The present invention relates to a secure Personal Identification Number (PIN) Entry Device (PED) and more particularly to a secure PED device that is integrated with mobile phone devices.
Secure PEDs are used in connection with Point of Sale (POS) devices, ATMS, or computers for performing secure PIN entry requiring electronic transactions. These transactions are typically payment transactions or secure information exchange. The function of the PEDs is to prevent third parties from tampering with the above mentioned transaction devices in an attempt to steal the PIN from consumers who use them. PEDs must go through a certification process administered by local or global certification authorities. In order for the PEDs to pass the certification process they must meet certain security standards including secure storage of public/private keys provided from acquiring banks and processors for encryption and authentication. The PEDs must also have the ability to deter tampering with the device, i.e., be “Tamper Resistant”, “Tamper Evident”, and “Tamper Responsive”. A device is “Tamper Resistant” if it prevents easy access to the PED and does not allow third parties to intercept the key strokes and steal the customer's PINs. A device is “Tamper Evident” if it becomes very apparent to the user when the device has been tampered with. A device is “Tamper Responsive” if in case someone attempts to tamper with the PED, the secure data of the PED that are used for the transactions get automatically erased from the memory thereby making the device useless for secure transactions. In one example, the certification requirements for the PEDs are described in the Payment Card Industry (PCI) PED specification, published on the Visa International website http://international.visa.com/fb/vendors/pin/reference.jsp. A secure PED must be certified by the appropriate authorities approved by Visa and MasterCard and once it has passed certification according to specifications and test, the device name is published as “certified.” A secure PED may be a stand-alone device or it may be integrated with the transaction device, as is the case for POS and ATM. However, most PEDs have a rectangular, box-like form and are usually large compared to typical mobile phone devices.
A mobile phone device is defined by its functionality and “form factor”. The main function of a mobile phone is to make phone calls in a mobile environment. Accordingly, a mobile phone or phone module includes hardware and software components that provide voice and data functionality over a wireless network. Today there are simple low cost mobile phones that perform just phone calls. There are also more expensive mobile phones that come with different ancillary features like digital cameras, PDA features, SMS, MMS, music, games, email, video streaming, among others. However, the core function of a mobile phone is simply its ability to make phone calls and if this function is removed the device is not a mobile phone anymore. Conversely if there is phone capability and any of the other ancillary features are removed, the device would still be a mobile phone. However, having the ability to make a phone calls in mobile environments alone does not make a device a “mobile phone”.
Another important characteristic that defines a mobile phone is its “form factor”, i.e., the look and feel of the device. Mobile phones come in several different physical styles or “form factors”. While manufacturers are continually coming up with new types of designs, there are several common categories used to describe form factors of mobile phones:
All these mobile phone designs are recognized as mobile phones and have the following common features. They are small enough so as to fit in a person's hand. Typical dimensions are in the range of 2-8 inches length and 1.5-3 inches width. They have a shape such that one can put the mobile phone up to his ear to listen and at the same time close to his mouth to talk. They have low weight. The weight is in the range of 4-9 ounces. If the device is larger or smaller it acquires another recognizable form factor. For example, a PC or a laptop can perform mobile phone functions when one plugs a radio module into it, but it still has the form factor of a PC or a laptop. The same is true with Tablet PC, or even a POS device that can perform mobile phone functions like a Lipman8000 mobile POS which can also dial a phone call, nonetheless it is still has a POS form factor and not a mobile phone form factor. Today's convergence of PDAs and mobile phones is still considered by the general public as having the form factor of a mobile phone because of size, shape and weight. These PDA-mobile phone devices are sized to fit into one's hand and one can hold them up close to his ears to listen and at the same time close to his mouth to talk in a way similar to how the average person would consider using a mobile phone. A larger size or a smaller size than that would start turning the mobile phone into a different form factor. For example one day when mobile phone capabilities are inserted into a wristwatch, that form factor will no longer be a mobile phone form factor, but it would be the form factor of a wristwatch. Thus form factor is important for defining a mobile phone.
Mobile phones have been combined with card readers to provide a new range of POS type terminals for conducting financial services transactions. While there are several card readers available today for mobile phones, offered by Semtek, Symbol, Apriva, none of these devices meet the PED security certification requirements. Most of these prior art devices are focused on the credit card market and are not designed for conducting debit card transaction where PIN entry is required. The keypads on the mobile phones are not secure and have not been approved or certified by major financial institutions. Accordingly, the current mobile phone-card reader combination devices do not meet the security requirements and cannot be certified for PIN entry requiring transactions.
