EP4674149A1 - Method and system for secure deferred transfer of information to a mobile application - Google Patents

Method and system for secure deferred transfer of information to a mobile application

Info

Publication number
EP4674149A1
EP4674149A1 EP24763305.0A EP24763305A EP4674149A1 EP 4674149 A1 EP4674149 A1 EP 4674149A1 EP 24763305 A EP24763305 A EP 24763305A EP 4674149 A1 EP4674149 A1 EP 4674149A1
Authority
EP
European Patent Office
Prior art keywords
tokens
mobile application
reusable
remote server
communication device
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
EP24763305.0A
Other languages
German (de)
French (fr)
Inventor
Morten TRANBERG
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Phonestamp Aps
Original Assignee
Phonestamp Aps
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Phonestamp Aps filed Critical Phonestamp Aps
Publication of EP4674149A1 publication Critical patent/EP4674149A1/en
Pending legal-status Critical Current

Links

Classifications

    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00—Arrangements for program control, e.g. control units
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0807—Network architectures or network communication protocols for network security for authentication of entities using tickets, e.g. Kerberos
    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
    • G06F16/90—Details of database functions independent of the retrieved data types
    • G06F16/95—Retrieval from the web
    • G06F16/955—Retrieval from the web using information identifiers, e.g. uniform resource locators [URL]
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04W—WIRELESS COMMUNICATION NETWORKS
    • H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04W—WIRELESS COMMUNICATION NETWORKS
    • H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/40—Security arrangements using identity modules
    • H04W12/47—Security arrangements using identity modules using near field communication [NFC] or radio frequency identification [RFID] modules
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04W—WIRELESS COMMUNICATION NETWORKS
    • H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60—Context-dependent security
    • H04W12/69—Identity-dependent
    • H04W12/77—Graphical identity

