US2020286088A1PendingUtilityA1

Method, device, and system for securing payment data for transmission over open communication networks

Assignee: BLUECHAIN PTY LTDPriority: Jan 19, 2010Filed: May 28, 2020Published: Sep 10, 2020
Est. expiryJan 19, 2030(~3.5 yrs left)· nominal 20-yr term from priority
G06Q 20/20G06Q 20/388G06Q 20/40H04L 9/3263H04L 2209/805H04L 9/3247H04L 2209/56G06Q 20/3829
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for securing payment data for transmission over open communication networks is disclosed. The method comprises establishing a data connection between a first and a second transceiver device, the first transceiver device configured as a merchant device and the second transceiver device configured as a customer transceiver device. The merchant device transmits a first data package which comprises a unique merchant identifier and transaction request data, to the customer transceiver device over the data connection. The merchant device receives a cryptogram from the customer transceiver device. The cryptogram having been generated from using a secret key and a counter value together with the received unique merchant identifier and the transaction request data. The method comprises forming an authorization request comprising the received cryptogram, merchant identifier and the transaction request data and submitting said authorisation request to at least one of an issuer and an acquirer to facilitate authorisation and processing of said transaction request data.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for performing a secure transaction using a merchant transceiver device, the method comprising:
 establishing a first secure wireless data connection with a customer transceiver device, the customer transceiver device being presented in proximity to the merchant transceiver device;   transmitting a first data package to the customer transceiver device over the secure wireless data connection, the first data package comprising a unique merchant identifier and transaction request data;   determining a breakdown in the first secure wireless connection;   responsive to determining a breakdown in the first secure wireless connection, storing a transaction state in a memory comprised in the merchant transceiver device, the transaction state comprising transaction related data created by the merchant transceiver device or received by the merchant transceiver device from the customer transceiver device;   re-establishing the first secure wireless connection with the customer transceiver device;   responsive to re-establishing the first secure wireless connection, retrieving the stored transaction state;   receiving from the customer transceiver device a customer authorisation data package, wherein the received customer authorisation data package is encrypted based on a customer transceiver device key and a transaction counter key, the customer transceiver device key and the transaction counter key being unique to each customer transceiver device and the transaction counter key being incremented after each transaction by the customer transceiver device;   transmitting a payment authorisation request to at least one payment authoriser computing device over a second secure connection, the payment authorisation request comprising the received customer authorisation data package, the unique merchant identifier and the transaction request data; and   receiving an outcome of the payment authorisation request from the at least one payment authoriser.   
     
     
         2 . The method of  claim 1 , wherein the first secure wireless data connection with the customer transceiver device is established over at least one of NFC, Bluetooth or WiFi technologies. 
     
     
         3 . The method of  claim 1 , further comprising receiving an account selection request from the customer transceiver device. 
     
     
         4 . The method of  claim 1 , wherein the customer authorisation data comprises data representative of a user selected account, and a customer identifier and a merchant identifier value. 
     
     
         5 . The method of  claim 4 , wherein the customer identifier comprises a Personal Identification Number (PIN) or a biometric identifier. 
     
     
         6 . The method of  claim 1 , further comprising encrypting the payment authorisation request using a public key issued by the at least one payment authoriser before transmitting the payment authorisation request to the at least one payment authoriser. 
     
     
         7 . The method of  claim 1 , further comprising the merchant transceiver device transmitting to the customer transceiver device a second data package comprising a signed certificate of the payment authoriser and a signature of a unique dynamic value using a merchant private key stored on the merchant transceiver device. 
     
     
         8 . The method of  claim 1 , further comprising on determining a breakdown in the first secure wireless connection, transmitting the stored transaction state to the at least one payment authoriser computing device over the second secure connection. 
     
     
         9 . The method of  claim 1 , wherein the first secure wireless data connection is established using Near Field Communication (NFC) between a first contactless interface module provided in the merchant transceiver device and a second contactless interface module provided in the customer transceiver device. 
     
     
         10 . The method of  claim 9 , wherein the first secure wireless data connection is established by the first contactless interface module energising the second contactless interface module. 
     
