Provisioning method and system with message conversion

US11296862B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11296862-B2
Application numberUS-201916554955-A
CountryUS
Kind codeB2
Filing dateAug 29, 2019
Priority dateAug 29, 2019
Publication dateApr 5, 2022
Grant dateApr 5, 2022

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method is disclosed. The method comprises receiving, from a communication device, a provisioning request message including a user device identifier and a cryptogram in a first message format, which is received from the user device by the communication device during a message exchange process between the user device and the communication device. The method also includes generating an authorization request message in a second message format, the authorization request message comprising the cryptogram, transmitting the authorization request message to an authorizing computer, and receiving an authorization response message from the authorizing computer. The method also includes providing access data to the communication device.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: receiving, by a server computer from a communication device, an initialization request message to provision access data; providing, by the server computer to the communication device, a dynamic data element; receiving, by the server computer from the communication device, a provisioning request message including a user device identifier and a cryptogram in a first message format, which is received from a user device by the communication device during a message exchange process between the user device and the communication device, wherein the cryptogram is formed using at least a first cryptographic key that is on the user device and the dynamic data element, and wherein the first cryptographic key is derived on the user device; generating, by the server computer, an authorization request message in a second message format by mapping data elements of the provisioning request in the first message format to corresponding data elements of the authorization request message in the second message format, the authorization request message comprising the cryptogram; transmitting, by the server computer, the authorization request message to an authorizing computer, wherein the cryptogram is validated using a second cryptographic key that is on the authorizing computer; receiving, by the server computer, an authorization response message from the authorizing computer; and in response to receiving the authorization response message, providing, by the server computer, access data to the communication device. 2. The method of claim 1 , wherein the communication device is a mobile phone and the user device is a card. 3. The method of claim 1 , wherein the cryptogram is formed using a DES or triple DES encryption process. 4. The method of claim 1 , further comprising: verifying that the authorization response message comprises a positive authorization indicator, prior to providing the access data to the communication device. 5. The method of claim 1 , wherein the first message format is an HTTP/S message format, and the second message format is an ISO 8583 message format. 6. The method of claim 1 , wherein the authorization request message further comprises a value. 7. The method of claim 1 , wherein the access data comprises data that can allow a user of the communication device to access a secure location. 8. The method of claim 1 , wherein the user device is in the form of a payment card. 9. The method of claim 1 , wherein the user device and the communication device communicate via NFC. 10. The method of claim 1 , wherein the user device identifier is a primary account number. 11. A server computer comprising: a processor; and a computer readable medium, the computer readable medium comprising code, executable by the processor to implement a method comprising: receiving, from a communication device, an initialization request message to provision access data; providing, to the communication device, a dynamic data element; receiving, from the communication device, a provisioning request message including a user device identifier and a cryptogram in a first message format, which is received from a user device by the communication device during a message exchange process between the user device and the communication device, wherein the cryptogram is formed using at least a first cryptographic key that is on the user device and the dynamic data element, and wherein the first cryptographic key is derived on the user device; generating an authorization request message in a second message format by mapping data elements of the provisioning request in the first message format to corresponding data elements of the authorization request message in the second message format, the authorization request message comprising the cryptogram; transmitting the authorization request message to an authorizing computer, wherein the cryptogram is validated using a second cryptographic key that is on the authorizing computer; receiving an authorization response message from the authorizing computer; and in response to receiving the authorization response message, providing access data to the communication device. 12. The server computer of claim 11 , wherein the authorization request message comprises a zero value amount, the cryptogram, and the user device identifier. 13. The server computer of claim 11 , wherein the authorization response message comprises the user device identifier and an authorization indicator. 14. The server computer of claim 11 , wherein the access data comprises a token. 15. The server computer of claim 11 , wherein the dynamic data element comprises a random number. 16. A method comprising: transmitting, by a communication device to a server computer, an initialization request message to provision access data; receiving, by the communication device from the server computer, a dynamic data element; performing, by a communication device, a message exchange process with a user device, wherein a cryptogram is received from the user device by the communication device during the message exchange process, wherein the cryptogram is formed using at least a first cryptographic key that is on the user device and the dynamic data element; transmitting, by the communication device, a provisioning request message including a user device identifier and the cryptogram to a server computer, which generates an authorization request message comprising the cryptogram in a second message format by mapping data elements of the provisioning request in the first message format to corresponding data elements of the authorization request message in the second message format, transmits the authorization request message to an authorizing computer, which verifies the cryptogram using a second cryptographic key that is on the authorizing computer; and receiving, by the communication device, access data in response to transmitting the provisioning request message. 17. The method of claim 16 , wherein the communication device is a mobile phone and the user device is a card. 18. The method of claim 16 , wherein the server computer is in communication with an access data vault, and wherein the server computer retrieves the access data from the access data vault, and transmits the access data to the communication device, after receiving an authorization response message from the authorizing computer, which is responsive to the authorization request message. 19. The method of claim 16 , wherein the provisioning request message is in an XML data format.

Assignees

Inventors

Classifications

  • Conversion or adaptation of application format or content (adding application control or application functional data H04L67/561) · CPC title

  • for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

  • for supporting key management in a packet data network (cryptographic mechanisms or cryptographic arrangements for key management H04L9/08) · CPC title

  • H04L9/0618Primary

    Block ciphers, i.e. encrypting groups of characters of a plain text message using fixed encryption transformation · CPC title

  • involving additional devices, e.g. trusted platform module [TPM], smartcard or USB · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11296862B2 cover?
A method is disclosed. The method comprises receiving, from a communication device, a provisioning request message including a user device identifier and a cryptogram in a first message format, which is received from the user device by the communication device during a message exchange process between the user device and the communication device. The method also includes generating an authoriza…
Who is the assignee on this patent?
Visa Int Service Ass
What technology area does this patent fall under?
Primary CPC classification H04L9/0618. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 05 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).