CA2948481C

Establishment of a secure session between a card reader and a mobile device

Abstract

Disclosed is a technique for establishing a secure communication session between a mobile device and a card reader. The technique can involve using a trusted, remote validation server to validate security information of both the card reader and a POS module in the mobile device prior to, and as a precondition of, the card reader and the POS module establishing a secure communication session with each other. In certain embodiments the POS module sends the security information of both the card reader and the POS module to the validation server. The security information can include cryptographic keys of the POS module and the card reader and additional security information related to the POS module and its software environment.

CA2948481C, drawing sheet 1
Sheet 1 of 10

Term

8.6 yearsleft in the term

Expires 7 May 2035.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

33 claims: 6 independent, 27 dependent

  1. 1
    CLAIMS What is claimed is:1. A method comprising: detecting, by a point-of-sale (POS) software module that executes in a mobile device, initiation of a session between the POS software module and a mobile card reader coupled to the mobile device;receiving, by the POS software module from the mobile card reader, security related information of the mobile card reader;transmitting, by the POS software module, the received security related information of the mobile card reader and security related information of the POS software module from the mobile device to a remote computer system, wherein the security related information of the POS software module includes data indicative of a software environment of the POS software module;validating, by the remote computer system, the transmitted security related information of the mobile card reader and the security related information of the POS software module;signing, by the remote computer system, a cryptographic key of the POS software module;receiving, by the POS software module, an indication that the security related information of the POS software module and the security related information of the mobile card reader have been validated by the remote computer system, wherein the indication includes the cryptographic key of the POS software module, signed by the remote computer system;sending, by the POS software module, the cryptographic key of the POS software module, signed by the remote computer system, from the POS software module to the mobile card reader;generating, by the POS software module, in cooperation with the mobile card reader, a secure session key;and WSLEGAL\074889\00053\27514822v3 Date Reçue/Date Received 2022-11-18 encrypting, by the POS software module, using the generated secure session key, data communicated between the POS software module and the mobile card reader.
  2. 4
    A method comprising:receiving, by a POS software module executed by one or more processors of a mobile device, from a mobile card reader coupled to the mobile device, security related information of the mobile card reader;sending, by the POS software module, the security related information received from the mobile card reader and security related information associated with the POS software module, from the mobile device, to a remote computer system, for validation, by the remote computer system, of the security related information received from the mobile card reader and the security related information associated with the POS software module;receiving, by the POS software module, an indication that the security related information received from the mobile card reader and the security related information associated with the POS software module has been validated by the remote computer system, wherein the indication includes a cryptographic key of the POS software module, signed by the remote computer system;sending, by the POS software module, from the mobile device, to the mobile card reader, the cryptographic key of the POS software module, signed by the remote computer system;generating, by the POS software module based on communication with the mobile card reader, a secure session key;and WSLEGAL\074889\00053\27514822v3 Date Reçue/Date Received 2022-11-18 performing, by the POS software module, using the generated secure session key, at least one of: encrypting data communicated to the mobile card reader;or decrypting data received from the mobile card reader.
  3. 9
    A non-transitory machine-readable storage medium storing instructions that form at least a portion of a point-of-sale (POS) software module and that, when executed by one or more processors of a mobile device, cause the one or more processors to perform operations comprising:receiving, by the POS software module, from a mobile card reader coupled to the mobile device, security related information of the mobile card reader;sending, by the POS software module, the security related information received from the mobile card reader and security related information associated with the POS software module, from the mobile device, to a remote computer system, for validation, by the remote computer system, of the security related information received from the mobile card reader and the security related information associated with the POS software module;WSLEGAL\074889\00053\27514822v3 Date Reçue/Date Received 2022-11-18 receiving, by the POS software module, an indication that the security related information received from the mobile card reader and the security related information associated with the POS software module has been validated by the remote computer system, wherein the indication includes a cryptographic key of the POS software module, signed by the remote computer system;sending, by the POS software module, from the mobile device, to the mobile card reader, the cryptographic key of the POS software module, signed by the remote computer system;generating, by the POS software module based on communication with the mobile card reader, a secure session key;and performing, by the POS software module, using the generated secure session key, at least one of: encrypting data communicated to the mobile card reader;or decrypting data received from the mobile card reader.
  4. 14
    A mobile card reader comprising:a card interface to read information from a card;a processor coupled to the card interface;an interface to enable the mobile card reader to communicate with a mobile device;and a memory storing instructions that, when executed by the processor, cause the mobile card reader to perform operations including, when the mobile card reader is in communication with the mobile device: sending security related information of the mobile card reader to an application executing on the mobile device, the security related information for transmission by the mobile device to a remote server system;receiving from the application an indication that the application has been validated by the remote server system, the indication indicating that the remote server system has validated the security related information of the mobile card reader and security related information of the application;and in response to receiving the indication that the application has been validated by the remote server system, generating a secure session key with which to carry out encrypted communication between the application and the mobile card reader.
  5. 21
    A method comprising:sending, by a mobile card reader in communication with a mobile device via an interface, security related information of the mobile card reader to an application executing on the mobile device, the security related information for transmission by the mobile device to a remote server system;receiving, by the mobile card reader and from the application on the mobile device, an indication that the application has been validated by the remote server system, the indication indicating that the remote server system has validated the security related information of the mobile card reader and security related information of the application;and in response to receiving the indication that the application has been validated by the remote server system, generating, by the mobile card reader, a secure session key with which to carry out encrypted communication between the application executing on the mobile device and the mobile card reader. WSLEGAL\074889\00053\27514822v3 Date Reçue/Date Received 2022-11-18
  6. 28
    One or more non-transitory computer readable media storing instructions executable by a processor of a mobile card reader to cause the processor to perform operations comprising:determining that the mobile card reader is in communication with a mobile device via an interface;based at least on determining that the mobile card reader is in communication with the mobile device, sending security related information of the mobile card reader to an application executing on the mobile device, the security related information for transmission by the mobile device to a remote server system;receiving from the application an indication that the application has been validated by the remote server system, the indication indicating that the remote server system has validated the security related information of the mobile card reader and security related information of the application;and WSLEGAL\074889\00053\27514822v3 Date Reçue/Date Received 2022-11-18 in response to receiving the indication that the application has been validated by the remote server system, generating a secure session key with which to carry out encrypted communication between the application and the mobile card reader.