are however limited to situations where the mobile communication devices have a digital loyalty mobile application installed. Installing the digital loyalty mobile application on the mobile communication device is an extra burden on the customer, compared to the paper counterparts, before they can acquire their digital loyalty information from the merchant.

[0007] A need therefore exists for a method and supporting system to securely improve the customer onboarding process when using one or more reusable tokens to transfer digital loyalty information to mobile communication devices when the digital loyalty mobile application is not yet installed.Object of the invention

[0008] An object of the invention is a method and system to securely transfer information to a mobile application using one or more reusable tokens on a mobile communication device where the mobile application is not installed.Description of the invention

[0009] The above described object and several other objects are intended to be obtained in a first aspect of the invention by providing a method for secure deferred transfer of information to a mobile application. The method comprises steps of:providing of one or more reusable tokens on a computer readable medium for a mobile application,reading of the one or more reusable tokens from the computer readable medium on a mobile communication device where the mobile application is not installed,sending from the mobile communication device to a remote server the read one or more reusable tokens,creating one or more one-time tokens in the remote server as a function of the received one or more reusable tokens,embedding the created one or more one-time tokens in the remote server into a deferred deep-link targeting the mobile application,sending from the remote server the deferred deep-link to the mobile communication device,executing the received deferred deep-link on the mobile communication device,sending from the mobile application to the remote server the embedded one or more one-time tokens,sending from the remote server to the mobile application information associated with the received one or more one-time tokens.

[0010] Thereby information originally associated with the one or more reusable tokens can be securely transferred to the mobile application after it has been installed on the mobile communication. This is done through the use of one or more one-time tokens that ensures that the reusable tokens are only exposed initially to the mobile communication device and not to the user or any intermediate component or system that may, intentionally or accidentally, open the deferred deep-link multiple times.

[0011] By storing the one or more reusable tokens in the computer readable medium as an URL targeting the remote server, a standard mobile communication device will out-of-the-box be able to automatically load the URL and send the reusable tokens to the remote server.

[0012] If the computer readable medium is a QR code or an NFC tag a standard mobile communication device will also be able to out-of-the-box read the computer readable medium without requiring any custom hardware or software.

[0013] The execution of a deferred deep-link may include opening of the received deferred deep-link in a browser of the mobile communication device, installing the mobile application on the mobile communication device, and opening the mobile application on the mobile communication device. In order for a browser on a standard mobile communication device to open a redirected deferred-link, the browser may require a click on the deferred deep-link. This may be done by the user of the mobile communication device.

[0014] Common mobile communication devices include iOS and Android based mobile communication devices. On iOS based mobile communication devices it is common for deferred deep-link solutions to use the iOS pasteboard to copy the deferred deep-link from the browser to the mobile application. On Android based mobile communication devices it is common for deferred deep-link solutions to use the Play Install Referrer Library to get the deferred deep-link targeting the mobile application.

[0015] The embedded one or more one-time tokens may be extracted from the deferred deep-link in the mobile application before they are sent to the remote server or from the deferred deep-link in the remote service before it returns the information associated with the one or more one-time tokens. It may also be that the one or more one-time tokens are not extracted from the deferred deep-link and that the remote service uses the deferred deep-link directly to find the information associated with the one or more one-time tokens.

[0016] The method for secure deferred transfer of information to a mobile application is especially useful in loyalty applications where the information associated with the reusable or one-time tokens is digital loyalty information, that is to be transferred between a merchant and a consumer upon purchase of a product or service. In this situation it is critical that the transfer of loyalty information between the merchant and the consumer is frictionless and fast. This requires a minimum number of consistent manual steps. With the above method the process of onboarding and transferring initial digital loyalty information to a consumer is the same as transferring digital loyalty information to a consumer that has already acquired the mobile application. Both processes are initiated by letting the consumer's mobile communication device read the merchant's computer readable medium. When the consumer’s mobile communication device has read the merchant’s computer readable medium, the merchant does not have to do anything else to transfer the digital loyalty information to the consumer. This adds great value to merchant stores with busy-hours or a large number of employees that may only work in the store for a limited number of hours during a week or month.

[0017] Exemplary, digital loyalty information that is typically transferred from a merchant to a consumer upon a purchase of a product or service is loyalty points, rewards, coupons, stamps, lotteries or tickets. A common example of this is bonus stamp cards where a consumer will receive a stamp per purchase of a specific product or product group. When the stamp card is full, the consumer may redeem the card and get a free or discounted product of choice.

