Updating mobile devices with additional elements
Abstract
The present disclosure is directed to a system and method for wirelessly accessing broadband services using intelligent cards. In some implementations, a broadband service card includes a physical interface, a communication module, secure memory, and service module. The physical interface connects to a port of a consumer host device. The communication module wirelessly receives RF signals from and transmits RF signals to a wireless broadband network. The secure memory stores user credentials used to securely authenticate the card and access a service foreign to the consumer host device through the wireless broadband network independent of the consumer host device. The user credentials are associated with a broadband service provider. The service module accesses the foreign service using the user credentials in response to at least an event and transmits a service request to the broadband service provider using the wireless broadband core network.
Term
2 yearsto projected expiry
Projected expiry 12 September 2028, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
1 claim: 1 independent, 0 dependent
- 1Claims Zastrzeżenia patentowe 1. A housing (102) for a mobile device, comprising:1. Obudowa (102) do urządzenia mobilnego, zawierająca: powierzchnie boczne ukształtowane, aby przylegać do co najmniej części jednej albo więcej powierzchni bocznych urządzenia mobilnego (106);side surfaces shaped to abut to at least a portion of one or more side surfaces of the mobile device (106);a rear surface formed to adhere to at least a portion of the back surface of the mobile device (106) and connected to the side surface, the side surfaces and the back surface forming an opening in which at least a portion of the mobile device (106) is placed, the first portion at least one surface comprises a connector (112) for connection to the port of the mobile device (106);a physical interface (110) included in at least one of the surfaces, and a circuit (114) configured to connect the physical interface (110) to the connector (112);and a transaction card (104) characterized by: powierzchnię tylną ukształtowaną, aby przylegać do co najmniej części tylnej powierzchni urządzenia mobilnego (106) oraz połączoną z powierzchnią boczną, przy czym powierzchnie boczne oraz powierzchnia tylna tworzą otwór, w którym umieszcza się co najmniej część urządzenia mobilnego (106), przy czym pierwsza część co najmniej jednej z powierzchni obejmuje złącze (112) do łączenia do portu urządzenia mobilnego (106);fizyczny interfejs (110) zawarty w co najmniej jednej z powierzchni, oraz obwód (114) skonfigurowany, aby łączyć fizyczny interfejs (110) do złącza (112);oraz kartę do transakcji (104) znamienna poprzez: a physical interface configured to connect to the port of the mobile device, the mobile device comprising a GUI graphical interface (116);a communication module configured to wirelessly receive radio frequency signals from and transmit radio frequency signals to the access terminal;fizyczny interfejs skonfigurowany, aby łączyć się do portu urządzenia mobilnego, przy czym urządzenie mobilne obejmuje Interfejs graficzny GUI(116);moduł komunikacyjny skonfigurowany, aby bezprzewodowo odbierać sygnały o częstotliwości radiowej z oraz nadawać sygnały o częstotliwości radiowej do terminala dostępowego;bezpieczną pamięć (1400) skonfigurowaną, aby przechowywać wiele wybieralnych danych uwierzytelniających użytkownika (714), przy czym dane uwierzytelniające użytkownika wykonują transakcje z terminalami dostępowymi oraz są powiązane z różnymi instytucjami;secure memory (1400) configured to store a plurality of selectable user credentials (714), wherein the user credentials perform transactions with access terminals and are associated with different institutions;a user interface module (704) configured to display and receive information via a graphical GUI (116) of the mobile host device;and a transaction module configured to dynamically switch between a plurality of selectable user credentials in response to at least an event and wirelessly transmit to the access terminal a response to a desired transaction including user credentials selected from a plurality of selectable user credentials. moduł użytkownik-interfejs (704) skonfigurowany, aby przedstawiać oraz odbierać informacje poprzez interfejs graficzny GUI(116) mobilnego urządzenia hosta;oraz moduł transakcji skonfigurowany, aby dynamicznie przełączać pomiędzy wieloma wybieralnymi danymi uwierzytelniającymi użytkownika w odpowiedzi na co najmniej zdarzenie oraz bezprzewodowo nadawać do terminala dostępowego odpowiedzi na żądaną transakcję obejmującą dane uwierzytelniające użytkownika wybierane z wielu wybieralnych danych uwierzytelniających użytkownika. 2. A housing according to claim 1. 1, wherein the physical interface (110) configured to receive the card for transaction (104) includes an SD (SecureDigital) or microSD (SD) card slot. 2. Obudowa według zastrz. 1, przy czym fizyczny interfejs (110) skonfigurowany, aby odbierać kartę do transakcji (104), zawiera gniazdo kart SD (ang. SecureDigital) albo microSD. 3. A housing according to claim 1. 1, wherein the transaction card (104) is integrated with the housing (102). 3. Obudowa według zastrz. 1, , przy czym karta do transakcji (104) jest zintegrowana z obudową (102). 4. A housing according to claim 1. 1, and circuit (114) further comprising a processing module (202) configured to convert signals between a form compatible with the transaction card (104) and a form compatible with the mobile device (106), optionally wherein the processing module (202) converts between the signal SD and a USB signal (Universal Serial Bus). 4. Obudowa według zastrz. 1, a obwód (114) ponadto zawierający moduł przetwarzania (202) skonfigurowany, aby konwertować sygnały pomiędzy postacią kompatybilną z karta do transakcji (104) oraz postacią kompatybilną z urządzeniem mobilnym (106), przy czym opcjonalnie moduł przetwarzania (202) konwertuje pomiędzy sygnałem SD a sygnałem USB (ang. Universal Serial Bus). 5. Housing according to claim 1. 1, wherein the connector (116) includes a first interface configured to connect to the port of the mobile device (106) and a second interface configured to substantially duplicate the original port of the mobile device (106). 5. Obudowa według zastrz. 1, przy czym złącze (116) obejmuje pierwszy interfejs skonfigurowany, aby łączyć się do portu urządzenia mobilnego (106) oraz drugi interfejs skonfigurowany, aby zasadniczo duplikować oryginalny port urządzenia mobilnego (106). 6. Housing according to claim 1, wherein the physical interface comprises at least one of an SD interface, a miniSD interface, a microSD interface, an MMC interface, a miniMMC, a microMMC, a firewire or an Apple iDock interface, or a USB interface. 6. Obudowa według zastrz. 1, przy czym fizyczny interfejs zawiera co najmniej jeden spośród interfejsu SD, interfejsu miniSD, interfejsu microSD, interfejsu MMC, miniMMC, microMMC, firewire albo interfejsu apple iDock, albo interfejsu USB. 7. A housing according to claim 1. 1, wherein the communication module performs the transaction independently of the mobile device (106). 7. Obudowa według zastrz. 1, przy czym moduł komunikacyjny wykonuje transakcję niezależnie od urządzenia mobilnego (106). 8. A housing according to claim 1. 1, wherein the secure memory (1400) stores multiple security frameworks (1406) for multiple user credentials (1402), and the communication module performs the requested transaction using a security framework from multiple security frameworks (1406) corresponding to the selected user credentials (1402). 8. Obudowa według zastrz. 1, przy czym bezpieczna pamięć (1400) przechowuje wiele szkieletów bezpieczeństwa (1406) dla wielu danych uwierzytelniających użytkownika (1402), a moduł komunikacyjny wykonuje żądaną transakcję wykorzystując szkielet bezpieczeństwa z wielu szkieletów bezpieczeństwa (1406) odpowiadających wybranym danym uwierzytelniającym użytkownika (1402). 9. Housing according to claim 1, wherein the user interface module (704) shows information associated with the requested transaction via the GUI (116) GUI of the mobile device;optionally wherein the information provided is based, at least in part, on at least one real-time content during the transaction, locally stored offline content, or online content associated with the financial institution;or wherein the user interface module (704) is further configured to present a user identification request comprising at least one of a Personal Identification Number, a user ID and password, or a biometric signature via a GUI (116) Graphics Interface of the mobile device, wherein the processing module in addition, it is configured 9. Obudowa według zastrz. 1, w której moduł użytkownikinterfejs (704) przedstawia informacje powiązane z żądaną transakcją poprzez Interfejs graficzny GUI (116) urządzenia mobilnego;opcjonalnie w której przedstawione informacje oparte są, co najmniej częściowo, na co najmniej jednej zawartości w czasie rzeczywistym podczas transakcji, lokalnie przechowywanej zawartości offline, albo zawartości online powiązanej z instytucją finansową;albo w której moduł użytkownik-interfejs (704) ponadto skonfigurowany jest, aby przedstawiać żądanie identyfikacji użytkownika obejmujące co najmniej jeden spośród Osobistego numeru identyfikacyjnego, ID użytkownika oraz hasła, albo biometrycznego podpisu poprzez Interfejs graficzny GUI (116) urządzenia mobilnego, przy czym przetwarzający moduł ponadto skonfigurowany jest, aby weryfikować podane ID użytkownika z ID użytkownika przechowywanym lokalnie w bezpiecznej pamięci przed wykonaniem żądanej transakcji. 10. A housing according to claim 1. 1, wherein the communication module selectively switches the radio frequency antenna between the active state and the inactive state in response to at least an event. 10. Obudowa według zastrz. 1, przy czym moduł komunikacyjny selektywnie przełącza Antenę częstotliwości radiowej pomiędzy stanem aktywnym a stanem nieaktywnym w odpowiedzi na co najmniej zdarzenie. 11. Obudowa według zastrz. 1, przy czym bezprzewodowe sygnały o częstotliwości radiowej zawierają co najmniej jedne spośród bezstykowych sygnałów, zbliżeniowych sygnałów, sygnałów NFC bliskiego zasięgu, sygnałów Bluetooth, sygnałów UWB, albo sygnałów RFID. 11. The housing of claim 1 The apparatus of claim 1, wherein the wireless radio frequency signals comprise at least one of contactless signals, proximity signals, short range NFC signals, Bluetooth signals, UWB signals, or RFID signals. 12. Housing according to claim 1. 1, wherein the communication module further comprises a protocol translation module further configured to convert signals between wireless protocols compatible with individual terminals and the internal transaction application. 12. Obudowa według zastrz. 1, przy czym moduł komunikacyjny ponadto zawiera moduł translacji protokołów ponadto skonfigurowany, aby przekształcać sygnały pomiędzy bezprzewodowymi protokołami kompatybilnymi z pojedynczymi terminalami oraz wewnętrzną aplikacją transakcji. 13. Housing according to claim 1. 1, further comprising a cryptographic module configured to decrypt the received signals prior to processing by the transaction module and to encrypt at least a portion of the transaction responses prior to wireless transmission. 13. Obudowa według zastrz. 1, ponadto zawierająca moduł kryptograficzny skonfigurowany, aby deszyfrować odebrane sygnały przed przetwarzaniem przez moduł transakcji oraz szyfrować co najmniej część odpowiedzi transakcji przed bezprzewodową transmisją. 14. Housing according to claim 1 1, further comprising an authentication module configured to authenticate at least one of the mobile device network of the host, mobile device, or user. 14. Obudowa według zastrz. 1, ponadto zawierająca moduł uwierzytelniania skonfigurowany, aby uwierzytelniać co najmniej jedno spośród sieci mobilnego urządzenia hosta, urządzenia mobilnego, albo użytkownika. 15. Housing according to claim 1. 1, further comprising an initial charging module configured to perform one or more authentication processes in response to at least a connection to the port of the mobile device. 15. Obudowa według zastrz. 1, ponadto zawierająca moduł ładowania początkowego skonfigurowany, aby wykonywać jeden albo więcej procesów uwierzytelniania w odpowiedzi na co najmniej podłączenie do portu urządzenia mobilnego. 16. Obudowa według zastrz. 1, ponadto zawierająca moduł aktywacyjny skonfigurowany, aby aktywować dostęp do danych uwierzytelniających użytkownika z wielu wybieralnych danych uwierzytelniających użytkownika oraz nadawać do powiązanej instytucji finansowej żądania, aby aktywować powiązane konto użytkownika. 16. The housing of claim 1. 1, further comprising an activation module configured to activate access to user credentials from a plurality of selectable user credentials and transmit to the associated financial institution the request to activate the associated user account. 17. Housing according to claim 1 1, wherein the transaction module is further configured to receive user selections via a GUI graphical interface (116) for different user accounts associated with multiple selectable user credentials. 17. Obudowa według zastrz. 1, przy czym moduł transakcji ponadto skonfigurowany jest, aby odbierać wybory użytkownika poprzez Interfejs graficzny GUI (116) dla różnych kont użytkownika powiązanych z wieloma wybieralnymi danymi uwierzytelniającymi użytkownika. 18. Housing according to claim 1. 1, and the communication module further configured to receive requests to update multiple selectable user credentials (1402) via a wireless connection to a core cellular network or a wired connection to a broadband network, and optionally further configured to at least add new user credentials or delete existing user credentials based on at least partially update requests. 18. Obudowa według zastrz. 1, a moduł komunikacyjny ponadto skonfigurowany, aby odbierać żądania do aktualizacji wielu wybieralnych danych uwierzytelniających użytkownika (1402) poprzez połączenie bezprzewodowe z rdzeniową siecią komórkową albo połączenie przewodowe z siecią szerokopasmową oraz opcjonalnie ponadto skonfigurowany, aby co najmniej dodawać nowe zestawy danych uwierzytelniających użytkownika albo usuwać istniejące dane uwierzytelniające użytkownika w oparciu o co najmniej częściowo żądania aktualizacji. 19. Housing according to claim 1 1, wherein the plurality of user selectable credentials (1402) includes default user credentials, the communication module is further configured to switch to the default user credentials in response to at least completing the requested transaction using different of the plurality of user selectable credentials;or the plurality of user selectable credentials (1402) includes default user credentials, the security module is further configured to switch to default user credentials in response to at least the expiration of the time period to complete the transaction using non-default user credentials;19. Obudowa według zastrz. 1, przy czym wiele wybieralnych danych uwierzytelniających użytkownika (1402) obejmuje domyślne dane uwierzytelniające użytkownika, moduł komunikacyjny ponadto skonfigurowany jest, aby przełączać się na domyślne dane uwierzytelniające użytkownika w odpowiedzi na co najmniej ukończenie żądanej transakcji z wykorzystaniem różnych z wielu wybieralnych danych uwierzytelniających użytkownika;albo wiele wybieralnych danych uwierzytelniających użytkownika (1402) obejmuje domyślne dane uwierzytelniające użytkownika, moduł zabezpieczający ponadto skonfigurowany jest, aby przełączać się na domyślne dane uwierzytelniające użytkownika w odpowiedzi na co najmniej wygaśnięcie okresu czasu do ukończenia transakcji z wykorzystaniem nie-domyślnych danych uwierzytelniających użytkownika;albo wiele wybieralnych danych uwierzytelniających (1402) jest ładowanych do bezpiecznej pamięci (1400) z różnych instytucji. DOCUMENTS PROVIDED IN THE DESCRIPTION DOKUMENTY PRZYTOCZONE W OPISIE Lista przytoczonych przez Zgłaszającego dokumentów została zamieszczona wyłącznie do informacji czytelnika i nie stanowi części składowej europejskiego dokumentu patentowego. Została ona zestawiona z największą starannością;EUP nie ponosi jednakże żadnej odpowiedzialności za ewentualne błędy lub braki. The list of documents cited by the Applicant is provided only to the reader's information and is not a part of the European patent document. It was combined with the utmost care;The EUP is not liable for any errors or omissions, however. Literatura patentowa przytoczona w opisie Patent literature cited in the description 1/16 1/16 2/16 2/16 3/16 3/16 4/16 4/16 5/16 5/16 6/16 6/16 INSTYTUCJA g THE INSTITUTION g INSTITUTION INSTYTUCJA INSTITUTION INSTYTUCJA NETWORK OF A RADIO AREA SIEĆ OBSZARU RADIOWEGO CELL CORE NETWORK KOMÓRKOWA SIEĆ RDZENIOWA 7/16 7/16 8/16 8/16 9/16 9/16 ΖΖΖΖΖ3 θ ' ΖΖΖΖΖ3 θ' 1406a 1406b 1406c 1408 1406a 1406b 1406c 1408 10/16 10/16 11/16 11/16 12/16 12/16 13/16 13/16 14/16 14/16 15/16 15/16 16/16 16/16
208 paragraphs in 2 sections, as filed
TECHNICAL FIELD [0002] The invention relates to mobile devices and, more particularly, to updating devices using additional elements.
mobile
BACKGROUND [0003] Portable electronic devices and tokens have become an integral part of the daily experience of the user. There is a wide range of popular handheld and portable devices that users have in their possession, including communication, business and entertainment devices such as mobile phones, music players, digital cameras, smart cards, memory tokens and a variety of possible combinations of the above devices and tokens. All of these devices have a common feature such that the consumer is accustomed to wearing them most of the time and to most places. This is appropriate for various demographic and age groups regardless of the level of consumer eccentricity, their age group, their technical level or origin.
