System and methods for validating and performing operations on homomorphically encrypted data
Abstract
A system and method of validating and performing operations on homomorphically encrypted data are described herein. The methods include processing a secure financial transaction by receiving a transaction request to complete a financial transaction, with at least a portion of the request encrypted according to a homomorphic encryption scheme, and the transaction request comprising confidential cardholder data including an account number, non-confidential cardholder data, and transaction data, and retrieving one or more sets of encrypted comparison cardholder data encrypted according to a homomorphic encryption scheme. The confidential cardholder data is then compared to each set of the comparison cardholder data using one or more homomorphic operations to determine which set of comparison cardholder data matches the confidential cardholder data and validating the confidential cardholder data. An encrypted indicator is generated indicating authorization or rejection of the request and forwarded to a party seeking authorization to complete the financial transaction.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of processing a secure financial transaction, comprising:
receiving a transaction request to complete a financial transaction, with at least a portion of the request encrypted according to a homomorphic encryption scheme, and the transaction request comprising confidential cardholder data including an account number, non-confidential cardholder data, and transaction data; retrieving one or more sets of encrypted comparison cardholder data from a cardholder data database, each set of encrypted comparison cardholder data encrypted according to a homomorphic encryption scheme; comparing the encrypted confidential cardholder data to each set of the encrypted comparison cardholder data using one or more homomorphic operations to determine which set of comparison cardholder data matches the confidential cardholder data and validating the confidential cardholder data; generating an encrypted indicator indicating authorization or rejection of the request to complete the financial transaction based upon at least the validation of the confidential cardholder data; and forwarding the encrypted indicator authorization or rejection of the request to complete the financial transaction to a party seeking authorization to complete the financial transaction, wherein the confidential cardholder data is never decrypted during the method.
2 . The method of claim 1 , wherein the homomorphic encryption scheme is a fully homomorphic encryption scheme or a somewhat homomorphic encryption scheme.
3 . The method of claim 1 , wherein the confidential cardholder data includes one or more of: a portion of the account number, the account number, an expiry date and a Card Verification Value (CVV) number.
4 . The method of claim 1 , wherein the non-confidential cardholder data includes one or more of: a bank name, a cardholder name, a Bank Identification Number (BIN) and the last four digits of the account number.
5 . The method of claim 1 , wherein the transaction data includes one or more of: a transaction amount, a transaction date and a merchant identifier.
6 . The method of claim 1 , further including executing a step of retrieving the transaction data and executing the step of comparing the transaction data using one or more homomorphic operations to determine whether the transaction amount can be authorized.
7 . The method of claim 1 , wherein a portion of the request is compared to the set of comparison data to reduce the size of the set of comparison data prior to comparing the encrypted confidential cardholder data.
8 . The method of claim 1 , wherein the one or more homomorphic operations combine to form an XNOR operation.
9 . The method of claim 1 , wherein the financial transaction is a credit card transaction or a debit card transaction or a stored-value card transaction.
10 . The method of claim 1 , wherein the request to complete the financial transaction is received by one or more of: a bank, a credit card company, a card issuer or a payment processor.
11 . A non-transient computer-readable medium containing computer-readable instructions which when executed by a computer processor perform the method of:
receiving a request to complete a financial transaction with at least a portion of the request encrypted according to a homomorphic encryption scheme, and the transaction request comprising confidential cardholder data including an account number, non-confidential cardholder data and transaction data; retrieving one or more sets of encrypted comparison cardholder data from a cardholder data database, each set of encrypted comparison cardholder data encrypted according to a homomorphic encryption scheme; comparing the confidential cardholder data to each set of the comparison cardholder data using one or more homomorphic operations to determine which set of comparison cardholder data matches the confidential cardholder data and validating the confidential cardholder data; generating an encrypted indicator indicating authorization or rejection of the request to complete the financial transaction based upon at least the validation of the confidential cardholder data; and forwarding the encrypted indicator indicating authorization or rejection of the request to complete the financial transaction to a party seeking authorization to complete the financial transaction, wherein the confidential cardholder data is never decrypted during the method.
12 . The method of claim 1 , wherein the homomorphic encryption scheme is a fully homomorphic encryption scheme or a somewhat homomorphic encryption scheme.
13 . The computer-readable medium of claim 11 , wherein the confidential cardholder data includes one or more of: a portion of the account number, an account number, an expiry date and a Card Verification Value (CVV) number.
14 . The computer-readable medium of claim 11 , wherein the non-confidential cardholder data includes one or more of: a bank name, a cardholder name, a Bank Identification Number (BIN) and the last four digits of the account number.
15 . The computer-readable medium of claim 11 , wherein the transaction data includes one or more of: a transaction amount, a transaction date and a merchant identifier.
16 . The computer-readable medium of claim 11 , further including executing a step of retrieving the transaction data and executing the step of comparing the transaction data using one or more homomorphic operations to determine whether the transaction amount can be authorized.
17 . The computer-readable medium of claim 11 , wherein a portion of the request is compared to the set of comparison data to reduce the size of the set of comparison data prior to comparing the encrypted confidential cardholder data.
18 . The computer-readable medium of claim 11 , wherein the one or more homomorphic operations combine to form an XNOR operation.
19 . The computer-readable medium of claim 11 , wherein the financial transaction is a credit card transaction or a debit card transaction or a stored-value card transaction.
20 . The computer-readable medium of claim 11 , wherein the request to complete the financial transaction is received by one or more of: a bank, a credit card company, a card issuer or a payment processor.Join the waitlist — get patent alerts
Track US2017293913A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.