Definitions

  • the present invention relates generally to mobile applications, and more specifically to methods and systems for secure transfer of information to a mobile application after it has been installed on a mobile communication device.
  • exemplary digital loyalty information include loyalty points, rewards, coupons, stamps, lotteries and tickets. This exemplary digital loyalty information can be acquired after, for example, a sale of a good or service, and can be used or redeemed immediately or at a later point in time.
  • PII Personal Identifiable Information
  • GDPR European General Data Protection Regulation
  • Known methods for transferring loyalty information to mobile communication devices without using PII include embedding one or more re-usable tokens into computer readable mediums such as near field communication (NFC) tags or quick response (QR) codes, which can be read or scanned, respectively, by a mobile communication device and used to authorize access to digital loyalty information through an installed digital loyalty mobile application running on the same mobile communication device.
  • NFC near field communication
  • QR quick response
  • An object of the invention is a method and system to securely transfer information to a mobile application using one or more reusable tokens on a mobile communication device where the mobile application is not installed.
  • the above described object and several other objects are intended to be obtained in a first aspect of the invention by providing a method for secure deferred transfer of information to a mobile application.
  • the method comprises steps of:
  • information originally associated with the one or more reusable tokens can be securely transferred to the mobile application after it has been installed on the mobile communication. This is done through the use of one or more one-time tokens that ensures that the reusable tokens are only exposed initially to the mobile communication device and not to the user or any intermediate component or system that may, intentionally or accidentally, open the deferred deep-link multiple times.
  • a standard mobile communication device By storing the one or more reusable tokens in the computer readable medium as an URL targeting the remote server, a standard mobile communication device will out-of-the-box be able to automatically load the URL and send the reusable tokens to the remote server.
  • the computer readable medium is a QR code or an NFC tag a standard mobile communication device will also be able to out-of-the-box read the computer readable medium without requiring any custom hardware or software.
  • the execution of a deferred deep-link may include opening of the received deferred deep-link in a browser of the mobile communication device, installing the mobile application on the mobile communication device, and opening the mobile application on the mobile communication device.
  • the browser may require a click on the deferred deep-link. This may be done by the user of the mobile communication device.
  • Common mobile communication devices include iOS and Android based mobile communication devices. On iOS based mobile communication devices it is common for deferred deep-link solutions to use the iOS pasteboard to copy the deferred deep-link from the browser to the mobile application. On Android based mobile communication devices it is common for deferred deep-link solutions to use the Play Install Referrer Library to get the deferred deep-link targeting the mobile application.
  • the embedded one or more one-time tokens may be extracted from the deferred deep-link in the mobile application before they are sent to the remote server or from the deferred deep-link in the remote service before it returns the information associated with the one or more one-time tokens. It may also be that the one or more one-time tokens are not extracted from the deferred deep-link and that the remote service uses the deferred deep-link directly to find the information associated with the one or more one-time tokens.
  • Exemplary, digital loyalty information that is typically transferred from a merchant to a consumer upon a purchase of a product or service is loyalty points, rewards, coupons, stamps, lotteries or tickets.
  • a common example of this is bonus stamp cards where a consumer will receive a stamp per purchase of a specific product or product group. When the stamp card is full, the consumer may redeem the card and get a free or discounted product of choice.
  • Reusable tokens are tokens that can be used multiple times to transfer information to a mobile application on a mobile communication device.
  • the information transferred may, for example, be digital loyalty information.
  • the information transferred with a reusable token may be the same for each usage of the reusable token or the information may vary for each usage of the reusable token.
  • One-time tokens are tokens that can only be used once to transfer information to a mobile application on a mobile communication device.
  • the information transferred may, for example, be digital loyalty information.
  • One-time tokens may be created on-demand or beforehand by any known random or pseudo-random method with enough entropy needed by the mobile application.
  • the information transferred with one or more one-time tokens created as a function of given one or more reusable tokens may or may not be the same as the information transferred with the given one or more reusable tokens.
  • a computer readable medium can be a QR code, NFC tag or any other computer readable medium that can be read, scanned, or otherwise captured by a mobile communication device.
  • the mobile communication device may communicate with the computer readable medium using a camera, using RFID based NFC technologies, or using other suitable local area network (LAN) communication technologies.
  • LAN local area network
  • the mobile communication device can be a digital watch, cellular phone, a wireless personal digital assistant (PDA), tablet, a laptop computer, or any other device where a mobile application can be installed.
  • the mobile communication device can be NFC-enabled with support for reading NFC tags, equipped with a camera with support for scanning QR codes, and contain other peripherals that can be used to communicate with computer readable mediums.
  • the mobile communication device may communicate with the remote server using a wide area network (WAN) or other suitable communication infrastructure.
  • WAN wide area network
  • the mobile application can be a mobile loyalty application containing digital loyalty information, or any other purpose specific mobile software application.
  • the remote server may include multiple physical or virtual servers, computers and cloud solutions which may be located at different geographic locations and running multiple server side applications including a token authorization service, deferred deep-link service, etc.
  • the remote server may consist of a storage, processing, memory and communication unit.
  • Deferred deep-linking is a technique for transferring links through the install process of a mobile application on a mobile communication device.
  • deferred deep-link techniques do not guarantee at-most-once delivery of the deferred deep link to the newly installed mobile application.
  • a deferred deep-link can, for example, be opened on a mobile communication device by a user clicking on the deferred deep-link in the browser of the mobile communication device.
  • the deferred deep-link may be implemented using Play Install Referrer Library on Android, the pasteboard on iOS or any other methods or combination of methods available on a targeted mobile communication device.
