Method and system for contactless transactions without user credentials
A method for generation of an application cryptogram for use in a payment transaction includes: storing, in a first memory, a single use key associated with a transaction account; electronically transmitting the single use key to a processing server; receiving an encrypted session key and a server encryption key from the processing server; executing a first query to store the encrypted session key in the first memory and a second query to store the server encryption key in a second memory; decrypting the encrypted session key using the server encryption key; generating an application cryptogram based on the decrypted session key; and electronically transmitting the generated application cryptogram for use in a payment transaction.
1 . A method for provisioning of a session key, said method comprising:
receiving, by a processing server, from a computing device, a session key request including a single use key and an account identifier, wherein the single use key is a payment token that is associated with a transaction account;
generating, by the processing server, a session key based on the received single use key and an account identification number included in an account profile;
encrypting, by the processing server, the generated session key using a server encryption key;
transmitting, by the processing server, the encrypted session key and the server encryption key to the computing device; and
generating, by the computing device, an application cryptogram without requiring input of a personal identification number (PIN).
2 . The method of claim 1 , further comprising:
receiving, by the processing server, a transaction message related to a payment transaction, wherein the transaction message includes at least a first application cryptogram;
generating, by the processing server, a second application cryptogram based on the generated session key; and
verifying, by the processing server, equivalence of the first application cryptogram and the second application cryptogram.
3 . The method of claim 2 , further comprising:
transmitting, by the processing server, a result of the verification to a financial institution associated with the transaction account for use in authorization of the related payment transaction.
4 . The method of claim 1 , further comprising:
receiving, by the processing server, an integrity check value from the computing device; and
verifying, by the processing server, device integrity of the computing device based on the received integrity check value.
5 . The method of claim 4 , wherein verification of the device integrity is performed prior to transmission of the encrypted session key and server encryption key to the computing device.
6 . A system for provisioning of a session key, comprising:
a processing server; and
a computing device,
wherein the processing server includes
a receiving device configured to receive a single use key and an account identifier from a computing device, wherein the single use key is a payment token that is associated with a transaction account, and
a processing device configured to (i) generate a session key based on the received single use key and an account identification number included in an account profile, and (ii) encrypt the generated session key using a server encryption key, and
a transmitting device configured to transmit the encrypted session key and the server encryption key to the computing device, and
wherein the computing device is configured to generate an application cryptogram without requiring input of a personal identification number (PIN).
7 . The system of claim 6 , wherein
the receiving device of the processing server is further configured to receive a transaction message related to a payment transaction, wherein the transaction message includes at least a first application cryptogram and
the processing device of the processing server is further configured to
generate a second application cryptogram based on the generated session key, and
verify equivalence of the first application cryptogram and the second application cryptogram.
8 . The system of claim 7 , wherein the transmitting device of the processing server is further configured to transmit a result of the verification to a financial institution associated with the transaction account for use in authorization of the related payment transaction.
9 . The system of claim 6 , wherein
the receiving device of the processing server is further configured to receive an integrity check value from the computing device, and
the processing device of the processing server is configured to verify device integrity of the computing device based on the received integrity check value.
10 . The system of claim 9 , wherein verification of the device integrity is performed prior to transmission of the encrypted session key and server encryption key to the computing device.