Authentication of mobile device for secure transaction

US2016189136A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016189136-A1
Application numberUS-201414588335-A
CountryUS
Kind codeA1
Filing dateDec 31, 2014
Priority dateDec 31, 2014
Publication dateJun 30, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

There are provided systems and methods for authenticating a mobile device for use in a secure transaction. A user having a master device authenticated for use in a secure transaction system, such as an electronic payment system, identifies a secondary device to be enabled for use in processing a secure transaction. The secondary device connects to a companion device and shares information associated with the secondary device and companion device with a transaction processing server, which returns authentication information associated with both devices. When the user initiates a secure transaction, the secondary device identifies whether the third device is in proximity. The secure transaction is processed only if the second and third devices are in communication and authenticated during the transaction. If the secondary device is lost or stolen, the device may be disabled until reauthenticated through the master device.

First claim

Opening claim text (preview).

What is claimed is: 1 . In a secure transaction system having master device associated with a user account, the master device configured to engage in a secure transaction with a second device, a mobile device comprising: a secure element storing at least one identifier of a companion device and authentication information associated with the mobile device and the user account; a companion detection module comprising a short range wireless communication system configured to detect the presence of a companion device; and a secure transaction module configured to engage in a secure transaction with the second device while a companion device is detected, the secure transaction being associated with the user account. 2 . The mobile device of claim 1 , wherein the secure transaction module is configured to terminate a secure transaction if the presence of a companion device is not detected. 3 . The mobile device of claim 1 , wherein the companion detection module is configured to receive authentication information associated with the companion device; and wherein the secure transaction module is configured to generate a transaction message comprising the stored authentication information and the received authentication information. 4 . The mobile device of claim 1 , wherein the secure transaction module is further configured to detect communication from the master device, and engage in an authentication process, including receiving the authentication information from the master device. 5 . The mobile device of claim 4 , wherein the secure transaction module is further configured to terminate the secure transaction if a companion device is not detected. 6 . The mobile device of claim 5 , wherein if the secure transaction is initiated without a detected companion device, the secure transaction module disables secure transaction processing on the mobile device until the mobile device is re-authenticated through the master device. 7 . In an electronic payment system having a first device authenticated by a service provider for electronic payments associated with a user account, a method for delegating secure transactions to a second mobile device, the method comprising the steps: authenticating the second device for use with the account; storing authentication information on the second device, the authentication information including authentication information associated with a third device; detecting the third device in proximity to the second device; and processing an electronic payment transaction through the second device while the third device is detected. 8 . The method of claim 7 wherein the stored authentication information further comprises authentication information associated with the second device, including a payment token associated with the second device and a private key associated with the second device. 9 . The method of claim 8 wherein the stored authentication information further comprises a public key associated with the third device. 10 . The method of claim 9 wherein the step of processing further comprises the steps: establishing communication between the second device and a third party device; receiving transaction data from the third party device; using the private key associated with the second device, encrypting the transaction data, second device authentication information and third device authenticating information to produce a transaction message; and transmitting the transaction message to the third party device. 11 . The method of claim 9 wherein the step of authenticating further comprises the following steps performed on the first device: accessing the user account; connecting to the second device; receiving a second device identifier associated with the second device; receiving a third device identifier associated with the third device; and requesting authentication information for the second device, as a transaction-enabled device, and the third device, as a companion device. 12 . The method of claim 7 wherein the step of detecting further comprises the steps: determining detection information for the third device through the stored authentication information; and running a short range communication protocol associated with the third device comprising one of near field communication, radio communication, infrared communication, Bluetooth communication, Bluetooth Low Energy (BLE) communication, LTE Direct communication, and WiFi communication. 13 . In an electronic payment system having a first device authenticated by a service provider for electronic payments associated with a user account, a system for delegating secure transactions to a secondary device, the system comprising: a secure transaction module configure to process an electronic payment transaction from an authorized device; a database storing user account information, including an account identifier and an associated device authentication information; and an authentication module configured to receive a transaction message associated with a secondary device, the transaction message including authentication information associated with a third device, and authenticate the received transaction if the secondary device and a third device are authenticated. 14 . The system of claim 13 , wherein the stored used account information further includes at least one restriction associated with the user account information. 15 . The system of claim 14 , wherein the associated device authentication information comprises a first device identifier for authenticating electronic payments originating from the first device. 16 . The system of claim 15 , wherein the associated device authentication information comprises a second device identifier and a third device identifier for authenticating electronic payments originating from the second device. 17 . The system of claim 13 , wherein the authentication module further comprises an administration module configured to generate a payment token and encryption keys for authorized devices. 18 . The system of claim 13 wherein the authentication module is further configured to deny authentication of the received transaction if either the secondary or third device are not authenticated. 19 . The system of claim 13 wherein the authentication of the second device includes decrypting the transaction message using a stored public key associated with the second device. 20 . The system of claim 13 wherein the user account information includes a mapping of potential companion devices that may be used to authenticate the secondary device, and wherein the authentication of the secondary and third devices includes verifying an associated mapping of the devices in the database.

Assignees

Inventors

Classifications

  • using secure elements embedded in M-devices · CPC title

  • Authentication · CPC title

  • Use of secure elements separate from M-devices · CPC title

  • Services using short range communication, e.g. near-field communication [NFC], radio-frequency identification [RFID] or low energy communication · CPC title

  • Electricity · mapped topic

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016189136A1 cover?
There are provided systems and methods for authenticating a mobile device for use in a secure transaction. A user having a master device authenticated for use in a secure transaction system, such as an electronic payment system, identifies a secondary device to be enabled for use in processing a secure transaction. The secondary device connects to a companion device and shares information assoc…
Who is the assignee on this patent?
Ebay Inc
What technology area does this patent fall under?
Primary CPC classification G06Q20/3227. Mapped technology areas include Physics.
When was this patent published?
Publication date Thu Jun 30 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).