[0004] These shared mobile devices offer opportunities for expanding memory. MicroSD (Micro Secure Digital) is a popular interface for high-end mobile phones while some models of SD and MMC (MultiMediaCard) interfaces are also available. MicroSD is the least common one supported by most of these devices and tokens (in terms of size). In addition, adapters for converting microSD to miniSD, SD, MMC and USB are available. Although the most popular MP3 player (iPod) offers its own interface, and competing solutions offer standard interfaces. Digital cameras mainly offer SD and MMC, while xD (extreme digital) has a different option. Micro and mini versions of these interfaces are also available in several models. Mini-USB is increasingly available on phones,
[0005] US 2006/0291483 describes a cellular telephone gateway and communication device (MPG) which is connected via an electrical signal transmission carrier to a telephone operating in a first communication network in accordance with a first communication protocol, to add communication functions for at least a second one. message on the network, according to the second communication protocol. The mobile communication system is also described. The system includes MPG placed between the mobile phone and the battery and the Subscriber Identification Module. MPG connects to the SIM card interface of the mobile phone through which it includes the SIM management functions and controls the connections. It connects to the data / signaling interface of the phone, using it for communication,
[0006] US 2003/0064689 describes a replaceable housing equipped with one or more I / O ports and complementary electronics to add one or more I / O ports to a mobile device into which a replaceable housing is attached. In various embodiments, the I / O ports may include a mouse PS / 2 port, a serial port, a parallel port, a serial bus port, and so on. In various embodiments, the supplemental electronics are packaged in ASICs with output pins similar to those of the smart card, which may include a properly equipped protocol processor for unpacking and packaging data input / generated in accordance with selected I / O protocols. In one embodiment, the housing is U-shaped. In the wireless form of the cellular phone,
[0007] US Patent No. 6,970,130 B1 discloses a navigation device for removably connecting to and providing navigation capabilities to a portable handheld computing device. The navigation device includes a navigation receiver for receiving navigation signals from a plurality of sources; a processor coupled to the navigation receiver to determine the position of the navigation device as a function of the received beacon signals; and interface / connector.
SUMMARY [0008] The invention relates to a housing for a mobile device in accordance with claim 1. Preferred embodiments are described in dependent claims 2 - 19.
[0009] The details of one or more embodiments of the invention are set forth in the accompanying drawings and the description below. Other features, objectives and advantages of the invention will become apparent from the description and drawings, and from the claims.
DESCRIPTION OF THE DRAWINGS [0010] FIG. 1 is an example of a system update in accordance with some disclosure implementations;
FIG. 2A to 2C show section views of some implementations of the housing of Fig. 1;
FIG. 3A and 3B illustrate an example of the seats in the housing of Fig. 1;
FIG. 4 shows an example of the housing converter module of Fig. 1;
FIG. 5 is an example of a transaction system that broadcasts transaction information;
FIG. 6 is an example of a transaction system that transmits transaction information via a cellular network;
FIG. 7 is an example of the transaction card of Fig. 5 in accordance with some implementations of the disclosure;
FIG. 8 is an example of a smart card that selectively switches the antenna;
FIG. 9 is another example of a transaction system;
FIG. 10 is a diagram depicting the processes of personalizing smart cards;
FIG. 11 is a diagram illustrating an example of a method for initializing a smart card;
FIG. 12 is an example of a connection diagram showing connection sessions with a smart card;
FIG. 13 is a diagram illustrating an example of a method for activating a transaction card;
FIG. 14 is an example of a secure smart card memory for storing multiple user credentials; and
FIG. 15 is a diagram illustrating an example of a method for dynamically switching between user accounts.
[0011] Similar references in various drawings indicate similar elements.
DETAILED DESCRIPTION [0012] FIG. 1 is a block diagram illustrating an example of a mobile device expansion system 100, e.g. an iPhone, through additional external devices using a housing for a mobile device. For example, the system 100 may add an external microSD slot for a mobile host device, e.g. an iPhone, using a flexible casing that includes at least a portion of the mobile device and connects to the port of the mobile device. In addition to the microSD, the system 100 may add an external device memory to the mobile device using other interfaces such as, for example, MMC (MultiMediaCard), SD, miniSD, Firewire, and / or others. By adding an external device (e.g., memory, transaction cards), the system 100 can update the mobile device, which does not include expansion slots with additional external devices, the dimensions of the device being maintained. For example, the housing can increase dimensions by 5 percent or less. In other words, the housing can add device slots to the mobile device while maintaining essentially original attributes, such as speaker outputs, network signal strength, headphone ports, battery charging, docking ports, and others. In some implementations, the system 100 may update a mobile device with an external device memory, a transaction card, and / or other devices. For example, a smart card can wirelessly perform transactions with various enterprises using a single smart card and independent mobile host devices. In other words, a single intelligent card contained in the housing can perform a payment transaction with a financial institution, gain access to control the transaction with the enterprise network, conduct a ticket purchase transaction from a transport company and / or identity validation transaction with a government agency. In such implementations, each transaction can securely identify the user and user privileges for services received from different enterprises. Thanks to this, the housing including a smart card can act as a logical wallet. In some of these implementations, the housing may include a circuit that converts signals between a form compatible with the external memory of the device (e.g., microSD) and a form compatible with the mobile device (e.g., USB). Additionally,
[0013] At an advanced level, the system 100 includes a housing 102, an external device 104, a mobile device 106 and a network 108. The housing 102 includes a socket 110 for connecting to an external device 104, a connection 112 for connecting to a mobile device 106, and a communication circuit 114 connecting the socket 110, the antenna 115 to amplify the transmission and receiving RF signals, and the connector 112. The housing 102 can update the mobile device 106 with the external device 104. In addition, the housing 102 includes at least a portion of the mobile device 106. When the mobile device 106 is included, the housing 102 may include other aspects that discover the ports of the mobile device 106 for connecting to external peripheral devices such that the housing 102 does not substantially interfere with such connections. In other words, the housing 102 may either include ports substantially aligned with the ports of the mobile device 106 or have openings that allow substantially unrestricted access to the original ports of the device 106 (see FIG 2C). The mobile device 106 may be communicatively connected to the network 108. The mobile device 106 includes a graphical GUI interface 116 for presenting information to and / or receiving information from users.
[0014] The enclosure 102 may include any software, hardware, and / or firmware configured to update the mobile device 106 from one or more external device slots. For example, the housing 102 may include a microSD slot and a physical interface for connecting to the port of the mobile device. In this example, the housing 102 can connect the microSD slot to the mobile device 106 using a physical interface. In some implementations, the housing 102 may include one or more of the following: one or more sockets for an external device (e.g., memory, wireless transaction cards); one or more connectors that connect to the mobile device 106; one or more circuits for connecting one or more sockets to one or more connectors; processing module, which converts signals between different formats; a biometric reader that determines the biometric devices charging, user information of the mobile device 106; and / or other elements. In some implementations, the housing 102 may be formed of a flexible material such as, for example, silicone rubber, soft neoprene, and / or other material. The aperture formed by the housing 102 may be substantially the same or smaller than the dimensions of the mobile device 106. For hole sizes that are smaller, the housing 102 may be slightly adjusted to overlap the mobile device 106. The housing 102 may substantially retain the attributes of the mobile device. 106, such as size, availability of peripheral device provision, battery life, signal strength, access to the display and all other external devices, connections to the wireless network if there is, the possibility of connecting to a PC if it is, and any other properties provided by the device. While maintaining the attributes, the added functionality may not impair the operation of the device, which is certified by regulatory authorities (eg, FCC) and does not violate the warranty issued for the device 106.
[0015] In the implementation shown, the housing 102 includes a socket 110, a connector 112 and a circuit 114. The socket 110 can comprise MMC, miniMMC, microMMC, SD, miniSD, microSD, and / or other sockets. The socket 110 may include an opening such that the outer device 104 may be inserted into the housing 102 upon insertion of the mobile device 106. In some implementations, the socket 110 may be formed on the back surface such that the housing 102 is removed or at least a portion moved from the device surface mobile 106 to insert an external device 104. In some implementations, socket 110 and external device 104 are integrated in housing 102, and in this case, external device 104 may not be removed without damaging the housing 102. Connector 112 includes at least a portion that Connects to the port of the mobile device 106. The connector 112 may include USB, iDock, microUSB, Firewire, serial port, and / or other connectors offered by the mobile device 106. In some implementations, the connector 112 may include a first interface for connecting to the mobile device 106 and a second interface for connecting to an external device . The second interface may be substantially similar in size and interface capabilities to the original connector of the mobile device 106. In these examples, the connector 112 may transmit one or more signals from an external device to the mobile device 106 without, for example, interference in connection to the external device 104. For example, the connector 112 may include a second interface that connects to a power source of the mobile device 106 and transmits a signal to the charging mobile device 106. Circuit 114 may include any software, hardware, and firmware for communicating connection of socket 110 to connector 112. For example, circuit 114 may include one or more wire connections between socket 110 and connector 112. In addition, circuit 114 may also include an antenna amplifier, which may enhance the reception capabilities of the mobile device 106 and / or the reception capabilities of wireless cards for transactions inserted into the socket 110 (see FIG 2A). In some implementations, the circuit 114 may perform one or more of the following: transmit signals between the socket 110 and the connector 112; convert or otherwise convert signals between forms compatible with an external device 104 and forms compatible with a mobile device 106; detecting biometric user information of the mobile device 106; manage access to external device 104 based on at least partially detected biometric information; amplify the signal reception of the host device through an integrated antenna amplifier; amplify the reception of the wireless card signal for the transaction put into the slot; provide access to the software and system on the device inserted in the socket for the application located on the mobile device; and / or other processes. provide access to the software and system on the device inserted in the socket for the application located on the mobile device; and / or other processes. provide access to the software and system on the device inserted in the socket for the application located on the mobile device; and / or other processes.
[0016] The external device 104 may include any software, hardware, and / or firmware configured to update the mobile device 106 with one or more features and / or functions. For example, the external device 104 may include a fixed memory (e.g., flash, EEPROM) for storing information received, e.g., from the mobile device 106. The external device 104 may update the mobile device 106, e.g., an external memory, a wireless transaction card. , a receiver-transmitter, a broadband transceiver, and / or other elements. With respect to the memory, the external device 104 may be a Flash or memory packet, which is a nonvolatile memory that can be electrically erased and re-programmed. The external device 104 may be a memory card, USB Flash Drive and / or other storage device. For example, the external device 104 may include an EEPROM (EEPROM) which is erased and programmed in blocks. With respect to memory cards, external device 104 may be MMC, microMMC, miniMMC, SD, microSD, miniSD, Memory Stick, Mamory Stick Duo, xD-Picture card, SDHC (Secure Digital High Capacity), and / or other card memory. In some implementations, the external device 104 may include a memory having a capacity between 1MB and 1TB. Alternatively or additionally, the external device 104 may be a transaction card as discussed with reference to FIG. 5 to 14. In these implementations, the external card 104 may wirelessly perform transactions with, for example, a device sales point. In some implementations, the external card 104 is integrated in the housing 102. The external card 104 may store user credentials for the credit card, debit card, prepaid card, gift card, account check, and / or other user accounts. In addition, the smart card can also store user credentials for other applications such as loyalty (points for purchases), airline (access to clubs, check-ins), state (driving license), membership (clubs) and / or other, where user credentials they are used to identify the user so that he can deliver goods and / or services. By storing multiple user credentials in a single external card 104, the system 100 can perform transactions with various institutions without requiring multiple instruments, as discussed in more detail with reference to FIG. 5-14.
[0017] The mobile device 106 includes an electronic device operating with an interface from the housing 102 using one or more ports. For example, the mobile device 106 may have an iDock port that connects to the housing 102. In this disclosure, the mobile device 106 includes cell phones (e.g., iPhone), other phones, pagers, portable computers, SIP phones, smartphones, palmtops. (PDAs), digital cameras, MP3 players, video cameras, which one or more processors or other devices, or any other suitable processing devices may transmit information from the enclosure 102 through one or more ports and may not have another slot for the outer card 104, which could be directly connected. One or more ports may include, for example, a USB port, an iDockt port, a FireWire port, a serial port and / or any other interface port provided by the mobile device for connection to peripheral devices, and / or other ports. In some implementations, the mobile devices 106 may be based on cellular radio technology. For example, the mobile device 106 may support the PDA to wirelessly connect to an external or unsecured network. In another example, the mobile device 106 may include a digital media player that includes an input device, such as a keyboard, jog wheel, jog wheel, touch screen, or other device that can receive information or select user interface elements, and an output device, which transforms information associated with the system 100, including digital data, visual information, or GUI 116.
