System, method, and computer program product for a secure element-based communication interface between a kernel application and a contactless payment application
Patent Information
- Application Number
- EP2023957858
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-10-31
- Publication Date
- 2026-09-09
AI Technical Summary
Secure elements in user devices cannot simultaneously perform the functions of a card reader and a card emulator when both a payment application and a kernel application are stored within the same secure element.
A computer-implemented method and system for establishing secure element-based communication interfaces between kernel applications and contactless payment applications, allowing for the selection of a payment application and associated kernel application, establishment of a communication channel, and exchange of contactless communication protocol commands and responses to initiate a payment transaction.
Enables secure and efficient communication between kernel and payment applications within a secure element, allowing for seamless initiation of contactless payment transactions without the need for physical card taps or simultaneous card reader and card emulator modes.
Smart Images

Figure US2023078266_08052025_PF_FP_ABST
Abstract
Description
SYSTEM, METHOD, AND COMPUTER PROGRAM PRODUCT FOR A SECURE ELEMENT-BASED COMMUNICATION INTERFACE BETWEEN A KERNEL APPLICATION AND A CONTACTLESS PAYMENT APPLICATIONBACKGROUND1. Field
[0001] This disclosure relates generally to communication between secure element-based applications and, in some non-limiting embodiments or aspects, to systems, methods, and computer program products for establishing secure elementbased communication interfaces between kernel applications and contactless payment applications.2. Technical Considerations
[0002] Certain user devices (e.g., smartphones, smart watches, etc.) may store payment credentials, which are used to communicate with a merchant point-of-sale (PCS) device to initiate payment transactions. In some scenarios, a secure element (e.g., a secure element chip) of a user device may be used to store payment applications (e.g., associated with issuer systems) that store payment credentials (e.g., an account identifier, a token, and / or a key) on the user device. When a user initiates a contactless payment transaction, the user device may send payment credentials via a contactless communication channel (e.g., near field communication (NFC) channel) to a kernel application (e.g., Europay, MasterCard, and Visa (EMV) kernel application) stored on a merchant PCS device. For example, a user may initiate a contactless payment transaction by communicating payment credentials from a user device to a merchant PCS device via the contactless communication channel by holding the user device within a predetermined range of the merchant PCS device. As such, the secure element of the user device performs the function of a card emulator.
[0003] In other scenarios, user devices may store at least one kernel application, which can be used to initiate a contactless payment transaction when a user taps a contactless payment card to a user device. For example, a secure element of a user device may be used to store the kernel application(s) (e.g., associated with at least one payment network). When a user initiates a contactless payment transaction, the user device may receive payment credentials via a contactless communication channel (e.g., NFC channel) from a contactless payment card. For example, a user may initiate a contactless payment transaction by communicating payment credentialsfrom a contactless payment card to a user device by holding the contactless payment card with a predetermined range of the user device As such, the secure element of the user device performs the function of a card reader.
[0004] However, when a payment application and a kernel application are both stored in the secure element of the same user device, the secure element is unable to perform the functions of a card reader and a card emulator at the same time, for example, because secure element and / or the contactless communication (e.g., NFC) hardware communicatively coupled with the secure element cannot be in a card reader mode and a card emulation mode simultaneously (e.g., the secure element cannot trigger the contactless communication / NFC transceiver into card emulation mode and card reader mode at the same time). As such, a user must either hold a contactless payment card within the predetermined range of the user device in card reader mode or hold a user device in card emulation mode near a separate POS device.SUMMARY
[0005] Accordingly, it is an object of the present disclosure to provide systems, methods, and computer program products for secure element-based communication interfaces between a kernel application and a contactless payment application that overcome some or all of the deficiencies identified above.
[0006] According to non-limiting embodiments or aspects, provided is a computer- implemented method for establishing secure element-based communication interfaces between kernel applications and contactless payment applications. In some non-limiting embodiments or aspects, an example method may include receiving an input from a user of a user device indicating selection of a payment application stored in a secure element of the user device. A kernel application stored in the secure element of the user device associated with the payment application may be selected. A communication channel may be established between the kernel application and the payment application in the secure element of the user device. Contactless communication protocol commands and responses may be communicated between the kernel application and the payment application via the communication channel in the secure element. A payment transaction may be initiated based on the contactless communication protocol commands and responses communicated between the kernel application and the payment application via the communication channel in the secure element.
[0007] In some non-limiting embodiments or aspects, the method may further include retrieving a list of payment applications and a list of kernel applications stored in the secure element of the user device. The input may indicate selection of the payment application from the list of payment applications. Selecting the kernel application may include determining the kernel application from the list of kernel applications based on the input indicating selection of the payment application associated with the kernel application.
[0008] In some non-limiting embodiments or aspects, the payment application may include a contactless communication protocol payment application.
[0009] In some non-limiting embodiments or aspects, the kernel application may include a contactless communication protocol payment application.
[0010] In some non-limiting embodiments or aspects, the communication channel may be established via an interface defined in an executable object file.
[0011] In some non-limiting embodiments or aspects, communicating the contactless communication protocol commands and responses between the kernel application and the payment application via the communication channel in the secure element may include transmitting, by the kernel application, at least one contactless communication protocol command to the payment application via the communication channel in the secure element. The payment application may receive the at least one contactless communication protocol command from the kernel application via the communication channel in the secure element. The payment application may transmit at least one contactless communication protocol response to the kernel application via the communication channel in the secure element in response to receiving the at least one contactless communication protocol command. The kernel application may receive the at least one contactless communication protocol response from the payment application via the communication channel in the secure element.
[0012] In some non-limiting embodiments or aspects, the at least one contactless communication protocol command may include a first byte array, and the at least one contactless communication protocol response may include a second byte array.
[0013] In some non-limiting embodiments or aspects, initiating the payment transaction may include transmitting, by the kernel application, an account identifier based on the contactless communication protocol commands and responses to an application on the user device.
[0014] In some non-limiting embodiments or aspects, initiating the payment transaction may further include generating, by the application on the user device, an authorization request including the account identifier in response to receiving the account identifier from the kernel application. The application on the user device may communicate the authorization request including the account identifier.
[0015] In non-limiting embodiments or aspects, initiating the payment transaction may further include communicating, by the application on the user device, at least one communication including the account identifier to at least one computing device separate from the user device.
[0016] According to non-limiting embodiments or aspects, provided is a system for establishing secure element-based communication interfaces between kernel applications and contactless payment applications. In some non-limiting embodiments or aspects, an example system may include at least one processor and at least one non-transitory computer-readable medium storing instructions that, when executed by the at least one processor, cause the at least one processor to receive an input from a user of a user device indicating selection of a payment application stored in a secure element of the user device. A kernel application stored in the secure element of the user device associated with the payment application may be selected. A communication channel may be established between the kernel application and the payment application in the secure element of the user device. Contactless communication protocol commands and responses may be communicated between the kernel application and the payment application via the communication channel in the secure element. A payment transaction may be initiated based on the contactless communication protocol commands and responses communicated between the kernel application and the payment application via the communication channel in the secure element.
[0017] In some non-limiting embodiments or aspects, the instructions may further cause the at least one processor to retrieve a list of payment applications and a list of kernel applications stored in the secure element of the user device. The input may indicate selection of the payment application from the list of payment applications. The kernel application may be determined from the list of kernel applications based on the input indicating selection of the payment application associated with the kernel application.
[0018] In some non-limiting embodiments or aspects, the payment application may include a contactless communication protocol payment application.
[0019] In some non-limiting embodiments or aspects, the kernel application may include a contactless communication protocol payment application.
[0020] In some non-limiting embodiments or aspects, the communication channel may be established via an interface defined in an executable object file.
[0021] In some non-limiting embodiments or aspects, when communicating the contactless communication protocol commands and responses between the kernel application and the payment application via the communication channel in the secure element, the instructions may cause the at least one processor to transmit, by the kernel application, at least one contactless communication protocol command to the payment application via the communication channel in the secure element. The payment application may receive the at least one contactless communication protocol command from the kernel application via the communication channel in the secure element. The payment application may transmit at least one contactless communication protocol response to the kernel application via the communication channel in the secure element in response to receiving the at least one contactless communication protocol command. The kernel application may receive the at least one contactless communication protocol response from the payment application via the communication channel in the secure element.
[0022] In some non-limiting embodiments or aspects, the at least one contactless communication protocol command may include a first byte array, and the at least one contactless communication protocol response may include a second byte array.
[0023] In some non-limiting embodiments or aspects, when initiating the payment transaction, the instructions may cause the at least one processor to transmit, by the kernel application, an account identifier based on the contactless communication protocol commands and responses to an application on the user device.
[0024] In some non-limiting embodiments or aspects, when initiating the payment transaction, the instructions may further cause the at least one processor to generate, by the application on the user device, an authorization request including the account identifier in response to receiving the account identifier from the kernel application. The application on the user device may communicate the authorization request including the account identifier.
[0025] In some non-limiting embodiments or aspects, when initiating the payment transaction, the instructions may further cause the at least one processor to communicate, by the application on the user device, at least one communication including the account identifier to at least one computing device separate from the user device.
[0026] According to non-limiting embodiments or aspects, provided is a computer program product for establishing secure element-based communication interfaces between kernel applications and contactless payment applications. In some nonlimiting embodiments or aspects, an example computer program product may include at least one non-transitory computer-readable medium including program instructions that, when executed by at least one processor, cause the at least one processor to receive an input from a user of a user device indicating selection of a payment application stored in a secure element of the user device. A kernel application stored in the secure element of the user device associated with the payment application may be selected. A communication channel may be established between the kernel application and the payment application in the secure element of the user device. Contactless communication protocol commands and responses may be communicated between the kernel application and the payment application via the communication channel in the secure element. A payment transaction may be initiated based on the contactless communication protocol commands and responses communicated between the kernel application and the payment application via the communication channel in the secure element.
[0027] In some non-limiting embodiments or aspects, the instructions may further cause the at least one processor to retrieve a list of payment applications and a list of kernel applications stored in the secure element of the user device. The input may indicate selection of the payment application from the list of payment applications. The kernel application may be determined from the list of kernel applications based on the input indicating selection of the payment application associated with the kernel application.
[0028] In some non-limiting embodiments or aspects, the payment application may include a contactless communication protocol payment application.
[0029] In some non-limiting embodiments or aspects, the kernel application may include a contactless communication protocol payment application.
[0030] In some non-limiting embodiments or aspects, the communication channel may be established via an interface defined in an executable object file.
[0031] In some non-limiting embodiments or aspects, when communicating the contactless communication protocol commands and responses between the kernel application and the payment application via the communication channel in the secure element, the instructions may cause the at least one processor to transmit, by the kernel application, at least one contactless communication protocol command to the payment application via the communication channel in the secure element. The payment application may receive the at least one contactless communication protocol command from the kernel application via the communication channel in the secure element. The payment application may transmit at least one contactless communication protocol response to the kernel application via the communication channel in the secure element in response to receiving the at least one contactless communication protocol command. The kernel application may receive the at least one contactless communication protocol response from the payment application via the communication channel in the secure element.
[0032] In some non-limiting embodiments or aspects, the at least one contactless communication protocol command may include a first byte array, and the at least one contactless communication protocol response may include a second byte array.
[0033] In some non-limiting embodiments or aspects, when initiating the payment transaction, the instructions may cause the at least one processor to transmit, by the kernel application, an account identifier based on the contactless communication protocol commands and responses to an application on the user device.
[0034] In some non-limiting embodiments or aspects, when initiating the payment transaction, the instructions may further cause the at least one processor to generate, by the application on the user device, an authorization request comprising the account identifier in response to receiving the account identifier from the kernel application. The application on the user device may communicate the authorization request including the account identifier.
[0035] In non-limiting embodiments or aspects, when initiating the payment transaction, the instructions may further cause the at least one processor to communicate, by the application on the user device, at least one communication including the account identifier to at least one computing device separate from the user device.
