US2021297266A1PendingUtilityA1
Method and system for performing a transaction and for performing a verification of legitimate access to, or use of digital data
Est. expiryJun 13, 2023(expired)· nominal 20-yr term from priority
H04L 2209/56G06Q 20/3825H04L 9/3234G06F 2221/2115G06F 21/73G06Q 20/02H04L 9/3247G06F 21/10
55
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method for performing an electronic transaction is disclosed. The method provides authentication data and authentication software to an electronic device and preferably stored in a secure storage location or other location inaccessible to the user or the operating system of the device. The authentication software is activated to generate a digital signature from the authentication data. Next, the digital signature is provided to the other transaction party.
Claims
exact text as granted — not AI-modified1 . A method for performing an electronic transaction between a first transaction party and a second transaction party using an electronic device operated by the first transaction party, the electronic device having an operating system creating a run-time environment for user applications and authentication software running in a separate operating environment, independent from and inaccessible to the operating system, the electronic device having a memory comprising storage locations, part of the memory being accessible to the user and operating system, part of the memory being a secure area,
wherein the electronic device comprises a system for accessing a memory location in the memory, wherein the system for accessing the memory location is configured to selectively report the storage locations of the secure area, the storage locations of said secure area not being reported to the operating system while at the same time being reported to the authentication software running in the separate operating environment, the method comprising: providing a private key, at least, in the user accessible area of the electronic device, the private key being encrypted, thereby rendering the private key inaccessible to the user; providing authentication software in the electronic device, the private key being accessible to the authentication software; activating the authentication software to decrypt the private key in the secure area and to generate a digital signature from the private key, wherein the authentication software is run in a secure processing environment inaccessible to the operating system; and providing by the electronic device the digital signature to the second transaction party.
2 . The method according to claim 1 , wherein the second transaction party provides the private key to the first transaction party.
3 . The method according to claim 1 , wherein the second transaction party stores the digital signature together with data identifying the first transaction party.
4 . The method according to claim 1 , wherein the private key is unique for the authentication software and is provided by a trusted third party, and is not known to the second transaction party.
5 . The method according to claim 1 , wherein the private key is encrypted by the second transaction party using an encryption key before the private key is provided to the first transaction party.
6 . The method according to claim 1 , wherein the authentication software retrieves a decryption key associated with the encryption key and decrypts the private key at a first use.
7 . The method according to claim 1 , wherein the authentication software run in a secure processing environment such that it may obtain the private key without the private key passing through an unsecured part of said electronic device.
8 . The method according to claim 1 , wherein a decryption key for decrypting the private key is inaccessible to the user and to any user-operated software, thereby rendering the private key inaccessible to the user.
9 . The method according to claim 1 , wherein a decryption key for decrypting the private key is incorporated in the electronic device
10 . The method according to claim 1 , wherein the private key is encrypted using at least two encryption layers.
11 . The method according to claim 10 , wherein at least one encryption layer may be decrypted by the authentication software.
12 . The method according to claim 1 , wherein the private key may be decrypted using a decryption key associated with at least one serial number of a hardware component of the electronic device.
13 . The method according to claim 1 , wherein the private key is decrypted using a decryption key which is associated with a user identifying number, in particular a personal identifying number, PIN, or a number or a template associated with a fingerprint of the user.
14 . The method according to claim 1 , further comprising identifying the user of the electronic device before activating the authentication software.
15 . The method of claim 1 , wherein the second transaction party includes a server and the electronic device is a client device connected to the server over a network.
16 . The method according to claim 1 , wherein the system for accessing the memory location in the memory in the electronic device comprises a system for controlling the accessibility of data in said memory.
17 . The method according to claim 1 , wherein the electronic device comprises a system for controlling instructions and data flowing between hardware components of the electronic device, the operating system requesting data from said hardware components via said system, wherein said system is a system for accessing a memory location in a memory connected to the electronic device.
18 . The method according to claim 17 , wherein the storage locations of the secure area are accessible by said system for controlling instructions and data but the storage locations are not reported by said system for controlling instructions and data to the operating system.
19 . The method according to claim 1 , wherein the electronic device comprises a console independent from and inaccessible to the operating system (OS), the memory being a secure location in the electronic device in or behind the console, and the authentication software is run in a secure processing environment in the console inaccessible to said operating system.
20 . An electronic device comprising
a network interface configured for an electronic transaction between a first transaction party and a second transaction party, the electronic device being operated by the first transaction party; a processor configured for an operating system creating a run-time environment for user applications and authentication software running in a separate operating environment, independent from and inaccessible to the operating system; and a memory comprising storage locations, part of the memory being accessible to the user and operating system, part of the memory being a secure area; a system for accessing a memory location in the memory, wherein the system for accessing the memory location is configured to selectively report the storage locations of the secure area, the storage locations of said secure area not being reported to the operating system while at the same time being reported to the authentication software running in the separate operating environment, wherein the memory in the electronic device stores a private key, at least, in the user accessible area of the electronic device, the private key being encrypted, thereby rendering the private key inaccessible to the user, and storing authentication software, the private key being accessible to the authentication software; wherein the processor is configured to: activate the authentication software to decrypt the private key in the secure area and to generate a digital signature from the private key, wherein the authentication software is run in a secure processing environment inaccessible to the operating system; and provide the digital signature to the second transaction party.
21 . The device according to claim 20 , wherein the authentication software run in a secure processing environment such that it may obtain the private key without the private key passing through an unsecured part of said electronic device.
22 . The device according to claim 20 , incorporating the decryption key for decrypting the private key, wherein a decryption key for decrypting the private key is inaccessible to the user and to any user-operated software, thereby rendering the private key inaccessible to the user.
23 . The device according to claim 20 , wherein the electronic device comprises a system for controlling instructions and data flowing between hardware components of the electronic device, the operating system requesting data from said hardware components via said system, wherein said system is a system for accessing a memory location in a memory connected to the electronic device.
24 . The device according to claim 20 , wherein the storage locations of the secure area are accessible by said system for controlling instructions and data but the storage locations are not reported by said system for controlling instructions and data to the operating system.
25 . The device according to claim 20 , wherein the electronic device comprises a console independent from and inaccessible to the operating system (OS), the memory being a secure location in the electronic device in or behind the console, and the authentication software is run in a secure processing environment in the console inaccessible to said operating system.Join the waitlist — get patent alerts
Track US2021297266A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.