The GUI 116 includes a GUI graphic interface operable to allow the user of the mobile device 106 to connect at least to the part of the system 100 for any suitable purposes, such as performing transactions and / or presenting transaction history. In general, the GUI 116 provides a specific user with an efficient and user-friendly representation of data provided by or communicated in the system 100 and / or also efficient and user-friendly elements so that he can manage the settings himself and gain access to the services offered by the institutions. The GUI 116 may comprise a plurality of personalized frames or views with interactive fields, sliding lists, and / or buttons operated by the user. The term graphical GUI interface can be used in singular or plural number, to describe one or more graphical user interfaces and each of the displays of a particular graphical user interface. The GUI 116 may include any graphical user interface such as a generic web browser or touch screen that processes information in the system 100 and presents the results to the user. [0019] The network 108 allows wireless or wire communication between the institution and any other local or remote computer, such as a mobile device 106. The network 108 may be a whole or part of the enterprise or a secure network. While a single network is depicted, the network 108 may be a contiguous network logically subdivided into different subnets or virtual networks without departing from the scope of the disclosure, as soon as at least a part of the network 108 may allow communication with the mobile device 106. In some implementations, the network 108 includes any internal or external network, network, sub-network, or a combination thereof operable to allow communication between the various components in the system 100. 108 may communicate, for example, IP (Internet Protocol) packets, Frame Relay frames, Asynchronous Transfer Mode (ATM), voice, image, data, and other relevant information between the network addresses. The network 108 may comprise one or more LANs), RAN, MAN, WAN, all or part of a global computer network known as the Internet, and / or any other communication systems or systems in one or more locations. the network 108 includes any internal or external network, network, sub-network, or a combination thereof operable to allow communication between the various components in the system 100. The network 108 may communicate, for example, IP (Internet Protocol) packets, Frame Relay frames. , ATM (Asynchronous Transfer Mode), voice, image, data, and other relevant information between network addresses. The network 108 may comprise one or more LANs), RAN, MAN, WAN, all or part of a global computer network known as the Internet, and / or any other communication systems or systems in one or more locations. the network 108 includes any internal or external network, network, sub-network, or a combination thereof operable to allow communication between the various components in the system 100. The network 108 may communicate, for example, IP (Internet Protocol) packets, Frame Relay frames. , ATM (Asynchronous Transfer Mode), voice, image, data, and other relevant information between network addresses. The network 108 may comprise one or more LANs), RAN, MAN, WAN, all or part of a global computer network known as the Internet, and / or any other communication systems or systems in one or more locations. Frame Relay frames, ATM (Asynchronous Transfer Mode), voice, image, data, and other relevant information between network addresses. The network 108 may comprise one or more LANs), RAN, MAN, WAN, all or part of a global computer network known as the Internet, and / or any other communication systems or systems in one or more locations. Frame Relay frames, ATM (Asynchronous Transfer Mode), voice, image, data, and other relevant information between network addresses. The network 108 may comprise one or more LANs), RAN, MAN, WAN, all or part of a global computer network known as the Internet, and / or any other communication systems or systems in one or more locations.
[0020] FIG. 2A to 2C are sectional views of the housing 102 of Fig. 1. In particular, the views show housing members 102 that at least extend the mobile device 106 with the card 104. In FIG. 2A, the housing 102 includes a port-to-card converter module 202 (e.g., USB-microSD), a reader 204, and an antenna 206. The converter module 202 can include any software, hardware, and / or firmware that converts between convertible signals and signals. compatible with the mobile device 106. In the example shown, the converter module 202 converts between SD signals and USB signals. The reader 204 may include any software, hardware, and / or firmware that verifies or otherwise specifies the user information information such as biometric information. In the example shown, the reader 204 determines the fingerprints of the user and can verify if the user has access to the card 104. In addition, the reader 204 can transfer biometric information to the application on the mobile device 106 (via the converter 202 and / or the connector), for example, to securely verify the identity of the holder devices. Host mobile device 106 may include biometric identity verification for applications such as mobile banking. In some implementations, the application may use a biometric reader 204 to first register the biometric identity of the user at the First use and then match the biometric identities of the identity holder. the reader 204 may transmit biometric information to the application on the mobile device 106 (via the converter 202 and / or the connector), for example, to securely verify the identity of the device holder. Host mobile device 106 may include biometric identity verification for applications such as mobile banking. In some implementations, the application may use a biometric reader 204 to first register the biometric identity of the user at the First use and then match the biometric identities of the identity holder. the reader 204 may transmit biometric information to the application on the mobile device 106 (via the converter 202 and / or the connector), for example, to securely verify the identity of the device holder. Host mobile device 106 may include biometric identity verification for applications such as mobile banking. In some implementations, the application may use a biometric reader 204 to first register the biometric identity of the user at the First use and then match the biometric identities of the identity holder.
devices
Secure registered biometric storage of biometric user identity can be provided by removable secure card 104 or can be located in a special secure memory integrated with the housing. For example, when the user changes the device 106, the identity cover can be deleted from the first device (if the housing 102 and the card 104 are removed). In addition, another application operating on the CPU 102 may also use biometric data to secure access to specific properties and / or services. The antenna 206 may wirelessly transmit and receive RF signals associated with the card 104. In transaction-card implementations, the antenna 206 may extend the range of the transaction card 104 to perform wireless transactions. FIG. 2B is another representation of the section view of the housing 102. In this view, the connector 208 of the mobile device 106 is illustrated. For example, the connector 208 may be an iDock iPhone connector having 30 pins. FIG. 2C is yet another cross-sectional view of the housing 102. In this view, the housing 102 includes openings 214A and 214B for the loudspeakers included with the mobile device 106 and selecting 212 for connecting power to the connector 112 and connector 208. In this case, the mobile device 106 can be charged using the 208 connector without removing the housing 102.
[0021] FIG. 3A and 3B show different implementations of socket 110. In FIG. 3A, the socket 110 may be formed in the housing 102 such that the card 104 may be inserted and removed without lifting or otherwise removing at least a portion of the housing 102. FIG. 3B, the seat 110 is formed within the housing 102 such that the housing is at least partially lifted or otherwise removed to insert and remove the card 104.
[0022] FIG. 4 shows some implementations of the conversion module 202 that converts between USB and SD signals. As shown, the conversion module 202 may receive a plurality of input data associated with the card 104 and convert the signals into a form compatible with the connector 208 of the mobile device 106. In some implementations, the conversion module 202 may convert, e.g., between data formats. In some implementations, the conversion module 202 may transmit input data to corresponding outputs such as VDD and GND.
[0023] FIG. 5 is a block diagram illustrating an example of a transaction system 500 for wirelessly performing transactions with various enterprises using a single smart card. For example, system 500 may include a single microSD card that performs transactions with various enterprises (e.g., financial institutions) independently of the mobile host device. For example, a single microSD card can perform a payment transaction with a financial institution, an access control transaction with an enterprise network, a ticket purchase transaction from a transport company, and / or an identity verification transaction with a government agency. In such implementations, each transaction can securely identify the user and user privileges with respect to services provided by various enterprises. In addition to the microSD, the system 500 may include other storage interfaces that connect the smart card to the host device such as, for example, MMC, SD, USB, Firewire, and / or others. The host device may include a mobile phone, a smartphone, a PDA, an MP3 device, a digital camera, a camcorder, a client, a computer, and / or another device that includes, for example, a mass storage interface. In some implementations, the smart card can be a card that is inserted into the host device and performs transactions independently of the host device. In performing the transaction, the smart card can use a dual interface that connects the host device via a physical interface (e.g., SD, MMC, USB) and external devices via a wireless connection (e.g., NFC, ISO 14443, Bluetooth). The smart card can control or otherwise operate one or more hardware components of a mobile host device (e.g., display, cellular radio technology) using a physical interface and wirelessly communicate with the access terminal using a wireless interface. In some implementations, a smart card includes multiple user credentials with each set of identities associated with different institutions. For example, a smart card may store user credentials for a credit card, debit card, prepaid card, gift card, account check, and / or other user accounts. In addition, the smart card can also store user credentials for other applications such as loyalty (points for purchases), (access to clubs, check-in), state (driving license), membership (clubs) and / or others where the user's credentials are used to identify the user so that he can deliver the goods and / or services. By storing multiple user credentials in a single external card 104, system 500 can perform transactions with various institutions without requiring multiple instruments. In other words, a single smart card may act as a logical wallet that locally stores information for different user accounts and switches between different user accounts in response to at least an event. By providing a smart card, the system 500 can wirelessly perform transactions with institutions without requiring additional hardware or software, and / or firmware and / or without requiring changes to existing hardware, software, and / or firmware for the reader terminals to enable the user to perform transactions wirelessly. In addition, the system 500 may eliminate, minimize or otherwise limit the number of instruments a person has to perform transactions using different user accounts. In other words, the smart card can act as many different instruments, but can be implemented as a single device. what a person has to perform transactions using different user accounts. In other words, the smart card can act as many different instruments, but can be implemented as a single device. what a person has to perform transactions using different user accounts. In other words, the smart card can act as many different instruments, but can be implemented as a single device.
At a higher level, the system 500 includes offline storage 502 and clients 504a and 504b connected to the institution 506 via the network 108. Although not shown, the system 500 may include several intermediary parties between the institution 506 and the network such as, for example, the transaction buyer and / or a network payment host. Offline storage 502 includes a mobile device 106a having a transaction card 104a and a sales point (POS) of the device 514 that performs transactions with clients. Access point 514 includes a graphical GUI interface 509 for presenting information to and / or receiving information from users. In some implementations, the ACCESS POINT 514 may send a request to perform transactions to the transaction card 104. The transaction card 104 may transmit transaction information to an ACCESS POINT 514. The client 504 includes a GUI 515 for displaying information associated with the system 500. The client 504a includes a card reader 516 that connects the card to transaction 104c with a client 504a. Institution 506 may authenticate a transaction based on at least partial information transmitted by the transaction card 104. The mobile device 106 includes a GUI 116 to display information associated with the financial transaction.
[0025] Enterprise 502 is generally at least part of an enterprise having a physical presence (e.g., building) for operation. For example, enterprise 502 may sell goods and / or services from a physical location (e.g., physical storage) directly to customers. In this example, enterprise 502 buys or otherwise receives goods (e.g., produces) from distributors (not shown) and then can sell these goods to customers, such as users of a mobile device 106. In general, company 502 may offer face-to-face sales customers when delivering goods and / or services. For example, enterprise 502 may be a virtual warehouse so that the user selects a good or service using the Internet and acquires and receives goods or services in the enterprise 502. The company 502 may provide one or more of the following services related to goods: inventories, storage, distribution, and / or transport. As a result, the company 502 may not be able to immediately distribute the goods received from the distributors. The company 502 may comprise a single retail building, one or more buildings in a single geographical location, and / or a plurality of geographically dispersed buildings. In some cases, two or more entities may represent part of the same legal entity or branch. For example, company 502 and distributors may be branches of one enterprise. In summary, company 502 can wirelessly perform financial transactions with a mobile device 106. stocks, storage, distribution, and / or transport. As a result, the company 502 may not be able to immediately distribute the goods received from the distributors. The company 502 may comprise a single retail building, one or more buildings in a single geographical location, and / or a plurality of geographically dispersed buildings. In some cases, two or more entities may represent part of the same legal entity or branch. For example, company 502 and distributors may be branches of one enterprise. In summary, company 502 can wirelessly perform financial transactions with a mobile device 106. stocks, storage, distribution, and / or transport. As a result, the company 502 may not be able to immediately distribute the goods received from the distributors. The company 502 may comprise a single retail building, one or more buildings in a single geographical location, and / or a plurality of geographically dispersed buildings. In some cases, two or more entities may represent part of the same legal entity or branch. For example, company 502 and distributors may be branches of one enterprise. In summary, company 502 can wirelessly perform financial transactions with a mobile device 106. The company 502 may comprise a single retail building, one or more buildings in a single geographical location, and / or a plurality of geographically dispersed buildings. In some cases, two or more entities may represent part of the same legal entity or branch. For example, company 502 and distributors may be branches of one enterprise. In summary, company 502 can wirelessly perform financial transactions with a mobile device 106. The company 502 may comprise a single retail building, one or more buildings in a single geographical location, and / or a plurality of geographically dispersed buildings. In some cases, two or more entities may represent part of the same legal entity or branch. For example, company 502 and distributors may be branches of one enterprise. In summary, company 502 can wirelessly perform financial transactions with a mobile device 106. enterprise 502 and distributors may be branches of one enterprise. In summary, company 502 can wirelessly perform financial transactions with a mobile device 106. enterprise 502 and distributors may be branches of one enterprise. In summary, company 502 can wirelessly perform financial transactions with a mobile device 106.
[0026] The transaction card 104 may include any software, hardware, and / or firmware configured to wirelessly execute transactions from the access point 514 using one of the plurality of selectable user accounts. For example, the transaction card 104 may select user credentials associated with one of the plurality of selectable user accounts (e.g., financial accounts) and perform a contactless transaction from the access point 514 using the selected account and the independent mobile device 106a. In other words, the transaction card 104 can perform transactions wirelessly without the aspects of transactions performed by the mobile device 106. In addition, the transaction card 104 can store user credentials and / or applications locally (e.g., a payment application, access applications) for many selectable user accounts. The transaction card 104 may dynamically switch between user credentials and payment applications in response to at least an event. The switching event may include user selection via GUI 116, Transaction completion, detection of signal type, determination of transaction type (e.g., purchase of clothes, groceries), change of geographical area (e.g., GPS), and / or other events. Different user accounts may include a credit card account (e.g., Visa, MasterCard), merchant account (e.g., Target, Dillard), prepaid card, gift card, bank card (e.g., Bank of America), airline card, ID card , driving license, and / or other. In some implementations, the transaction card 104 may include user credentials for any combination of financial, retail, airline, corporate, state and / or other accounts. In some implementations, the transaction card 104 may locally store applications for multiple selectable user accounts. For example, the transaction card 104 may execute different applications for each of the other user credentials. Different applications may execute transactions using various reader infrastructures, formats, protocols, encryption, type / structure of user credentials exchanged with the terminal, and / or other aspects. the transaction card 104 may store applications locally for many selectable user accounts. For example, the transaction card 104 may execute different applications for each of the other user credentials. Different applications may execute transactions using various reader infrastructures, formats, protocols, encryption, type / structure of user credentials exchanged with the terminal, and / or other aspects. the transaction card 104 may store applications locally for many selectable user accounts. For example, the transaction card 104 may execute different applications for each of the other user credentials. Different applications may execute transactions using various reader infrastructures, formats, protocols, encryption, type / structure of user credentials exchanged with the terminal, and / or other aspects.