  • One or more one-time tokens can, for example, be encoded into the path or query part of a deferred deep-link.
  • a second aspect of the invention is providing a system for secure transfer of information to a mobile application.
  • the system compromising:
  • a mobile application software package is a software package that can be installed on a mobile communication device. Upon the installation of the mobile application software package on a mobile communication device, a mobile application based on the mobile application software package can be started on the mobile communication device. The started mobile application, and thereby the mobile application software package, will in this case use the mobile communication device to communicate with the computer readable medium and the remote server.
  • the mobile application software package can directly and deferred receive information associated with reusable tokens.
  • the mobile application software package When the mobile application software package is installed on a mobile communication device, it may directly receive one or more reusable tokens from the computer readable medium.
  • the mobile application software package is able to exchange the received one or more reusable tokens to information through the remote server.
  • the mobile application software package After the mobile application software package has been installed on a mobile communication device, it may receive one or more one-time tokens from a remote server.
  • the mobile application software package is able to exchange the received one or more one-time tokens to information through the remote server.
  • the information acquired by the mobile application software package, whether directly or deferred, will be related to a mobile application running on a mobile communication device.
  • the advantage of being able to perform deferred transfer of information to a mobile application by the mobile application software package is that it can acquire information associated to one or more reusable tokens that was read before the mobile application software package is installed.
  • the use of one-time tokens makes the deferred transfer secure and ensures that the reusable tokens are only exposed initially after being read and not to all intermediate components or users that may take part in installing the mobile application software package.
  • the remote server may receive the one or more reusable tokens from the computer readable medium as an URL. This will allow a standard mobile communication device to out-of-the-box send the reusable tokens to the remote server.
  • the computer readable medium may be a QR code or an NFC tag. This will allow a standard mobile communication device to read the computer readable medium without requiring any custom hardware or software.
  • the system for secure deferred transfer of information to a mobile application is especially useful in loyalty applications where the information associated with the reusable or one-time tokens is digital loyalty information.
  • the digital loyalty information transferred using the system may include loyalty points, rewards, coupons, stamps, lotteries or tickets.
  • system 100 one embodiment of the present invention is shown as a system 100.
  • the system 100 includes a computer readable medium 110, a mobile communication device 120, and a remote server 140 whereby the computer readable medium 110 is connected to the mobile communication device 120 and the mobile communication device 120 is connected to the remote server 140.
  • the mobile communication device 120 includes a browser 130, an app store 150 and a mobile application 160 whereby the browser 130 is connected to the app store 150 and the app store 150 is connected to the mobile application 160.
  • the mobile communication device 120 is used by the user 170.
  • the browser 130 is the standard web application on the mobile communication device 120 used to open URLs and can more specifically be used to open URLs on the remote server 140.
  • the app store 150 is the standard application manager on the mobile communication device 120 used to install mobile applications, such as the mobile application 160, on the mobile communication device 120.
  • the mobile application 160 is a mobile business application compatible with the mobile communication device 120 it is installed on, and can communicate with compatible business services on the remote server 140.
  • the browser 130, app store 150 and mobile application 160 on the mobile communication device 120 can all communicate with and through core functionality specific to the operating system (OS) of the mobile communication device 120.
  • OS operating system
  • the computer readable medium 110 includes an URL containing an embedded one or more reusable tokens for a mobile application.
  • the mobile communication device 120 When the mobile communication device 120 reads, scans or in other ways captures the URL including the one or more reusable tokens from the computer readable medium 110 using interaction A, the mobile communication device 120 will open the URL in its browser 130. The browser 130 on the mobile communication device 120 will load the URL and connect to the remote server 140 using interaction B. The remote server 140 extracts the one or more reusable tokens from the URL and creates a deferred deep-link containing one or more one-time tokens. The remote server 140 returns a page with the deferred deep-link to the browser 130.
  • the browser 130 will, possibly through one or more intermediate steps, open the app store 150 of the mobile communication device 120 using interaction C where the user 170 can download and install the mobile application 160.
  • the mobile application 160 When the installed mobile application 160 is started by the user 170 of the mobile communication device 120, the mobile application 160 is loaded with the deferred deep-link using a deferred deep-link technique applicable on the specific type of mobile communication device 120. This may be through interaction D or any other communication channel available on the mobile communication device 120.
  • the mobile application 160 extracts the one or more one-time tokens from the given deferred deep-link and sends the one or more one-time tokens to the remote server 140 using interaction E.
  • the remote server 140 receives the one or more one-time token, it returns the associated digital loyalty information to the mobile application 160 over interaction E.
  • system 200 one embodiment of the present invention is shown as a system 200.
  • the system 200 includes a computer readable medium 210, a mobile application software package 260, and a remote server 240.
  • the mobile application software package 260 includes a deferred deep link software component 2601 and a computer readable software component 2602.
  • the remote server 240 includes a token exchange component 2401, a one-time token component 2402, and a reusable token component 2403.
  • the computer readable medium 210 is connected to the token exchange component 2401 and the computer readable software component 2602.
  • the token exchange component 2401 is connected to the deferred deep-link software component 2601.
  • the deferred deep-link software component 2601 is connected to the one-time token component 2402 whereas the computer readable software component 2602 is connected to the reusable token component 2403.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Signal Processing (AREA)
  • Databases & Information Systems (AREA)
  • Physics & Mathematics (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Security & Cryptography (AREA)
  • Data Mining & Analysis (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • Software Systems (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

