Software pin entry
Abstract
A mobile device can send an identification code of a card reader coupled to the mobile device to a server system. In response to sending the identification code, the mobile device can receive a cryptographic key from the server system. The mobile device can receive a passcode via a user interface of the mobile device. The mobile device can then utilize the cryptographic key from the server system to facilitate secure communication between the card reader and the mobile device. Secure communication, for example, includes encrypting the passcode using the cryptographic key before sending the encrypted passcode from the mobile device to the card reader.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system comprising:
a merchant point-of-sale (POS) application executable by one or more processors of a merchant device to:
display a user interface for personal identification number (PIN) entry,
receive input on the user interface representing a PIN,
encrypt the PIN using a copy of a first cryptographic key stored on the merchant device, wherein the first cryptographic key is a symmetric key shared between a card reader and the merchant POS application,
transmit the encrypted PIN to the card reader,
receive an encrypted message from the card reader, and
transmit the encrypted message to a payment processing server; and
the card reader configured to:
receive the encrypted PIN from the merchant device,
decrypt the encrypted PIN using a copy of the first cryptographic key stored on the card reader,
transmit the PIN to a card coupled to the card reader,
receive an approval of the PIN from the card,
encrypt a message for the merchant device using a second cryptographic key stored on the card reader to generate the encrypted message, and
transmit the encrypted message to the merchant device in response to receiving the approval.
2 . The system of claim 1 , further comprising:
a payment processing application executable by one or more processors of the payment processing server to:
receive the encrypted message from the merchant device; and
decrypt the encrypted message with a copy of the second cryptographic key.
3 . The system of claim 2 , wherein the merchant POS application is executable by the one or more processors to send an identification code of the card reader to the payment processing server; and wherein the payment processing application is configured to obtain the copy of the second cryptographic key based on the identification code.
4 . The system of claim 1 , wherein the merchant POS application executable by the one or more processors to further encrypt the encrypted message from the card reader using a public key corresponding to the payment processing server.
5 . The system of claim 4 , further comprising:
a payment processing application executable by one or more processors of the payment processing server to:
receive the encrypted message from the merchant device; and
decrypt the encrypted message with a copy of the second cryptographic key and a private key corresponding to the payment processing server and the public key.
6 . The system of claim 1 , further comprising:
a payment processing application executable by one or more processors of the payment processing server to:
process the encrypted message for a payment transaction; and
relay the processed message to a card issuer associated with the card for approval of the payment transaction.
7 . A method comprising:
sending, by a mobile device to a server system, an identification code of a card reader coupled to the mobile device; in response to sending the identification code, receiving, by the mobile device, a cryptographic key from the server system; receiving a passcode via a user interface of the mobile device; and utilizing the cryptographic key from the server system to facilitate secure communication between the card reader and the mobile device, wherein said utilizing includes encrypting the passcode using the cryptographic key before sending the encrypted passcode from the mobile device to the card reader.
8 . The method of claim 7 , wherein receiving the passcode includes:
receiving user input on a touchscreen display of the mobile device; and determining the passcode based on the user input.
9 . The method of claim 7 , wherein the secure communication between the card reader and the mobile device is performed through an audio jack of the mobile device.
10 . The method of claim 7 , wherein said utilizing the cryptographic key includes:
receiving, at the mobile device, encrypted data from the card reader; and decrypting, by the mobile device and using the cryptographic key, the encrypted data received from the card reader.
11 . The method of claim 10 , further comprising processing the decrypted data to authenticate a payment transaction.
12 . The method of claim 11 , wherein receiving the passcode is in response to initializing the payment transaction and wherein the decrypted data includes an acknowledgement of a passcode match corresponding to the passcode.
13 . The method of claim 11 , wherein the encrypted data includes an authentication code generated by a card accessed by the card reader; and wherein processing the decrypted data includes sending the authentication code to a payment service computer system to authenticate the payment transaction.
14 . The method of claim 7 , further comprising: prior to said utilizing the cryptographic key, verifying a certificate of a card reader with the server system.
15 . The method of claim 14 , wherein verifying the certificate includes:
receiving, at the mobile device, the certificate from the card reader; sending the certificate from the mobile device to the server system to verify a signature of the certificate; and receiving, at the mobile device, a verification of the certificate from the server system to authenticate the card reader.
16 . The method of claim 7 , wherein said sending the identification code includes:
encrypting the identification code using a public key from the server system; and sending the encrypted identification code to the server system.
17 . A system comprising:
a merchant point-of-sale (POS) application executable by one or more processors of a merchant computing device to:
send an identification code of a card reader coupled to the merchant computing device to a server computer system;
in response to sending the identification code, receive a cryptographic key from the server computer system;
receive a passcode via a user interface of the merchant computing device; and
utilize the cryptographic key from the server computer system to facilitate secure communication between the card reader and the merchant computing device, wherein utilizing of the cryptographic key includes encrypting the passcode using the cryptographic key before sending the encrypted passcode from the merchant computing device to the card reader.
18 . The system of claim 17 , wherein the secure communication between the card reader and the merchant computing device is performed through an audio jack of the merchant computing device.
19 . The system of claim 17 , wherein the merchant POS application is executable to utilize the cryptographic key by at least:
receiving, at the merchant computing device, encrypted data from the card reader; and decrypting, by the merchant computing device and using the cryptographic key, the encrypted data received from the card reader.
20 . The system of claim 17 , wherein the merchant POS application is executable to verify, prior to utilizing the cryptographic key, a certificate of a card reader with the server computer system; and wherein the merchant POS application is executable to verify the certificate by at least:
receiving, at the merchant computing device, the certificate from the card reader; sending the certificate from the merchant computing device to the server computer system to verify a signature of the certificate; and receiving, at the merchant computing device, a verification of the certificate from the server computer system to authenticate the card reader.
21 . The system of claim 17 , wherein the merchant POS application is executable to send the identification code by at least:
encrypting the identification code using a public key from the server computer system; and sending the encrypted identification code to the server computer system.Join the waitlist — get patent alerts
Track US2016275515A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.