Methods and systems for securing and utilizing a personal data store on a mobile device

    公开(公告)号:US11405782B2

    公开(公告)日:2022-08-02

    申请号:US16925688

    申请日:2020-07-10

    Inventor: Ashfaq Kamal

    Abstract: Methods and apparatus for securing access to an encrypted personal data store on a mobile device. In some embodiments, a universal integrated circuit card (UICC) processor receives, from a mobile device processor of a mobile device having an encrypted Personal Data Store (PDS), a PDS access request associated with a mobile application, then determines that access control rules are stored in at least one access control rules database and transmits to the mobile device processor, the access control rules governing access to the data in the encrypted PDS. The process also includes the UICC processor receiving a request for a symmetric shared secret and transmitting the symmetric shared secret to the mobile device processor for use in accessing the PID of the user stored in the encrypted PDS in accordance with the access control rules.

    Methods for securely storing sensitive data on mobile device

    公开(公告)号:US11238139B2

    公开(公告)日:2022-02-01

    申请号:US16751534

    申请日:2020-01-24

    Inventor: Ashfaq Kamal

    Abstract: Methods and systems for protecting sensitive data and applications on a mobile device. In an embodiment, a mobile device processor of a mobile device downloads, from a digital wallet server computer, a mobile wallet application including a white box software development kit (SDK) which includes code protection processes, then obfuscates, by running the code protection processes of the white box SDK, consumer financial data and consumer authentication data and stores the obfuscated consumer financial data and consumer authentication data in a regular memory of the mobile device. The process also includes protecting, by the mobile device processor running the white box SDK, sensitive applications stored in the regular memory which execute during a transaction from attack, and re-obfuscating, by the mobile device processor, at least one of the consumer financial data and the consumer authentication data according to a predetermined time interval.

    SYSTEMS AND METHODS FOR MANAGING DIGITAL IDENTITIES ASSOCIATED WITH MOBILE DEVICES

    公开(公告)号:US20210409397A1

    公开(公告)日:2021-12-30

    申请号:US17473630

    申请日:2021-09-13

    Abstract: Systems and methods are provided for enabling, providing, and managing digital identities in association with mobile devices. One example method includes determining, by a mobile device, that identity data of a user is changed, and prompting the user to identify a third party separate from the mobile device to authenticate the user. The method also includes requesting the third party to authenticate the user, and causing an authentication interface of the third party to be displayed at the mobile device where the authentication interface solicits login credentials for an account of the user at the third party. The method then includes granting, by the mobile device, access to one or more aspects of a mobile application installed at the mobile device, in response to an indication of a successful authentication of the user from the third party.

    SYSTEMS AND METHODS FOR USE IN MANAGING DIGITAL IDENTITIES

    公开(公告)号:US20210383388A1

    公开(公告)日:2021-12-09

    申请号:US17409530

    申请日:2021-08-23

    Abstract: Systems and methods are provided for managing digital identities associated with users. One exemplary method includes receiving, at a computing device, an encrypted message from a communication device associated with a user where the message includes a changed attribute for the user. The method also includes generating a first hash of a first digital identity for the user with the changed attribute and generating a second hash of a second digital identity of the user stored in a ledger data structure. And, in response to the first hash not matching the second hash, the method then includes broadcasting a pending status of the first digital identity to a relying party for the second digital identity, and storing a certification of the changed attribute, received from the relying party in response to the pending status, based on verification of the changed attribute by the relying party.

    Systems and methods for managing digital identities associated with mobile devices

    公开(公告)号:US11122036B2

    公开(公告)日:2021-09-14

    申请号:US16134348

    申请日:2018-09-18

    Abstract: Systems and methods are provided for use in enabling, providing, and managing digital identities in association with mobile communication devices. One exemplary method includes capturing an image of a physical document comprising a biometric of a user associated with the physical document, and extracting the biometric from the image and converting it to a biometric template. The method also includes capturing a biometric of the user and comparing it to the biometric template. The method then includes, when the captured biometric matches the biometric template, transmitting a message to an identification provider comprising at least the image of the physical document and the biometric template, whereby the biometric template is verified against a repository, and binding data representative of the mobile communication device, a mobile application included therein, and the biometric template and/or the captured biometric of the user into a token.