[0036] Further non-limiting embodiments or aspects will be set forth in the following numbered clauses:
[0037] Clause 1 : A computer-implemented method, comprising: receiving, with at least one processor, an input from a user of a user device indicating selection of a payment application stored in a secure element of the user device; selecting, with at least one processor, a kernel application stored in the secure element of the user device associated with the payment application; establishing, with at least one processor, a communication channel between the kernel application and the payment application in the secure element of the user device; communicating, with at least one processor, contactless communication protocol commands and responses between the kernel application and the payment application via the communication channel in the secure element; and initiating, with at least one processor, a payment transaction based on the contactless communication protocol commands and responses communicated between the kernel application and the payment application via the communication channel in the secure element.
[0038] Clause 2: The computer-implemented method of clause 1 , further comprising: retrieving, with at least one processor, a list of payment applications and a list of kernel applications stored in the secure element of the user device, wherein the input indicates selection of the payment application from the list of payment applications, and wherein selecting the kernel application comprises determining the kernel application from the list of kernel applications based on the input indicating selection of the payment application associated with the kernel application.
[0039] Clause 3: The computer-implemented method of either clause 1 or clause 2, wherein the payment application comprises a contactless communication protocol payment application.
[0040] Clause 4: The computer-implemented method of any of clauses 1 -3, wherein the kernel application comprises a contactless communication protocol payment application.
[0041] Clause 5: The computer-implemented method of any of clauses 1 -4, wherein the communication channel is established via an interface defined in an executable object file.
[0042] Clause 6: The computer-implemented method of any of clauses 1 -5, wherein communicating the contactless communication protocol commands and responses between the kernel application and the payment application via thecommunication channel in the secure element comprises: transmitting, by the kernel application, at least one contactless communication protocol command to the payment application via the communication channel in the secure element; receiving, by the payment application, the at least one contactless communication protocol command from the kernel application via the communication channel in the secure element; transmitting, by the payment application, at least one contactless communication protocol response to the kernel application via the communication channel in the secure element in response to receiving the at least one contactless communication protocol command; and receiving, by the kernel application, the at least one contactless communication protocol response from the payment application via the communication channel in the secure element.
[0043] Clause 7: The computer-implemented method of any of clauses 1 -6, wherein the at least one contactless communication protocol command comprises a first byte array, and wherein the at least one contactless communication protocol response comprises a second byte array.
[0044] Clause 8: The computer-implemented method of any of clauses 1 -7, wherein initiating the payment transaction comprises: transmitting, by the kernel application, an account identifier based on the contactless communication protocol commands and responses to an application on the user device.
[0045] Clause 9: The computer-implemented method of any of clauses 1 -8, wherein initiating the payment transaction further comprises: generating, by the application on the user device, an authorization request comprising the account identifier in response to receiving the account identifier from the kernel application; and communicating, by the application on the user device, the authorization request comprising the account identifier.
[0046] Clause 10: The computer-implemented method of any of clauses 1 -9, wherein, initiating the payment transaction further comprises: communicating, by the application on the user device, at least one communication comprising the account identifier to at least one computing device separate from the user device.
[0047] Clause 11 : A system, comprising: at least one processor; and at least one non-transitory computer-readable medium storing instructions that, when executed by the at least one processor, cause the at least one processor to: receive an input from a user of a user device indicating selection of a payment application stored in a secure element of the user device; select a kernel application stored in the secure elementof the user device associated with the payment application; establish a communication channel between the kernel application and the payment application in the secure element of the user device; communicate contactless communication protocol commands and responses between the kernel application and the payment application via the communication channel in the secure element; and initiate a payment transaction based on the contactless communication protocol commands and responses communicated between the kernel application and the payment application via the communication channel in the secure element.
[0048] Clause 12: The system of clause 11 , wherein the instructions further cause the at least one processor to: retrieve a list of payment applications and a list of kernel applications stored in the secure element of the user device, wherein the input indicates selection of the payment application from the list of payment applications, and wherein, when selecting the kernel application, the instructions cause the at least one processor to determine the kernel application from the list of kernel applications based on the input indicating selection of the payment application associated with the kernel application.
[0049] Clause 13: The system of either clause 1 1 or clause 12, wherein the payment application comprises a contactless communication protocol payment application.
[0050] Clause 14: The system of any of clauses 1 1 -13, wherein the kernel application comprises a contactless communication protocol payment application.
[0051] Clause 15: The system of any of clauses 11 -14, wherein the communication channel is established via an interface defined in an executable object file.
[0052] Clause 16: The system of any of clauses 1 1 -15, wherein, when communicating the contactless communication protocol commands and responses between the kernel application and the payment application via the communication channel in the secure element, the instructions cause the at least one processor to: transmit, by the kernel application, at least one contactless communication protocol command to the payment application via the communication channel in the secure element; receive by the payment application, the at least one contactless communication protocol command from the kernel application via the communication channel in the secure element; transmit, by the payment application, at least one contactless communication protocol response to the kernel application via the communication channel in the secure element in response to receiving the at leastone contactless communication protocol command; and receive, by the kernel application, the at least one contactless communication protocol response from the payment application via the communication channel in the secure element.
[0053] Clause 17: The system of any of clauses 1 1 -16, wherein the at least one contactless communication protocol command comprises a first byte array, and wherein the at least one contactless communication protocol response comprises a second byte array.
[0054] Clause 18: The system of any of clauses 1 1 -17, wherein, when initiating the payment transaction, the instructions cause the at least one processor to: transmit, by the kernel application, an account identifier based on the contactless communication protocol commands and responses to an application on the user device.
[0055] Clause 19: The system of any of clauses 1 1 -18, wherein, when initiating the payment transaction, the instructions further cause the at least one processor to: generate, by the application on the user device, an authorization request comprising the account identifier in response to receiving the account identifier from the kernel application; and communicate, by the application on the user device, the authorization request comprising the account identifier.
[0056] Clause 20: The system of any of clauses 1 1 -19, wherein, when initiating the payment transaction, the instructions further cause the at least one processor to: communicate, by the application on the user device, at least one communication comprising the account identifier to at least one computing device separate from the user device.
[0057] Clause 21 : A computer program product, comprising at least one non- transitory computer-readable medium including program instructions that, when executed by at least one processor, cause the at least one processor to: receive an input from a user of a user device indicating selection of a payment application stored in a secure element of the user device; select a kernel application stored in the secure element of the user device associated with the payment application; establish a communication channel between the kernel application and the payment application in the secure element of the user device; communicate contactless communication protocol commands and responses between the kernel application and the payment application via the communication channel in the secure element; and initiate a payment transaction based on the contactless communication protocol commandsand responses communicated between the kernel application and the payment application via the communication channel in the secure element.
[0058] Clause 22: The computer program product of clause 21 , wherein the instructions further cause the at least one processor to: retrieve a list of payment applications and a list of kernel applications stored in the secure element of the user device, wherein the input indicates selection of the payment application from the list of payment applications, and wherein, when selecting the kernel application, the instructions cause the at least one processor to determine the kernel application from the list of kernel applications based on the input indicating selection of the payment application associated with the kernel application.
[0059] Clause 23: The computer program product of either clause 21 or clause 22, wherein the payment application comprises a contactless communication protocol payment application.
[0060] Clause 24: The computer program product of any of clauses 21 -23, wherein the kernel application comprises a contactless communication protocol payment application.
[0061] Clause 25: The computer program product of any of clauses 21 -24, wherein the communication channel is established via an interface defined in an executable object file.
[0062] Clause 26: The computer program product of any of clauses 21 -25, wherein, when communicating the contactless communication protocol commands and responses between the kernel application and the payment application via the communication channel in the secure element, the instructions cause the at least one processor to: transmit, by the kernel application, at least one contactless communication protocol command to the payment application via the communication channel in the secure element; receive by the payment application, the at least one contactless communication protocol command from the kernel application via the communication channel in the secure element; transmit, by the payment application, at least one contactless communication protocol response to the kernel application via the communication channel in the secure element in response to receiving the at least one contactless communication protocol command; and receive, by the kernel application, the at least one contactless communication protocol response from the payment application via the communication channel in the secure element.
[0063] Clause 27: The computer program product of any of clauses 21 -26, wherein the at least one contactless communication protocol command comprises a first byte array, and wherein the at least one contactless communication protocol response comprises a second byte array.
[0064] Clause 28: The computer program product of any of clauses 21 -27, wherein, when initiating the payment transaction, the instructions cause the at least one processor to: transmit, by the kernel application, an account identifier based on the contactless communication protocol commands and responses to an application on the user device.
[0065] Clause 29: The computer program product of any of clauses 21 -28, wherein, when initiating the payment transaction, the instructions further cause the at least one processor to: generate, by the application on the user device, an authorization request comprising the account identifier in response to receiving the account identifier from the kernel application; and communicate, by the application on the user device, the authorization request comprising the account identifier.
[0066] Clause 30: The computer program product of any of clauses 21 -29, wherein, when initiating the payment transaction, the instructions further cause the at least one processor to: communicate, by the application on the user device, at least one communication comprising the account identifier to at least one computing device separate from the user device.
[0067] These and other features and characteristics of the present disclosure, as well as the methods of operation and functions of the related elements of structures and the combination of parts and economies of manufacture, will become more apparent upon consideration of the following description and the appended claims with reference to the accompanying drawings, all of which form a part of this specification, wherein like reference numerals designate corresponding parts in the various figures. It is to be expressly understood, however, that the drawings are for the purpose of illustration and description only and are not intended as a definition of the limits of the disclosed subject matter.BRIEF DESCRIPTION OF THE DRAWINGS
[0068] Additional advantages and details are explained in greater detail below with reference to the non-limiting, exemplary embodiments that are illustrated in the accompanying schematic figures, in which:
[0069] FIG. 1 is a schematic diagram of an example system for establishing secure element-based communication interfaces between kernel applications and a contactless payment applications, according to some non-limiting embodiments or aspects;
[0070] FIG. 2 is a flow diagram for an example process for establishing secure element-based communication interfaces between kernel applications and a contactless payment applications, according to some non-limiting embodiments or aspects;
[0071] FIG. 3 is a diagram of an example environment in which methods, systems, and / or computer program products, described herein, may be implemented, according to some non-limiting embodiments or aspects;
[0072] FIG. 4 is a schematic diagram of example components of one or more devices of FIG. 1 and / or FIG. 3, according to some non-limiting embodiments or aspects;
[0073] FIG. 5 is an example diagram of an example system for establishing secure element-based communication interfaces between kernel applications and a contactless payment applications, according to some non-limiting embodiments or aspects;
[0074] FIG. 6 is an example graphical user interface (GUI) for use in a system for establishing secure element-based communication interfaces between kernel applications and contactless payment applications, according to some non-limiting embodiments or aspects; and
[0075] FIG. 7 is a swimlane diagram of an example process for establishing secure element-based communication interfaces between kernel applications and a contactless payment applications, according to some non-limiting embodiments or aspects.DESCRIPTION
[0076] For purposes of the description hereinafter, the terms “end,” “upper,” “lower,” “right,” “left,” “vertical,” “horizontal,” “top,” “bottom,” “lateral,” “longitudinal,” and derivatives thereof shall relate to the embodiments as they are oriented in the drawing figures. However, it is to be understood that the embodiments may assume various alternative variations and step sequences, except where expressly specified to the contrary. It is also to be understood that the specific devices and processes illustratedin the attached drawings, and described in the following specification, are simply exemplary embodiments or aspects of the disclosed subject matter. Hence, specific dimensions and other physical characteristics related to the embodiments or aspects disclosed herein are not to be considered as limiting.
[0077] No aspect, component, element, structure, act, step, function, instruction, and / or the like used herein should be construed as critical or essential unless explicitly described as such. Also, as used herein, the articles “a” and “an” are intended to include one or more items and may be used interchangeably with “one or more” and “at least one.” Furthermore, as used herein, the term “set” is intended to include one or more items (e.g., related items, unrelated items, a combination of related and unrelated items, and / or the like) and may be used interchangeably with “one or more” or “at least one.” Where only one item is intended, the term “one” or similar language is used. Also, as used herein, the terms “has,” “have,” “having,” or the like are intended to be open-ended terms. Further, the phrase “based on” is intended to mean “based at least partially on” unless explicitly stated otherwise.