A method and system for secure deferred transfer of information to a mobile application. The method and system provides a secure mechanism for transfer of information to a mobile application using one or more reusable tokens on a mobile communication device where the mobile application is not installed. One or more reusable tokens are provided on a computer readable medium for a mobile application and the one or more reusable tokens are read from the computer readable medium by a mobile communication device where the mobile application is not installed. The mobile communication device sends to a remote server the read one or more reusable tokens, where one or more one-time tokens are created in the remote server as a function of the received one or more reusable tokens. The created one or more one-time tokens are embedded in the remote server into a deferred deep-link targeting the mobile application and from the remote server the deferred deep-link is sent to the mobile communication device. The received deferred deep-link is executed on the mobile communication device. The mobile application sends to the remote server the embedded one or more one-time tokens and the remote server returns to the mobile application information associated with the received one or more one-time tokens.

Description

    Method and system for secure deferred transfer of information to a mobile application Field of the invention
  • The present invention relates generally to mobile applications, and more specifically to methods and systems for secure transfer of information to a mobile application after it has been installed on a mobile communication device.
  • Background of the invention
  • Physical loyalty cards have for centuries been used by merchants to increase retention of customers and ensure that they return to buy more goods or services.
  • With the increased popularity of mobile communication devices the physical loyalty cards are being replaced by loyalty information in digital solutions on mobile communication devices that, compared to their physical counterparts, can help customers to keep track of their earned loyalty and increase merchants' insights into the use of their loyalty programs. Exemplary digital loyalty information include loyalty points, rewards, coupons, stamps, lotteries and tickets. This exemplary digital loyalty information can be acquired after, for example, a sale of a good or service, and can be used or redeemed immediately or at a later point in time.
  • With the increased focus on Personal Identifiable Information (PII), for example due to the European General Data Protection Regulation (GDPR), it may not be desirable to track customer loyalty on mobile communication devices through PII, for example, telephone numbers or email addresses. Thus alternative methods for transferring loyalty information to mobile communication devices are needed.
  • Known methods for transferring loyalty information to mobile communication devices without using PII include embedding one or more re-usable tokens into computer readable mediums such as near field communication (NFC) tags or quick response (QR) codes, which can be read or scanned, respectively, by a mobile communication device and used to authorize access to digital loyalty information through an installed digital loyalty mobile application running on the same mobile communication device.
  • These methods are however limited to situations where the mobile communication devices have a digital loyalty mobile application installed. Installing the digital loyalty mobile application on the mobile communication device is an extra burden on the customer, compared to the paper counterparts, before they can acquire their digital loyalty information from the merchant.
  • A need therefore exists for a method and supporting system to securely improve the customer onboarding process when using one or more reusable tokens to transfer digital loyalty information to mobile communication devices when the digital loyalty mobile application is not yet installed.
  • Object of the invention
  • An object of the invention is a method and system to securely transfer information to a mobile application using one or more reusable tokens on a mobile communication device where the mobile application is not installed.
  • Description of the invention
  • The above described object and several other objects are intended to be obtained in a first aspect of the invention by providing a method for secure deferred transfer of information to a mobile application. The method comprises steps of:
    • providing of one or more reusable tokens on a computer readable medium for a mobile application,
    • reading of the one or more reusable tokens from the computer readable medium on a mobile communication device where the mobile application is not installed,
    • sending from the mobile communication device to a remote server the read one or more reusable tokens,
    • creating one or more one-time tokens in the remote server as a function of the received one or more reusable tokens,
    • embedding the created one or more one-time tokens in the remote server into a deferred deep-link targeting the mobile application,
    • sending from the remote server the deferred deep-link to the mobile communication device,
    • executing the received deferred deep-link on the mobile communication device,
    • sending from the mobile application to the remote server the embedded one or more one-time tokens,
    • sending from the remote server to the mobile application information associated with the received one or more one-time tokens.
  • Thereby information originally associated with the one or more reusable tokens can be securely transferred to the mobile application after it has been installed on the mobile communication. This is done through the use of one or more one-time tokens that ensures that the reusable tokens are only exposed initially to the mobile communication device and not to the user or any intermediate component or system that may, intentionally or accidentally, open the deferred deep-link multiple times.
  • By storing the one or more reusable tokens in the computer readable medium as an URL targeting the remote server, a standard mobile communication device will out-of-the-box be able to automatically load the URL and send the reusable tokens to the remote server.
  • If the computer readable medium is a QR code or an NFC tag a standard mobile communication device will also be able to out-of-the-box read the computer readable medium without requiring any custom hardware or software.
  • The execution of a deferred deep-link may include opening of the received deferred deep-link in a browser of the mobile communication device, installing the mobile application on the mobile communication device, and opening the mobile application on the mobile communication device. In order for a browser on a standard mobile communication device to open a redirected deferred-link, the browser may require a click on the deferred deep-link. This may be done by the user of the mobile communication device.
  • Common mobile communication devices include iOS and Android based mobile communication devices. On iOS based mobile communication devices it is common for deferred deep-link solutions to use the iOS pasteboard to copy the deferred deep-link from the browser to the mobile application. On Android based mobile communication devices it is common for deferred deep-link solutions to use the Play Install Referrer Library to get the deferred deep-link targeting the mobile application.
  • The embedded one or more one-time tokens may be extracted from the deferred deep-link in the mobile application before they are sent to the remote server or from the deferred deep-link in the remote service before it returns the information associated with the one or more one-time tokens. It may also be that the one or more one-time tokens are not extracted from the deferred deep-link and that the remote service uses the deferred deep-link directly to find the information associated with the one or more one-time tokens.
