User interfaces for managing secure operations

The method and interface streamline secure operations by using an external automotive head unit to communicate with an external receiving device, addressing inefficiencies and safety concerns in existing techniques, ensuring safer and more efficient vehicle operation.

JP2025106289APending Publication Date: 2025-07-15APPLE INC
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2025042570
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2020-10-21
Filing Date
2025-03-17
Publication Date
2025-07-15

AI Technical Summary

Technical Problem

Existing techniques for managing secure operations on electronic devices are cumbersome and inefficient, particularly when users are operating vehicles, often requiring multiple inputs and permissions that can be unsafe and distracting.

Method used

A method and interface that allows for secure operations to be managed through an external automotive head unit, reducing the need for user inputs by communicating with an external receiving device to perform transfer operations efficiently and securely.

Benefits of technology

Enhances safety and efficiency by minimizing user distraction and cognitive burden while operating a vehicle, reducing redundant user inputs, and optimizing processor and battery usage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025106289000001_ABST
    Figure 2025106289000001_ABST
Patent Text Reader

Abstract

To provide a faster, more secure and more efficient method, program, computer system, and non-transitory computer-readable medium for managing secure operations.SOLUTION: The present method includes: receiving, from an external automobile head unit, first data corresponding to input received at one or more input components of the external automobile head unit, the first data corresponding to a request to perform a first transfer operation from a first account to a second account using an application on a computer system associated with the first account; and initiating a process, in response to receiving the first data, to perform the first transfer operation using the application on the computer system, wherein, performing the first transfer operation includes transmitting, to an external receiving device, second data that includes information that identifies the first account.SELECTED DRAWING: Figure 8
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application claims priority to U.S. patent application Ser. No. 17 / 076,694, filed Oct. 21, 2020, entitled “USER INTERFACES FOR MANAGING SECURE OPERATIONS,” and U.S. provisional patent application Ser. No. 63 / 041,969, filed Jun. 21, 2020, entitled “USER INTERFACES FOR MANAGING SECURE OPERATIONS.” The entire contents of each of these applications are hereby incorporated by reference.

[0002] This disclosure generally relates to computer user interfaces, and more specifically to techniques for managing secure operations via inputs received at an external device.

Background Art

[0003] Users often use personal electronic devices to perform operations. Such techniques typically require the user to provide various inputs and permissions to perform these operations.

Summary of the Invention

[0004] However, some techniques for managing secure operations using electronic devices are generally cumbersome and inefficient. For example, some existing techniques require the user to provide various inputs and permissions to perform these operations on a personal device (e.g., a mobile phone), and these inputs may not be convenient or safe for the user to provide while the user is operating a vehicle.

[0005] Accordingly, the present technology provides a faster, more secure, and more efficient method and interface for managing secure operations using an electronic device to the electronic device. Such a method and interface optionally complement or replace other methods for managing secure operations. Such a method and interface is safer, such as not distracting the user while the user is operating a vehicle. Such a method and interface reduces the cognitive burden on the user and creates a more efficient human-machine interface.

[0006] According to some embodiments, a method is described. The method is executed in a computer system that includes one or more input components and communicates with an external automotive head unit that communicates with an external receiving device. The method includes receiving, at one or more input components of the external automotive head unit, first data corresponding to an input received in response to a request to perform a first transfer operation from a first account to a second account using an application on the computer system associated with the first account, and starting, in response to receiving the first data, a process of performing the first transfer operation using an application on the computer system, wherein performing the first transfer operation includes transmitting, to the external receiving device, second data including information identifying the first account.

[0007] According to some embodiments, a non-transitory computer-readable storage medium is described. The non-transitory computer-readable storage medium stores one or more programs configured to be executed by one or more processors of a computer system that includes one or more input components and communicates with an external automotive head unit that communicates with an external receiving device. The one or more programs receive first data corresponding to an input received by one or more input components of the external automotive head unit in response to a request to perform a first transfer operation from a first account to a second account using an application on the computer system associated with the first account, start a process to perform the first transfer operation using the application on the computer system in response to receiving the first data, and the performing of the first transfer operation includes sending, to the external receiving device, second data including information identifying the first account, and includes instructions.

[0008] According to some embodiments, a transitory computer-readable storage medium is described. The transitory computer-readable storage medium stores one or more programs configured to be executed by one or more processors of a computer system that includes one or more input components and communicates with an external automotive head unit that communicates with an external receiving device. The one or more programs receive first data corresponding to an input received by one or more input components of the external automotive head unit in response to a request to perform a first transfer operation from a first account to a second account using an application on the computer system associated with the first account, start a process to perform the first transfer operation using the application on the computer system in response to receiving the first data, and the performing of the first transfer operation includes sending, to the external receiving device, second data including information identifying the first account, and includes instructions.

[0009] According to some embodiments, a computer system is described. The computer system includes one or more processors that communicate with an external automotive head unit including one or more input components, and the computer system communicates with an external receiving device. The computer system further includes a memory storing one or more programs configured to be executed by the one or more processors. The one or more programs include instructions for receiving first data corresponding to an input received by one or more input components of the external automotive head unit in response to a request to perform a first transfer operation from a first account to a second account using an application on the computer system associated with the first account, starting a process to perform the first transfer operation using the application on the computer system in response to receiving the first data, and performing the first transfer operation includes sending second data including information identifying the first account to the external receiving device.

[0010] According to some embodiments, a computer system is described. The computer system communicates with an external automotive head unit including one or more input components, and the computer system communicates with an external receiving device. The computer system includes means for receiving first data corresponding to an input received by one or more input components of the external automotive head unit in response to a request to perform a first transfer operation from a first account to a second account using an application on the computer system associated with the first account, and means for starting a process to perform the first transfer operation using the application on the computer system in response to receiving the first data, where performing the first transfer operation includes sending second data including information identifying the first account to the external receiving device.

[0011] According to some embodiments, a method is described. The method is executed in a computer system. The computer system receives a first request from an external input device that interacts with a first part of a user interface associated with a secure transaction, which requests a separate permission from the user when permitted by the computer system while the computer system is connected to the external input device. In response to receiving the first request, the computer system provides an option to initiate a secure transaction via the external input device without requesting a separate permission from the user according to a determination that the external input device meets a set of permission criteria, and cancels the option to initiate a secure transaction without requesting a separate permission from the user according to a determination that the external input device does not meet the set of permission criteria.

[0012] According to some embodiments, a non-transitory computer-readable storage medium is described. The non-transitory computer-readable storage medium stores one or more programs configured to be executed by one or more processors of a computer system. The one or more programs include instructions to receive a first request from an external input device that interacts with a first part of a user interface associated with a secure transaction, which requests a separate permission from the user when permitted by the computer system while the computer system is connected to the external input device. In response to receiving the first request, the one or more programs provide an option to initiate a secure transaction via the external input device without requesting a separate permission from the user according to a determination that the external input device meets a set of permission criteria, and further include instructions to cancel the option to initiate a secure transaction without requesting a separate permission from the user according to a determination that the external input device does not meet the set of permission criteria.

[0013] According to some embodiments, a non-transitory computer-readable storage medium is described. The non-transitory computer-readable storage medium stores one or more programs configured to be executed by one or more processors of a computer system. The one or more programs include instructions to receive a first request from an external input device that interacts with a first portion of a user interface associated with a secure transaction, the first request requesting a separate permission from a user when permitted by the computer system while the computer system is connected to the external input device. The one or more programs further include instructions to, in response to receiving the first request, provide an option to initiate a secure transaction via the external input device without requesting a separate permission from the user according to a determination that the external input device meets a set of permission criteria, and to refrain from providing an option to initiate a secure transaction without requesting a separate permission from the user according to a determination that the external input device does not meet the set of permission criteria.

[0014] According to some embodiments, a computer system is described. The computer system includes one or more processors and a memory storing one or more programs configured to be executed by the one or more processors. The one or more programs include instructions to receive a first request from an external input device that interacts with a first portion of a user interface associated with a secure transaction, the first request requesting a separate permission from a user when permitted by the computer system while the computer system is connected to the external input device. The one or more programs further include instructions to, in response to receiving the first request, provide an option to initiate a secure transaction via the external input device without requesting a separate permission from the user according to a determination that the external input device meets a set of permission criteria, and to refrain from providing an option to initiate a secure transaction without requesting a separate permission from the user according to a determination that the external input device does not meet the set of permission criteria.

[0015] According to some embodiments, a computer system is described. The computer system, while the computer system is connected to an external input device, when permitted from the computer system, receives a first request from an external input device that interacts with a first portion of a user interface associated with a secure transaction that requests a separate permission from a user, and in response to receiving the first request, provides an option to initiate a secure transaction via the external input device without requesting a separate permission from the user according to a determination that the external input device meets a set of permission criteria, and according to a determination that the external input device does not meet the set of permission criteria, stops providing an option to initiate a secure transaction without requesting a separate permission from the user.

[0016] The executable instructions for performing these functions are optionally included within a non-transitory computer-readable storage medium or other computer program product configured to be executed by one or more processors. The executable instructions for performing these functions are optionally included within a temporary computer-readable storage medium or other computer program product configured to be executed by one or more processors.

[0017] Accordingly, a faster and more efficient method and interface for managing secure operations are provided to the device, thereby increasing the effectiveness, efficiency, and user satisfaction of such a device. Such a method and interface can complement or replace other methods for managing secure operations.

Brief Description of the Drawings

[0018] To better understand the various embodiments described, the following "Modes for Carrying Out the Invention" should be referred to in conjunction with the following drawings, and like reference numerals refer to corresponding parts throughout the following figures.

[0019]

Figure 1A

[0020]

Figure 1B

[0021]

Figure 2

[0022]

Figure 3

[0023]

Figure 4A

[0024]

Figure 4B

[0025]

Figure 5A

[0026]

Figure 5B

[0027]

Figure 6A

Figure 6B

Figure 6C

Figure 6D

Figure 6E

Figure 6F

[0028]

Figure 7A

Figure 7B

Figure 7C

Figure 7D

Figure 7E

Figure 7F

Figure 7G

Figure 7H

Figure 7I

Figure 7J

Figure 7K

Figure 7L

Figure 7M

[0029]

Figure 8

[0030]

Figure 9

DETAILED DESCRIPTION OF THE INVENTION

[0031] The following description describes exemplary methods, parameters, etc. However, it should be recognized that such description is not intended as a limitation on the scope of the present disclosure, but rather as a description of exemplary embodiments.

[0032] There is a need for an electronic device that provides an efficient method and interface for managing secure operations. For example, there is a need to provide a technology that enhances safety when managing operations that can be performed while a vehicle is being operated. Such a method and interface are safer, such as not distracting the user while the user is operating the vehicle. Such a technology can reduce the cognitive burden on the user who needs to perform the operation, thereby enhancing productivity. Further, such a technology can reduce the power of the processor and battery that would otherwise be wasted on redundant user input.

[0033] Hereinafter, FIGS. 1A-1B, 2, 3, 4A-4B, and 5A-5B provide an illustration of an exemplary device for performing a technique for managing secure operations.

[0034] FIGS. 6A-6F show an exemplary user interface for performing secure operations according to some embodiments. FIGS. 7A-7M show an exemplary user interface for performing secure operations according to some embodiments. FIG. 8 is a flowchart showing a method for performing secure operations according to some embodiments. FIG. 9 is a flowchart showing a method for providing an option to initiate a secure operation according to some embodiments. The user interfaces of FIGS. 6A-6F and 7A-7M are used to illustrate the processes described below, including the processes of FIGS. 8 and 9.

[0035] The processes described below improve the operability of a device by various techniques, including providing improved visual feedback to a user, reducing the number of inputs required to perform an operation, providing additional control options without cluttering the user interface with additional displayed controls, performing an operation when a set of conditions is met without requiring further user input, and / or by additional techniques, (e.g., assisting the user to provide appropriate inputs when operating / interacting with the device and reducing user errors), making the user-device interface more efficient. These techniques also reduce power usage and improve the battery life of the device by enabling the user to use the device more quickly and efficiently.

[0036] In addition, in the methods described herein where one or more steps depend on one or more conditions being satisfied, it should be understood that the described methods can be repeated multiple times, such that over the course of the repetitions, all of the conditions on which the steps of the method depend are satisfied in different repetitions of the method. For example, if a method requires performing a first step when a condition is satisfied and a second step when the condition is not satisfied, one of ordinary skill in the art will understand that the claimed steps are repeated not in a particular order, but both until the condition is satisfied and until the condition ceases to be satisfied. Thus, a method described in terms of one or more steps that depend on one or more conditions being satisfied can be rewritten as a method that is repeated until each of the conditions described in the method is satisfied. However, this is not required in claims for a system or computer-readable medium that includes instructions to perform actions that depend on the satisfaction of one or more corresponding conditions, and thus can determine whether the situation-dependent nature is satisfied without explicitly repeating the steps of the method until all of the conditions on which the steps of the method depend are satisfied. One of ordinary skill in the art will also understand that a system or computer-readable storage medium can repeat the steps of the method as many times as necessary to ensure that all of the conditional steps are executed, similar to a method with conditional steps.

[0037] In the following description, for purposes of explaining various elements, terms such as "first", "second", etc. are used, but these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of the various embodiments described, a first touch can be referred to as a second touch, and similarly, a second touch can be referred to as a first touch. The first touch and the second touch are both touches, but they are not the same touch.

[0038] The terms used in the description of the various embodiments described herein are for the purpose of describing particular embodiments only and are not intended to be limiting. In the description of the various embodiments and the appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly dictates otherwise. Also, as used herein, the term "and / or" refers to any and all combinations of one or more of the associated listed items and is to be understood to include the same. It is further understood that the terms "includes," "including," "comprises," and / or "comprising," when used in this specification, specify the presence of the stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0039] The term "if" may optionally be construed to mean "when" or "upon", or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrases "if it is determined" or "if [a stated condition or event] is detected" may optionally be construed to mean "upon determining" or "in response to determining", or "upon detecting [the stated condition or event]" or "in response to detecting [the stated condition or event]", depending on the context.

[0040] Embodiments of electronic devices, user interfaces for such devices, and related processes for using such devices are described. In some embodiments, the device is a portable communication device, such as a cellular phone, that also includes other functions, such as PDA functionality and / or music player functionality. Exemplary embodiments of portable multifunctional devices include, but are not limited to, devices such as the iPhone®, iPod Touch®, and iPad® from Apple Inc. of Cupertino, California. Optionally, other portable electronic devices, such as a laptop computer or a tablet computer having a touch-sensitive surface (e.g., a touch screen display and / or a touch pad), are also used. Also, in some embodiments, it should be understood that the device is not a portable communication device, but a desktop computer having a touch-sensing surface (e.g., a touch screen display and / or a touch pad). In some embodiments, the electronic device is a computer system that communicates (e.g., via wired communication, via wireless communication) with a display generation component. The display generation component is configured to provide a visual output, such as a display via a CRT display, a display via an LED display, or a display via image projection. In some embodiments, the display generation component is integrated with the computer system. In some embodiments, the display generation component is separate from the computer system. As used herein, "displaying" content includes transmitting data (e.g., image data or video data) to an integrated or external display generation component via a wired or wireless connection in order to visually generate the content, such that the content (e.g., video data rendered or decoded by a display controller 156) is displayed.

[0041] In the following discussion, an electronic device including a display and a touch sensing surface will be described. However, it should be understood that the electronic device optionally includes one or more other physical user interface devices such as a physical keyboard, a mouse, and / or a joystick.

[0042] The device typically supports various applications such as one or more of a drawing application, a presentation application, a word processing application, a website creation application, a disk authoring application, a spreadsheet application, a game application, a phone application, a video conferencing application, an email application, an instant messaging application, a training support application, a photo management application, a digital camera application, a digital video camera application, a web browsing application, a digital music player application, and / or a digital video player application.

[0043] The various applications executed on the device optionally use at least one common physical user interface device such as a touch sensing surface. One or more functions of the touch sensing surface, as well as the corresponding information displayed on the device, are optionally adjusted and / or changed for each application and / or within an individual application. Thus, the common physical architecture of the device (such as a touch sensing surface) optionally supports various applications with a user interface that is intuitive and transparent to the user.

[0044] Attention is now directed to an embodiment of a portable device having a touch-sensing display. FIG. 1A is a block diagram showing a portable multifunctional device 100 having a touch-sensing display system 112 according to some embodiments. The touch-sensing display 112 may be referred to herein, for convenience, as a “touch screen,” and may be known or referred to as a “touch-sensing display system.” The device 100 includes a memory 102 (optionally including one or more computer-readable storage media), a memory controller 122, one or more processing units (CPUs) 120, a peripheral device interface 118, an RF circuit 108, an audio circuit 110, a speaker 111, a microphone 113, an input / output (I / O) subsystem 106, other input control devices 116, and an external port 124. The device 100 optionally includes one or more optical sensors 164. The device 100 optionally includes one or more contact intensity sensors 165 (e.g., a touch-sensing surface such as the touch-sensing display system 112 of the device 100) for detecting the intensity of a contact on the device 100. The device 100 optionally includes one or more haptic output generators 167 for generating haptic output on the device 100 (e.g., generating haptic output on a touch-sensing surface such as the touch-sensing display system 112 of the device 100 or the touch pad 355 of the device 300). These components optionally communicate via one or more communication buses or signal lines 103.

[0045] As used in this specification and the claims, the term "intensity" of a contact on a touch sensing surface refers to the force or pressure (force per unit area) of a contact (e.g., a finger contact) on the touch sensing surface, or a proxy for the force or pressure of a contact on the touch sensing surface. The intensity of a contact has a range of values that includes at least four distinct values, and more typically, hundreds (e.g., at least 256) of distinct values. The intensity of a contact is optionally determined (or measured) using a variety of techniques and a variety of sensors or combinations of sensors. For example, one or more force sensors under or adjacent to the touch sensing surface are optionally used to measure the force at various points on the touch sensing surface. In some implementations, force measurements from multiple force sensors are combined (e.g., weighted averaged) to determine the estimated force of the contact. Similarly, a pressure-sensitive tip of a stylus is optionally used to determine the pressure of the stylus on the touch sensing surface. Alternatively, the size and / or change in size of the contact area detected on the touch sensing surface, the capacitance and / or change in capacitance of the touch sensing surface proximate to the contact, and / or the resistance and / or change in resistance of the touch sensing surface proximate to the contact are optionally used as an alternative to the force or pressure of a contact on the touch sensing surface. In some implementations, an alternative measurement of the force or pressure of a contact is used directly to determine whether it exceeds an intensity threshold (e.g., the intensity threshold is described in units corresponding to the alternative measurement). In some implementations, a proxy measurement of the contact force or pressure is converted to an estimated value of the force or pressure, and the estimated value of the force or pressure is used to determine whether it exceeds an intensity threshold (e.g., the intensity threshold is a pressure threshold measured in units of pressure). By using the intensity of a contact as an attribute of user input, a user can access additional device functions that may otherwise be inaccessible to the user on a reduced-size device with a limited implementation area for displaying affordances (e.g., on a touch sensing display), and / or receive user input (e.g., via a touch sensing display, a touch sensing surface, or a physical / mechanical control such as a knob or button).

[0046] As used in this specification and the claims, the term "haptic output" refers to a physical displacement of the device relative to its previous position, a physical displacement of a component of the device (e.g., a touch-sensitive surface) relative to another component of the device (e.g., the housing), or a displacement of a component relative to the center of mass of the device that will be detected by the user's sense of touch. For example, in a situation where the device or a component of the device is in contact with a touch-sensitive surface of the user (e.g., the finger, palm, or other part of the user's hand), the haptic output generated by the physical displacement will be interpreted by the user as a tactile sensation corresponding to a perceived change in the physical characteristics of the device or the component of the device. For example, the movement of a touch-sensitive surface (e.g., a touch-sensitive display or a trackpad) may optionally be interpreted by the user as a "down click" or "up click" of a physical actuator button. In some cases, even when there is no movement of a physical actuator button associated with a touch-sensitive surface that has been physically pressed (e.g., displaced) by the user's action, the user may feel a tactile sensation such as a "down click" or "up click". As another example, the movement of a touch-sensitive surface may optionally be interpreted or perceived by the user as "roughness" of the touch-sensitive surface, even if there is no change in the smoothness of the touch-sensitive surface. Such interpretation of touch by the user depends on the user's individual sensory perception, but there are many sensory perceptions of touch that are common to a majority of users. Therefore, when a haptic output is described as corresponding to a particular sensory perception of the user (e.g., "up click", "down click", "roughness"), unless otherwise specified, the generated haptic output corresponds to a physical displacement of a device or a component of the device that produces the described sensory perception of a typical (or average) user.

[0047] Device 100 is merely an example of a portable multifunctional device. It should be understood that device 100 may optionally have more or fewer components than those shown, may optionally combine two or more components, or may optionally have different configurations or arrangements of those components. The various components shown in FIG. 1A are implemented in a combination of hardware, software, or both hardware and software, including one or more signal processing circuits and / or application-specific integrated circuits.

[0048] Memory 102 optionally includes high-speed random access memory and also optionally includes non-volatile memory such as one or more magnetic disk storage devices, flash memory devices, or other non-volatile solid-state memory devices. Memory controller 122 optionally controls access to memory 102 by other components of device 100.

[0049] Peripheral interface 118 can be used to couple the input and output peripheral devices of the device to CPU 120 and memory 102. One or more processors 120 operate or execute various software programs and / or instruction sets stored in memory 102 to perform various functions for device 100 and process data. In some embodiments, peripheral interface 118, CPU 120, and memory controller 122 are optionally implemented on a single chip such as chip 104. In some other embodiments, they are optionally implemented on separate chips.