[0078] As used herein, the term “acquirer institution” may refer to an entity licensed and / or approved by a transaction service provider to originate transactions (e.g., payment transactions) using a payment device associated with the transaction service provider. The transactions the acquirer institution may originate may include payment transactions (e.g., purchases, original credit transactions (OCTs), account funding transactions (AFTs), and / or the like). In some non-limiting embodiments or aspects, an acquirer institution may be a financial institution, such as a bank. As used herein, the term “acquirer system” may refer to one or more computing devices operated by or on behalf of an acquirer institution, such as a server computer executing one or more software applications.
[0079] As used herein, the term “account identifier” may include one or more primary account numbers (PANs), tokens, or other identifiers associated with a customer account. The term “token” may refer to an identifier that is used as a substitute or replacement identifier for an original account identifier, such as a PAN. Account identifiers may be alphanumeric or any combination of characters and / or symbols. Tokens may be associated with a PAN or other original account identifier in one or more data structures (e.g., one or more databases, and / or the like) such that they may be used to conduct a transaction without directly using the original accountidentifier. In some examples, an original account identifier, such as a PAN, may be associated with a plurality of tokens for different individuals or purposes.
[0080] As used herein, the term “communication” may refer to the reception, receipt, transmission, transfer, provision, and / or the like of data (e.g., information, signals, messages, instructions, commands, and / or the like). For one unit (e.g., a device, a system, a component of a device or system, combinations thereof, and / or the like) to be in communication with another unit means that the one unit is able to directly or indirectly receive information from and / or transmit information to the other unit. This may refer to a direct or indirect connection (e.g., a direct communication connection, an indirect communication connection, and / or the like) that is wired and / or wireless in nature. Additionally, two units may be in communication with each other even though the information transmitted may be modified, processed, relayed, and / or routed between the first and second unit. For example, a first unit may be in communication with a second unit even though the first unit passively receives information and does not actively transmit information to the second unit. As another example, a first unit may be in communication with a second unit if at least one intermediary unit processes information received from the first unit and communicates the processed information to the second unit.
[0081] As used herein, the term “computing device” may refer to one or more electronic devices configured to process data. A computing device may, in some examples, include the necessary components to receive, process, and output data, such as a processor, a display, a memory, an input device, a network interface, and / or the like. A computing device may be a mobile device. As an example, a mobile device may include a cellular phone (e.g., a smartphone or standard cellular phone), a portable computer, a wearable device (e.g., watches, glasses, lenses, clothing, and / or the like), a personal digital assistant (PDA), and / or other like devices. A computing device may also be a desktop computer or other form of non-mobile computer.
[0082] As used herein, the terms “electronic wallet” and “electronic wallet application” refer to one or more electronic devices and / or software applications configured to initiate and / or conduct payment transactions. For example, an electronic wallet may include a mobile device executing an electronic wallet application, and may further include server-side software and / or databases for maintaining and providing transaction data to the mobile device. An “electronic wallet provider” may include an entity that provides and / or maintains an electronic wallet for a customer, such asGoogle Pay®, Android Pay®, Apple Pay®, Samsung Pay®, and / or other like electronic payment systems. In some non-limiting examples, an issuer bank may be an electronic wallet provider.
[0083] As used herein, the term “issuer institution” may refer to one or more entities, such as a bank, that provide accounts to customers for conducting transactions (e.g., payment transactions), such as initiating credit and / or debit payments. For example, an issuer institution may provide an account identifier, such as a PAN, to a customer that uniquely identifies one or more accounts associated with that customer. The account identifier may be embodied on a portable financial device, such as a physical financial instrument, e.g., a payment card, and / or may be electronic and used for electronic payments. The term “issuer system” refers to one or more computer devices operated by or on behalf of an issuer institution, such as a server computer executing one or more software applications. For example, an issuer system may include one or more authorization servers for authorizing a transaction.
[0084] As used herein, the term “merchant” may refer to an individual or entity that provides goods and / or services, or access to goods and / or services, to customers based on a transaction, such as a payment transaction. The term “merchant” or “merchant system” may also refer to one or more computer systems operated by or on behalf of a merchant, such as a server computer executing one or more software applications.
[0085] As used herein, a “point-of-sale (POS) device” may refer to one or more devices, which may be used by a merchant to conduct a transaction (e.g., a payment transaction) and / or process a transaction. For example, a POS device may include one or more client devices. Additionally or alternatively, a POS device may include peripheral devices, card readers, scanning devices (e.g., code scanners), Bluetooth® communication receivers, near-field communication (NFC) receivers, radio frequency identification (RFID) receivers, and / or other contactless transceivers or receivers, contact-based receivers, payment terminals, and / or the like. As used herein, a “point- of-sale (POS) system” may refer to one or more client devices and / or peripheral devices used by a merchant to conduct a transaction. For example, a POS system may include one or more POS devices and / or other like devices that may be used to conduct a payment transaction. In some non-limiting embodiments or aspects, a POS system (e.g., a merchant POS system) may include one or more server computersprogrammed or configured to process online payment transactions through webpages, mobile applications, and / or the like.
[0086] As used herein, the terms “client” and “client device” may refer to one or more client-side devices or systems (e.g., remote from a transaction service provider) used to initiate or facilitate a transaction (e.g., a payment transaction). As an example, a “client device” may refer to one or more POS devices used by a merchant, one or more acquirer host computers used by an acquirer, one or more mobile devices used by a user, and / or the like. In some non-limiting embodiments or aspects, a client device may be an electronic device configured to communicate with one or more networks and initiate or facilitate transactions. For example, a client device may include one or more computers, portable computers, laptop computers, tablet computers, mobile devices, cellular phones, wearable devices (e.g., watches, glasses, lenses, clothing, and / or the like), PDAs, and / or the like. Moreover, a “client” may also refer to an entity (e.g., a merchant, an acquirer, and / or the like) that owns, utilizes, and / or operates a client device for initiating transactions (e.g., for initiating transactions with a transaction service provider).
[0087] As used herein, the term “payment device” may refer to a payment card (e.g., a credit or debit card), a gift card, a smartcard, smart media, a payroll card, a healthcare card, a wristband, a machine-readable medium containing account information, a keychain device or fob, an RFID transponder, a retailer discount or loyalty card, a cellular phone, an electronic wallet mobile application, a personal digital assistant (PDA), a pager, a security card, a computing device, an access card, a wireless terminal, a transponder, and / or the like. In some non-limiting embodiments or aspects, the payment device may include volatile or non-volatile memory to store information (e.g., an account identifier, a name of the account holder, and / or the like).
[0088] As used herein, the term “payment gateway” may refer to an entity and / or a payment processing system operated by or on behalf of such an entity (e.g., a merchant service provider, a payment service provider, a payment facilitator, a payment facilitator that contracts with an acquirer, a payment aggregator, and / or the like), which provides payment services (e.g., transaction service provider payment services, payment processing services, and / or the like) to one or more merchants. The payment services may be associated with the use of portable financial devices managed by a transaction service provider. As used herein, the term “payment gateway system” may refer to one or more computer systems, computer devices,servers, groups of servers, and / or the like, operated by or on behalf of a payment gateway.
[0089] As used herein, the term “server” may refer to or include one or more computing devices that are operated by or facilitate communication and processing for multiple parties in a network environment, such as the Internet, although it will be appreciated that communication may be facilitated over one or more public or private network environments and that various other arrangements are possible. Further, multiple computing devices (e.g., servers, point-of-sale (POS) devices, mobile devices, etc.) directly or indirectly communicating in the network environment may constitute a “system.” Reference to “a server” or “a processor,” as used herein, may refer to a previously-recited server and / or processor that is recited as performing a previous step or function, a different server and / or processor, and / or a combination of servers and / or processors. For example, as used in the specification and the claims, a first server and / or a first processor that is recited as performing a first step or function may refer to the same or different server and / or a processor recited as performing a second step or function.
[0090] As used herein, the term “transaction service provider” may refer to an entity that receives transaction authorization requests from merchants or other entities and provides guarantees of payment, in some cases through an agreement between the transaction service provider and an issuer institution. For example, a transaction service provider may include a payment network such as Visa® or any other entity that processes transactions. The term “transaction processing system” may refer to one or more computer systems operated by or on behalf of a transaction service provider, such as a transaction processing server executing one or more software applications. A transaction processing server may include one or more processors and, in some non-limiting embodiments or aspects, may be operated by or on behalf of a transaction service provider.
[0091] Non-limiting embodiments or aspects of the disclosed subject matter are directed to systems, methods, and computer program products for establishing secure element-based communication interfaces between kernel applications and contactless payment applications. An input may be received from a user of a user device indicating selection of a payment application stored in a secure element of the user device. A kernel application stored in the secure element of the user device associated with the payment application may be selected. A communication channel may beestablished between the kernel application and the payment application in the secure element of the user device. Contactless communication protocol commands and / or responses may be communicated between the kernel application and the payment application via the communication channel in the secure element. A payment transaction may be initiated based on the contactless communication protocol commands and / or responses communicated between the kernel application and the payment application via the communication channel in the secure element. In this way, the disclosure is directed to processing a payment transaction by enabling communication between the kernel application and the payment application in the secure element of a user device. A user of the user device may choose to either tap a physical payment device, such as a payment card (e.g., for NFC payment) or select a payment application from a user interface to complete the payment transaction. In a case where the user selects the payment application, the NFC chip may be disabled, and a corresponding kernel application may be selected. The kernel application may establish a communication channel with the payment application within the secure element on the user device. The kernel application and the payment application may then exchange commands and responses (e.g., Application Protocol Data Unit (APDU) commands and responses that would be used for NFC payment) via the communication channel, and the kernel application may use the payment credentials captured from that exchange for the payment transaction. As such, the disclosed subject matter enables users to select an installed payment application in order to complete a payment transaction via an installed kernel application by allowing for a communication channel between the payment application and the corresponding kernel application within a secure element of the same user device without requiring a physical tap and / or communication via the NFC chip. After selecting the existing payment application on the user device, the user is not required to retrieve and tap a physical payment card and / or enter payment details (e.g., payment card details). This is an advantage over existing devices in which the NFC chip of a device is able to operate in either reader mode or card emulation mode, but not both. Additionally, nonlimiting embodiments or aspects of the disclosed subject matter may retrieve a list of payment applications and a list of kernel applications stored in the secure element of the user device. The input may indicate selection of the payment application from the list of payment applications. When selecting the kernel application, the kernel application may be determined from the list of kernel applications based on the inputindicating selection of the payment application associated with the kernel application. The payment application may include a contactless communication protocol payment application. The kernel application may include a contactless communication protocol payment application. The communication channel may be established via an interface defined in an executable object file. When communicating the contactless communication protocol commands and responses between the kernel application and the payment application via the communication channel in the secure element, the kernel application may transmit at least one contactless communication protocol command to the payment application via the communication channel in the secure element. The payment application may receive the at least one contactless communication protocol command from the kernel application via the communication channel in the secure element. The payment application may transmit at least one contactless communication protocol response to the kernel application via the communication channel in the secure element in response to receiving the at least one contactless communication protocol command. The kernel application may receive the at least one contactless communication protocol response from the payment application via the communication channel in the secure element. The at least one contactless communication protocol command may include a first byte array, and the at least one contactless communication protocol response may include a second byte array. When initiating the payment transaction, the kernel application may transmit an account identifier based on the contactless communication protocol commands and responses to an application on the user device. As such, once the user selects to use an existing payment application to complete the transaction, the user device automatically determines the kernel application associated with the selected payment application and the kernel application established a secure communication connection with the payment application communicate in the secure element of the user device, whereby the kernel application securely receives account credentials (e.g., an account identifier) from the payment application stored in the secure element of the user device. The kernel application may communicate the account credentials to an application executing on the user device to authenticate and / or complete the transaction.