  • The method for secure deferred transfer of information to a mobile application is especially useful in loyalty applications where the information associated with the reusable or one-time tokens is digital loyalty information, that is to be transferred between a merchant and a consumer upon purchase of a product or service. In this situation it is critical that the transfer of loyalty information between the merchant and the consumer is frictionless and fast. This requires a minimum number of consistent manual steps. With the above method the process of onboarding and transferring initial digital loyalty information to a consumer is the same as transferring digital loyalty information to a consumer that has already acquired the mobile application. Both processes are initiated by letting the consumer's mobile communication device read the merchant's computer readable medium. When the consumer’s mobile communication device has read the merchant’s computer readable medium, the merchant does not have to do anything else to transfer the digital loyalty information to the consumer. This adds great value to merchant stores with busy-hours or a large number of employees that may only work in the store for a limited number of hours during a week or month.
  • Exemplary, digital loyalty information that is typically transferred from a merchant to a consumer upon a purchase of a product or service is loyalty points, rewards, coupons, stamps, lotteries or tickets. A common example of this is bonus stamp cards where a consumer will receive a stamp per purchase of a specific product or product group. When the stamp card is full, the consumer may redeem the card and get a free or discounted product of choice.
  • Reusable tokens are tokens that can be used multiple times to transfer information to a mobile application on a mobile communication device. The information transferred may, for example, be digital loyalty information. The information transferred with a reusable token may be the same for each usage of the reusable token or the information may vary for each usage of the reusable token.
  • One-time tokens are tokens that can only be used once to transfer information to a mobile application on a mobile communication device. The information transferred may, for example, be digital loyalty information. One-time tokens may be created on-demand or beforehand by any known random or pseudo-random method with enough entropy needed by the mobile application. The information transferred with one or more one-time tokens created as a function of given one or more reusable tokens may or may not be the same as the information transferred with the given one or more reusable tokens.
  • A computer readable medium can be a QR code, NFC tag or any other computer readable medium that can be read, scanned, or otherwise captured by a mobile communication device. The mobile communication device may communicate with the computer readable medium using a camera, using RFID based NFC technologies, or using other suitable local area network (LAN) communication technologies.
  • The mobile communication device can be a digital watch, cellular phone, a wireless personal digital assistant (PDA), tablet, a laptop computer, or any other device where a mobile application can be installed. The mobile communication device can be NFC-enabled with support for reading NFC tags, equipped with a camera with support for scanning QR codes, and contain other peripherals that can be used to communicate with computer readable mediums. The mobile communication device may communicate with the remote server using a wide area network (WAN) or other suitable communication infrastructure.
  • The mobile application can be a mobile loyalty application containing digital loyalty information, or any other purpose specific mobile software application.
  • The remote server may include multiple physical or virtual servers, computers and cloud solutions which may be located at different geographic locations and running multiple server side applications including a token authorization service, deferred deep-link service, etc. The remote server may consist of a storage, processing, memory and communication unit.
  • Deferred deep-linking is a technique for transferring links through the install process of a mobile application on a mobile communication device. In general, deferred deep-link techniques do not guarantee at-most-once delivery of the deferred deep link to the newly installed mobile application. A deferred deep-link can, for example, be opened on a mobile communication device by a user clicking on the deferred deep-link in the browser of the mobile communication device. The deferred deep-link may be implemented using Play Install Referrer Library on Android, the pasteboard on iOS or any other methods or combination of methods available on a targeted mobile communication device. One or more one-time tokens can, for example, be encoded into the path or query part of a deferred deep-link.
  • A second aspect of the invention is providing a system for secure transfer of information to a mobile application. The system compromising:
    • a computer readable medium capable of
      • storing and exposing one or more reusable tokens for a mobile application software package, wherein
    • the mobile application software package including
      • a deferred deep-link software component capable of
        • receiving one or more one-time tokens embedded into a deferred deep-link from a remote server,
        • sending the one or more one-time tokens to the remote server,
        • receiving information associated with the sent one or more one-time tokens from the remote server,
      • a computer readable software component capable of
        • receiving one or more reusable tokens from the computer readable medium,
        • sending the one or more reusable tokens to the remote server,
        • receiving information associated with the sent one or more reusable tokens from the remote server, wherein
    • the remote server including
      • a token exchange component capable of
        • receiving one or more reusable tokens from the computer readable medium,
        • creating one or more one-time tokens as a function of the received one or more reusable tokens,
        • embedding of the created one or more one-time tokens into a deferred deep-link targeting the mobile application software package,
        • sending of the deferred deep-link to the mobile application software package,
      • a reusable token component capable of
        • receiving one or more reusable tokens from the mobile application software package
        • sending information associated with the one or more reusable tokens to the mobile application software package
      • a one-time token component capable of
        • receiving one or more one-time tokens from the mobile application software package
        • sending information associated with the one or more one-time tokens to the mobile application software package.
  • A mobile application software package is a software package that can be installed on a mobile communication device. Upon the installation of the mobile application software package on a mobile communication device, a mobile application based on the mobile application software package can be started on the mobile communication device. The started mobile application, and thereby the mobile application software package, will in this case use the mobile communication device to communicate with the computer readable medium and the remote server.
