IP Library Patent Application 14591171
Patent Application
App. No. 14/591,171

SYSTEMS AND METHODS FOR FACILITATING DECRYPTION OF PAYLOADS RECEIVED FROM ENCRYPTION DEVICES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/591,171
Abstract

Systems and methods for facilitating decryption of encrypted payloads are described herein. In various embodiments, the system includes an encryption device operatively connected to a device management system. According to particular embodiments, the device management system receives payloads from the encryption device and facilitates decryption of the encryption device payloads based at least in part on a serial number associated with the encryption device included in the encryption device payload.

Claims (116)

1 . A point to point encryption management system configured to receive information from a plurality of point of interaction devices, the point to point encryption management system comprising a) a database for storing device information and b) at least one processor operatively coupled to the database, the at least one processor configured for:

receiving a payload originating from a point of interaction device, the payload including encrypted payment information and a device identifier;

parsing the payload to extract the device identifier;

retrieving an identifier table from the database, the identifier table comprising one or more device identifiers received by the point to point encryption management system;

comparing the device identifier to the identifier table to determine whether the device identifier is included in the identifier table;

upon determining that the device identifier is included in the identifier table, facilitating decryption of the encrypted payment information.

2 . The computer system of claim 1 , wherein the at least one processor is further configured for: retrieving, from memory, a digital fingerprint associated with a record of the point of interaction device.

3 . The computer system of claim 2 , wherein the digital fingerprint is created by the point to point encryption management system for the point of interaction device based on the format of one or more payloads that originated from the point of interaction device.

4 . The computer system of claim 3 , wherein the at least one processor is further configured for:

comparing the payload to the digital fingerprint to determine whether the point of interaction device has been compromised; and

upon determining that the point of interaction device has not been compromised, facilitating decryption of the encrypted payment information.

5 . The computer system of claim 4 , wherein the device identifier comprises a device serial number.

6 . A point to point encryption management system configured to receive information from a plurality of point of interaction devices, the point to point encryption management system comprising a) a database for storing device information and b) at least one processor operatively coupled to the database, the at least one processor configured for:

receiving a payload originating from a point of interaction device, the payload including encrypted data and a device serial number;

parsing the payload to extract the device serial number;

retrieving a serial number table from the database, the serial number table comprising one or more serial numbers received by the point to point encryption management system;

comparing the device serial number to the serial number table to determine whether the device serial number is included in the serial number table;

upon determining that the device serial number is included in the table, retrieving, from memory, a fingerprint associated with a record of the point of interaction device, wherein the fingerprint is an identifier created by the point to point encryption management system for the point of interaction device based on the format of one or more payloads that originated from the point of interaction device;

comparing the payload to the fingerprint to determine whether the point of interaction device has been compromised; and

upon determining that the point of interaction device has not been compromised, facilitating decryption of the encrypted payment card information.

7 . The computer system of claim 6 , wherein receiving the payload originating from the point to point encryption device comprises receiving the payload from a merchant computer system.

8 . The computer system of claim 7 , wherein receiving the payload originating from the point to point encryption device comprises receiving the payload from a third party payment processing system.

9 . The computer system of claim 6 , wherein, upon determining that the device serial number is included in the table, retrieving a state associated with the point of interaction device.

10 . The computer system of claim 9 , wherein the at least one processor is further configured for:

comparing the state associated with the point of interaction device with a list of decryptable states in a table; and

based on determining that the state associated with the point of interaction device is a decryptable state, facilitating decryption of the encrypted payment card information.

11 . The computer system of claim 6 , wherein:

the computer system further comprises an hardware security module; and

facilitating decryption of the encrypted data comprises transmitting the encrypted data to the hardware security module for decryption.

12 . A computer-implemented method for decrypting encrypted data, the computer-implemented method comprising:

providing at least one encryption device comprising at least one processor configured to transmit encrypted data and a device serial number, and

providing an encryption management system configured to receive information from the encryption device and at least one computer terminal located at a key injection facility, the encryption management system comprising a) a database for storing device information and b) at least one processor operatively coupled to the database, the at least one processor configured for:

receiving an initial device serial number from the at least one terminal located at the key injection facility;

writing the initial device serial number to a table in memory and storing the table in a database;

receiving a payload at least partially originating from the encryption device, the payload including encrypted data and the device serial number;

parsing the payload to extract the device serial number;

retrieving the table from the database;

comparing the device serial number to the initial device serial number to determine whether the device serial number is included in the table;

upon determining that the device serial number and the initial device serial number are the same serial number, facilitating decryption of the encrypted data.