[0092] FIG. 1 is a schematic diagram of an example system 100 for establishing secure element-based communication interfaces between kernel applications and contactless payment applications. In some non-limiting embodiments or aspects,system 100 may include user device 102, secure element 104, transceiver 106, merchant system 108, and / or POS device 110.
[0093] User device 102 may include a computing device configured to communicate with merchant system 108 and / or POS device 1 10 (e.g., via a wired or wireless communication connection). For example, user device 102 may include a computing device, such as a desktop computer, a portable computer (e.g., a tablet computer, a laptop computer, and / or the like), a mobile device (e.g., a cellular phone, a smartphone, a personal digital assistant, a wearable device, and / or the like), and / or other like devices. In some non-limiting embodiments or aspects, user device 102 may be associated with a user (e.g., an individual operating user device 102).
[0094] In some non-limiting embodiments or aspects, user device 102 may include a secure element (e.g., secure element 104) and / or a transceiver (e.g., transceiver 106), as described herein. In some non-limiting embodiments or aspects, user device 102 may include a processor and / or a non-transitory computer-readable medium (e.g., memory and / or storage), as described herein.
[0095] Secure element 104 may include a hardware component of user device 102 that is configured to store (e.g., securely store) sensitive data (e.g., financial data, cryptographic keys, etc.), run secure applications (e.g., financial applications, cryptographic applications, etc.) that require access to the sensitive data. In some non-limiting embodiments or aspects, secure element 104 may include a removable secure element (e.g., a subscriber identity module (SIM) card or a universal subscriber identity module (USIM) card), an embedded secure element (eSE), an integrated secure element (iSE) (e.g., a secure processing unit (SPU)), any combination thereof, and / or the like. Secure element 104 may be configured to prevent unauthorized access to and / or tampering with the sensitive data and / or secure applications. For example, secure element 104 may include a secure element chip (e.g., a secure element integrated circuit (IC) and / or memory storing a secure element platform certified in accordance with EMVCo security evaluation procedures). The secure element chip may be integrated into user device 102 by a manufacturer of user device 102. In some non-limiting embodiments or aspects, secure element 104 may be configured to perform the techniques described herein. In some non-limiting embodiments or aspects, secure element 104 may include a processor and / or memory (e.g., physically or logically separate from the processor and / or memory allocated for other applications on user device 102). In some non-limiting embodiments or aspects,secure element 104 may be in communication with user device 102 and / or transceiver 106. In some non-limiting embodiments or aspects, secure element 104 may be capable of receiving information from and / or communicating information to user device 102 and / or transceiver 106.
[0096] Transceiver 106 may include hardware (e.g., an antenna, IC, circuitry, and / or at least one non-transitory computer-readable medium storing associated data and / or software) for communicating contactless communication protocol (e.g., commands and / or responses). For example, transceiver 106 may include at least one NFC chip, at least one RFID chip, and / or the like. In some non-limiting embodiments or aspects, transceiver 106 may be programmed to perform the techniques described herein. In some non-limiting embodiments or aspects, transceiver 106 may be in communication with user device 102 and / or secure element 104. In some non-limiting embodiments or aspects, transceiver 106 may be capable of receiving information from and / or communicating information to user device 102 and / or secure element 104.
[0097] In some non-limiting embodiments or aspects, user device 102 may be in communication with merchant system 108. For example, user device 102 may receive information from and / or communicate information to merchant system 108.
[0098] Merchant system 108 may include a computing device, such as a server, a group of servers, a client device, a group of client devices, and / or other like devices. In some non-limiting embodiments or aspects, merchant system 108 may be associated with a merchant, as described herein. Merchant system 108 may include POS device 1 10. In some non-limiting embodiments or aspects, merchant system 108 may receive information from and / or communicate information to POS device 1 10.
[0099] POS Device 1 10 may include a computing device, such as a client device, a group of client devices, and / or other like devices, as described herein. In some nonlimiting embodiments or aspects, POS device 1 10 may be a POS device associated with a merchant, as described herein. In some non-limiting embodiments or aspects, POS device 1 10 may be external to merchant system 108. In some non-limiting embodiments or aspects, POS device may receive information from and / or communicate information to user device 102.
[0100] In some non-limiting embodiments or aspects, user device 102 may store a list of payment applications and / or a list of kernel applications. For example, user device 102 may store the list of payment applications and / or the list of kernel applications in secure element 104. The list of payment applications may include oneor more payment applications. The list of kernel applications may include one or more kernel applications. In some non-limiting embodiments or aspects, each payment application may be associated with a kernel application. In some non-limiting embodiments or aspects, one or more payment applications of the list of payment applications may be associated with a kernel application.
[0101] In some non-limiting embodiments or aspects, user device 102 may retrieve the list of payment applications and / or the list of kernel applications. For example, user device 102 may retrieve the list of payment applications and / or the list of kernel applications from secure element 104.
[0102] In some non-limiting embodiments or aspects, user device 102 may display the list of payment applications. For example, user device 102 may display the list of payment applications for completing a payment transaction via a display of user device 102 in response to retrieving the list of payment applications and / or the list of kernel applications from secure element 104.
[0103] In some non-limiting embodiments or aspects, user device 102 may receive an input from a user of user device 102. For example, user device 102 may receive an input from the user of user device 102 indicating selection of a payment application from the list of payment applications. In some non-limiting embodiments or aspects, user device 102 may receive the input from the user of user device 102 via a user interface (Ul) presented via the display, where the GUI includes the list of payment applications.
[0104] The payment application may include a contactless communication protocol payment application. In some non-limiting embodiments or aspects, the payment application may be associated with an issuer system.
[0105] In some non-limiting embodiments or aspects, user device 102 may select the kernel application stored in secure element 104 associated with the payment application. For example, user device 102 may select the kernel application stored in secure element 104 associated with the payment application based on the input received from the user. In some non-limiting embodiments or aspects, when selecting the kernel application, user device 102 may determine the kernel application from the list of kernel applications based on the input indicating selection of the payment application associated with the kernel application.
[0106] The kernel application may include a contactless communication protocol payment application. The kernel application may be associated with a payment network and / or a transaction service provider system.
[0107] In some non-limiting embodiments or aspects, user device 102 may establish a communication channel between the kernel application and the payment application in secure element 104. The communication channel may be established via an interface defined in an executable object file.
[0108] In some non-limiting embodiments or aspects, user device 102 may communicate contactless communication protocol commands and / or responses. For example, user device 102 may communicate contactless communication protocol commands and / or responses (e.g., application protocol data unit (APDU) commands and / or responses, NFC commands and / or responses, etc.) between the kernel application and the payment application via the communication channel in secure element 104. In some non-limiting embodiments or aspects, the contactless communication protocol may include NFC, payWave®, Apple Pay®, Samsung Pay®, Google Pay ®, and / or the like. In some non-limiting embodiments or aspects, communicating the contactless communication protocol commands and responses between the kernel application and the payment application via the communication channel in secure element 104 may include transmitting at least one contactless communication protocol command to the payment application. For example, the kernel application may transmit at least one contactless communication protocol command to the payment application via the communication channel in secure element 104.
[0109] In some non-limiting embodiments or aspects, communicating the contactless communication protocol commands and responses between the kernel application and the payment application via the communication channel in secure element 104 may include receiving the at least one contactless communication protocol command. For example, the payment application may receive the a least one contactless communication protocol command from the kernel application via the communication channel in secure element 104, in response to the kernel application transmitting the at least one contactless communication protocol command.
[0110] In some non-limiting embodiments or aspects, communicating the contactless communication protocol commands and responses between the kernel application and the payment application via the communication channel in secureelement 104 may include transmitting at least one contactless communication protocol response. For example, the payment application may transmit at least one contactless communication protocol response to the kernel application via the communication channel in secure element 104 in response to receiving the at least one contactless communication protocol command.
[0111] In some non-limiting embodiments or aspects, communicating the contactless communication protocol commands and responses between the kernel application and the payment application via the communication channel in secure element 104 may include receiving the at least one contactless communication protocol response. For example, the kernel application may receive the at least one contactless communication protocol response from the payment application via the communication channel in secure element 104 in response to the payment application transmitting the at least one contactless communication protocol response.
[0112] In some non-limiting embodiments or aspects, the commands and / or responses may include a byte array. For example, the at least one contactless communication protocol command may include a first byte array and / or the at least one contactless communication protocol response may include a second byte array. The first byte array and / or the second byte array may include one or more parameters. In some non-limiting embodiments or aspects, the commands and / or responses may include another object type, such as a string, a class object, and / or the like. For example, user device 102 (e.g., secure element 104, the payment application, and / or the kernel application thereof) may transform the first byte array and / or the second byte array into another object type (e.g., a string and / or a class object).
[0113] In some non-limiting embodiments or aspects, user device 102 may initiate a payment transaction. For example, user device 102 may initiate a payment transaction based on the contactless communication protocol commands and responses communicated between the kernel application and the payment application via the communication channel in secure element 104.
[0114] In some non-limiting embodiments or aspects, initiating the payment transaction may include transmitting an account identifier to user device 102. For example, the kernel application may transmit an account identifier based on the contactless communication protocol commands and / or responses to an application (e.g., a mobile application, a merchant application, and / or the like) on user device 102.For example, the application may include an application associated with a merchant (e.g., associated with merchant system 108) and / or the like.
[0115] In some non-limiting embodiments or aspects, the account identifier may be associated with the user of user device 102. In some non-limiting embodiments or aspects, the account identifier may be stored in and / or retrieved from secure element 104 (e.g., a memory of secure element 104). For example, the kernel application may retrieve the account identifier from a memory of secure element 104.
[0116] In some non-limiting embodiments or aspects, the account identifier may include a static account identifier (e.g., a PAN, a payment token, and / or the like). In some non-limiting embodiments or aspects, the account identifier may include a dynamic account identifier (e.g., a cryptogram generated using a cryptographic key, such as an EMV application cryptogram generated by the payment application using a secret cryptographic key and / or retrieved by the kernel application and / or EMV data tags, such as application transaction counter (ATC) and / or application interchange profile (AIP)). In some non-limiting embodiments or aspects, the account identifier may include a static account identifier and a dynamic account identifier. For example, the kernel application may transmit the dynamic account identifier in addition to or in lieu of the static account identifier.
[0117] In some non-limiting embodiments or aspects, initiating the payment transaction may include generating an authorization request comprising the account identifier. For example, the application (e.g., mobile application, merchant application, and / or the like) on user device 102 may generate an authorization request including the account identifier in response to receiving the account identifier from the kernel application.
[0118] In some non-limiting embodiments or aspects, initiating the payment transaction may include communicating the authorization request comprising the account identifier. For example, the application on user device 102 may communicate the authorization request comprising the account identifier to merchant system 108, and / or POS device 110.
[0119] In some non-limiting embodiments or aspects, initiating the payment transaction may include communicating at least one communication including the account identifier to at least one computing device separate from the user device. For example, the application on user device 102 may communicate the at least onecommunication comprising the account identifier to merchant system 108, and / or POS device 1 10.
[0120] The number and arrangement of systems and devices shown in FIG. 1 are provided as an example. There may be additional systems and / or devices, fewer systems and / or devices, different systems and / or devices, and / or differently arranged systems and / or devices than those shown in FIG. 1. Furthermore, two or more systems or devices shown in FIG. 1 may be implemented within a single system or device, or a single system or device shown in FIG. 1 may be implemented as multiple distributed systems or devices. Additionally or alternatively, a set of systems (e.g., one or more systems) or a set of devices (e.g., one or more devices) of system 100 may perform one or more functions described as being performed by another set of systems or another set of devices of system 100.
