SYSTEM AND METHOD FOR FRAUD DETECTION
    1.
    发明申请

    公开(公告)号:US20180330382A1

    公开(公告)日:2018-11-15

    申请号:US15977742

    申请日:2018-05-11

    发明人: Geng Chen Pai Peng

    摘要: A method for authenticating a counterparty to a digital transaction includes obtaining, at a mobile terminal from a unverified counterparty, characteristic content associated with the digital transaction to be displayed in a trusted user interface provided by the mobile terminal, sending, by the mobile terminal, data associated with the characteristic content to an authentication server; and obtaining, from the authentication server, a result of an authentication judgment by the authentication server, the authentication judgment based on the data associated with the characteristic content and an item of reference content.

    SCREENSHOT BASED TUI PROCESS FOR IN-APP PURCHASE AUTHENTICATION

    公开(公告)号:US20200081615A1

    公开(公告)日:2020-03-12

    申请号:US16124991

    申请日:2018-09-07

    摘要: A method for generating a secure single-tap authentication user interface includes obtaining a screenshot of content from an application operating in an execution environment outside of a trusted execution environment, generating graphical elements of a single-tap authentication user interface, and generating a progress switching layer. Additionally, the method includes responsive to an authentication request, generating a composited display, the composited display comprising the screenshot of content from the application, the graphical elements of the single-tap authentication user interface, and the progress switching layer, passing the composited display from outside the trusted execution environment to the trusted execution environment and displaying, by the trusted execution environment, the composited display as part of a trusted user interface (TUI).

    Screenshot based TUI process for in-app purchase authentication

    公开(公告)号:US11204693B2

    公开(公告)日:2021-12-21

    申请号:US16124991

    申请日:2018-09-07

    摘要: A method for generating a secure single-tap authentication user interface includes obtaining a screenshot of content from an application operating in an execution environment outside of a trusted execution environment, generating graphical elements of a single-tap authentication user interface, and generating a progress switching layer. Additionally, the method includes responsive to an authentication request, generating a composited display, the composited display comprising the screenshot of content from the application, the graphical elements of the single-tap authentication user interface, and the progress switching layer, passing the composited display from outside the trusted execution environment to the trusted execution environment and displaying, by the trusted execution environment, the composited display as part of a trusted user interface (TUI).

    Trust-zone-based end-to-end security

    公开(公告)号:US10193700B2

    公开(公告)日:2019-01-29

    申请号:US15054020

    申请日:2016-02-25

    IPC分类号: H04L9/32 H04W12/06 H04L29/06

    摘要: Methods, electronic devices, and systems for exchanging encrypted information. A method for exchanging encrypted information by an electronic device includes generating one or more device certificates and one or more device public private key pairs. The one or more device certificates are signed using a device unique private key that is pre-stored on the electronic device. The method also includes sending the one or more device certificates to a server of a token service provider (TSP). The method further includes receiving one or more TSP certificates from the TSP server. The method includes identifying one or more TSP public keys of the TSP server based on the one or more received TSP certificates. Additionally, the method includes transmitting a message including the information encrypted based on the one or more identified TSP public keys and a signature of the electronic device.

    System and method for trustzone attested authenticators

    公开(公告)号:US09787648B2

    公开(公告)日:2017-10-10

    申请号:US14596040

    申请日:2015-01-13

    IPC分类号: H04L9/32 H04L29/06

    摘要: A method includes receiving a challenge from an authentication consumer. The method also includes generating for display a figure associated with an identification, a public certificate, and a private key after receiving the challenge. The figure, the identification, the public certificate, and the private key are stored in a TrustZone (TZ) enriched environment. The method further includes receiving an input identification. The method includes verifying that the input identification matches the identification. The method also includes transmitting the challenge to the authentication consumer in response to verifying that the input identification matches the identification.

    TRUST-ZONE-BASED END-TO-END SECURITY
    10.
    发明申请
    TRUST-ZONE-BASED END-TO-END SECURITY 审中-公开
    基于信任区域的端到端安全

    公开(公告)号:US20160254918A1

    公开(公告)日:2016-09-01

    申请号:US15054020

    申请日:2016-02-25

    IPC分类号: H04L9/32 H04W12/06 H04L29/06

    摘要: Methods, electronic devices, and systems for exchanging encrypted information. A method for exchanging encrypted information by an electronic device includes generating one or more device certificates and one or more device public private key pairs. The one or more device certificates are signed using a device unique private key that is pre-stored on the electronic device. The method also includes sending the one or more device certificates to a server of a token service provider (TSP). The method further includes receiving one or more TSP certificates from the TSP server. The method includes identifying one or more TSP public keys of the TSP server based on the one or more received TSP certificates. Additionally, the method includes transmitting a message including the information encrypted based on the one or more identified TSP public keys and a signature of the electronic device.

    摘要翻译: 方法,电子设备和用于交换加密信息的系统。 用于通过电子设备交换加密信息的方法包括生成一个或多个设备证书和一个或多个设备公共私钥对。 一个或多个设备证书使用预先存储在电子设备上的设备唯一专用密钥进行签名。 该方法还包括将一个或多个设备证书发送到令牌服务提供商(TSP)的服务器。 该方法还包括从TSP服务器接收一个或多个TSP证书。 该方法包括基于一个或多个接收的TSP证书来识别TSP服务器的一个或多个TSP公开密钥。 此外,该方法包括发送包括基于一个或多个所识别的TSP公钥加密的信息和电子设备的签名的消息。