[0050] The RF (radio frequency) circuit 108 transmits and receives RF signals, also called electromagnetic signals. The RF circuit 108 converts electrical signals into electromagnetic signals or vice versa and communicates with a communication network and other communication devices via electromagnetic signals. The RF circuit 108 optionally includes well-known circuits for performing these functions, such as, but not limited to, an antenna system, an RF transceiver, one or more amplifiers, a tuner, one or more oscillators, a digital signal processor, a CODEC chipset, a subscriber identity module (SIM) card, a memory, and the like. The RF circuit 108 optionally communicates wirelessly with networks such as the Internet, also called the World Wide Web (WWW), an intranet, and / or a wireless network such as a cellular telephone network, a wireless local area network (LAN), and / or a metropolitan area network (MAN), as well as with other devices. The RF circuit 108 optionally includes well-known circuits for detecting a near field communication (NFC) field by, for example, a short-range communication radio. Wireless communication optionally includes, but is not limited to only, Global System for Mobile Communications (GSM) for mobile communication, Enhanced Data GSM Environment (EDGE), high-speed downlink packet access (HSDPA), high-speed uplink packet access (HSUPA), Evolution, Data-Only (EV-DO), HSPA, HSPA+, Dual-Cell HSPA (DC-HSPDA), Long Termevolution, LTE), Near Field Communication (NFC), Wideband Code Division Multiple Access (W-CDMA), Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Bluetooth, Bluetooth Low Energy (BTLE), Wireless Fidelity (Wi-Fi) (e.g., IEEE802.11a, IEEE802.11b, IEEE802.11g, IEEE802.11n, and / or IEEE802.11ac), Voice over Internet Protocol (VoIP), Wi-MAX, protocols for email (e.g., Internet Message Access Protocol (IMAP) and / or Post Office Protocol (POP)), instant messaging (e.g., Extensible Messaging and Presence Protocol (XMPP), Session Initiation Protocol for Instant Messaging and Presence Leveraging Extensions (SIMPLE), Instant Messaging and Presence Service (IMPS)), and / or Short Message Service (SMS), or any other suitable communication protocol including communication protocols not yet developed as of the filing date of this specification. Use any one of a plurality of communication standards, protocols, and technologies.

[0051] The audio circuit 110, speaker 111, and microphone 113 provide an audio interface between the user and the device 100. The audio circuit 110 receives audio data from the peripheral device interface 118, converts this audio data into an electrical signal, and transmits this electrical signal to the speaker 111. The speaker 111 converts the electrical signal into human audible sound waves. Also, the audio circuit 110 receives the electrical signal converted from sound waves by the microphone 113. The audio circuit 110 converts the electrical signal into audio data and transmits this audio data to the peripheral device interface 118 for processing. The audio data is optionally obtained from and / or transmitted to the memory 102 and / or the RF circuit 108 by the peripheral device interface 118. In some embodiments, the audio circuit 110 also includes a headset jack (e.g., 212 of FIG. 2). The headset jack provides an interface between the audio circuit 110 and a removable audio input / output peripheral device such as an output-only headset or a headset with both output (e.g., mono or stereo headphones) and input (e.g., microphone).

[0052] The I / O subsystem 106 couples input / output peripheral devices on the device 100, such as the touch screen 112 and other input control devices 116, to the peripheral device interface 118. The I / O subsystem 106 optionally includes a display controller 156, an optical sensor controller 158, a depth camera controller 169, an intensity sensor controller 159, a tactile feedback controller 161, and one or more input controllers 160 for other input devices or control devices. The one or more input controllers 160 receive electrical signals from and transmit electrical signals to the other input control devices 116. The other input control devices 116 optionally include physical buttons (e.g., push buttons, rocker buttons, etc.), dials, slider switches, joysticks, click wheels, etc. In some embodiments, the input controller(s) 160 are optionally coupled to (or not coupled to any of) a keyboard, an infrared port, a USB port, and pointer devices such as a mouse. One or more buttons (e.g., 208 in FIG. 2) optionally include up / down buttons for volume control of the speaker 111 and / or the microphone 113. One or more buttons optionally include push buttons (e.g., 206 in FIG. 2). In some embodiments, the electronic device is a computer system that communicates with one or more input devices (e.g., via wired communication or wireless communication). In some embodiments, the one or more input devices include a touch sensing surface (e.g., a trackpad as part of a touch sensing display). In some embodiments, the one or more input devices include one or more camera sensors (e.g., one or more optical sensors 164 and / or one or more depth camera sensors 175) for tracking a user's gesture (e.g., a hand gesture) as an input. In some embodiments, the one or more input devices are integrated with the computer system. In some embodiments, the one or more input devices are separate from the computer system.

[0053] As described in U.S. Patent Application No. 11 / 322,549, filed December 23, 2005, "Unlocking a Device by Performing Gestures on an Unlock Image," and U.S. Patent No. 7,657,849, which are hereby incorporated by reference in their entirety, a quick press of a push button optionally unlocks the touch screen 112 or, optionally, initiates a process of unlocking the device using gestures on the touch screen. A longer press of a push button (e.g., 206) optionally turns the power to the device 100 on or off. The functionality of one or more of the buttons is optionally customizable by the user. The touch screen 112 is used to implement virtual or soft buttons and one or more soft keyboards.

[0054] The touch-sensitive display 112 provides an input interface and an output interface between the device and the user. The display controller 156 receives electrical signals from the touch screen 112 and / or transmits electrical signals to the touch screen 112. The touch screen 112 displays a visual output to the user. This visual output optionally includes graphics, text, icons, videos, and any combination thereof (collectively referred to as "graphics"). In some embodiments, some or all of the visual output optionally corresponds to user interface objects.

[0055] The touch screen 112 has a touch sensing surface, sensor, or set of sensors that accepts input from a user based on tactile and / or haptic contact. The touch screen 112 and the display controller 156 detect a contact (and any movement or interruption of the contact) on the touch screen 112 (along with any associated modules and / or instruction sets within the memory 102) and convert the detected contact into an interaction with a user interface object (e.g., one or more soft keys, icons, web pages, or images) displayed on the touch screen 112. In an exemplary embodiment, the point of contact between the touch screen 112 and the user corresponds to the user's finger.

[0056] The touch screen 112 optionally uses LCD (liquid crystal display) technology, LPD (light emitting polymer display) technology, or LED (light emitting diode) technology, although in other embodiments other display technologies are also used. The touch screen 112 and the display controller 156 optionally detect a contact and any movement or interruption thereof using any of a plurality of touch sensing technologies, now known or later developed, including, but not limited to, capacitive, resistive, infrared, and surface acoustic wave technologies, as well as other proximity sensor arrays or other elements for determining one or more points of contact with the touch screen 112. In an exemplary embodiment, projected mutual capacitance sensing technology, such as that found in the iPhone (registered trademark) and iPod Touch (registered trademark) from Apple Inc. of Cupertino, California, is used.

[0057] In some embodiments, the touch-sensitive display of touch screen 112 is optionally similar to a multi-touch sensitive touch pad described in U.S. Patent Nos. 6,323,846 (Westerman et al.), 6,570,557 (Westerman et al.), and / or 6,677,932 (Westerman), each of which is hereby incorporated by reference in its entirety, and / or U.S. Patent Application Publication No. 2002 / 0015024 (A1). However, while touch screen 112 displays visual output from device 100, a touch-sensitive touch pad does not provide visual output.

[0058] The touch sensing displays in some embodiments of the touch screen 112 are described in the following applications: (1) U.S. Patent Application No. 11 / 381,313, filed May 2, 2006, "Multipoint Touch Surface Controller"; (2) U.S. Patent Application No. 10 / 840,862, filed May 6, 2004, "Multipoint Touchscreen"; (3) U.S. Patent Application No. 10 / 903,964, filed Jul. 30, 2004, "Gestures For Touch Sensitive Input Devices"; (4) U.S. Patent Application No. 11 / 048,264, filed Jan. 31, 2005, "Gestures For Touch Sensitive Input Devices"; (5) U.S. Patent Application No. 11 / 038,590, filed Jan. 18, 2005, "Mode-Based Graphical User Interfaces For Touch Sensitive Input Devices"; (6) U.S. Patent Application No. 11 / 228,758, filed Sep. 16, 2005, "Virtual Input Device Placement On A Touch Screen User Interface"; (7) U.S. Patent Application No. 11 / 228,700, filed Sep. 16, 2005, "Operation Of A Computer With A Touch Screen Interface"; (8) U.S. Patent Application No. 11 / 228,737, filed Sep. 16, 2005, "Activating Virtual Keys Of A Touch-Screen Virtual Keyboard"; and (9) U.S. Patent Application No. 11 / 367,749, filed Mar. 3, 2006, "Multi-Functional Hand-Held Device". All of these applications are hereby incorporated by reference in their entirety.

[0059] The touch screen 112 optionally has a video resolution exceeding 100 dpi. In some embodiments, the touch screen has a video resolution of about 160 dpi. The user optionally touches the touch screen 112 using any suitable object or appendage such as a stylus, finger, etc. In some embodiments, the user interface is designed to operate primarily using finger-based contact and gestures, although this may be less accurate than stylus-based input due to the larger contact area of the finger on the touch screen. In some embodiments, the device converts rough input by the finger into the position or command of an accurate pointer / cursor for performing the action desired by the user.

[0060] In some embodiments, in addition to the touch screen, the device 100 optionally includes a touch pad for activating or deactivating certain functions. In some embodiments, the touch pad, unlike the touch screen, is a touch-sensitive area of the device that does not display a visual output. The touch pad is optionally a touch-sensitive surface separate from the touch screen 112 or an extension of the touch-sensitive surface formed by the touch screen.

[0061] The device 100 also includes a power system 162 that supplies power to various components. The power system 162 optionally includes a power management system, one or more power sources (e.g., battery, alternating current (AC)), a recharge system, a power outage detection circuit, a power converter or inverter, a power status indicator (e.g., light-emitting diode (LED)), and any other components associated with the generation, management, and distribution of power within a portable device.

[0062] Device 100 also optionally includes one or more optical sensors 164. FIG. 1A shows an optical sensor coupled to an optical sensor controller 158 within I / O subsystem 106. The optical sensor 164 optionally includes a charge-coupled device (CCD) or a complementary metal-oxide semiconductor (CMOS) phototransistor. The optical sensor 164 receives light from the environment projected through one or more lenses and converts the light into data representing an image. The optical sensor 164 cooperates with an imaging module 143 (also called a camera module) to optionally capture a still image or a video. In some embodiments, the optical sensor is located on the back surface of device 100 opposite touch screen display 112 on the front of the device, and thus the touch screen display can be used as a viewfinder for obtaining still images and / or videos. In some embodiments, the optical sensor is disposed on the front of the device so that the user's image can optionally be obtained for a video conference while the user is viewing other video conference participants on the touch screen display. In some embodiments, the position of the optical sensor 164 can be changed by the user (e.g., by rotating the lens and sensor within the device housing), and thus a single optical sensor 164 can be used for both video conferencing and for obtaining still images and / or videos along with the touch screen display.

[0063] Device 100 optionally also includes one or more depth camera sensors 175. FIG. 1A shows a depth camera sensor coupled to a depth camera controller 169 within the I / O subsystem 106. The depth camera sensor 175 receives data from the environment and creates a three-dimensional model of an object (e.g., a face) within the scene from the viewpoint (e.g., the depth camera sensor). In some embodiments, in cooperation with the imaging module 143 (also referred to as the camera module), the depth camera sensor 175 is optionally used to determine depth maps of different portions of an image captured by the imaging module 143. In some embodiments, while a user views other video conference participants on a touch screen display, an image of the user with depth information is optionally acquired for the video conference, and a depth camera sensor is disposed on the front surface of the device 100 to capture a self-portrait image with depth map data. In some embodiments, the depth camera sensor 175 is disposed on the back surface of the device, or on both the back and front surfaces of the device 100. In some embodiments, the position of the depth camera sensor 175 can be changed by the user (e.g., by rotating the lens and sensor within the device housing), such that the depth camera sensor 175 is used with the touch screen display for both video conferencing and for acquiring still images and / or videos.

[0064] Device 100 also optionally includes one or more contact intensity sensors 165. FIG. 1A shows a contact intensity sensor coupled to an intensity sensor controller 159 within I / O subsystem 106. The contact intensity sensor 165 optionally includes one or more piezoresistive strain gauges, capacitive force sensors, electro-force sensors, piezoelectric force sensors, optical force sensors, capacitive touch sensing surfaces, or other intensity sensors (e.g., sensors used to measure the force (or pressure) of contact on a touch sensing surface). The contact intensity sensor 165 receives contact intensity information (e.g., pressure information, or a proxy for pressure information) from the environment. In some embodiments, at least one contact intensity sensor is juxtaposed with, or proximate to, a touch sensing surface (e.g., touch sensing display system 112). In some embodiments, at least one contact intensity sensor is disposed on the back of device 100, opposite a touch screen display 112 disposed on the front of device 100.

[0065] Device 100 also optionally includes one or more proximity sensors 166. FIG. 1A shows proximity sensor 166 coupled to peripheral device interface 118. Alternatively, proximity sensor 166 is optionally coupled to input controller 160 within I / O subsystem 106. Proximity sensor 166 functions, optionally, in a manner described in U.S. Patent Application Nos. 11 / 241,839, "Proximity Detector In Handheld Device", 11 / 240,788, "Proximity Detector In Handheld Device", 11 / 620,702, "Using Ambient Light Sensor To Augment Proximity Sensor Output", 11 / 586,862, "Automated Response To And Sensing Of User Activity In Portable Devices", and 11 / 638,251, "Methods And Systems For Automatic Configuration Of Peripherals", which are hereby incorporated by reference in their entirety. In some embodiments, when the multifunctional device is placed near the user's ear (e.g., when the user is making a phone call), the proximity sensor turns off and disables touch screen 112.

[0066] Device 100 also optionally includes one or more haptic output generators 167. FIG. 1A shows a haptic output generator coupled to a haptic feedback controller 161 within I / O subsystem 106. The haptic output generator 167 optionally includes one or more electroacoustic devices, such as speakers or other audio components, and / or electromechanical devices that convert energy, such as motors, solenoids, electroactive polymers, piezoelectric actuators, electrostatic actuators, or other haptic output generating components (e.g., components that convert an electrical signal into a haptic output on the device), into linear movement. The contact intensity sensor 165 receives haptic feedback generation instructions from the haptic feedback module 133 and generates haptic outputs on the device 100 that can be sensed by a user of the device 100. In some embodiments, at least one haptic output generator is juxtaposed with or proximate to a touch sensing surface (e.g., touch sensing display system 112) and optionally generates haptic outputs by moving the touch sensing surface in a vertical direction (e.g., in / out of the surface of the device 100) or in a horizontal direction (e.g., back and forth within the same plane as the surface of the device 100). In some embodiments, at least one haptic output generator sensor is disposed on the back of the device 100, which is opposite the touch screen display 112 disposed on the front of the device 100.

[0067] Device 100 also optionally includes one or more accelerometers 168. FIG. 1A shows an accelerometer 168 coupled to the peripheral device interface 118. Alternatively, the accelerometer 168 is optionally coupled to the input controller 160 within the I / O subsystem 106. The accelerometer 168 functions, optionally, as described in both U.S. Patent Application Publication No. 20050190059, "Acceleration-based Theft Detection System for Portable Electronic Devices," and U.S. Patent Application Publication No. 20060017692, "Methods And Apparatuses For Operating A Portable Device Based On An Accelerometer," which are hereby incorporated by reference in their entirety. In some embodiments, information is displayed on the touch screen display in a portrait or landscape display based on analysis of data received from one or more accelerometers. In addition to the accelerometer(s) 168, device 100 optionally includes a magnetometer and a GPS (or GLONASS or other global navigation system) receiver for obtaining information regarding the position and orientation (e.g., portrait or landscape orientation) of device 100.

[0068] In some embodiments, the software components stored in the memory 102 include an operating system 126, a communication module (or instruction set) 128, a touch / motion module (or instruction set) 130, a graphics module (or instruction set) 132, a text input module (or instruction set) 134, a Global Positioning System (GPS) module (or instruction set) 135, and an application (or instruction set) 136. Further, in some embodiments, the memory 102 (FIG. 1A) or 370 (FIG. 3) stores a device / global internal state 157 as shown in FIGS. 1A and 3. The device / global internal state 157 includes an active application state indicating which application is active if there is a currently active application, a display state indicating which application, view, or other information occupies various regions of the touch screen display 112, a sensor state including information obtained from various sensors and input control devices 116 of the device, and one or more of position information regarding the position and / or orientation of the device.

[0069] The operating system 126 (e.g., an embedded operating system such as Darwin, RTXC, LINUX, UNIX, OS X, iOS, WINDOWS, or VxWorks) includes various software components and / or drivers that control and manage general system tasks (e.g., memory management, storage device control, power management, etc.) and facilitate communication between various hardware components and software components.

[0070] The communication module 128 facilitates communication with other devices via one or more external ports 124 and also includes various software components for processing data received by the RF circuit 108 and / or the external port 124. The external ports 124 (e.g., Universal Serial Bus (USB), FIREWIRE, etc.) are adapted to couple to other devices either directly or indirectly via a network (e.g., the Internet, a wireless LAN, etc.). In some embodiments, the external port is a multi-pin (e.g., 30-pin) connector that is the same as or similar to and / or is adapted to the 30-pin connector used on iPod (registered trademark) devices (a trademark of Apple Inc.).

[0071] The contact / motion module 130 optionally detects contact with the touch screen 112 and other touch-sensing devices (e.g., a touch pad or a physical click wheel) (in cooperation with the display controller 156). The contact / motion module 130 includes various software components for performing various operations related to the detection of contact, such as determining whether contact has occurred (e.g., detecting a finger-down event), determining the intensity of the contact (e.g., the force or pressure of the contact, or an alternative to the force or pressure of the contact), determining whether there is movement of the contact, tracking movement across the touch-sensing surface (e.g., detecting one or more events of dragging a finger), and determining whether the contact has ceased (e.g., detecting a finger-up event or an interruption of the contact). The contact / motion module 130 receives contact data from the touch-sensing surface. Determining the movement of the contact point, represented by a series of contact data, optionally includes determining the speed (magnitude), velocity (magnitude and direction), and / or acceleration (change in magnitude and / or direction) of the contact point. These operations are optionally applied to a single contact (e.g., contact with one finger) or multiple simultaneous contacts (e.g., "multi-touch" / contact with multiple fingers). In some embodiments, the contact / motion module 130 and the display controller 156 detect contact on the touch pad.

[0072] In some embodiments, the contact / motion module 130 uses a set of one or more intensity thresholds to determine whether an action has been performed by the user (e.g., to determine whether the user has "clicked" on an icon). In some embodiments, at least one subset of the intensity thresholds is determined according to software parameters (e.g., the intensity thresholds can be adjusted without changing the physical hardware of the device 100, rather than being determined by the activation thresholds of specific physical actuators). For example, the mouse "click" threshold of a trackpad or touch screen display can be set to any of a wide range of default thresholds without changing the trackpad or touch screen display hardware. Additionally, in some implementations, the user of the device is provided with software settings to adjust one or more of the set of intensity thresholds (e.g., by adjusting individual intensity thresholds and / or adjusting multiple intensity thresholds at once according to system-level click "intensity" parameters).

[0073] The contact / motion module 130 optionally detects gesture inputs by the user. Different gestures on the touch-sensitive surface have different contact patterns (e.g., the detected movement, timing, and / or intensity of the contact is different). Thus, gestures are optionally detected by detecting a specific contact pattern. For example, detecting a finger tap gesture includes detecting a finger down event followed by detecting a finger up (lift off) event at the same position (or substantially the same position) as the finger down event (e.g., the position of an icon). As another example, detecting a finger swipe gesture on the touch-sensitive surface includes detecting a finger down event followed by detecting one or more finger drag events and then followed by detecting a finger up (lift off) event.

[0074] The graphic module 132 includes various known software components that render and display graphics on the touch screen 112 or other display, including components that vary the visual impact of the displayed graphics (e.g., brightness, transparency, saturation, contrast, or other visual characteristics). As used herein, the term "graphic" includes, but is not limited to, any object that can be displayed to a user, including letters, web pages, icons (such as user interface objects including soft keys), digital images, videos, animations, and the like.

[0075] In some embodiments, the graphic module 132 stores data representing the graphics that will be used. Each graphic is optionally assigned a corresponding code. The graphic module 132 receives, from an application or the like, one or more codes that specify the graphic to be displayed, along with coordinate data and other graphic characteristic data as needed, and then generates the screen image data to be output to the display controller 156.

[0076] The haptic feedback module 133 includes various software components for generating the instructions used by the haptic output generator 167 to generate haptic output at one or more locations on the device 100, depending on the interaction of the user with the device 100.

[0077] The text input module 134 is optionally a component of the graphic module 132 and provides a soft keyboard for entering text in various applications (e.g., contacts 137, email 140, IM 141, browser 147, and any other application that requires text input).

[0078] The GPS module 135 determines the location of the device and provides this information for use within various applications (e.g., to the phone 138 for location-based dialing, to the camera 143 as picture / video metadata, and to applications that provide location-based services such as a weather widget, a local yellow pages widget, and a map / navigation widget).

