US2018225654A1PendingUtilityA1

Biometric authentication of mobile financial transactions by trusted service managers

Assignee: PAYPAL INCPriority: Jun 6, 2008Filed: Dec 29, 2017Published: Aug 9, 2018
Est. expiryJun 6, 2028(~1.9 yrs left)· nominal 20-yr term from priority
G07C 9/257G06Q 20/3674H04L 2209/80G06Q 20/204G06Q 20/367G07F 7/0826G06Q 20/3227G06Q 20/3821G06Q 20/3829G06Q 20/40G06Q 20/4012G06Q 40/00G06Q 20/3223G06Q 20/1085H04L 63/0861G06Q 20/382H04L 2209/56G06Q 20/3278H04L 63/0823G06Q 20/40145H04L 9/3231H04W 4/80G06Q 20/20H04W 12/06G06Q 20/32G07C 9/00087G06Q 20/3265H04W 12/069
58
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In one embodiment, a method comprises storing a biometric trait of a user in a data communication device of the user, comparing a biometric trait input into the device with the biometric trait stored in the device, generating a certificate authenticating the user within the device if the biometric trait input into the device matches the biometric trait stored in the device, and facilitating a financial transaction of the user using the certificate.

Claims

exact text as granted — not AI-modified
1 . An application function authorization system, comprising:
 a first secure element that is located in a user device and that is configured to provide a first application;   a second secure element that is located in the user device, that is coupled to the first secure element, and that stores user authentication data and application function authorization information; and   tunnel circuitry that is coupled to the second secure element and that is configured to prevent access to user data transmitted through the tunnel circuitry by non-authorized subsystems in the user device, wherein the second secure element is configured to:
 receive user data transmitted through the tunnel circuitry; 
 verify the user data using the user authentication data; and 
 provide, in response to the verification of the user data, the application function authentication information to the first application provided by the first secure element in order to enable the application to perform an application function. 
   
     
     
         2 . The system of  claim 1 , wherein the application function includes generating transaction instructions for processing a transaction. 
     
     
         3 . The system of  claim 1 , wherein the first secure element is configured to provide at least one second application. 
     
     
         4 . The system of  claim 1 , further comprising:
 a user data input device coupled to the tunnel circuitry and configured to receive the user data from a user.   
     
     
         5 . The system of  claim 4 , wherein the user data input device is a user biometric trait input device that is configured to receive user biometric trait data from the user. 
     
     
         6 . The system of  claim 1 , wherein the first secure element is a Trusted Service Manager (TSM) certified by a third party. 
     
     
         7 . The system of  claim 1 , wherein the application function includes a wireless transmission. 
     
     
         8 . A method for authorizing an application function, comprising:
 transmitting, via tunnel circuitry to a first secure portion of a secured system, user data, wherein the tunnel circuitry prevents access to transmitted user data by non-authorized subsystems;   authenticating, using the first secure portion of the secured system via user authentication data that is stored in the secure portion of the secured system, the user data; and   transmitting, from the first secure portion of the secured system to a first application provided by a second secure portion of the secured system in response to authenticating the user data, application function authorization information that is stored in the first secure portion of the secured system, wherein the application function authorization information enables the first application to perform an application function.   
     
     
         9 . The method of  claim 8 , wherein the application function includes generating payment instructions for completing a payment. 
     
     
         10 . The method of  claim 9 , further comprising:
 providing, using the second secure portion of the secured system, at least a second application.   
     
     
         11 . The method of  claim 8 , further comprising:
 receiving, from a user data input device coupled to the tunnel circuitry, the user data from a user.   
     
     
         12 . The method of  claim 11 , wherein the user data input device is a user biometric trait input device that receives user biometric trait data from the user. 
     
     
         13 . The method of  claim 8 , wherein the second secure portion of the secured system is a Trusted Service Manager (TSM) certified by a third party. 
     
     
         14 . The method of  claim 8 , wherein the application function includes a wireless transmission. 
     
     
         15 . A non-transitory machine-readable medium having stored thereon machine-readable instructions executed to cause a machine to perform operations comprising:
 transmitting, through tunnel circuitry located in a device, user data to a first security module, wherein access to the user data by non-authorized subsystems in the device is prevented by the tunnel circuitry;   accessing user authentication data and application function authorization information from the first security module;   determining, through the first security module, whether the user data matches the user authentication data; and   releasing, through the first security module, the application function authorization information to a first application that is provided by a second security module that is located in the device in response to determining a match between the user data and the user authentication data, wherein the authentication function authentication information enables the application to perform an application function.   
     
     
         16 . The non-transitory computer readable medium of  claim 15 , wherein the application function includes generating instructions for transferring money. 
     
     
         17 . The non-transitory computer readable medium of  claim 16 , wherein the operations further comprise:
 providing, through the second security module, at least one second application.   
     
     
         18 . The non-transitory computer readable medium of  claim 15 , wherein the operations further comprise:
 receiving, through a user data input device located in the device and coupled to the tunnel circuitry, the user data from a user.   
     
     
         19 . The non-transitory computer readable medium of  claim 18 , wherein the user data input device is a user biometric trait input device that receives a user biometric trait data from a user. 
     
     
         20 . The non-transitory computer readable medium of  claim 15 , wherein the second security module is a Trusted Service Manager (TSM) certified by a third party.

Join the waitlist — get patent alerts

Track US2018225654A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.