13 . A computer system for point to point encryption of payment transactions, the computer system comprising:

at least one point of interaction device comprising a) one or more magnetic read heads for reading consumer payment cards and b) at least one processor configured to transmit consumer payment card information and a device serial number associated with the at least one point of interaction device;

a hardware security module configured for decryption of payment card information; and

a point to point encryption management system configured to receive information from the point of interaction device and at least one computer terminal located at a key injection facility, the point to point encryption management system comprising a) a database for storing device information and b) at least one processor operatively coupled to the database, the at least one processor configured for:

receiving an initial device serial number from the at least one computer terminal located at the key injection facility;

writing the initial device serial number to a table in memory and storing the table in the database;

receiving a first payload originating from the point of interaction device, the first payload including first encrypted payment card information and the device serial number;

parsing the payload to extract the device serial number;

retrieving the table from the database;

comparing the device serial number to the initial device serial number to determine whether the device serial number is included in the table;

upon determining that the device serial number and the initial device serial number are the same serial number:

facilitating decryption of the payment card information; and

creating a fingerprint for the point of interaction device based on the format of the first payload and storing the payload identifier in memory;

receiving a second payload originating from the point of interaction device including encrypted second payment card information and the device serial number;

parsing the received second payload to extract the device serial number;

retrieving the table from the database;

comparing the device serial number to the initial device serial number to determine whether the device serial number is included in the table;

upon determining that the device serial number and the initial device serial number are the same serial number, retrieving the fingerprint;

comparing the second payload to the fingerprint to determine whether the point of interaction device has been compromised; and

upon determining that the point of interaction device has not been compromised, transmitting the second payment information to the hardware security module for decryption.

14 . The computer system of claim 13 , wherein receiving the first payload originating from the point to point encryption device comprises receiving the payload from a merchant computer system.

15 . The computer system of claim 13 , wherein receiving the first payload originating from the point to point encryption device comprises receiving the payload from a third party payment processing system.

16 . A computer system decrypting payment transactions, the computer system comprising:

at least one point of interaction device comprising one or more processors configured to transmit consumer payment card information and a device serial number associated with the at least one point of interaction device; and

a point to point encryption management system configured to receive information from the point of interaction device and at least one computer terminal located at a key injection facility, the point to point encryption management system comprising a) a database for storing device information and b) at least one processor operatively coupled to the database, the at least one processor configured for:

receiving an initial device serial number from the at least one computer terminal located at the key injection facility;

writing the initial device serial number to a table in memory and storing the table in the database;

receiving a payload at least partially originating from the point of interaction device, the payload including encrypted payment card information and the device serial number;

parsing the payload to extract the device serial number;

retrieving the table from the database;

comparing the device serial number to the initial device serial number to determine whether the device serial number is included in the table;

upon determining that the device serial number and the initial device serial number are the same serial number, facilitating decryption of the payment card information.

17 . The computer system of claim 16 , wherein receiving the payload at least partially originating from the point to point encryption device comprises receiving the payload from a merchant computer system.

18 . The computer system of claim 16 , wherein receiving the payload at least partially originating from the point to point encryption device comprises receiving the payload from a third party payment processing system.

19 . The computer system of claim 16 , wherein the at least one processor is further configured for, upon determining that the device serial number and the initial device serial number are the same serial number, creating a payload identifier for the point of interaction device and storing the payload identifier for the point of interaction device in memory.

20 . The computer system of claim 19 , wherein:

the received payload is a first payload received that originated from the point of interaction device; and

the at least one processor is further configured for:

receiving a second payload originating from the point of interaction device including encrypted second payment card information and a second device serial number;

parsing the received second payload to extract the second device serial number;

retrieving the table from the database;

comparing the second device serial number to the initial device serial number to determine whether the second device serial number is included in the table;

upon determining that the second device serial number and the initial device serial number are the same serial number, retrieving the payload identifier;

comparing the second payload to the payload identifier to determine whether the point of interaction device has been compromised; and

upon determining that the point of interaction device has not been compromised, facilitating decryption of the second payment information.

21 . The computer system of claim 20 , wherein the payload identifier comprises a fingerprint based at least in part on the format of the received payload.