[0079] The application 136 optionally includes the following modules (or sets of instructions) or subsets or supersets thereof. ● A contact module 137 (which may also be referred to as an address book or contact list), ● A phone module 138, ● A video conferencing module 139, ● An email client module 140, ● An instant messaging (IM) module 141, ● A training support module 142, ● A camera module 143 for still images and / or videos, ● An image management module 144, ● A video player module, ● A music player module, ● A browser module 147, ● A calendar module 148, ● Optionally, a widget module 149 that includes one or more of a weather widget 149-1, a stock price widget 149-2, a calculator widget 149-3, an alarm clock widget 149-4, a dictionary widget 149-5, and other widgets obtained by the user, as well as a user-created widget 149-6, ● A widget creator module 150 for creating the user-created widget 149-6, ● A search module 151, ● A video and music player module 152 that integrates the video player module and the music player module ● Note module 153, ● Map module 154, and / or ● Online video module 155.

[0080] Examples of other applications 136 that are optionally stored in the memory 102 include other word processing applications, other image editing applications, drawing applications, presentation applications, JAVA-compatible applications, encryption, digital rights management, voice recognition, and voice replication.

[0081] In conjunction with the touch screen 112, the display controller 156, the contact / motion module 130, the graphic module 132, and the text input module 134, the contact module 137 is optionally used to add name(s) to the address book, delete name(s) from the address book, associate a phone number(s), an email address(es), an address(es), or other information with a name, associate an image with a name, classify and sort names, provide a phone number or email address to initiate and / or facilitate communication by phone 138, the video conferencing module 139, email 140, or IM 141, etc., for managing the address book or contact list (e.g., stored in the application internal state 192 of the contact module 137 in the memory 102 or the memory 370).

[0082] The telephone module 138 is used in cooperation with the RF circuit 108, the audio circuit 110, the speaker 111, the microphone 113, the touch screen 112, the display controller 156, the contact / motion module 130, the graphic module 132, and the text input module 134 to optionally input a character sequence corresponding to a telephone number, access one or more telephone numbers in the contact module 137, modify the input telephone number, dial an individual telephone number, execute a call, and release the connection and stop the call when the call ends. As described above, the wireless communication optionally uses any of a plurality of communication standards, protocols, and technologies.

[0083] The videoconference module 139 includes executable instructions for starting, executing, and ending a videoconference between the user and one or more other participants according to the user's instructions in cooperation with the RF circuit 108, the audio circuit 110, the speaker 111, the microphone 113, the touch screen 112, the display controller 156, the optical sensor 164, the optical sensor controller 158, the contact / motion module 130, the graphic module 132, the text input module 134, the contact module 137, and the telephone module 138.

[0084] The email client module 140 includes executable instructions for creating, sending, receiving, and managing emails according to the user's instructions in cooperation with the RF circuit 108, the touch screen 112, the display controller 156, the contact / motion module 130, the graphic module 132, and the text input module 134. In cooperation with the image management module 144, the email client module 140 makes it very easy to create and send emails with still or moving images captured by the camera module 143.

[0085] The instant messaging module 141 cooperates with the RF circuit 108, the touch screen 112, the display controller 156, the contact / motion module 130, the graphic module 132, and the text input module 134 to input a character sequence corresponding to an instant message, correct previously input characters, (e.g., for instant messages based on telephone communication, using the Short Message Service (SMS) or Multimedia Message Service (MMS) protocol, or for instant messages based on the Internet, using XMPP, SIMPLE, or IMPS), send individual instant messages, receive instant messages, and include executable instructions for viewing received instant messages. In some embodiments, the instant messages to be sent and / or received optionally include graphics, photos, audio files, video files, and / or other attachment files supported by MMS and / or Enhanced Messaging Service (EMS). As used herein, "instant messaging" refers to both telephone communication-based messages (e.g., messages sent using SMS or MMS) and Internet-based messages (e.g., messages sent using XMPP, SIMPLE, or IMPS).

[0086] The training support module 142, in cooperation with the RF circuit 108, touch screen 112, display controller 156, contact / motion module 130, graphic module 132, text input module 134, GPS module 135, map module 154, and music player module, creates training (e.g., having time, distance, and / or calorie burn goals), communicates with a training sensor (sports device), receives training sensor data, calibrates sensors used to monitor the training, selects and plays music for the training, and includes executable instructions for displaying, storing, and transmitting training data.

[0087] The camera module 143, in cooperation with the touch screen 112, display controller 156, optical sensor 164, optical sensor controller 158, contact / motion module 130, graphic module 132, and image management module 144, includes executable instructions for capturing still images or videos (including video streams) and storing them in the memory 102, modifying the characteristics of still images or videos, or deleting still images or videos from the memory 102.

[0088] The image management module 144, in cooperation with the touch screen 112, display controller 156, contact / motion module 130, graphic module 132, text input module 134, and camera module 143, includes executable instructions for arranging, modifying (e.g., editing), or otherwise operating on, labeling, deleting, presenting (e.g., in a digital slide show or album), and storing still images and / or videos.

[0089] The browser module 147 includes executable instructions for browsing the Internet according to user instructions, including searching for, linking to, receiving, and displaying a web page or a portion thereof, as well as attached files and other files linked to the web page, in cooperation with the RF circuit 108, the touch screen 112, the display controller 156, the contact / motion module 130, the graphic module 132, and the text input module 134.

[0090] The calendar module 148 includes executable instructions for creating, displaying, modifying, and storing a calendar and data associated with the calendar (e.g., calendar items, to-do lists, etc.) according to user instructions, in cooperation with the RF circuit 108, the touch screen 112, the display controller 156, the contact / motion module 130, the graphic module 132, the text input module 134, the email client module 140, and the browser module 147.

[0091] The widget module 149 cooperates with the RF circuit 108, the touch screen 112, the display controller 156, the contact / motion module 130, the graphic module 132, the text input module 134, and the browser module 147, and optionally, mini-applications (e.g., weather widget 149-1, stock price widget 149-2, calculator widget 149-3, alarm clock widget 149-4, and dictionary widget 149-5) that are downloaded and used by the user, or mini-applications (e.g., user-created widget 149-6) created by the user. In some embodiments, the widget includes an HTML (Hypertext Markup Language) file, a CSS (Cascading Style Sheets) file, and a JavaScript file. In some embodiments, the widget includes an XML (Extensible Markup Language) file and a JavaScript file (e.g., Yahoo! widget).

[0092] The widget creator module 150 cooperates with the RF circuit 108, the touch screen 112, the display controller 156, the contact / motion module 130, the graphic module 132, the text input module 134, and the browser module 147, and is used by the user to optionally create a widget (e.g., turn a user-specified portion of a web page into a widget).

[0093] The search module 151 cooperates with the touch screen 112, the display controller 156, the contact / motion module 130, the graphic module 132, and the text input module 134, and includes executable instructions for searching for characters, music, sounds, images, videos, and / or other files in the memory 102 that match one or more search criteria (e.g., one or more user-specified search terms) according to the user's instructions.

[0094] The video and music player module 152, in cooperation with the touch screen 112, the display controller 156, the touch / motion module 130, the graphic module 132, the audio circuit 110, the speaker 111, the RF circuit 108, and the browser module 147, includes executable instructions that enable a user to download and play recorded music and other sound files stored in one or more file formats such as MP3 or AAC files, and executable instructions for displaying, presenting, or otherwise playing videos (e.g., on the touch screen 112 or on an external display connected via the external port 124). In some embodiments, the device 100 optionally includes the functionality of an MP3 player such as an iPod (a trademark of Apple Inc.).

[0095] The memo module 153, in cooperation with the touch screen 112, the display controller 156, the touch / motion module 130, the graphic module 132, and the text input module 134, includes executable instructions for creating and managing memos, to-do lists, etc. according to the user's instructions.

[0096] The map module 154, in cooperation with the RF circuit 108, the touch screen 112, the display controller 156, the touch / motion module 130, the graphic module 132, the text input module 134, the GPS module 135, and the browser module 147, is optionally used to receive, display, modify, and store maps and data associated with the maps (e.g., driving routes, data regarding stores and other points of interest near a particular location or in its vicinity, and other location-based data) according to the user's instructions.

[0097] The online video module 155 cooperates with the touch screen 112, the display controller 156, the touch / motion module 130, the graphics module 132, the audio circuit 110, the speaker 111, the RF circuit 108, the text input module 134, the email client module 140, and the browser module 147 to enable a user to access a particular online video, browse a particular online video, receive it (e.g., by streaming and / or downloading), play it (e.g., on the touch screen or on an external display connected via the external port 124), send an email having a link to a particular online video, and perform other management of online videos in one or more file formats such as H.264. In some embodiments, instead of the email client module 140, the instant messaging module 141 is used to send a link to a particular online video. For additional explanation of the online video application, reference is made to U.S. Provisional Patent Application No. 60 / 936,562, filed Jun. 20, 2007, "Portable Multifunction Device, Method, and Graphical User Interface for Playing Online Videos", and U.S. Patent Application No. 11 / 968,067, filed Dec. 31, 2007, "Portable Multifunction Device, Method, and Graphical User Interface for Playing Online Videos", the entire contents of which are hereby incorporated by reference.

[0098] The modules and applications identified above each correspond to a set of executable instructions that perform one or more of the functions described above and the methods described in this application (e.g., the computer-implemented methods and other information processing methods described herein). These modules (e.g., instruction sets) need not be implemented as separate software programs, computer programs (e.g., including instructions), procedures, or modules, and thus, in various embodiments, various subsets of these modules may be optionally combined or otherwise reconfigured. For example, the video player module may optionally be combined with the music player module to form a single module (e.g., the video and music player module 152 of FIG. 1A). In some embodiments, the memory 102 optionally stores a subset of the modules and data structures identified above. Further, the memory 102 optionally stores additional modules and data structures not described above.

[0099] In some embodiments, the device 100 is a device in which the operation of a set of default functions in the device is performed only via a touch screen and / or a touch pad. By using the touch screen and / or the touch pad as the main input control device for the device 100 to operate, the number of physical input control devices (push buttons, dials, etc.) on the device 100 is optionally reduced.

[0100] The set of default functions that are executed only through the touch screen and / or touch pad optionally includes navigation between user interfaces. In some embodiments, the touch pad navigates the device 100 from any user interface displayed on the device 100 to the main menu, home menu, or root menu when touched by the user. In such embodiments, the "menu button" is implemented using the touch pad. In some other embodiments, the menu button is a physical push button or other physical input control device rather than a touch pad.

[0101] FIG. 1B is a block diagram showing exemplary components for event processing according to some embodiments. In some embodiments, the memory 102 (FIG. 1A) or 370 (FIG. 3) includes an event sorting unit 170 (e.g., within the operating system 126) and individual applications 136-1 (e.g., any of the aforementioned applications 137-151, 155, 380-390).

[0102] The event sorting unit 170 receives event information and determines the application 136-1 to which the event information is to be delivered and the application view 191 of the application 136-1. The event sorting unit 170 includes an event monitor 171 and an event dispatcher module 174. In some embodiments, the application 136-1 includes an application internal state 192 that indicates the current application view displayed on the touch-sensitive display 112 when the application is active or running. In some embodiments, the device / global internal state 157 is used by the event sorting unit 170 to determine which application(s) is / are currently active, and the application internal state 192 is used by the event sorting unit 170 to determine the application view 191 to which the event information is to be delivered.

[0103] In some embodiments, the application internal state 192 includes additional information such as resume information to be used when application 136-1 resumes execution, user interface state information indicating or ready to display the information being displayed by application 136-1, a state queue that enables the user to return to a previous state or view of application 136-1, and a redo / undo queue of previous actions performed by the user, among one or more of the above.

[0104] The event monitor 171 receives event information from the peripheral device interface 118. The event information includes information regarding sub-events (e.g., a user touch as part of a multi-touch gesture on the touch-sensitive display 112). The peripheral device interface 118 transmits information received from the I / O subsystem 106, or sensors such as the proximity sensor 166, the accelerometer(s) 168, and / or the microphone 113 (via the audio circuit 110). The information that the peripheral device interface 118 receives from the I / O subsystem 106 includes information from the touch-sensitive display 112 or a touch-sensitive surface.

[0105] In some embodiments, the event monitor 171 transmits requests to the peripheral device interface 118 at predetermined intervals. In response, the peripheral device interface 118 transmits event information. In other embodiments, the peripheral device interface 118 transmits event information only when there is an important event (e.g., receipt of an input that exceeds a predetermined noise threshold and / or exceeds a predetermined duration).

[0106] In some embodiments, the event sorter 170 also includes a hit view determination module 172 and / or an active event recognition unit determination module 173.

[0107] The hit view determination module 172 provides software procedures for determining where in one or more views a sub - event occurs when the touch - sensitive display 112 is displaying two or more views. A view is composed of control devices and other elements that a user can view on the display.

[0108] Another aspect of the user interface associated with an application is a set of views, sometimes referred to herein as application views or user - interface windows, within which information is displayed and touch - based gestures occur. The application view (of an individual application) in which a touch is detected optionally corresponds to a program level within the program hierarchy or view hierarchy of the application. For example, the lowest - level view in which a touch is detected is optionally referred to as the hit view, and the set of events recognized as appropriate input is optionally determined at least in part based on the hit view of the initial touch that initiates a touch - based gesture.

[0109] The hit view determination module 172 receives information related to sub - events of touch - based gestures. When an application has a plurality of hierarchically - structured views, the hit view determination module 172 identifies the hit view as the lowest - level view within the hierarchy in which the sub - event should be processed. In most situations, the hit view is the lowest - level view in which the start sub - event (e.g., the first sub - event in a sequence of sub - events that form an event or potential event) occurs. Once the hit view is identified by the hit view determination module 172, the hit view typically receives all sub - events related to the same touch or input source as the touch or input source identified as the hit view.

[0110] The active event recognition unit determination module 173 determines which view(s) within the view hierarchy should receive a particular sequence of sub-events. In some embodiments, the active event recognition unit determination module 173 determines that only the hit view should receive a particular sequence of sub-events. In other embodiments, the active event recognition unit determination module 173 determines that all views including the physical location of the sub-event are views actively involved, and thus determines that all views actively involved should receive a particular sequence of sub-events. In other embodiments, even if a touch sub-event is completely limited to an area associated with one particular view, the upper-level views within the hierarchy remain views that are actively involved.

[0111] The event dispatcher module 174 dispatches event information to an event recognition unit (e.g., event recognition unit 180). In embodiments including the active event recognition unit determination module 173, the event dispatcher module 174 distributes event information to the event recognition unit determined by the active event recognition unit determination module 173. In some embodiments, the event dispatcher module 174 stores the event information obtained by the individual event receiver 182 in an event queue.

[0112] In some embodiments, the operating system 126 includes an event sorter 170. Alternatively, the application 136-1 includes the event sorter 170. In still other embodiments, the event sorter 170 is a stand-alone module or part of another module stored in the memory 102 such as the touch / motion module 130.

[0113] In some embodiments, application 136-1 includes a plurality of event processing units 190 and one or more application views 191, each including instructions to process touch events that occur within an individual view of the application's user interface. Each application view 191 of application 136-1 includes one or more event recognition units 180. Typically, an individual application view 191 includes a plurality of event recognition units 180. In other embodiments, one or more of the event recognition units 180 are part of a separate module, such as a user interface kit, or a higher-level object from which application 136-1 inherits methods and other properties. In some embodiments, an individual event processing unit 190 includes one or more of event data 179 received from data update unit 176, object update unit 177, GUI update unit 178, and / or event sorting unit 170. The event processing unit 190 optionally utilizes or invokes data update unit 176, object update unit 177, or GUI update unit 178 to update the internal state 192 of the application. Alternatively, one or more of the application views 191 include one or more individual event processing units 190. Also, in some embodiments, one or more of data update unit 176, object update unit 177, and GUI update unit 178 are included within an individual application view 191.

[0114] An individual event recognition unit 180 receives event information (e.g., event data 179) from event sorting unit 170 and identifies an event from the event information. The event recognition unit 180 includes an event receiving unit 182 and an event comparison unit 184. In some embodiments, the event recognition unit 180 also includes at least a subset of metadata 183 and event distribution instructions 188 (optionally including sub-event distribution instructions).

[0115] The event receiver 182 receives event information from the event sorter 170. The event information includes sub-events, for example, information about a touch or a movement of a touch. Depending on the sub-event, the event information also includes additional information such as the position of the sub-event. When the sub-event is related to the movement of a touch, the event information also optionally includes the speed and direction of the sub-event. In some embodiments, the event includes a rotation of the device from one orientation to another (e.g., from portrait to landscape or vice versa), and the event information includes corresponding information about the current orientation of the device (also referred to as the posture of the device).

[0116] The event comparator 184 compares the event information with the definition of a defined event or sub-event and, based on the comparison, determines an event or sub-event or determines or updates the state of an event or sub-event. In some embodiments, the event comparator 184 includes an event definition 186. The event definition 186 includes definitions of events (e.g., a sequence of predefined sub-events) such as event 1 (187-1) and event 2 (187-2). In some embodiments, the sub-events within an event (187) include, for example, a touch start, a touch end, a touch movement, a touch cancellation, and multiple touches. In one example, the definition of event 1 (187-1) is a double tap on a displayed object. The double tap includes, for example, a first touch (touch start) on the displayed object for a predetermined stage, a first lift-off (touch end) for a predetermined stage, a second touch (touch start) on the displayed object for a predetermined stage, and a second lift-off (touch end) for a predetermined stage. In another example, the definition of event 2 (187-2) is a drag on a displayed object. The drag includes, for example, a touch (or contact) on the displayed object for a predetermined stage, a movement of the touch across the touch-sensitive display 112, and a lift-off of the touch (touch end). In some embodiments, the event also includes information about one or more associated event processing units 190.

[0117] In some embodiments, the event definition 187 includes the definition of events for individual user interface objects. In some embodiments, the event comparison unit 184 performs a hit test to determine which user interface object is associated with the sub - event. For example, within an application view where three user interface objects are displayed on the touch - sensitive display 112, when a touch is detected on the touch - sensitive display 112, the event comparison unit 184 performs a hit test to determine which of the three user interface objects is associated with the touch (sub - event). If each displayed object is associated with an individual event processing unit 190, the event comparison unit determines which event processing unit 190 should be activated using the result of the hit test. For example, the event comparison unit 184 selects the event processing unit associated with the sub - event and object that triggered the hit test.

[0118] In some embodiments, the definition of an individual event 187 also includes a delay action that delays the transmission of event information until it is determined whether the sequence of sub - events corresponds to the event type of the event recognition unit.

[0119] If the individual event recognition unit 180 determines that a series of sub - events does not match any of the events in the event definition 186, the individual event recognition unit 180 enters a state of event impossible, event failure, or event end, and then ignores the next sub - event of the touch - based gesture. In this situation, if there is another event recognition unit that remains active for the hit view, that event recognition unit continues to track and process the sub - events of the ongoing touch - based gesture.

[0120] In some embodiments, the individual event recognition unit 180 includes metadata 183 having configurable properties, flags, and / or lists indicating how the event distribution system should actively participate in event recognition units that perform sub-event distribution. In some embodiments, the metadata 183 includes configurable properties, flags, and / or lists indicating how event recognition units interact with each other or how they can interact with each other. In some embodiments, the metadata 183 includes configurable properties, flags, and / or lists indicating whether sub-events are distributed to various levels in the view hierarchy or program hierarchy.

[0121] In some embodiments, the individual event recognition unit 180 activates the event processing unit 190 associated with the event when one or more specific sub-events of the event are recognized. In some embodiments, the individual event recognition unit 180 distributes event information associated with the event to the event processing unit 190. Activating the event processing unit 190 is separate from sending (and deferring sending) sub-events to individual hit views. In some embodiments, the event recognition unit 180 sets a flag associated with the recognized event, and the event processing unit 190 associated with that flag captures the flag and executes a predefined process.

[0122] In some embodiments, the event distribution command 188 includes a sub-event distribution command that distributes event information about sub-events without activating the event processing unit. Instead, the sub-event distribution command distributes event information to an event processing unit associated with a series of sub-events or to a view actively involved. The event processing unit associated with a series of sub-events or an actively involved view receives the event information and executes a predetermined process.

[0123] In some embodiments, data update unit 176 creates and updates data used in application 136-1. For example, data update unit 176 updates the phone numbers used in contact module 137 or stores video files used in the video player module. In some embodiments, object update unit 177 creates and updates objects used in application 136-1. For example, object update unit 177 creates a new user interface object or updates the position of a user interface object. GUI update unit 178 updates the GUI. For example, GUI update unit 178 prepares display information and sends the display information to graphic module 132 for display on the touch-sensitive display.

[0124] In some embodiments, event processing unit(s) 190 includes or has access to data update unit 176, object update unit 177, and GUI update unit 178. In some embodiments, data update unit 176, object update unit 177, and GUI update unit 178 are included in a single module of individual application 136-1 or application view 191. In other embodiments, they are included in two or more software modules.

[0125] The foregoing description regarding event processing of a user's touch on the touch-sensitive display also applies to other forms of user input for operating portable multifunctional device 100 using an input device, it being understood that not all of them are initiated on the touch screen. For example, use as input corresponding to sub-events that optionally recognize movements of a mouse and presses of mouse buttons, movements of contacts such as taps, drags, scrolls on a touch pad, pen stylus input, movement of the device, spoken commands, detected eye movements, biometric input, and / or any combination thereof, optionally in association with single or multiple presses or holds of a keyboard.

