Hands-free fare gate operation
US-2018144563-A1 · May 24, 2018 · US
US2023006982A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2023006982-A1 |
| Application number | US-202217900838-A |
| Country | US |
| Kind code | A1 |
| Filing date | Aug 31, 2022 |
| Priority date | Feb 28, 2017 |
| Publication date | Jan 5, 2023 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
An Internet-connected device, such as a car, refrigerator, or even a laptop can use a second device, such as a cell phone, to support cryptographic operations and communication with token service providers or other processing services requiring pre-provisioned capabilities that may include cryptographic secrets. By removing the need to store personally sensitive data in “Internet of Things” (IoT) devices, a user's personal information and other sensitive financial information may be contained to a relatively small number of devices. This may help prevent theft of goods or services by IoT devices that are not always under the close control of the user.
Opening claim text (preview).
What is claimed is: 1 . A method of supporting a secure communication between an origin device lacking a token service capability and a server by using an enabler device with a token service support, the method comprising: receiving, by the enabler device, a message content from the server, wherein the message content is received by the server from the origin device corresponding to a communication with the server; activating, by the enabler device, a token service provider by generating a token; identifying, by the enabler device via the server, the origin device, wherein the origin device is void of a storage unit for storing data needed for the token service support; generating, by the enabler device, a cryptogram corresponding to the token, the message content, or a combination thereof; encrypting, by the enabler device, the token and the cryptogram; and sending, by the enabler device, the encrypted token and the cryptogram to the origin device for the secure communication with the server. 2 . The method of claim 1 , further comprising, sending to the origin device a personal identification number (PIN), the PIN used to derive an encryption key used for securing communication between the enabler device and the origin device. 3 . The method of claim 2 , further comprising, receiving at the enabler device via a user interface of the enabler device, the PIN, the PIN used to derive an encryption key used for securing communication with the origin device. 4 . The method of claim 1 , wherein receiving the message content by the enabler device further includes receiving a server public key infrastructure (PKI) certificate to the enabler device, the server PKI certificate including the server public key. 5 . The method of claim 1 , wherein identifying, via a wireless communication process, the origin device having the token support comprises broadcasting a WiFi Peer-to-peer message requesting a response from devices providing token support. 6 . The method of claim 1 , further comprising: validating a server certificate with a certificate authority prior to activating the encrypted message content by the token service provider. 7 . The method of claim 1 , wherein encrypting the token and the cryptogram at the enabler device comprises encrypting the message content using a shared secret between the enabler device and the token service provider, the shared secret stored in a trusted zone of the enabler device. 8 . The method of claim 1 , wherein encrypting the token and the cryptogram at the enabler device comprises encrypting the message content with a shared secret, the shared secret known by the enabler device and the token service provider. 9 . The method of claim 8 , further comprising decrypting the token and cryptogram at the enabler device using the shared secret. 10 . A method of supporting secure communication between an origin device lacking a trusted zone and a server by using an enabler device with trusted zone support, the method comprising: receiving, by the enabler device, a message content from the server, wherein the message content is received by the server from the origin device corresponding to a communication with the server; activating, by the enabler device, a token service provider by generating a token; identifying, by the enabler device via the server, the origin device, wherein the origin device is void of a storage unit for storing data needed for the trusted zone and the trusted zone support, wherein the enabler device having the trusted zone; generating, by the enabler device, a cryptogram corresponding to the token, the message content, or a combination thereof; encrypting, by the enabler device, the token and the cryptogram associated with the trusted zone; and sending, by the enabler device, the encrypted token and the cryptogram to the origin device for the secure communication with the server. 11 . The method of claim 10 , further comprising: sending, by the enabler device, a personal identification number (PIN); and wherein an encryption key for use in encrypting communication between the origin device and the enabler device is generated at least in part based on the PIN. 12 . The method of claim 11 , further comprising: receiving via a user interface of the enabler device, the PIN; and generating a local copy of the encryption key at the enabler device, wherein the local copy of the encryption key used for encrypting communication between the origin device and the enabler device. 13 . The method of claim 10 , wherein identifying the origin device comprises identifying the origin device via a Wi-Fi Direct message broadcast for communicating with the enabler device. 14 . The method of claim 10 , further comprising, sending, to the origin device, a server certificate. 15 . The method of claim 10 , further comprising provisioning a shared secret between the token service provider and the enabler device. 16 . The method of claim 10 , wherein the token and cryptogram includes data that causes the server to alter its operation to achieve a result desired by the origin device. 17 . A system of supporting secure communication between an origin device lacking a trusted zone and a server by using an enabler device with trusted zone support, the system comprising: the origin device is void of a storage unit for storing data needed for the trusted zone support; the enabler device having the trusted zone support; wherein the origin device is configured to receive a message content corresponding to a communication process with the server; wherein the origin device is configured to send the message content to the enabler device; wherein the enabler device is configured to receive a token generated at a token service provider; wherein the enabler device is configured to generate a cryptogram corresponding to the token, the message content, or a combination thereof; wherein the enabler device is configured to encrypt the token and the cryptogram; wherein the enabler device is configured to send the encrypted token and the cryptogram to the origin device; wherein the origin device is configured to send the encrypted token and cryptogram to the server; and wherein the origin device is configured to receive an acknowledgement that the token and cryptogram have been successfully processed at the server. 18 . The system of claim 17 , wherein the enabler device is configured to execute instructions stored in a first memory that cause the enabler device to: receive the transaction data from the origin device; encrypt the transaction data with the one secret; send the encrypted transaction data to the token service provider; receive a request payload from the token service provider; encrypt the request payload with a public key of a merchant server; and return the encrypted request payload to the origin device. 19 . The system of claim 18 , wherein the origin device is configured to send to a merchant server certificate with the transaction data to the enabler device, and the enabler device is configured to validate the merchant server certificate and extract the merchant server public key. 20 . The system of claim 19 , wherein the request payload received at the enabler device is encrypted with the one cryptographic secret, wherein the enabler device is configured to decrypt the request payload prior to encrypting the request payload with the merchant server public key.
Proxies · CPC title
involving passwords or one-time passwords (network architectures or network communication protocols for using one-time keys in a packet data network H04L63/067) · CPC title
using asymmetric-key encryption or public key infrastructure [PKI], e.g. key signature or public key certificates · CPC title
using credential vaults, e.g. password manager applications or one time password [OTP] applications · CPC title
applying encryption by an intermediary, e.g. receiving clear information at the intermediary and encrypting the received information at the intermediary before forwarding · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.