IP Library Granted Patent US 10,749,845
Granted Patent B2
US 10,749,845 · App. 16/021,399 · Granted Aug 18, 2020

Systems and methods for decryption as a service via a hardware security module

Inventors: Timothy William Barnett (Roswell, GA); Alexander I. Kasatkin (Alpharetta, GA); Christopher Hozumi Miyata (Tulsa, OK); Daniel Ruehle (Smyrna, GA)
Assignee: BLUEFIN PAYMENT SYSTEMS LLC
H04L63/0428G06F11/0766G06F16/23G06F16/2379G06F16/955G06F21/44G06F21/602G06F21/6227G06F21/6245G06F21/73G06F21/77G06Q10/00G06Q20/20G06Q20/223G06Q20/382G06Q20/3823G06Q20/401G06Q20/409G06Q20/4014H04L9/0861H04L9/0877H04L9/14H04L9/3226H04L9/3234H04L63/0435H04L63/061H04L63/08H04L63/0876H04L63/12H04L63/123G06Q10/10G06Q2220/00G06Q2220/10G16H10/60H04L63/20H04L2209/24H04L2209/56H04L2209/60H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,749,845
App. No.
16/021,399
Granted
Aug 18, 2020
Kind
B2
Abstract

Systems and methods for decryption of payloads are disclosed herein. In various embodiments, systems and methods herein are configured for decrypting thousands of transactions per second. Further, in particular embodiments, the systems and methods herein are scalable, such that many thousands of transactions can be processed per second upon replicating particular architectural components.

Claims (23)

1. A system for decryption of one or more payloads, the system comprising:

a hardware security module for decrypting encrypted elements of received payloads, the hardware security module operatively connected to at least one decryption server;

at least one read-only database operatively connected to a frontend server, the at least one read-only database configured to store authentication data for payloads;

a read/write database operatively connected to a master read-only database, the read/write database configured for transmitting updated authentication data to the master read-only database;

the at least one decryption server, wherein the at least one decryption server is configured to:

receive a particular payload, the particular payload comprising at least one encrypted element;

transmit the particular payload to the hardware security module for decryption of the at least one encrypted element;

upon receiving the particular payload from the hardware security module, parse the particular payload to determine whether the at least one encrypted element has been decrypted by the hardware security module; and

upon determining that the at least one encrypted element has not been decrypted by the hardware security module, transmit an error message to a read/write database operatively coupled to the frontend server; and

the frontend server configured to: 1) retrieve authentication data associated with the particular payload; 2) compare the authentication data to the particular payload to authenticate the particular payload before the particular payload is transmitted to the hardware security module.

2. The system of claim 1 , wherein the at least one decryption server is further configured to, upon determining that the at least one encrypted element has been decrypted by the hardware security module, transmitting the particular payload to a third-party partner.

3. The system of claim 1 , wherein the master read-only database is operatively connected to the at least one read-only database and configured for refreshing the authentication data stored at the at least one read-only database.

4. A computer-implemented method for decryption of one or more payloads, the method comprising:

providing a hardware security module for decrypting encrypted elements of received payloads, the hardware security module operatively connected to at least one decryption server;

providing at least one read-only database operatively connected to a frontend server, the at least one read-only database configured to store authentication data for payloads and the frontend server configured to: 1) retrieve authentication data associated with the particular payload; and 2) compare the authentication data to the particular payload to authenticate the particular payload before the particular payload is transmitted to the hardware security module;

providing a read/write database operatively connected to a master read-only database, the read/write database configured for transmitting updated authentication data to the master read-only database;

providing the at least one decryption server;

receiving a particular payload, the particular payload comprising at least one encrypted element;

transmitting the particular payload to the hardware security module for decryption of the at least one encrypted element;

upon receiving the particular payload from the hardware security module, parsing the particular payload to determine whether the at least one encrypted element has been decrypted by the hardware security module; and

upon determining that the at least one encrypted element has not been decrypted by the hardware security module, transmitting an error message to a read/write database operatively coupled to the frontend server.

5. The computer-implemented method of claim 4 , wherein the computer-implemented method further comprises the step of, upon determining that the at least one encrypted element has been decrypted by the hardware security module, transmitting the particular payload to a third-party partner.

6. The computer-implemented method of claim 4 , wherein the computer-implemented method further comprises the step of providing the master read-only database operatively connected to the at least one read-only database, the master read-only database configured for refreshing the authentication data stored at the at least one read-only database.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Jun 7, 2022
From: GOLDMAN SACHS SPECIALTY LENDING GROUP, L.P.
To: BLUEFIN PAYMENT SYSTEMS LLC
Reel/Frame 060119/0857 →
SECURITY INTEREST Recorded Jun 6, 2022
From: BLUEFIN PAYMENT SYSTEMS LLC
To: TRUIST BANK
Reel/Frame 060105/0919 →
SECURITY INTEREST Recorded Sep 27, 2019
From: BLUEFIN PAYMENT SYSTEMS LLC
To: GOLDMAN SACHS SPECIALTY LENDING GROUP, L.P.
Reel/Frame 050509/0785 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2018
From: BARNETT, TIMOTHY WILLIAM; KASATKIN, ALEXANDER I.; MIYATA, CHRISTOPHER HOZUMI; RUEHLE, DANIEL
To: BLUEFIN PAYMENT SYSTEMS LLC
Reel/Frame 046302/0670 →
Continuity (8)
Continuation 15597402 · May 17, 2017
Continuation 15218352 · Jul 25, 2016
Continuation 14663238 · Mar 19, 2015
Continuation In Part 14591223 · Jan 7, 2015
Continuation In Part 14591218 · Jan 7, 2015
Continuation In Part 14591171
Provisional Application 61955739 · Mar 19, 2014
Related Publication 20180309735A1 · Oct 25, 2018