IP Library Granted Patent US 11,973,742
Granted Patent B2
US 11,973,742 · App. 17/284,750 · Granted Apr 30, 2024

Techniques for securely communicating sensitive data for disparate data messages

Inventors: Andreas Aabye (San Mateo, CA); Christian Aabye (Redwood City, CA)
Assignee: VISA INTERNATIONAL SERVICE ASSOCIATION
H04L63/0414H04L9/0866H04L9/0894H04L9/321H04L63/102H04L2209/16H04L2209/20H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,973,742
App. No.
17/284,750
Granted
Apr 30, 2024
Kind
B2
Abstract

Systems and methods are disclosed for securely communicating sensitive such as an identifier. A user device may receive a first message comprising a terminal type indicator. For certain values of the terminal type indicator, the user device may be configured to transmit a request message comprising a first identifier and an encrypted identifier. For other values of the terminal type indicator, the user device may be configured to generating an obfuscated identifier based at least in part on a first portion of a second identifier and a second portion of the encrypted identifier. The user device may then transmit a request message that includes the obfuscated identifier and the encrypted identifier.

Claims (68)

1. A computer-implemented method, comprising:

receiving, by a user device from an access device, a first message comprising a terminal type indicator, the user device storing a primary account number and static account number;

generating, by the user device, an encrypted primary account number based on encrypting at least a portion of the primary account number;

generating, for transmission, a second message comprising a data field;

in response to the terminal type indicator indicating a first terminal type:

transmitting, from the user device to the access device, the second message, the data field of the second message being populated with the static account number, the second message further comprising the encrypted primary account number; and

in response to the terminal type indicator indicating a second terminal type:

generating, by the user device, an obfuscated primary account number based at least in part on a first portion of the primary account number and a second portion of the encrypted primary account number; and

transmitting, from the user device to the access device, the second message, the data field of the second message being populated with the obfuscated primary account number, the second message further comprising the encrypted primary account number.

2. The computer-implemented method of claim 1 , further comprising:

obtaining, by the user device, a stored counter value, wherein the encrypted primary account number is generated further utilizing the stored counter value;

generating a modified counter value in response to transmitting the second-message; and

storing the modified counter value at the user device.

3. The computer-implemented method of claim 2 , wherein generating the encrypted primary account number further comprises encrypting the primary account number and the modified counter value with a unique derivation key stored at the user device.

4. The computer-implemented method of claim 1 , wherein the second portion of the encrypted primary account number comprises a right-most seven digits of the encrypted primary account number.

5. The computer-implemented method of claim 1 , wherein the first portion of the primary account number comprises a left-most eight digits of the primary account number.

6. The computer-implemented method of claim 1 , wherein the portion of the primary account number comprises an identification number associated with an acquirer.

7. The computer-implemented method of claim 1 , wherein transmitting the second message comprising the static account number and the encrypted primary account number to the access device, causes the access device to:

compare the static account number to a plurality of stored identifiers;

reject the second message when the static account number is included in the plurality of stored identifiers, wherein rejecting the second message causes the user device to be denied access to a resource managed by the access device; and

approve the second-message when the static account number is not included in the plurality of stored identifiers, wherein approving the second message causes the user device to be granted access to the resource managed by the access device.

8. The computer-implemented method of claim 1 , wherein transmitting the second message comprising the static account number and the encrypted primary account number to the access device, causes the access device to:

generate an authorization request message comprising the static account number and the encrypted primary account number; and

transmit the authorization request message to an authorizing entity computer.

9. The computer-implemented method of claim 8 , wherein the authorizing entity computer is configured to:

receive the authorization request message comprising static account number and the encrypted primary account number;

identify a stored primary account number associated with the static account number;

generate a decrypted primary account number from the encrypted primary account number;

compare the stored primary account number (stored PAN) to the decrypted primary account number; and

process the authorization request message based at least in part on comparing the stored primary account number to the decrypted primary account number.

