Secure sidecar container
US-2024330031-A1 · Oct 3, 2024 · US
US9681305B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9681305-B2 |
| Application number | US-201314784502-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jun 5, 2013 |
| Priority date | Jun 5, 2013 |
| Publication date | Jun 13, 2017 |
| Grant date | Jun 13, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A system and method are disclosed herein leveraging financial networks standards with mobile device data and SIM card chip knowledge to authenticate a device. For instance, a party to a transaction may utilize these elements of information, not traditionally associated with wireless transactions, to achieve a lower probability of fraud and/or a higher confidence associated with the transaction.
Opening claim text (preview).
The invention claimed is: 1. A method comprising: linking, by a fraud prevention computer, an identifier of a mobile device user to a unique SIM card hardware identifier of a SIM card of a mobile device of the mobile device user; associating, by the fraud prevention computer and in an electronic registry and in response to a funding source link request, a mobile device user identifier with transaction account information of the mobile device user, the unique SIM card hardware identifier of the SIM card of the mobile device, and a unique mobile device hardware identifier; encrypting, by the fraud prevention computer, the transaction account information; storing, by the fraud prevention computer, the transaction account information; linking, by the fraud prevention computer, a stand-in token to the transaction account information; storing, by the fraud prevention computer, the stand-in token in the SIM card; transmitting, by the fraud prevention computer, public key data of a public key to a memory location of the SIM card, wherein the public key data is securely stored in the memory location of the SIM card; transmitting, by the fraud prevention computer, private key data of a private key to the memory location of the SIM card, wherein the private key data is securely stored to the memory location of the SIM card, wherein the SIM card is pre-provisioned with a holding block ready to receive the public key data and the private key data, wherein the private key is linked to a user menu of the mobile device, wherein the user menu requests payment via a transaction request message to create a signed transaction request message; signing, by the fraud prevention computer, the public key and the identifier of the mobile device user with a private master key that corresponds to the public key, to bind the public key and the identifier to a public master key and to create a certificate; receiving, by the fraud prevention computer, the signed transaction request message over a mobile network via a transaction application stored to a memory associated with the mobile device, wherein the private key data is appended to the transaction request message to create a signed message, and wherein the public key data is appended to the signed transaction request message by the transaction application, issuing, by the fraud prevention computer, a verification request, in response to the public key reading the signed transaction request message and a session being initiated; verifying, by the fraud prevention computer and in response to the public key reading the signed transaction request message, that the public key is correct; validating, by the fraud prevention computer, by comparing the mobile device hardware identifier captured with the transaction request message with expected mobile device hardware identifier information stored in the electronic registry and associated with the received public key; validating, by the fraud prevention computer, by comparing the SIM card hardware identifier information captured with the transaction request message with expected SIM card hardware identifier information stored in the electronic registry and associated with the received public key; verifying, by the fraud prevention computer, that the private key data is correct; appending, by the fraud prevention computer, transaction account information of the mobile device user to the transaction request message, wherein the user menu of the mobile device provides merchant identification data to an application; receiving, by the fraud prevention computer and from the mobile device, a validation of the merchant identification data; and transmitting, by the fraud prevention computer, the appended transaction request to a financial transaction processor for authorization. 2. The method of claim 1 , wherein the transaction account information is not stored to the memory coupled to the mobile device. 3. The method of claim 1 , wherein at least one of the SIM card hardware identifier information or the mobile device hardware identifier captured during transmitting of the transaction request message via the mobile device are captured by a mobile network operator. 4. The method of claim 1 , wherein the SIM card hardware identifier information comprises an international Mobile subscriber identity (IMSI) code. 5. The method of claim 1 , wherein the mobile device hardware identifier comprises an international Mobile Equipment Identity (IMEI) code. 6. The method of claim 1 , further comprising validating, by the fraud prevention computer, by comparing mobile device location information captured with the transaction request message with expected mobile device location information stored in the electronic registry and associated with the received public key. 7. The method of claim 6 , wherein the mobile device location information captured during transmitting of the transaction request message via the mobile device are captured by a mobile network operator. 8. The method of claim 6 , wherein the mobile device location information comprises a Mobile Subscriber Integrated Services Digital Network Number (MSISDN). 9. The method of claim 1 , further comprising requesting the mobile device user enter a user passcode prior to accessing the transaction application. 10. The method of claim 1 , further comprising storing the transaction application to the memory associated with the mobile device. 11. The method of claim 1 , wherein the transaction processor formats the appended transaction request message into International organization for standardization format. 12. The method of claim 1 , wherein an issuer receives the transmitted appended request to a transaction processor for authorization decisioning. 13. The method of claim 1 , wherein the transaction application locates the mobile device hardware identifier from an operating system of the mobile device. 14. The method of claim 1 , further comprising pre-provisioning a secure memory location of the SIM card for receiving at least one of the public key data or the private key data prior to issuing the SIM card for use on a mobile network. 15. The method of claim 1 , further comprising presenting government issued identification in concert with providing at least one of the unique mobile device hardware identifier to a registry or providing the unique SIM card hardware identifier to the electronic registry. 16. The method of claim 1 , further comprising at least one of providing the unique mobile device hardware identifier to the electronic registry or providing the unique SIM card hardware identifier to the electronic registry. 17. The method of claim 1 , wherein a trusted certificate authority working with the mobile network operator transmits at least one of the private key data or the public key data to the memory location of the SIM card. 18. The method of claim 1 , further comprising: transmitting, by the fraud prevention computer and to the transaction application, at least one of: that the public key is incorrect, that the mobile device hardware identifier is incorrect, that the SIM card hardware identifier information is incorrect, that the private key is incorrect, or displaying, via the mobile device, a message indicating that the transaction will not proceed. 19. A system comprising: a tangible, non-transitory memory communicating with a processor, the tangible, non-transitory memory having instructions stored thereon that, in response to execution by the processor, cause a fraud prevention pr
for supporting key management in a packet data network (cryptographic mechanisms or cryptographic arrangements for key management H04L9/08) · CPC title
using a predetermined code, e.g. password, passphrase or PIN (network architectures or network communication protocols for supporting authentication of entities using passwords in a packet data network H04L63/083) · CPC title
involving fraud or risk level assessment in transaction processing · CPC title
Key management, e.g. using generic bootstrapping architecture [GBA] · CPC title
involving digital signatures · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.