US2018349913A1PendingUtilityA1

Systems and methods for authorizing a transaction with an unexpected cryptogram

Assignee: SIMPLY TAPP INCPriority: Aug 30, 2011Filed: Jun 1, 2018Published: Dec 6, 2018
Est. expiryAug 30, 2031(~5.1 yrs left)· nominal 20-yr term from priority
G06Q 20/02H04L 9/3234G06Q 20/385H04L 9/321G06Q 20/40G06Q 20/40975G06Q 20/3223H04L 9/3271H04L 2209/56G06Q 20/20H04L 2209/80G06Q 20/382G06Q 20/32G06Q 20/326G06Q 20/3278
43
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods are described for performing a timely authorization of digital credential data delivered from a mobile device that is without access to a local persistently stored permanent cryptographic key. An application executable in the operating system of a mobile device receives a first non-permanent cryptographic key associated with the account from a remote computer system, stores the first non-permanent cryptographic key as a local cryptographic key associated with the account; generates a response cryptogram using the local cryptographic key and without accessing the permanent cryptographic key and sends a device response communication from the mobile device to an electronic reader of a POS terminal, the device response communication comprising an application data protocol unit containing the response cryptogram and an account identifier for the account.

Claims

exact text as granted — not AI-modified
1 . A method for secure application-based participation in a payment card transaction authorization process by a mobile device, the method comprising:
 at a mobile device, executing an application in an operating system of the mobile device, the application configured to generate response cryptograms using data associated with an account that has an associated digital credential without accessing a permanent cryptographic key issued for the digital credential and send the response cryptograms over a first communications channel;   receiving by the application over a wireless network from a remote computer system, a first set of data associated with the account, the first set of data comprising a first non-permanent cryptographic key associated with the account;   locally storing the first non-permanent cryptographic key at the mobile device as a local cryptographic key associated with the account; and   sending information to a point-of-sale (POS) terminal from the mobile device, wherein sending information to the POS terminal comprises:
 generating, by the application, a response cryptogram using the local cryptographic key, wherein the response cryptogram does not include the local cryptographic key associated with the account used to generate the response cryptogram; and 
 sending a device response communication from the mobile device to an electronic reader through the first communications channel, the device response communication comprising an application data protocol unit containing the response cryptogram and an account identifier for the account. 
   
     
     
         2 . The method of  claim 1 , further comprising:
 receiving by the application over the wireless network from the remote computer system, a second set of data associated with the account, the second set of data comprising a second non-permanent cryptographic key associated with the account; and   storing the received second non-permanent cryptographic key as the local cryptographic key associated with the account to change the local cryptographic key associated with the account.   
     
     
         3 . The method of  claim 2 , wherein the local cryptographic key associated with the account is changed between interrogations. 
     
     
         4 . The method of  claim 1 , wherein the mobile device is an NFC emulating device, wherein the first communications channel is an NFC communications channel and the first set of data associated with the account and the second set of data associated with the account are received via a data connection over the internet. 
     
     
         5 . The method of  claim 1 , wherein the response cryptogram is a hash. 
     
     
         6 . The method of  claim 1 , wherein generating the response cryptogram using the local cryptographic key comprises generating the response cryptogram using a set of inputs specified by a card specification. 
     
     
         7 . The method of  claim 1 , wherein the first non-permanent cryptographic key and second non-permanent cryptographic key are shared by a remote payment authorization process. 
     
     
         8 . The method of  claim 1 , wherein the first non-permanent cryptographic key and second non-permanent cryptographic key are associated with an issuer master key. 
     
     
         9 . The method of  claim 1 , further comprising, at the remote computer system:
 prior to the mobile device sending the response cryptogram to the POS terminal,
 generating the first non-permanent cryptographic key, 
 associating the first non-permanent cryptographic key with the account, and 
 sending the first non-permanent cryptographic key and the account identifier to the mobile device over the wireless network; and 
   subsequent to the mobile device sending the response cryptogram to the POS terminal,
 generating the second non-permanent cryptographic key, 
 associating the second non-permanent cryptographic key with the account and 
 sending the second non-permanent cryptographic key and the account identifier to the mobile device over the wireless network. 
   
     
     
         10 . The method of  claim 10 , wherein the digital credential comprises a secure element representation maintained at the remote computer system. 
     
     
         11 . A system for secure application-based participation by a mobile device in payment card transaction authorization process, the system comprising:
 a mobile device comprising:
 a controller configured to route communications received over a communications channel; 
 a wireless interface to connect to a wireless network that is separate from the communications channel; 
 a processor; 
 a computer readable storage medium accessible by the processor, the computer readable storage medium storing an application executable in an operating system of the mobile device to:
 receive over the wireless network from a remote computer system, a first set of data associated with the account having an associated digital credential, the first set of data comprising a first non-permanent cryptographic key associated with the account; 
 store the first non-permanent cryptographic key at the mobile device as a local cryptographic key associated with the account; 
 generate a response cryptogram using the local cryptographic key and without accessing a permanent cryptographic key issued for the digital credential, wherein the response cryptogram does not include the local cryptographic key associated with the account used to generate the response cryptogram; and 
 send a device response communication from the mobile device to an electronic reader of a POS terminal through the communications channel, the device response communication comprising an application data protocol unit containing the response cryptogram and an account identifier for the account. 
 
   
     
     
         12 . The system of  claim 11 , wherein the application is further executable to:
 receive over the wireless network from the remote computer system, a second set of data associated with the account, the second set of data comprising a second non-permanent cryptographic key associated with the account;   store the received second non-permanent cryptographic key as the local cryptographic key associated with the account to change the local cryptographic key associated with the account.   
     
     
         13 . The system of  claim 12 , wherein the application is executable to change the local cryptographic key associated with the account between interrogations. 
     
     
         14 . The system of  claim 11 , wherein the mobile device is an NFC emulating device, the communications channel is an NFC channel, and the application is further executable to request and receive the first set of data associated with the account and the second set of data associated with the account via a data connection over the internet to the remote computer system. 
     
     
         15 . The system of  claim 11 , wherein the response cryptogram is a hash. 
     
     
         16 . The system of  claim 11 , wherein generating the response cryptogram using the local cryptographic key comprises generating the response cryptogram using a set of inputs specified by a card specification. 
     
     
         17 . The system  claim 11 , wherein the first non-permanent cryptographic key and second non-permanent cryptographic key are shared by a remote payment authorization process. 
     
     
         18 . The system of  claim 11 , wherein the first non-permanent cryptographic key and second non-permanent cryptographic key are associated with an issuer master key. 
     
     
         19 . The system of  claim 11 , further comprising the remote computer system, the remote computer system configured to generate non-permanent cryptographic keys associated with the account and send the non-permanent cryptographic keys associated with the account and the account identifier to the mobile device over the wireless network. 
     
     
         20 . The system of claim  21 , wherein the remote computer system comprises a secure element representation for the account, wherein the digital credential comprises the secure element representation.

Join the waitlist — get patent alerts

Track US2018349913A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.