[0027] The transaction card 104 may perform transactions from the access point 514 using short-range signals such as NFC (e.g., ISO 18092 / ECMA 340), ISO 14443, ISO 15693, Felica, MiFARE, Bluetooth, UWB (Ultrawideband). , RFID (Radio Frequency Identifier), and / or other signals compatible with retail payment terminals (e.g., access point 514). In some implementations, the transaction card 104 may include one or more chipsets that perform system and security processes to independently execute the transaction. Thus, the mobile device 106 does not require additional hardware, software, and / or firmware to wirelessly perform transactions from the access point 514 such as NFC transactions. In some implementations, transaction card 104 may perform one or more of the following: dynamically switch between user credentials and / or applications in response to at least one or more events; wirelessly receive a request from an access point 514 to perform a transaction and / or send a response; convert between wireless protocols and protocols compatible with transaction card 104; convert between transaction-card protocols and protocols compatible with a mobile device 106; present and receive information (e.g., PIN request, PIN) from the user via GUI 116; decrypt and encrypt the information wirelessly transmitted between the transaction card 104 and the access point 514; execute applications locally stored in the transaction card 104; selectively enable / disable the transaction card antenna 104 based on at least partially one or more events; perform authentication processes based on at least partially received information, e.g., via GUI 116; assign the host signature to the access point 514 in response to at least a transaction call; store, at least in part, transaction details between the card 104 and the access point 514; generate and / or display notifications (e.g., audio-visual notifications) to the user via GUI 116; generate and / or broadcast wireless communication messages to the institution 506 using the mobile device 106 if it is networked; and / or other. In some implementations, the transaction card 104 may initiate a transaction in response to at least a user selecting a graphical element in the GUI 116. The transaction card 104 may initiate a transaction from the access point 514 in response to at least a wireless request transmitted by the access point 514. In some implementations, the card for transaction 104, it can selectively enable / disable the antenna in response to one or more events. One or more events may include a user request, Transaction completion, inserting the card 104 into different mobile devices, changing the location, time events, detection of an incorrect user input PIN, changing the wireless network to which the device is connected, message received from the institution 506 using a method of wireless communication such as SMS, and / or other events. For example, the transaction card 104 may receive one or more commands to disable the antenna from the cellular network (not shown) via the mobile device 106.
[0028] In some implementations, the transaction card 104 may initiate a transaction in response to at least a user selecting a graphical element in the GUI 116. The transaction card 104 may initiate a transaction from an ACCESS POINT 514 in response to at least a wireless request granted by the ACCESS POINT. 514. In some implementations, the transaction card 104 may selectively enable / disable the antenna in response to one or more events. One or more events may include a user request, completion of a transaction, inserting the card 104 into various mobile devices, changing the location, time event, detection of an incorrect user input PIN, changing the wireless network to which the device is connected, message received from the institution 506 using wireless communication methods such as SMS and / or other events. For example, the transaction card 104 may receive one or more commands to disable the cellular network antenna (not shown) via the mobile device 106. In some implementations, the transaction card 104 may request a user ID such as a PIN, a combination of a user ID and a biometric password. signature, and / or others.
[0029] With regard to translation between protocols, the transaction card 104 may process information in, for example, ISO 106416, a standard security protocol, and / or others. In this case, the transaction card 104 may convert between an NFC protocol (e.g., ISO 18092) and a transaction-card protocol. In some implementations, ISO 106416 commands may be included in interface commands used to transmit data between the host device 514 and the card 104. In addition, the transaction card 104 may connect the mobile device 106 via a physical interface such as a MicroSD, Mini-SD SD, MMC. , miniMMC, microMMC, USB, miniUSB, microUSB, firewire, Apple iDock, and / or others. With regard to secure processing, the transaction card 104 may implement one or more encryption algorithms, to secure transaction information such as the card number (e.g., credit card number, debit card number, bank account number), PIN, and / or other information requiring protection. The security information may include expiration date, card verification code, user name, home phone number, user code and / or other user information associated with card holder identity verification. In some implementations, the transaction card 104 may perform a private key (symmetric algorithm) such as DES, TDES and / or other or public key (asymmetric algorithm) such as RSA, elliptic curves, and / or others. In addition, the transaction card 104 may include memory (e.g., Flash, EEPROM) for storing user data, applications, offline websites, and / or other information. transaction card 104 can be compatible and act as a storage device. For example, if the wireless interface of the transaction card 104 is not available or deactivated, the transaction card 104 may act as a mass storage device allowing users to access data stored in the storage element (e.g., Flash). In some implementations, the transaction card 104 may execute a set of initialization commands in response to at least insertion into the mobile device 106. These initialization commands may include determining the device information to the mobile device 106 (e.g., telephone number, signature, network connection information). , location information and other available properties), determining user-related information (e.g., PIN code, activation code), increasing counters,
[0030] In some implementations, the transaction card 104 may automatically perform one or more fraud control processes. For example, a transaction card 104 may identify an operational change and automatically notify a financial institution based on at least a partially identified change. The transaction card 104 may perform two fraud control processes: (1) determine the violation of one or more rules; and (2) automatically perform one or more actions in response to at least the violation. Regarding the rules, the transaction card 104 may locally store rules related to updating the operational aspects of the transaction card 104. For example, the transaction card 104 may store a policy indicating a change in the host mobile device 106 as an offending activity. In some implementations, the transaction card 104 may store policies based on at least partial updates of one or more of the following: a telephone number of the host device 106; MAC address of the host device 106; a wireless network connected to the host device 106; location of the host device; and / or other aspects. In response to one or more events corresponding to or otherwise violating the rules, the transaction card 104 may perform one or more processes to substantially prevent or otherwise notify the institutions 506 of potential infringing activity. For example, the transaction card 104 may execute a command to block the associated user account and / or card for transaction 104. Alternatively or additionally, the transaction card 104 may issue a command to the institution 506, to call the host mobile device 106. In some implementations, the transaction card 104 may execute the command based on, at least in part, the type of event. In some instances, the transaction card 104 may initiate a connection with the institution 506 in response to at least a change in the host device number 106. In some instances, the transaction card 104 may resume the activation process in response to at least a specific type of event. The activation process may involve activating the transaction card and / or financial account as discussed in detail with reference to FIG. 13. In some implementations, the transaction card 104 may execute a command to disconnect the GUI 116 with the transaction card 104. The transaction card 104 may provide a disconnection notice via GUI 116 prior to executing the command. In some implementations, the transaction card 104 may instruct the institution 506 to deactivate the account associated with the card 104.
[0031] In some implementations, the access point 514 may transmit the transaction request 517 to the transaction card 512 for information to generate an authentication request 518. In response to at least a transaction request, the transaction card 512 may transmit one or more responses of the information identification transaction 519. associated with the user account. In some implementations, the access point 514 may transmit the request 518 to authenticate the transaction to the institution 506. The authentication information may include an account number, number of transactions, user credentials, and / or other information. In response to at least transaction request 518, the institution 506 may grant the authentication response 520 to the access point 514. In some implementations, access point 114 may reply 520 to transaction card 512. Transaction response 520 may include, for example, an acknowledgment provided to the user via GUI 116a. In some implementations, the institution 506 may transmit the authentication response 120 to the mobile device via the core cellular network (see FIG 7). In this implementation, the institution 506 could have saved the connection between the mobile device 106 and the transaction card 104 during the user login process, loaded automatically after the user 104 activated the card when, for example, the card 104 is first inserted into the mobile device 106, and / or other event. In the depicted implementation, access point 514 includes GUI 509. confirmation presented to the user via GUI 116a. In some implementations, the institution 506 may transmit the authentication response 120 to the mobile device via the core cellular network (see FIG 7). In this implementation, the institution 506 could have saved the connection between the mobile device 106 and the transaction card 104 during the user login process, loaded automatically after the user 104 activated the card when, for example, the card 104 is first inserted into the mobile device 106, and / or other event. In the depicted implementation, access point 514 includes GUI 509. confirmation presented to the user via GUI 116a. In some implementations, the institution 506 may transmit the authentication response 120 to the mobile device via the core cellular network (see FIG 7). In this implementation, the institution 506 could have saved the connection between the mobile device 106 and the transaction card 104 during the user login process, loaded automatically after the user 104 activated the card when, for example, the card 104 is first inserted into the mobile device 106, and / or other event. In the depicted implementation, access point 514 includes GUI 509. the institution 506 could have stored the connection between the mobile device 106 and the transaction card 104 during the user login process, loaded automatically after the user 104 activated the card when, for example, the card 104 is first inserted into the mobile device 106, and / or other event . In the depicted implementation, access point 514 includes GUI 509. the institution 506 could have stored the connection between the mobile device 106 and the transaction card 104 during the user login process, loaded automatically after the user 104 activated the card when, for example, the card 104 is first inserted into the mobile device 106, and / or other event . In the depicted implementation, access point 514 includes GUI 509.
The GUI 509 includes a GUI graphic interface operable to allow the user of the access point 514 to connect to at least a portion of the system 500 for any suitable purpose, such as entering user information about the transaction (e.g., PIN, accepting a transaction) and / or presenting transaction information (e.g., number of transactions). Generally, the GUI 509 provides a specific user with an efficient and user-friendly representation of data provided by or communicated in the system 500 and / or also efficient and user-friendly elements to initiate a card-to-transaction transaction with the card 104. The GUI 509 may represent a series of images or displays to the user, for example, to accept the transaction and enter security information such as a PIN.
[0033] In some implementations, the transaction card 104 may be implemented differently. The transaction card 104 may be implemented as KeyFOB and remains active outside the mobile device 106 as a FOB. In this case, the transaction card 104 may be passive and powered by the generated magnetic induction field of the access point 514. The transaction card 104 may be implemented in the form of an industrial chip chip placed on the PCB or an IC chip. In some implementations, the transaction card 104 may be implemented in the form of a stand-alone unit powered by an external AC adapter or an independent box. In some implementations, the transaction card 104 may be implemented as an external attachment to the mobile device 106 (e.g.,
[0034] In some implementations, the transaction card 104 may operate in accordance with one or more of the following modes: active card emulation; active reader; self-improvement; turning off permanently; memory; inactive; and / or other modes. The transaction card 104 may operate in the active card emulation mode to convert the mobile device 106 to a non-contact payment device with a financial tool (FV), which may be, for example, a credit card, debit card, gift card and / or other retail payment product. . In this mode, the transaction card 104 may perform payment transactions with any terminal for retail payments (e.g., ACCESS POINT 514), which accepts contactless payment transactions. E.g, such terminals may be contactless-operated terminals currently used by vendors as MasterCard paypass, Visa paywave, Amex ExpressPay, Disclosure Zip, and / or other payment programs. After activation of the transaction card antenna 104 in this mode, the merchant terminal can detect the presence of the host device from the transaction card 104 and ask the user to authorize the transaction by entering the PIN, signature on the terminal interface, confirmation of the transaction amount, and / or other operation. In this mode, this transaction can be handled as a normal card transaction. In other words, the access point 514 may receive the transaction card 104 as a plastic card for a non-contact payment and may communicate with the transaction card 104 a plastic contactless payment card to perform payment transactions. In these implementations, when the card 104 operates in the active card emulation mode, the access point 514 can wirelessly communicate with the transaction card 104 using the same signals used to communicate with a plastic card for a non-contact payment. In this mode of active card emulation, the transaction card 104 emulates a contactless plastic payment card and may be back compatible with the access point 514. In this implementation, neither the terminal nor the financial institution may require additional transaction processing software. In addition, the transaction card 104 in this mode can be used for other applications such as physical access control (to open gateways of the corporate environment or the transition environment), logical access control (network access request via PC),
[0035] In active reader mode, the transaction card 104 may convert the mobile device 106 to a contactless reader device capable of receiving data when in the range of the sending terminal (e.g., access point 514). In some implementations, this mode may require special NFC equipment with the reader mode as part of the transaction card 104. In an event in which the mobile device 106 is near (e.g., 10 cm or less) transmitting the terminal, the card reader mode for transaction 104 may activate and ask the user for authentication to receive data via GUI 116. This mode may only be suitable for mobile devices 106 with a UI element, such as an OK button and a screen, LED to indicate which data reception is required, and / or other interfaces . When the user authorizes the transmission,unit. For example, the transaction card 104 in this mode may receive content through promotional posters, validated ticket purchase, and / or other. For example, the transaction card 104 in this mode may act as a mobile POS terminal receiving transaction information from a plastic non-contact card / FOB and instructing a point
<td>access</td><td>514 to prepare an authentication request</td>
<td>transactions</td><td>for institutions 506 through a core network</td>
<td>cell.</td><td>When the institution 506 authenticates the transaction,</td>
<td>device</td><td>mobile 106 can display confirmation</td>
<td>transactions</td><td>user through GUI 116.</td>
[0036] With reference to the self-improvement mode, the card for
<td>transactions</td><td>104 can execute the version of the reader mode. IN</td>
<td>some</td><td>implementations, the self-improvement mode can be</td>
<td>activated</td><td>by special action (e.g., pressing</td>
zeroing buttons, entering the administrator password via GUI 116). In response to at least the activation of this mode, the transaction card 104 may be configured to receive personalization data by, for example, a wireless short-range interface with another transaction card such as a plastic contactless card according to this functionality and issued by the institution 506 or a specially prepared administrative card for this purpose. The personalization data received in this mode may include encrypted FV information that is stored in the secured transaction card memory 104. In some implementations, the transaction card 104 in this mode can synthesize the user correspond to the internal module account receive the FV information via the contactless transmitter interface and / or other. The transaction card 104 may then provide FV information that and personalize the security, which includes, for example, a payment application to perform transactions with the institutions 506 and associated user credentials. The self-improvement mode can be used to personalize the transaction card 104 in a given area again. In some implementations, previous data can be deleted if the self-improvement mode is activated. The self-improvement mode can be a peer-to-peer personalization mode where the card 104 can receive personalization information from the next transaction card 104. This mode can represent an additional personalization mode compared to the factory, store and / or OTA sending of personalization scenarios that can be scenarios server client personalization. In some implementations, the self-improvement mode may be a peer-to-peer personalization mode, where the transaction card 104 receives the personalization information from the next transaction card. Because two transaction cards 104 are used in this mode, the mode can be different scenarios of server-client personalization as with the factory, store and OTA personalization.
[0037] With respect to the inactive mode, the transaction card 104 may temporarily deactivate the contactless interface. In some implementations, the inactive mode may be activated via a physical interface with a mobile device 106 such as a microSD interface. In response to at least activation of the inactive mode, the transaction card
104 can temporarily work as a storage card. In some implementations, the card 104 may also go into this state after pressing the reset button. In this mode, the transaction card 104 may store locally stored information including the financial data of the user. In this mode, the transaction card 104 may perform the activation process and if successful, return to the active mode. Institutions 506 may use this mode to temporarily prevent use in response to at least identifying at least potentially unfair activity.
