Apparatus and method for secure electronic payment

US10699274B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10699274-B2
Application numberUS-201615221030-A
CountryUS
Kind codeB2
Filing dateJul 27, 2016
Priority dateAug 24, 2015
Publication dateJun 30, 2020
Grant dateJun 30, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

An apparatus and method for secure electronic payment are provided. The method includes authenticating a user of an electronic device executing a trusted payment application in a trusted execution environment of the electronic device, receiving credit card data from the user, generating credit card track data based on the received credit card data, and storing the credit card track data.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for secure electronic payment, the method comprising: authenticating a user of an electronic device by executing a trusted payment application in a trusted execution environment of the electronic device; receiving credit card data from the user; generating, using a processor, credit card track data by the trusted payment application executing in the trusted execution environment based on the credit card data; storing the credit card track data in a secure memory of the electronic device; and rejecting input of raw credit card track data not generated via the generating of the credit card track data. 2. The method of claim 1 , wherein the generating of the credit card track data in the trusted execution environment based on the credit card data comprises: performing a mutual authentication process with a credit card processor corresponding to the credit card data; transmitting the credit card data to the credit card processor; and receiving the credit card track data from the credit card processor, the credit card track data generated based on the credit card data. 3. The method of claim 2 , wherein the performing of the mutual authentication process comprises: transmitting at least one first digital certificate to the credit card processor, the at least one first digital certificate signed with a private key of the electronic device; receiving at least one second digital certificate from the credit card processor, the at least one second digital certificate signed with a private key of the credit card processor; verifying the at least one second digital certificate based on a corresponding public key of the credit card processor; and receiving a verification of the at least one first digital certificate from the credit card processor. 4. The method of claim 1 , wherein the credit card data comprises a credit card number, a credit card expiration date, a Card Verification Value (CVV), an issuing bank, identification of a credit card processor, or a billing zip code. 5. The method of claim 1 , wherein the credit card data is generated dynamically and used for a single transaction. 6. The method of claim 1 , wherein authenticating the user comprises receiving biometric information of the user. 7. The method of claim 1 , wherein the credit card data is generated in a same format as the data on the credit card's magnetic strip. 8. A method for secure electronic payment, the method comprising: authenticating a user of an electronic device executing a trusted payment application in a trusted execution environment of the electronic device; receiving credit card data from the user; generating credit card track data in the trusted execution environment based on the credit card data; storing the credit card track data in a secure memory of the electronic device, the secure memory being accessible only via the trusted execution environment; rejecting input of raw credit card track data not generated via the generating of the credit card track data; and transmitting the credit card track data to a magnetic card reader, wherein the transmitting of the credit card track data to the magnetic card reader comprises applying an electrical signal to a magnetic stripe swipe simulator based on the credit card track data so as to generate a magnetic field capable of being read by the magnetic card reader, and wherein the generating of the credit card track data comprises generating the credit card track data by the trusted payment application executing in the trusted execution environment. 9. An electronic device for secure electronic payment, the electronic device comprising: a memory including a secure memory and an unsecure memory; a magnetic stripe swipe simulator configured to generate a magnetic field capable of being read by a magnetic card reader; and a processor configured to execute a trusted execution environment including a trusted payment application, the processor configured to execute the trusted payment application to: authenticate a user, receive credit card data from the user, generate credit card track data by the trusted payment application executing in the trusted execution environment based on the credit card data, store the credit card track data in the secure memory, and reject input of raw credit card track data not generated via the generating of the credit card track data. 10. The electronic device of claim 9 , wherein the magnetic stripe swipe simulator comprises a copper coil wound in a substantially rectangular shape and electronically coupled to the processor. 11. The electronic device of claim 9 , wherein the processor comprises a system on chip (SoC) dedicated to executing the trusted execution environment. 12. The electronic device of claim 9 , wherein the instructions to generate the credit card track data in the trusted execution environment based on the received credit card data comprise instructions to: perform a mutual authentication process with a credit card processor corresponding to the received credit card data; transmit the credit card data to the credit card processor; and receive the credit card track data from the credit card processor, the credit card track data generated based on the credit card data. 13. The electronic device of claim 12 , wherein the mutual authentication process comprises instructions to: transmit at least one first digital certificate to the credit card processor, the at least one first digital certificate signed with a private key of the electronic device; receive at least one second digital certificate from the credit card processor, the at least one second digital certificate signed with a private key of the credit card processor; verify the at least one second digital certificate based on a corresponding public key of the credit card processor; and receive a verification of the at least one first digital certificate from the credit card processor. 14. The electronic device of claim 9 , wherein the credit card data comprises a credit card number, a credit card expiration date, a Card Verification Value (CVV), an issuing bank, identification of a credit card processor, or a billing zip code. 15. The electronic device of claim 9 , wherein the processor is further configured to execute instructions comprising: controlling the magnetic stripe swipe simulator to broadcast the stored credit card track data to the magnetic card reader, wherein the instructions to control the magnetic stripe swipe simulator to broadcast the stored credit card track data to the magnetic card reader comprise instructions to apply an electrical signal to the magnetic stripe swipe simulator based on the credit card track data so as to generate a magnetic field capable of being read by the magnetic card reader. 16. The electronic device of claim 9 , wherein the credit card data is generated dynamically and used for a single transaction. 17. The electronic device of claim 9 , wherein the credit card data is generated in a same format as the data on the credit card's magnetic strip. 18. A non-transitory computer-readable storage medium storing instructions that, when executed, cause at least one processor to perform a method comprising: authenticating a user of an electronic device executing a trusted payment application in a trusted execution environment of the electronic device; receiving credit card data from the user; generating, by the at least one processor, credit card track data by the trusted payment application executing in the trusted executi

Assignees

Inventors

Classifications

  • using certificates or pre-shared keys · CPC title

  • Authentication · CPC title

  • Services using short range communication, e.g. near-field communication [NFC], radio-frequency identification [RFID] or low energy communication · CPC title

  • using cards, e.g. integrated circuit [IC] cards or magnetic cards · CPC title

  • Identity check for transactions · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10699274B2 cover?
An apparatus and method for secure electronic payment are provided. The method includes authenticating a user of an electronic device executing a trusted payment application in a trusted execution environment of the electronic device, receiving credit card data from the user, generating credit card track data based on the received credit card data, and storing the credit card track data.
Who is the assignee on this patent?
Samsung Electronics Co Ltd
What technology area does this patent fall under?
Primary CPC classification G06Q20/4014. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jun 30 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).