  • With the system the mobile application software package can directly and deferred receive information associated with reusable tokens. When the mobile application software package is installed on a mobile communication device, it may directly receive one or more reusable tokens from the computer readable medium. The mobile application software package is able to exchange the received one or more reusable tokens to information through the remote server. After the mobile application software package has been installed on a mobile communication device, it may receive one or more one-time tokens from a remote server. The mobile application software package is able to exchange the received one or more one-time tokens to information through the remote server. The information acquired by the mobile application software package, whether directly or deferred, will be related to a mobile application running on a mobile communication device.
  • The advantage of being able to perform deferred transfer of information to a mobile application by the mobile application software package is that it can acquire information associated to one or more reusable tokens that was read before the mobile application software package is installed. The use of one-time tokens makes the deferred transfer secure and ensures that the reusable tokens are only exposed initially after being read and not to all intermediate components or users that may take part in installing the mobile application software package.
  • The remote server may receive the one or more reusable tokens from the computer readable medium as an URL. This will allow a standard mobile communication device to out-of-the-box send the reusable tokens to the remote server.
  • The computer readable medium may be a QR code or an NFC tag. This will allow a standard mobile communication device to read the computer readable medium without requiring any custom hardware or software.
  • Similar to the method, the system for secure deferred transfer of information to a mobile application is especially useful in loyalty applications where the information associated with the reusable or one-time tokens is digital loyalty information.
  • The digital loyalty information transferred using the system may include loyalty points, rewards, coupons, stamps, lotteries or tickets.
  • Brief description of the figures
  • The method and system in the present invention will now be described in more detail with regard to the accompanying figures. The figures show one way of implementing the present invention and is not to be construed as being limiting to other possible embodiments falling within the scope of the attached claim set.
  • is a schematic representation of an embodiment that uses the method in the present invention.
  • is a schematic representation of an embodiment of the system in the present invention.
  • Detailed description of the preferred embodiments
  • Referring to , one embodiment of the present invention is shown as a system 100.
  • The system 100 includes a computer readable medium 110, a mobile communication device 120, and a remote server 140 whereby the computer readable medium 110 is connected to the mobile communication device 120 and the mobile communication device 120 is connected to the remote server 140. The mobile communication device 120 includes a browser 130, an app store 150 and a mobile application 160 whereby the browser 130 is connected to the app store 150 and the app store 150 is connected to the mobile application 160. The mobile communication device 120 is used by the user 170.
  • The browser 130 is the standard web application on the mobile communication device 120 used to open URLs and can more specifically be used to open URLs on the remote server 140. The app store 150 is the standard application manager on the mobile communication device 120 used to install mobile applications, such as the mobile application 160, on the mobile communication device 120. The mobile application 160 is a mobile business application compatible with the mobile communication device 120 it is installed on, and can communicate with compatible business services on the remote server 140. The browser 130, app store 150 and mobile application 160 on the mobile communication device 120 can all communicate with and through core functionality specific to the operating system (OS) of the mobile communication device 120.
  • In system 100 the computer readable medium 110 includes an URL containing an embedded one or more reusable tokens for a mobile application.
  • When the mobile communication device 120 reads, scans or in other ways captures the URL including the one or more reusable tokens from the computer readable medium 110 using interaction A, the mobile communication device 120 will open the URL in its browser 130. The browser 130 on the mobile communication device 120 will load the URL and connect to the remote server 140 using interaction B. The remote server 140 extracts the one or more reusable tokens from the URL and creates a deferred deep-link containing one or more one-time tokens. The remote server 140 returns a page with the deferred deep-link to the browser 130.
  • When the user 170 of the mobile communication device 120 clicks the deferred deep-link in the browser 130, the browser 130 will, possibly through one or more intermediate steps, open the app store 150 of the mobile communication device 120 using interaction C where the user 170 can download and install the mobile application 160.
  • When the installed mobile application 160 is started by the user 170 of the mobile communication device 120, the mobile application 160 is loaded with the deferred deep-link using a deferred deep-link technique applicable on the specific type of mobile communication device 120. This may be through interaction D or any other communication channel available on the mobile communication device 120.
  • The mobile application 160 extracts the one or more one-time tokens from the given deferred deep-link and sends the one or more one-time tokens to the remote server 140 using interaction E. When the remote server 140 receives the one or more one-time token, it returns the associated digital loyalty information to the mobile application 160 over interaction E.
  • Referring to , one embodiment of the present invention is shown as a system 200.
  • The system 200 includes a computer readable medium 210, a mobile application software package 260, and a remote server 240. The mobile application software package 260 includes a deferred deep link software component 2601 and a computer readable software component 2602. The remote server 240 includes a token exchange component 2401, a one-time token component 2402, and a reusable token component 2403.
  • The computer readable medium 210 is connected to the token exchange component 2401 and the computer readable software component 2602. The token exchange component 2401 is connected to the deferred deep-link software component 2601. The deferred deep-link software component 2601 is connected to the one-time token component 2402 whereas the computer readable software component 2602 is connected to the reusable token component 2403.
  • When the one or more reusable tokens from the computer readable medium 210 is received in the token exchange component 2401 of the remote server 240 over interaction I, the token exchange component 2401 creates a deferred deep-link containing one or more one-time tokens. The deferred deep-link is sent from the token exchange server 2401 to the deferred deep-link software component 2601 over interaction II. Once the deferred deep-link is received in the deferred deep-link software component 2601, it uses the one or more one-time tokens from the deferred deep-link to get the information associated with the one or more one-time tokens from the one-time token component 2402 over interaction III.
  • When the one or more reusable tokens from the computer readable medium 210 is received in the computer readable software component 2602 over interaction IV, the computer readable software component 2602 uses the one or more reusable tokens to get the information associated with the one or more reusable tokens from the reusable token component 2403 over interaction V.

