IP Library › Granted Patent US 10,134,034
Granted Patent B2
US 10,134,034 · App. 13/912,120 · Granted Nov 20, 2018

Terminal data encryption

Inventors: Ayman Hammad (Pleasanton, CA); Patrick Faith (Pleasanton, CA)
Assignee: Visa U.S.A. Inc.
G06Q20/3829G06Q20/085G06Q20/20G06Q20/367G06Q20/3672G06Q20/3674G06Q20/382G06Q20/385G06Q20/3821G06Q20/40G06Q20/401G06Q30/06G06Q40/00H04L9/3271G06Q20/105G06Q20/204G06Q2220/00H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,134,034
App. No.
13/912,120
Granted
Nov 20, 2018
Kind
B2
Abstract

A method is disclosed. The method includes generating an initial key after interacting with an access device, storing the initial key at a key storage location, altering the initial key with a public key to form an altered key, and sending the altered key to a server computer along with an identifier for the access device. The altered key is changed to the initial key at the server computer and is stored with the identifier in a database in operative communication with the server computer. The initial keys that are stored at the key storage location and in the database are used to alter and restore transaction data associated with multiple financial transactions that are conducted using the access device.

Claims (22)

1. A method comprising:

receiving, with one or more servers of a payment processing network, an altered key and an identifier of a point of sale device, the altered key having first cryptographic properties resulting from being formed at least in part by an alteration of an initial key with a public key, the first cryptographic properties including an ability to obtain the initial key by further altering the altered key, the initial key having second cryptographic properties resulting from being generated based at least in part on an initialization interaction between the point of sale device and a first portable consumer device, the second cryptographic properties including the initial key being a terminal-specific symmetric key that is unavailable for interception prior to the initialization interaction, wherein the receiving of the altered key with the one or more servers of the payment processing network inhibits unauthorized interception of the unaltered initial key;

further altering, with the one or more servers, the altered key to obtain the initial key, the further altering of the altered key enabled at least in part by the altered key having been formed at least in part by the alteration of the initial key with the public key;

sending, with the one or more servers, the initial key to a key storage location;

associating the initial key that is stored at the key storage location with the received identifier of the point of sale device;

receiving, with the one or more servers, altered transaction data associated with a plurality of financial transactions that are conducted using the point of sale device;

determining, with the one or more servers, that the altered transaction data was altered with the initial key that is stored at the key storage location based at least in part on the associated identifier of the point of sale device; and

further altering, with the one or more servers, the altered transaction data using the initial key that is stored at the key storage location, the further altering of the altered transaction data enabled at least in part by the initial key having been generated based at least in part on the initialization interaction between the point of sale device and the first portable consumer device.

2. The method of claim 1 wherein the identifier is a terminal ID.

3. The method of claim 1 wherein the altered key is an encrypted symmetric key that was encrypted using a public key.

4. The method of claim 1 wherein the first portable consumer device is a payment card.

5. The method of claim 1 wherein the initial key is a symmetric key and wherein the key storage location is in the point of sale device.

6. The method of claim 1 further comprising:

receiving, with the one or more servers, an altered identifier based at least in part on the identifier,

wherein receiving the altered key and the altered identifier data is part of a special initialization transaction that is different from a transaction associated with a purchase at least in that the initialization transaction is initial with respect to later transactions associated with purchases.

7. The method of claim 1 wherein the initialization interaction comprises using the first portable consumer device to interact with the point of sale device in a financial transaction, and wherein altering comprises encrypting.

8. The method of claim 7 wherein the encrypting comprises performing an encryption process, the point of sale device being capable of performing the encryption process.

9. The method of claim 8 wherein the encryption process comprises elliptical curve cryptography.

10. The method of claim 1 wherein a host computer is coupled to the point of sale device.

11. The method of claim 10 wherein the public key is stored in the host computer.

12. The method of claim 10 wherein the host computer generates the initial key.

13. The method of claim 10 wherein the host computer performs the altering.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2013
From: HAMMAD, AYMAN; FAITH, PATRICK
To: VISA U.S.A. INC.
Reel/Frame 030563/0413 →
Continuity (5)
Continuation 11764351 · Jun 18, 2007
Provisional Application 60884089 · Jan 9, 2007
Provisional Application 60815430 · Jun 20, 2006
Provisional Application 60815059 · Jun 19, 2006
Related Publication 20130275310A1 · Oct 17, 2013
Cited By (1)
US 12,591,880