[0018] Reusable tokens are tokens that can be used multiple times to transfer information to a mobile application on a mobile communication device. The information transferred may, for example, be digital loyalty information. The information transferred with a reusable token may be the same for each usage of the reusable token or the information may vary for each usage of the reusable token.

[0019] One-time tokens are tokens that can only be used once to transfer information to a mobile application on a mobile communication device. The information transferred may, for example, be digital loyalty information. One-time tokens may be created on-demand or beforehand by any known random or pseudo-random method with enough entropy needed by the mobile application. The information transferred with one or more one-time tokens created as a function of given one or more reusable tokens may or may not be the same as the information transferred with the given one or more reusable tokens.

[0020] A computer readable medium can be a QR code, NFC tag or any other computer readable medium that can be read, scanned, or otherwise captured by a mobile communication device. The mobile communication device may communicate with the computer readable medium using a camera, using RFID based NFC technologies, or using other suitable local area network (LAN) communication technologies.

[0021] The mobile communication device can be a digital watch, cellular phone, a wireless personal digital assistant (PDA), tablet, a laptop computer, or any other device where a mobile application can be installed. The mobile communication device can be NFC-enabled with support for reading NFC tags, equipped with a camera with support for scanning QR codes, and contain other peripherals that can be used to communicate with computer readable mediums. The mobile communication device may communicate with the remote server using a wide area network (WAN) or other suitable communication infrastructure.

[0022] The mobile application can be a mobile loyalty application containing digital loyalty information, or any other purpose specific mobile software application.

[0023] The remote server may include multiple physical or virtual servers, computers and cloud solutions which may be located at different geographic locations and running multiple server side applications including a token authorization service, deferred deep-link service, etc. The remote server may consist of a storage, processing, memory and communication unit.

[0024] Deferred deep-linking is a technique for transferring links through the install process of a mobile application on a mobile communication device. In general, deferred deep-link techniques do not guarantee at-most-once delivery of the deferred deep link to the newly installed mobile application. A deferred deep-link can, for example, be opened on a mobile communication device by a user clicking on the deferred deep-link in the browser of the mobile communication device. The deferred deep-link may be implemented using Play Install Referrer Library on Android, the pasteboard on iOS or any other methods or combination of methods available on a targeted mobile communication device. One or more one-time tokens can, for example, be encoded into the path or query part of a deferred deep-link.

[0025] A second aspect of the invention is providing a system for secure transfer of information to a mobile application. The system compromising:a computer readable medium capable ofstoring and exposing one or more reusable tokens for a mobile application software package, whereinthe mobile application software package includinga deferred deep-link software component capable ofreceiving one or more one-time tokens embedded into a deferred deep-link from a remote server,sending the one or more one-time tokens to the remote server,receiving information associated with the sent one or more one-time tokens from the remote server,a computer readable software component capable ofreceiving one or more reusable tokens from the computer readable medium,sending the one or more reusable tokens to the remote server,receiving information associated with the sent one or more reusable tokens from the remote server, whereinthe remote server includinga token exchange component capable ofreceiving one or more reusable tokens from the computer readable medium,creating one or more one-time tokens as a function of the received one or more reusable tokens,embedding of the created one or more one-time tokens into a deferred deep-link targeting the mobile application software package,sending of the deferred deep-link to the mobile application software package,a reusable token component capable ofreceiving one or more reusable tokens from the mobile application software packagesending information associated with the one or more reusable tokens to the mobile application software packagea one-time token component capable ofreceiving one or more one-time tokens from the mobile application software packagesending information associated with the one or more one-time tokens to the mobile application software package.

[0026] A mobile application software package is a software package that can be installed on a mobile communication device. Upon the installation of the mobile application software package on a mobile communication device, a mobile application based on the mobile application software package can be started on the mobile communication device. The started mobile application, and thereby the mobile application software package, will in this case use the mobile communication device to communicate with the computer readable medium and the remote server.

[0027] With the system the mobile application software package can directly and deferred receive information associated with reusable tokens. When the mobile application software package is installed on a mobile communication device, it may directly receive one or more reusable tokens from the computer readable medium. The mobile application software package is able to exchange the received one or more reusable tokens to information through the remote server. After the mobile application software package has been installed on a mobile communication device, it may receive one or more one-time tokens from a remote server. The mobile application software package is able to exchange the received one or more one-time tokens to information through the remote server. The information acquired by the mobile application software package, whether directly or deferred, will be related to a mobile application running on a mobile communication device.