[0038] With respect to the disabled mode, the transaction card 104 may permanently deactivate the contactless interface. In some implementations, the disabled mode is activated via a physical interface with a mobile device 106 such as a microSD interface. In response to at least activation of the disabled mode, the transaction card 104 may permanently act as a storage medium. In an event in which the reset button is pressed, the transaction card 104 may, in some implementations, be executed to enter any other modes. In addition, the transaction card 104 may delete financial content in memory in response to at least activating this mode. In some implementations, the institutions 506 may use this mode to delete card data for transaction 104 that is physically lost,
[0039] With respect to the memory mode, the transaction card
104 may act as mass storage such that memory is available through conventional methods. In some implementations, the transaction card 104 may automatically activate this mode in response to at least removing from the host device, inserted into an unauthorized host device, and / or other events. The transaction card 104 may be switched into an active mode with memory mode by, for example, inserting the card 104 into an authorized device or it may be switched with this mode including self-improvement to re-personalize the device for a new host device or a new user account. In some implementations, the memory mode can work essentially the same as the inactive mode.
[0040] In some implementations, the transaction card 104 may be re-personalized / updated, for example, by using the device management software and / or hardware resetting. For example, the user may want to personalize the transaction card 104 again to change host devices, to have multiple host devices, and / or for other reasons. With regard to device software management, the user may need to place the transaction card 104 in the host device to run the device management application software. In some implementations, the device management application software may be an application directly installed on the client 504, integrated as a plug-in for a normal synchronization application such as ActiveSync, available via a plug-in browser running on the plug-in service provider's website, and / or from other sources. The user can log in to the application and verify the identity, and in response to verification, the application may allow access to the device section in the device management application.
The device management application can read the transaction card 104 and display MAC addresses, device signatures that have been inserted into the plug-in, and / or other specific device information. The mobile device 106 may be marked as active and the host device may be shown as rejected or inactive. The application may allow the user to update the status of a new host device, and in response to at least a selection, the device management application may install the signature on the host device and mark the update status as acceptable in the secure transaction card memory 104. The user may also update the status of the mobile device 106 at rejected. Otherwise, the devices may be active and the transaction card 104 may be switched between two devices. With regard to the hardware reset process, the reset button on the physical transaction card 104 can be used to activate the self-improvement mode. In this mode, financial data can be deleted and can be re-loaded. When the transaction card 104 is inserted into a new host device, the delivery process may begin as discussed above.
[0041] Access point 514 may include any software, hardware, and / or firmware that wirelessly receives account information to perform transactions from one or more institutions 506. For example, access point 514 may be an electronic cash register capable of wirelessly transmitting information about transactions from the transaction card 104a. Access point 514 may transmit information in one or more of the following formats: 14443 Type A / B, Felica, MiFare, ISO 18092, ISO 15693; and / or other. Transaction information may include verification of information, checking number, routing number, account number, transaction amount, time, driver license number, dealer ID, seller parameters, credit card number, debit card number, digital signature and / or other information. In some implementations, transaction information can be encrypted. In the depicted implementation, the access point 514 can wirelessly receive the encrypted transaction information from the card to the transaction 104 and electronically send information to one or more 506 institutions for authentication. For example, the access point 514 may receive an indication of which amount the transaction has been accepted or rejected for the account being identified and / or requesting additional information from the transaction card 104.
[0042] As used in this disclosure, the client 504 may have a personal computer, touch screen terminal, workstation, computer network, desktop, kiosk, wireless data port, smarfon, PDA, one or more processors in these or other devices, or any other suitable processing or electronic device used to visualize the transaction information associated with the transaction card 104. For example, the client 504 may be a PDA to wirelessly connect to an external or unsecured network. In a further example, the client 504 may include a laptop that includes an input device, such as a keyboard, touch screen, mouse, or other device that can accept information, and an output device that transforms information associated with transactions performed with institutions 506, including digital data, visual information, or GUI 515. In some implementations, the client 504b can wirelessly communicate with the transaction card 104b using, for example, the NFC protocol. In some implementations, the client 504a includes a 516 card reader having a physical interface to communicate with the transaction card 104c. In some implementations, the card reader 516 may at least include an adapter that adapts the interface supported by the client 504 (e.g., USB, Firewire, Bluetooth, WiFi) to the physical interface supported by the card 104 (e.g., SD / NFC). In this case, the client 504a may not include a transceiver for wireless communication. the client 504b can wirelessly communicate with the transaction card 104b using, for example, the NFC protocol. In some implementations, the client 504a includes a 516 card reader having a physical interface to communicate with the transaction card 104c. In some implementations, the card reader 516 may at least include an adapter that adapts the interface supported by the client 504 (e.g., USB, Firewire, Bluetooth, WiFi) to the physical interface supported by the card 104 (e.g., SD / NFC). In this case, the client 504a may not include a transceiver for wireless communication. the client 504b can wirelessly communicate with the transaction card 104b using, for example, the NFC protocol. In some implementations, the client 504a includes a 516 card reader having a physical interface to communicate with the transaction card 104c. In some implementations, the card reader 516 may at least include an adapter that adapts the interface supported by the client 504 (e.g., USB, Firewire, Bluetooth, WiFi) to the physical interface supported by the card 104 (e.g., SD / NFC). In this case, the client 504a may not include a transceiver for wireless communication. the card reader 516 may at least include an adapter that adapts the interface supported by the client 504 (e.g., USB, Firewire, Bluetooth, WiFi) to the physical interface supported by the card 104 (e.g., SD / NFC). In this case, the client 504a may not include a transceiver for wireless communication. the card reader 516 may at least include an adapter that adapts the interface supported by the client 504 (e.g., USB, Firewire, Bluetooth, WiFi) to the physical interface supported by the card 104 (e.g., SD / NFC). In this case, the client 504a may not include a transceiver for wireless communication.
The GUI 515 includes a graphical GUI interface operable to enable the client user 504 to connect to at least a portion of the system 500 for any suitable target, so as to visualize the transaction information. Generally, the GUI 515 provides a particular user with an efficient and user-friendly representation of data provided by or communicated in the system 500. The GUI 515 may comprise a plurality of personalized frames or views having interactive fields, scroll lists, and / or user-operated switches. The term GUI GUI can be used in singular or plural to describe one or more graphical user interfaces and each of the displays of a particular graphical user interface. The GUI 515 can include any graphical user interface, such as a standard web browser or touch screen that processes information in the 500 system and presents the results to the user. Institutions 506 may accept data from client 504 using, for example, a web browser (e.g., Microsoft Internet Explorer or Mozilla Firefox) and send relevant responses (e.g., HTML or XML) to the browser using network 108. In some implementations, GUI 116c transaction cards 104c can be presented via the GUI 515a client 504a. In these implementations, the GUI 515a can download user credentials from the GUI 116c and complete the financial forms presented in the GUI 515a. For example, GUI 515a can present a forum to a user to enter credit card information to buy goods online,
[0044] Institutions 506a-c may include any enterprise that can authenticate transactions received over network 108. For example, institutions 506a may be a credit card provider that specifies whether to authorize a transaction based, at least in part, on information received over network 506. Institutions 506 may be a credit card provider, bank, association (e.g., VISA), retailer (e.g., Target), prepaid / gift card provider, online bank, government entity, club, and / or others. Generally, institutions 506 may perform one or more of the following: receive a request to authenticate the transaction; identify the account number and other transaction information (e.g., PIN); identify the means and / or credit limit associated with the identified account; identify the access privileges associated with the user account; determine if the transaction request exceeds the funds and / or the credit limit and / or violates any other rules associated with the account; give an indication whether the transaction has been accepted or rejected; and / or other processes. With regard to banking, institutions 506 may identify the account number (e.g., bank account, debit card number) and related verification information (e.g., PIN, code) and specify the funds available to the account holder. Based on at least partially identified means, the institutions 506 can either accept or reject the requested transaction or request additional information. What to encrypt,
[0045] FIG. 6 is a block diagram illustrating an example of a transaction system 600 for wireless communication of transaction information using cellular radio technology. For example, the system 600 may wirelessly communicate transaction confirmation to a transaction card 104 using a mobile host device 110 and cellular radio technology. In some implementations, cellular radio technology may include GSM (Global System for Mobile Communication), CDMA (Code Division Multiple Access), UMTS (Universal Mobile Telecommunication System), and / or any other cellular technology. Institutions 106 may assign one or more mobile host devices 110 to the transaction card 104 in response to one or more events. In some examples,
[0046] In the depicted implementation, the core cellular network 602 typically includes various switching elements, gateways, and service control functions for providing cellular services. The core cellular network 602 often provides these services via a plurality of cellular access networks (e.g., RAN) and further connects the cellular system with other communication systems such as network 108 via MSC 606. According to the cellular standard, the core cellular network 602 may include a circuit part of the circuit. (or voice commutation) to process voice calls and part of packet switching (or data commutation) to handle data transfer such as, for example, e-mail messages and web browsing. Part of circuit switching includes MSC 606, which switches or links telephone connections between the radio access network (RAN) 604 and the network 108 or other network, between the cellular core network or the other. In the case where the core network 602 is a core network of GSM, the core network 602 may comprise a packet-switched part, also known as GPRS (General Packet Radio Service), including SGSN (not shown), similar to the MSC 606, for servicing and tracking devices communications 106, and GGSN (not shown) for establishing connections between packet switched networks and communication devices 110. The SGSN may also include subscriber data useful in establishing and servicing telephone calls. The core cellular network 602 may further include a home location register (HLR) to maintain "permanent" subscriber data and a guest subscriber register (VLR) (and / or SGSN) for "temporarily" maintaining subscriber data retrieved from the HLR and current location information of communication devices. 110 using a wireless way of communication. In addition, the core cellular network 602 may include Authentication, Authorization, and AAA protocol that performs an authentication role; authorizing and controlling the access of devices 110 operating with access to the GSM 602 core network. While the core network description 602 is described with respect to the GSM network, the core network 602 may include other cellular radio technologies such as UMTS, CDMA, and others without leaving the network. from the scope of this disclosure.
[0047] The RAN 604 provides a radio connection between the mobile devices and the core cellular network 602, thereby providing voice in real time, data, and multimedia services (e.g., calls) to the mobile devices through the macrocell 608. In general, the RAN 604 communicates frames airborne by radio frequency (RF) links. In particular, RAN 604 converts between airframes to a physical link based on messages for transmission through a core cellular network 602. RAN 604 may implement, for example, one of the following wireless interface standards during transmission: AMPS (Advanced Mobile Phone Service), GSM standards, CDMA (Code Division Multiple Access), TDMA (Time Division Multiple Access), IS-54 (TDMA), GPRS (General Packet Radio Service), EDGE (ang. Enhanced Data Rates for Global Evolution), or your own radio interfaces. Users can subscribe to RAN 604, for example, to receive a cell phone service, GPS (Global Positioning System) service, XM radio service, etc.
[0048] RAN 604 may include Base Stations (BS) 610 connected to Base Station Controllers (BSCs) 612. BS 610 receives and transmits the air frames in the geographical area RAN 604 and communicates with other mobile devices 106 connected to the core GSM 602 network. Each BSC 612 is associated with one or more BS 610 and controls the associated BS 610. For example, the BSC 612 may provide functions such as forwarding, connection configuration data, control of RF power levels, or any other appropriate radio resource management and signaling functions to and with BS 610. The MSC 606 supports access to BSC 612 and network 108. The MSC 606 can be connected to the BSC 612 via a standard interface such as the A-interface. While the RAN 604 elements are described in relation to the GSM network, RAN 604 may include other cellular technologies such as UMTS, CDMA, and / or others. In the case of UMTS, RAN 604 may include Node B and RNC (Radio Network Controllers).
[0049] The contactless smart card 614 is a pocket card with integrated circuits that processes information. For example, the smart card 614 can wirelessly receive transaction information, process information using the applications placed on it, and wirelessly broadcast the response. The contactless smart card 614 can wirelessly communicate with card readers via RFID induction technology at data rates of 106 to 848 kbit / s. The card 614 can wirelessly communicate with near-reader readers between 10cm (e.g., ISO / IEC 14443) to 50cm (e.g., ISO 15693). The contactless smart card 614 operates independently of the internal power supply and draws energy from the radio frequency interrogation signals to power the electronics in it. Smart card 614 can be a memory card or a microprocessor card. In general, memory cards include only nonvolatile memory storage components and may include some specific security logic. Microprocessor cards include components of volatile memory and a microprocessor. In some implementations, the smart card 614 may have the dimensions of a normal credit card (e.g., 85.60 x 53.98 x 0.76 mm, 5 x 15 x 76 mm). In some implementations, the smart card 614 may be a pocket card or other security token. The smart card 614 may include a security system with tamper-proof properties (e.g., a secure cryptoprocessor, a secure file system, human-readable features) and / or may be configured to provide security services (e.g., confidentiality of stored information).
[0050] In some aspects of the operation, the institution 506 may wirelessly communicate with the mobile host device
106 using the core cellular network 602. For example, the institution 506 may transmit information to the host host device 106 in response to at least an event. The information may include, for example, transaction information (e.g., transaction confirmation, transaction history), scenarios, applications, websites, and / or other information associated with the institution 506. The event may include completion of the transaction, determining whether the transaction card 104 is outside the operational range of the terminal access point, receiving requests from the user of the mobile host device, and / or others. For example, the institution 506 may identify a host mobile device 106 associated with the card 104 that performs transactions and transmits transaction information to the host host device 106 using the core cellular network 602.
[0051] In some implementations, the system 600 may perform one or more modes discussed with reference to FIG. 5. For example, the transaction card 104 may be re-personalized / updated using cellular radio technology of the mobile host device 106. The user may want to personalize the transaction card 104 again, to change the host device, to have multiple host devices, and / or for other reasons . With regard to device software management, a user may send to the institution 506 a request to re-personalize the transaction card 104 using the cellular radio technology of the host device 106.
[0052] FIG. 7 is a block diagram illustrating an example of the transaction card 104 of Fig. 1 in accordance with some implementations of the disclosure. Generally, the transaction card 104 includes personalized modules that perform financial transactions independently of the mobile device 106. The provided transaction card 104 is for example only target, and the transaction card 104 may include some, all or different modules without departing from the scope of the disclosure .
In some implementations, the transaction card 104 may include interface layer 702, API / UI 704, network server 706, real-time backbone 708, transaction applications 710, value-added applications 712, user credentials 714, real-time OS 716, contactless chipset 718, antenna control function 720, antenna 722, memory of institution 724, and free memory 726. In some implementations, the host controller includes interface layer 702, API / UI 704, network server 706, real-time backbone 708, contactless chipset 718, and antenna control functions 720. In some implementations, the security module includes transaction applications 710 and user credentials 714. Institution 724 memory and free memory 726 may be included on Flash. In some implementations, the contactless chipset 718 can be connected to the security module or operate independently. Antenna 722 can be an electronic circuitry.
