US2018295121A1PendingUtilityA1

Secure element authentication

Assignee: MICROSOFT TECHNOLOGY LICENSING LLCPriority: Dec 3, 2010Filed: Jun 13, 2018Published: Oct 11, 2018
Est. expiryDec 3, 2030(~4.4 yrs left)· nominal 20-yr term from priority
H04L 9/0897H04W 12/04H04L 9/30H04L 63/06H04L 9/3271H04L 9/3234H04L 9/3226G06Q 20/34H04L 2209/80H04L 9/14H04L 63/0853G07C 9/00174H04L 9/3247H04W 12/06H04L 63/083H04W 12/069
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Secure element authentication techniques are described. In implementations, a confirmation is received that an identity of a user has been physically verified using one or more physical documents. One or more credentials that are usable to authenticate the user are caused to be stored in a secure element of a mobile communication device of the user, the secure element implemented using tamper-resistant hardware.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 receiving, from an application executing on a mobile communication device, a request for a secure element to provision credentials for the application;   based at least on receiving the provisioning request, storing the credentials in the secure element;   receiving, by the application, a request for a signature of data using the credentials; and   based at least on receiving the request for the signature, returning the signature stored in the secure element without exposing the credentials outside of the secure element.   
     
     
         2 . The method of  claim 1 , wherein an integrated circuit implements the secure element. 
     
     
         3 . The method of  claim 2 , wherein the integrated circuit is resistant to removal from a circuit board of the mobile communication device. 
     
     
         4 . The method of  claim 1 , wherein the credentials are configured to authenticate a user's identity for the application. 
     
     
         5 . The method of  claim 1 , wherein the secure element includes a private key configured to decrypt data that includes the credentials encrypted using a corresponding public key, the secure element configured to perform the decryption without exposing the private key and the one or more credentials outside of the secure element. 
     
     
         6 . The method of  claim 5 , wherein the private key is configured during manufacture of the secure element. 
     
     
         7 . The method of  claim 1 , wherein the one or more credentials are configured for use by the mobile communication device to authenticate the user to make a purchase using information relating to a credit card, provide an identifier for use as a transit access card, provide an identifier associated with a loyalty card, or provide credentials usable by the mobile communication device to access a premises. 
     
     
         8 . A mobile computing device comprising a secure element implemented in tamper-resistant hardware that is configured to:
 receive, from an application executing on the mobile communication device, a request for the secure element to provision credentials for the application;   based at least on receiving the provisioning request, store the credentials in the secure element;   receive a request by the application for a signature of data using the credentials; and   based at least on receiving the request for the signature, return the signature stored in the secure element without exposing the credentials outside of the secure element.   
     
     
         9 . The mobile computing device of  claim 8 , wherein an integrated circuit implements the secure element. 
     
     
         10 . The mobile computing device of  claim 9 , wherein the integrated circuit is resistant to removal from a circuit board of the mobile communication device. 
     
     
         11 . The mobile computing device of  claim 8 , wherein the credentials are configured to authenticate a user's identity for the application. 
     
     
         12 . The mobile computing device of  claim 8 , wherein the secure element includes a private key configured to decrypt data that includes the credentials encrypted using a corresponding public key, the secure element configured to perform the decryption without exposing the private key and the one or more credentials outside of the secure element. 
     
     
         13 . The mobile computing device of  claim 12 , wherein the private key is configured during manufacture of the secure element. 
     
     
         14 . The mobile computing device of  claim 8 , wherein the one or more credentials are configured for use by the mobile communication device to authenticate the user to make a purchase using information relating to a credit card, provide an identifier for use as a transit access card, provide an identifier associated with a loyalty card, or provide credentials usable by the mobile communication device to access a premises. 
     
     
         15 . One or more computer storage media storing computer readable instructions that, when executed by at least a processor, cause the at least one processor to perform operations comprising:
 receiving, from an application executing on a mobile communication device, a request for a secure element to provision credentials for the application;   in response to the provisioning request, storing the credentials in the secure element;   receiving, by the application, a request for a signature of data using the credentials; and   in response to the request for the signature, returning the signature stored in the secure element without exposing the credentials outside of the secure element.   
     
     
         16 . The one or more computer storage media of  claim 15 , wherein an integrated circuit implements the secure element. 
     
     
         17 . The one or more computer storage media of  claim 16 , wherein the integrated circuit is resistant to removal from a circuit board of the mobile communication device. 
     
     
         18 . The one or more computer storage media of  claim 15 , wherein the credentials are configured to authenticate a user's identity for the application. 
     
     
         19 . The one or more computer storage media of  claim 15 , wherein the secure element includes a private key configured to decrypt data that includes the credentials encrypted using a corresponding public key, the secure element configured to perform the decryption without exposing the private key and the one or more credentials outside of the secure element, and wherein the private key is configured during manufacture of the secure element. 
     
     
         20 . The one or more computer storage media of  claim 15 , wherein the one or more credentials are configured for use by the mobile communication device to authenticate the user to make a purchase using information relating to a credit card, provide an identifier for use as a transit access card, provide an identifier associated with a loyalty card, or provide credentials usable by the mobile communication device to access a premises.

Join the waitlist — get patent alerts

Track US2018295121A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.