Patents by Inventor Hadi Nahari

Hadi Nahari has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20230410171
    Abstract: Systems and methods for use with a service provider and a consumer electronic device include a trusted remote attestation agent (TRAA) configured to perform a set of checking procedures or mechanisms to help ensure the security status of a consumer electronic device (e.g., a mobile terminal or phone) that holds financial instruments. The checking procedures may include: self-verifying integrity by the TRAA; checking for presence of a provisioning SIM card (one that was present when the financial instruments were enabled on the device); checking that a communication connection between the consumer electronic device and the service provider is available and active; and checking that communication connectivity to a home mobile network is available and active. The frequency of the checking mechanisms may be adjusted, for example, according to a risk-profile of a user associated with the device or the location (e.g., GPS location) of the device.
    Type: Application
    Filed: June 16, 2023
    Publication date: December 21, 2023
    Inventor: Hadi Nahari
  • Patent number: 11720943
    Abstract: Systems and methods for use with a service provider and a consumer electronic device include a trusted remote attestation agent (TRAA) configured to perform a set of checking procedures or mechanisms to help ensure the security status of a consumer electronic device (e.g., a mobile terminal or phone) that holds financial instruments. The checking procedures may include: self-verifying integrity by the TRAA; checking for presence of a provisioning SIM card (one that was present when the financial instruments were enabled on the device); checking that a communication connection between the consumer electronic device and the service provider is available and active; and checking that communication connectivity to a home mobile network is available and active. The frequency of the checking mechanisms may be adjusted, for example, according to a risk-profile of a user associated with the device or the location (e.g., GPS location) of the device.
    Type: Grant
    Filed: December 23, 2021
    Date of Patent: August 8, 2023
    Assignee: PayPal, Inc.
    Inventor: Hadi Nahari
  • Publication number: 20220114634
    Abstract: Systems and methods for use with a service provider and a consumer electronic device include a trusted remote attestation agent (TRAA) configured to perform a set of checking procedures or mechanisms to help ensure the security status of a consumer electronic device (e.g., a mobile terminal or phone) that holds financial instruments. The checking procedures may include: self-verifying integrity by the TRAA; checking for presence of a provisioning SIM card (one that was present when the financial instruments were enabled on the device); checking that a communication connection between the consumer electronic device and the service provider is available and active; and checking that communication connectivity to a home mobile network is available and active. The frequency of the checking mechanisms may be adjusted, for example, according to a risk-profile of a user associated with the device or the location (e.g., GPS location) of the device.
    Type: Application
    Filed: December 23, 2021
    Publication date: April 14, 2022
    Inventor: Hadi Nahari
  • Patent number: 11276093
    Abstract: Systems and methods for use with a service provider and a consumer electronic device include a trusted remote attestation agent (TRAA) configured to perform a set of checking procedures or mechanisms to help ensure the security status of a consumer electronic device (e.g., a mobile terminal or phone) that holds financial instruments. The checking procedures may include: self-verifying integrity by the TRAA; checking for presence of a provisioning SIM card (one that was present when the financial instruments were enabled on the device); checking that a communication connection between the consumer electronic device and the service provider is available and active; and checking that communication connectivity to a home mobile network is available and active. The frequency of the checking mechanisms may be adjusted, for example, according to a risk-profile of a user associated with the device or the location (e.g., GPS location) of the device.
    Type: Grant
    Filed: March 31, 2020
    Date of Patent: March 15, 2022
    Assignee: PayPal, Inc.
    Inventor: Hadi Nahari
  • Publication number: 20200294026
    Abstract: Systems and methods for use with a service provider and a consumer electronic device include a trusted remote attestation agent (TRAA) configured to perform a set of checking procedures or mechanisms to help ensure the security status of a consumer electronic device (e.g., a mobile terminal or phone) that holds financial instruments. The checking procedures may include: self-verifying integrity by the TRAA; checking for presence of a provisioning SIM card (one that was present when the financial instruments were enabled on the device); checking that a communication connection between the consumer electronic device and the service provider is available and active; and checking that communication connectivity to a home mobile network is available and active. The frequency of the checking mechanisms may be adjusted, for example, according to a risk-profile of a user associated with the device or the location (e.g., GPS location) of the device.
    Type: Application
    Filed: March 31, 2020
    Publication date: September 17, 2020
    Inventor: Hadi Nahari
  • Patent number: 10748144
    Abstract: Various embodiments include a first detection being made that a first program residing on a device is requesting authentication. The first program resides in a first portion of the device. An authentication step can be performed by referencing a unique identifier accessible via a request sent by the first program to a second program residing on the device, where the second program resides in a second portion of the mobile device. The second portion has a greater level of security than the first portion (e.g. physical separation may exist between the first and second portions). Accordingly, integrity of the first program can be verified (e.g. an authentic, authorized version of a program is making a transaction request rather than an unauthorized version).
    Type: Grant
    Filed: August 14, 2018
    Date of Patent: August 18, 2020
    Assignee: PAYPAL, INC.
