IP Library Granted Patent US 12,101,395
Granted Patent B2
US 12,101,395 · App. 17/036,510 · Granted Sep 24, 2024

Cryptographic lock-and-key generation, distribution, and validation

Inventor: Jeffrey Stephen Cooper (Kitchener, CA)
Assignee: NCR Atleos Corporation
H04L9/0825G06F13/10G07C9/00182G16Y10/75G16Y30/10H04L9/0891H04L9/14G07C2009/00412
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,101,395
App. No.
17/036,510
Granted
Sep 24, 2024
Kind
B2
Abstract

Cryptographic techniques are provided for generating, distributing, validation, and processing secure commands on different devices and/or peripherals. A control device generates and encrypts a key corresponding to a secure command using a private key of control device to produce a key envelope. Control device further encrypts the key envelope with a recipient's public key producing a recipient envelope. The recipient envelope is delivered to a recipient's device. The recipient's device decrypts the recipient envelope with a private key of the recipient's device producing the key envelope. The key envelope is delivered back to the control device. The control device decrypts the key envelope producing the key, validates the key, and processes a secure command on behalf of a secure resource or delivers the secure command to the secure resource for processing. In an embodiment, control device maintains audit records/audit trail, which is maintained on the control device.

Claims (21)

1. A method, comprising:

receiving, by a control device, a key request from a server, the key request containing a public key of a recipient device and an identifier of a second device associated with a resource;

in response to the receiving, generating, by the control device, a key for access to the resource, the key being associated with the identifier and a command identifier associated with the key request;

wherein the control device is separate from a the second device, wherein the control device is integrated into a terminal, the terminal is an automated teller machine, a self-service terminal, a point-of-sale terminal, or a kiosk, and wherein the second device is a peripheral device of the control device;

encrypting, by the control device, the key with a private key of the control device to produce a key envelope;

encrypting, by the control device, the key envelope with the public key of the recipient device to produce a recipient envelope;

providing, by the control device, the recipient envelope to the server, wherein the server delivers the recipient envelope to the recipient device after a recipient associated with the public key of the recipient device authenticates to the server;

receiving, by the control device, the key envelope from a requestor, wherein the recipient device decrypts the recipient envelope with a recipient private key maintained on the recipient device to obtain the key envelope and send the key envelope to the control device;

decrypting, by a control device, the key envelope with the private key to produce the key;

upon successfully validating the key decrypted, processing, by the control device, on behalf of or issuing a command corresponding to the command identifier to the second device associated with the resource causing the second device to provide access to the resource as defined by the key to the requestor based on the decrypting; or

upon unsuccessfully validating the key decrypted, remove the key decrypted and terminate connection.

2. The method of claim 1 , wherein the receiving further includes receiving one or more of key usage conditions and key expiry conditions with the key request and associating the key usage conditions and the key expiry conditions with the key.

3. The method of claim 2 , wherein the encrypting the key further includes identifying the recipient device as the server.

4. The method of claim 2 , wherein the encrypting the key further includes identifying the recipient device as a certain device operated by the requestor.

5. The method of claim 1 , wherein the receiving further includes receiving the key envelope over a wireless connection between a certain device operated by the requestor and the control device.

6. The method of claim 1 , wherein the decrypting further includes validating one or more of usage conditions and expiry conditions associated with the key.

7. The method of claim 1 , wherein the processing further includes removing the key before processing on behalf of or issuing the command to the second device the resource.

8. The method of claim 1 , wherein the processing further includes sending an unlock signal as the command to a networked attached electromechanical device.

9. The method of claim 1 , wherein the processing further includes issuing the command over a network to an Internet-of-Things (IoT) device.

10. The method of claim 1 , wherein the processing further includes issuing the command to an integrated peripheral device of the control device.

11. The method of claim 1 further comprising, maintaining, by the control device, audit records on the control device as non-repudiation evidence that the recipient device caused the command to be processed on the second device and on behalf of the resource.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PROPERTIES SECTION BY INCLUDING IT WITH TEN PREVIOUSLY OMITTED PROPERTY NUMBERS PREVIOUSLY RECORDED ON REEL 65346 FRAME 367. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Aug 13, 2025
From: NCR ATLEOS CORPORATION; CARDTRONICS USA, LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 072445/0072 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2024
From: NCR VOYIX CORPORATION
To: NCR ATLEOS CORPORATION
Reel/Frame 067464/0882 →
CHANGE OF NAME Recorded May 20, 2024
From: NCR CORPORATION
To: NCR VOYIX CORPORATION
Reel/Frame 067464/0595 →
CORRECTIVE ASSIGNMENT TO CORRECT THE DOCUMENT DATE AND REMOVE THE OATH/DECLARATION (37 CFR 1.63) PREVIOUSLY RECORDED AT REEL: 065331 FRAME: 0297. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 31, 2023
From: NCR ATLEOS CORPORATION
To: CITIBANK, N.A.
Reel/Frame 065627/0332 →
SECURITY INTEREST Recorded Oct 25, 2023
From: NCR ATLEOS CORPORATION; CARDTRONICS USA, LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 065346/0367 →
SECURITY INTEREST Recorded Oct 24, 2023
From: NCR ATLEOS CORPORATION
To: CITIBANK, N.A.
Reel/Frame 065331/0297 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2020
From: COOPER, JEFFREY STEPHEN
To: NCR CORPORATION
Reel/Frame 053918/0263 →
Continuity (1)
Related Publication 20220103351A1 · Mar 31, 2022