[0126] FIG. 2 shows a portable multifunctional device 100 having a touch screen 112, according to some embodiments. The touch screen optionally displays one or more graphics within a user interface (UI) 200. In this embodiment, as well as in other embodiments described below, a user can select one or more of those graphics by performing a gesture on the graphics, for example, using one or more fingers 202 (not drawn to scale in the figure) or one or more styli 203 (not drawn to scale in the figure). In some embodiments, the selection of one or more graphics is performed when the user interrupts contact with the one or more graphics. In some embodiments, the gesture optionally includes one or more taps, one or more swipes (left to right, right to left, upward and / or downward), and / or rolling (right to left, left to right, upward and / or downward) of a finger in contact with the device 100. In some implementations or situations, an accidental contact with a graphic does not select the graphic. For example, a swipe gesture that sweeps over an application icon does not optionally select the corresponding application if the gesture corresponding to selection is a tap.

[0127] The device 100 also optionally includes one or more physical buttons, such as a "home" button or a menu button 204. As described above, the menu button 204 is optionally used to navigate to any application 136 within a set of applications optionally running on the device 100. Alternatively, in some embodiments, the menu button is implemented as a soft key within a GUI displayed on the touch screen 112.

[0128] In some embodiments, device 100 includes a touch screen 112, a menu button 204, a push button 206 for turning the device on / off and locking the device, volume adjustment buttons 208, a subscriber identity module (SIM) card slot 210, a headset jack 212, and a docking / charging external port 124. The push button 206 is optionally used to turn the device on / off by pressing the button and holding it down for a predetermined time interval, to lock the device by pressing the button and releasing it before the predetermined time interval has elapsed, and / or to unlock the device or initiate an unlock process. In an alternative embodiment, device 100 also accepts verbal input via a microphone 113 to activate or deactivate some functions. Device 100 optionally also includes one or more contact intensity sensors 165 for detecting the intensity of a contact on the touch screen 112 and / or one or more haptic output generators 167 for generating a haptic output to the user of device 100.

[0129] FIG. 3 is a block diagram of an exemplary multifunctional device having a display and a touch sensing surface, in accordance with some embodiments. Device 300 need not be portable. In some embodiments, device 300 is a laptop computer, desktop computer, tablet computer, multimedia player device, navigation device, educational device (such as a child's learning toy), game system, or a control device (e.g., a home or industrial controller). Device 300 typically includes one or more processing units (CPUs) 310, one or more networks or other communication interfaces 360, memory 370, and one or more communication buses 320 that interconnect these components. Communication bus 320 optionally includes circuitry (sometimes called a chipset) that interconnects and controls communication between system components. Device 300 includes an input / output (I / O) interface 330 that includes a display 340, which is typically a touch screen display. I / O interface 330 also optionally includes a keyboard and / or mouse (or other pointing device) 350, a touch pad 355, a touch output generator 357 that generates a touch output on device 300 (e.g., similar to touch output generator 167 described above with reference to FIG. 1A), and a sensor 359 (e.g., light, acceleration, proximity, touch sensing, and / or a contact intensity sensor similar to contact intensity sensor 165 described above with reference to FIG. 1A). Memory 370 includes high-speed random access memory such as DRAM, SRAM, DDR RAM, or other random access solid state memory devices, and optionally includes non-volatile memory such as one or more magnetic disk storage devices, optical disk storage devices, flash memory devices, or other non-volatile solid state storage devices. Memory 370 optionally includes one or more storage devices that are remotely located from the CPU(s) 310.In some embodiments, the memory 370 stores programs, modules, and data structures similar to, or a subset of, the programs, modules, and data structures stored in the memory 102 of the portable multifunctional device 100 (FIG. 1A). Further, the memory 370 optionally stores additional programs, modules, and data structures that are not present in the memory 102 of the portable multifunctional device 100. For example, the memory 370 of the device 300 optionally stores a drawing module 380, a presentation module 382, a word processing module 384, a website creation module 386, a disk authoring module 388, and / or a spreadsheet module 390, whereas the memory 102 of the portable multifunctional device 100 (FIG. 1A) optionally does not store these modules.

[0130] Each of the elements identified above in FIG. 3 is optionally stored in one or more of the memory devices described above. Each of the modules identified above corresponds to an instruction set for performing the functions described above. The modules or computer programs identified above (e.g., instruction sets, or instructions) need not be implemented as separate software programs (e.g., computer programs including instructions), procedures, or modules, and thus, in various embodiments, various subsets of these modules are optionally combined or otherwise reconfigured. In some embodiments, the memory 370 optionally stores a subset of the modules and data structures identified above. Further, the memory 370 optionally stores additional modules and data structures not described above.

[0131] Next, optionally direct attention to an embodiment of a user interface, for example, implemented on the portable multifunctional device 100.

[0132] FIG. 4A shows an exemplary user interface of a menu of an application on a portable multifunctional device 100 according to some embodiments. A similar user interface is optionally implemented on device 300. In some embodiments, the user interface 400 includes the following elements, or subsets or supersets thereof. ● One or more signal strength indicators (s) 402 for wireless communication (s), such as cellular and Wi-Fi signals, ● Time 404, ● Bluetooth indicator 405, ● Battery status indicator 406, ● A tray 408 having icons of frequently used applications, such as ○ An icon 416 of the phone module 138 labeled "Phone", optionally including an indicator 414 of the number of missed calls or voice mail messages, ○ An icon 418 of the email client module 140 labeled "Mail", optionally including an indicator 410 of the number of unread emails, ○ An icon 420 of the browser module 147 labeled "Browser", and ○ An icon 422 for the video and music player module 152, also referred to as the iPod (trademark of Apple Inc.) module 152, labeled "iPod", and ● Icons of other applications, such as ○ An icon 424 of the IM module 141 labeled "Message", ○ An icon 426 of the calendar module 148 labeled "Calendar", ○ An icon 428 of the image management module 144 labeled "Photos", ○ An icon 430 of the camera module 143 labeled "Camera", ○ An icon 432 of the online video module 155 labeled "Online Video", 〇 The icon 434 of the stock price widget 149-2, labeled with 「Stock Price」, ○ The icon 436 of the map module 154, labeled with 「Map」, 〇 The icon 438 of the weather widget 149-1, labeled with 「Weather」, 〇 The icon 440 of the alarm clock widget 149-4, labeled with 「Clock」, ○ The icon 442 of the training support module 142, labeled with 「Training Support」, ○ The icon 444 of the memo module 153, labeled with 「Memo」, and ○ The icon 446 of the settings application or module, labeled with 「Settings」, which provides access to the settings of the device 100 and its various applications 136.

[0133] Note that the icon labels shown in FIG. 4A are merely illustrative. For example, the icon 422 of the video and music player module 152 is labeled with 「Music」 or 「Music Player」. Other labels are optionally used for various application icons. In some embodiments, the label for an individual application icon includes the name of the application corresponding to the individual application icon. In some embodiments, the label for a particular application icon is different from the name of the application corresponding to that particular application icon.

[0134] FIG. 4B shows an exemplary user interface on a device (e.g., device 300 of FIG. 3) having a touch sensing surface 451 (e.g., the tablet or touch pad 355 of FIG. 3) separate from the display 450 (e.g., touch screen display 112). The device 300 also optionally includes one or more contact intensity sensors (e.g., one or more of sensors 359) for detecting the intensity of contact on the touch sensing surface 451, and / or one or more haptic output generators 357 for generating haptic output to the user of the device 300.

[0135] Some of the following examples are given with reference to inputs on the touch screen display 112 (where the touch sensing surface and the display are combined), but in some embodiments, the device detects inputs on a touch sensing surface separate from the display, as shown in FIG. 4B. In some embodiments, the touch sensing surface (e.g., 451 in FIG. 4B) has a primary axis (e.g., 452 in FIG. 4B) that corresponds to a primary axis (e.g., 453 in FIG. 4B) on the display (e.g., 450). According to these embodiments, the device detects contacts (e.g., 460 and 462 in FIG. 4B) with the touch sensing surface 451 at positions (e.g., in FIG. 4B, 460 corresponds to 468 and 462 corresponds to 470) that correspond to respective positions on the display. In this way, user inputs (e.g., contacts 460 and 462 and their movements) detected by the device on the touch sensing surface (e.g., 451 in FIG. 4B) are used by the device to operate the user interface on the display (e.g., 450 in FIG. 4B) of the multifunctional device when the touch sensing surface is separate from the display. It should be understood that a similar method is optionally used for other user interfaces described herein.

[0136] In addition, while the following examples are given mainly with reference to finger inputs (e.g., finger contact, finger tap gesture, finger swipe gesture), in some embodiments, one or more of the finger inputs may be replaced by inputs from another input device (e.g., mouse-based input or stylus input). For example, a swipe gesture may optionally be a mouse click (e.g., instead of a contact), followed by a mouse click that involves movement of the cursor along the path of the swipe (e.g., instead of movement of a contact). As another example, a tap gesture may optionally be replaced by a mouse click while the cursor is located over the position of the tap gesture (e.g., instead of detecting a contact and then ceasing to detect the contact). Similarly, it should be understood that when multiple user inputs are detected simultaneously, multiple computer mice may optionally be used simultaneously, or mouse and finger contacts may optionally be used simultaneously.

[0137] FIG. 5A shows an exemplary personal electronic device 500. The device 500 includes a body 502. In some embodiments, the device 500 can include some or all of the features described with respect to devices 100 and 300 (e.g., FIGS. 1A - 4B). In some embodiments, the device 500 has a touch-sensitive display screen 504, hereinafter referred to as touch screen 504. Alternatively, or in addition to the touch screen 504, the device 500 has a display and a touch-sensitive surface. Similar to devices 100 and 300, in some embodiments, the touch screen 504 (or touch-sensitive surface) optionally includes one or more intensity sensors that detect the intensity of an applied contact (e.g., touch). One or more intensity sensors of the touch screen 504 (or touch-sensitive surface) can provide output data representative of the intensity of the touch. The user interface of the device 500 can respond to the touch(es) based on its intensity, which means that touches of different intensities can call different user interface operations on the device 500.

[0138] Exemplary techniques for detecting and processing touch intensity are described, for example, in International Patent Application No. PCT / US2013 / 040061, filed May 8, 2013, published as International Publication No. WO / 2013 / 169849, "Device, Method, and Graphical User Interface for Displaying User Interface Objects Corresponding to an Application", and International Patent Application No. PCT / US2013 / 069483, filed Nov. 11, 2013, published as International Publication No. WO / 2014 / 105276, "Device, Method, and Graphical User Interface for Transitioning Between Touch Input to Display Output Relationships", each of which is hereby incorporated by reference in its entirety.

[0139] In some embodiments, device 500 has one or more input mechanisms 506 and 508. Input mechanisms 506 and 508, if included, can be physical. Examples of physical input mechanisms include push buttons and rotatable mechanisms. In some embodiments, device 500 has one or more attachment mechanisms. Such attachment mechanisms, if included, can enable device 500 to be attached, for example, to hats, glasses, earrings, necklaces, shirts, jackets, bracelets, watch straps, chains, pants, belts, shoes, wallets, backpacks, etc. These attachment mechanisms enable a user to wear device 500.

[0140] FIG. 5B shows an exemplary personal electronic device 500. In some embodiments, device 500 can include some or all of the components described with respect to FIGS. 1A, 1B, and 3. Device 500 has a bus 512 that operably couples an I / O section 514 to one or more computer processors 516 and a memory 518. The I / O section 514 can be connected to a touch-sensitive display 504, which can have a touch-sensing component 522 and optionally an intensity sensor 524 (e.g., a contact intensity sensor). Additionally, the I / O section 514 can be connected to a communication unit 530 that receives application and operating system data using Wi-Fi, Bluetooth, near field communication (NFC), cellular, and / or other wireless communication technologies. The device 500 can include input mechanisms 506 and / or 508. The input mechanism 506 can optionally be, for example, a rotatable input device or a depressible and rotatable input device. In some examples, the input mechanism 508 can optionally be a button.

[0141] In some examples, the input mechanism 508 can optionally be a microphone. The personal electronic device 500 can optionally include various sensors such as a GPS sensor 532, an accelerometer 534, a direction sensor 540 (e.g., a compass), a gyroscope 536, a motion sensor 538, and / or combinations thereof, all of which can be operably connected to the I / O section 514.

[0142] The memory 518 of the personal electronic device 500 can include one or more non-transitory computer-readable storage media for storing computer-executable instructions, which, when executed by one or more computer processors 516, can cause the computer processor to execute techniques described below, including, for example, processes 800 and 900 (FIGS. 8 and 9). A computer-readable storage media can be any media that can tangibly contain or store computer-executable instructions used by or related to an instruction execution system, apparatus, or device. In some embodiments, the storage media is a transitory computer-readable storage media. In some embodiments, the storage media is a non-transitory computer-readable storage media. Non-transitory computer-readable storage media can include, but are not limited to, magnetic storage devices, optical storage devices, and / or semiconductor storage devices. Examples of such storage devices include magnetic disks, optical disks based on CD, DVD, or Blu-ray technology, and persistent solid-state memories such as flash, solid-state drives. The personal electronic device 500 is not limited to the components and configurations of FIG. 5B and can include other or additional components in multiple configurations.

[0143] As used herein, the term "affordance" refers to a user-interaction graphical user interface object that is optionally displayed on the display screen of devices 100, 300, and / or 500 (FIGS. 1A, 3, and 5A-5B). For example, images (e.g., icons), buttons, and text (e.g., hyperlinks) each optionally constitute an affordance.

[0144] As used herein, the term "focus selector" refers to an input element that indicates the current part of the user interface with which the user is interacting. In some implementations that include a cursor or other position marker, the cursor acts as the "focus selector," and thus, while the cursor is positioned over a particular user interface element (e.g., a button, window, slider, or other user interface element), when an input (e.g., a press input) is detected on a touch-sensitive surface (e.g., the touchpad 355 of FIG. 3 or the touch-sensitive surface 451 of FIG. 4B), the particular user interface element is adjusted according to the detected input. In some implementations that include a touch screen display (e.g., the touch-sensitive display system 112 of FIG. 1A or the touch screen 112 of FIG. 4A) that enables direct interaction with user interface elements on the touch screen display, the detected contact on the touch screen acts as the "focus selector," and thus, when an input (e.g., a press input by contact) is detected at the location of a particular user interface element (e.g., a button, window, slider, or other user interface element) on the touch screen display, the particular user interface element is adjusted according to the detected input. In some implementations, the focus is moved from one region of the user interface to another region of the user interface without moving the corresponding cursor or the contact on the touch screen display (e.g., by using the tab key or arrow keys to move the focus from one button to another button), and in these implementations, the focus selector moves in accordance with the movement of the focus between different regions of the user interface. Regardless of the specific form the focus selector takes, the focus selector is generally a user interface element (or a contact on the touch screen display) that is controlled by the user to convey information about the interaction with the user interface that the user intends (e.g., by indicating to the device the user interface element through which the user intends to interact).For example, the position of a focus selector (e.g., a cursor, a contact, or a selection box) over an individual button while a press input is detected on a touch-sensing surface (e.g., a touch pad or a touch screen) indicates that the user intends to activate that individual button (as opposed to other user interface elements shown on the device's display).

[0145] As used in this specification and the claims, the term "characteristic strength" of a contact refers to the characteristics of that contact based on one or more strengths of the contact. In some embodiments, the characteristic strength is based on a plurality of strength samples. The characteristic strength is optionally based on a set of strength samples collected during a predetermined period (e.g., 0.05, 0.1, 0.2, 0.5, 1, 2, 5, 10 seconds) associated with a predetermined number of strength samples, i.e., a predetermined event (e.g., after detecting a contact, before detecting a lift-off of the contact, before or after detecting a start of movement of the contact, before detecting an end of the contact, before or after detecting an increase in the strength of the contact, and / or before or after detecting a decrease in the strength of the contact). The characteristic strength of a contact is optionally based on one or more of a maximum value of the strength of the contact, a mean value of the strength of the contact, an average value of the strength of the contact, a top 10 percentile value of the strength of the contact, a maximum one-half value of the strength of the contact, a maximum 90 percent value of the strength of the contact, etc. In some embodiments, the duration of the contact is used when determining the characteristic strength (e.g., when the characteristic strength is the average of the strength of the contact over time). In some embodiments, the characteristic strength is compared to a set of one or more strength thresholds to determine whether an action has been performed by a user. For example, the set of one or more strength thresholds optionally includes a first strength threshold and a second strength threshold. In this example, a contact having a characteristic strength not exceeding the first threshold results in a first action, a contact having a characteristic strength exceeding the first strength threshold but not exceeding the second strength threshold results in a second action, and a contact having a characteristic strength exceeding the second threshold results in a third action. In some embodiments, the comparison between the characteristic strength and one or more thresholds is not used to determine whether to perform a first action or a second action, but rather is used to determine whether to perform one or more actions (e.g., whether to perform an individual action or to refrain from performing an individual action).

[0146] In some embodiments, for the purpose of determining the characteristic intensity, a portion of the gesture is identified. For example, the touch sensing surface optionally receives continuous swipe contacts that transition from a starting position to reach an ending position where the intensity of the contact is increasing. In this example, the characteristic intensity of the contact at the ending position is optionally based on only a portion of the continuous swipe contact (e.g., only the portion of the swipe contact at the ending position) rather than the entire swipe contact. In some embodiments, optionally, a smoothing algorithm is applied to the intensity of the swipe contact before determining the characteristic intensity of the contact. For example, the smoothing algorithm optionally includes one or more of a non - weighted moving average smoothing algorithm, a triangular smoothing algorithm, a median filter smoothing algorithm, and / or an exponential smoothing algorithm. In some situations, these smoothing algorithms eliminate narrow spikes or drops in the width of the swipe contact intensity for the purpose of determining the characteristic intensity.

[0147] The intensity of a contact on the touch sensing surface is optionally characterized relative to one or more intensity thresholds such as a contact detection intensity threshold, a light press intensity threshold, a deep press intensity threshold, and / or one or more other intensity thresholds. In some embodiments, the light press intensity threshold typically corresponds to the intensity at which the device performs an operation associated with clicking a button of a physical mouse or a trackpad. In some embodiments, the deep press intensity threshold typically corresponds to the intensity at which the device performs an operation different from an operation associated with clicking a button of a physical mouse or a trackpad. In some embodiments, when a contact having a characteristic intensity below the light press intensity threshold (e.g., and above a nominal contact detection intensity threshold below which contact is not detected) is detected, the device moves the focus selector in accordance with the movement of the contact on the touch sensing surface without performing an operation associated with the light press intensity threshold or the deep press intensity threshold. Generally, unless otherwise specified, these intensity thresholds are consistent among various sets of user interface values.

[0148] An increase in the characteristic intensity of contact from an intensity below the light pressing intensity threshold to an intensity between the light pressing intensity threshold and the deep pressing intensity threshold may be referred to as an input of "light pressing". An increase in the characteristic intensity of contact from an intensity below the deep pressing intensity threshold to an intensity above the deep pressing intensity threshold may be referred to as an input of "deep pressing". An increase in the characteristic intensity of contact from an intensity below the contact detection intensity threshold to an intensity between the contact detection intensity threshold and the light pressing intensity threshold may be referred to as the detection of contact on the touch surface. A decrease in the characteristic intensity of contact from an intensity above the contact detection intensity threshold to an intensity below the contact detection intensity threshold may be referred to as the detection of lift-off of contact from the touch surface. In some embodiments, the contact detection intensity threshold is zero. In some embodiments, the contact detection intensity threshold is greater than zero.

[0149] In some embodiments described herein, in response to detecting a gesture that includes an individual pressing input, or in response to detecting an individual pressing input performed by an individual contact (or multiple contacts), one or more operations are performed, and the individual pressing input is detected based at least in part on detecting an increase in the intensity of a contact (or multiple contacts) above a pressing input intensity threshold. In some embodiments, the individual operation is performed in response to detecting an increase in the intensity of an individual contact above the pressing input intensity threshold (e.g., the "downstroke" of an individual pressing input). In some embodiments, the pressing input includes an increase in the intensity of an individual contact above the pressing input intensity threshold, and a subsequent decrease in the intensity of the contact below the pressing input intensity threshold, and the individual operation is performed in response to detecting a subsequent decrease in the intensity of the individual contact below the pressing input threshold (e.g., the "upstroke" of an individual pressing input).

[0150] In some embodiments, the device employs intensity hysteresis to avoid spurious inputs sometimes referred to as "jitter", and the device defines or selects a hysteresis intensity threshold having a predefined relationship to the press input intensity threshold (e.g., the hysteresis intensity threshold is X intensity units lower than the press input intensity threshold, or the hysteresis intensity threshold is 75%, 90%, or some reasonable percentage of the press input intensity threshold). Thus, in some embodiments, a press input includes an increase in the intensity of an individual contact above the press input intensity threshold, and a subsequent decrease in the intensity of the contact below the hysteresis intensity threshold corresponding to the press input intensity threshold, and an individual operation is performed in response to detecting a subsequent decrease in the intensity of an individual contact below the hysteresis intensity threshold (e.g., the "upstroke" of an individual press input). Similarly, in some embodiments, a press input is detected only when the device detects an increase in the intensity of a contact from an intensity below the hysteresis intensity threshold to an intensity above the press input intensity threshold, and optionally, a subsequent decrease in the intensity of the contact to an intensity below the hysteresis intensity, and an individual operation is performed in response to detecting the press input (e.g., an increase in the intensity of the contact or a decrease in the intensity of the contact, depending on the situation).

