IP Library › Granted Patent US 11,682,008
Granted Patent B2
US 11,682,008 · App. 17/034,001 · Granted Jun 20, 2023

Method of authenticating a customer, method of carrying out a payment transaction and payment system implementing the specified methods

Inventor: Vadim Nikolaevich Aleksandrov (Moscow, RU)
G06Q20/3829G06F21/602G06Q20/108G06Q20/3223G06Q20/3278G06Q20/341G06Q20/385G06Q20/3825G06Q20/3827G06Q20/38215G06Q20/40145G06Q30/0185G06Q40/02H04L9/0825H04L9/3228H04L9/3231H04L9/3242H04L9/3247G06Q2220/00H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,682,008
App. No.
17/034,001
Granted
Jun 20, 2023
Kind
B2
Abstract

The invention relates to the field of technical infrastructures that ensure the implementation of financial transactions between economic entities, in particular to payment systems that provide ease of use and confidential data security. The present invention is the method of authenticating a customer, the method of carrying out a payment transaction comprising said authentication method, and the payment system implementing the specified methods, which ensure the achievement of a technical effect consisting in expanding the functionality of the payment system and reducing its vulnerability, in particular, by making it possible to conduct a payment transaction in a contactless way, on condition that the reference value of the customer authentication data is stored exclusively on the customer's device, as well as by combining the advantages of online and offline customer authentication procedures.

Claims (151)

1. A method of authenticating a customer during a payment transaction, wherein a reference value of a customer authentication data is stored on a customer's payment device, the method comprising:

exchanging data between a payment terminal and the customer's device,

inputting a value of the customer authentication data by the customer through a terminal input device, and

verifying that the inputted value of the customer authentication data matches the reference one,

characterized in that the method comprises

exchanging data between the payment terminal and the customer's bank server,

wherein during the process of data exchange between the terminal and the customer's device

the customer's device

generates a session key of the customer's device using a unique key of the customer's device and a variable data that change with each transaction;

performs a one-way conversion of the reference value of the customer authentication data;

encrypts the converted reference value of the customer authentication data using the session key of the customer's device;

transmits to the terminal a customer's device data set comprising the converted reference value of the customer authentication data in an encrypted form, a customer's device identifier and the variable data;

during the process of data exchange between the payment terminal and the customer's bank server

the terminal

performs a one-way conversion of the inputted value of the customer authentication data;

transmits to the customer's bank server a terminal data set comprising the converted reference value of the customer authentication data in the encrypted form, the converted inputted value of the customer authentication data, the customer's device identifier, and the variable data;

the customer's bank server

generates the unique key of the customer's device using a master key of the customer's bank server and the customer's device identifier;

generates the session key of the customer's device using the unique key of the customer's device and the variable data;

encrypts the converted inputted value of the customer authentication data using the session key of the customer's device;

verifies that the inputted value of the customer authentication data matches the reference one by comparing the converted inputted value of the customer authentication data with the converted reference value of the customer authentication data in the encrypted form.

2. The method according to claim 1 , characterized in that a one-way cryptographic hash function is used to perform a one-way conversion of the inputted and reference values of the customer authentication data.

3. The method according to claim 2 , characterized in that the arguments of the hash function comprise the variable data.

4. The method according to claim 1 , characterized in that the variable data comprise a one-time-use terminal code generated by the terminal and transmitted to the customer's device during the process of data exchange between the terminal and the customer's device.

5. The method according to claim 1 , characterized in that the variable data comprise a value of a transaction counter of the customer's device.

6. The method according to claim 1 , characterized in that the data exchange between the payment terminal and the customer's device is performed via a wireless data transmission channel.

7. The method according to claim 6 , characterized in that the wireless data transmission channel is implemented using NFC technology.

8. The method according to claim 1 , characterized in that a primary account number is used as the customer's device identifier.

9. The method according to claim 1 , characterized in that

in the process of data exchange between the payment terminal and the customer's bank server,

the customer's bank server

finds a primary account number in the customer database using the customer's device identifier;

generates the unique key of the customer's device using the master key of the customer's bank server and the primary account number.

