Management of identities in a transaction infrastructure
US-2015227920-A1 · Aug 13, 2015 · US
US10664824B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10664824-B2 |
| Application number | US-201815949790-A |
| Country | US |
| Kind code | B2 |
| Filing date | Apr 10, 2018 |
| Priority date | Dec 19, 2013 |
| Publication date | May 26, 2020 |
| Grant date | May 26, 2020 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Techniques for enhancing the security of a communication device when conducting a transaction using the communication device may include receiving a cryptogram generation key replenishment request that includes transaction log information derived from transaction data stored in a transaction log on a communication device, verifying that the transaction log information in the replenishment request is consistent with the previously received transaction information, and providing a new cryptogram generation key to the communication device in response to verifying the transaction log information in the replenishment request.
Opening claim text (preview).
What is claimed is: 1. A method for enhancing security of a communication device when conducting a transaction using the communication device, the method comprising: providing, by a remote computer, a first transaction cryptogram generation key to the communication device, wherein the first transaction cryptogram generation key is associated with a set of one or more limited-use thresholds that limits usage of the first transaction cryptogram generation key and the first transaction cryptogram generation key is usable for more than one transaction; receiving, by the remote computer, transaction information for each transaction conducted by the communication device using the first transaction cryptogram generation key; receiving, by the remote computer, a replenishment request for a second transaction cryptogram generation key, the replenishment request including transaction log information derived from transaction data stored in a transaction log on the communication device, the transaction data being unique for each transaction conducted by the communication device using the first transaction cryptogram generation key; verifying, by the remote computer, that the transaction log information in the replenishment request is consistent with the previously received transaction information; and providing, by the remote computer, the second transaction cryptogram generation key to the communication device in response to verifying the transaction log information in the replenishment request, wherein providing the second transaction cryptogram generation key to the communication device includes providing, to the communication device, a key index that includes information pertaining to generation of the second transaction cryptogram generation key. 2. The method of claim 1 , wherein the key index includes at least one of: time information indicating when the second transaction cryptogram generation key is generated; and a replenishment counter value indicating a number of times that the communication device has been replenished with a transaction cryptogram generation key. 3. The method of claim 1 , wherein the key index includes: a pseudo-random number that is used as a seed to generate the second transaction cryptogram generation key; or a transaction counter value indicating a number of transactions that has been previously conducted by a mobile application of the communication device at the time the second transaction cryptogram generation key is generated. 4. The method of claim 1 , wherein the set of one or more limited-use thresholds includes at least one of: a time-to-live indicating a time duration that the first transaction cryptogram generation key is valid for; a predetermined number of transactions that the first transaction cryptogram generation key is valid for; and a cumulative transaction amount indicating a total transaction amount that the first transaction cryptogram generation key is valid for. 5. The method of claim 4 , wherein the set of one or more limited-use thresholds includes an international usage threshold and a domestic usage threshold. 6. The method of claim 1 , wherein the transaction log stored on the communication device includes: for each transaction conducted using the first transaction cryptogram generation key: a transaction timestamp indicating the time of the corresponding transaction; and an application transaction counter value associated with the corresponding transaction. 7. The method of claim 1 , wherein the transaction log information in the replenishment request includes an authentication code computed over at least the transaction log using the first transaction cryptogram generation key. 8. The method of claim 1 , wherein the replenishment request is received by the remote computer in response to: the communication device determining that a next transaction conducted with the first transaction cryptogram generation key will exhaust the one or more limited-use thresholds of the first transaction cryptogram generation key; the communication device determining that the one or more limited-use thresholds associated with the first transaction cryptogram generation key has been exhausted; or the communication device receiving a push message requesting the communication device to replenish the first transaction cryptogram generation key. 9. The method of claim 1 , wherein the second transaction cryptogram generation key has a usage limit that is different than a usage limit of the first transaction cryptogram generation key. 10. A server computer comprising: a hardware processor; and a memory coupled to the hardware processor and storing code implementing operations for enhancing security of a communication device when conducting transactions using the communication device, the operations including: providing a first transaction cryptogram generation key to the communication device, wherein the first transaction cryptogram generation key is associated with a set of one or more limited-use thresholds that limits usage of the first transaction cryptogram generation key and the first transaction cryptogram generation key is usable for more than one transaction; receiving transaction information for each transaction conducted by the communication device using the first transaction cryptogram generation key; receiving a replenishment request for a second transaction cryptogram generation key, the replenishment request including transaction log information derived from transaction data stored in a transaction log on the communication device, the transaction data being unique for each transaction conducted by the communication device using the first transaction cryptogram generation key; verifying that the transaction log information in the replenishment request is consistent with the previously received transaction information; and providing the second transaction cryptogram generation key to the communication device in response to verifying the transaction log information in the replenishment request, wherein providing the second transaction cryptogram generation key to the communication device includes providing, to the communication device, a key index that includes information pertaining to generation of the second transaction cryptogram generation key. 11. The server computer of claim 10 , wherein the key index includes at least one of: time information indicating when the second transaction cryptogram generation key is generated; and a replenishment counter value indicating a number of times that the communication device has been replenished with a transaction cryptogram generation key. 12. The server computer of claim 10 , wherein the key index includes: a pseudo-random number that is used as a seed to generate the second transaction cryptogram generation key; or a transaction counter value indicating a number of transactions that has been previously conducted by a mobile application of the communication device at the time the second transaction cryptogram generation key is generated. 13. The server computer of claim 10 , wherein the set of one or more limited-use thresholds includes at least one of: a time-to-live indicating a time duration that the first transaction cryptogram generation key is valid for; a predetermined number of transactions that the first transaction cryptogram generation key is valid for; and a cumulative transaction amount indicating a total transaction amount that the first transaction cryptogram generation key is valid for. 14. The server computer of claim 13 , wherein the set of one or more limited-use thresholds includes an int
Aspects of commerce using mobile devices [M-devices] · CPC title
Key scheduling, i.e. generating round keys or sub-keys for block encryption · CPC title
Business processing using cryptography · CPC title
involving random numbers or seeds · CPC title
wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.