22 . The computer system of claim 21 , wherein the payload includes the encrypted payment card information in hexadecimal or base64 format and the device serial number in hexadecimal or character format.

23 . The computer system of claim 22 , wherein the fingerprint is at least partially based on the hexadecimal or base64 format of the encrypted payment card information.

24 . The computer system of claim 22 , wherein the fingerprint is at least partially based on the hexadecimal or character format of the device serial number.

25 . The computer system of claim 16 , wherein:

the computer system further comprises an hardware security module; and

facilitating decryption of the payment card information comprises transmitting the encrypted payment card information to the hardware security module for decryption.

26 . A computer-implemented method for decrypting payment transactions, the method comprising:

providing at least one point of interaction device comprising one or more processors configured to transmit consumer payment information and a device serial number associated with the at least one point of interaction device; and

providing a point to point encryption management system configured to receive information from the point of interaction device, the point to point encryption management system comprising a) a database for storing device information and b) at least one processor operatively coupled to the database;

receiving, by the least one processor, an initial device serial number at least one computer third party computing device;

writing, by the least one processor, the initial device serial number to a table in memory and storing the table in the database;

receiving, by the at least one processor, a payload at least partially originating from the point of interaction device, the payload including encrypted payment information and the device serial number;

parsing, by the at least one processor, the payload to extract the device serial number;

comparing, by the at least one processor, the device serial number to the initial device serial number to determine whether the device serial number and the initial serial number are the same serial number; and

upon determining that the device serial number and the initial device serial number are the same serial number, facilitating decryption of the payment information.

27 . The computer-implemented method of claim 26 , wherein receiving the payload at least partially originating from the point to point encryption device comprises receiving the payload from a merchant computer system.

28 . The computer-implemented method of claim 26 , wherein receiving the payload at least partially originating from the point to point encryption device comprises receiving the payload from a third party payment processing system.

29 . The computer-implemented method of claim 26 , wherein the method further comprises, upon determining that the device serial number and the initial device serial number are the same serial number, creating, by the at least one processor, a payload identifier for the point of interaction device and storing the payload identifier for the point of interaction device in memory.

30 . The computer-implemented method of claim 29 , wherein:

the received payload is a first payload received that originated from the point of interaction device; and

the method further comprises:

receiving, by the at least one processor, a second payload originating from the point of interaction device including encrypted second payment information and a second device serial number;

parsing, by the at least one processor, the received second payload to extract the second device serial number;

comparing, by the at least one processor, the second device serial number to the initial device serial number to determine whether the second device serial number is included in the table;

upon determining that the second device serial number and the initial device serial number are the same serial number, retrieving, by the at least one processor, the payload identifier;

comparing, by the at least one processor, the second payload to the payload identifier to determine whether the point of interaction device has been compromised; and

upon determining that the point of interaction device has not been compromised, facilitating decryption of the second payment information.

31 . The computer-implemented method of claim 30 , wherein the payload identifier comprises a fingerprint based at least in part on the format of the received payload.

32 . The computer-implemented method of claim 26 , wherein:

the method further comprises providing a hardware security module; and

facilitating decryption of the payment information comprises transmitting, by the at least one processor, the encrypted payment information to the hardware security module for decryption.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Jun 7, 2022
From: GOLDMAN SACHS SPECIALTY LENDING GROUP, L.P.
To: BLUEFIN PAYMENT SYSTEMS LLC
Reel/Frame 060119/0857 →
SECURITY INTEREST Recorded Jun 6, 2022
From: BLUEFIN PAYMENT SYSTEMS LLC
To: TRUIST BANK
Reel/Frame 060105/0919 →
SECURITY INTEREST Recorded Aug 22, 2019
From: BLUEFIN PAYMENT SYSTEMS LLC
To: GOLDMAN SACHS SPECIALTY LENDING GROUP, L.P.
Reel/Frame 050134/0263 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 7, 2015
From: BARNETT, TIMOTHY WILLIAM; MIYATA, CHRISTOPHER HOZUMI; KASATKIN, ALEXANDER I.
To: CAPITAL PAYMENTS, LLC
Reel/Frame 034652/0547 →
MERGER AND CHANGE OF NAME Recorded Jan 7, 2015
From: CAPITAL PAYMENTS, LLC; BLUEFIN PAYMENT SYSTEMS, LLC
To: BLUEFIN PAYMENT SYSTEMS LLC
Reel/Frame 034652/0878 →