[0121] Referring now to FIG. 2, shown is a flow diagram for an example process 200 for establishing secure element-based communication interfaces between kernel applications and contactless payment applications. The steps shown in FIG. 2 are for example purposes only. It will be appreciated that additional, fewer, different, and / or a different order of steps may be used in non-limiting embodiments or aspects. In some non-limiting embodiments or aspects, one or more steps of process 200 may be performed (e.g., completely, partially, etc.) by user device 102. In some non-limiting embodiments or aspects, one or more steps of process 200 may be performed (e.g., completely, partially, etc.) by another device or group of devices, separate from or including user device 102, such as secure element 104, transceiver 106, merchant system 108 (e.g., one or more devices of merchant system 108), and / or POS device 1 10.
[0122] As shown in FIG, 2, at step 202, process 200 may include receiving an input from a user. For example, user device 102 may receive an input from a user of user device 102. The input may indicate selection of a payment application (e.g., from a list of payment applications stored in secure element 104, as described herein).
[0123] In some non-limiting embodiments or aspects, user device 102 may receive the input from the user via a graphical user interview (GUI) displayed via a display of user device 102. For example, the GUI may display a list of payment applications, as described herein.
[0124] In some non-limiting embodiments or aspects, the payment application may include a contactless communication protocol payment application. In some non-limiting embodiments or aspects, the payment application may be associated with an issuer.
[0125] In some non-limiting embodiments or aspects, a list of payment applications and / or a list of kernel applications may be stored. For example, user device 102 and / or secure element 104 may store the list of payment applications and / or the list of kernel applications (e.g., in secure element 104). In some non-limiting embodiments or aspects, the list of payment applications may include one or more payment applications. In some non-limiting embodiments or aspects, the list of kernel applications may include one or more kernel applications. In some non-limiting embodiments or aspects, each of the payment applications may be associated with a kernel application. In some non-limiting embodiments or aspects, one or more payment applications may be associated with a kernel application (e.g., multiple payment applications may be associated with the same kernel application).
[0126] In some non-limiting embodiments or aspects, the list of payment applications and / or the list of kernel applications may be retrieved (e.g., before receiving the selection of the payment application). For example, user device 102 may retrieve the list of payment applications and / or the list of kernel applications stored in secure element 104 of user device 102.
[0127] In some non-limiting embodiments or aspects, the list of payment applications may be displayed via user device 102 (e.g., before receiving the selection of the payment application and / or after retrieving the list of payment applications). For example, user device 102 may display the list of payment applications for completing a payment transaction via a display of user device 102 in response to retrieving the list of payment applications and / or the list of kernel applications from secure element 104.
[0128] As shown in FIG. 2, at step 204, process 200 may include selecting a kernel application. For example, user device 102 and / or secure element 104 may select the kernel application stored in secure element 104 associated with the payment application based on the input received from the user.
[0129] In some non-limiting embodiments or aspects, when selecting the kernel application, user device 102 may determine the kernel application from the list of kernel applications. For example, user device 102 may determine the kernel application from the list of kernel applications based on the input indicating selection of the payment application associated with the kernel application.
[0130] In some non-limiting embodiments or aspects, the kernel application may include a contactless communication protocol payment application. In some nonlimiting embodiments or aspects, the kernel application may be associated with a payment network and / or a transaction service provider system.
[0131] In some non-limiting embodiments or aspects, the kernel application may include a contactless communication protocol payment application. For example, the contactless communication protocol may include NFC, payWave®, Apple Pay®, Samsung Pay®, Google Pay®, and / or the like.
[0132] As shown in FIG. 2, at step 206, process 200 may include establishing a communication channel. For example, the kernel application may establish a communication channel with the payment application in secure element 104 of user device 102.
[0133] In some non-limiting embodiments or aspects, the communication channel may be established via an interface defined in an executable object file. For example, the kernel application may establish the communication channel via an interface defined in an executable object file stored in secure element 104.
[0134] As shown in FIG. 2, at step 208, process 200 may include communicating contactless communication protocol commands and / or responses via the communication channel. For example, the kernel application and / or the payment application may communicate (e.g., generate, transmit, and / or receive) contactless communication protocol commands and / or responses via the communication channel in secure element 104. In some non-limiting embodiments or aspects, the contactless communication protocol may include NFC, payWave®, Apple Pay®, Samsung Pay®, Google Pay®, and / or the like.
[0135] In some non-limiting embodiments or aspects, communicating the contactless communication protocol commands and responses may include transmitting at least one contactless communication protocol command to the payment application. For example, the kernel application may transmit at least one contactless communication protocol command to the payment application via the communication channel in secure element 104.
[0136] In some non-limiting embodiments or aspects, communicating the contactless communication protocol commands and responses may include receiving the at least one contactless communication protocol command. For example, the payment application may receive the a least one contactless communication protocolcommand from the kernel application via the communication channel in secure element 104, in response to the kernel application transmitting the at least one contactless communication protocol command.
[0137] In some non-limiting embodiments or aspects, communicating the contactless communication protocol commands and responses may include transmitting at least one contactless communication protocol response. For example, the payment application may transmit at least one contactless communication protocol response to the kernel application via the communication channel in secure element 104 in response to receiving the at least one contactless communication protocol command.
[0138] In some non-limiting embodiments or aspects, communicating the contactless communication protocol commands and responses may include receiving the at least one contactless communication protocol response. For example, the kernel application may receive the at least one contactless communication protocol response from the payment application via the communication channel in secure element 104 in response to the payment application transmitting the at least one contactless communication protocol response.
[0139] In some non-limiting embodiments or aspects, the commands and / or responses may include a byte array. For example, the at least one contactless communication protocol command may include a first byte array and / or the at least one contactless communication protocol response may include a second byte array. The first byte array and / or the second byte array may include one or more parameters. In some non-limiting embodiments or aspects, the commands and / or responses may include another object type, such as a string, a class object, and / or the like. For example, user device 102 (e.g., secure element 104, the payment application, and / or the kernel application thereof) may transform the first byte array and / or the second byte array into another object type (e.g., a string and / or a class object).
[0140] As shown in FIG. 2, at step 210, process 200 may include initiating a payment transaction. For example, user device 102 may initiate a payment transaction based on the contactless communication protocol commands and responses communicated between the kernel application and the payment application via the communication channel in secure element 104.
[0141] In some non-limiting embodiments or aspects, initiating the payment transaction may include transmitting an account identifier to user device 102. Forexample, the kernel application may transmit an account identifier based on the contactless communication protocol commands and / or responses to an application (e.g., a mobile application, a merchant application, and / or the like) on user device 102.
[0142] In some non-limiting embodiments or aspects, the account identifier may be associated with the user of user device 102. In some non-limiting embodiments or aspects, the account identifier may be stored in and / or retrieved from secure element 104 (e.g., a memory of secure element 104).
[0143] In some non-limiting embodiments or aspects, the account identifier may include a static account identifier (e.g., a PAN, a payment token, and / or the like). In some non-limiting embodiments or aspects, the account identifier may include a dynamic account identifier (e.g., a cryptogram generated using a cryptographic key, such as an EMV application cryptogram generated by the payment application using a secret cryptographic key and / or retrieved by the kernel application and / or EMV data tags, such as application transaction counter (ATC) and / or application interchange profile (AIP)). In some non-limiting embodiments or aspects, the account identifier may include a static account identifier and a dynamic account identifier. For example, the kernel application may transmit the dynamic account identifier in addition to or in lieu of the static account identifier.
[0144] In some non-limiting embodiments or aspects, the payment application may communicate the account identifier to the kernel application. For example, the kernel application may receive the account identifier from the payment application via a contactless communication protocol command and / or response.
[0145] In some non-limiting embodiments or aspects, initiating the payment transaction may include generating an authorization request based on the account identifier. For example, the application on user device 102 may generate an authorization request including the account identifier in response to receiving the account identifier from the kernel application.
[0146] In some non-limiting embodiments or aspects, initiating the payment transaction may include communicating the authorization request including the account identifier. For example, the application on user device 102 may communicate the authorization request comprising the account identifier to at least one of a merchant system (e.g., merchant system 108), an acquirer system, a payment gateway, a transaction service provider system, an issuer system, any combination thereof, and / or the like.
[0147] In some non-limiting embodiments or aspects, initiating the payment transaction may include communicating at least one communication including the account identifier to at least one computing device separate from the user device. For example, the application on user device 102 may communicate the at least one communication comprising the account identifier to at least one of a merchant system (e.g., merchant system 108), an acquirer system, a payment gateway, a transaction service provider system, an issuer system, any combination thereof, and / or the like.
[0148] In some non-limiting embodiments or aspects, user device 102 may communicate the at least one communication comprising the account identifier to a payment gateway and / or merchant system 108. The payment gateway and / or merchant system 108 may generate an authorization request based on the account identifier in response to receiving the at least one communication comprising the account identifier.
[0149] In some non-limiting embodiments or aspects, the payment gateway and / or merchant system 108 may communicate the authorization request to an acquirer system and / or a transaction service provider system. In some non-limiting embodiments or aspects, upon receiving the authorization request, the acquirer system and / or the transaction service provider system may communicate the authorization request to an issuer system.
[0150] In some non-limiting embodiments or aspects, the issuer system may receive the authorization request. In some non-limiting embodiments or aspects, the issuer system may determine whether to approve or reject (e.g., deny) the payment transaction based on the authorization request.
[0151] In some non-limiting embodiments or aspects, the issuer system may generate an authorization response message based on determining whether to approve or reject the payment transaction. The authorization response message may include an indication of the determination to approve or reject the payment transaction. In some non-limiting embodiments or aspects, the issuer system may communicate the authorization response message. For example, the issuer system may communicate the authorization response message including the indication of whether the payment transaction is approved or rejected to merchant system 108 (e.g., via the transaction service provider system, the acquirer system, the payment gateway, and / or the like).
[0152] Referring now to FIG. 3, FIG. 3 is a diagram of a non-limiting embodiment or aspect of an example environment 300 in which methods, systems, and / or computer program products, described herein, may be implemented. As shown in FIG. 3, environment 300 may include transaction service provider system 302, issuer system 304, user device 306, merchant system 308, acquirer system 310, and communication network 312. In some non-limiting embodiments or aspects, each of user device 102, secure element 104, and transceiver 106 may be the same as, similar to, and / or part of user device 306. In some non-limiting embodiments or aspects, merchant system 108 and / or POS device 1 10 may be the same as, similar to, and / or part of merchant system 308. In some non-limiting embodiments or aspects, at least one of user device 102, secure element 104, transceiver 106, merchant system 108, and / or POS device 1 10 may be implemented by (e.g., part of) another system, another device, another group of systems, or another group of devices, separate from or including user device 306 and / or merchant system 308.
[0153] Transaction service provider system 302 may include one or more devices capable of receiving information from and / or communicating information to issuer system 304, user device 306, merchant system 308, and / or acquirer system 310 via communication network 312. For example, transaction service provider system 302 may include a computing device, such as a server (e.g., a transaction processing server), a group of servers, and / or other like devices. In some non-limiting embodiments or aspects, transaction service provider system 302 may be associated with a transaction service provider as described herein. In some non-limiting embodiments or aspects, transaction service provider system 302 may be in communication with a data storage device, which may be local or remote to transaction service provider system 302. In some non-limiting embodiments or aspects, transaction service provider system 302 may be capable of receiving information from, storing information in, communicating information to, or searching information stored in the data storage device.
[0154] Issuer system 304 may include one or more devices capable of receiving information and / or communicating information to transaction service provider system 302, user device 306, merchant system 308, and / or acquirer system 310 via communication network 312. For example, issuer system 304 may include a computing device, such as a server, a group of servers, and / or other like devices. In some non-limiting embodiments or aspects, issuer system 304 may be associated withan issuer institution as described herein. For example, issuer system 304 may be associated with an issuer institution that issued a credit account, debit account, credit card, debit card, and / or the like to a user associated with user device 306.