Prior art POS devices with a certified PED have used a phone as an external modem for providing communications, similar to the way personal computers use a phone as an external modem for providing communications. However this is not a certified PED “integrated” with the phone as one device, but rather a POS that links to a phone. All these prior art POS devices function as standalone POS that link to other communication mediums, such as cable modems, DSL modems, or other dialup terminals, independent of the phone and thus are not considered to be an integrated unit with the phone. Furthermore, these devices do not have the form factor of a mobile phone. There are also prior art POS with a certified PED that use a wireless modem. However, these are wireless POS devices, and not a wireless mobile phone-POS with an “integrated” secure PED. Also, these devices do not have the form factor of a mobile device. Some of the wireless POS allow one to plug a separate microphone headset to dial a phone call, but it is still a POS and has the form factor of a POS and one would not consider it a mobile phone.
Accordingly, there is a need for a secure PED module that is certified by the various financial institutions and can be integrated with a mobile phone as one device to provide the small and convenient form factor and functionality of a mobile phone, while having the capabilities of a secure PED to enable POS various payment transactions including debit, and EMV.
In general, in one aspect this invention features a secure mobile phone-point of sale (mobile phone-POS) system for conducting secure PIN entry requiring electronic transactions. The secure mobile phone-POS includes a mobile phone, a secure PED and software and hardware components for processing the secure PIN entry requiring electronic transactions. The secure PED includes a keypad, a screen display and security components effecting the keypad and the screen display to meet certification requirements of a certification institution for conducting the secure PIN entry requiring transactions. The secure PED is integrated with the mobile phone and the system has the functionality of both the mobile phone and the secure PED.
Implementations of this aspect of the invention include the following. The secure mobile phone-POS system has a mobile phone form factor. The mobile phone form factor may be bar type, clamshell, flip or slide. The mobile phone-POS system has a length in the range of 2-8 inches, width in the range of 1.5-3 inches and weight in the range of 5-10 ounces. The mobile phone includes a serial interface port and the secure PED is integrated with the mobile phone via the serial interface port. The mobile phone includes a Printed Circuit Board Assembly (PCBA) and the secure PED is integrated directly with the mobile phone's PCBA. The mobile phone includes a mobile phone PCBA and the secure PED comprises a PED PCBA and the mobile phone PCBA is integrated with the PED PCBA via a connector. The secure PED includes a Printed Circuit Board Assembly (PCBA) and the mobile phone includes a radio communication module integrated directly onto the secure PED's PCBA. The mobile phone further includes an antenna, a speaker, and a microphone, and the antenna, the speaker and the microphone are integrated directly onto the secure PED's PCBA. The mobile phone-POS system further includes a PCBA and the mobile phone and the secure PED are integrated directly onto the mobile phone-POS PCBA. The mobile phone includes a Subscriber Identification Module (SIM) slot and the secure PED is integrated with the mobile phone via the SIM slot. The certification requirements of a certification institution may be the Payment Card Industry (PCI) PED specification, Europay MasterCard Visa (EMV) Level 1 and level 2 standard compliance, Bank Card testing Center of China (BCTC), Zentraler Kreditausschuss (ZKA) and Interac. The security components include a microprocessor, RAM, SAM slot for receiving a SAM module, smart card reader/writer, screen display, keypad, battery, flash memory, erasable memory, and detector switches, serial port, magnetic card reader, hardware id, real time clock, Bluetooth, Infrared port, SIM slot for connecting to the mobile phone or SIM slot for receiving a SIM card. The software components include a secure transaction application and a transaction application commanding protocol (TACP). The hardware components include microprocessor, RAM, SIM slot, SIM card, SAM card, SAM slot, smart card reader/writer, screen display, keypad, battery, flash memory, erasable memory, serial port, magnetic card reader, real time clock, Bluetooth, Infrared port, IrDA and printer. The software and hardware components for processing the secure PIN entry requiring electronic transactions may be included in the secure PED or the mobile phone. The mobile phone may also include a phone screen display and a phone keypad that do not meet certification requirements of a certification institution for conducting the secure PIN entry requiring transactions.