    METHODS AND SYSTEMS FOR SECURELY STORING SENSITIVE DATA ON SMART CARDS

    公开(公告)号:US20180219680A1

    公开(公告)日:2018-08-02

    申请号:US15422611

    申请日:2017-02-02

    Abstract: Methods and systems for permitting sensitive cardholder data to be securely stored in a regular storage element of a smart transaction card. In an embodiment, a transaction card processor of the smart transaction card installs a security application compatible with the operating system of the smart transaction card and that includes a white box cardlet. The transaction card processor uses a code protection process of the white box cardlet to obfuscate biometric reference template data stored in the regular memory of a biometric sensor, next stores the obfuscated biometric reference template data in the regular memory, and then re-obfuscates the biometric reference template data at a predetermined time interval.

    METHODS AND SYSTEMS FOR BROWSER-BASED MOBILE DEVICE AND USER AUTHENTICATION

    公开(公告)号:US20170243224A1

    公开(公告)日:2017-08-24

    申请号:US15047129

    申请日:2016-02-18

    Inventor: Ashfaq Kamal

    CPC classification number: G06Q20/40145 G06Q20/10 G06Q20/322 G06Q20/3224

    Abstract: Methods and systems for authenticating both a browser-based user mobile device and the user in association with an online transaction. In an embodiment, the process includes receiving, by a cloud-based authentication service computer, a user authentication request from a user mobile device. A mobile transaction application determines that the user and the entity involved in the online transaction are enrolled in a cloud-based authentication service, identifies a user data structure and a user profile, determines that the received user authentication data and user mobile device identification data matches data stored in the user profile, and determines that a requirement of the entity is satisfied. The mobile transaction application then transmits a positive user authentication message to an entity computer.

    OPEN, ON-DEVICE CARDHOLDER VERIFICATION METHOD FOR MOBILE DEVICES
    10.
    发明申请
    OPEN, ON-DEVICE CARDHOLDER VERIFICATION METHOD FOR MOBILE DEVICES 审中-公开
    用于移动设备的开放式设备摄像机验证方法

    公开(公告)号:US20160162893A1

    公开(公告)日:2016-06-09

    申请号:US14561575

    申请日:2014-12-05

    CPC classification number: G06Q20/405 G06Q20/3226 G06Q20/34

    Abstract: An open, on-device Cardholder Verification Method (“CVM”) controller may receive CVM policies from issuers and store the policies in a database. The open, on-device CVM controller may then receive a request from a remote mobile device, and automatically determine at least one issuer associated with the request. Appropriate CVM policies may be retrieved and transmitted to the remote mobile device. An open, on-device CVM application executing on the mobile device may then receive a CVM authentication request, associated with a payment token, from a payment application. Responsive to the authentication request, a CVM policy may be accessed based on the payment token. It may then be arranged for an authenticator of the mobile device to authenticate a user in accordance with the CVM policy. When the user is authenticated, an authentication success indication may be sent from the open, on-device CVM application to the payment application.

    Abstract translation: 开放的设备上的持卡人验证方法(“CVM”)控制器可以从发行者接收CVM策略,并将策略存储在数据库中。 打开的设备上的CVM控制器然后可以从远程移动设备接收请求,并且自动地确定与该请求相关联的至少一个发行者。 可以检索适当的CVM策略并将其发送到远程移动设备。 在移动设备上执行的开放的设备上CVM应用程序然后可以从支付应用程序接收与支付令牌相关联的CVM认证请求。 响应于认证请求,可以基于付款令牌来访问CVM策略。 然后可以安排移动设备的认证者根据CVM策略认证用户。 当用户被认证时,认证成功指示可以从打开的在设备CVM应用发送到支付应用。

Patent Agency Ranking