[0155] User device 306 may include one or more devices capable of receiving information from and / or communicating information to transaction service provider system 302, issuer system 304, merchant system 308, and / or acquirer system 310 via communication network 312. Additionally or alternatively, each user device 306 may include a device capable of receiving information from and / or communicating information to other customer devices 306 via communication network 312, another network (e.g., an ad hoc network, a local network, a private network, a virtual private network, and / or the like), and / or any other suitable communication technique. For example, user device 306 may include a client device and / or the like. In some nonlimiting embodiments or aspects, user device 306 may or may not be capable of receiving information (e.g., from merchant system 308 or from another user device 306) via a short-range wireless communication connection (e.g., an NFC communication connection, an RFID communication connection, a Bluetooth® communication connection, a Zigbee® communication connection, and / or the like), and / or communicating information (e.g., to merchant system 308) via a short-range wireless communication connection.
[0156] Merchant system 308 may include one or more devices capable of receiving information from and / or communicating information to transaction service provider system 302, issuer system 304, user device 306, and / or acquirer system 310 via communication network 312. Merchant system 308 may also include a device capable of receiving information from user device 306 via communication network 312, a communication connection (e.g., an NFC communication connection, an RFID communication connection, a Bluetooth® communication connection, a Zigbee® communication connection, and / or the like) with user device 306, and / or the like, and / or communicating information to user device 306 via communication network 312, the communication connection, and / or the like. In some non-limiting embodiments or aspects, merchant system 308 may include a computing device, such as a server, a group of servers, a client device, a group of client devices, and / or other like devices. In some non-limiting embodiments or aspects, merchant system 308 may be associated with a merchant as described herein. In some non-limiting embodiments or aspects, merchant system 308 may include one or more client devices. Forexample, merchant system 308 may include a client device that allows a merchant to communicate information to transaction service provider system 302. In some nonlimiting embodiments or aspects, merchant system 308 may include one or more devices, such as computers, computer systems, and / or peripheral devices capable of being used by a merchant to conduct a transaction with a user. For example, merchant system 308 may include a POS device and / or a POS system.
[0157] Acquirer system 310 may include one or more devices capable of receiving information from and / or communicating information to transaction service provider system 302, issuer system 304, user device 306, and / or merchant system 308 via communication network 312. For example, acquirer system 310 may include a computing device, a server, a group of servers, and / or the like. In some non-limiting embodiments or aspects, acquirer system 310 may be associated with an acquirer as described herein.
[0158] Communication network 312 may include one or more wired and / or wireless networks. For example, communication network 312 may include a cellular network (e.g., a long-term evolution (LTE®) network, a third generation (3G) network, a fourth generation (4G) network, a fifth generation (5G) network, a code division multiple access (CDMA) network, and / or the like), a public land mobile network (PLMN), a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a telephone network (e.g., the public switched telephone network (PSTN)), a private network (e.g., a private network associated with a transaction service provider), an ad hoc network, an intranet, the Internet, a fiber optic-based network, a cloud computing network, and / or the like, and / or a combination of these or other types of networks.
[0159] The number and arrangement of systems, devices, and / or networks shown in FIG. 3 are provided as an example. There may be additional systems, devices, and / or networks; fewer systems, devices, and / or networks; different systems, devices, and / or networks; and / or differently arranged systems, devices, and / or networks than those shown in FIG. 3. Furthermore, two or more systems or devices shown in FIG. 3 may be implemented within a single system or device, or a single system or device shown in FIG. 3 may be implemented as multiple, distributed systems or devices. Additionally or alternatively, a set of systems (e.g., one or more systems) or a set of devices (e.g., one or more devices) of environment 300 may perform one or more functions described as being performed by another set of systems or another set of devices of environment 300.
[0160] Referring now to FIG. 4, shown is a schematic diagram of example components of a device 400 according to non-limiting embodiments or aspects. Device 400 may correspond to at least one of user device 102, secure element 104, NFC 106, merchant system 108, and / or POS device 1 10 in FIG. 1 , and / or at least one of transaction service provider system 302, issuer system 304, user device 306, merchant system 308, and / or acquirer system 310 in FIG. 3, as an example. In some non-limiting embodiments or aspects, such systems or devices in FIG. 1 or FIG. 3 may include at least one device 400 and / or at least one component of device 400. The number and arrangement of components shown in FIG. 4 are provided as an example. In some non-limiting embodiments or aspects, device 400 may include additional components, fewer components, different components, or differently arranged components than those shown in FIG. 4. Additionally or alternatively, a set of components (e.g., one or more components) of device 400 may perform one or more functions described as being performed by another set of components of device 400.
[0161] As shown in FIG. 4, device 400 may include bus 402, processor 404, memory 406, storage component 408, input component 410, output component 412, and communication interface 414. Bus 402 may include a component that permits communication among the components of device 400. In some non-limiting embodiments or aspects, processor 404 may be implemented in hardware, firmware, or a combination of hardware and software. For example, processor 404 may include a processor (e.g., a central processing unit (CPU), a graphics processing unit (GPU), an accelerated processing unit (APU), etc.), a microprocessor, a digital signal processor (DSP), and / or any processing component (e.g., a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), etc.) that can be programmed to perform a function. In some non-limiting embodiments or aspects, processor 404 may be the same as or similar to GPU 104. Memory 406 may include random access memory (RAM), read only memory (ROM), and / or another type of dynamic or static storage device (e.g., flash memory, magnetic memory, optical memory, etc.) that stores information and / or instructions for use by processor 404. In some non-limiting embodiments or aspects, memory 406 may be the same as or similar to memory 106.
[0162] With continued reference to FIG. 4, storage component 408 may store information and / or software related to the operation and use of device 400. For example, storage component 408 may include a hard disk (e.g., a magnetic disk, anoptical disk, a magneto-optic disk, a solid state disk, etc.) and / or another type of computer-readable medium. Input component 410 may include a component that permits device 400 to receive information, such as via user input (e.g., a touch screen display, a keyboard, a keypad, a mouse, a button, a switch, a microphone, etc.). Additionally or alternatively, input component 410 may include a sensor for sensing information (e.g., a global positioning system (GPS) component, an accelerometer, a gyroscope, an actuator, etc.). Output component 412 may include a component that provides output information from device 400 (e.g., a display, a speaker, one or more light-emitting diodes (LEDs), etc.). Communication interface 414 may include a transceiver-like component (e.g., a transceiver, a separate receiver and transmitter, etc.) that enables device 400 to communicate with other devices, such as via a wired connection, a wireless connection, or a combination of wired and wireless connections. Communication interface 414 may permit device 400 to receive information from another device and / or provide information to another device. For example, communication interface 414 may include an Ethernet interface, an optical interface, a coaxial interface, an infrared interface, a radio frequency (RF) interface, a universal serial bus (USB) interface, a Wi-Fi® interface, a cellular network interface, and / or the like.
[0163] Device 400 may perform one or more processes described herein. Device 400 may perform these processes based on processor 404 executing software instructions stored by a computer-readable medium, such as memory 406 and / or storage component 408. A computer-readable medium may include any non- transitory memory device. A memory device includes memory space located inside of a single physical storage device or memory space spread across multiple physical storage devices. Software instructions may be read into memory 406 and / or storage component 408 from another computer-readable medium or from another device via communication interface 414. When executed, software instructions stored in memory 406 and / or storage component 408 may cause processor 404 to perform one or more processes described herein. Additionally or alternatively, hardwired circuitry may be used in place of or in combination with software instructions to perform one or more processes described herein. Thus, embodiments described herein are not limited to any specific combination of hardware circuitry and software. The term “programmed or configured,” as used herein, refers to an arrangement of software, hardware circuitry, or any combination thereof on one or more devices.
[0164] Referring now to FIG. 5, shown is an example diagram of an example system 500 for establishing secure element-based communication interfaces between kernel applications and contactless payment applications, according to some nonlimiting embodiments or aspects. As shown in FIG. 5, system 500 may include user device 502. In some non-limiting embodiments or aspects, user device 502 may be the same as, similar to, and / or part of user device 102 and / or user device 306.
[0165] In some non-limiting embodiments or aspects, user device 502 may include secure element 504 and / or NFC transceiver 506. In some non-limiting embodiments or aspects, secure element 504 may be the same as, similar to, and / or part of secure element 104. In some non-limiting embodiments or aspects, NFC transceiver 506 may be the same as, similar to, and / or part of transceiver 106.
[0166] In some non-limiting embodiments or aspects, secure element 504 may include a secure element chip installed by a manufacturer of user device 502. In some non-limiting embodiments or aspects, secure element 504 may include entry point 508, proximity payment service environment (PPSE) 510, contactless registry service (CRS) 512, kernel applications 514a, 514b, and / or payment applications 516a, 516b. In some non-limiting embodiments or aspects, each of entry point 508, PPSE 510, and / or CRS 512 may include a software application. For example, each of entry point 508, PPSE 510, and / or CRS 512 may include a software application stored in secure element 504 of user device 502.
[0167] In some non-limiting embodiments or aspects, secure element 504 may store payment applications (e.g., payments applications 516a, 516b) and / or kernel applications (e.g., kernel applications 514a, 514b). In some non-limiting embodiments or aspects, user device 502 and / or secure element 504 may generate and / or store (e.g., in CRS 512) a list of payment applications (e.g., including payment applications 516a, 516b) based on the payment applications stored in secure element 504. In some non-limiting embodiments or aspects, user device 502 and / or secure element 504 may generate and / or store (e.g., in entry point 508) the list of kernel applications (e.g., including kernel applications 514a, 514b) based on the kernel applications stored in secure element 504.
[0168] In some non-limiting embodiments or aspects, upon initiation of a payment transaction (e.g., a tap to device payment transaction) between a user of user device 502 and a merchant system, user device 502 may retrieve the list of payment applications and / or the list of kernel applications from secure element 504. In somenon-limiting embodiments or aspects, user device 502 may retrieve the list of payment applications including payment applications 516a, 516b from CRS 512. In some nonlimiting embodiments or aspects, user device 502 may retrieve the list of kernel applications 514a, 514b from entry point 508.
[0169] In some non-limiting embodiments or aspects, a payment application of the list of payment applications may correspond to a kernel application of the list of kernel applications. For example, payment application 516a may correspond to kernel application 514a, and payment application 516b may correspond to kernel application 514b. In some non-limiting embodiments or aspects, a payment application may be associated with a transaction service provider system and / or an issuer system (e.g., a bank). In some non-limiting embodiments or aspects, a kernel application may be associated with a transaction service provider system. In some non-limiting embodiments or aspects, one or more payment applications of the list of payment applications may be associated with a single kernel application of the list of kernel applications. For example, payment applications 516a and 516b may both correspond to kernel application 514a. As another example, payment applications 516a and 516b may both correspond to kernel application 514b. As another example, payment application 516a may correspond to kernel application 514b, and payment application 516b may correspond to kernel application 514a.
[0170] In some non-limiting embodiments or aspects, user device 502 may determine a list of active payment applications. For example, user device 502 may determine a list of active payment applications based on the list of payment applications and the corresponding kernel applications in response to retrieving the list of payment applications and / or the list of kernel applications. The list of active payment applications may include only the payment applications with corresponding kernel applications stored in secure element 504. In some non-limiting embodiments or aspects, the list of active payment applications may exclude any payment application of the list of payment applications which does not have a corresponding kernel application stored in secure element 504.
[0171] In some non-limiting embodiments or aspects, user device 502 may display the list of payment applications via a GUI on a display of user device 502. Additionally or alternatively, user device 502 may display the list of active payment applications via a GUI on a display of user device 502. For example, user device 502 may display the list of active payment applications via a GUI on a display of user device 502 inresponse to determining the list of active payment applications. In some non-limiting embodiments or aspects, the GUI may display a plurality of payment methods including NFC (e.g., tap to pay) and / or the list of active payment applications.