In general in another aspect the invention features a secure mobile phone-POS system for conducting secure PIN entry requiring electronic transactions, including a mobile phone, a secure PED and software and hardware components for processing the secure PIN entry requiring electronic transactions. The mobile phone includes a keypad, a screen display, a Printed Circuit Board Assembly (PCBA) and software and hardware components for processing the secure PIN entry requiring electronic transactions. The secure PED includes security components effecting the keypad and the screen display of the mobile phone to meet certification requirements of a certification institution for conducting the secure PIN entry requiring transactions. The secure PED is integrated directly with the mobile phone's PCBA. The secure mobile phone-POS has the functionality of both the mobile phone and the secure PED and a mobile form factor
In general in another aspect the invention features a method for conducting secure PIN entry requiring electronic transactions, comprising the following steps. First providing a mobile phone. Next, providing a secure PED that includes a keypad, a screen display and security components effecting the keypad and the screen display to meet certification requirements of a certification institution for conducting the secure PIN entry requiring transactions. Next, providing software and hardware components for processing the secure PIN entry requiring electronic transactions. Finally, integrating the secure PED with the mobile phone to form one unit.
In general in another aspect the invention features a pin entry device including a keypad, a screen display and security components effecting the keypad and the screen display to meet certification requirements of a certification institution for entering and displaying security sensitive information, respectively. The pin entry device is integrated with a non-secure mobile phone thereby upgrading the mobile phone's non-secure screen display and keypad with the security components.
Among the advantages of this invention may be one or more of the following. The secure PED is a self-sufficient payment enabling module. It is capable of accepting entry and displaying information in a way that satisfies the payment card industry security standards. The secure PED performs electronic payment transactions by interacting with banking cards and payment processors. Depending on the level of integration the secure PED may not have payment processing functionality implemented by the device itself. The secure PED is responsible for the secure PIN entry and display functionality and the mobile phone is responsible for sending the data for processing of the transaction by a host. The secure PED with or without payment processing capability conforms to security standards imposed by the payment industry. These standards are the same standards that are applicable for networked POS (Point Of Sale) Terminals commonly used in the industry.
Referring to
There are several ways of integrating the secure PED 90 to a mobile phone 200. Referring to
Referring to
Referring to
Referring to
Examples of integrated mobile phone-POS systems 100 are shown in
The integrated mobile phone-POS system 100 includes all the hardware components and software components that are required to process electronic payment transactions for banking cards. In one example these software components include a secure transaction application and a transaction application commanding protocol (TACP), described in U.S. patent application Ser. No. 11/226,823, filed on Sep. 14, 2005, and entitled “SYSTEM AND METHOD FOR A SECURE TRANSACTION MODULE” the contents of which are expressly incorporated herein by reference. Only external power supply and communication channel are needed to successfully authorize transaction with the card issuing institution. Depending on the level of integration the PED may not have payment processing functionality implemented by the device itself. In such cases payment processing functionality may be performed by the mobile phone. However, the PED is still responsible for the secure PIN entry and display functionality. The PED with or without payment processing capability conforms to security standards imposed by the payment industry.
The secure PED of this invention is certified by international and national authorities and institutions. All hardware and software components of the secure PED as well as the PCBA circuitry and packaging are implemented in accordance with the standards that are required for certification. Certification has been obtained by Payment Card Industry (PCI), Europay MasterCard VISA (EMV) and Bank Card Testing Center of China (BCTC) according to PCI PIN Entry Device specification, Europay MasterCard VISA Level 1 and Level 2 standard compliance (EMV Smart Card processing compliance), and BCTC specification, respectively. Certification has also been obtained by the Zentraler Kreditausschuss (ZKA) and Interac
Several embodiments of the present invention have been described. Nevertheless, it will be understood that various modifications may be made without departing from the spirit and scope of the invention. Accordingly, other embodiments are within the scope of the following claims.
This application claims the benefit of U.S. provisional application Ser. No. 60/634,399 filed on Dec. 8, 2004 and entitled SECURE PIN ENTRY DEVICE FOR MOBILE PHONES, which is commonly assigned and the contents of which are expressly incorporated herein by reference. This application is also a continuation in part and claims the benefit of U.S. patent application Ser. No. 11/226,823, filed on Sep. 14, 2005, and entitled “SYSTEM AND METHOD FOR A SECURE TRANSACTION MODULE” the contents of which are expressly incorporated herein by reference.
Number | Date | Country | |
---|---|---|---|
60634399 | Dec 2004 | US |
Number | Date | Country | |
---|---|---|---|
Parent | 11226823 | Sep 2005 | US |
Child | 11296555 | Dec 2005 | US |