    Inventors: Sebastien Ludovic Jean Taveau, Hadi Nahari
  • Publication number: 20190130393
    Abstract: Various embodiments include a first detection being made that a first program residing on a device is requesting authentication. The first program resides in a first portion of the device. An authentication step can be performed by referencing a unique identifier accessible via a request sent by the first program to a second program residing on the device, where the second program resides in a second portion of the mobile device. The second portion has a greater level of security than the first portion (e.g. physical separation may exist between the first and second portions). Accordingly, integrity of the first program can be verified (e.g. an authentic, authorized version of a program is making a transaction request rather than an unauthorized version).
    Type: Application
    Filed: August 14, 2018
    Publication date: May 2, 2019
    Inventors: Sebastien Ludovic Jean Taveau, Hadi Nahari
  • Patent number: 10120993
    Abstract: A system includes a tag having a machine readable tag identifier (Tag ID) configured to be read by a reader; and a device to be identified by the tag, in which: the device is configured to communicate with the reader; the device has access to a secure Tag ID; and the device communicates a verification to the reader if the machine readable Tag ID communicated to the device from the reader matches the secure Tag ID. A method includes: reading a Tag ID from a tag attached to a device; communicating the Tag ID read from the tag to the device; comparing a secure Tag ID of the device to the Tag ID read from the tag; and responding with a “match” or “no-match” message from the device, according to which the device is either trusted or not trusted as being identified by the Tag ID. A method of verifying a trusted agent (TA) on a device includes: storing a digital signature of the TA in a secure vault of the device; and verifying the TA by verifying the digital signature of the TA each time the TA is used.
    Type: Grant
    Filed: September 14, 2015
    Date of Patent: November 6, 2018
    Assignee: PAYPAL, INC.
    Inventors: Sebastien Taveau, Hadi Nahari
  • Patent number: 10055729
    Abstract: An initial communication pathway is established between a first execution environment of a mobile device and a second execution environment of the mobile device. The first and second execution environments are executed in parallel with each other. The second execution environment has a higher level of security than the first execution environment. A request is received from a first entity to authenticate itself. The first entity resides in the first execution environment of the mobile device. The first entity is authenticated in response to the request. The authentication is performed by a second entity that resides in the second execution environment of the mobile device. The receiving of the request and the authenticating are performed using a direct communication link between the first execution environment and the second execution environment while bypassing the initial communication pathway.
    Type: Grant
    Filed: March 25, 2016
    Date of Patent: August 21, 2018
    Assignee: PAYPAL, INC.
    Inventors: Sebastien Ludovic Jean Taveau, Hadi Nahari
  • Patent number: 10050975
    Abstract: A detection is made that a first entity residing on a mobile device is requesting authentication. The first entity resides in a first portion of the mobile device. A determination is made that the mobile device is unable to establish network connections with a remote authentication server that is configured to authenticate the first entity. A local authentication process is performed in response to the determination that the mobile device is unable to establish network connections with the remote authentication server. Without accessing the remote authentication server, the local authentication process is performed by a second entity that resides in a second portion of the mobile device. The second portion has a greater level of security than the first portion.
    Type: Grant
    Filed: March 17, 2016
    Date of Patent: August 14, 2018
    Assignee: PAYPAL, INC.
    Inventors: Sebastien Ludovic Jean Taveau, Hadi Nahari
  • Patent number: 10032164
    Abstract: A system and method for facilitating electronic commerce over a network, according to one or more embodiments, includes communicating with a user via a user device over the network, distributing a resident application to the user device over the network, displaying a service icon on the user device, and receiving an authentication request from the user via the user device over the network. The service icon is linked to the resident application, and the authentication request includes user credentials inputted by the user via user selection of the service icon and resulting user access of the resident application. The system and method includes communicating with the resident application on the user device to request user confirmation of the authentication request, receiving user confirmation from the user via the user device over the network, authorizing the authentication request, and notifying the user of the authorized authentication request over the network via the resident application.
    Type: Grant
    Filed: December 16, 2010
    Date of Patent: July 24, 2018
    Assignee: PAYPAL, INC.
    Inventor: Hadi Nahari
  • Patent number: 9923876
    Abstract: A user inserts a received random sequence into the user's password or PIN. The user enters and transmits this randomized password to a service provider. The service provider extracts the password to determine whether to authenticate the user.
    Type: Grant
    Filed: May 9, 2016
    Date of Patent: March 20, 2018
    Assignee: PAYPAL, INC.
    Inventor: Hadi Nahari
  • Publication number: 20180068298
    Abstract: Systems and methods for use with a service provider and a consumer electronic device include a trusted remote attestation agent (TRAA) configured to perform a set of checking procedures or mechanisms to help ensure the security status of a consumer electronic device (e.g., a mobile terminal or phone) that holds financial instruments. The checking procedures may include: self-verifying integrity by the TRAA; checking for presence of a provisioning SIM card (one that was present when the financial instruments were enabled on the device); checking that a communication connection between the consumer electronic device and the service provider is available and active; and checking that communication connectivity to a home mobile network is available and active. The frequency of the checking mechanisms may be adjusted, for example, according to a risk-profile of a user associated with the device or the location (e.g., GPS location) of the device.