[0028] The advantage of being able to perform deferred transfer of information to a mobile application by the mobile application software package is that it can acquire information associated to one or more reusable tokens that was read before the mobile application software package is installed. The use of one-time tokens makes the deferred transfer secure and ensures that the reusable tokens are only exposed initially after being read and not to all intermediate components or users that may take part in installing the mobile application software package.

[0029] The remote server may receive the one or more reusable tokens from the computer readable medium as an URL. This will allow a standard mobile communication device to out-of-the-box send the reusable tokens to the remote server.

[0030] The computer readable medium may be a QR code or an NFC tag. This will allow a standard mobile communication device to read the computer readable medium without requiring any custom hardware or software.

[0031] Similar to the method, the system for secure deferred transfer of information to a mobile application is especially useful in loyalty applications where the information associated with the reusable or one-time tokens is digital loyalty information.

[0032] The digital loyalty information transferred using the system may include loyalty points, rewards, coupons, stamps, lotteries or tickets.Brief description of the figures

[0033] The method and system in the present invention will now be described in more detail with regard to the accompanying figures. The figures show one way of implementing the present invention and is not to be construed as being limiting to other possible embodiments falling within the scope of the attached claim set.

[0034] is a schematic representation of an embodiment that uses the method in the present invention.

[0035] is a schematic representation of an embodiment of the system in the present invention.Detailed description of the preferred embodiments

[0036] Referring to, one embodiment of the present invention is shown as a system 100.

[0037] The system 100 includes a computer readable medium 110, a mobile communication device 120, and a remote server 140 whereby the computer readable medium 110 is connected to the mobile communication device 120 and the mobile communication device 120 is connected to the remote server 140. The mobile communication device 120 includes a browser 130, an app store 150 and a mobile application 160 whereby the browser 130 is connected to the app store 150 and the app store 150 is connected to the mobile application 160. The mobile communication device 120 is used by the user 170.

[0038] The browser 130 is the standard web application on the mobile communication device 120 used to open URLs and can more specifically be used to open URLs on the remote server 140. The app store 150 is the standard application manager on the mobile communication device 120 used to install mobile applications, such as the mobile application 160, on the mobile communication device 120. The mobile application 160 is a mobile business application compatible with the mobile communication device 120 it is installed on, and can communicate with compatible business services on the remote server 140. The browser 130, app store 150 and mobile application 160 on the mobile communication device 120 can all communicate with and through core functionality specific to the operating system (OS) of the mobile communication device 120.

[0039] In system 100 the computer readable medium 110 includes an URL containing an embedded one or more reusable tokens for a mobile application.

[0040] When the mobile communication device 120 reads, scans or in other ways captures the URL including the one or more reusable tokens from the computer readable medium 110 using interaction A, the mobile communication device 120 will open the URL in its browser 130. The browser 130 on the mobile communication device 120 will load the URL and connect to the remote server 140 using interaction B. The remote server 140 extracts the one or more reusable tokens from the URL and creates a deferred deep-link containing one or more one-time tokens. The remote server 140 returns a page with the deferred deep-link to the browser 130.

[0041] When the user 170 of the mobile communication device 120 clicks the deferred deep-link in the browser 130, the browser 130 will, possibly through one or more intermediate steps, open the app store 150 of the mobile communication device 120 using interaction C where the user 170 can download and install the mobile application 160.

[0042] When the installed mobile application 160 is started by the user 170 of the mobile communication device 120, the mobile application 160 is loaded with the deferred deep-link using a deferred deep-link technique applicable on the specific type of mobile communication device 120. This may be through interaction D or any other communication channel available on the mobile communication device 120.

[0043] The mobile application 160 extracts the one or more one-time tokens from the given deferred deep-link and sends the one or more one-time tokens to the remote server 140 using interaction E. When the remote server 140 receives the one or more one-time token, it returns the associated digital loyalty information to the mobile application 160 over interaction E.

[0044] Referring to, one embodiment of the present invention is shown as a system 200.

[0045] The system 200 includes a computer readable medium 210, a mobile application software package 260, and a remote server 240. The mobile application software package 260 includes a deferred deep link software component 2601 and a computer readable software component 2602. The remote server 240 includes a token exchange component 2401, a one-time token component 2402, and a reusable token component 2403.

[0046] The computer readable medium 210 is connected to the token exchange component 2401 and the computer readable software component 2602. The token exchange component 2401 is connected to the deferred deep-link software component 2601. The deferred deep-link software component 2601 is connected to the one-time token component 2402 whereas the computer readable software component 2602 is connected to the reusable token component 2403.