10. The computer-implemented method of claim 1 , wherein transmitting the second message comprising the obfuscated primary account number and the encrypted primary account number to the access device, causes the access device to:

generate an authorization request message comprising the obfuscated primary account number and the encrypted primary account number; and

transmit the authorization request message to an authorizing entity computer, wherein transmitting the authorization request message comprising the obfuscated primary account number and the encrypted primary account number causes the authorizing entity computer to derive a derivation key based at least in part on a corresponding portion of the obfuscated primary account number, generate a decrypted identifier from the encrypted primary account number utilizing the derivation key, and process the authorization request message utilizing the decrypted identifier.

11. A user device, comprising:

one or more processors; and

one or more memories storing computer-executable instructions, wherein executing the computer-executable instructions by the one or more processors, causes the user device to:

store a primary account number and static account number;

receive, from an access device, a first message comprising a terminal type indicator;

generate an encrypted primary account number based on encrypting at least a portion of the primary account number;

generate, for transmission, a second message comprising a data field;

in response to the terminal type indicator indicating a first terminal type:

transmit, to the access device, the second message, the data field of the second message being populated with the static account number, the second message further comprising the encrypted primary account number; and

in response to the terminal type indicator indicating a second terminal type:

generate an obfuscated primary account number based at least in part on a first portion of the primary account number and a second portion of the encrypted primary account number; and

transmit, to the access device, the second message, the data field of the second message being populated with the obfuscated primary account number, the second message further comprising the encrypted primary account number.

12. The user device of claim 11 , wherein executing the computer-executable instructions by the one or more processors, further causes the user device to:

obtain a stored counter value, wherein the encrypted primary account number-is generated further utilizing the stored counter value;

generate a modified counter value in response to transmitting the second message; and

store the modified counter value at the user device.

13. The user device of claim 12 , wherein generating the encrypted primary account number further comprises encrypting the primary account number and the modified counter value with a unique derivation key stored at the user device.

14. The user device of claim 11 , wherein the second portion of the encrypted primary account number comprises a right-most seven digits of the encrypted primary account number.

15. The user device of claim 11 , wherein the first portion of the primary account number comprises a left-most eight digits of the primary account number.

16. The user device of claim 11 , wherein transmitting the second message comprising the static account number and the encrypted primary account number to the access device, causes the access device to:

compare the static account number to a plurality of stored identifiers;

reject the second message when the static account number is included in the plurality of stored identifiers, wherein rejecting the second message causes the user device to be denied access to a resource managed by the access device; and

approve the second message when the static account number is not included in the plurality of stored identifiers, wherein approving the second message causes the user device to be granted access to the resource managed by the access device.

17. The user device of claim 11 , wherein transmitting the second message comprising the static account number and the encrypted primary account number to the access device, causes the access device to:

generate an authorization request message comprising the static account number and the encrypted primary account number; and

transmit the authorization request message to an authorizing entity computer.

18. The user device of claim 17 , wherein the authorizing entity computer is configured to:

receive the authorization request message comprising the static account number and the encrypted primary account number;

identify a stored primary account number associated with the static account number;

generate a decrypted primary account number from the encrypted primary account number;

compare the stored primary account number (stored PAN) to the decrypted primary account number; and

process the authorization request message based at least in part on comparing the stored primary account number to the decrypted primary account number.

19. The user device of claim 11 , wherein transmitting the second message comprising the obfuscated primary account number and the encrypted primary account number to the access device, causes the access device to:

generate an authorization request message comprising the obfuscated primary account number and the encrypted primary account number; and

transmit the authorization request message to an authorizing entity computer, wherein transmitting the authorization request message comprising the obfuscated primary account number and the encrypted primary account number causes the authorizing entity computer to derive a derivation key based at least in part on a corresponding portion of the obfuscated primary account number, generate a decrypted primary account number from the encrypted primary account number utilizing the derivation key, and process the authorization request message utilizing the decrypted primary account number.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2021
From: AABYE, ANDREAS; AABYE, CHRISTIAN
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 055895/0482 →
Continuity (1)
Related Publication 20210352049A1 · Nov 11, 2021
Cited By (1)
US 12,531,839