Remote authentication system
US-9160741-B2 · Oct 13, 2015 · US
US11238140B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11238140-B2 |
| Application number | US-201716311144-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jul 11, 2017 |
| Priority date | Jul 11, 2016 |
| Publication date | Feb 1, 2022 |
| Grant date | Feb 1, 2022 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Encryption key exchange processes are disclosed. A disclosed method includes initiating communication between a portable communication device including a token and a first limited use encryption key, and an access device. After communication is initiated, the portable communication device receives a second limited use key from a remote server via the access device. The portable communication device then replaces the first limited use key with the second limited use key. The second limited use key is thereafter used to create access data such as cryptograms that can be used to conduct access transactions.
Opening claim text (preview).
What is claimed is: 1. A method comprising: initiating communication between a portable communication device comprising a token and a first limited use key, and a point of sale terminal, which generates authorization request message for a transaction and transmits the authorization request message to a remote server; receiving, by the portable communication device, from the remote server via the point of sale terminal, a second limited use key, wherein the point of sale terminal receives an authorization response message authorizing the transaction from the remote server, the authorization response message including the second limited use key, and wherein the portable communication device receives the second limited use key from the point of sale terminal when the portable communication device is in short range communication or in contact with the point of sale terminal; and replacing, by the portable communication device, the first limited use key with the second limited use key. 2. The method of claim 1 , wherein the portable communication device is in a form of a wearable device. 3. The method of claim 1 , wherein the authorization request message comprises a transaction amount. 4. The method of claim 1 , wherein the portable communication device is a mobile phone. 5. The method of claim 1 , further comprising: encrypting, using the second limited use key and by the portable communication device, transaction data for another transaction to form a cryptogram; and transmitting, by the portable communication device, the token and the cryptogram to another point of sale terminal to conduct the transaction. 6. The method of claim 5 , wherein the transaction is a payment transaction. 7. The method of claim 1 , wherein the portable communication device does not have a secure element. 8. The method of claim 1 , wherein the second limited use key is received in a message from the point of sale terminal, the message being one of multiple messages passing between the portable communication device and the point of sale terminal in a single physical interaction between the portable communication device and the point of sale terminal. 9. A portable communication device comprising: a processor; and a non-transitory computer readable medium, the non-transitory computer readable medium comprising code, executable by the processor to implement a method comprising: initiating communication between the portable communication device comprising a token and a first limited use key, and a point of sale terminal, which generates an authorization request message for a transaction and transmits the authorization request message to a remote server; receiving from the remote server via the point of sale terminal, a second limited use key, wherein the point of sale terminal receives an authorization response message authorizing the transaction from the remote server, the authorization response message including the second limited use key, and wherein the portable communication device receives the second limited use key from the point of sale terminal when the portable communication device is in short range communication or in contact with the point of sale terminal; and replacing the first limited use key with the second limited use key. 10. The portable communication device of claim 9 , wherein the portable communication device is in a form of a card or a wearable device. 11. The portable communication device of claim 9 , wherein the method further comprises: encrypting, using the second limited use key and by the portable communication device, transaction data for another transaction to form a cryptogram; and transmitting, by the portable communication device, the token and the cryptogram to another point of sale terminal to conduct the another transaction. 12. The portable communication device of claim 9 , wherein the portable communication device does not have a secure element. 13. A method comprising: communicating, by an point of sale terminal, with a portable communication device comprising a token and a first limited use key; generating authorization request message for a transaction and transmitting the authorization request message to a remote server; receiving, by the point of sale terminal, a second limited use key from a remote server computer in an authorization response message authorizing the transaction from the remote server; and providing, by the point of sale terminal, to the portable communication device, the second limited use key, wherein the portable communication device is in short range communication or in contact with the point of sale terminal. 14. The method of claim 13 , wherein the point of sale terminal comprises a contactless reader, and wherein the portable communication device is capable of communicating with the contactless reader through a wireless communication medium. 15. The method of claim 13 , further comprising: receiving, by the point of sale terminal, a cryptogram and the token from the portable communication device. 16. The method of claim 15 , wherein the cryptogram is created using the first limited use key. 17. The method of claim 15 , wherein the authorization request message comprises the cryptogram and the token; and wherein the remote server is an authorizing entity computer. 18. The method of claim 17 , wherein the authorization response message comprises the token. 19. The method of claim 15 , wherein the cryptogram is generated using the second limited use key and a TDES encryption function. 20. An access device configured to perform the method of claim 13 .
Key exchange · CPC title
Access security · CPC title
Key generation or derivation · CPC title
Key distribution or pre-distribution; Key agreement · CPC title
User authentication · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.