[0172] In some non-limiting embodiments or aspects, secure element 504 may activate a card emulation mode and / or a reader mode. In some non-limiting embodiments or aspects, NFC transceiver 506 may control secure element 504 via a single-wire connection between secure element 504 and NFC transceiver 506. For example, NFC transceiver 506 may activate and / or de-activate reader mode of secure element 504 using a single-wire protocol (SWP) via the connection point. In some non-limiting embodiments or aspects, NFC transceiver 506 may activate (e.g., turn on) reader mode using the SWP upon initiation of the payment transaction.
[0173] In some non-limiting embodiments or aspects, user device 502, may receive an input from a user indicating selection of a payment method of the plurality of payment methods. For example, user device 502 may receive an input from the user indicating selection of payment application 516b from the list of payment applications and / or from the list of active payment applications.
[0174] In some non-limiting embodiments or aspects, NFC transceiver 506 may deactivate (e.g., turn off) a reader mode of secure element 504 via the connection between NFC transceiver 506 and secure element 504. For example, NFC transceiver 506 may turn off reader mode of secure element 504 via the single-wire connection using a SWP in response to user device 502 receiving the selection of payment application 516b from the user.
[0175] In some non-limiting embodiments or aspects, user device 502 may select the kernel application associated with the payment application from the list of kernel applications stored in secure element 504. In some non-limiting embodiments or aspects, selecting the kernel application may include determining the kernel application from the list of kernel applications based on the input from the user indicating selection of the payment application associated with the kernel application. For example, based on the user selecting payment application 516b, user device 502 may select kernel application 514b. In some non-limiting embodiments or aspects, user device 502 may select the kernel application before or after turning off reader mode of secure element 504.
[0176] In some non-limiting embodiments or aspects, the payment application may include a contactless communication protocol payment application. In some non-limiting embodiments or aspects, the kernel application may include a contactless communication protocol payment application.
[0177] In some non-limiting embodiments or aspects, user device 502, secure element 504, and / or kernel application 514b may establish a communication channel between the kernel application and the payment application. For example, kernel application 514b may establish a communication channel between kernel application 514b and payment application 516b in secure element 504. The communication channel may be established via an interface defined in an executable object file (e.g., stored in the secure element 504).
[0178] In some non-limiting embodiments or aspects, user device 502 may communicate contactless communication protocol commands and / or responses between the kernel application and the payment application via the communication channel (e.g., without actually communicating wireless signals with NFC transceiver 506). For example, kernel application 514b may communicate contactless communication protocol commands and / or responses to payment application 516b. Kernel application 514b may receive contactless communication commands and / or responses from payment application 516b. In some non-limiting embodiments or aspects, the contactless communication protocol commands and / or responses communicated between kernel application 514b and payment application 516b via the communication channel in secure element 504 may include the commands and / or responses that would have otherwise been communicated between NFC transceiver 506 and another device if the user had selected NFC payment.
[0179] In some non-limiting embodiments or aspects, kernel application 514b may transmit at least one contactless communication protocol command to payment application 516b via the communication channel in secure element 504. Payment application 516b may receive the at least one contactless communication protocol command from kernel application 514b via the communication channel. In response to receiving the contactless communication protocol command, payment application 516b may transmit at least one contactless communication protocol response to kernel application 514b via the communication channel. Kernel application 514b may receive the at least one contactless communication protocol response from payment application 516b via the communication.
[0180] In some non-limiting embodiments or aspects, the at least one contactless communication protocol command may include a first byte array. For example, thecontactless communication protocol command may include a first byte array including an APDU command transmitted from kernel application 514b to payment application 516b. In some non-limiting embodiments or aspects, the at least one contactless communication protocol response may include a second byte array. For example, the contactless communication protocol response may include a second byte array including an APDU response transmitted from payment application 516b to kernel application 514b. In some non-limiting embodiments or aspects, the commands and / or responses may include another object type, such as a string, a class object, and / or the like. For example, user device 102 (e.g., secure element 104, the payment application, and / or the kernel application thereof) may transform the first byte array and / or the second byte array into another object type (e.g., a string and / or a class object).
[0181] In some non-limiting embodiments or aspects, user device 502 may initiate a payment transaction based on the contactless communication protocol commands and / or responses. For example, user device 502 may initiate a payment transaction based on the contactless communication protocol commands and / or responses communicated between kernel application 514b and payment application 516b via the communication channel in secure element 504.
[0182] In some non-limiting embodiments or aspects, when initiating the payment transaction, kernel application 514b may transmit an account identifier. For example, kernel application 514b may transmit an account identifier based on the contactless communication protocol commands and / or responses to an application (e.g., a mobile application, a merchant application, and / or the like, which may be outside of secure element 504) on user device 502. In some non-limiting embodiments or aspects, kernel application 514b may receive the account identifier from payment application 516b. In some non-limiting embodiments or aspects, the account identifier may include a static account identifier (e.g., a PAN, a payment token, and / or the like). In some non-limiting embodiments or aspects, the account identifier may include a dynamic account identifier (e.g., a cryptogram generated using a cryptographic key, such as an EMV application cryptogram generated by the payment application using a secret cryptographic key and / or retrieved by the kernel application and / or EMV data tags, such as application transaction counter (ATC) and / or application interchange profile (AIP)). In some non-limiting embodiments or aspects, the account identifier may include a static account identifier and a dynamic account identifier. For example,the kernel application may transmit the dynamic account identifier in addition to or in lieu of the static account identifier.
[0183] In some non-limiting embodiments or aspects, when initiating the payment transaction, the application on user device 502 may generate an authorization request. The authorization request may include the account identifier. For example, the application on user device 502 may generate the authorization request including the account identifier in response to receiving the account identifier from kernel application 514b.
[0184] In some non-limiting embodiments or aspects, the application on user device 502 may communicate the authorization request including the account identifier. For example, the application on user device 502 may communicate the authorization request including the account identifier to a merchant system, an acquirer system, a payment gateway, a transaction service provider system, an issuer system, and / or the like, as described herein.
[0185] In some non-limiting embodiments or aspects, the application on user device 502 may generate and / or communicate at least one communication including the account identifier to at least one computing device separate from user device 502. For example, the application on user device 502 may generate and / or communicate at least one communication including the account identifier to a merchant system, an acquirer system, a payment gateway, a transaction service provider system, and / or an issuer system, as described herein.
[0186] Referring now to FIG. 6, FIG. 6 is an example graphical user interface (GUI) 600 for use in a system for establishing secure element-based communication interfaces between kernel applications and a contactless payment applications, according to some non-limiting embodiments or aspects.
[0187] In some non-limiting embodiments or aspects, GUI 600 may be presented (e.g., displayed) via a display of a user device (e.g., user device 102 and / or user device 502).
[0188] In some non-limiting embodiments or aspects, GUI 600 may include a plurality of payment methods, such as NFC payment 602, payment application 604, and / or payment application 606. In some non-limiting embodiments or aspects, GUI 600 may display a card wallet including one or more of the plurality of payment methods. For example, the card wallet may include payment application 604 and / or payment application 606. In some non-limiting embodiments or aspects, GUI 600 maydisplay data associated with a merchant and / or data associated with the payment transaction. For example, GUI 600 may display a merchant name associated with the merchant, a merchant address associated with the merchant, a transaction date, a transaction time, a transaction amount, etc.
[0189] In some non-limiting embodiments or aspects, GUI 600 may display a message. For example, GUI 600 may display a message prompting the user to select a payment method for example, NFC payment 602 (e.g., choose tap card) or payment application 604, 606 (e.g., choose card from card wallet).
[0190] In some non-limiting embodiments or aspects, GUI 600 may be configured to receive an input, such as a selection from the user. For example, GUI 600 may receive an input from the user in response to displaying the message including the prompt. In some non-limiting embodiments or aspects, GUI 600 may update and / or change based on the input from a user.
[0191] In some non-limiting embodiments or aspects, if the user selects NFC payment 602, the user may be required to retrieve a payment device (e.g., a payment card) and move (e.g., tap) the payment device near the user device displaying GUI 600. For example, if the user selects NFC payment 602, the user may be required to retrieve a payment card and tap it against the user device.
[0192] In some non-limiting embodiments or aspects, if the user selects one of payment application 604, 606, then GUI 600 may update and / or change based on the user selection.
[0193] In some non-limiting embodiments or aspects, if the user selects payment application 604 then a secure element of the user device (e.g., secure element 104, 504) may be triggered to turn off a reader mode with a transceiver of the user device (e.g., transceiver 106, NFC transceiver 506). In response to the reader mode being turned off, a kernel application corresponding to payment application 604 may be selected based on the user’s selection of payment application 604. The kernel application may open a communication channel with payment application 604 within the secure element (e.g., 104, 504) of the user device. The kernel application may communicate contactless communication protocol commands and / or responses through the established communication channel in the secure element (e.g., 104, 504) of the user device. The kernel application may obtain (e.g., receive from payment application 604) the payment credentials (e.g., account identifier) associated with payment application 604. The kernel application may communicate the paymentcredentials (e.g., account identifier) associated with payment application 604 to at least one computing device separate from the user device for authorizing the transaction.
[0194] Referring now to FIG. 7, shown is a swimlane diagram of an example process 700 for establishing secure element-based communication interfaces between kernel applications and a contactless payment applications, according to some non-limiting embodiments or aspects. The steps shown in FIG. 7 are for example purposes only. It will be appreciated that additional, fewer, different, and / or a different order of steps may be used in non-limiting embodiments or aspects.
[0195] In some non-limiting embodiments or aspects, user device 702 may include a secure element (e.g., secure element 104, 504) and / or a transceiver (e.g., transceiver 106, NFC transceiver 506).
[0196] As shown in FIG. 7, at step 710, user device 702 may retrieve and / or generate a list of payment applications (e.g., including payment application 708) and / or a list of kernel applications (e.g., including kernel application 706). For example, user device 702 may retrieve a list of payment applications from a CRS (e.g., CRS 512) of the secure element of user device 702. Additionally or alternatively user device 702 may retrieve a list of kernel applications from an entry point (e.g., entry point 508) of the secure element of user device 702.
[0197] In some non-limiting embodiments or aspects, a payment application of the list of payment applications may correspond to a kernel application of the list of kernel applications. For example, payment application 708 may correspond to kernel application 706. In some non-limiting embodiments or aspects, payment application 708 may be associated with a transaction service provider system and / or an issuer system (e.g., a bank). In some non-limiting embodiments or aspects, a kernel application 706 may be associated with a transaction service provider system.
[0198] In some non-limiting embodiments or aspects, user device 702 may determine the list of active payment applications. For example, user device 702 may determine a list of active payment applications based on the list of payment applications and the corresponding kernel applications in response to retrieving the list of payment applications and / or the list of kernel applications. The list of active payment applications may include only the payment applications with corresponding kernel applications stored in the secure element. In some non-limiting embodiments or aspects, the list of active payment applications may exclude any paymentapplication of the list of payment applications which does not have a corresponding kernel application stored in the secure element.
[0199] As shown in FIG. 7, at step 712, user device 702 may display the list of payment applications (and / or the list of active payment applications) via GUI 704 on the display of user device 702. For example, user device 702 may display the list of active payment applications via GUI 704 in response to determining the list of active payment applications.
[0200] In some non-limiting embodiments or aspects, GUI 704 may display a plurality of payment methods including NFC (e.g., tap to pay) and / or the list of active payment applications. GUI 704 may display a NFC tap icon and / or a card wallet including an icon for each application of the list of active payment applications. GUI 704 may display data associated with the payment transaction (e.g., merchant data, user data, transaction data, and / or the like). GUI 704 may display a message prompting the user to select a payment method from the plurality of payment methods.
[0201] As shown in FIG. 7, at step 714, the secure element of user device 702 may be triggered to turn on (e.g., activate) reader mode with the transceiver. For example, the transceiver may turn on a reader mode of the transceiver (e.g., NFC transceiver 506 in reader mode) via a single-wire connection using a SWP upon initiating the transaction.
[0202] As shown in FIG. 7, at step 716, user device 702 may receive an input from the user including a selection of one of the payment methods of the plurality of payments methods.