[0047] When the one or more reusable tokens from the computer readable medium 210 is received in the token exchange component 2401 of the remote server 240 over interaction I, the token exchange component 2401 creates a deferred deep-link containing one or more one-time tokens. The deferred deep-link is sent from the token exchange server 2401 to the deferred deep-link software component 2601 over interaction II. Once the deferred deep-link is received in the deferred deep-link software component 2601, it uses the one or more one-time tokens from the deferred deep-link to get the information associated with the one or more one-time tokens from the one-time token component 2402 over interaction III.

[0048] When the one or more reusable tokens from the computer readable medium 210 is received in the computer readable software component 2602 over interaction IV, the computer readable software component 2602 uses the one or more reusable tokens to get the information associated with the one or more reusable tokens from the reusable token component 2403 over interaction V.

Claims

Method for secure deferred transfer of information to a mobile application, the method comprises steps of:providing one or more reusable tokens on a computer readable medium (110) for a mobile application (160),reading of the one or more reusable tokens from the computer readable medium (110) on a mobile communication device (120) where the mobile application (160) is not installed,sending from the mobile communication device (120) to a remote server (140) the read one or more reusable tokens,creating one or more one-time tokens in the remote server (140) as a function of the received one or more reusable tokens,embedding the created one or more one-time tokens in the remote server (140) into a deferred deep-link targeting the mobile application (160),sending from the remote server (140) the deferred deep-link to the mobile communication device (120),executing the received deferred deep-link on the mobile communication device (120),sending from the mobile application (160) to the remote server (140) the embedded one or more one-time tokens,sending from the remote server (140) to the mobile application (160) information associated with the received one or more one-time tokens.A method according to claim 1, wherein the one or more reusable tokens are stored in the computer readable medium (110) as an URL.A method according to any one of claims 1 or 2, wherein the computer readable medium (110) is a QR code or an NFC tag.A method according to any one of claims 1 to 3, wherein the execution of the received deferred deep-link on the mobile communication device (120) compromises a user selecting the deferred deep-link in the browser (130) of the mobile communication device (120) via an input device operatively coupled to the mobile communication device (120).A method according to claim 4 wherein the execution of the received deferred deep-link comprises a copy of the deferred deep-link from the browser (130) to the pasteboard on a mobile communication device (120).A method according to claim 4 wherein the execution of the received deferred deep-link comprises the use of the Play Install Referrer Library on a mobile communication device (120).A method according to any one of claims 1 to 6 wherein the information associated with the reusable or one-time tokens is digital loyalty information.A method according to claim 7 wherein the digital loyalty information is loyalty points, rewards, coupons, stamps, lotteries or tickets.A system for secure transfer of information to a mobile application, the system compromising:a computer readable medium (210) capable ofstoring and exposing one or more reusable tokens for a mobile application software package (260), whereinthe mobile application software package (260) includinga deferred deep-link software component (2601) capable of receiving one or more one-time tokens embedded into a deferred deep-link from a remote server (240), sending the one or more one-time tokens to the remote server (240), receiving information associated with the sent one or more one-time tokens from the remote server (240),a computer readable software component (2602) capable of receiving one or more reusable tokens from the computer readable medium (210), sending the one or more reusable tokens to the remote server (240), receiving information associated with the sent one or more reusable tokens from the remote server (240), whereinthe remote server (240) includinga token exchange component capable of receiving one or more reusable tokens from the computer readable medium (210), creating one or more one-time tokens as a function of the received one or more reusable tokens, embedding of the created one or more one-time tokens into a deferred deep-link targeting the mobile application software package (260), sending of the deferred deep-link to the mobile application software package (260),a reusable token component capable of receiving one or more reusable tokens from the mobile application software package (260), sending information associated with the one or more reusable tokens to the mobile application software package (260),a one-time token component capable of receiving one or more one-time tokens from the mobile application software package (260), sending information associated with the one or more one-time tokens to the mobile application software package (260).A system according to claim 9, wherein the one or more reusable tokens are stored in the computer readable medium (210) as an URL.A system according to any one of claims 9 or 10, wherein the computer readable medium (210) is a QR code or an NFC tag.A system according to any one of claims 9 to 11 wherein, the information associated with the reusable or one-time tokens is digital loyalty information.A system according to claim 12 wherein the digital loyalty information is loyalty points, rewards, coupons, stamps, lotteries or tickets.