Method, server, and storage medium for verifying transactions using a smart card

US10878413B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10878413-B2
Application numberUS-201615177413-A
CountryUS
Kind codeB2
Filing dateJun 9, 2016
Priority dateJan 7, 2014
Publication dateDec 29, 2020
Grant dateDec 29, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method, server and storage medium for verifying a transaction using a smart card are disclosed. A server receives a transaction request to perform a transaction with a user of the smart card. The transaction request includes identification information and encrypted data extracted from the smart card, and transaction information. The server determines a user account linked to the identification information. The server performs a first verification process to authenticate the smart card by verifying that the smart card possesses a correct decryption key corresponding to the identification information. The server performs a second verification process to authenticate the smart card by verifying that the encrypted data extracted from the smart card encodes stored data corresponding to the respective user account linked to the identification information. If the first and the second verification processes are successful, the server processes the transaction in accordance with the transaction information.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for verifying a transaction using a smart card, the method comprising: receiving, by a server comprising a memory storing instructions and a processor, a transaction request from a first terminal to perform a transaction with a user of the smart card, wherein: the transaction request includes card identification information, encrypted card data, and transaction information, the card identification information and the encrypted card data are extracted by the first terminal from the smart card, and un-encrypted card data and a decryption key associated with the card identification information are stored in the memory of the server; determining, by the server, a respective user account linked to the card identification information; performing, by the server, a first verification process to authenticate a first aspect of the smart card, the first verification process comprising: verifying that the smart card possesses a same decryption key as the decryption key stored in the memory and associated with the card identification information, and a decryption circuit; in accordance with successful completion of the first verification process, performing a second verification process to authenticate a second aspect of the smart card, the second verification process comprising: obtaining the un-encrypted card data and the stored decryption key from the memory of the server according to the respective user account, decrypting, with the stored decryption key, the encrypted card data included in the transaction request from the first terminal, determining whether the encrypted card data as decrypted by the server matches the stored un-encrypted card data, and in accordance with a determination that the encrypted card data as decrypted by the server matches the stored un-encrypted card data, authenticating the user of the smart card as an authorized user of the smart card; and in accordance with successful completion of the first and the second verification processes, processing, by the server, the transaction in accordance with the transaction information. 2. The method of claim 1 , wherein verifying that the smart card possesses the same decryption key as the decryption key stored in the memory and associated with the card identification information, and a decryption circuit comprises: generating a pseudo-random string, and storing the pseudo-random string in association with the transaction request; encrypting the pseudo-random string with a stored encryption key corresponding to the card identification information, wherein the stored encryption key and the stored decryption key corresponding to the card identification information form an encryption-decryption key pair; sending the encrypted pseudo-random string to the first terminal for processing by the smart card; in response to sending the encrypted pseudo-random string, receiving, from the first terminal, a decrypted string, wherein the decrypted string corresponds to a decryption process performed by the smart card on the encrypted pseudo-random string with a respective decryption key stored on the smart card; and comparing the decrypted string to the stored pseudo-random string to determine whether the decrypted string and the stored pseudo-random string are identical. 3. The method of claim 1 , wherein processing the transaction further comprises: processing the transaction request according to the transaction information and payment information linked to the respective user account. 4. The method of claim 1 , further comprising: providing updated card data to the smart card, wherein the updated card data is encrypted with the stored encryption key corresponding to the respective user account. 5. The method of claim 1 , wherein processing the transaction further comprises: in accordance with a determination that the transaction information is associated with a security risk, performing a third verification process including: sending a notification to an electronic device linked to the respective user account; and in response to receiving an authorization message from the electronic device, processing the transaction request corresponding to the transaction request. 6. The method of claim 5 , wherein the security risk is detected when the transaction information indicates at least one of: a transaction amount exceeding a single transaction limit, a transaction amount exceeding a daily transaction limit, a transaction location outside of a predetermined radius from a predefined home location, and one or more items corresponding to the transaction that do match a purchasing profile for the respective user account. 7. A server, comprising: one or more processors; and a memory storing one or more programs to be executed by the one or more processors, the one or more programs comprising instructions for: receiving a transaction request from a first terminal to perform a transaction with a user of a smart card, wherein: the transaction request includes card identification information encrypted card data, and transaction information, the card identification information and the encrypted card data are extracted by the first terminal from the smart card, and un-encrypted card data and a decryption key associated with the card identification information are stored in the memory of the server; determining a respective user account linked to the card identification information; performing a first verification process to authenticate a first aspect of the smart card, the first verification process comprising: verifying that the smart card possesses a same decryption key as the decryption key stored in the memory and associated with the card identification information, and a decryption circuit; in accordance with successful completion of the first verification process, performing a second verification process to authenticate a second aspect of the smart card, the second verification process comprising: obtaining the un-encrypted card data and the stored decryption key from the memory of the server according to the respective user account, decrypting, with the stored decryption key, the encrypted card data included in the transaction request from the first terminal, determining whether the encrypted card data as decrypted by the server matches the stored un-encrypted card data, and in accordance with a determination that the encrypted card data as decrypted by the server matches the stored un-encrypted card data, authenticating the user of the smart card as an authorized user of the smart card; and in accordance with successful completion of the first and the second verification processes, processing the transaction in accordance with the transaction information. 8. The server of claim 7 , wherein the one or more programs further comprise instructions for: generating a pseudo-random string, and storing the pseudo-random string in association with the transaction request; encrypting the pseudo-random string with a stored encryption key corresponding to the card identification information, wherein the stored encryption key and the stored decryption key corresponding to the card identification information form an encryption-decryption key pair; sending the encrypted pseudo-random string to the first terminal for processing by the smart card; in response to sending the encrypted pseudo-random string, receiving, from the first terminal, a decrypted string, wherein the decrypted string corresponds to a decryption process performed by the smart card on the encrypted pseudo-random string with a respective decryption key stored on the smart card; and comparing the decrypted string to the stored pseudo-random string to determine whether the decrypte

Assignees

Inventors

Classifications

  • using location information · CPC title

  • involving key management · CPC title

  • the marking being simulated using a light source, e.g. a barcode shown on a display or a laser beam with time-varying intensity profile · CPC title

  • Electronic credentials · CPC title

  • involving the use of external additional devices, e.g. dongles or smart cards · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10878413B2 cover?
A method, server and storage medium for verifying a transaction using a smart card are disclosed. A server receives a transaction request to perform a transaction with a user of the smart card. The transaction request includes identification information and encrypted data extracted from the smart card, and transaction information. The server determines a user account linked to the identificatio…
Who is the assignee on this patent?
Tencent Tech Shenzhen Co Ltd
What technology area does this patent fall under?
Primary CPC classification G06Q20/4015. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Dec 29 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).