[0151] For ease of explanation, the description of an operation performed in response to a press input associated with a press input intensity threshold, or a gesture including a press input, is optionally triggered in response to detecting any of an increase in the intensity of a contact above the press input intensity threshold, an increase in the intensity of a contact from an intensity below the hysteresis intensity threshold to an intensity above the press input intensity threshold, a decrease in the intensity of a contact below the press input intensity threshold, and / or a decrease in the intensity of a contact below the hysteresis intensity threshold corresponding to the press input intensity threshold. Further, in examples where an operation is described as being performed in response to detecting a decrease in the intensity of a contact below the press input intensity threshold, the operation is optionally performed in response to detecting a decrease in the intensity of a contact corresponding to and below a lower hysteresis intensity threshold corresponding to the press input intensity threshold.

[0152] Next, attention is directed to embodiments of a user interface ("UI") and related processes implemented on an electronic device such as the portable multifunctional device 100, device 300, or device 500.

[0153] Figures 6A-6F illustrate exemplary user interfaces for performing secure operations, according to some embodiments. Specifically, Figures 6A-6F illustrate exemplary user interfaces that can be displayed during a scenario in which a secure transaction (e.g., transferring a parking spot between accounts) is completed in response to receiving one or more gestures and biometric data from a user of device 600. The user interfaces in these figures are used to illustrate the processes described below, including the processes in Figures 8 and 9. In some embodiments, the exemplary user interfaces of Figures 6A-6F can be combined with, or displayed simultaneously with, the exemplary user interfaces of Figures 7A-7M described below.

[0154] Figure 6A shows device 600 displaying user interface 602 on a touch-sensitive display. In some embodiments, device 600 includes one or more features of devices 100, 300, and 500 described above.

[0155] As shown in Figure 6A, user interface 602 includes application icons 604. Application icons 604 include a plurality of application icons for launching different applications that cause different user interfaces to be displayed on device 600. Application icons 604 include a parking application icon 604a for launching a parking application and a coffee shop application icon 604b for launching a coffee shop application. In Figure 6A, device 600 detects a tap gesture 650a on (e.g., directed at, corresponding to the location of) parking application icon 604a.

[0156] As shown in FIG. 6B, in response to detecting a tap gesture 650a, device 600 launches a parking application corresponding to parking application icon 604a and displays a user interface 610 of the parking application. User interface 610 includes an account identifier 612, current parking information 614, and recommended parking information 616. Account identifier 612 indicates that device 600 is currently logged in to a specific account (e.g., "Jane's account") that is recognized by and / or belongs to (e.g., stored in a database that communicates with) the parking application. Recommended parking information 616 includes information about one or more available parking spots recommended to the user of device 600.

[0157] As shown in FIG. 6B, current parking information 614 indicates that parking spot #31 located in Garage A at 123 Gala Street is currently assigned to Jane's account. Current parking spot information 614 also includes a time frame (e.g., 9:00 a.m. to 11:00 a.m.) during which parking spot #31 is assigned to Jane's account before it is automatically transferred back to the account associated with Garage A. Further, the current parking information includes a check-in control 618 for transferring parking spot #31 from Jane's account to the account belonging to Garage A. In FIG. 6B, device 600 detects a tap gesture 650b on check-in control 618.

[0158] As shown in FIG. 6C, in response to detecting a tap gesture 650b, device 600 initiates a process that includes performing a transaction (e.g., performing a secure operation) to transfer parking spot #31 from Jane's account to the account associated with Garage A. As shown in FIG. 6C, in response to detecting a tap gesture 650b, device 600 displays user interface 620 over a portion of user interface 610 and blurs a portion of user 610 that remains displayed in FIG. 6C. User interface 620 includes transaction information 622, a confirmation command 624, and an input command 626. Transaction information 622 includes information such as the electronic mail address (e.g., "jane - apples@mail.com") assigned (e.g., filed) to the specific account (e.g., "Jane's account") to which parking spot #31 is currently assigned, and an identifier ("Garage A") associated with the account to which parking spot #31 is to be transferred. In FIG. 6C, the parking application is configured to perform the transfer operation using Jane's account (e.g., and / or the email address assigned to Jane's account). Confirmation command 624 indicates that an input needs to be received on hardware button 648 (e.g., "side button") for the transaction to be initiated, and input command 626 indicates that hardware button 648 needs to be quickly double - clicked (e.g., "double - clicked") to initiate the transaction. In FIG. 6C, device 600 detects a double - click input 650c on hardware button 648.

[0159] In FIG. 6D, in response to detecting a double - click input 650c, the device 600 initiates an authentication process to cause the camera 646a and / or the camera 646b to capture an image in order to obtain biometric data (e.g., data corresponding to one or more features of the user's face). As part of the authentication process, the device 600 also replaces the confirmation command 624 with a biometric identification status indicator 628, indicating that the device 600 is attempting to capture an image to obtain biometric information.

[0160] In FIG. 6D, after capturing a set of images, device 600 obtains biometric data (e.g., one or more features of the user's face) to authenticate the user so that the transaction can be permitted. Device 600 uses the newly obtained biometric data to authenticate the current user of device 600 by matching (e.g., matching within a certain confidence level) the newly obtained biometric data to previously stored biometric data associated with a known user having permission to complete a secure transaction via device 600. In some embodiments, the biometric data (e.g., previously stored biometric data and newly captured biometric data) is accessible to an application for managing secure transactions (or operations) on device 600. In some embodiments, the parking application does not have access to the biometric data. In some embodiments, if device 600 is unable to match the newly obtained biometric data to the previously stored biometric data, device 600 continues to capture images and obtain additional biometric data to match to the previously stored biometric data. In some embodiments, device 600 captures images only over a predetermined period of time. In some embodiments, if device 600 is unable to match the biometric data, device 600 displays an indication that it cannot transfer parking spot #31 to garage A because it cannot authenticate the user of device 600, and / or displays controls for completing the authentication of the transaction in another way (e.g., via entry of a password). In some embodiments, device 600 can authenticate the user by capturing and comparing other types of biometric data, such as finger data (e.g., captured via a touch-sensitive display including a fingerprint sensor), voice data (e.g., via one or more microphones).In FIG. 6D, device 600 (or another device communicating with device 600) matches a newly acquired set of biometric data with previously stored biometric data, thereby authenticating the current user of device 600 as a user having permission to complete a secure transaction via device 600.

[0161] In FIG. 6E, in response to authenticating the current user of device 600 as a user having permission to complete a secure transaction (e.g., via Jane's account), device 600 causes parking spot #31 to be transferred from Jane's account to the account of Garage A. In some embodiments, device 600 uses a secure hardware component (e.g., a hardware chip) that stores information representing Jane's account (e.g., Jane's email address, a device-specific account identifier) to cause parking spot #31 to be transferred from Jane's account to the account of Garage A. In some embodiments, the secure hardware component does not store or have access to primary information (e.g., a primary account number) associated with Jane's account. In some embodiments, authenticating that the current user of device 600 has permission to complete a secure transaction permits device 600 to use the secure hardware component to complete the secure transaction.

[0162] As shown in FIG. 6E, in response to authenticating the current user of device 600 as a user having permission to complete a secure transaction, device 600 also replaces biometric identification status indicator 628 with authenticated status indicator 630 to indicate that the user has been authenticated and the transfer is complete.

[0163] As shown in FIG. 6F, after completing the transfer, device 600 stops displaying user interface 620 and updates user interface 610 to indicate that parking spot #31 is no longer assigned to Jane's account (e.g., via confirmation command 624). Additionally, after completing the transfer, device 600 also receives and displays a notification 632 indicating that the transfer has been completed (e.g., from one or more external devices).

[0164] FIGS. 7A - 7M illustrate exemplary user interfaces for performing secure operations according to some embodiments. Specifically, FIGS. 7A - 7M illustrate exemplary user interfaces that can be displayed during scenarios where one or more secure transactions are to be completed in response to receiving one or more gestures on a touch - sensitive display of automotive head unit 700 that communicates with device 600. The user interfaces in these figures are used to illustrate processes described below, including the processes in FIGS. 8 and 9.

[0165] As shown in FIG. 7A, device 600 operably communicates with automotive head unit 700 as indicated by communication link 708. In some embodiments, device 600 operably communicates with automotive head unit 700 via a wireless or wired connection. In some embodiments, automotive head unit 700 includes a touch - sensitive display and is installed on the dashboard of the automobile. In some embodiments, automotive head unit 700 includes one or more features of devices 100, 300, and 500 described above.

[0166] As shown in FIG. 7A, the device 600 displays a user interface 670 that includes a lock indication 672 indicating that the device 600 is in a locked state (e.g., a state where one or more functions (e.g., display function, input function) of the display that are available in the unlocked state are disabled / unavailable). While the device 600 is in the locked state, one or more operations that can be performed when the device 600 is in the unlocked state cannot be performed when the device 600 is in the locked state. The one or more operations include performing one or more operations for the device 600 to interact with the automotive head unit 700 while the device 600 is in the locked state without receiving prior permission to interact. The one or more operations for interacting with the automotive head unit 700 include causing the automotive head unit 700 to display one or more user interface components (e.g., user interfaces, icons) corresponding to an application installed on the device 600 (e.g., by sending commands and data).

[0167] In FIG. 7A, the device 600 has not received prior permission to interact with the automotive head unit 700 while the device 600 is operating in the locked state. Thus, in FIG. 7A, the device 600 causes the automotive head unit 700 to display a user interface 714. The user interface 714 is displayed in response to the device 600 detecting a connection between the automotive head unit 700 and the device 600 (e.g., an operational communication has been established). The user interface 714 includes a command for the user to unlock the device 600 in order to cause the device 600 to start a "car player" on the automotive head unit 700 and / or to cause the automotive head unit 700 to display one or more user interface components corresponding to an application installed on the device 600.

[0168] As shown in FIG. 7A, while the device 600 is operating in a locked state, since the device 600 has not received a previous permission to interact with (e.g., provide data to and / or receive data from) the automotive head unit 700, the device 600 displays a notification 676 that includes an instruction similar to the instruction displayed on the automotive head unit 700. In some embodiments, when the device 600 is operably communicating with and has received a previous permission to interact with another display device (e.g., the automotive head unit 700), the device 600 causes the other display device to display one or more user interface components corresponding to the applications installed on the device 600. In FIG. 7A, the device 600 receives an upward swipe gesture 750a on the user interface 670 and authenticates the user to perform a secure operation of unlocking the device 600 by obtaining biometric data (e.g., via one or more of cameras 646a and 646b). In some embodiments, the device 600 obtains biometric data (e.g., via cameras 646a and / or 646b) and / or authenticates the user of the device 600 to unlock the device 600 using one or more techniques similar to those described above (e.g., in response to detecting the gesture 650c of FIG. 6C).

[0169] As shown in FIG. 7B, in response to receiving the upward swipe gesture 750a and authenticating the user of the device 600, the device 600 switches to operating in an unlocked state and stops displaying the user interface 670. Further, in response to receiving the upward swipe gesture 750a and authenticating the user of the device 600, the device 600 displays a user interface 602 that includes an application icon 604. In FIG. 7B, since the user interface 602 was the last user interface displayed by the device 600 before the device 600 entered the locked state, the user interface 602 is displayed.

[0170] As shown in FIG. 7B, since the device 600 is operating in an unlocked state, the device 600 causes the automotive head unit 700 to display a user interface 702 that includes an enlarged set of application icons 704. The application icons 704 correspond to the same applications as the parking application icons 604a (e.g., an application on the automotive head unit 700 that is compatible with the parking application of the application icon 604 (e.g., can access data therefrom) is launched; the device 600 causes the automotive head unit 700 to display an interface directly generated by the parking application on the device 600), and include a parking application icon 704a and a coffee shop application icon 704b that corresponds to the same application as the coffee shop application icon 604b. The application icons 704 are larger than the application icons 604, and as a result, the application icons 704 are more readable and interactable by the user operating the vehicle. Additionally, the application icons 704 are a subset of the application icons 604. That is, the number of application icons 704 is less than the number of application icons 604, and some of the application icons included in the application icons 604 are not included in the application icons 704 (e.g., the camera application icon).

[0171] As shown in FIG. 7B, in response to receiving an upward swipe gesture 750a and authenticating the user of device 600, device 600 also displays a user interface 660 superimposed on user interface 602. While device 600 is operating in a locked state and has not received a previous permission to interact with automotive head unit 700, device 600 displays user interface 660. User interface 660 includes a control 661 that permits interaction while locked. In FIG. 7B, device 600 detects a tap gesture 750b on control 661 that permits control while locked.

[0172] In FIG. 7C, in response to detecting tap gesture 750b, device 600 receives permission to interact with automotive head unit 700 while device 600 is operating in a locked state and stops displaying user interface 660. As shown in FIG. 7C, in response to detecting tap gesture 750b, device 600 displays a user interface 662 superimposed on user interface 602. User interface 662 is a user interface for setting a trust level assigned to automotive head unit 700, which, as will be further described below, device 600 uses to determine whether automotive head unit 700 is trusted to initiate one or more secure operations. As shown in FIG. 7C, user interface 662 includes three options 664; an "always" option 664a, a "once" option 664b, and a "never" option 664c.

[0173] When the "Always" option 664a is selected (e.g., via a gesture such as a tap gesture), the device 600 is configured to permanently trust the automotive head unit 700. As a result, the automotive head unit 700 is trusted by the device 600 until the device 600 is manually reconfigured to not trust the automotive head unit 700 (e.g., via one or more inputs on a different interface). Thus, in a scenario where the device 600 is disconnected (e.g., the operable communication is terminated) and then reconnected to the automotive head unit 700 (e.g., the operable communication is started) after the "Always" option 664a is selected, since the automotive head unit 700 is a permanently trusted device, the device 600 does not display the user interface shown in FIGS. 7A - 7C.

[0174] When the "Once" option 664b is selected, the device 600 is configured to temporarily trust the automotive head unit 700. As a result, the automotive head unit 700 is trusted by the device 600 until the device 600 is disconnected from the automotive head unit 700. Thus, in a scenario where the device 600 is disconnected (e.g., the operable communication is terminated) and then reconnected to the automotive head unit 700 (e.g., the operable communication is started) after the "Once" option 664b is selected, since the automotive head unit 700 is no longer a trusted device, the device 600 redisplay the user interface shown in FIGS. 7A - 7C.

[0175] When the "Do not" option 664c is selected, the device 600 is configured not to trust the automotive head unit 700, and as a result, the automotive head unit 700 ceases to be a trusted device. Thus, in a scenario where after the "Do not" option 664c is selected, the device 600 is disconnected (e.g., the operable communication is terminated) and then reconnected to the automotive head unit 700 (e.g., the operable communication is initiated), since the automotive head unit 700 is not a trusted device, the device 600 displays the user interfaces shown in FIGS. 7A - 7C.

[0176] FIG. 7C shows a user interface 662 that includes three options 664 for setting the trust level of the device 600 with respect to the automotive head unit 700. However, the automotive head unit 700 may be trusted or not trusted based on other factors. In some embodiments, the device 600 is configured to trust the automotive head unit 700 if the automotive head unit 700 is a particular type of display device, such as a display device from a particular manufacturer, or has a particular type of software installed. In some embodiments, the device 600 is configured to trust the automotive head unit 700 if the device 600 is physically connected to a vehicle that includes hardware trusted by the device 600 (e.g., a secure identification chip). In some embodiments, if the device 600 trusts the automotive head unit 700 based on other factors, the user interface 662 is not displayed in response to detecting a tap gesture 750b.

[0177] FIGS. 7D - 7E show exemplary user interfaces that are displayed after the "Do not" option 664c is selected in FIG. 7C. In FIG. 7C, the device 600 detects a tap gesture 750c3 on the "Do not" option 664c.

[0178] In FIG. 7D, in response to detecting the tap gesture 750c3, the device 600 is configured such that the automotive head unit 700 is not a trusted device, as described above in connection with FIG. 7C. As shown in FIG. 7D, since the device 600 is configured to enter a locked state after a predetermined period has elapsed since the tap gesture 750c3 was detected and a predetermined period has passed, the device 600 is also in a locked state (e.g., as indicated by the lock indicator 672). In particular, since the device 600 has received permission to interact (e.g., via the tap gesture 750b on the control 661 that permits interaction while locked in FIG. 7B), the device 600 continues to interact with the automotive head unit 700 (e.g., to display the user interface 702) while the device 600 is in the locked state. In FIG. 7D, the device 600 receives an indication from the automotive head unit 700 that a tap gesture 752d1 has been detected at a position on the automotive head unit 700 corresponding to the parking application icon 704a.

[0179] As shown in FIG. 7E, in response to the device 600 receiving an indication that the tap gesture 752d1 has been detected, the device 600 causes the automotive head unit 700 to display the user interface 710. The user interface 710 corresponds to the user interface 610 described above in connection with FIGS. 6B-6D. Accordingly, the user interface 710 is a user interface for a parking application. Compared to the user interface 610 in FIG. 6B, the user interface 710 includes less information (e.g., does not include recommendation information on the user interface 710) than the information displayed on the user interface 610. Also, one or more similar components (e.g., the account identifier 712) displayed on the user interface 710 are enlarged compared to the corresponding components (e.g., the account identifier 612) on the user interface 610. However, the user interface 610 in FIG. 6B and the user interface 710 convey similar information.

[0180] As shown in FIG. 7E, the user interface 710 includes an account identifier 712 and current parking information 714 (displayed using, for example, the same techniques and for the same reasons as described above in connection with account identifier 612 and current parking information 614). As shown in FIG. 7E, the account identifier 712 indicates that the device 600 is currently logged in to "Jane's account", and currently, the parking information 714 indicates that parking spot #31 in Garage A is currently assigned to Jane's account.

[0181] In particular, as shown in FIG. 7E, in response to the device 600 receiving an indication that a tap gesture 752d1 has been detected, the device 600 does not display a control corresponding to the check-in control 618. Here, the device 600 does not display a control corresponding to the check-in control 618 because the automotive head unit 700 is not a trusted device (e.g., due to a tap gesture 750c3 on the "No" option 664c). Instead of displaying a check control, the device 600 causes the automotive head unit 700 to display an instruction 716 indicating that the user must complete a check-in process on the device 600 (e.g., via one or more inputs on the device 600 as described above in connection with FIGS. 6A - 6E). In some embodiments, the device 600 causes the automotive head unit 700 to display the instruction 716 even if the device is a trusted device when the parking application on the device 600 does not have an already filed (e.g., linked) account for the application. Thus, in FIG. 7E, since the automotive head unit 700 is not trusted by the device 600, one or more inputs for the device 600 to complete a secure operation cannot be detected on the automotive head unit 700.

[0182] Figures 7F - 7I show exemplary user interfaces that are displayed after the "Always" option 664a or the "Once" option 644b is selected in FIG. 7C. In FIG. 7C, the device 600 detects a tap gesture 750c1 on the "Always" option 664a or a tap gesture 750c2 on the "Once" option 644b. In FIG. 7F, in response to detecting the tap gesture 750c1 or the tap gesture 750c2, the device 600 is configured such that the automotive head unit 700 (as described above in connection with FIG. 7C, for example) is a trusted device. In FIG. 7F, the automotive head unit 700 and the device 600 display the same respective user interfaces as the user interface displayed in FIG. 7D. In FIG. 7F, the device 600 receives an indication from the automotive head unit 700 that a tap gesture 752d1 has been detected at a location on the automotive head unit 700 corresponding to the parking application icon 704a.

[0183] In response to the device 600 receiving an indication that the tap gesture 752d1 has been detected, as shown in FIG. 7G, the device 600 causes the automotive head unit 700 to display the user interface 710. The user interface 710 of FIG. 7G includes the same components as those described above in connection with the user interface of FIG. 7E, except for one separate component. As shown in FIG. 7G, the user interface 710 includes a check-in control 718 that was not displayed in FIG. 7E and excludes the instruction 716 that was displayed in FIG. 7E. In FIG. 7G, since the automotive head unit 700 is trusted by the device 600 (e.g., via the selection of the "Always" option 664a or the "Once" option 644b), the device 600 causes the automotive head unit 700 to display the check-in control. In some embodiments where the tap gesture 750c2 on the "Once" option 644b in FIG. 7C was detected, when the user interface 710 is redisplayed after the device 600 is disconnected and then reconnected to the automotive head unit 700, the check-in control 718 is not displayed. In some embodiments where the tap gesture 750c1 on the "Always" option 644a in FIG. 7C was detected, when the user interface 710 is redisplayed after the device 600 is disconnected and then reconnected to the automotive head unit 700, the check-in control 718 is displayed. In FIG. 7G, the device 600 receives an indication from the automotive head unit 700 that the tap gesture 752g has been detected at the position on the automotive head unit 700 corresponding to the check-in control 718. In some embodiments, if account information regarding Jane's account (e.g., Jane's email address) is not stored in a secure hardware component and is not configured to be used to complete a transaction using the parking application, the check-in control 718 is not displayed.

[0184] As shown in FIG. 7H, in response to receiving an indication that a tap gesture 752g has been detected, device 600 causes the vehicle head unit 700 to replace the check-in control 718 with the confirmation control 728. In FIG. 7H, device 600 receives an indication from the vehicle head unit 700 that a tap gesture 752h has been detected at a position on the vehicle head unit 700 corresponding to the confirmation control 728.

