EP4167166A1

Method, device and secure element for conducting a secured financial transaction on a device

Abstract

A method of conducting a secured financial transaction on a device used as a payment terminal, the device comprising a central processing unit and a secure element, the method comprising: acquiring a purchase amount to be debited from a financial account; acquiring data relating to the financial account through the device; and obtaining a transaction authorization from a financial institution related to the financial account, the authorization being based, at least partially, on data processed solely by the secure element independently of data processed by the central processing unit; wherein the data processed solely by the secure element include at least a portion of the acquired data relating to the financial account.

EP4167166A1, drawing sheet 1
Sheet 1 of 18

Term

6.4 yearsto projected expiry

Projected expiry 28 February 2033, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

28 claims: 10 independent, 18 dependent

  1. 1
    A method of operating a mobile device used as a payment terminal, the mobile device being distinct from a dedicated payment terminal, the mobile device being configured to run a point of sale (POS) application and to operate a secure element, the mobile device comprising a central processing unit, a contactless interface and a communication interface, the method comprising:operating, by the secure element, a Europay, MasterCard, and Visa (EMV) transaction module at a second security level;acquiring, by the secure element, via the contactless interface of the mobile device, data associated with a payment apparatus, the EMV transaction module configured to process the data acquired via the contactless interface to provide processed data;operating, by the secure element, an operating system (OS) at a first security level, the OS configured to process the processed data provided by the EMV transaction module, wherein the first security level is different from the second security level;obtaining a transaction authorization from a remote financial server, the transaction authorization being based, at least partially, on data that is inaccessible to the central processing unit and processed by the secure element, wherein a security level of the secure element causes the data to be inaccessible to the central processing unit;and wherein the data that is inaccessible to the central processing unit and processed by the secure element include at least a portion of the data associated with the payment apparatus.
  2. 4
    The method of any of claims 1-3, wherein the at least the portion of the data associated with the payment apparatus being solely accessible by the secure element comprises payment credentials.
  3. 5
    The method of any of claims 1-4, further comprising identifying a start payment message applet from a payment control application, wherein the data associated with the payment apparatus is acquired based on the identification of the start payment message applet, and wherein the payment control application is operating at a third security level.
  4. 8
    The method of any of claims 1-7, further comprising:operating a first module to provide access to a hardware layer of the secure element;and operating a second module, the second module running on top of the first module.
  5. 9
    The method of any of claims 1-8, wherein the first security level comprises a first certification level, and wherein the second security level comprises a second certification level.
  6. 10
    The method of any of claims 1-9, wherein the data associated with the payment apparatus comprises data associated with a financial account.
  7. 11
    The method of any of claims 1-10, wherein the data associated with the payment apparatus is solely processed by the secure element independently of data processed by the central processing unit.
  8. 12
    A mobile device used as a payment terminal, the mobile device being distinct from a dedicated payment terminal, the mobile device being configured to run a point of sale (POS) application and to operate a secure element, the mobile device comprising a non-transitory computer readable storage medium comprising computer-executable instructions, a central processing unit, a contactless interface and a communication interface, the computer-executable instructions, upon execution, causing to execute:operating, by the secure element, a Europay, MasterCard, and Visa (EMV) transaction module at a second security level;acquiring, by the secure element, via the contactless interface of the mobile device, data associated with a payment apparatus, the EMV transaction module configured to process the data acquired via the contactless interface to provide processed data;operating by the secure element, an operating system (OS) at a first security level, the OS configured to process the processed data provided by the EMV transaction module, wherein the first security level is different from the second security level;obtaining a transaction authorization from a remote financial server, the transaction authorization being based, at least partially, on data that is inaccessible to the central processing unit and processed by the secure element, wherein a security level of the secure element causes the data to be inaccessible to the central processing unit;and wherein the data that is inaccessible to the central processing unit and processed by the secure element include at least a portion of the data associated with the payment apparatus.
  9. 15
    The mobile device of any of claims 12-14, wherein the at least the portion of the data associated with the payment apparatus being solely accessible by the secure element comprises payment credentials.
  10. 16
    The mobile device of any of claims 12-14, further comprising identifying a start payment message applet from a payment control application, wherein the data associated with the payment apparatus is acquired based on the identification of the start payment message applet, and wherein the payment control application is operating at a third security level.
  11. 17
    The mobile device of any of claims 12-16, wherein the computer-executable instructions, upon execution, cause to execute:operating a first module to provide access to a hardware layer of the secure element;and operating a second module, the second module running on top of the first module.
  12. 18
    The mobile device of any of claims 12-17, wherein the first security level comprises a first certification level, and wherein the second security level comprises a second certification level.
  13. 19
    The mobile device of any of claims 12-18, wherein the data associated with the payment apparatus comprises data associated with a financial account.
  14. 20
    The mobile device of any of claims 12-19, wherein the data associated with the payment apparatus is solely processed by the secure element independently of data processed by the central processing unit
  15. 21
    A computer readable storage medium comprising computer-executable instructions for execution by a mobile device used as a payment terminal, the mobile device being configured to run a point of sale (POS) application and to operate a secure element, the mobile device comprising a central processing unit, a contactless interface and a communication interface, the computer-executable instructions, upon execution, causing to execute:operating, by the secure element, a Europay, MasterCard, and Visa (EMV) transaction module at a second security level;acquiring, by the secure element, via the contactless interface of the mobile device, data associated with a payment apparatus, the EMV transaction module configured to process the data acquired via the contactless interface to provide processed data;operating by the secure element, an operating system (OS) at a first security level, the OS configured to process the processed data provided by the EMV transaction module, wherein the first security level is different from the second security level;obtaining a transaction authorization from a remote financial server, the transaction authorization being based, at least partially, on data that is inaccessible to the central processing unit and processed by the secure element, wherein a security level of the secure element causes the data to be inaccessible to the central processing unit;and wherein the data that is inaccessible to the central processing unit and processed by the secure element include at least a portion of the data associated with the payment apparatus.
  16. 24
    The computer readable storage medium of any of claims 21-23, wherein the at least the portion of the data associated with the payment apparatus being solely accessible by the secure element comprises payment credentials.