10. The method according to claim 1 , characterized in that a bank smart card is used as the customer's device.

11. The method according to claim 1 , characterized in that a mobile device capable of software or software and hardware emulation of a bank card is used as the customer's device.

12. The method according to claim 1 , characterized in that the customer authentication data comprise a numeric and/or alphabetic code, and the terminal input device comprises a keyboard.

13. The method according to claim 1 , characterized in that the customer authentication data comprise a biometric data, and the terminal input device is configured to record the customer's biometric data.

14. The method according to claim 1 , characterized in that

in the process of data exchange between the payment terminal and the customer's bank server

the terminal

generates a session key of the terminal;

encrypts the terminal data set using the session key of the terminal;

encrypts the session key of the terminal with a public key of the customer's bank server;

transmits the session key of the terminal and the terminal data set in an encrypted form to the customer's bank server;

the customer's bank server

decrypts the session key of the terminal using a private key of the customer's bank server;

decrypts the terminal data set using the session key of the terminal.

15. The method according to claim 1 , characterized in that

in the process of data exchange between the terminal and the customer's device

the customer's device

transmits a public key certificate of the customer's bank server to the terminal;

the terminal

verifies a digital signature of the public key certificate of the customer's bank server using a public key of a certification authority;

extracts a public key of the customer's bank server from the public key certificate of the customer's bank server;

the customer's device

transmits a public key certificate of the customer's device to the terminal;

the terminal

verifies a digital signature of the public key certificate of the customer's device using the public key of the customer's bank server;

extracts a public key of the customer's device from the public key certificate of the customer's device;

generates a one-time-use terminal code,

transmits the one-time-use terminal code to the customer's device;

the customer's device

encrypts the one-time-use terminal code using a private key of the customer's device,

transmits the one-time-use terminal code in an encrypted form to the terminal;

the terminal

decrypts the one-time-use terminal code received from the customer's device;

compares the decrypted one-time-use terminal code received from the customer's device with the one-time-use terminal code generated by the terminal.

16. A method of carrying out the payment transaction, comprising data exchange between the customer's payment device, the payment terminal, a seller's server, the customer's bank server, a seller's bank server, characterized in that the method comprises the authentication of the customer according to the method of claim 1 .

17. The method according to claim 16 , characterized in that

in the process of data exchange between the payment terminal and the customer's device

the customer's device

transmits to the terminal an Internet address of the customer's bank server,

the data exchange between the payment terminal and the customer's bank server from the terminal side is performed using the Internet address of the customer's bank server received from the customer's device.

18. The method according to claim 16 , characterized in that

in the process of data exchange between the terminal and the customer's device

the customer's device

transmits a public key certificate of the customer's bank server to the terminal;

the terminal

verifies a digital signature of the public key certificate of the customer's bank server using a public key of a certification authority;

extracts a public key of the customer's bank server from the public key certificate of the customer's bank server;

the customer's device

transmits a public key certificate of the customer's device to the terminal;

the terminal

verifies a digital signature of the public key certificate of the customer's device using the public key of the customer's bank server;

extracts a public key of the customer's device from the public key certificate of the customer's device;

generates a one-time-use terminal code,

transmits the one-time-use terminal code to the customer's device;

the customer's device

encrypts the one-time-use terminal code using a private key of the customer's device,

transmits the one-time-use terminal code in an encrypted form to the terminal;

the terminal

decrypts the one-time-use terminal code received from the customer's device;

compares the decrypted one-time-use terminal code received from the customer's device with the one-time-use terminal code generated by the terminal.

19. The method according to claim 18 , characterized in that

in the process of data exchange between the terminal and the customer's device

the terminal

transmits a certificate of the terminal to the customer's device;

the customer's device

verifies a digital signature of the certificate of the terminal using the public key of the certification authority.

