Securing Personal Identification Numbers For Mobile Payment Applications By Combining With Random Components
Abstract
Systems and methods can secure personal identification numbers associated with secure elements within mobile devices. A host application of the mobile device can receive a personal identification number (PIN) or user PIN from a user. The application can generate one or more random PIN components. The application can compute a PIN for the secure element based upon the user PIN and each of the one or more random components. The SE can be configured using the PIN computed for the secure element. Each of the one or more random components may be stored in one or more distinct, diverse locations. In addition to entering the correct user PIN, each of the one or more random components must be retrieved from the diverse locations in order to reconstruct the PIN for the secure element whenever performing a transaction using the secure element.
Claims
exact text as granted — not AI-modified1 . A computer-implemented method to secure personal identification numbers, the method comprising:
generating, by a mobile computing device, two or more random PIN components; determining, by the mobile computing device, a first secure memory PIN based at least in part on a first user PIN input via the mobile computing device and the two or more generated random PIN components; configuring, by the mobile computing device, the secure memory associated with the mobile computing device using the determined first secure memory PIN; receiving, by the mobile computing device, an input of a second user PIN and a request to access the secure memory associated with the mobile computing device; determining, by the mobile computing device, a second secure memory PIN based at least in part on the second user PIN and the two or more random PIN components; determining, by the mobile computing device, that the determined first secure memory PIN and the determined second secure memory PIN match; and providing, by the mobile computing device, access to the secure memory in response to determining that the determined first secure memory PIN and the determined second secure memory PIN match.
2 . The computer-implemented method of claim 1 , wherein the two or more random PIN components are stored at various diverse locations, and further comprising:
retrieving, by the mobile computing device, the two or more generated random PIN components from the various diverse locations where the two or more generated random PIN components were stored.
3 . The computer-implemented method of claim 1 , wherein one or more of the two or more generated random PIN components is generated by a random number generator.
4 . The computer-implemented method of claim 2 , wherein at least one of the various distinct locations comprises a second computing device accessible through a network by the mobile computing device.
5 . The computer-implemented method of claim 4 , wherein the second computing device makes the at least one of the two or more random PIN components accessible for deletion by the user via the mobile computing device.
6 . The computer-implemented method of claim 4 , further comprising, in response to an attempt to access the at least one PIN component stored on the second computing device, generating, by the second computing device, a use audit trail entry, wherein the use audit trail comprises a catalogue of recorded attempts to access the at least one of the two or more random PIN components stored on the second computing device.
7 . The computer-implemented method of claim 1 , wherein determining the secure memory PIN further comprises increasing the entropy over the user PIN.
8 . The computer-implemented method of claim 1 , wherein determining the secure memory PIN further comprises applying a numerical space reduction functionality, wherein the numerical space reduction functionality reduces the range of outputs of the derivation function to match the numerical space allowance for an acceptable secure memory PIN.
9 . The computer-implemented method of claim 1 , further comprising, in response to receiving a notification of a factory reset of the mobile computing device, deleting, by the mobile computing device, one or more of two or more random PIN components stored by the mobile computing device.
10 . The computer-implemented method of claim 1 , wherein if the user PIN is not received from the user of the mobile computing device, the mobile computing device denies access to the secure memory.
11 . A computer program product, comprising:
a non-transitory computer-readable medium having computer-readable program instructions embodied therein that when executed by a computing device cause the computing device to secure personal identification numbers, the computer-readable instructions comprising:
computer-readable program instructions to generate two or more random user personal identification number (PIN) components;
computer-readable program instructions to determine a first secure memory PIN based at least in part on a user PIN and the at least one random PIN component; and
computer-readable program instructions to configure a secure memory using the determined first secure memory PIN;
computer-readable program instructions to receive an input of a second user PIN and a request to access the secure memory;
computer-readable program instructions to determine a second secure memory PIN based at least in part on the second user PIN and the two or more random PIN components;
computer-readable program instructions to determine that the determined first secure memory PIN and the determined second secure memory PIN match; and
computer-readable program instructions to provide access to the secure memory in response to determining that the determined first secure memory PIN and the determined second secure memory PIN match.
12 . The computer program product of claim 11 , further comprising computer-readable program instructions to receive an input of the user PIN.
13 . The computer program product of claim 12 , wherein if the input of the user PIN is not received, the computing device denies access to the secure memory.
14 . The computer program product of claim 11 , wherein the two or more random PIN components are stored at various diverse locations, and further comprising:
computer-readable program instructions to retrieve the two or more random PIN component from the various distinct locations where the two or more generated random PIN components were stored.
15 . The computer program product of claim 14 , wherein at least one of the various distinct locations comprises a second computing device accessible via a network.
16 . The computer program product of claim 11 , further comprising, in response to receiving a notification of a factory reset, computer-readable program instructions to delete one or more of two or more random PIN components.
17 . A system to secure personal identification numbers, the system comprising:
a storage medium; and a processor communicatively coupled to the storage medium, wherein the processor executes application code instructions that are stored in the storage medium and that cause the system to:
generate two or more random personal identification number (PIN) components;
determine a first secure memory PIN based at least in part on a user PIN and the two or more random PIN components; and
configure a secure memory using the determined first secure memory PIN;
receive an input of a second user PIN and a request to access the secure memory;
determine a second secure memory PIN based at least in part on the second user PIN and the two or more random PIN components;
determine that the determined first secure memory PIN and the determined second secure memory PIN match; and
provide access to the secure memory in response to determining that the determined first secure memory PIN and the determined second secure memory PIN match.
18 . The system of claim 17 , wherein the two or more random PIN components are stored at various diverse locations, and wherein the processor is further configured to execute computer-executable instructions stored in the storage medium to cause the system to:
retrieve the two or more random PIN components from the various distinct locations where the two or more generated random PIN components were stored.
19 . The system of claim 18 , wherein at least one of the various distinct locations comprises a host memory.
20 . The system of claim 18 , wherein at least one of the various distinct locations comprises a second computing device accessible through a network.Join the waitlist — get patent alerts
Track US2017255936A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.