IP Library Granted Patent US 10,477,393
Granted Patent B2
US 10,477,393 · App. 16/020,796 · Granted Nov 12, 2019

Embedding cloud-based functionalities in a communication device

Inventor: Eduardo Lopez (Menlo Park, CA)
Assignee: Visa International Service Association
H04W12/04G06F9/455G06F21/44G06Q20/32G06Q20/322G06Q20/327G06Q20/3227G06Q20/3278G06Q20/382G06Q20/385G06Q20/3825G06Q20/3829H04W4/80H04L63/068H04W88/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,477,393
App. No.
16/020,796
Granted
Nov 12, 2019
Kind
B2
Abstract

Techniques for enhancing the security of a communication device may include providing an application agent and a transaction application that executes on a communication device. The application agent may receive, from the application, a cryptogram key generated by a remote computer, and store the cryptogram key on the communication device. When the application agent receives a request to conduct a transaction from the application, the application agent may generate a transaction cryptogram using the cryptogram key, and provides the transaction cryptogram to an access device.

Claims (30)

1. A server computer comprising:

a hardware processor; and

a memory storing code, which when executed by the hardware processor, causes the server computer to perform operations including:

generating by the server computer a first cryptogram key that is usable for generation of a first transaction cryptogram to conduct a first transaction;

transmitting the first cryptogram key to a first application executing in a first memory region of a communication device, wherein the first application executing in the first memory region of the communication device provides the first cryptogram key to an application agent executing in a second memory region of the communication device to store the first cryptogram key in the second memory region of the communication device;

receiving by the server computer a replenishment request for a second cryptogram key from the first application executing in the first memory region of the communication device, the replenishment request including transaction log information derived from a transaction log; and

generating by the server computer the second cryptogram key that is usable for generation of a second transaction cryptogram to conduct a second transaction upon determining that the transaction log information in the replenishment request matches transaction log information stored at the server computer and transmitting the second cryptogram key to the first application of the communication device.

2. The server computer of claim 1 , wherein the first cryptogram key is a limited-use key.

3. The server computer of claim 1 , wherein the transaction log information includes an authentication code generated from the transaction log.

4. The server computer of claim 1 , wherein the transaction log includes transaction data for each of a plurality of transactions conducted using the first cryptogram key.

5. The server computer of claim 1 , wherein the server computer does not communication with the application agent except via the first application executing in the first memory region of the communication device.

6. The server computer of claim 1 , wherein the second memory region is a trusted execution environment.

7. The server computer of claim 6 , wherein the trusted execution environment is implemented in a virtual machine.

8. The server computer of claim 6 , wherein the trusted execution environment is implemented as a secure operating mode in a processor of the communication device.

9. The server computer of claim 1 , wherein the first cryptogram key is usable for generation of two types of transaction cryptogram.

10. The server computer of claim 9 , wherein the two types of transaction cryptogram includes a magnetic-stripe based transaction cryptogram and a chip based transaction cryptogram.

11. A method comprising:

generating, by a server computer, a first cryptogram key that is usable for generation of a first transaction cryptogram to conduct a first transaction;

transmitting, by the server computer, the first cryptogram key to a first application executing in a first memory region of a communication device, wherein the first application executing in the first memory region of the communication device provides the first cryptogram key to an application agent executing in a second memory region of the communication device to store the first cryptogram key in the second memory region of the communication device;

receiving, by the server computer, a replenishment request for a second cryptogram key from the first application executing in the first memory region of the communication device, the replenishment request including transaction log information derived from a transaction log; and

generating, by the server computer, the second cryptogram key that is usable for generation of a second transaction cryptogram to conduct a second transaction upon determining that the transaction log information in the replenishment request matches transaction log information stored at the server computer and transmitting the second cryptogram key to the first application of the communication device.

12. The method of claim 11 , wherein the first cryptogram key is a limited-use key.

13. The method of claim 11 , wherein the transaction log information includes an authentication code generated from the transaction log.

14. The method of claim 11 , wherein the transaction log includes transaction data for each of a plurality of transactions conducted using the first cryptogram key.

15. The method of claim 11 , wherein the server computer does not communication with the application agent except via the first application executing in the first memory region of the communication device.

16. The method of claim 11 , wherein the second memory region is a trusted execution environment.

17. The method of claim 16 , wherein the trusted execution environment is implemented in a virtual machine.

18. The method of claim 16 , wherein the trusted execution environment is implemented as a secure operating mode in a processor of the communication device.

19. The method of claim 11 , wherein the first cryptogram key is usable for generation of two types of transaction cryptogram.

20. The method of claim 19 , wherein the two types of transaction cryptogram includes a magnetic-stripe based transaction cryptogram and a chip based transaction cryptogram.

Continuity (4)
Continuation 15682348 · Aug 21, 2017
Continuation 14834028 · Aug 24, 2015
Provisional Application 62040935 · Aug 22, 2014
Related Publication 20180324584A1 · Nov 8, 2018
Cited By (2)
US 12,327,244 US 12,469,021