[0054] Interface layer 702 includes connections to both host devices, i.e., a physical connection, and an external connection, i.e., wireless / non-contact connection. In payment implementations, the wireless connection may be based on a suitable wireless standard such as a non-contact (e.g., ISP 14443 A / B), proximity (e.g., ISO 15693), NFC (e.g., ISO 18092), and / or others. In some implementations, the wireless connection may use another wireless short-range protocol, such as Bluetooth, other own connections used by retail payment terminals (Felica in Japan, MiFare in Asia, etc.), and / or others. With respect to the physical interface, the interface layer 702 can physically connect the mobile device 106 using an SD protocol such as MicroSD, Mini-SD or SD (full-size).
106 can communicate using protocols such as USB, MMC, iPhone or other interface.
[0055] The API / UI 704 layer may include any software, hardware, and / or firmware that acts as an API between the mobile device 106 and the transaction card 104 and the GUI 111. Before performing the transaction, the transaction card 104 may automatically install drivers in the mobile device 106 in response to at least insertion. For example, the transaction card 104 may automatically install the MicroSD device driver on the device 110 allowing the transaction card 104 to connect to the mobile device 106. In some implementations, the transaction card 104 may install an advanced device driver such as the MMR (Mass Memory with) API. Radio). In this implementation, the interface can control a class of plug-ins that contain mass storage like a radio interface. The MMR API can perform one or more of the following: connect / disconnect to / from the MMR (microcontroller in a plug-in); transmit data using the MM protocol (e.g., SD, MMC, XD, USB, Firewire); send encrypted data to the MMR controller; receive confirmation of success or error; receive a status word indicating the error description; turn on / off the radio; send instructions to the transaction card 104 to enable the antenna in a certain mode of operation (e.g., send mode, listening mode); transmit data such as sending instructions to the controller to transmit data over the radio; listen for data such as sending instructions to the controller to listen to data; read data such as sending instructions to the controller to send data received via a radio watch; and / or other. In some implementations, MMR can be TCP / IP compliant.
[0056] In some implementations, the API may operate in accordance with two processes: (1) a transaction card 104 as a master device and a mobile device 106 as a slave device; and (2) the UI card as the main device. In the first process, the transaction card 104 may transmit one or more commands to the mobile device 106 in response to, e.g. inserting the transaction card 104 into the slot on the mobile device 106, transaction between the transaction card 104 and the access point 514, and or other events. In some implementations, the transaction card 104 may request that the mobile device 106 perform one or more of the following functions: retrieve the user input data; Download the signature; display data; send data; receive data; and / or other. The command to download user input data may present a request via the GUI 111 for data from the user. In some implementations, downloading the user input data may present a request for a plurality of input data. The input data can be in any suitable format such as numeric, alphanumeric, and / or other strings. The signature download command may request that the mobile device 106 provide identification data such as, for example, telephone number, device ID, such as IMEI or MAC address, network code, subscription ID like SIM card number, connection status, location information, tags Wi-Fi, GPS data, and / or other specific device information. The data display command can show the dialog to the user via the GUI 111. In some implementations, dialogue can disappear after a period of time, a user's choice, and / or another event. The send command may request that the mobile device 106 transmit a data packet using its own connection to the outside world (e.g., SMS, cellular, Wi-Fi). The data reception command may request that the mobile device 106 open the connection channel with certain parameters and identify the data received via the connection. In some implementations, the command may request the mobile device 106 to forward data (e.g., SMS) meeting certain criteria to forward it to the transaction card 104. The data reception command may request that the mobile device 106 open the connection channel with certain parameters and identify the data received via the connection. In some implementations, the command may request the mobile device 106 to forward data (e.g., SMS) meeting certain criteria to forward it to the transaction card 104. The data reception command may request that the mobile device 106 open the connection channel with certain parameters and identify the data received via the connection. In some implementations, the command may request the mobile device 106 to forward data (e.g., SMS) meeting certain criteria to forward it to the transaction card 104.
[0057] With reference to the UI as a master device, the UI may perform one or more of the following commands: Command / Response of the security module; Enable / disable; Save / Read Flash memory; send data with or without encryption; Receive data with or without decryption; Download URL data / send URL data; and / or other. The commands of the security module may refer to the security function provided by the card and are directed to the security module in the transaction card 104 (eg, command in the ISO 110416 standard, own instructions). In some implementations, the commands may include encryption, authentication, data provisioning, security domain creation, security domain updates, updating user credentials after key verification, and / or others. In some implementations, commands can include smart card commands without security, such as, for example, commands to read transaction history. The transaction history read request may read the secure memory 724 of the transaction card 104. In some implementations, specific flags or areas of secure memory 724 may be saved after security verification. The Activate / Deactivate command can activate or deactivate certain functions of the transaction card 104. The Reading / Writing Flash memory command can perform a reading / writing task in a specific area of unprotected memory 726. The send command with or without encryption can instruct the transaction card 104, to transmit data using a wireless connection to, e.g., access point 514. Additionally, the data may be encrypted by the transaction card 104 prior to transmission using, for example, key capabilities and encryption stored in the security module. The command to receive data with or without decryption may instruct the transaction card 104 to switch to listen mode to receive data from a wireless connection to the terminal / reader (e.g., access point 514). In some implementations, data decryption may be requested by the security module using, for example, keys and decryption algorithms available in the security module, i.e., on-board decryption. The Get URL Data / Send URLs command can instruct the 706 web server to return to offline pages and retrieve or send instructions using, for example, an offline URL.
[0058] Network server 706, as part of the OS of the transaction card
104, may assign or otherwise include URL addressing to specific files stored in the memory 726 (e.g., flash) of the transaction card 104. In some implementations, the Web Server 706 locates the file using the URL and returns the file to the browser using the HTTP, HTTPS transfer . In some implementations, the file definition can be formatted using the languages of the HTML, XHTML, WML and / or XML standards. The file may include links that indicate additional offline storage locations in memory 726 and / or websites to which the mobile device 106 has access. In some implementations, the network server 706 may support security protocols such as SSL. The network server 706 may carry the application in memory 726 to the mobile device 106 for installation and execution.
[0059] As part of the real time OS, the real-time framework 708 may perform one or more functions based on at least partially one or more time periods. For example, the real-time skeleton 708 may run an internal clock available on the CPU to provide timestamps in response to at least requested events. The real-time framework 708 may allow pre-scheduling of specific tasks such that tasks are performed in response to at least certain time and / or event based triggers. In some implementations, the real-time skeleton 708 may allow the CPU to introduce delays in specific transactions. In another implementation, part of WAP standards called WTAI (Wireless Telephony Application Interface) can be implemented,
[0060] Transaction applications 710 may include any software, hardware, and / or firmware that exchanges transaction information from an institution using, in some instances, a specific sequence and / or data format. For example, transaction applications 710 may generate a response to a transaction request by selecting, downloading, or otherwise acquiring user credentials in the response, in a format compatible with the access points processing the application. In some implementations, transaction applications 710 may perform one or more of the following: grant the transaction card 104 properties in response to at least an identification request received from the access point 514; receive a request to perform transactions from, e.g., access point 514; identify user credentials in the memory of the institution 724 in response to at least a request; generate a transaction response based on at least partially user credentials; transmit a transaction response to the access point 514 using, for example, a contactless chipset; receive clean data, e.g. a random number, from access point 514 and provide a response containing encrypted data by encrypting the clean data received from the transaction
710 may over the network using the cryptographic capability of the security element; transmit encrypted data using a contactless chipset 718; increase the transaction counter along with every received transaction request; set the counter value of the demand response transaction from the access point 514; store the transaction details of the access point transaction 514 in the institution's memory history area 724; assign a transaction history to the smart card processor 104 in response to such a request; receive ISO 110416 requests from the CPU of the smart card 104; execute corresponding transactions using the OS security element; provide answers to the CPU; and / or other processes. When generating a transaction response, the transaction application generates a response in a specific format associated with the institution 506 either in its own format and defined by the institution 506 and processed by the access point 514. The transaction request may include one or more of the following: user credentials (e.g., account number); expiry date, card verification numbers; transaction counter; and / or another card or user information. In some implementations, transaction application 710 may contain a browser application that allows transactions. The browser application 710 can be a browser that can be installed if the device 106 does not have a browser or has a browser that is not compatible with the network server 706 on the card 104. After installing the browser 710,
[0061] The real time OS 716 may perform or otherwise include one or more of the following: real time framework 708; a host process that implements the physical interface between the transaction-card CPU and the mobile device 106; an interface that implements the physical interface between the transaction-card CPU and the security module; a memory management process that implements the physical interface ISO 110416 between the transaction-card CPU and memory 724 and / or 726; application-layer process that implements API and UI capabilities; network server 706; antenna control functions 720; power management; and / or other. In some implementations, the real-time OS 716 may manage the physical interface between the transaction-card CPU and secure memory 724, which includes memory splits to allow, that certain memory areas have limited access and / or buffers / data flows. In some implementations, the security module may include an OS security module provided by the security module's service provider and may be compliant with the specifications for Visa and MasterCard. The OS security module can serialize data in the security module to suit the Paypass and / or payWave specifications or other available contactless specifications for non-contact payments. In addition, the security module may store signatures of the host device and allow antenna modes 722 in secure memory 724. In some implementations, the real time OS 716 may include a microcontroller OS configured to personalize secure memory 724 by, for example, convert raw FV data (account number) . expiration date, card verification number (CVN), other specific application details) to secure encrypted information. In addition, the microcontroller OS may display the 104 as MicroSD card to the host device. The OS microcontroller can divide the memory into a user section and a section of protected device applications. In this example, the application section of the device can be used to store specific service provider applications that either operate with this memory segment or are installed on a host device with that memory segment. The OS microcontroller can divide the memory into a user section and a section of protected device applications. In this example, the application section of the device can be used to store specific service provider applications that either operate with this memory segment or are installed on a host device with that memory segment. The OS microcontroller can divide the memory into a user section and a section of protected device applications. In this example, the application section of the device can be used to store specific service provider applications that either operate with this memory segment or are installed on a host device with that memory segment.
[0062] The security module of the chip may provide security features of the tamper-proof encryption, authentication, user authentication data management by using multiple security domains, on-board processing capabilities for personalization, access and storage, and / or others. In some implementations, the chip security module may include a contactless chipset 718.
[0063] The contactless chipset 718 may provide implementation of a hardware protocol and / or drivers for RF communication. For example, the contactless chipset 718 may include an on-board RF circuitry for an interface to connect to the outside world using a wireless / non-contact connection. The wireless connection may be, for example, a client connection to a node (terminal / reader / base station), a client node (passive tag), or a peer-to-peer (another transaction card 104).
[0064] The antenna control function 720 may control the radio frequency availability of the antenna. For example, the antenna control function 720 may enable / disable the antenna 722 in response to, for example, successful authentication, completion of routine determination by OS 716, and / or other event. The antenna 722 may be a short-range wireless antenna connected to the NFC by switch software such as a NAND gateway or other element.
[0065] The portfolio management system 728 may selectively switch between multiple credentials 714 when transactions are performed. For example, the portfolio management system 728 may identify a default account, switch policy, and / or other information. In some implementations, the portfolio management system 728 can automatically switch to default user credentials in response to at least an event such as completing transactions using non-default credentials. The switching rules may identify user credentials and associated events, e.g. when the portfolio management system 728 switches to user credentials in response to at least a determination event.
[0066] FIG. 8 is a block diagram illustrating an example of smart card 800 in accordance with some implementations of the disclosure. For example, the transaction card of Fig. 1 may be implemented in accordance with the illustrated intelligent card 800. In general, intelligent card 800 may obtain independent access to services and / or transactions. The intelligent card 800 is for illustrative purposes only and may include some, all or different elements without departing from the scope of the disclosure.
As shown, intelligent card 800 includes antenna 802, switch plus tuning circuit 804, security module and contactless chipset 806, CPU 808 and memory 810. Antenna 802 wirelessly transmits and receives signals such as NFC signals. In some implementations, the switch plus tuning circuit 804 can dynamically adjust the impedance of the antenna 802 to tune to transmit and / or receive frequency. In addition, the switch plus tuning circuit 804 may selectively enable and disable the antenna 802 in response to at least the command from the CPU 808. In some implementations, the antenna 802 may be a short-range wireless antenna connected to the NFC by switch software such as a NAND gateway or other enabling item. for the code from the 808 CPU to turn on and turn off the 802 antenna. In some implementations, the card 800 may include NFC (not shown), which may be a passive implementation of short-range NFC wireless technology fed from the reader terminal to transmit data or a more efficient implementation using the eNFC chipset to power the active reader mode and self-improvement mode. In addition, the card 800 may include external zeroing with a needle blade (not shown) that forces the CPU 808 to depersonalize the memory or security element.
[0068] The CPU 808 may transmit switch commands in response to an event, such as a user request, a completed transaction, and / or others. When enabled, the security chip and non-contact chipset 806 is connected to antenna 802 and performs one or more of the following: formatting signals for wireless communication in accordance with one or more formats; decrypts received messages and encrypts transmitted messages; authenticates user credentials locally stored in memory 810; and / or other processes. Memory 810 may include a secured and unsecured portion. In this implementation, secure memory 810 may store one or more user credentials that are not available by the user. Additionally, memory 810 can store offline websites, applications, transaction history, and / or other data. In some implementations, memory 810 may include 64 MB to 32 GB of Flash memory. In addition, memory 810 can be divided into user memory and device application memory. The 806 chipset may include a security module, e.g. Visa and / or MasterCard certified for storing financial data tools and / or in accordance with global standards.
In addition to the user's financial tools, the secure element may store the signatures of the host devices and / or antenna modes allowed.