Claims (13)

  1. Method for secure deferred transfer of information to a mobile application, the method comprises steps of:
    • providing one or more reusable tokens on a computer readable medium (110) for a mobile application (160),
    • reading of the one or more reusable tokens from the computer readable medium (110) on a mobile communication device (120) where the mobile application (160) is not installed,
    • sending from the mobile communication device (120) to a remote server (140) the read one or more reusable tokens,
    • creating one or more one-time tokens in the remote server (140) as a function of the received one or more reusable tokens,
    • embedding the created one or more one-time tokens in the remote server (140) into a deferred deep-link targeting the mobile application (160),
    • sending from the remote server (140) the deferred deep-link to the mobile communication device (120),
    • executing the received deferred deep-link on the mobile communication device (120),
    • sending from the mobile application (160) to the remote server (140) the embedded one or more one-time tokens,
    • sending from the remote server (140) to the mobile application (160) information associated with the received one or more one-time tokens.
  2. A method according to claim 1, wherein the one or more reusable tokens are stored in the computer readable medium (110) as an URL.
  3. A method according to any one of claims 1 or 2, wherein the computer readable medium (110) is a QR code or an NFC tag.
  4. A method according to any one of claims 1 to 3, wherein the execution of the received deferred deep-link on the mobile communication device (120) compromises a user selecting the deferred deep-link in the browser (130) of the mobile communication device (120) via an input device operatively coupled to the mobile communication device (120).
  5. A method according to claim 4 wherein the execution of the received deferred deep-link comprises a copy of the deferred deep-link from the browser (130) to the pasteboard on a mobile communication device (120).
  6. A method according to claim 4 wherein the execution of the received deferred deep-link comprises the use of the Play Install Referrer Library on a mobile communication device (120).
  7. A method according to any one of claims 1 to 6 wherein the information associated with the reusable or one-time tokens is digital loyalty information.
  8. A method according to claim 7 wherein the digital loyalty information is loyalty points, rewards, coupons, stamps, lotteries or tickets.
  9. A system for secure transfer of information to a mobile application, the system compromising:
    • a computer readable medium (210) capable of
      • storing and exposing one or more reusable tokens for a mobile application software package (260), wherein
    • the mobile application software package (260) including
      • a deferred deep-link software component (2601) capable of receiving one or more one-time tokens embedded into a deferred deep-link from a remote server (240), sending the one or more one-time tokens to the remote server (240), receiving information associated with the sent one or more one-time tokens from the remote server (240),
      • a computer readable software component (2602) capable of receiving one or more reusable tokens from the computer readable medium (210), sending the one or more reusable tokens to the remote server (240), receiving information associated with the sent one or more reusable tokens from the remote server (240), wherein
    • the remote server (240) including
      • a token exchange component capable of receiving one or more reusable tokens from the computer readable medium (210), creating one or more one-time tokens as a function of the received one or more reusable tokens, embedding of the created one or more one-time tokens into a deferred deep-link targeting the mobile application software package (260), sending of the deferred deep-link to the mobile application software package (260),
      • a reusable token component capable of receiving one or more reusable tokens from the mobile application software package (260), sending information associated with the one or more reusable tokens to the mobile application software package (260),
      • a one-time token component capable of receiving one or more one-time tokens from the mobile application software package (260), sending information associated with the one or more one-time tokens to the mobile application software package (260).
  10. A system according to claim 9, wherein the one or more reusable tokens are stored in the computer readable medium (210) as an URL.
  11. A system according to any one of claims 9 or 10, wherein the computer readable medium (210) is a QR code or an NFC tag.
  12. A system according to any one of claims 9 to 11 wherein, the information associated with the reusable or one-time tokens is digital loyalty information.
  13. A system according to claim 12 wherein the digital loyalty information is loyalty points, rewards, coupons, stamps, lotteries or tickets.
EP24763305.0A 2023-03-02 2024-02-29 Method and system for secure deferred transfer of information to a mobile application Pending EP4674149A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
DKPA202300193A DK182038B1 (en) 2023-03-02 2023-03-02 Method and system for secure deferred transfer of information to a mobile application
PCT/DK2024/050039 WO2024179651A1 (en) 2023-03-02 2024-02-29 Method and system for secure deferred transfer of information to a mobile application