[0185] In FIG. 7I, in response to receiving an indication that a tap gesture 752h has been detected, device 600 causes the parking spot #31 to be transferred from Jane's account to the Garage A account. In some embodiments, the transfer is performed in response to the tap gesture 752g on the check-in control 718 without requiring further confirmation input. In FIG. 7I, when device 600 causes the parking spot #31 to be transferred from Jane's account to the Garage A account, device 600 (not the vehicle head unit 700) communicates with one or more external devices (e.g., a database, an account management server) that update the Jane's account information and the Garage A account information to perform the transfer. In some embodiments, information corresponding to Jane's account (e.g., Jane's email address) is stored in a secure hardware component of device 600, and device 600 accesses the information corresponding to Jane's account within the secure hardware component. In some embodiments, device 600 transmits the accessed information corresponding to Jane's account (e.g., or a token corresponding to the accessed information) to one or more external devices as part of performing the transfer.

[0186] Returning to FIGS. 6C-6D, in response to detecting a confirmation gesture (e.g., double click input 650c), device 600 authenticates the user by capturing biometric data (e.g., via cameras 646a and 646b), and then transfers parking spot #31. However, in FIG. 7H, after receiving an indication that tap gesture 752h has been detected, device 600 transfers parking spot #31 from Jane's account to the Garage A account without authenticating the user of device 600 and / or automotive head unit 700. In FIG. 7H, since automotive head unit 700 is trusted by device 600, device 600 does not need to authenticate the user by capturing biometric data. When the user is operating the vehicle, for reasons of simplicity and safety, it may be useful to allow a user of a trusted display device to complete a transaction without providing biometric data (or other authentication data) via device 600. In some embodiments, when device 600 is unlocked in FIGS. 6A-6B, since device 600 has previously authenticated the user, device 600 also does not need to authenticate the user via biometric data.

[0187] As shown in FIG. 7I, in response to receiving an indication that tap gesture 752h has been detected, device 600 causes automotive head unit 700 to display a transaction interface 720 that includes transaction information 722. Transaction interface 720 includes information regarding a completed transaction for transferring parking spot #31 from Jane's account to the Garage A account. Transaction information 722 is displayed using a similar technique as described above in relation to transaction information 622 of FIG. 6E. Here, transaction information 722 and transaction information 622 are displayed using different layouts. In some embodiments, transaction information 722 and the transaction information are displayed using the same layout.

[0188] Figures 7J through 7L illustrate exemplary user interfaces that are displayed in a scenario where, after the "always" option 664a or the "one time" option 644b is selected in Figure 7C, a different type of transaction (e.g., a payment transaction) using a different application (e.g., a coffee shop application) is being attempted. Returning to Figure 7F (or Figure 7D), the device 600 receives an indication from the automotive head unit 700 that a tap gesture 752d2 has been detected at a location on the automotive head unit 700 corresponding to the coffee shop application icon 704b.

[0189] As shown in Figure 7J, in response to receiving an indication that the tap gesture 752d2 has been detected, the device 600 causes the automotive head unit 700 to display a user interface 730 that is the user interface of the coffee shop application. The user interface 730 includes order recommendations 734 along with purchase controls 738. In Figure 7J, since the automotive head unit 700 is a trusted device (e.g., the "always" option 664a or the "one time" option 644b was previously selected in Figure 7C), the device 600 causes the automotive head unit 700 to display the purchase controls 738. In some embodiments, the device 600 does not cause the automotive head unit 700 to display the purchase controls 738 if the automotive head unit 700 is not trusted by the device 600. In some embodiments, the automotive head unit 700 can display an instruction (e.g., an instruction similar to instruction 716 as described above with reference to Figure 7E) indicating that the device 600 must be used to purchase an item from the coffee shop. In Figure 7J, the device 600 receives an indication from the automotive head unit 700 that a tap gesture 752j has been detected at a location on the automotive head unit 700 corresponding to the confirmation control 728.

[0190] In response to receiving an indication that a tap gesture 752j has been detected, as shown in FIG. 7K, device 600 causes user interface 740 to be displayed on automotive head unit 700. User interface 740 is a user interface for purchasing an order associated with Jane's account. In FIG. 7J, Jane's account is associated with a favorite order that includes a cup of drip coffee priced at $2.59. As shown in FIG. 7J, Jane's account is also associated with a card representation 734 (“Jane's Card”), which is a representation of a payment card linked to a bank account associated with Jane. As shown in FIG. 7J, user interface 740 also includes an order confirmation control 742 that is similar to confirmation control 728 of FIG. 7H. In FIG. 7K, device 600 receives an indication from automotive head unit 700 that a tap gesture 752k has been detected at a location on automotive head unit 700 corresponding to confirmation control 728.

[0191] In response to receiving an indication that a tap gesture 752k has been detected, as shown in FIG. 7L, device 600 causes $2.59 to be transferred from the bank account associated with Jane's card to the bank account associated with Garage A (and / or the parking application) without capturing biometric data (for example, for the same reasons described above in connection with FIG. 7I) and / or without authenticating the user of the automotive head unit 700 and / or device 600. In FIG. 7L, when device 600 causes money to be transferred from the bank account associated with Jane's card to the bank account associated with Garage A, device 600 (and not the automotive head unit 700) communicates with one or more external devices (for example, a database, an account management server) to update the balances of Jane's account and Garage A's account to reflect the completed transaction. In some embodiments, device 600 uses a secure hardware component (for example, a hardware chip) that stores information representing the account number associated with Jane's card to cause money to be transferred from Jane's account to Garage A's account. In some embodiments, the secure hardware component does not store, or have access to, the primary information (for example, the primary account number) associated with Jane's card. In some embodiments, if device 600 is not configured to process a transaction using Jane's card, device 600 is unable to process the transaction and device 600 does not display the purchase control 638 within the user interface 730, regardless of whether the automotive head unit 700 is trusted by device 600.

[0192] In response to receiving an indication that a tap gesture 752k has been detected, as shown in FIG. 7L, device 600 causes automotive head unit 700 to display user interface 760 including transaction information 762. Transaction information 762 displays information similar to transaction information 722, as described above with respect to FIG. 7L. Additionally, transaction information 762 in FIG. 7L is displayed using the same layout as transaction information 722 in FIG. 7L. As shown in FIG. 7L, transaction information 762 indicates that $2.59 has been transferred from the account associated with Jane's card, as represented by card representation 762.

[0193] FIG. 7M shows a device 600 that displays a settings user interface having settings 772. The settings 772 are enabled (e.g., “on”) and are settings to enable processing of transactions via gestures received at an automotive head unit 700. Returning to the embodiments described above in connection with FIGS. 7A-7M, the device 600 was able to process various transactions in response to detecting a gesture received on the automotive head unit 700 if the automotive head unit 700 was trusted by the device 600. Thus, in the embodiments described above in connection with FIGS. 7A-7M, the settings 772 were on. In some embodiments, when the settings 772 are off, the device 600 cannot process various transactions in response to detecting a gesture received on the automotive head unit 700, regardless of whether the automotive head unit 700 is trusted by the device 600. In some embodiments, there are one or more other settings similar to the settings 772. These settings can enable a user of the device 600 to control whether the device 600 can process various transactions for a particular application. In some embodiments, the device 600 is configured to be able to process transactions for a parking spot application via gestures received at the automotive head unit 700 (e.g., via one or more settings) and not be able to for a coffee shop application.Accordingly, in some of these embodiments, regardless of whether the automotive head unit 700 is trusted by the device 600, when the device 600 causes one or more user interfaces of a parking application (e.g., the user interface 710 of FIG. 7G) to be displayed on the automotive head unit 700, the device 600 causes a transaction control (e.g., the check control 718) to be displayed on the automotive head unit 700, and when the device 600 causes one or more user interfaces of a coffee shop application (e.g., the user interface 710 of FIG. 7G) to be displayed on the automotive head unit 700, the device 600 does not cause a transaction control (e.g., the purchase control 738) to be displayed on the automotive head unit 700.

[0194] FIG. 8 is a flow diagram showing a method of performing secure operations using a computer system, according to some embodiments. The method 800 is executed in a computer system (e.g., 100, 300, 500, 600). The computer system (e.g., 600) communicates (e.g., wirelessly, wired) with an external automotive head unit (e.g., 700) (e.g., an integrated hardware interface (e.g., a stereo head unit, an infotainment system) of multiple entertainment and information systems (e.g., sound, navigation) of an automobile) that includes one or more input components (e.g., a touch-sensing surface (e.g., a touch screen), a hardware button), and the computer system communicates with an external receiving device (e.g., a transaction management server, a payment terminal). Some of the operations of the method 800 are optionally combined, the order of some of the operations is optionally changed, and some of the operations are optionally omitted.

[0195] As will be described below, method 800 provides an intuitive way to perform secure operations using a computer system. This method reduces the cognitive burden on the user performing secure operations using the computer system, thereby creating a more efficient human-machine interface. This method also enables the user to perform secure operations using the computer system more safely and securely. In the case of a battery-operated computing device, power is conserved and the battery charging interval is increased by enabling the user to perform operations using the computer system faster and more efficiently.

[0196] The computer system receives (802) first data corresponding to an input (e.g., 752g, 752h, 752j, 752k) (e.g., selection of a payment-selectable user interface object) received by one or more input components of an external automotive head unit (e.g., 700) in response to a request to perform a first transfer operation from a first account (e.g., Jane's account shown by 712, Jane's card shown by 734) (e.g., an account associated with the user of the computer system, a credit account, a debit account, a cash balance account) to a second account (e.g., a garage account, a coffee shop account) (e.g., an account associated with a merchant) using an application (e.g., a digital point-of-sale application, a digital wallet application, an e-commerce application) on the computer system (e.g., 600) associated with the first account from an external automotive head unit (e.g., 700).

[0197] In response to receiving first data (e.g., data associated with input 752g, 752h, 752j, or 752k), the computer system starts a process (e.g., a process that can request one or more additional inputs (e.g., inputs on the computer system to fully complete) using an application on the computer system to perform a first transfer operation (e.g., a transaction (e.g., a payment transaction, a purchase)) (804). In some embodiments, in response to receiving the first data, a first operation is performed. In some embodiments, the first data includes one or more parameters or variables that affect the operation (e.g., the amount of the purchase, the item for the purchase). As part of performing the first transfer operation, the computer system transmits to an external receiving device second data that includes information identifying the first account (e.g., an encrypted representation of an account stored on the computer system (e.g., a device-specific account number), a representation of a payment account (e.g., a credit, debit, and / or cash balance account)). In some embodiments, the second data includes information other than the account identifier (e.g., transaction parameters (e.g., price, amount)). By performing a transfer operation using an application on the computer system based on an input on an automotive head unit, the ability to perform the transfer operation is provided to the user without the need to directly interact with the computer system. By performing an operation without the need to directly interact with the computer system, the safety of the user while using the computer system and operating the vehicle can be enhanced. Also, by performing a transfer operation using an application on the computer system based on an input on the automotive head unit, an option to perform an operation using the input on the head unit is provided to the user.By providing additional control options, the operability of the computer system is improved, (for example, assisting the user to provide appropriate input when operating / devicing interacting with the device and reducing user errors), making the user-device interface more efficient, and in addition, reducing power consumption and improving the battery life of the device by enabling the user to use the computer system more quickly and efficiently.

[0198] In some embodiments, an application (for example, the applications shown as 604a, 704a, 604b, 704b) was configured to perform a transfer operation from a first account (for example, and continue to be configured) (for example, the first account was previously associated with the application (for example, the first account is filed with the application)). In some embodiments, a second application that was not previously configured to perform a transfer operation from an existing account (for example, the first account) cannot be used with the external vehicle head unit to perform the transfer operation (for example, until the second application is associated with the existing account). By performing the transfer operation using an application on a computer system that was already configured to operate using the first account, the risk of incorrect operations is reduced (for example, by reducing the risk of using the wrong account or errors in providing account information). By reducing the risk of errors when operating the computer system, the operability of the computer system is improved, (for example, assisting the user to provide appropriate input when operating / devicing interacting with the device and reducing user errors), making the user-device interface more efficient, and in addition, reducing power consumption and improving the battery life of the device by enabling the user to use the computer system more quickly and efficiently.

[0199] In some embodiments, a second application (e.g., the applications shown as 604a, 704a, 604b, 704b) different from a first application (e.g., the applications shown as 604a, 704a, 604b, 704b) is installed on a computer system (e.g., 600). In some embodiments, in accordance with the second application (e.g., the applications shown as 604a, 704a, 604b, 704b) being configured to perform a transfer operation from a third account (e.g., Jane's account as indicated by 712, Jane's card as indicated by 734) (e.g., an account different from the first account, the same account as the first account), the second application is configured to perform the transfer operation in response to a request to perform a transfer operation from a third account (e.g., Jane's account, Jane's card) received from an external vehicle head unit (e.g., 700). In some embodiments, in accordance with the second application (e.g., the applications shown as 604a, 704a, 604b, 704b) not being configured to perform a transfer operation from a third account (e.g., not configured (e.g., pre-configured) to perform a transfer operation from any existing account). In some embodiments, the second application is not configured to perform a transfer operation in response to a request (e.g., 752g, 752h, 752j, 752k) to perform a transfer operation from a third account (e.g., Jane's account as indicated by 712, Jane's card as indicated by 734) received from an external vehicle head unit (e.g., 700). In some embodiments, only installed applications that are already configured to perform transfer operations from one or more existing accounts can perform transfer operations based on inputs received at the external vehicle head unit.Based on whether a given application is already configured to perform operations using an account, perform a transfer operation using the application on a computer system to reduce the risk of incorrect operations (e.g., by reducing the risk of using the wrong account or errors in providing account information). By reducing the risk of errors when operating the computer system, improve the operability of the computer system, make the user-device interface more efficient (e.g., by assisting the user to provide appropriate inputs when operating / interacting with the device and reducing user errors), and in addition, reduce power consumption and improve the battery life of the device by enabling the user to use the computer system more quickly and efficiently.

[0200] In some embodiments, the second application is configured to perform a transfer operation from a third account. In some embodiments, the computer system receives, from an external automotive head unit (e.g., 700) (e.g., in some embodiments, from an external automotive head unit different from this external automotive head unit), a second application (e.g., the applications shown as 604a, 704a, 604b, 704b) for use in performing a second transfer operation from a third account (e.g., Jane's account as indicated by 712, Jane's card as indicated by 734) (e.g., an account associated with a user of the computer system, a credit account, a debit account, a cash balance account) to a fourth account (e.g., the account of Garage A, the account of the coffee shop) (e.g., an account associated with a merchant, the same account as the second account, an account different from the second account). The computer system receives third data (e.g., before receiving the first data, after receiving the first data) corresponding to an input (e.g., 752g, 752h, 752j, 752k) (e.g., selection of a payment-selectable user interface object) received by one or more input components of the external automotive head unit (e.g., 700) in response to a request to perform the second transfer operation. In some embodiments, in response to receiving the third data, the computer system starts a process (e.g., a process that can request one or more additional inputs (e.g., inputs at the computer system to complete fully)) of using the second application (e.g., the applications shown as 604a, 704a, 604b, 704b) to perform the second transfer operation (e.g., a transaction (e.g., a payment transaction, a purchase)) (and, in some embodiments, performing the first operation in response to receiving the first data). In some embodiments, the first data is one or more parameters or variables that affect the operation (e.g., the amount of the purchase, the items for the purchase).In some embodiments, as part of performing the second transfer operation, the computer system transmits to an external receiving device fourth data (e.g., an encrypted representation of an account stored on the computer system (e.g., a device-specific account number), a representation of a payment account (e.g., credit, debit, and / or cash balance account)) that includes information identifying a third account (e.g., Jane's account as indicated by 712, Jane's card as indicated by 734). In some embodiments, the second data includes information other than the account identifier (e.g., transaction parameters (e.g., price, quantity)). By using a second application on the computer system to perform the second transfer operation based on an input on the automotive head unit, the user is provided with the ability to perform the second transfer operation without having to directly interact with the computer system. By performing operations without having to directly interact with the computer system, the safety of the user while using the computer system and operating the automobile can be enhanced. Also, by using an application on the computer system to perform a transfer operation based on an input on the automotive head unit, the user is provided with the option of using the input on the head unit to perform an operation. By providing additional control options, the operability of the computer system is improved, (e.g., by assisting the user to provide appropriate inputs when operating / devicing interacting with the device and reducing user errors), making the user-device interface more efficient, and in addition, reducing power consumption and improving the battery life of the device by enabling the user to use the computer system more quickly and efficiently.

[0201] In some embodiments, a computer system (e.g., 600) communicates with (e.g., includes) a display generation component (e.g., a display (e.g., an integrated touch screen display)), and the display generation component is in a locked state (e.g., 760) (e.g., a state in which one or more functions of the display (e.g., a display that is available in an unlocked state) or functions (e.g., a display function, an input function) are disabled / unavailable) while the computer system (e.g., 600) is receiving the first data. Also, while the computer system is in the locked state, by performing a transfer operation using an application on the computer system based on an input on an automotive head unit, an option to perform an operation using the input on the head unit is provided to the user without the need to separately unlock the computer system, thereby reducing the risk of unintended input in the computer system, and by doing so, increasing the security of the system by enabling the computer system to remain in the locked state more frequently (e.g., while still being usable). By providing additional control options and improving security, the operability of the computer system is improved, the user-device interface is made more efficient and secure (e.g., by assisting the user to provide appropriate input when operating / interacting with the device and reducing user errors), and in addition, the power consumption is reduced and the battery life of the device is improved by enabling the user to use the computer system more quickly, efficiently, and securely.

[0202] In some embodiments, an external automotive head unit (e.g., 700) is permitted to request execution of a transfer operation from a first account (e.g., Jane's account as indicated by 712, Jane's card as indicated by 734) (e.g., and from other accounts accessible from and / or stored on a computer system) (e.g., before receiving the first data). In some embodiments, a non-permitted (e.g., untrusted) external automotive head unit cannot request execution of a transfer operation from an account accessible from and / or stored on a computer system. Only when the automotive head unit is permitted, based on an input on the automotive head unit, using an application on the computer system to execute a transfer operation reduces the risk of unauthorized operations (e.g., especially when the user of the computer system is not controlling the input provided by the head unit). By reducing the risk of unauthorized operations and improving the security of the computer system, the operability of the computer system is improved, (e.g., assisting the user to provide appropriate input when operating / interacting with the device and reducing user errors) making the user-device interface more efficient, and in addition, reducing power consumption and improving the battery life of the device by enabling the user to use the computer system more quickly and efficiently.

[0203] In some embodiments, before detecting the first data (e.g., the data associated with inputs 752g, 752h, 752j, or 752k), the computer system receives a first set of one or more inputs (e.g., 750c1, 750c2) (e.g., inputs at an external automotive head unit and / or at the computer system). In some embodiments, in response to the first set of one or more inputs (e.g., 750a, 750b, 750c1, 750c2), the computer system permits (e.g., permits prior to communicating) the connection of an external automotive head unit (e.g., 700) to the computer system (e.g., 600) while the computer system is in a locked state (e.g., 760) (e.g., a state in which one or more functions of the computer system that are available while unlocked are unavailable), and permits the external automotive head unit (e.g., 700) to request the execution of a transfer operation from a first account (e.g., and / or from other accounts accessible from and / or stored on the computer system). Permitting the external automotive head unit to request the execution of a transfer operation based on previous user input provides additional control options to the user and reduces the need for permission input for each operation. By providing additional control options and enabling operations to be performed without requiring input at a particular time, the operability of the computer system is improved, the user-device interface is made more efficient (e.g., by assisting the user in providing appropriate input when operating / devicing interacting with the device and reducing user errors), and in addition, the power consumption is reduced and the battery life of the device is improved by enabling the user to use the computer system more quickly and efficiently. Also, by performing the transfer operation using a permitted (e.g., trusted) external automotive head unit, security is enhanced by reducing the risk of unauthorized requests for the transfer operation.By reducing the risk of unauthorized operation and improving the security of a computer system, the operability of the computer system is improved, (for example, by assisting the user to provide appropriate input when operating the device / interacting with the device and reducing user errors), the user-device interface is made more efficient, and in addition, by enabling the user to use the computer system more quickly and efficiently, the power consumption is reduced and the battery life of the device is improved.

[0204] In some embodiments, while the computer system is communicating with (e.g., while connected to) an external vehicle unit (e.g., 700), and while the computer system (e.g., 600) is in a locked state (e.g., 760) (e.g., a state in which one or more functions of the computer system that are available while in an unlocked state are unavailable), the computer system receives a second set of one or more inputs (e.g., 750a). In some embodiments, in response to the second set of one or more inputs (e.g., 750a), the computer system transitions the computer system (e.g., 600) to an unlocked state (e.g., 602) (e.g., a state in which one or more functions of the computer system that were unavailable while in the locked state are available), and permits the external vehicle head unit (e.g., 700) to request the execution of a transfer operation from a first account (e.g., as well as from other accounts accessible from and / or stored on the computer system). In some embodiments, permitting is done simultaneously (e.g., as a result) as part of transitioning the computer system to an unlocked state. By permitting the external vehicle head unit to request the execution of a transfer operation based on a user input that also unlocks the computer system, the number of inputs required to execute a set of operations is reduced, and since unlocking the computer system correlates with the intended use of the system, the risk of unintended operations of the computer system is also reduced. By reducing the number of inputs required to execute a set of operations and reducing the risk of unintended operation inputs, the operability of the device is improved, (e.g., by assisting the user to provide appropriate inputs when operating / interacting with the device and reducing user errors), the user-device interface is made more efficient, and in addition, by enabling the user to use the device more quickly and efficiently, the power consumption is reduced and the battery life of the device is improved.By allowing an external automotive head unit to request execution of a transfer operation based on user input that also unlocks a computer system, an option is provided to the user to link the unit's permission with another permission function, thereby improving security. By improving the security of the computer system, the operability of the computer system is enhanced, (e.g., by assisting the user to provide appropriate input when operating the device / interacting with the device and reducing user errors), making the user-device interface more efficient, and in addition, reducing power consumption and improving the battery life of the device by enabling the user to use the computer system more quickly and efficiently.

[0205] In some embodiments, before receiving the first data (e.g., data associated with inputs 752g, 752h, 752j, or 752k), the computer system transmits to the automotive head unit fifth data including one or more user interface elements (e.g., 718, 738) that will be displayed by the automotive head unit. In some embodiments, the one or more user interface elements include one or more elements associated with an application (e.g., an identifier of the application) and / or associated with a first account (e.g., an identifier of the first account). By transmitting data including one or more user interface elements that will be displayed by the automotive head unit, visual feedback regarding the computer system and its connection to the head unit is provided to the user. By providing improved visual feedback to the user, the operability of the computer system is enhanced, (e.g., by assisting the user to provide appropriate input when operating the device / interacting with the device and reducing user errors), making the user-device interface more efficient, and in addition, reducing power consumption and improving the battery life of the computer system by enabling the user to use the computer system more quickly and efficiently.

[0206] In some embodiments, a computer system (e.g., 600) is a smartphone (e.g., a mobile computing device configured to make and receive phone calls via a cellular network) that includes a hardware security element (e.g., a chip that stores information representing an account that is not directly accessible to the computer system's operating system or installed applications, such as account-related information like a device-specific account number provided by the issuer of the account (e.g., different from the account number)). In some embodiments, the security element does not store or have access to a primary account number. In some embodiments, the security element provides an encrypted version of a device-specific account number (e.g., a version specific to a given transaction) that is decrypted by the issuer of the account to identify the account as part of a transfer operation. In some embodiments, information identifying a first account is stored in the hardware security element.

[0207] In some embodiments, while a computer system (e.g., 600) is communicating with a second external vehicle head unit (e.g., 700) and a second external receiving device that includes one or more input components different from the external vehicle head unit (e.g., 700), the computer system receives (808) sixth data corresponding to an input (e.g., 752g, 752h, 752j, 752k) received by one or more input components of the second external vehicle head unit in response to a request to perform a third transfer operation from a first account to a fifth account (e.g., an account associated with a supplier) using an application (e.g., a digital in-store application, a digital wallet application, an e-commerce application, an application different from the first or second application, the same application as the first and / or second application) from the second external vehicle head unit. In some embodiments, while a computer system (e.g., 600) is communicating with a second external vehicle head unit (e.g., 700) and a second external receiving device that includes one or more input components, the computer system initiates (810) a process (e.g., a process that can request one or more additional inputs (e.g., inputs on the computer system to fully complete)) to perform the third transfer operation using an application on the computer system (e.g., 600) in response to receiving the sixth data. In some embodiments, as part of performing the third transfer operation, the computer system transmits seventh data including information identifying the first account to the second external receiving device. (e.g., an encrypted representation of an account (e.g., a device-specific account number) stored on the computer system, a representation of a payment account (e.g., credit, debit, and / or cash balance account)). In some embodiments, the first operation is performed in response to receiving the first data. In some embodiments, the second data includes information other than an account identifier (e.g., includes transaction parameters (e.g., price, quantity)).By providing the ability to request transfer operations in a computer system to different head units, additional options for operating the computer system are provided to the user. By providing additional control options and performing operations without requiring input at a specific time, the operability of the computer system is improved, (e.g., assisting the user to provide appropriate input when operating / interacting with a device and reducing user errors), making the user-device interface more efficient. In addition, by enabling the user to use the computer system more quickly and efficiently, power consumption is reduced and the battery life of the device is improved.

[0208] Note that the details of the process (e.g., FIG. 8) described above in connection with method 800 are also applicable in a similar manner to the methods described later. For example, method 800 optionally includes one or more of the characteristics of the various methods described later with reference to method 900. For example, using method 800, a process for performing a first transfer operation can be initiated (e.g., 804) when an external input device meets a set of permission criteria and provides the option to initiate a secure transaction (e.g., at 906). For the sake of brevity, these details are not repeated below.

[0209] FIG. 9 is a flowchart showing a method of providing an option to initiate a secure operation using a computer system according to some embodiments. Method 900 is executed in a computer system (e.g., 100, 300, 500, 600). Some operations of method 900 are optionally combined, the order of some operations is optionally changed, and some operations are optionally omitted.

[0210] As described below, method 900 provides an intuitive way to provide an option to initiate a secure operation using a computer system. This method reduces the cognitive burden on the user of providing an option to initiate a secure operation using a computer system, thereby creating a more efficient human-machine interface. This method also enables the user to perform secure operations using the computer system more safely and securely. In the case of battery-operated computing devices, power is conserved and the battery charging interval is increased by enabling the option to initiate a secure operation using the computer system to be provided more quickly and efficiently.

[0211] While a computer system (e.g., 600) is connected to an external input device (e.g., 700) (e.g., an automotive head unit (e.g., an integrated hardware interface for multiple entertainment and information systems in an automobile (e.g., sound, navigation) (e.g., a stereo head unit, an infotainment system))), the computer system requests a separate permission from the user (e.g., 646a, 646b, 638) when permitted from the computer system (e.g., 600). A secure transaction (e.g., a transfer of resources (e.g., credit, funds) from a first account (e.g., an account associated with a user of the computer system) to a second account (e.g., an account associated with a merchant)) (e.g., a transaction that requires additional authentication when executed on the computer system via one or more inputs received via one or more input devices of the computer system, such as entering a password, or biometric authentication such as fingerprint authentication, face authentication, iris authentication, or other biometric authentication)) is associated with a user interface (e.g., 710, 730) (e.g., an interface of a digital storefront application, a digital wallet application, an e-commerce transaction application, an interface displayed on an external input device (e.g., generated at least in part based on data from the computer system)) and receives a first request (e.g., 752d1, 752d2) (e.g., a selection of an option or variable) from the external input device that interacts with a first part of the user interface (902).

[0212] In response to receiving a first request (e.g., 752d1, 752d2) (904), and according to a determination that an external input device (e.g., 700) meets a set of permission criteria (e.g., a set of criteria that are met when the external input device is permitted by a previous user input, when the external input device is a first type of device, and / or when the external input device is not a second type of device), the computer system has the option (e.g., 718) (e.g., a selectable user interface object, a prompt (e.g., a visual prompt or an audio prompt) for using one or more input devices of the external input device (e.g., a touch-sensing surface, a microphone)) to initiate a secure transaction (906) via the external input device (e.g., 700) without requesting a separate permission from the user.

[0213] In response to receiving a first request (e.g., 752d1, 752d2) (904), and in accordance with a determination that an external input device (e.g., 700) does not meet a set of permission criteria, the computer system stops providing an option (e.g., 716 in FIG. 7E) to initiate a secure transaction without requesting a separate permission from the user (912). In some embodiments, as part of stopping providing an option to initiate a secure transaction without requesting a separate permission from the user, the computer system provides a second option to initiate a secure transaction that requests a separate permission from the user at the external input device and / or at the computer system. By providing an option to initiate a secure transaction without requesting a separate permission in response to a request at the external input device, an option is provided to the user to execute a secure transaction without requesting a separate permission and without the need to directly interact with the computer system. By providing an option to execute an operation without the need to directly interact with the computer system and reducing the number of inputs required, the ease of use of the computer can be enhanced, and by doing so, an option is also provided to the user to execute an operation using inputs on the external input device. By providing additional control options, the operability of the computer system is improved, (e.g., by assisting the user to provide appropriate inputs when operating / interacting with the device and reducing user errors), making the user-device interface more efficient, and in addition, by enabling the user to use the computer system more quickly and efficiently, power consumption is reduced and the battery life of the device is improved. By providing an option to initiate a secure transaction when the external input device meets a set of permission criteria, security is enhanced by not providing an option when the external input device does not meet the criteria.By improving the security of a computer system, the operability of the computer system is enhanced, (e.g., by assisting the user to provide appropriate input when operating / devicing interacting with a device and reducing user errors), making the user-device interface more efficient, and in addition, reducing power consumption and improving the battery life of the device by enabling the user to use the computer system more securely, quickly, and efficiently.

[0214] In some embodiments, an external input device (e.g., 700) is an external automotive head unit (e.g., an integrated hardware interface for a plurality of entertainment and information systems of an automobile (e.g., sound, navigation)) (e.g., a stereo head unit, an infotainment system). In some embodiments, a computer system (e.g., 600) is a smartphone (e.g., a mobile computing device configured to make and receive phone calls via a cellular network) that includes a hardware security element for use in secure transactions (e.g., a chip that stores account-related information (e.g., a device-specific account number different from the account number, such as provided by the issuer of the account) that is not directly accessible to the operating system of the computer system or installed applications). In some embodiments, the security element does not store or have access to a primary account number. In some embodiments, the security element provides an encrypted version of the device-specific account number (e.g., a version specific to a given transaction) that is decrypted by the issuer of the account to identify the account as part of a transfer operation.

[0215] In some embodiments, a computer system (e.g., 600) includes one or more external device communication interfaces (e.g., a communication system, a wired communication bus, a wireless communication bus, a data bus for transferring data between the computer system and one or more external devices). In some embodiments, the computer system detects a connection (e.g., 708) of the computer system to an external input device via one or more external device communication interfaces. In some embodiments, a first request (e.g., 752d1, 752d2) is received after detecting a connection of the computer system to an external input device.

[0216] In some embodiments, a computer system (e.g., 600) communicates with one or more hardware input devices (e.g., the touch-sensitive display of 600) (e.g., a touch-sensitive surface (e.g., a touch screen), a microphone, a biometric reader (e.g., a fingerprint reader, an optical sensor and / or a depth sensor for detecting facial features)). In some embodiments, a secure transaction requests permission from a user provided via one or more hardware input devices (e.g., not an external input device) when permitted by the computer system (e.g., 600) (e.g., permission to execute a secure transaction using information (account information, information identifying an account) stored in a hardware security element (e.g., a chip that stores account information not directly accessible to the operating system of the computer system or an installed application)). In some embodiments, a computer receives a request at the computer system that executes the secure transaction. In some embodiments, in accordance with a determination that permission has been provided (e.g., provided before receiving the first request, provided after receiving the first request) via one or more hardware input devices after receiving the first request, the computer system executes the secure transaction. By requesting permission to execute a secure transaction, security is improved by reducing the risk of unauthorized requests. By improving the security of the computer system, the operability of the computer system is improved, the user-device interface is made more efficient (e.g., by assisting the user to provide appropriate input when operating / interacting with the device and reducing user errors), and in addition, the power consumption is reduced and the battery life of the device is improved by enabling the user to use the computer system more securely, quickly, and efficiently.

[0217] In some embodiments, one or more hardware input devices include a biometric reader (e.g., 646a, 646b) (e.g., a fingerprint reader, an optical sensor and / or a depth sensor for detecting facial features), and permission from a user provided via the one or more hardware input devices is a biometric permission (e.g., indicated by 628, 630) (e.g., a permitted fingerprint scan or a permitted face scan) received via the biometric reader (e.g., 646a, 646b) (e.g., permission to execute a secure transaction using information (account information, information identifying an account) stored from a hardware security element (e.g., a chip that stores account information not directly accessible to the operating system of a computer system or an installed application)). By requiring permission via a biometric reader, security is improved by reducing the risk of unauthorized requests. By improving the security of the computer system, the operability of the computer system is improved, (e.g., by assisting the user to provide appropriate input when operating / interacting with the device and reducing user errors), making the user-device interface more efficient, and in addition, reducing power consumption and improving the battery life of the device by enabling the user to use the computer system more securely, quickly, and efficiently.

[0218] In some embodiments, after providing an option (e.g., 718) to initiate a secure transaction without requiring separate permission from the user, a request (e.g., 752g, 752h) (e.g., an input, a selection of a payment-selectable user interface object displayed on the display of the external input device, an audio command received at the external input device) to proceed with the secure transaction is received (908) from an external input device (e.g., 700). In some embodiments, as part of providing the option, the computer system transmits to the external input device data including one or more user interface elements to be displayed by the external input device. In some embodiments, in response to receiving a request to proceed with the secure transaction from an external input device (e.g., 700), the computer system executes a secure transaction including securely transmitting to an external receiving device (e.g., a transaction management server, a payment terminal) first data (e.g., an encrypted representation of an account (e.g., a device-specific account number) stored on the computer system, a representation of a payment account (e.g., a credit, debit, and / or cash balance account)) including information identifying a first account (e.g., "Jane's account" as indicated by 612, 712, "Jane's card" as indicated by 734) for use in the secure transaction. In some embodiments, the second data includes information other than the account identifier (e.g., transaction parameters (e.g., price, quantity)). By executing the secure transaction based on a request from the external input device, an option to perform an operation using the input at the external input device is provided to the user.By providing additional control options, improve the operability of the computer system, (e.g., assist the user in providing appropriate input when operating / devicing interacting with the device and reduce user errors), make the user-device interface more efficient, and in addition, reduce power consumption and improve the battery life of the device by enabling the user to use the computer system more quickly and efficiently.

[0219] In some embodiments, a computer system (e.g., 600) communicates with (e.g., includes) a display generation component (e.g., a display (e.g., an integrated touch screen display)). In some embodiments, performing a secure transaction (e.g., including securely transmitting first data including information identifying a first account to an external receiving device) occurs while the display generation component is in a locked state (e.g., 670) (e.g., a state in which one or more functions of the display (e.g., display function, input function) that are available in an unlocked state are disabled / unavailable). By performing a secure transaction while the display generation component communicating with the computer system is in a locked state, an option is provided to the user to perform the transaction without the need to interact with (e.g., view or provide input to the component) the display generation component. By providing additional control options, the operability of the computer system is improved, the user-device interface is made more efficient (e.g., by assisting the user to provide appropriate input when operating / interacting with the device and reducing user errors), and in addition, the power consumption is reduced and the battery life of the device is improved by enabling the user to use the computer system more quickly and efficiently. Also, by performing a secure transaction while the display generation component communicating with the computer system is in a locked state, security is enhanced by enabling the computer system to remain in a locked state while still permitting interaction via an external input device. By improving the security of the computer system, the operability of the computer system is improved, the user-device interface is made more efficient (e.g., by assisting the user to provide appropriate input when operating / interacting with the device and reducing user errors), and in addition, the power consumption is reduced and the battery life of the device is improved by enabling the user to use the computer system more securely, quickly, and efficiently.

[0220] In some embodiments, the secure transaction is executed using a first application (e.g., the application corresponding to 604a, 604b) on a computer system (e.g., 600). In some embodiments, the user interface (e.g., 720, 760) is an interface displayed on an external input device (e.g., 700). In some embodiments, the user interface (e.g., 720, 760) is arranged according to a first interface layout template (e.g., a scheme for arranging graphic elements and / or content of the interface), and information provided by the first application (e.g., the application corresponding to 604a, 604b) (e.g., 722, 762) (e.g., an identifier of the first application (e.g., text and / or graphic), a parameter affecting the execution of the secure transaction (e.g., the amount of credit or currency to be transferred, the service or goods to be purchased), an identifier of the account used in the secure transaction). In some embodiments, the computer system receives a second request (e.g., 752d1, 752d2) from an external input device (e.g., 700) that interacts with a first portion of a second user interface (e.g., 720, 760) (e.g., an interface that is the same as the user interface, an interface different from the user interface) associated with a second secure transaction that is executed using a second application (e.g., the application corresponding to 604a, 604b) on the computer system (e.g., 600) and that requests a separate permission from the user when displayed on the external input device (e.g., 700) and permitted by the computer system (e.g., 600). In some embodiments, the second application (e.g., the application corresponding to 604a, 604b) is different from the first application.In some embodiments, the second user interface (e.g., 720, 760) is arranged according to a first interface layout template and includes information (e.g., 722, 762) provided by a second application (e.g., the application corresponding to 604a, 604b) (e.g., an identifier of the second application (e.g., text and / or graphic), a parameter affecting the execution of a secure transaction (e.g., the amount of credit or currency to be transferred, the service or goods to be purchased), an identifier of an account used within the second secure transaction). By arranging interfaces corresponding to different applications for performing different secure transactions according to the same interface layout, improved visual feedback is provided to the user to consistently notify the user about the aspects of the secure transaction. By providing improved visual feedback to the user, the operability of the computer system is improved, (e.g., by assisting the user to provide appropriate input when operating / interacting with the device and reducing user errors) making the user-device interface more efficient, and in addition, reducing power consumption and improving the battery life of the computer system by enabling the user to use the computer system more quickly and efficiently.

[0221] In some embodiments, a set of permission criteria is satisfied when a computer system receives a first set of one or more inputs (e.g., 750a) (e.g., selection of an option within a peripheral device management interface, a set of inputs received at an external input device, a set of inputs received at the computer system) before the computer system receives a first request (e.g., 752d1, 752d2) (e.g., and while not detecting movement of a motor vehicle connected to an external input device). In some embodiments, in response to the first set of one or more inputs (e.g., 750a), the computer system permits the connection of an external input device (e.g., 700) to the computer system (e.g., 600) while the computer system is in a locked state (e.g., 670) (e.g., a state in which one or more functions of the computer system that are available while in an unlocked state are unavailable). Permitting the connection of an external input device to the computer system while the computer system is in a locked state provides additional control options to the user and reduces the need for permitted inputs at the time a secure transaction is requested. By providing additional control options, the operability of the computer system is improved, (e.g., assisting the user to provide appropriate inputs when operating / devicing interacting with the device and reducing user errors), making the user-device interface more efficient, and in addition, reducing power usage and improving the battery life of the device by enabling the user to use the computer system more quickly and efficiently. Linking the permission function to satisfy the permission criteria based on previous inputs that also permitted the connection of an external input device to the computer system while in a locked state enhances security by reducing the risk of unintended permissions.By improving the security of a computer system, the operability of the computer system is enhanced, (for example, by assisting the user to provide appropriate input when operating / devicing interacting with a device and reducing user errors), making the user-device interface more efficient, and in addition, reducing power consumption and improving the battery life of the device by enabling the user to use the computer system more securely, quickly, and efficiently.

[0222] In some embodiments, an external input device (e.g., 700) is configured (e.g., set) based on a second set of one or more inputs (e.g., 750b, 750c1, 750c2) (e.g., a second option selection within a peripheral device management interface, a set of inputs received at the external input device, a set of inputs received at a computer system) received after receiving a first set of one or more inputs (e.g., 750a) to a state (e.g., a duration for which the external input device meets a set of permission criteria (e.g., permanent (e.g., until revoked), temporary (e.g., over a transient duration (e.g., one day, one week), or over a preset number of connection events (e.g., one connection event, five connection events))) that meets the set of permission criteria. By establishing a state of the external input device that affects satisfaction of the permission criteria, additional control options are provided to the user for precisely controlling the relationship between the computer system and the external input device. By providing additional control options, the operability of the computer system is improved, (e.g., assisting the user to provide appropriate inputs when operating / devicing interacting with the device and reducing user errors), making the user-device interface more efficient, and in addition, reducing power usage and improving the battery life of the device by enabling the user to use the computer system more quickly and efficiently. By satisfying the permission criteria based on previous inputs, the user is provided with an opportunity to provide permission outside the context of executing a particular secure transaction, thereby enhancing security and reducing the risk of unintended permissions. By improving the security of the computer system, the operability of the computer system is improved, (e.g., assisting the user to provide appropriate inputs when operating / devicing interacting with the device and reducing user errors), making the user-device interface more efficient, and in addition, reducing power usage and improving the battery life of the device by enabling the user to use the computer system more securely, quickly, and efficiently.

[0223] In some embodiments, an external input device (e.g., 700) meets a set of permission criteria based on being in a long-term (e.g., indefinite until revoked) permission state. In some embodiments, a computer system (e.g., 600) receives a first set of one or more inputs (e.g., 750a, 750b, 752c1) during a connection session (e.g., a session that starts with a connection of the computer system to the external input device and is transmitted when that connection is terminated) that is also a connection session in which a first request (e.g., 752d1, 752d2) to the external input device was received, or during a previous connection session different from the connection session in which a first request (e.g., 752d1, 752d2) to the external input device was received.

[0224] In some embodiments, an external input device (e.g., 700) meets a set of permission criteria based on being in a short-term (e.g., temporary or transient duration (e.g., one day, one week) or expiring without requiring further user input over a preset number of connection events (e.g., one connection event, five connection events)) permission state. In some embodiments, a computer system receives a first set of one or more inputs (e.g., 750a, 750b, 750c2) during a connection session (e.g., a session that starts with a connection of the computer system to the external input device and is transmitted when that connection is terminated) that is also a connection session in which a first request (e.g., 752d1, 752d2) to the external input device was received. In some embodiments, when the state is a temporary permission state, no (e.g., cannot be received) set of one or more inputs was received during a previous connection session different from the connection session in which a first request was received.