     
         11 . A merchant transceiver device for performing a secure transaction, the merchant transceiver device comprising at least one processor and memory comprising computer executable code to configure the at least one processor to:
 establish a first secure wireless data connection with a customer transceiver device, the customer transceiver device being presented in proximity to the merchant transceiver device;   transmit a first data package to the customer transceiver device over the secure wireless data connection, the first data package comprising a unique merchant identifier and transaction request data;   receive from the customer transceiver device customer authorisation data package, wherein the received customer authorisation data package is encrypted based on a customer transceiver device key and a transaction counter key, the customer transceiver device key and the transaction counter key being unique to each customer transceiver device and the transaction counter key being incremented after each transaction by the customer transceiver device;   determine a breakdown in the first secure wireless connection on removal of the customer transceiver device from the proximity of the merchant transceiver device;   responsive to determining a breakdown in the first secure wireless connection, store a transaction state in the memory, the transaction state comprising transaction related data created by the merchant transceiver device or received by the merchant transceiver device from the customer transceiver device;   re-establish the first secure wireless connection when the customer transceiver device reappears in proximity of the merchant transceiver device;   responsive to re-establishing the first secure wireless connection, retrieve the stored transaction state;   based on the stored transaction state, transmit a payment authorisation request to at least one payment authoriser computing device over a second secure connection, the payment authorisation request comprising the received customer authorisation data package, the unique merchant identifier and the transaction request data; and   receive an outcome of the payment authorisation request from the at least one payment authoriser.   
     
     
         12 . The merchant transceiver device of  claim 11 , wherein the first secure wireless data connection with the customer transceiver device is established over least one of NFC, Bluetooth or WiFi technologies. 
     
     
         13 . The merchant transceiver device of  claim 11 , wherein the at least one processor is further configured to receive an account selection request from the customer transceiver device. 
     
     
         14 . The merchant transceiver device of  claim 11 , wherein the customer authorisation data comprises data representative of a user selected account, and a customer identifier and a merchant identifier value. 
     
     
         15 . The merchant device of  claim 14 , wherein the customer identifier comprises a Personal Identification Number (PIN) or a biometric identifier. 
     
     
         16 . The merchant transceiver device of  claim 11 , wherein the at least one processor is further configured to encrypt the payment authorisation request using a public key issued by the at least one payment authoriser before transmitting the payment authorisation request to the at least one payment authoriser. 
     
     
         17 . The merchant transceiver device of  claim 11 , further comprising a contactless merchant interface module for establishing the first secure wireless data connection with the customer transceiver device. 
     
     
         18 . The merchant transceiver device of  claim 11 , wherein the at least one processor is further configured to determine whether more than one customer transceiver devices are present in the proximity of the merchant transceiver device before establishing the first secure wireless data connection, wherein when more than one customer transceiver devices are present in the proximity of the merchant transceiver device, the merchant transceiver device transmits to each of the customer transceiver devices a message requesting that only a single customer transceiver device be presented in the proximity of the merchant transceiver device. 
     
     
         19 . A customer transceiver device for performing a secure transaction, the customer transceiver device comprising at least one processor and memory comprising computer executable code to configure the at least one processor to:
 establish a first secure wireless data connection with a merchant transceiver device when the customer transceiver device is presented in proximity to the merchant transceiver device;   receive a first data package from the merchant transceiver device over the secure wireless data connection, the first data package comprising a unique merchant identifier and transaction request data;   determine a breakdown in the first secure wireless connection on removal of the customer transceiver device from the proximity of the merchant transceiver device;   responsive to determining the breakdown in the first secure wireless connection, store a transaction state in the memory, the transaction state comprising transaction related data created by the customer transceiver device or received by the customer transceiver device from the merchant transceiver device;   re-establish the first secure wireless connection when the customer transceiver device reappears in proximity of the merchant transceiver device;   responsive to re-establishing the first secure wireless connection, retrieve the stored transaction state; and   based on the stored transaction state, transmit to the merchant transceiver device a customer authorisation data package, wherein the transmitted customer authorisation data package is encrypted based on a customer transceiver device key and a transaction counter key, the customer transceiver device key and the transaction counter key being unique to the customer transceiver device and the transaction counter key being incremented after each transaction by the customer transceiver device.   
     
     
         20 . The customer transceiver device of  claim 19 , wherein the at least one processor is further configured to receive an indication of an outcome of a payment authorisation request from the merchant transceiver device.

Join the waitlist — get patent alerts

Track US2020286088A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.