Publications (1)

Publication Number Publication Date
EP4674149A1 true EP4674149A1 (en) 2026-01-07

Family

ID=92589153

Family Applications (1)

Application Number Title Priority Date Filing Date
EP24763305.0A Pending EP4674149A1 (en) 2023-03-02 2024-02-29 Method and system for secure deferred transfer of information to a mobile application

Country Status (3)

Country Link
EP (1) EP4674149A1 (en)
DK (1) DK182038B1 (en)
WO (1) WO2024179651A1 (en)

Family Cites Families (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9092774B2 (en) * 2012-09-14 2015-07-28 William BECOREST Augmented reality messaging system and method based on multi-factor recognition
US9742661B2 (en) * 2012-11-07 2017-08-22 Pure Oxygen Labs LLC Uniform resource locator mapping and routing system and method
US9936330B2 (en) * 2014-01-30 2018-04-03 Yozio Inc. Methods for exchanging data amongst mobile applications using superlinks
US9628992B2 (en) * 2015-07-31 2017-04-18 Wyfi, Inc. WiFi access management system and methods of operation thereof
US10356087B1 (en) * 2016-08-26 2019-07-16 Intelligent Waves Llc System, method and computer program product for credential provisioning in a mobile device platform
US20200128287A1 (en) * 2017-06-26 2020-04-23 Uzi MAIMON Captured content sharing interface
EP3777070B1 (en) * 2018-04-10 2022-10-12 Visa International Service Association Deep link authentication
CN110875933B (en) * 2018-08-29 2022-05-10 阿里巴巴集团控股有限公司 Information matching confirmation method and device
US12177210B2 (en) * 2019-12-05 2024-12-24 Identité, Inc Full-duplex password-less authentication
US11641665B2 (en) * 2020-09-09 2023-05-02 Self Financial, Inc. Resource utilization retrieval and modification

Also Published As

Publication number Publication date
DK182038B1 (en) 2025-06-10
DK202300193A1 (en) 2024-10-08
WO2024179651A1 (en) 2024-09-06

Similar Documents

Publication Publication Date Title
US8046257B2 (en) System and method for distribution, redemption and processing of electronic coupons
CA2498366C (en) Optimised messages containing barcode information for mobile receiving devices
EP2255340B1 (en) Method and devices for installing and retrieving linked mifare applications
CN110009329B (en) System, method and computer readable medium for managing contactless commerce transactions
US20120316950A1 (en) System and method for augmentation of retail pos data streams with transaction information
US20140025519A1 (en) System and method for acquiring electronic data records
CN101809579A (en) Method, system, trusted service manager, service provider and memory element for managing access rights for trusted applications
US20100088191A1 (en) System and Method for Using Customer Information in Electronic Commerce
CN101320435B (en) Information processing system, information processing device
US20210256484A1 (en) System for transmitting payment information using mobile terminal and method thereof
JP5534186B2 (en) Information processing system, information processing server, information processing method, information processing program, etc.
US20160140595A1 (en) Method for processing electronic coupons
CN103049847A (en) Electronic receipt/invoice record transmitting method in NFC (Near Field Communication) mobilephone payment
CN107729124A (en) Transaction methods and device, electronic equipment
WO2024179651A1 (en) Method and system for secure deferred transfer of information to a mobile application
US20100052855A1 (en) Method and Apparatus for Cross-Media Use of RFID Readers and RFID Tags
US20240403854A1 (en) Method for managing a till e-receipt
KR20120015239A (en) Mobile payment method and devices that support it
WO2014092106A1 (en) Information processing device and information processing method
CN102077226A (en) Communication method of at least one targeted message from a service provider to a mobile end user
KR102510980B1 (en) Coupon transaction service method to prevent double use
KR102878173B1 (en) Method and recording medium for providing digital identity authentication-based casino service
Hirakawa et al. A study on digital watermarking usage in the mobile marketing field: Cases in Japan
KR20090077344A (en) Game item purchase information operation method and system and program recording medium therefor
KR20170020572A (en) Method and device for identifying member's information of store using nfc

Legal Events

Date Code Title Description
STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE

PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE

17P Request for examination filed

Effective date: 20250902

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR