IP Library Granted Patent US 7,558,951
Granted Patent B2
US 7,558,951 · App. 11/001,973 · Granted Jul 7, 2009

System and method for secure transactions over a network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,558,951
App. No.
11/001,973
Granted
Jul 7, 2009
Kind
B2
Abstract

The public Internet is the world's largest system of inter-networked computers. Adequate security means for protecting sensitive data communicated over the Internet is not, however, provided. The present invention, therefore, provides a system and method for performing secure transactions over an insecure packet-switched communication network. This is achieved by interconnecting a number of master nodes over the insecure communication network. The master nodes are capable of transmitting encrypted data packets over the insecure network via pseudo-random communication paths. The master nodes are further capable of returning to any state in a secure transaction in the event of a network failure. The master nodes are also capable of using new keys to encrypt each data packet.

Claims (69)

1. A method of providing reliable transactions over a communication network comprising the steps of:

determining a need in a node in a transaction network to update a transmission path capacity indicator between the node and a designation node in the transaction network;

formulating an application layer transaction request message in the node as a probe packet for the purposes of updating the transmission path capacity indicator;

selecting one of a plurality of output ports on the node for transmitting the probe packet to the destination node;

transmitting the probe packet to an adjacent node;

receiving an application layer transaction response message from the adjacent node correlated with the probe packet using a message identifier number;

determining a time duration in the node based on a first time associated with the transmission of the probe packet and a second time associated with the receipt of the application layer transaction response message; and

updating the transmission path capacity indicator based on the time duration.

2. A method for providing reliable transactions over a communication network comprising the step of:

receiving a node in a transaction network an application layer transaction response message serving as a probe response from an adjacent node;

determining an associated probe request is enqued in a memory of the node;

determining that the node receiving the probe response generated the associated probe request;

updating a transmission path capacity indicator based in part on the probe response; and

de-enquing the probe request in the memory of the node.

3. A method for providing secure transactions over a network node comprising the steps of:

receiving an encrypted data packet comprising an application layer message at an input port on a first network node from a second network node, the encrypted data packet comprising a checksum, message identifier, and data;

determining that a message-received timer has not expired;

validating the encrypted data packet by processing the checksum and the data;

determining the message identifier is a currently active message identifier;

retrieving a first current encryption key from memory;

using the current first encryption key and the data packet to derive a first new encryption key;

decrypting the data using the first new encryption key to produce a second data;

replacing the first current encryption key with the first new encryption key;

selecting an output port based on a criteria;

formulating a second encrypted data packet using the second data and the first new encryption key;

transmitting the second encrypted data packet on the output port; and

sending a positive acknowledgement message to the second network node.

4. The method of claim 1 wherein the time duration is determined by calculating a time duration based on a first timestamp indicator stored in a memory of the node associated with the probe packet and a second timestamp indicator stored in the memory associated with the application layer transaction response message.

5. The method of claim 1 further comprising the steps of:

receiving an application layer transaction request at the node;

selecting an output port based on a transmission path capacity indicator; and

transmitting the application layer transaction request on the output port.

6. The method of claim 1 wherein determining a need in a node in a transaction network to update the transmission path capacity indicator is based on the expiry of a timer.

7. The method of claim 1 wherein the application layer transaction request message is an electronic transaction request message.

8. The method of claim 1 wherein the selecting of an output port based on a criteria comprises:

maintaining a plurality of path capacity indicators wherein each path capacity indicator is associated with an output port;

receiving a second application layer transaction message at an input port;

selecting the output port based in part on its associated path capacity indicator; and

transmitting the second application layer transaction on the output port.

9. The method of claim 8 wherein each of the output port identifiers is associated with a destination node.

10. The method of claim 3 wherein the positive acknowledgement message includes the message identifier.

11. The method of claim 3 further comprising the steps of:

deriving a second new encryption key from a second current encryption key;

replacing the second current encryption key with the second new encryption key;

encrypting the payload data using the second new encryption key; and

appending a second checksum and a second message identifier to the payload data to form the second message.

12. The method of claim 3 wherein the current key is selected from one from a set of restart keys.

13. The method of claim 3 further comprising the step of:

determining the timer associated with the output port has expired.

14. A method for providing secure transactions at a node in a communications network comprising:

receiving an application layer message from a second network node on an input port on the network node wherein the message comprises a message identifier, payload and checksum;

determining the integrity of the message by processing the checksum;

determining a current decryption key is defined;

deriving a new decryption key using the current decryption key;

attempting to decrypt the message;

determining the message has not been successfully decryption;

selecting one from a plurality of re-start keys as the new decryption key;

attempting to decrypt the message;

determining the message has not been successfully decrypted;

using one of the plurality of re-start keys to encrypt a negative response message; and

sending the negative response message to the second network node.

15. The method of claim 14 wherein the negative response message includes the message identifier.

16. A method for providing reliable transactions over a communications network comprising the steps of:

receiving an application layer transaction request message functioning as a probe request message in a node of a transaction network;

determining that a corresponding application layer transaction response message functioning as a probe response message is enqued in a memory of the node;

determining that the node did not generate the corresponding probe request message;

de-enquing the probe request message from the memory of the node;

transmitting the probe response message to a second node from which the node receiving the probe request; and

enquing the probe response message in the memory of the node.

Assignments (14)
CORRECTIVE ASSIGNMENT TO CORRECT THE EXECUTION DATE AND EFFECTIVE DATE PREVIOUSLY RECORDED AT REEL: 051554 FRAME: 0557. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 23, 2020
From: FIRST DATA MERCHANT SERVICES CORPORATION
To: FIRST DATA MERCHANT SERVICES LLC
Reel/Frame 051691/0049 →
MERGER Recorded Jan 9, 2020
From: FIRST DATA MERCHANT SERVICES CORPORATION
To: FIRST DATA MERCHANT SERVICES LLC
Reel/Frame 051554/0557 →
MERGER Recorded Jan 7, 2020
From: DW HOLDINGS, INC.
To: FIRST DATA MERCHANT SERVICES CORPORATION
Reel/Frame 051442/0271 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Aug 19, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: FIRST DATA CORPORATION; DW HOLDINGS, INC.; FIRST DATA RESOURCES, INC. (K/N/A FIRST DATA RESOURCES, LLC); FUNDSXPRESS FINANCIAL NETWORKS, INC.; INTELLIGENT RESULTS, INC. (K/N/A FIRST DATA SOLUTIONS, INC.); LINKPOINT INTERNATIONAL, INC.; MONEY NETWORK FINANCIAL, LLC; SIZE TECHNOLOGIES, INC.; TASQ TECHNOLOGY, INC.; TELECHECK INTERNATIONAL, INC.
Reel/Frame 050090/0060 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Aug 19, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: FIRST DATA CORPORATION; DW HOLDINGS, INC.; FIRST DATA RESOURCES, LLC; FUNDSXPRESS FINANCIAL NETWORK, INC.; FIRST DATA SOLUTIONS, INC.; LINKPOINT INTERNATIONAL, INC.; MONEY NETWORK FINANCIAL, LLC; SIZE TECHNOLOGIES, INC.; TASQ TECHNOLOGY, INC.; TELECHECK INTERNATIONAL, INC.
Reel/Frame 050091/0474 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Aug 19, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: FIRST DATA CORPORATION
Reel/Frame 050094/0455 →
RELEASE OF SECURITY INTEREST Recorded Jul 30, 2019
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: CARDSERVICE INTERNATIONAL, INC.; DW HOLDINGS INC.; FIRST DATA CORPORATION; FIRST DATA RESOURCES, LLC; FUNDSXPRESS, INC.; INTELLIGENT RESULTS, INC.; LINKPOINT INTERNATIONAL, INC.; SIZE TECHNOLOGIES, INC.; TASQ TECHNOLOGY, INC.; TELECHECK INTERNATIONAL, INC.; TELECHECK SERVICES, INC.
Reel/Frame 049902/0919 →
SECURITY AGREEMENT Recorded Jan 31, 2011
From: DW HOLDINGS, INC.; FIRST DATA RESOURCES, LLC; FUNDSXPRESS FINANCIAL NETWORKS, INC.; FIRST DATA SOLUTIONS, INC.; LINKPOINT INTERNATIONAL, INC.; MONEY NETWORK FINANCIAL, LLC; SIZE TECHNOLOGIES, INC.; TASQ TECHNOLOGY, INC.; TELECHECK INTERNATIONAL, INC
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 025719/0590 →
SECURITY AGREEMENT Recorded Nov 17, 2010
From: DW HOLDINGS, INC.; FIRST DATA RESOURCES, INC. (K/N/A FIRST DATA RESOURCES, LLC); FUNDSXPRESS FINANCIAL NETWORKS, INC.; INTELLIGENT RESULTS, INC. (K/N/A FIRST DATA SOLUTIONS, INC.); LINKPOINT INTERNATIONAL, INC.; MONEY NETWORK FINANCIAL, LLC; SIZE TECHNOLOGIES, INC.; TASQ TECHNOLOGY, INC.; TELECHECK INTERNATIONAL, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 025368/0183 →
SECURITY AGREEMENT Recorded Oct 31, 2007
From: FIRST DATA CORPORATION; CARDSERVICE INTERNATIONAL, INC.; FUNDSXPRESS, INC.; LINKPOINT INTERNATIONAL, INC.; TASQ TECHNOLOGY, INC.; TELECHECK SERVICES, INC.; DW HOLDINGS, INC.; FIRST DATA RESOURCES, INC.; INTELLIGENT RESULTS, INC.; SIZE TECHNOLOGIES, INC.; TELECHECK INTERNATIONAL, INC.
To: CREDIT SUISSE, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 020045/0165 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2007
From: DATAWIRE COMMUNICATION NETWORKS, INC.
To: DW HOLDINGS, INC.
Reel/Frame 019100/0138 →
RELEASE OF SECURITY INTEREST Recorded Mar 19, 2007
From: HORIZON TECHNOLOGY FUNDING COMPANY LLC
To: DATAWIRE COMMUNICATION NETWORKS INC.
Reel/Frame 019055/0204 →
SECURITY INTEREST Recorded Aug 28, 2006
From: DATAWIRE COMMUNICATION NETWORKS INC.
To: HORIZON TECHNOLOGY FUNDING COMPANY LLC
Reel/Frame 018239/0558 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 2, 2004
From: MUNSHI, ANEES
To: DATAWIRE COMMUNICATION NETWORKS, INC.
Reel/Frame 016055/0720 →