Tamper-proofing and identity validation in a secure electronic transaction processing system

US10692090B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10692090-B2
Application numberUS-201715417067-A
CountryUS
Kind codeB2
Filing dateJan 26, 2017
Priority dateJan 26, 2016
Publication dateJun 23, 2020
Grant dateJun 23, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Tamper-proofing and secure identity validation techniques in a transaction processing system and secure electronic payment techniques are disclosed. A tamper-proof transaction processing device is provided and comprises at least two different strength adhesives to secure parts of the device together and a housing comprising at least a first and second protective layer. An electronic component comprising a secure element chip storing unique information relating to the chip is located between the first and second protective layer in the housing. In another aspect, a transaction processing system includes a payment instrument that is configured to approve only negative value and/or zero value transaction requests. Another aspect provides an identity card checking system and method where the identity card is brought into proximity of a data processing device and identity information is displayed on the screen of the data processing device for the period of time while the card is in proximity.

First claim

Opening claim text (preview).

The invention claimed is: 1. An electronic payment system, comprising: a payment instrument that is configured to approve only negative value payment requests and/or zero value payment requests; a data processing device that is communicatively coupleable via a first communication link to the payment instrument that is configured to approve only negative value payment requests and/or zero value payment requests, the data processing device communicatively coupleable to a server via a second communication link; and a service dispensing device that is communicatively coupleable to the server via a third communication link; wherein the data processing device is configured to: receive a first input including at least a payment amount; transmit a payment request to the payment instrument, the payment request including at least the payment amount; receive a first data package generated by the payment instrument, the first data package based on the payment request; generate a transaction request data package based on the first data package; and transmit the transaction request data package to the server; wherein the data processing device and/or the server is configured to determine whether to approve or decline a transaction, and in the event the transaction is approved, the server is configured to generate a trusted data package based on the transaction request data package and transmit the trusted data package to the service dispensing device; and wherein the service dispensing device is configured to: receive the trusted data package from the server; determine the authenticity of the trusted data package; and in the event the trusted data package is determined to be authentic, provide one or more services. 2. The system of claim 1 , wherein the first data package is generated based on a negative or zero value payment request. 3. An electronic payment system, comprising: a data processing device that is communicatively coupleable via a first communication link to a payment instrument that is configured to approve only negative value payment requests and/or zero value payment requests, the data processing device communicatively coupleable to a server via a second communication link; and a service dispensing device that is communicatively coupleable to the server via a third communication link; wherein the data processing device configured to: receive a first input including at least a payment amount; transmit a payment request to the payment instrument, the payment request including at least the payment amount; receive a first data package generated by the payment instrument, the first data package based on the payment request; generate a transaction request data package based on the first data package; and transmit the transaction request data package to the server; wherein the data processing device and/or the server is configured to determine whether to approve or decline a transaction, and in the event the transaction is approved, the server is configured to generate a trusted data package based on the transaction request data package and transmit the trusted data package to the service dispensing device; and wherein the service dispensing device is configured to: receive the trusted data package from the server; determine the authenticity of the trusted data package; and in the event the trusted data package is determined to be authentic, provide one or more services, wherein the payment instrument is located proximate the service dispensing device. 4. The system of claim 1 , wherein the payment instrument is secured to a surface of the service dispensing device. 5. The system of claim 4 , wherein the payment instrument comprises: a housing comprising at least a first and second protective layer; an electronic component that is housed by the housing, the component comprising a secure element chip storing unique information relating to the chip; wherein the electronic component is located between the first and second protective layer, the device further comprising at least two different strength adhesives to secure different parts of the device together, and the first protective layer is secured to the surface of the service dispensing device using a relatively strong adhesive. 6. The system of claim 5 , wherein the chip is provided in a first region of the component, and a relatively strong adhesive is used to secure at least part of the chip to at least part of the first protective layer and a relatively weak or no adhesive is used to secure at least part of the first region of the chip to at least part of the second protective layer, such that detachment of the electronic component from the device through the application of a force in a direction away from the first protective layer causes the chip to remain attached to the first protective layer. 7. The system of claim 6 , wherein a relatively weak adhesive is used to secure at least part of a region outside the first region of the electronic component to the first protective layer. 8. The system of claim 7 , wherein a relatively strong adhesive is used to secure at least part of the region outside the first region of the electronic component to the second protective layer. 9. The system of claim 6 , wherein the relatively strong adhesive is Epoxy, Methacrylate or contact bond adhesive, and/or the relatively weak adhesive is removable PermaTack. 10. The system of claim 5 , wherein a top surface of the first protective layer includes indicia that tampering of the device has occurred. 11. The system of claim 5 , wherein the component is a contactless EMV smart card. 12. The system of claim 1 , wherein the server is configured to determine whether to approve or decline a transaction based on the transaction request data package. 13. The system of claim, 1 wherein the trusted data package includes at least a set of instructions that specify at least one parameter relating to the one or more services and/or identification information that includes an image of the registered payment instrument user. 14. The system of claim 1 , wherein the first data package includes at least a unique identifier associated with the payment instrument, and wherein the transaction request data package also includes the unique identifier. 15. The system of claim 14 , wherein the unique identifier is one of a PAN associated with the payment instrument and a tokenised PAN associated with the payment instrument. 16. The system of claim 14 , further comprising a database communicatively coupled to the server, and wherein the server is further configured to: generate a lookup request based on the unique identifier; query the database using the lookup request; and receive a response from the database, the response indicating whether the unique identifier was found in the database; wherein the server generates the trusted data package only in the event that the response indicates that the unique identifier was found in the database. 17. The system of claim 1 , wherein the server is further configured to encrypt and sign the trusted data package and to transmit the encrypted signed trusted data package to the service dispensing device and the service dispensing device is configured to: attempt decryption and digital signature checking of the encrypted trusted data package; and determine the encrypted trusted data package including digital signature to be authentic upon successful decryption of the encrypted trusted data package. 18. The system of claim 1 , wherein the data processing devi

Assignees

Inventors

Classifications

  • insuring higher security of transaction · CPC title

  • G06Q20/20Primary

    Point-of-sale [POS] network systems · CPC title

  • at least one of the further markings being adapted for galvanic or wireless sensing, e.g. an RFID tag with both a wireless and an optical interface or memory, or a contact type smart card with ISO 7816 contacts and an optical interface or memory · CPC title

  • G06Q20/405Primary

    Establishing or using transaction specific rules · CPC title

  • Active cards, i.e. cards including their own processing means, e.g. including an IC or chip · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10692090B2 cover?
Tamper-proofing and secure identity validation techniques in a transaction processing system and secure electronic payment techniques are disclosed. A tamper-proof transaction processing device is provided and comprises at least two different strength adhesives to secure parts of the device together and a housing comprising at least a first and second protective layer. An electronic component c…
Who is the assignee on this patent?
Worldpay Ltd
What technology area does this patent fall under?
Primary CPC classification G06Q20/20. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jun 23 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).