Web server bypass of backend process on near field communications and secure element chips

US9027102B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9027102-B2
Application numberUS-201213470203-A
CountryUS
Kind codeB2
Filing dateMay 11, 2012
Priority dateMay 11, 2012
Publication dateMay 5, 2015
Grant dateMay 5, 2015

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A mobile access terminal providing access to data in a secure element of the mobile access terminal is provided. The mobile access terminal comprises the secure element; a web browser; a near field communications system; an over-the-air proxy; an application programming interface layer; and a web server residing on a secure storage area of the mobile access terminal, wherein the web browser is provided with exclusive access to the web server.

First claim

Opening claim text (preview).

What is claimed is: 1. A mobile access terminal providing access to secure information in a secure element of the mobile access terminal comprising: the secure element storing the secure information; a web browser configured to transmit a secure information request to a server and transmit the secure information to a vendor; a trusted security zone, wherein the trusted security zone provides at least one chipset with a hardware root of trust, a secure execution environment for applications, and secure access to peripherals, wherein the trusted security zone stores a certificate and a secret key for use by an enterprise application on the mobile access terminal to verify the identity of the mobile access terminal to an enterprise cloud service, and wherein the enterprise application accesses the server to create a secure tunnel to retrieve the certificate and secret key; and the server residing and executing within at least one of the secure element or the trusted security zone of the mobile access terminal, wherein the server is configured to provide access to the secure information stored in the secure element exclusively to the web browser in response to receiving the secure information request from the web browser, and wherein the server is configured to block access to the secure information stored in the secure element when receiving secure information requests from entities other than the web browser. 2. The system of claim 1 , wherein the server comprises one or more of software and hardware. 3. The system of claim 1 , wherein the server is operable to interact with the web browser to share data from the secure element. 4. The system of claim 1 , wherein a call session control function resides on the core of the secure element. 5. The system of claim 1 , wherein the secure element comprises dedicated, embedded hardware in the mobile access terminal. 6. The system of claim 1 , wherein the secure element further comprises a kernel of an operating system. 7. The system of claim 1 , wherein the server is secure and is protected from being compromised. 8. A method for securing user data on a mobile access terminal comprising: providing, by a mobile access terminal, a secure element, a web browser, a trusted security zone, and a server, wherein the server executes from and is located in at least one of the secure element or the trusted security zone, and wherein the trusted security zone provides at least one chipset with a hardware root of trust, a secure execution environment for applications, and secure access to peripherals; securely storing, by the mobile access terminal, secure user data of the user of the mobile access terminal in a secure storage area, wherein the secure user data comprises a certificate and a secret key stored in the trusted security zone of the mobile access terminal for use by an enterprise application on the mobile access terminal to verify the identity of the mobile access terminal to an enterprise cloud service, and wherein the enterprise application accesses the server to create a secure tunnel to retrieve the certificate and secret key; initiating, by the mobile access terminal, a transaction with another system; transmitting a secure user data request from the web browser to the server in response to initiating the transaction with the other system; accessing, by the web browser, the secure user data from the secure storage area via the server in response to the server receiving the secure user data request from the web browser, wherein the server is configured to provide access to the secure user data stored in the secure storage area exclusively to the web browser in response to receiving the secure user data request from the web browser, and wherein the server is configured to block access to the secure user data stored in the secure storage area when receiving secure user data requests from entities other than the web browser; and executing a secure transaction, by the mobile access terminal, with the other system. 9. The method of claim 8 , wherein the server is operable to interface with the web browser to share data from one or more of the secure element and the trusted security zone. 10. The method of claim 8 , further comprising a call session control function residing on the core of the secure element. 11. The method of claim 8 , wherein the trusted security zone is built into the mobile access terminal processor architecture. 12. The method of claim 8 , wherein the enterprise application accesses the server using a Hypertext Transfer Protocol Secure (HTTPS) protocol to create the secure tunnel to retrieve the certificate and secret key. 13. The method of claim 8 , wherein the secure storage area comprises at least one of the secure element or the trusted security zone. 14. A mobile access terminal providing access to secure information in the mobile access terminal, the mobile access terminal comprising: a secure element; a web browser configured to transmit a secure information request to a server and transmit the secure information to a vendor; a trusted security zone, wherein the trusted security zone provides at least one chipset with a hardware root of trust, a secure execution environment for applications, and secure access to peripherals, and wherein the trusted security zone and the secure element are located in a core of the mobile access terminal; the server residing and executing within at least one of the secure element or the trusted security zone, wherein the server is configured to provide access to the secure information stored in the secure element or the trusted security zone exclusively to the web browser in response to receiving the secure information request from the web browser, and wherein the server is configured to block access to the secure information stored in the secure element or the trusted security zone when receiving secure information requests from entities other than the web browser; and an enterprise application communicating with an enterprise cloud service, wherein the enterprise application accesses the server to create a secure tunnel to retrieve a certificate and a secret key stored in the trusted security zone, and wherein the certificate and the secret key are used to confirm the identity of the mobile access terminal to the enterprise cloud service. 15. The system of claim 14 , wherein the server comprises one or more of software and hardware. 16. The system of claim 14 , wherein the server is operable to interact with the web browser to share data from one or more of the secure element and the trusted security zone. 17. The system of claim 14 , wherein the server resides within the trusted security zone of the mobile access terminal, and wherein the server enables communication using a Hypertext Transfer Protocol Secure (HTTPS) protocol.

Assignees

Inventors

Classifications

  • Protecting personal data, e.g. for financial or medical purposes · CPC title

  • RFID or NFC payments by means of M-devices · CPC title

  • H04W12/08Primary

    Access security · CPC title

  • using secure elements embedded in M-devices · CPC title

  • Electricity · mapped topic

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9027102B2 cover?
A mobile access terminal providing access to data in a secure element of the mobile access terminal is provided. The mobile access terminal comprises the secure element; a web browser; a near field communications system; an over-the-air proxy; an application programming interface layer; and a web server residing on a secure storage area of the mobile access terminal, wherein the web browser is …
Who is the assignee on this patent?
Katzer Robin Dale, Paczkowski Lyle W, Sprint Communications Co
What technology area does this patent fall under?
Primary CPC classification G06F21/6245. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue May 05 2015 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).