US2020336315A1PendingUtilityA1
Validation cryptogram for transaction
Est. expiryMar 15, 2036(~9.6 yrs left)· nominal 20-yr term from priority
H04L 2463/102H04L 2209/56H04L 63/12H04L 63/0428H04L 9/3247H04L 9/14H04L 9/30H04L 9/0618
54
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method for validating an interaction is disclosed. A first interaction cryptogram can be generated by a first device using information about a first party to the interaction and a second party to the interaction. A second interaction cryptogram can be generated by a second device also using information about the first party to the interaction and the second party to the interaction. Verifying each cryptogram can validate that the interaction details have not been changed, and that both the first party and second party legitimately authorized the interaction.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method comprising:
receiving, by a server computer from a sender device, a peer-to-peer interaction request including interaction details and one or more cryptograms, the interaction details including receiver information for a receiver device, wherein the receiver information was not encrypted with a first key; recreating, by the server computer, a first cryptogram from the one or more cryptograms, wherein the first cryptogram is recreated by using the receiver information, from the interaction details received from the receiver device, that was not encrypted with the first key, a cryptographic key associated with the sender device, and an algorithm used at the sender device to create the first cryptogram; determining, by the server computer, whether the recreated first cryptogram, that was recreated using the receiver information from the interaction details received from the receiver device, matches the first cryptogram of the one or more cryptograms received from the sender device; verifying, by the server computer, the first cryptogram; and coordinating, by the server computer, a peer-to-peer transfer from a sender account to a receiver account.
22 . The method according to claim 21 , wherein the verifying, by the server computer, the first cryptogram comprises verifying that the recreated first cryptogram, that was recreated using the receiver information from the interaction details received from the receiver device, matches the first cryptogram of the received one or more cryptograms.
23 . The method according to claim 21 , further comprising, before receiving from the sender device, the peer-to-peer interaction request:
providing, by the server computer, the first key to the sender device, wherein the first key is a first symmetric key; storing, by the server computer, a copy of the first key; providing, by the server computer, a second key to the receiver device, wherein the second key is a second symmetric key; storing, by the server computer, a copy of the second key; receiving, by the server computer, a third key from a coordination computer, wherein the third key is a public key that corresponding to a private key of the coordination computer; and storing, by the server computer, a copy of the third key.
24 . The method according to claim 23 , further comprising, before receiving from the sender device, the peer-to-peer interaction request:
providing, by the server computer, a first token with the first key; and providing, by the server computer, a second token with the second key.
25 . The method according to claim 24 , further comprising after coordinating the peer-to-peer transfer from the sender account to the receiver account, de-tokenizing the first token and the second token.
26 . The method of claim 23 , wherein the interaction details further include sender information, wherein a second cryptogram is generated using the sender information, and wherein the method further comprises verifying, by the server computer, the second cryptogram.
27 . The method of claim 26 , wherein the first cryptogram was further generated using the sender information, and wherein the second cryptogram was further generated using the receiver information, such that the first cryptogram and the second cryptogram were both generated using both the sender information and the receiver information.
28 . The method of claim 27 , the method further comprising:
determining, by the server computer, the first key associated with the sender device, wherein the first cryptogram is verified using the first key; determining, by the server computer, the second key associated with the receiver device, wherein the second cryptogram is verified using the second key; determining, by the server computer, the third key associated with the coordination computer, wherein the peer-to-peer interaction request includes a digital signature generated using the interaction details by the coordination computer; and verifying, by the server computer, the digital signature using the third key.
29 . The method according to claim 21 , further comprising, before coordinating the peer-to-peer transfer from the sender account to the receiver account, authorizing the peer-to-peer transfer from the sender account to the receiver account based on the verified first cryptogram,
wherein the authorizing the peer-to-peer transfer comprises analyzing an interaction velocity.
30 . A server computer comprising:
a processor; and a computer readable medium, the computer readable medium comprising code, executable by the processor, for implementing a method comprising: receiving, by the server computer from a sender device, a peer-to-peer interaction request including interaction details and one or more cryptograms, the interaction details including receiver information for a receiver device, wherein the receiver information was not encrypted with a first key; recreating, by the server computer, a first cryptogram from the one or more cryptograms, wherein the first cryptogram is recreated by using the receiver information, from the interaction details received from the receiver device, that was not encrypted with the first key, a cryptographic key associated with the sender device, and an algorithm used at the sender device to create the first cryptogram; determining, by the server computer, whether the recreated first cryptogram, that was recreated using the receiver information from the interaction details received from the receiver device, matches the first cryptogram of the one or more cryptograms received from the sender device; verifying, by the server computer, the first cryptogram; and coordinating, by the server computer, a peer-to-peer transfer from a sender account to a receiver account.
31 . The server computer according to claim 30 , wherein the verifying, by the server computer, the first cryptogram comprises verifying that the recreated first cryptogram, that was recreated using the receiver information from the interaction details received from the receiver device, matches the first cryptogram of the received one or more cryptograms.
32 . The server computer according to claim 30 , further comprising, before receiving from the sender device, the peer-to-peer interaction request:
providing, by the server computer, the first key to the sender device, wherein the first key is a first symmetric key; storing, by the server computer, a copy of the first key; providing, by the server computer, a second key to the receiver device, wherein the second key is a second symmetric key; storing, by the server computer, a copy of the second key; receiving, by the server computer, a third key from a coordination computer, wherein the third key is a public key that corresponding to a private key of the coordination computer; and storing, by the server computer, a copy of the third key.
33 . The server computer according to claim 32 , further comprising, before receiving from the sender device, the peer-to-peer interaction request:
providing, by the server computer, a first token with the first key; and providing, by the server computer, a second token with the second key.
34 . The server computer according to claim 33 , further comprising after coordinating the peer-to-peer transfer from the sender account to the receiver account, de-tokenizing the first token and the second token.
35 . The server computer according to claim 32 , wherein the interaction details further include sender information, wherein a second cryptogram is generated using the sender information, and wherein the method further comprises verifying, by the server computer, the second cryptogram.
36 . The server computer according to claim 35 , the method further comprising:
determining, by the server computer, the first key associated with the sender device, wherein the first cryptogram is verified using the first key; determining, by the server computer, the second key associated with the receiver device, wherein the second cryptogram is verified using the second key; determining, by the server computer, the third key associated with the coordination computer, wherein the peer-to-peer interaction request includes a digital signature generated using the interaction details by the coordination computer; and verifying, by the server computer, the digital signature using the third key.
37 . A method comprising:
receiving, by a server computer from a sender device, a peer-to-peer interaction request including interaction details and one or more cryptograms, the interaction details including receiver information for a receiver device, wherein the receiver information was not encrypted with a first key; decrypting, by the server computer, a first cryptogram using the first key; determining, by the server computer, the interaction details from the decrypted first cryptogram; determining, by the server computer, whether the interaction details from the decrypted first cryptogram matches the interaction details received from the receiver device; verifying, by the server computer, that the interaction details from the decrypted first cryptogram matches the interaction details received from the receiver device; and coordinating, by the server computer, a peer-to-peer transfer from a sender account to a receiver account.
38 . The method according to claim 37 , wherein the decrypting, by the server computer, the first cryptogram using the first key comprising reversing a cryptographic algorithm that generated the first cryptogram.
39 . The method according to claim 37 , wherein the interaction details comprise transaction details.
40 . The method according to claim 39 , wherein the transaction details comprise a value to be transferred and sender account information.Join the waitlist — get patent alerts
Track US2020336315A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.