[0069] In some implementations, the CPU 808 may switch the 802 antenna between an active and inactive mode based on, at least in part, a personalization parameter determined by, for example, a user, a distributor (e.g., a financial institution, a service provider), and / or other. For example, the CPU 808 may activate the antenna 802 when the smart card 800 is physically connected to the host device and when the handshaking with the host device is successfully performed. In some implementations, the CPU 808 may automatically deactivate the 802 antenna when the smart card 800 is removed from the host device. In some implementations, the 802 antenna is always active so that the intelligent card 800 can be used as a separate access device (e.g., a device on a key chain). With regard to the reconciliation process, The CPU 808 may perform one or more authentication processes prior to activation of the smart card 800 and / or the antenna 802 as shown in FIG. 7. By way of example, the CPU 808 may perform physical authentication, device authentication, and / or user authentication. For example, the CPU 808 may activate the antenna 802 in response to at least detecting a connection to the physical interface with the host device (e.g., an SD interface) and successful installation of the device driver for accessing the mass storage (e.g., SD device driver) on the host device . In some implementations, device authentication may include physical authentication in addition to comparing signatures with device signatures stored in memory (e.g., a security module (SE)), which are created during the first use (delivered) until the signature is calculated using, for example, a unique parameter of the host device. In the event, there is no signature of the host device in memory, the CPU 808 may connect to the first compatible host device card 800 that is inserted. A compatible host device can be a device that can successfully perform physical authentication. If the signature of the host device is present in memory, the CPU 808 compares the stored signature with the real-time signature of the current host device. If the signatures match, the CPU 808 can go to the end of the initial load. If the signatures do not match, the host device is discarded, the initial load is dropped and the card [0070] Authentication physical verification
800 returns to the mode it was in before it was inserted into the device.
the user may include user connections using a user-entered PIN, an x.509 certificate that is unique to the user and stored on the host device, and / or other processes. The device and user authentication can verify the physical connection with the device by comparing the device signature and user authentication by verifying the user's PIN or certificate. In some implementations, the user can choose a PIN or certificate at a specific time. In this case, the CPU 808 can create a copy of the plug-in software on the host device. For example, the plug-in software can request a user's PIN in real time, read the user certificate installed on the device (e.g., x.509), and / or others. The operation of the plug-in software can be customized by the service provider. Regardless of this, user feedback data can be compared stored in memory. In alignment, the 802 antenna can be activated. In the case of unsatisfactory matching of the certificate, then the card 800 is deactivated. In the event of a bad PIN match, the user may be asked to repeat entering the PIN until the match is successful or the number of attempts exceeds the threshold. The disk service provider can successfully adjust the trial threshold with user data. In the event of a bad PIN match, the user may be asked to repeat entering the PIN until the match is successful or the number of attempts exceeds the threshold. The disk service provider can successfully adjust the trial threshold with user data. In the event of a bad PIN match, the user may be asked to repeat entering the PIN until the match is successful or the number of attempts exceeds the threshold. The disk service provider can successfully adjust the trial threshold with user data.
[0071] With regard to network authentication, the host device may be a cellular telephone in which the card 800 may request network authentication prior to activation. For example, the card 800 may be distributed by the Wireless Network Operator (WNO), which requires network authentication. In this example, the flag in memory can be set to enabled, indicating that network authentication is required. If the flag is set to enabled, the unique identity with the allowed network is stored locally in memory such as MNC (Mobile Network Code) for GSM networks, NID for CDMA networks, SSID for broadband networks, and / or identifiers. If the flag is enabled, the CPU 808 in response to at least insertion may request a special plug-in software downloaded to the host device and from which the copy is created. This plug-in software can query the host device to answer the details of the network. In some cases, the type of the unique network unit ID and the method of obtaining information about it from the host device may be variable and dependent on the network service provider and the capabilities of the host device. If the locally stored ID corresponds to the requested ID, the CPU 808 activates the 802 antenna to allow access, otherwise the services are denied.
[0072] FIG. 9 shows an example of a transaction system 900 for wirelessly communicating transaction information using one of a plurality of interfaces. For example, the system 900 may combine the transaction card 104 using a wired or wireless interface. With respect to wired interfaces, the system 900 includes an intermediary 904 and a reader 906. The proxy 904 can include any software, hardware, and / or firmware configured to convert between a compatible format with the card 104 a format compatible with the client 504c. For example, the proxy 904 can convert between the microSD protocol and the USB protocol. The reader 906 may include any software, hardware, and / or firmware configured to directly connect to the card 104h. For example, the reader 906 may be a microSD reader that the client 504d connects to the card 104h using the microSD protocol. With regard to wireless interfaces, the system 900 may include a cellular interface 902 and a short-range wireless interface 908. With respect to the cellular interface 902, the institutions 106 may wirelessly communicate with the transaction card 104e using cellular radio technology of the mobile device 106e. For example, the cellular interface 902 may be a CDMA interface, a GSM interface, a UMTS interface, and / or another cellular interface. With respect to the 908 short-range wireless interface, institutions 106 may communicate wirelessly with the transaction card 104f using, for example, Wi-Fi technology.
Bluetooth, and / or another wireless interface. In these implementations, the client 504e may attach a transceiver used for wireless communication with the transaction card 104f.
is a diagram of 1000 card personalization (e.g., transaction cards, memory cards). In particular, the intelligent card can be personalized by issuing it to the user, i.e., the initial edition, or after issuing to the user, i.e., after [0073] FIG. smart edition. With regard to the initial release, smart cards can be personalized in bulk, for example, in a factory. In this example, each smart card can be loaded with user credentials, a security framework, applications, offline websites, and / or other data. In some implementations, the smart card can be personalized individually, for example, by a bank branch. In this case, the smart card can be individually loaded with data associated with the user after, for example, acquisition of the disk. As to the issue, the smart card can be personalized wirelessly. For example, the transaction card 104 may be personalized via a cellular connection established using a mobile device 106. In some implementations, the smart card may be personalized by synchronization with a computer such as the client 504. The transaction card 104 may receive from a company at least affiliated with the institution 506 pre-activation personalization data including user credentials, a payment application, and at least one operational flag, policy tables, or user interface. The personalization data presented in the card can be updated after activation using at least one of the following methods: wireless messages or OTA messages containing specific and secure update instructions; Internet or client application running on a PC connected to the transaction card 104 by a host device or card reader; an internet application wirelessly connected to a transaction card 104 by a host mobile device or a transaction card user interface interface 104; and / or other methods. [0074] In some implementations, the provision of a smart card may be based on at least partially a distribution unit (e.g., a financial institution, a wireless operator, a user). For example, a smart card can be distributed by a financial institution such as a bank. In bank implementation, a smart card can be pre-delivered with user accounts. In this case, the intelligent card may be activated in response to at least the first placement in the host device. Antenna mode can be set to physical authentication only by default. In some examples, the user can choose PIN authentication himself to prevent unauthorized use or by connecting a PC and plug-in software if the host device does not have a screen or keyboard. In a wireless operator implementation, a smart card may need to authenticate the device before activation. In some examples, the user may provide financial data (e.g., credit or debit) using one of several methods. In addition, the user can add user authentication. In the user implementation, the user may acquire a smart card from, e.g. retailer or other channels such as OEMs of the host device. In this case, the user may activate the card in a variety of devices in a manner selected by the provider.
[0075] With respect to the activation of financial transactions, a smart card may be configured in memory mode when the user acquires a disk from, for example a bank, a wireless operator, an external provider, and / or others. Activation of the card may include the following two stages: 1) physical, defining the availability of the antenna at a given set of conditions desired by the provider; and b) logical, in a financial institution denoting the activation of the financial medium on the card. In some implementations, the activation may be based, at least in part, on the device distributor, the choice of antenna availability, and / or the host device type as shown in Table 1 below.
Table 1:
<td>Plug-in Seller and Mode distribution</td><td>Initial Plug-In status and selection of antenna availability</td><td>The device does not have a screen / keyboard</td><td>The device has a screen / keyboard</td>
<td>FI:</td><td>Plug-In is in</td><td>Manually:</td><td>If</td>
<td>Institution</td><td>memory mode,</td><td>user</td><td>the device has</td>
<td>financial</td><td>it can be fully</td><td>must</td><td>wireless</td>
<td>(bank or</td><td>personalized</td><td>call</td><td>access after</td>
<td>retailer)</td><td>information about</td><td>at the number</td><td>inserting, plug-in</td>
<td>forwards</td><td>user account</td><td>FI, to</td><td>in starts</td>
<td>Plug-in</td><td>(FV) and mode</td><td>activate</td><td>website and</td>
<td>directly</td><td>the antenna is</td><td>your account,</td><td>moves</td>
<td>to the subscriber</td><td>set to</td><td>Device</td><td>user on</td>
<td>or from</td><td>physical</td><td>maybe only</td><td>FI page.</td>
<td>participation</td><td>authentication</td><td>work with</td><td>User alone</td>
<td>vendors /</td><td></td><td>single</td><td>he activates his</td>
<td>intermediaries</td><td></td><td>account.</td><td>account via</td>
<td>e.t.c.</td><td></td><td>User</td><td>introduction</td>
<td></td><td></td><td>maybe more</td><td>account number</td>
<td></td><td></td><td>get on</td><td>and</td>
<td></td><td></td><td>page FI in</td><td>fit</td>
<td></td><td></td><td>Internet</td><td>secret</td>
<td></td><td></td><td>use</td><td>personal</td>
<td></td><td></td><td>c Other</td><td>information (on</td>
<td></td><td></td><td>computer,</td><td>example</td>
<td></td><td></td><td>to</td><td>last 4</td>
<td></td><td></td><td>activate</td><td>the numbers of SSN or</td>
<td></td><td></td><td>your account</td><td>home phone number). The user may also optionally choose a PIN</td>
<td></td><td></td><td></td><td>(change authenticated e user on availability antennas) at the same time. If Internet connection is not available, the device can automatically choose voice call with the FI number to activate the account. If wireless connection no It is also available (the device is only PDA) the user must go on manual activation (look to the left)</td>
<td>WNO: Operator</td><td>Plug-In is in</td><td>Lack</td><td>Assumption:</td>
<td>network</td><td>memory mode,</td><td>usage</td><td>Device</td>
<td>wireless</td><td>it is partly</td><td></td><td>It has</td>
<td>j sends</td><td>personalized</td><td></td><td>functional</td>
<td>Plug-in</td><td>(signature</td><td></td><td>wireless</td>
<td>connected with</td><td>devices for</td><td></td><td>connection.</td>
<td>device</td><td>host device</td><td></td><td>Operator</td>
<td>host</td><td>it's loaded,</td><td></td><td>offers</td>
<td>user</td><td>to prevent</td><td></td><td>combined</td>
<td>he can choose</td><td>before change</td><td></td><td>apps</td>
<td>favorable</td><td>host device</td><td></td><td>management</td>
<td>device</td><td>by the user)</td><td></td><td>portfolio. If</td>
<td>host and</td><td>while</td><td></td><td>user</td>
<td>the plugin is from</td><td>FV information no</td><td></td><td>clicks on</td>
<td>connected</td><td>they are loaded.</td><td></td><td>apps</td>
<td>if</td><td>Availability of the antenna</td><td></td><td>management</td>
<td>user</td><td>is set to</td><td></td><td>portfolio,</td>
<td>would like to</td><td>authentication</td><td></td><td>the user is</td>
<td>use the</td><td>devices (plug-in</td><td></td><td>invited to</td>
<td>this service</td><td>it can only be used with the host device it was sent to)</td><td></td><td>login with partner FI operator for new account. When login is successful, account details are Downloads</td>
<td></td><td></td><td></td><td>wirelessly or via Internet to plugin and activated to use. The device can use multiple FIs in this scenario and store a lot of FV. The user can choose introduction of PIN for FV in applications management wallet to convert availability antenna user and authentication and devices for which FV Plug-in is connected with the signature of the device. After removed from the device, the antenna turns off and the plugin transforms into a simple one mass memory. When Plug-in is placed in other device host signature no fits and the antenna stays disabled.</td>
<td>WNO: Operator network wireless j sends plug-in connected to device host</td><td>Plug-In is in memory mode, and is non-personalized. The availability of the antenna is set to network authentication. Plug-In</td><td>Lack usage</td><td>Assumption: Device It has functional wireless connection. Plug-In will connect to</td>
<td>user</td><td>will connect with</td><td></td><td>Internet access</td>
<td>he can choose</td><td>first</td><td></td><td>portal</td>
<td>favorable</td><td>device, to</td><td></td><td>operator and</td>
<td>device</td><td>which he will stay</td><td></td><td>application</td>
<td>host and</td><td>inserted and where</td><td></td><td>management</td>
<td>the plugin is from</td><td>authentication</td><td></td><td>portfolio</td>
<td>it</td><td>network will succeed</td><td></td><td>will be</td>
<td>connected if you would like to use this service.</td><td>a.</td><td></td><td>downloaded after confirmation by user. The user can reject the download and choose manually entering FV data through the use of another wallet provider either directly from the FI website. Plug-In is connected to the device and to the supplier's network. If the device is unlocked and used in another network, the plug-in will not work and will return to memory mode. When removed from the device, the plug-in will return to the mode memory.</td>
<td>OEM 1:</td><td>authentication</td><td>Lack</td><td>Option A:</td>
<td>Manufacturer</td><td>devices</td><td>usage</td><td>Manufacturer</td>
<td>phone</td><td>(device connects</td><td></td><td>Devices</td>
<td>mobile</td><td>with a mobile phone)</td><td></td><td>proposes a portfolio management application, the rest of the process is such as above. Option B: Wireless Operator I suggest apps</td>
<td></td><td></td><td colspan="2"></td><td>management portfolio. The user goes to portal wireless operator and downloads this apps wirelessly. The rest of the process is such as above Option C: user navigates apps management wallet to a third party (for example, paypal or Google). Login is offered to participating FI and FV are personalized in a plugin via the Internet Option D: user navigates to the FI page and activates new ones account that is personalized via the Internet on a plug-in.</td>
<td>OEM 2: different</td><td>authentication</td><td>User</td><td></td><td>If</td>
<td>manufacturer</td><td>devices</td><td>must</td><td></td><td>the device has</td>
<td></td><td></td><td>connect</td><td></td><td>wireless</td>
<td></td><td></td><td>device</td><td></td><td>connection</td>
<td></td><td></td><td>for PC</td><td>with</td><td>(it is</td>
<td></td><td></td><td>access</td><td>down</td><td>wireless</td>
<td></td><td></td><td>Internet</td><td></td><td>PDA): how</td>
<td></td><td></td><td>and</td><td></td><td>above if</td>
<td></td><td></td><td>log</td><td></td><td>device is not</td>
<td></td><td></td><td>on</td><td>PC</td><td>It has</td>
<td></td><td></td><td>by</td><td></td><td>wireless</td>
<td></td><td></td><td>entrance</td><td></td><td>connections</td>
<td></td><td></td><td colspan="2">directly</td><td>(is</td>
<td></td><td></td><td colspan="2">per page</td><td>not connected</td>
<td></td><td></td><td colspan="2">FI. Account</td><td>PDA):</td>
<td></td><td></td><td>is</td><td></td><td>Same as after</td>
<td></td><td></td><td>Downloads</td><td></td><td>left.</td>
<td></td><td></td><td>by Internet and connection a next device is activated. Including process the plug-in is associated with the signature of the device. After removing the host from the device, the antenna turns off. After connecting to another device, the device's signature fails a the device behaves only like mass device memory.</td><td></td>
The presented table is only an example. The user can activate the smart card using the same, similar or different processes without departing from the scope of the disclosure.
[0076] In the implementations illustrated, the transaction card 104 may be upgraded to perform a portfolio system using a plurality of user credentials. For example, the transaction card 104 may be upgraded, e.g., a portfolio management system 728 via a wireless or wired connection. Additionally, to upgrade the card to transaction 104, additional user credentials can be loaded into memory. In this case, the transaction card 104 may selectively switch between different user credentials based, at least in part, on the rules, user selections, events, and / or other aspects.