[0203] In some non-limiting embodiments or aspects, user device 702 may receive a selection of the NFC payment method based on the user selecting the NFC icon and / or by moving a payment device (e.g., a payment card) within a range of user device 702.
[0204] In some non-limiting embodiments or aspects, user device 702 may receive a selection of payment application 708.
[0205] In some non-limiting embodiments or aspects, the secure element of user device 702 may be configured to maintain reader mode on and / or switch off (e.g., deactivate) reader mode (e.g., activate a card emulation mode). For example, the secure element of user device 702 may maintain reader mode on or switch reader mode off (e.g., de-activate reader mode and activate card emulation mode) based on the input from the user.
[0206] If user device 702 receives an input from the user including a selection of the NFC payment method based on the user moving the payment card with a range of user device 702, then kernel application may maintain reader mode on. For example, kernel application 706 may interact with the payment card to complete the transaction using a contactless payment protocol (e.g., Europay, MasterCard, and Visa (EMV) contactless protocol) while the transceiver (NFC transceiver 506) is in reader mode.
[0207] If user device 702 receives an input from the user including a selection of payment application 708, the secure element of user device 702 may be triggered to turn off reader mode (e.g., de-activating reader mode), activating a card emulation mode of the transceiver.
[0208] As shown in FIG. 7, at step 718, user device 702 may select the kernel application associated with the payment application from the list of kernel applications stored in the secure element. For example, user device 702 may select kernel application 706 associated with payment application 708 based on the input from the user including payment application 708. In some non-limiting embodiments or aspects, selecting the kernel application may include determining the kernel application from the list of kernel applications based on the input from the user indicating selection of the payment application associated with the kernel application. For example, based on the user selecting payment application 708, user device 702 may select kernel application 706. In some non-limiting embodiments or aspects, user device 702 may select the kernel application before or after turning off reader mode of the secure element.
[0209] In some non-limiting embodiments or aspects, payment application 708 may include a contactless communication protocol payment application. In some nonlimiting embodiments or aspects, kernel application 706 may include a contactless communication protocol payment application.
[0210] As shown in FIG. 7, at step 720, kernel application 706 may establish a communication channel between kernel application 7060 and the payment application 708. For example, kernel application 706 may establish a communication channel between kernel application 706 and payment application 708 in the secure element of user device 702. The communication channel may be established via an interface defined in an executable object file (e.g., stored in the secure element).
[0211] As shown in FIG. 7, at step 722, kernel application 706 and payment application 708 may communicate contactless communication protocol commands and / or responses via the communication channel (e.g., without actually communicating wireless signals with a transceiver of user device 702). For example, kernel application 706 may communicate contactless communication protocol commands and / or responses to payment application 708. Kernel application 706 may receive contactless communication commands and / or responses from payment application 708. In some non-limiting embodiments or aspects, the contactless communication protocol commands and / or responses communicated between kernel application 706 and payment application 708 may include the commands and / or responses that would have otherwise been communicated between the transceiver (e.g., NFC transceiver 506) and another device if the user had selected NFC payment.
[0212] In some non-limiting embodiments or aspects, kernel application 706 may transmit at least one contactless communication protocol command to payment application 708 via the communication channel the secure element (e.g., secure element 504). Payment application 708 may receive the at least one contactless communication protocol command from kernel application 706 via the communication channel. In response to receiving the contactless communication protocol command, payment application 708 may transmit at least one contactless communication protocol response to kernel application 706 via the communication channel. Kernel application 708 may receive the at least one contactless communication protocol response from payment application 706 via the communication.
[0213] In some non-limiting embodiments or aspects, the at least one contactless communication protocol command may include a first byte array. For example, the contactless communication protocol command may include a first byte array including an APDU command transmitted from kernel application 706 to payment application 708. In some non-limiting embodiments or aspects, the at least one contactless communication protocol response may include a second byte array. For example, the contactless communication protocol response may include a second byte array including an APDU response transmitted from payment application 708 to kernel application 706.
[0214] In some non-limiting embodiments or aspects, kernel application 706 may receive a communication protocol command and / or response including an accountidentifier from payment application 708. The account identifier may be associated with an account of the user of user device 702.
[0215] As shown in FIG. 7, at step 724, kernel application 706 may communicate a message to user device 702 (e.g., a payment application being executed on user device 702. In some non-limiting embodiments or aspects, kernel application 706 may transmit the account identifier based on the contactless communication protocol commands and / or responses to an application (e.g., a mobile application, a merchant application, and / or the like, which may be outside of the secure element) on user device 702.
[0216] As shown in FIG. 7, at step 726, user device 702 may initiate a payment transaction with a merchant. For example, the user of user device 702 may initiate a payment transaction with a merchant associated with a merchant system (e.g., merchant system 108, 308).
[0217] In some non-limiting embodiments or aspects, when initiating the payment transaction, the application on user device 702 may generate an authorization request. The authorization request may include the account identifier. For example, the application on user device 702 may generate the authorization request including the account identifier in response to receiving the account identifier from kernel application 706.
[0218] In some non-limiting embodiments or aspects, the application on user device 702 may communicate the authorization request including the account identifier. For example, the application on user device 702 may communicate the authorization request including the account identifier to a merchant system, an acquirer system, a payment gateway, a transaction service provider system, an issuer system, and / or the like, as described herein.
[0219] In some non-limiting embodiments or aspects, the application on user device 702 may generate and / or communicate at least one communication including the account identifier to at least one computing device separate from user device 702. For example, the application on user device 702 may generate and / or communicate at least one communication including the account identifier to a merchant system, an acquirer system, a payment gateway, a transaction service provider system, and / or an issuer system, as described herein.
[0220] Although embodiments have been described in detail for the purpose of illustration, it is to be understood that such detail is solely for that purpose and that thedisclosure is not limited to the disclosed embodiments or aspects, but, on the contrary, is intended to cover modifications and equivalent arrangements that are within the spirit and scope of the appended claims. For example, it is to be understood that the present disclosure contemplates that, to the extent possible, one or more features of any embodiment or aspect can be combined with one or more features of any other embodiment or aspect.
Claims
WHAT IS CLAIMED IS:1 . A computer-implemented method, comprising: receiving, with at least one processor, an input from a user of a user device indicating selection of a payment application stored in a secure element of the user device; selecting, with at least one processor, a kernel application stored in the secure element of the user device associated with the payment application; establishing, with at least one processor, a communication channel between the kernel application and the payment application in the secure element of the user device; communicating, with at least one processor, contactless communication protocol commands and responses between the kernel application and the payment application via the communication channel in the secure element; and initiating, with at least one processor, a payment transaction based on the contactless communication protocol commands and responses communicated between the kernel application and the payment application via the communication channel in the secure element.
2. The computer-implemented method of claim 1 , further comprising: retrieving, with at least one processor, a list of payment applications and a list of kernel applications stored in the secure element of the user device, wherein the input indicates selection of the payment application from the list of payment applications, and wherein selecting the kernel application comprises determining the kernel application from the list of kernel applications based on the input indicating selection of the payment application associated with the kernel application.
3. The computer-implemented method of claim 1 , wherein the payment application comprises a contactless communication protocol payment application.
4. The computer-implemented method of claim 1 , wherein the kernel application comprises a contactless communication protocol payment application.
5. The computer-implemented method of claim 1 , wherein the communication channel is established via an interface defined in an executable object file.
6. The computer-implemented method of claim 1 , wherein communicating the contactless communication protocol commands and responses between the kernel application and the payment application via the communication channel in the secure element comprises: transmitting, by the kernel application, at least one contactless communication protocol command to the payment application via the communication channel in the secure element; receiving, by the payment application, the at least one contactless communication protocol command from the kernel application via the communication channel in the secure element; transmitting, by the payment application, the at least one contactless communication protocol response to the kernel application via the communication channel in the secure element in response to receiving the at least one contactless communication protocol command; and receiving, by the kernel application, the at least one contactless communication protocol response from the payment application via the communication channel in the secure element.
7. The computer-implemented method of claim 6, wherein the at least one contactless communication protocol command comprises a first byte array, and wherein the at least one contactless communication protocol response comprises a second byte array.
8. The computer-implemented method of claim 1 , wherein initiating the payment transaction comprises:transmitting, by the kernel application, an account identifier based on the contactless communication protocol commands and responses to an application on the user device.
9. The computer-implemented method of claim 8, wherein initiating the payment transaction further comprises: generating, by the application on the user device, an authorization request comprising the account identifier in response to receiving the account identifier from the kernel application; and communicating, by the application on the user device, the authorization request comprising the account identifier.
10. The computer-implemented method of claim 8, wherein, initiating the payment transaction further comprises: communicating, by the application on the user device, at least one communication comprising the account identifier to at least one computing device separate from the user device.1 1. A system, comprising: at least one processor; and at least one non-transitory computer-readable medium storing instructions that, when executed by the at least one processor, cause the at least one processor to: receive an input from a user of a user device indicating selection of a payment application stored in a secure element of the user device; select a kernel application stored in the secure element of the user device associated with the payment application; establish a communication channel between the kernel application and the payment application in the secure element of the user device; communicate contactless communication protocol commands and responses between the kernel application and the payment application via the communication channel in the secure element; andinitiate a payment transaction based on the contactless communication protocol commands and responses communicated between the kernel application and the payment application via the communication channel in the secure element.
12. The system of claim 1 1 , wherein the instructions further cause the at least one processor to: retrieve a list of payment applications and a list of kernel applications stored in the secure element of the user device, wherein the input indicates selection of the payment application from the list of payment applications, and wherein, when selecting the kernel application, the instructions cause the at least one processor to determine the kernel application from the list of kernel applications based on the input indicating selection of the payment application associated with the kernel application.
13. The system of claim 1 1 , wherein the payment application comprises a contactless communication protocol payment application, and wherein the kernel application comprises a contactless communication protocol payment application.
14. The system of claim 11 , wherein the communication channel is established via an interface defined in an executable object file.
15. The system of claim 1 1 , wherein, when communicating the contactless communication protocol commands and responses between the kernel application and the payment application via the communication channel in the secure element, the instructions cause the at least one processor to: transmit, by the kernel application, at least one contactless communication protocol command to the payment application via the communication channel in the secure element; receive by the payment application, the at least one contactless communication protocol command from the kernel application via the communication channel in the secure element;transmit, by the payment application, the at least one contactless communication protocol response to the kernel application via the communication channel in the secure element in response to receiving the at least one contactless communication protocol command; and receive, by the kernel application, the at least one contactless communication protocol response from the payment application via the communication channel in the secure element.
16. The system of claim 16, wherein the at least one contactless communication protocol command comprises a first byte array, and wherein the at least one contactless communication protocol response comprises a second byte array.
17. The system of claim 1 1 , wherein, when initiating the payment transaction, the instructions cause the at least one processor to: transmit, by the kernel application, an account identifier based on the contactless communication protocol commands and responses to an application on the user device.
18. The system of claim 18, wherein, when initiating the payment transaction, the instructions further cause the at least one processor to: generate, by the application on the user device, an authorization request comprising the account identifier in response to receiving the account identifier from the kernel application; and communicate, by the application on the user device, the authorization request comprising the account identifier.
19. The system of claim 18, wherein, when initiating the payment transaction, the instructions further cause the at least one processor to: communicate, by the application on the user device, at least one communication comprising the account identifier to at least one computing device separate from the user device.
20. A computer program product, comprising at least one non- transitory computer-readable medium including program instructions that, when executed by at least one processor, cause the at least one processor to: receive an input from a user of a user device indicating selection of a payment application stored in a secure element of the user device; select a kernel application stored in the secure element of the user device associated with the payment application; establish a communication channel between the kernel application and the payment application in the secure element of the user device; communicate contactless communication protocol commands and responses between the kernel application and the payment application via the communication channel in the secure element; and initiate a payment transaction based on the contactless communication protocol commands and responses communicated between the kernel application and the payment application via the communication channel in the secure element.