Systems and methods for creating fingerprints of encryption devices
Abstract
Systems and methods for creating fingerprints for devices are described herein. In various embodiments, the system includes a device management system operatively coupled to a merchant system. According to particular embodiments, the device management system: 1) receives a first payload correspond to a device from the merchant system, the first payload including data in a particular format; 2) creates a fingerprint for the device by parsing the first payload and creating a record of a section format for each of one or more distinct sections of the particular format; and 3) comparing a format of each subsequent payload that corresponds to the device to the fingerprint for the device to determine whether the device has been compromised.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 - 20 . (canceled)
21 . A computer system for managing encryption device status changes comprising:
a P2PE management system comprising at least one processor and operatively connected to an encryption device, the at least one processor configured for:
changing a state of the encryption device based upon transactional information received from the encryption device, wherein changing the state of the encryption device based upon transaction information comprises:
receiving a transaction payload from an encryption device, the transaction payload comprising transaction information and non-transaction information;
determining whether the transaction information is unencrypted; and
in response to determining that the transaction information is unencrypted, disabling the encryption device by changing a state of the encryption device to a tampered state.
22 . The computer system of claim 21 , wherein the at least one processor is further configured for changing the state of the encryption device based on input from an operator.
23 . The computer system of claim 22 , wherein the at least one processor is further configured for changing the state of the encryption device based upon receiving an indication from a first operator that the encryption device is in transit from a manufacturer to a key injection facility.
24 . The computer system of claim 22 , wherein the at least one processor is further configured for changing the state of the encryption device to a stored state based upon receiving an indication from a second operator that the encryption device is stored at a merchant.
25 . The computer system of claim 24 , wherein the at least one processor is further configured for changing the state of the encryption device to a deployed state based upon receiving an indication from a third operator that the encryption device is deployed for use by the merchant.
26 . The computer system of claim 25 , wherein changing the state of the encryption device based upon transaction information further comprises:
receiving a first transaction payload from the encryption device, the first transaction payload being a first payload received from the encryption device, the first transaction payload comprising transaction information and non-transaction information; upon receiving the first transaction payload from the encryption device, changing the state of the encryption device from the deployed state to an active state.
27 . The computer system of claim 26 , wherein the at least one processor configured for facilitating decryption of the transaction information when the state of the at least one encryption device is in the active state.
28 . The computer system of claim 27 , wherein changing the state of the encryption device based upon transaction information further comprises, in response to determining that the transaction information is unencrypted, disabling facilitating decryption of the transaction information of the encryption device based on changing the state of the encryption device to the tampered state from the active state.
29 . The computer system of claim 28 , wherein:
the first transaction payload comprises transaction information and non-transaction information in a particular format; the at least one processor configured for saving an indication of the particular format; the transaction payload comprises transaction information and non-transaction information in a second particular format; and changing the state of the encryption device based upon transaction information further comprises, in response to determining that the second particular format does not match the indication of the particular format, disabling facilitating decryption of the transaction information of the encryption device and changing the state of the encryption device to the tampered state from the active state.
30 . A computer-implemented method for managing encryption device status changes, the method comprising the steps of:
providing a P2PE management system comprising at least one processor and operatively connected to an encryption device; changing, by the at least one processor, a state of the encryption device based upon transactional information received from the encryption device, wherein changing the state of the encryption device based upon transaction information comprises:
receiving a transaction payload from an encryption device, the transaction payload comprising transaction information and non-transaction information;
determining whether the transaction information is unencrypted; and
in response to determining that the transaction information is unencrypted, disabling the encryption device by changing a state of the encryption device to a tampered state.
31 . The computer-implemented method of claim 30 , wherein the method further comprises the step of changing, by the at least one processor, the state of the encryption device based on input from an operator.
32 . The computer-implemented method of claim 31 , wherein the at least one processor is further configured for changing the state of the encryption device based upon receiving an indication from a first operator that the encryption device is in transit from a manufacturer to a key injection facility.
33 . The computer-implemented method of claim 31 , wherein the method further comprises the step of changing, by the at least one processor, the state of the encryption device to a stored state based upon receiving an indication from a second operator that the encryption device is stored at a merchant.
34 . The computer-implemented method of claim 33 , wherein the method further comprises the step of changing, by the at least one processor, the state of the encryption device to a deployed state based upon receiving an indication from a third operator that the encryption device is deployed for use by the merchant.
35 . The computer-implemented method of claim 34 , wherein changing the state of the encryption device based upon transaction information further comprises:
receiving a first transaction payload from the encryption device, the first transaction payload being a first payload received from the encryption device, the first transaction payload comprising transaction information and non-transaction information; upon receiving the first transaction payload from the encryption device, changing the state of the encryption device from the deployed state to an active state.
36 . The computer-implemented method of claim 35 , wherein the method further comprises the step of facilitating decryption of the transaction information when the state of the at least one encryption device is in the active state.
37 . The computer-implemented method of claim 36 , wherein changing the state of the encryption device based upon transaction information further comprises, in response to determining that the transaction information is unencrypted, disabling facilitating decryption of the transaction information of the encryption device based on changing the state of the encryption device to the tampered state from the active state.
38 . The computer-implemented method of claim 37 , wherein:
the first transaction payload comprises transaction information and non-transaction information in a particular format; the method further comprises the step of saving an indication of the particular format; the transaction payload comprises transaction information and non-transaction information in a second particular format; and changing the state of the encryption device based upon transaction information further comprises, in response to determining that the second particular format does not match the indication of the particular format, disabling facilitating decryption of the transaction information of the encryption device and changing the state of the encryption device to the tampered state from the active state.
39 . A computer system for managing encryption device status changes comprising:
a P2PE management system comprising at least one processor and operatively connected to an encryption device, the at least one processor configured for:
changing the state of the encryption device based on input from an operator;
changing a state of the encryption device based upon transactional information received from the encryption device, wherein changing the state of the encryption device based upon transaction information comprises:
receiving a first transaction payload from an encryption device, the first transaction payload comprising first transaction information and first non-transaction information;
upon receiving the first transaction payload from the encryption device, changing the state of the encryption device from the deployed state to an active state and facilitating decryption of the first transaction information;
receiving a second transaction payload from the encryption device, the second transaction payload comprising second transaction information and second non-transaction information;
determining whether the second transaction information is unencrypted; and
in response to determining that the second transaction information is unencrypted, disabling the encryption device by changing the state of the encryption device from the active state to a tampered state.Join the waitlist — get patent alerts
Track US2021185020A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.