    Type: Application
    Filed: August 15, 2017
    Publication date: March 8, 2018
    Applicant: PayPal, Inc.
    Inventor: Hadi Nahari
  • Patent number: 9769593
    Abstract: Methods and systems utilize a shake and transfer process to initiate a wireless communication and provide a user device with time and location information of the communication, which can be associated with contact information of a user of the other device. As a result, a user has additional information associated with a contact, and the time and location information can be used to determine or track elapsed time and distance traveled between communications.
    Type: Grant
    Filed: July 14, 2014
    Date of Patent: September 19, 2017
    Assignee: PAYPAL, INC.
    Inventors: Sebastien Taveau, Carl Stone, Nadav Naaman, Hadi Nahari
  • Patent number: 9734496
    Abstract: Systems and methods for use with a service provider and a consumer electronic device include a trusted remote attestation agent (TRAA) configured to perform a set of checking procedures or mechanisms to determine the security status of a consumer electronic device (e.g., mobile terminal or phone) holding financial instruments. Checking procedures may include: self-verifying integrity by the TRAA; checking for presence of a provisioning SIM card (one present when financial instruments were enabled on the device); checking that communication connectivity between the device and service provider is available and active; and that communication connectivity to a home mobile network is available and active. Frequency of the checking mechanisms may be adjusted according to a risk-profile of a user associated with the device or the GPS location of the device. The checks may be used to temporarily disable or limit the use of the financial instruments from the device.
    Type: Grant
    Filed: March 31, 2010
    Date of Patent: August 15, 2017
    Assignee: PayPal, Inc.
    Inventor: Hadi Nahari
  • Publication number: 20170053107
    Abstract: Methods, systems, and computer program products for providing behavioral stochastic authentication (BSA) are disclosed. For example, a computer-implemented method may include authenticating a user of a mobile device at a plurality of different times based on authentication credentials, collecting stochastic data associated with the mobile device during time periods corresponding to authenticating the user of the mobile device at the plurality of different times, and in response to an authentication request, authenticating the user of the mobile device based on comparing current data associated with the mobile device and the collected stochastic data to determine that the user of the mobile device is trusted.
    Type: Application
    Filed: November 8, 2016
    Publication date: February 23, 2017
    Inventor: Hadi Nahari
  • Patent number: 9489503
    Abstract: Methods and systems for authenticating a user and a consumer electronic device (CED) to a financial services provider (FSP) for purposes of communications initiated from the device and needing security, such as purchases and financial transactions, are provided. The FSP may compile information about a user's behavior from various sources, both public and private, including the CED. The information may be of a stochastic nature, being gathered by sampling user data and behavior at chosen times. The information may include indicators of user behavior—such as the user using the device to check various accounts and web-pages—and data from the device—such as GPS location. Based on the compiled stochastic information, and using a sliding scale, a throttling mechanism, acceptance variation, and pinging information, the FSP can compare current information from the device with what is known about the user and the device to provide a more accurate and reliable authentication process.
    Type: Grant
    Filed: September 8, 2010
    Date of Patent: November 8, 2016
    Assignee: PAYPAL, INC.
    Inventor: Hadi Nahari
  • Patent number: 9467292
    Abstract: Systems and methods are provided for a device to engage in a zero-knowledge proof with an entity requiring authentication either of secret material or of the device itself. The device may provide protection of the secret material or its private key for device authentication using a hardware security module (HSM) of the device, which may include, for example, a read-only memory (ROM) accessible or programmable only by the device manufacturer. In the case of authenticating the device itself a zero-knowledge proof of knowledge may be used. The zero-knowledge proof or zero-knowledge proof of knowledge may be conducted via a communication channel on which an end-to-end (e.g.
    Type: Grant
    Filed: June 19, 2015
    Date of Patent: October 11, 2016
    Assignee: PAYPAL, INC.
    Inventor: Hadi Nahari
  • Publication number: 20160255059
    Abstract: A user inserts a received random sequence into the user's password or PIN. The user enters and transmits this randomized password to a service provider. The service provider extracts the password to determine whether to authenticate the user.
    Type: Application
    Filed: May 9, 2016
    Publication date: September 1, 2016
    Inventor: Hadi Nahari
  • Publication number: 20160210620
    Abstract: An initial communication pathway is established between a first execution environment of a mobile device and a second execution environment of the mobile device. The first and second execution environments are executed in parallel with each other. The second execution environment has a higher level of security than the first execution environment. A request is received from a first entity to authenticate itself. The first entity resides in the first execution environment of the mobile device. The first entity is authenticated in response to the request. The authentication is performed by a second entity that resides in the second execution environment of the mobile device. The receiving of the request and the authenticating are performed using a direct communication link between the first execution environment and the second execution environment while bypassing the initial communication pathway.
    Type: Application
    Filed: March 25, 2016
    Publication date: July 21, 2016
    Inventors: Sebastien Ludovic Jean Taveau, Hadi Nahari