20. The method according to claim 18 , characterized in that

in the process of data exchange between the payment terminal and the seller's server

the terminal

transmits a certificate of the terminal and the public key certificate of the customer's bank server to the seller's server;

the seller's server

verifies a digital signature of the certificate of the terminal using the public key of the certification authority;

verifies the digital signature of the public key certificate of the customer's bank server using the public key of the certification authority;

encrypts a seller's payment details using a private key of the seller's server;

transmits the seller's payment details in an encrypted form and a public key certificate of the seller's server to the terminal;

in the process of data exchange between the payment terminal and the customer's bank server

the terminal

transmits the seller's payment details in an encrypted form, the public key certificate of the seller's server and the certificate of the terminal to the customer's bank server;

the customer's bank server

verifies a digital signature of the public key certificate of the seller's server using the public key of the certification authority;

verifies the digital signature of the certificate of the terminal using the public key of the certification authority;

extracts a public key of the seller's server from the public key certificate of the seller's server;

decrypts the seller's payment details using the public key of the seller's server.

21. The method according to claim 16 , characterized in that it comprises an authentication of the customer's payment device.

22. The method according to claim 21 , characterized in that the authentication of the customer's payment device is an additional result of the authentication of the customer.

23. The method according to claim 21 , characterized in that when authenticating the customer's device

in the process of data exchange between the terminal and the customer's device

the customer's device

encrypts a customer's device authentication data using the session key of the customer's device;

transmits the customer's device authentication data and the customer's device authentication data in an encrypted form to the terminal;

in the process of data exchange between the payment terminal and the customer's bank server

the terminal

transmits the customer's device authentication data and the customer's device authentication data in an encrypted form to the customer's bank server;

the customer's bank server

encrypts the customer's device authentication data using the session key of the customer's device;

compares the customer's device authentication data, encrypted on the customer's device, with the customer's device authentication data, encrypted on the customer's bank server, in the encrypted form.

24. The method according to claim 23 , characterized in that the customer's device authentication data comprise the variable data.

25. The method according to claim 23 , characterized in that the customer's device authentication data comprise an Internet address of the customer's bank's server.

26. A payment system comprising

at least one payment terminal configured to exchange data with a customer's payment device, a seller's server, a customer's bank server, and a seller's bank server and comprising a terminal input device;

the seller's server configured to exchange data with the payment terminal;

the customer's payment device configured to exchange data with the payment terminal;

the customer's bank server configured to exchange data with the payment terminal;

the seller's bank server configured to exchange data with the payment terminal;

wherein the customer's device comprises a reference value of a customer authentication data stored on a machine-readable medium of the customer's device,

characterized in that it comprises program instructions stored on the machine-readable medium of the customer's payment device, which, when executed by at least one processor of the customer's device, allow

to generate a session key of the customer's device using a unique key of the customer's device and a variable data that change with each transaction;

to perform a one-way conversion of the reference value of the customer authentication data;

to encrypt the converted reference value of the customer authentication data using the session key of the customer's device;

to transmit a customer's device data set comprising the converted reference value of the customer authentication data in an encrypted form, a customer's device identifier and the variable data to the terminal;

it comprises program instructions stored on a machine-readable medium of the payment terminal, which, when executed by at least one processor of the payment terminal, allow

to perform a one-way conversion of a value of a customer authentication data inputted by a customer through the terminal input device;

to transmit a terminal data set comprising the converted reference value of the customer authentication data in the encrypted form, the converted inputted value of the customer authentication data, the customer's device identifier and the variable data to the customer's bank server;

it comprises program instructions stored on the computer-readable medium of the customer's bank server, which, when executed by at least one processor of the customer's bank server allow

to generate the unique key of the customer's device using a master key of the customer's bank server and the customer's device identifier;

to generate the session key of the customer's device using the unique key of the customer's device and the variable data;

to encrypt the converted inputted value of the customer authentication data using the session key of the customer's device;

to compare the converted inputted value of the customer authentication data with the converted reference value of the customer authentication data in the encrypted form, to verify that the inputted value of the customer authentication data matches the reference one, thereby authenticating the customer.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2026
From: VENCHEVA, OLGA
To: ONETAP2
Reel/Frame 073435/0255 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2025
From: ALEKSANDROV, VADIM NIKOLAEVICH
To: VENCHEVA, OLGA
Reel/Frame 071028/0551 →
Continuity (1)
Related Publication 20220101286A1 · Mar 31, 2022