US2016203480A1PendingUtilityA1
Pin creation system and method
Est. expiryJun 2, 2026(expired)· nominal 20-yr term from priority
G06Q 20/38215G06Q 20/4012G06Q 20/40145G06Q 2220/00H04L 9/50G07F 7/1016G06Q 20/3823G07F 7/1008G06Q 20/40G06Q 20/385G07F 7/1025
44
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A user may select or create a PIN at a non-secure input device, such as a web-enabled personal computer. PINs are stored at a financial host in encrypted form, as PIN offsets. The user selected PIN and a corresponding account number are sent in clear text form to the host, which selects a base PIN offset corresponding to the PIN. A host security module within the host converts the base PIN offset to an actual PIN offset using the actual account number. The actual PIN offset (corresponding to the new PIN and the account number) is then stored at the financial host.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system for permitting a user to establish a PIN, wherein the PIN corresponds to an account identifier of the user, and wherein PINs are stored in encrypted form, the system comprising:
a host computer system connected for receiving a PIN to be established and an account identifier corresponding to that PIN, the PIN and account identifier captured from a user at a non-secure input device, the host computer system comprising:
a database, including a first table for storing encrypted PINs, each encrypted PIN corresponding to an account identifier and a second table for storing base encrypted PINs, with each base encrypted PIN corresponding to one of each possible PIN to be established by a user, and with all base encrypted PINs created using a single base account identifier;
a server, the server receiving the PIN captured at the input device and selecting a base encrypted PIN from the second table corresponding to the captured PIN;
a security module, the security module receiving the selected base encrypted PIN from the second table, receiving the account identifier captured at the input device, and converting the selected base encrypted base PIN into a final encrypted PIN using the captured account identifier;
wherein the final encrypted PIN is stored in the first table as an encrypted PIN corresponding to the captured account identifier.
2 . The system of claim 1 , wherein the input device is a personal computer of the user that captures the PIN and account identifier in clear text form and provides the clear text PIN and account identifier to the host.
3 . The method of claim 2 , wherein the clear text PIN represents human recognizable characters.
4 . The method of claim 3 , wherein the clear text PIN is a string of alphanumeric characters.
5 . The method of claim 1 , wherein the captured PIN is based on user biometrics.
6 . The method of claim 1 , wherein the encrypted PINs stored in the database are PIN offsets, wherein the encrypted base PIN is a base PIN offset, and wherein the final encrypted PIN is a final PIN offset.
7 . The system of claim 1 , wherein the security module is a hardware security module (HSM) having a secure mode and a non-secure mode, and wherein the PIN is established with the HSM in the secure mode.
8 . The system of claim 7 , wherein the base encrypted PINs stored in the second table are encrypted using a private key, and wherein the HSM converts the selected base encrypted PIN into the final PIN using the private key.
9 . The method of claim 7 , wherein the HSM in the secure mode receives an encrypted PIN in the form of PIN block when a user conducts a transaction and enters a PIN, and wherein the HSM converts the PIN block into a PIN offset in order to compare the converted PIN offset to a PIN offset stored in the database.
10 . The method of claim 1 , wherein the PIN and account identifier are both associated with a financial account.
11 . The method of claim 10 , wherein the account identifier is a primary account number (PAN).
12 . A method for a user to establish a PIN to be associated with a user account identifier and to be stored at a host computer system, wherein the established PIN is subsequently used to authenticate transactions conducted by the user with the associated user account identifier, and wherein the host computer system includes a database that stores PINs in encrypted form as PIN offsets, the method comprising:
receiving, at the host computer system, a user-selected PIN captured in clear text form from the user at a non-secure input device; creating and encrypting, at a security module of the host computer system, a plurality of base PIN offsets using one base account identifier, the one base account identifier being the same for each of the created and encrypted base PIN offsets, each base encrypted PIN offset corresponding to one of a plurality of all possible, permitted PINs for selection by the user; selecting a base encrypted PIN offset at the host computer system corresponding to the captured user-selected PIN, wherein the selected base encrypted PIN offset is one of the plurality of base encrypted PIN offsets; using, at the security module, the user account identifier to convert the selected base encrypted PIN to a final encrypted PIN offset; and storing the final encrypted PIN offset in the database of the host computer system in association with the user account identifier.
13 . The method of claim 12 , wherein the security module is a hardware security module (HSM) having a secure mode and a non-secure mode, and wherein the PIN is established with the HSM in the secure mode.
14 . The method of claim 12 , wherein the clear text PIN represents human recognizable characters.
15 . The method of claim 14 , wherein the clear text PIN is a string of alphanumeric characters.
16 . The method of claim 12 , wherein the captured PIN is based on user biometrics.
17 . The method of claim 12 , wherein the one base account identifier is a user primary account number (PAN).
18 . The method of claim 12 , wherein the primary account number (PAN) is an account number of the user selecting the PIN.
19 . The method of claim 12 , wherein the step of creating and encrypting a plurality of base PIN offsets further comprises using an encryption key with the one base account identifier in order to create and encrypt the plurality of base PIN offsets, and wherein the step of using the user account identifier to convert the selected base encrypted PIN to a final encrypted PIN offset further comprises using the encryption key with the user account identifier to convert the selected base encrypted PIN to a final encrypted PIN offset.Join the waitlist — get patent alerts
Track US2016203480A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.