[0225] In some embodiments, an external input device (e.g., 700) satisfies a set of permission criteria based on inputs (e.g., 750a, 750b, 750c1, 750c2) (e.g., selection of options within a peripheral device management interface) received before receiving a first request (e.g., before connecting to the external input device), and the computer system permits (e.g., pre-permits) the external input device (e.g., 700) to provide a request to initiate one or more secure transactions that request a separate permission from the user if permitted by the computer system (e.g., 600). In some embodiments, the input that permits (e.g., pre-permits) the external input device to provide a request to initiate one or more secure transactions that request a separate permission from the user if permitted by the computer system is different from the input that permits the external input device to connect to the computer system while the computer system is in a locked state (e.g., a state in which one or more functions of the computer system that are available while unlocked are unavailable). By permitting the external input device based on previous inputs, it becomes possible for the user to better control the relationship between the computer system and the external input device. By providing additional control options, the operability of the computer system is improved, the user-device interface is made more efficient (e.g., by assisting the user to provide appropriate inputs when operating / devicing interacting with the device and reducing user errors), and in addition, the power consumption is reduced and the battery life of the device is improved by enabling the user to use the computer system more quickly and efficiently. By satisfying the permission criteria based on previous and explicit inputs that permit the secure transaction, the risk of unintended permissions is reduced and security is enhanced.By improving the security of a computer system, the operability of the computer system is enhanced, (e.g., by assisting the user to provide appropriate input when operating / devicing interacting with a device and reducing user errors), making the user-device interface more efficient, and in addition, reducing power consumption and improving the battery life of the device by enabling the user to use the computer system more securely, quickly, and efficiently.

[0226] In some embodiments, an external input device (e.g., 700) is permitted to provide a request to initiate one or more secure transactions that, based on input received (e.g., 750a) while the external input device (e.g., 700) is connected (e.g., while connected in the same connection session as when a first request was received), such as acceptance of a prompt to provide permission, meets a set of permission criteria, and the computer system requests a separate permission from the user when permitted by the computer system (e.g., 600). Permitting the external input device based on input received while it is connected enables the user to better control the relationship between the computer system and the external input device and also reduces the risk of inadvertently permitting an incorrect device. By providing additional control options and reducing the risk of errors, the operability of the computer system is enhanced, (e.g., by assisting the user to provide appropriate input when operating / devicing interacting with a device and reducing user errors), making the user-device interface more efficient, and in addition, reducing power consumption and improving the battery life of the device by enabling the user to use the computer system more quickly and efficiently.

[0227] In some embodiments, an external input device (e.g., 700) meets a set of permission criteria based on being identified as an external input device (e.g., 700) that is a first type of device (e.g., a pre - permitted type of device (e.g., a device from a particular manufacturer), a type of device having particular hardware (e.g., secure hardware), a type of device having particular software (e.g., secure software)). In some embodiments, a second type of external input device (e.g., not of the first type) does not meet the set of permission criteria. By permitting an external input device based on the device being a first type of device, the risk that a device without the required characteristics is permitted is reduced, thereby enhancing security and also reducing the need for explicit input to permit a first type of device. By enhancing security and reducing the number of inputs required to perform an operation, the operability of the computer system is improved, (e.g., by assisting the user to provide appropriate input when operating / interacting with the device and reducing user errors) making the user - device interface more efficient, and in addition, reducing power usage and improving the battery life of the device by enabling the user to use the computer system more quickly and efficiently.

[0228] In some embodiments, an external input device (e.g., 700) (e.g., an automotive head unit (e.g., an integrated hardware interface for multiple entertainment and information systems in a vehicle (e.g., sound, navigation) (e.g., a stereo head unit, an infotainment system))) meets a set of permission criteria based on being connected to a vehicle (e.g., an automobile, a motorcycle) identified as having authorized authentication hardware (e.g., an authenticated identification chip). By permitting an external input device based on it being connected to a vehicle identified as having authorized authentication hardware, security is enhanced and the need for explicit input to permit devices connected to such a vehicle is reduced. By enhancing security and reducing the number of inputs required to perform an operation, the operability of a computer system is improved, (e.g., by assisting the user to provide appropriate input when operating / devicing interacting with the device and reducing user errors), the user-device interface is made more efficient, and in addition, by enabling the user to use the computer system more quickly and efficiently, power consumption is reduced and the battery life of the device is improved.

[0229] Note that the details of the processes (e.g., FIG. 9) described above in connection with method 900 are also applicable in a similar manner to the methods described later. For example, method 900 optionally includes one or more of the characteristics of the various methods described above with reference to method 800. For example, using method 800, a process of performing a first transfer operation can be started (e.g., 804) when an external input device meets a set of permission criteria and provides the option to initiate a secure transaction (e.g., at 906). For the sake of brevity, these details are not repeated below.

[0230] The foregoing has been described with reference to specific embodiments for purposes of explanation. However, the above exemplary considerations are not intended to be exhaustive or to limit the invention to the precise forms disclosed. Many modifications and variations are possible in light of the above teachings. Embodiments have been selected and described in order to best explain the principles of the technology and their practical application, thereby enabling others skilled in the art to best utilize the technology and various embodiments with various modifications as are suited to the particular use contemplated.

[0231] Although the present disclosure and examples have been fully described with reference to the accompanying drawings, it should be noted that various changes and modifications will become apparent to those skilled in the art. Such changes and modifications are to be understood as being included within the scope of the present disclosure and examples as defined by the claims.

[0232] As described above, one aspect of the technology is to collect and use data available from various sources to improve the management and security of operations (e.g., transactions) performed on various devices. The present disclosure contemplates that in some cases, this collected data may include personal information data that uniquely identifies a particular person or personal information data that can be used to contact or locate a particular person. Such personal information data can include demographic data, location-based data, phone numbers, email addresses, Twitter IDs, home addresses, data or records related to a user's health or fitness level (e.g., vital sign measurements, medication information, exercise information), birthdays, or any other identifying or personal information.

[0233] The present disclosure recognizes that the use of such personal information data in the present technology can be a use that benefits the user. For example, the personal information data can be used to provide permission for an electronic device to perform a secure operation (e.g., a transaction) based on the provided personal information. Thus, the use of such personal information data enables the user to have calculated control and / or enhanced security regarding secure operations performed via the electronic device. Further, other uses of personal information data that benefit the user are also contemplated by the present disclosure. For example, health data and fitness data can be used to provide insights regarding the user's overall well-being, or can also be used as positive feedback to individuals using technologies that pursue wellness goals.

[0234] The present disclosure contemplates that entities involved in the collection, analysis, disclosure, transmission, storage, or other use of such personal information data will comply with firm privacy policies and / or privacy practices. Specifically, such entities should implement and consistently use privacy policies and practices that meet or exceed industry or government requirements for securely maintaining personal information data as confidential. Such policies should be readily accessible to users and updated as the collection and / or use of data changes. Personal information from users should be collected for the legitimate and proper use of the entity and should not be shared or sold except for those legitimate uses. Further, such collection / sharing should be carried out after informing the user and obtaining consent. Moreover, such entities should consider taking all necessary measures to protect and secure access to such personal information data and ensure that others with access rights to personal information data faithfully adhere to their privacy policies and procedures. Additionally, such entities can subject themselves to evaluation by third parties to demonstrate their compliance with widely accepted privacy policies and practices. In addition, the policies and practices should be adapted to the specific types of personal information data collected and / or accessed and should comply with applicable laws and regulations, including jurisdiction-specific considerations. For example, in the United States, the collection or access to certain health data may be governed by federal and / or state laws such as the Health Insurance Portability and Accountability Act (HIPAA), while health data in other countries may be subject to other regulations and policies and should be addressed accordingly. Therefore, different privacy practices should be maintained for different types of personal data in each country.

[0235] Notwithstanding the foregoing, the present disclosure also contemplates embodiments that selectively block a user from using or accessing personal information data. That is, the present disclosure is intended to provide hardware elements and / or software elements to prevent or block access to such personal information data. For example, when performing a secure operation (e.g., a payment transaction), the technology can be configured to allow a user to select an “opt-in” or “opt-out” of participating in the collection of personal information data either during or after registration for the service. In another example, a user can choose to provide other information (e.g., a password, etc.) to perform one or more secure operations using an electronic device. In yet another example, a user can choose to limit the length of time that collected data (e.g., biometric data) is maintained or to completely prohibit actions based on the collected data. In addition to providing “opt-in” and “opt-out” options, the present disclosure is intended to provide notice regarding access to or use of personal information. For example, a user may be notified when downloading an app that will access the user's personal information data and then again just prior to the personal information data being accessed by the app.

[0236] Furthermore, it is an intention of the present disclosure that personal information data should be managed and processed in a way that minimizes the risk of unintentional or unauthorized access or use. The risk can be minimized by restricting the collection of data and deleting it when it is no longer needed. Additionally, and when applicable in certain health-related applications, anonymization of data can be used to protect the privacy of the user. Anonymization can be facilitated, when appropriate, by removing certain identifiers (e.g., date of birth, etc.), controlling the amount or specificity of the data stored (e.g., collecting location data at the city level rather than the address level), controlling how the data is stored (e.g., aggregating the data across all users), and / or by other means.

[0237] Therefore, while the present disclosure broadly covers the use of personal information data for implementing one or more of the various disclosed embodiments, it is contemplated that the various embodiments can also be implemented without the need to access such personal information data. That is, the various embodiments of the present technology are not rendered inoperable by the absence of all or a portion of such personal information data. For example, secure operation can be performed based on non-personal information data such as content requested by a device associated with the user, or a minimal amount of personal information, other non-personal information available to the permission system, or publicly available information.

Claims

1. A method, A computer system, in which the computer system communicates with an external vehicle head unit including one or more input components, and the computer system communicates with an external receiving device, Receiving first data corresponding to an input received by the one or more input components of the external vehicle head unit in response to a request to execute a first transfer operation from a first account to a second account using an application on the computer system associated with the first account; In response to receiving the first data, starting a process of executing the first transfer operation using the application on the computer system, wherein executing the first transfer operation includes transmitting second data including information identifying the first account to the external receiving device; A method comprising the above.

2. The method according to claim 1, wherein the application was configured to execute a transfer operation from the first account before receiving the first data.

3. A second application different from the first application is installed on the computer system, According to the second application being configured to execute a transfer operation from a third account, the second application is configured to execute a transfer operation in response to a request to execute a transfer operation from the third account received from the external vehicle head unit; According to the second application not being configured to execute a transfer operation from a third account, the second application is not configured to execute a transfer operation in response to a request to execute a transfer operation from the third account received from the external vehicle head unit; The method according to claim 1 or 2.

4. The second application is configured to execute a transfer operation from the third account, and the method is, Receiving third data corresponding to an input received by the one or more input components of the external automotive head unit in response to a request to perform a second transfer operation from the third account to the fourth account using the second application from the external automotive head unit; In response to receiving the third data, starting a process of performing the second transfer operation using the second application, the process of performing the second transfer operation including transmitting fourth data including information for identifying the third account to the external receiving device; The method according to claim 3, further comprising.

5. The method according to any one of claims 1 to 4, wherein the computer system communicates with a display generation component, and the display generation component is in a locked state while the computer system is receiving the first data.

6. The method according to any one of claims 1 to 5, wherein the external automotive head unit is permitted to request execution of a transfer operation from the first account.

7. Receiving a first set of one or more inputs before detecting the first data; In response to the first set of one or more inputs; Permitting connection of the external automotive head unit to the computer system while the computer system is in a locked state; Permitting the external automotive head unit to request execution of a transfer operation from the first account; The method according to claim 6, further comprising.

8. Receiving a second set of one or more inputs while the computer system is communicating with the external automotive unit and while the computer system is in a locked state; In response to the second set of one or more inputs; Transitioning the computer system to an unlocked state; Permitting the external automotive head unit to request execution of a transfer operation from the first account; The method according to claim 6, further comprising.

9. Before receiving the first data, transmitting fifth data including one or more user interface elements to be displayed by the automotive head unit to the automotive head unit; The method according to any one of claims 1 to 8, further comprising

10. The method according to any one of claims 1 to 9, wherein the computer system is a smartphone including a hardware security element, and the information for identifying the first account is stored in the hardware security element.

11. While the computer system is communicating with a second external vehicle head unit and a second external receiving device including one or more input components different from the external vehicle head unit, Receiving, at the one or more input components of the second external vehicle head unit, sixth data corresponding to an input received at the one or more input components of the second external vehicle head unit in response to a request to execute a third transfer operation from the first account to a fifth account using the application from the second external vehicle head unit; In response to receiving the sixth data, starting a process of executing the third transfer operation using the application on the computer system, wherein executing the third transfer operation includes transmitting seventh data including information for identifying the first account to the second external receiving device. The method according to any one of claims 1 to 10, further comprising

12. A non-transitory computer-readable storage medium storing one or more programs configured to be executed by one or more processors of a computer system, wherein the one or more programs include instructions for executing the method according to any one of claims 1 to 11.

13. A computer system, One or more processors; A memory storing one or more programs configured to be executed by the one or more processors, Comprising, wherein the one or more programs include instructions for executing the method according to any one of claims 1 to 11. Computer system.

14. Means for executing the method according to any one of claims 1 to 11, A computer system comprising.

15. A non-transitory computer-readable storage medium storing one or more programs configured to be executed by one or more processors of a computer system, wherein the computer system communicates with an external automotive head unit including one or more input components, the computer system communicates with an external receiving device, and the one or more programs are responsive to receiving, by the one or more input components of the external automotive head unit, an input corresponding to a request to perform a first transfer operation from a first account to a second account using an application on the computer system associated with the first account, to receive first data corresponding to the input, responsive to receiving the first data, to start a process of performing the first transfer operation using the application on the computer system, and performing the first transfer operation includes transmitting, to the external receiving device, second data including information identifying the first account, instructions, the non-transitory computer-readable storage medium.

16. A computer system, one or more processors, wherein the computer system communicates with an external automotive head unit including one or more input components, and the computer system communicates with an external receiving device, and one or more processors; a memory storing one or more programs configured to be executed by the one or more processors; comprising, and the one or more programs are responsive to receiving, by the one or more input components of the external automotive head unit, an input corresponding to a request to perform a first transfer operation from a first account to a second account using an application on the computer system associated with the first account, to receive first data corresponding to the input, responsive to receiving the first data, to start a process of performing the first transfer operation using the application on the computer system, and performing the first transfer operation includes transmitting, to the external receiving device, second data including information identifying the first account, instructions, the computer system.

17. A computer system that communicates with an external automotive head unit including one or more input components, and the computer system communicates with an external receiving device. Means for receiving first data corresponding to an input received by the one or more input components of the external automotive head unit in response to a request to execute a first transfer operation from a first account to a second account using an application on the computer system associated with the first account. Means for starting a process of executing the first transfer operation using the application on the computer system in response to receiving the first data, where executing the first transfer operation includes transmitting second data including information identifying the first account to the external receiving device. A computer system comprising the above.

18. A method comprising: In a computer system, Receiving a first request from the external input device that interacts with a first part of a user interface associated with a secure transaction to request a separate permission from the user when permitted by the computer system while the computer system is connected to the external input device. In response to receiving the first request, Providing an option to start a secure transaction through the external input device without requesting the separate permission from the user according to a determination that the external input device meets a set of permission criteria. Withdrawing the option to start a secure transaction without requesting the separate permission from the user according to a determination that the external input device does not meet the set of permission criteria. A method including the above.

19. The method according to claim 18, wherein the external input device is an external automotive head unit.

20. The method according to claim 18 or 19, wherein the computer system is a smartphone including a hardware security element for use in the secure transaction.

21. The computer system includes one or more external device communication interfaces, and the method further includes detecting a connection of the computer system to the external input device via the one or more external device communication interfaces, wherein the first request is received after detecting the connection of the computer system to the external input device. The method according to any one of claims 18 to 20. **Claim 22** The computer system communicates with one or more hardware input devices, wherein the secure transaction requests permission from the user provided via the one or more hardware input devices when permitted by the computer system. The method according to any one of claims 18 to 21. **Claim 23** The method according to claim 22, wherein the one or more hardware input devices include a biometric reader, and the permission from the user provided via the one or more hardware input devices is a biometric permission received via the biometric reader. **Claim 24** receiving a request to proceed with the secure transaction from the external input device after providing the option to initiate the secure transaction without requesting the separate permission from the user; and securely transmitting, to an external receiving device, first data including information identifying a first account for use in the secure transaction in response to receiving the request to proceed with the secure transaction from the external input device, the method for executing the secure transaction further comprising: The method according to any one of claims 18 to 23. **Claim 25** The computer system communicates with a display generation component, wherein the secure transaction is executed while the display generation component is in a locked state. The method according to claim 24. **Claim 26** The secure transaction is executed using a first application on the computer system, wherein the user interface is an interface displayed on the external input device. The user interface is arranged according to a first interface layout template and includes information provided by the first application. The method further includes receiving, from the external input device, a second request that interacts with a first portion of a second user interface associated with a second secure transaction that is executed using a second application on the computer system and that requests a separate permission from the user when displayed on the external input device and permitted by the computer system. The second application is different from the first application. The second user interface is arranged according to the first interface layout template and includes information provided by the second application. The method according to any one of claims 18 to 25. **Claim 27** The set of permission criteria wherein the computer system receives a first set of one or more inputs before receiving the first request, and in response to the first set of one or more inputs, the computer system permits connection of the external input device to the computer system while the computer system is in a locked state. The method according to any one of claims 18 to 26, which is satisfied when. **Claim 28** The method according to claim 27, wherein the external input device satisfies the set of permission criteria based on a state established based on a second set of one or more inputs received after receiving the first set of one or more inputs. **Claim 29** The external input device satisfies the set of permission criteria based on the state being a long-term permission state, wherein the first set of one or more inputs is received while the computer system is in the connection session that is also the connection session in which the first request was received with the external input device, or while the computer system was in a previous connection session different from the connection session in which the first request was received with the external input device. is received. The method according to claim 28. **Claim 30** The external input device satisfies the set of permission criteria based on the state being a short-term permission state, and the first set of one or more inputs while the computer system is in the connection session that is also the connection session in which the first request was received with the external input device, received The method according to claim 28. **Claim 31** Permit the external input device to provide a request to initiate one or more secure transactions that, based on input received before the external input device receives the first request, satisfy the set of permission criteria and, when permitted by the computer system, request a separate permission from the user. The method according to any one of claims 18 to 30. **Claim 32** Permit the external input device to provide a request to initiate one or more secure transactions that, based on input received while the external input device is connected, satisfy the set of permission criteria and, when permitted by the computer system, request a separate permission from the user. The method according to any one of claims 18 to 30. **Claim 33** The method according to any one of claims 18 to 30, wherein the external input device satisfies the set of permission criteria based on being identified as being a device of a first type. **Claim 34** The method according to any one of claims 18 to 30, wherein the external input device satisfies the set of permission criteria based on being connected to a vehicle identified as having authorized authentication hardware. **Claim 35** A non-transitory computer-readable storage medium storing one or more programs configured to be executed by one or more processors of a computer system, the one or more programs including instructions for performing the method according to any one of claims 18 to 34. **Claim 36** A computer system, one or more processors, and a memory storing one or more programs configured to be executed by the one or more processors, wherein the one or more programs include instructions for performing the method according to any one of claims 18 to 34. Computer system. **Claim 37** Means for performing the method according to any one of claims 18 to 34, A computer system comprising. **Claim 38** A non-transitory computer-readable storage medium storing one or more programs configured to be executed by one or more processors of a computer system, wherein the one or more programs are While the computer system is connected to an external input device, when permitted from the computer system, receive a first request from the external input device that interacts with a first portion of a user interface associated with a secure transaction that requests a separate permission from the user In response to receiving the first request Provide an option to initiate a secure transaction via the external input device without requesting the separate permission from the user, according to a determination that the external input device meets a set of permission criteria Cease to provide the option to initiate a secure transaction without requesting the separate permission from the user, according to a determination that the external input device does not meet the set of permission criteria A non-transitory computer-readable storage medium containing instructions

39. A computer system comprising One or more processors and A memory storing one or more programs configured to be executed by the one or more processors, wherein the one or more programs are While the computer system is connected to an external input device, when permitted from the computer system, receive a first request from the external input device that interacts with a first portion of a user interface associated with a secure transaction that requests a separate permission from the user In response to receiving the first request Provide an option to initiate a secure transaction via the external input device without requesting the separate permission from the user, according to a determination that the external input device meets a set of permission criteria Cease to provide the option to initiate a secure transaction without requesting the separate permission from the user, according to a determination that the external input device does not meet the set of permission criteria A computer system containing instructions

40. A computer system comprising One or more processors and One or more processors and Means for receiving a first request from the external input device that interacts with a first part of a user interface associated with a secure transaction, which requests a separate permission from the user when permitted from the computer system while the computer system is connected to the external input device; In response to receiving the first request, Providing an option to initiate a secure transaction via the external input device without requesting the separate permission from the user according to a determination that the external input device meets a set of permission criteria; Ceasing to provide the option to initiate a secure transaction without requesting the separate permission from the user according to a determination that the external input device does not meet the set of permission criteria; Means; A computer system comprising.

Citation Information

Patent Citations

  • System for providing internet access to automotive vehicle having multimedia device

    JP2013054743A

  • Certification by a secondary approver

    JP2015503135A

  • Establishing a wireless display session between a computing device and a vehicle head unit

    JP2016503601A

  • Efficient head unit communication integration

    JP2016506671A

  • Efficient headunit communication integration

    US20150230277A1