[0077] FIG. 11 is a diagram illustrating an example of a method 1100 for automatically charging an initial smart card in response to at least placing it into a host device. In general, an intelligent card may perform one or more authentication procedures prior to activation. Many stages in this scheme can be carried out simultaneously and / or in different sequences as shown. The system 500 or system 600 may use methods with additional steps, fewer steps, and / or different steps if the methods are suitable.
[0078] Method 1100 begins at step 1102, where a housing attached to the host device is detected. For example, the transaction card 104 may detect insertion into a mobile device 106. If authentication is not required for any of the aspects of the smart card in decision step 1104, then execution is terminated. If authentication is required for at least one aspect, then execution proceeds to decision step 1106. If communication with the host device includes one or more errors, then, in step 1108, the error is indicated to the user. In an example, the transaction card 104 may show an indication of the communication error of the user using the GUI 111. If the communication error is not detected in decision step 1106, then execution proceeds to decision step 1110. In some implementations, the smart card loads the SD driver into the host device. If the smart card requires only physical authentication, then execution proceeds to decision step 1104. If the network authentication flag is not enabled, then, in step 1114, the antenna is turned on and the smart card is updated with the host-device signature. As for example, the transaction card 104 can activate the antenna for wireless transactions and load local memory with the signature host-device. If the network authentication flag is enabled at decision step 1104, then, at step 1116, the smart card transmits a request for the network ID to the host device. Then, in step 1118, the smart card retrieves the locally stored network ID.
[0079] Returning to decision step 1110, if authentication is not merely physical authentication, then execution proceeds to decision step 1124. If the authentication process involves device authentication, then, in step 1126, the smart card transmits a request for the network ID to the host device. In step 1128, the smart card retrieves locally stored device signatures. If the smart card does not include at least one device signature, then execution proceeds to decision step 1134. If the smart card includes one or more device signatures, then execution proceeds to decision step 1132. If one of the device signatures matches the network ID request, then execution proceeds to decision stage 1134. If the signatures and the network ID request do not match, then execution proceeds to step 1122 for deactivation. If user authentication is not included in the authentication process, then execution proceeds to decision step 1112 for physical authentication. If user authentication is included in decision step 1134, then execution proceeds to step 1138.
[0080] Returning to decision step 1124, if the authentication process does not involve device authentication, then execution proceeds to decision step 1136. If user authentication is not included in the process, then, in step 1122, the smart card is turned off. If the user authentication is included, then, in step 1138, the smart card requests the PIN number from the user using the host device. During authentication, the user is described in relation to the PIN being entered via the mobile host device, the user may be authenticated using other information such as biometric information (e.g., fingerprint). Again, returning to the example, the transaction card 104 may request the user to enter the PIN through the GUI 111. In step 1140, the smart card retrieves a locally stored PIN. If the PIN request and the stored PIN match at decision step 1142, then execution proceeds to decision step 1104 for physical authentication. If the PIN request and the stored PIN do not match in decision step 1142, then execution proceeds to decision step 1144. If the number of attempts does not exceed a certain threshold, then execution returns to step 1138. If the number of attempts has exceeded the threshold, then the antenna is deactivated in step 1122. In the example, if the transaction card 104 does not authenticate the device, network and / or user, the transaction card 104 can wirelessly give an indication to the associated financial institution using cellular radio technology of the host mobile device 110. In this case,
[0081] FIG. 12 is an example of a callout scheme 1200 in accordance with some implementations of the disclosure. As illustrated, schema 1200 includes network 1202, host device 1204, smart card 1206, and terminal 1208. Host device 1204 is configured to connect to network 1202 and includes a slot for inserting smart card 1206. Smart card 1206 is configured to transmit commands to and receive data from the user interface application 1210 performed by the host device 1210 and execute transactions independent of the host device 1210. The card 1206 includes a CPU 1212 for performing transactions and a wireless chipset 1214 for communication with the terminal 1208. The CPU 1212 performs a host controller / API 1216 configured,
[0082] As illustrated, schema 1200 may include multiple sessions 1220 between host 1204 and card 1206 and between tab 1206 and terminal 1208. Session 1220a shows the session managed by card 1206 using the network capabilities of host device 1210. In this example, card 1206 gives data to be transmitted over a cellular network connected to the host device 1204, and upon receiving cellular data, the host device 1204 transmits data to the network 1202. In response to receiving data from the network 1202, the host device 1204 can automatically transmit the received data to the card 1206. implementations, the card 1206 may transmit a device signature request to the host device 1204 as shown in session 1220b. For example, the card 1206 may request the device signature during the bootstrap process.
[0083] In some implementations, the card 1206 may receive a command to enable or disable the antenna via the host device 1204 as shown in session 1220d. For example, a financial institution may identify invalid transactions and issue a command over network 1202 to deactivate card 1206. Tab 1206 may authenticate a user by requesting a PIN using host device 1204. As shown in session 1220e, a user may enter a PIN into the card 1206 using the interface of the host device 1204, and in response to the evaluation of the given PIN, the card 1206 may display through the host device 1204 an indication that the user verification was successful or not. In some implementations, the user and / or financial institution may request the transaction history of the 1206 card as shown in session 1220f. For example, a financial institution may request a transaction history via a network 1202 connected to the host device 1204, and in response to at least a request, the card 1206 may assign a transaction history to a financial institution using the network 1202 connected to the host device 1204. In some implementations, the user may present offline web pages stored in tab 1206, as illustrated in session 1220. For example, tab 1206 may receive the request to display the offline web page by the user using the host device 1204 and present the offline page using the URL in the request. In some implementations, data stored in the memory of the card 1206 may be represented by, for example, a host device 1204 as shown in session 1220h. E.g, the user may request specific information associated with the transaction with specific data, and the card 1206 may retrieve data and present data to the user using the host device 1204. In addition, the user may enter data into the memory in the card 1206 as shown in session 1220i. For example, a user can update data with an annotation transaction, and in response to at least a request, card 1206 can indicate whether the update was successful or not.
[0084] Regarding the session between the card 1206 and the terminal, the scheme 1200 depicts a personalization session 1220k and a transaction session 12201. With regard to personalization, the financial institution may personalize the card 1206 with user credentials, user applications, web pages, and / or other information as shown in the 1220k session. For example, the terminal 1208 may transmit a request to the card 1206 including related data. Protocol translation 1218 may transform the personalization request into a form compatible with the card 1206. In response to at least request, the CPU 1212 transmits an indication of whether the personalization was successful or not using the protocol translation 1218. Before the terminal executes the transaction, the terminal 1208 may forward the transaction call to the card. 1206 as shown in session 12201.
[0085] FIG. 13 is a diagram illustrating an example of a method 1300 for activating a wireless transaction system including a smart card. Generally, an intelligent card may perform one or more activation processes in response to, e.g., user selection. Many stages in this scheme can be performed simultaneously and / or in different order as shown. The system 500 or system 600 may use methods with additional steps, fewer steps, and / or other steps if the methods are suitable.
[0086] Method 1300 begins at step 1302 where a request is received to activate the card for the transaction. For example, the user may select a graphic element displayed by the GUI 116 of the host device 106 of FIG. 1. If account activation is included in decision step 1304, then in step 1306, the request to activate the associated financial account is wirelessly transmitted to the financial institution using the cellular radio technology of the host device. For example, the transaction card 104d of Fig. 5 may wirelessly send a request for activation to the institution 506 using the cellular radio technology of the host mobile device 106d. If account activation is not included, then execution proceeds to decision step 1308. If the activation of the card is not included, then execution is terminated. If card activation is included, then execution proceeds to decision step 1310. If the activation code is not included, then in step 1312, one or more pre-programmed questions are presented to the user using the GUI of the host device. Returning to the initial example, the transaction card 104 may identify locally stored questions and present questions to the user using the GUI 116 of the host mobile device 106. In step 1314, the locally stored responses to the programmed questions are identified. Returning to decision step 1310, if the activation code is included, then execution proceeds to decision step 1316. If the activation code is manually entered by the user, then in step 1318, the activation code request is presented to the user via the host mobile device GUI. In the initial example, the transaction card 104 may present a request for an activation code such as a user string through the GUI 116 of the host mobile device 106. If the activation code is not manually entered by the user, then in step 1320, the transaction card wirelessly requests the activation code using cellular radio technology of the host device. In a cellular example, the transaction card 104 may send a request to a financial institution using the core cellular network 602. In any case, the locally stored activation code is identified in step 1322. If the locally stored information matches the information provided at decision step 1324, then in step 1326, the transaction card is activated. For example, the transaction card 104 may be activated in response to at least the introduction of a corresponding activation code by the user GUI 116. If the information provided does not correspond to the locally stored information, then execution is terminated.
[0087] FIG. 14 depicts an example of secure memory 1400 in accordance with some implementations of the disclosure. In general, the secure memory 1400 is configured to store user credentials for a wide variety of financial institutions. For example, the authenticator may be associated with the user (e.g., by credit card, bank account). In the depicted implementation, secure memory 1400 includes user credentials 1402a-c and associated security frameworks 1406a-c separated by logical barriers 1410-c. In addition, secure memory 1400 includes primary authentication data 1404 and a primary security framework 1408. Each user authentication data 1402 may be associated with a different user account and / or each other account with an institution. For each user, the credential 1402 is associated or otherwise associated with the security framework 1406. The security framework 1406 may be a payment application executed by the smart card in response to at least a user account selection. For example, the security framework 1406 can perform transactions according to a specific format, protocol, encryption, authentication.
security and / or other aspects of the request In some implementations, the framework 1406 may substantially prevent unauthorized access to user credentials. For example, each security framework 1406 may include a plurality of keys that provide different levels of access. Each application in the skeleton 1406 may then be configured to be available according to certain security levels. In some implementations, security frameworks 1406 may include different versions of payment applications for a type of financial instrument (e.g., Visa). In some implementations, the security framework 1406 may be identified using the application ID.
[0088] The main credential 1404 and the primary security framework 1408 may allow financial institutions to store or update user credentials 1402 and related security frameworks 1406. For example, the creation of a new key in the security framework 1406 may be protected by the primary key backbone. The barriers 1410 may generate security domains between various selectable credentials of the user 1402 and the associated managed account with the associated security framework 1406. For example,
In some implementations, a smart card (e.g., transaction card 104) can dynamically switch between user credentials 1402 and security frameworks 1406 in response to at least an event. For example, the smart card may switch to the default user credentials 1402 and the corresponding security framework 1406 after the transaction is completed. In some implementations, the smart card may switch user credentials 1402 and security framework 1406 in response to a user through, for example, a GUI 116. The smart card may by default switch between different user accounts based on at least partially different conditions. With regard to adding additional user accounts, the user can manually enter user credentials 1402 using the GUI of the host device. In some implementations, the memory 1400 can be updated OTA using cellular radio technology of the host device.
[0090] FIG. 15 is a diagram illustrating an exemplary method 1500 for dynamic switching between accounts choosing Fig. 1.
user. Generally, an intelligent card can dynamically switch between multiple selectable user credentials and associated security frameworks in response to at least an event. Many steps in this scheme can, as shown, take place simultaneously and / or in different order. The system 100 may use methods with additional steps, fewer steps, and / or different steps if the methods remain appropriate.
[0091] Method 1500 begins at step 1502, where the event is identified. For example, the transaction card 104 of Fig. 1 may specify that one or more of the following has been updated: network ID, telephone number, MAC address, and / or other information. In some implementations, the event may include identifying one or more aspects of the transaction or potential transaction. For example, the transaction card 104 may specify an enterprise, business type, goods and / or services, types of goods and / or services, and / or other aspects. In step 1504, the currently selected user account is determined. In an example, the transaction card 104 may determine the currently selected user credentials and the security framework. If user accounts are changed in decision step 1506, then, in step 1508, the smart card dynamically switches the currently selected user account to a different user account based on at least partially identified event. Again in the example, the transaction card 104 may dynamically change between multiple selectable user accounts based on, at least partially, one or more events.
Then, in step 1510, a request for execution is received. For example, the transaction card 104 may directly receive a wireless request to execute a transaction from the access point 514. In response to at least a request, the request to perform the transaction is presented to the user in step 1512. In an example, the transaction card 104 may request the user through the GUI 116 of the host device 106. In some implementations, the transaction card 104 may present to the user the currently selected user account via the GUI 116. In step 1514, the transaction request is performed using the selected user credentials and the corresponding security backbone in response to at least selection by the user. Again in the example, the transaction card 104 may execute a transaction request in response to at least a user selecting a graphic item in the GUI 116 of the host mobile device 106 and wirelessly transmit the authentication request directly to the access point 514. If the account selection is changed to the default account in decision step 1516, the intelligent the card automatically switches the selected user account to the default user credentials and the corresponding security framework. If the selection is not changed to the default account, execution is then terminated. If the account selection is changed to the default account in decision step 1516, the smart card automatically switches the selected user account to the default user credentials and the corresponding security framework. If the selection is not changed to the default account, execution is then terminated. If the account selection is changed to the default account in decision step 1516, the smart card automatically switches the selected user account to the default user credentials and the corresponding security framework. If the selection is not changed to the default account, execution is then terminated.
22414 / EP / 12
EP2196010 B1
Contents2
8 priority claims, no other members on record
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 97181307 | United States of America | P | |
| 97181307 | United States of America | P | |
| 08830698 | European Patent Office (EPO) | A | |
| 2008076275 | United States of America | W | |
| 2008076275 | United States of America | W | |
| EP20080830698 | – | – | – |
| US20070971813P | – | – | – |
| WO2008US76275 | – | – | – |
Numbers
- Publication, DOCDB
- 2196010
- Publication, EPODOC
- PL2196010T
- Application
- 830698
- Application, DOCDB
- 08830698
- Application, EPODOC
- PL20080830698T
Titles2
- English
- UPDATING MOBILE DEVICES WITH ADDITIONAL ELEMENTS
- Polish
- Aktualizacja urządzeń mobilnych dodatkowymi elementami
Classification
- CPC, 43
- G06K19/07739
- G06Q20/34
- G06Q20/20
- G06Q20/341
- G06Q20/352
- G06Q20/355
- G06Q20/3574
- G06Q20/3576
- G06Q40/00
- G07F7/0886
- G07F7/1008
- H04L63/083
- H04L2463/102
- H04M1/0274
- H04M17/103
- H04M17/106
- H04M2017/12
- H04M2017/14
- H04W88/02
- H04W52/0254
- H04W52/0274
- G06Q20/3227
- G06Q20/3278
- H04B1/3816
- H04W12/08
- Y02D30/70
- G06Q20/326
- H04M1/7246
- H04W12/069
- H04W12/068
- G06Q20/04
- H04B5/48
- G06K19/07707
- G06K19/07773
- G06Q20/3223
- G06F21/34
- H04L63/0853
- G06Q20/3226
- G06Q20/325
- G06K7/10237
- G06Q20/322
- H04L41/32
- H04L63/0876
- IPC, 3
- G06F1 16
- H04M1 02
- H04M1 7246