IP Library Granted Patent US 12711497
Granted Patent B2
US 12711497 · App. 18/413,514 · Granted Aug 18, 2026

Method and system for contactless transactions without user credentials

Inventors: Abhinava Srivastava (Singapore, SG); Sapankumar K. Mandloi (Stamford, CT); Anthony Lopreiato (Scarsdale, NY)
Assignee: Mastercard International Incorporated
G06Q20/3829G06Q20/204G06Q20/3821G06Q20/385G06Q20/4014H04L9/0819H04L9/0861H04L9/14H04L63/0428H04L63/067H04L63/08H04W12/033H04W12/10G06Q20/321G06Q2220/00H04L63/126H04L2209/56H04L2463/062H04W12/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12711497
App. No.
18/413,514
Filed
Jan 16, 2024
Granted
Aug 18, 2026
Kind
B2
Art Unit
3699
USPC
705/71
Abstract

A method for generation of an application cryptogram for use in a payment transaction includes: storing, in a first memory, a single use key associated with a transaction account; electronically transmitting the single use key to a processing server; receiving an encrypted session key and a server encryption key from the processing server; executing a first query to store the encrypted session key in the first memory and a second query to store the server encryption key in a second memory; decrypting the encrypted session key using the server encryption key; generating an application cryptogram based on the decrypted session key; and electronically transmitting the generated application cryptogram for use in a payment transaction.

Claims (34)

1 . A method for provisioning of a session key, said method comprising:

receiving, by a processing server, from a computing device, a session key request including a single use key and an account identifier, wherein the single use key is a payment token that is associated with a transaction account;

generating, by the processing server, a session key based on the received single use key and an account identification number included in an account profile;

encrypting, by the processing server, the generated session key using a server encryption key;

transmitting, by the processing server, the encrypted session key and the server encryption key to the computing device; and

generating, by the computing device, an application cryptogram without requiring input of a personal identification number (PIN).

2 . The method of claim 1 , further comprising:

receiving, by the processing server, a transaction message related to a payment transaction, wherein the transaction message includes at least a first application cryptogram;

generating, by the processing server, a second application cryptogram based on the generated session key; and

verifying, by the processing server, equivalence of the first application cryptogram and the second application cryptogram.

3 . The method of claim 2 , further comprising:

transmitting, by the processing server, a result of the verification to a financial institution associated with the transaction account for use in authorization of the related payment transaction.

4 . The method of claim 1 , further comprising:

receiving, by the processing server, an integrity check value from the computing device; and

verifying, by the processing server, device integrity of the computing device based on the received integrity check value.

5 . The method of claim 4 , wherein verification of the device integrity is performed prior to transmission of the encrypted session key and server encryption key to the computing device.

6 . A system for provisioning of a session key, comprising:

a processing server; and

a computing device,

wherein the processing server includes

a receiving device configured to receive a single use key and an account identifier from a computing device, wherein the single use key is a payment token that is associated with a transaction account, and

a processing device configured to (i) generate a session key based on the received single use key and an account identification number included in an account profile, and (ii) encrypt the generated session key using a server encryption key, and

a transmitting device configured to transmit the encrypted session key and the server encryption key to the computing device, and

wherein the computing device is configured to generate an application cryptogram without requiring input of a personal identification number (PIN).

7 . The system of claim 6 , wherein

the receiving device of the processing server is further configured to receive a transaction message related to a payment transaction, wherein the transaction message includes at least a first application cryptogram and

the processing device of the processing server is further configured to

generate a second application cryptogram based on the generated session key, and

verify equivalence of the first application cryptogram and the second application cryptogram.

8 . The system of claim 7 , wherein the transmitting device of the processing server is further configured to transmit a result of the verification to a financial institution associated with the transaction account for use in authorization of the related payment transaction.

9 . The system of claim 6 , wherein

the receiving device of the processing server is further configured to receive an integrity check value from the computing device, and

the processing device of the processing server is configured to verify device integrity of the computing device based on the received integrity check value.

10 . The system of claim 9 , wherein verification of the device integrity is performed prior to transmission of the encrypted session key and server encryption key to the computing device.