IP Library › Granted Patent US 12,731,140
Granted Patent B2
US 12,731,140 · App. 17/481,398 · Granted Sep 8, 2026

Systems and methods for validating transmissions over communication channels

Inventors: Carlos Eduardo Oliveira do Valle Silvestre (East Sussex, GB); Jonathan Ward Lupton (West Sussex, GB)
Assignee: American Express Travel Related Services Company, Inc.
G06Q20/401G06Q20/3278G06Q20/3823H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,731,140
App. No.
17/481,398
Granted
Sep 8, 2026
Kind
B2
Abstract

An authentication system may receive an authentication MAC, an integrity MAC, and data transmitted from a payment application and a payment terminal. A local integrity MAC may be generated using the data as an input to a first cryptographic operation. The system may compare the local integrity MAC to the received integrity MAC to authenticate the received integrity MAC. A local authentication MAC may be generated using a second cryptographic operation and compare the local authentication MAC to the received authentication MAC. The system may authenticate the payment application in response to a successful authentication of at least one of the received authentication MAC or the received integrity MAC.

Claims (42)

1 . A method comprising:

retrieving, at a payment application device, transaction data from a point-of-sale (POS) terminal relating to a transaction;

generating, at the payment application device, a first cryptographic code by applying a first cryptographic function to the transaction data and to account data corresponding to the payment application device;

generating, at the payment application device, a second cryptographic code by applying a second cryptographic function to second data that is available to an issuer host system without being transmitted from the payment application device; and

transmitting the transaction data, the account data, the first cryptographic code, and the second cryptographic code to the issuer host system for authentication of the payment application device;

determining, by the issuer host system, that the transmitted first cryptographic code fails to match a local first cryptographic code by comparing the local first cryptographic code to the transmitted first cryptographic code;

in response to the determining:

retrieving, by the issuer host system, the second data for input to the second cryptographic function, wherein the second data is generated independently from the transaction data received from the payment application device;

generating, by the issuer host system, a local second cryptographic code using the second cryptographic function;

authenticating, by the issuer host system, the transmitted second cryptographic code by comparing the local second cryptographic code to the transmitted second cryptographic code;

determining, based on the comparing, whether the local second cryptographic code matches the transmitted second cryptographic code; and

authenticating, by the issuer host system, the transaction in response to the transmitted second cryptographic code matching the local second cryptographic code, and denying the transaction in response to the transmitted second cryptographic code failing to match the local second cryptographic code;

receiving, at the payment application device, a reply message from the issuer host system in response to the transmitting, wherein the reply message indicates authentication of only one of the first cryptographic code or the second cryptographic code; and

completing or terminating the transaction, by the payment application device, based on the reply message.

2 . The method of claim 1 , wherein the first cryptographic code is an integrity Message Authentication Code (MAC) and wherein the second cryptographic code is an authentication Message Authentication Code (MAC).

3 . The method of claim 1 , wherein the transaction data includes an identifier of a product that has been scanned for purchase.

4 . The method of claim 1 , wherein the second data includes data obtained by the issuer host system independently from the transaction data received from the payment application device.

5 . The method of claim 1 , wherein the second data includes a transaction counter.

6 . The method of claim 1 , wherein the first cryptographic function and the second cryptographic function apply symmetric cryptographic operations.

7 . The method of claim 1 , wherein the payment application device is a chip card configured to generate Message Authentication Codes (MACs).

8 . A payment application system comprising:

a memory; and

at least one processor coupled to the memory and configured to:

retrieve transaction data from a point-of-sale (POS) terminal relating to a transaction;

generate a first cryptographic code by applying a first cryptographic function to the transaction data and to account data corresponding to the payment application system, the transaction data including a payment amount associated with the transaction;

generate a second cryptographic code by applying a second cryptographic function to second data that is available to an issuer host system without being transmitted from the payment application system;

transmit the transaction data, the account data, the first cryptographic code, and the second cryptographic code to the issuer host system for authentication of the payment application system;

determine, by the issuer host system, that the transmitted first cryptographic code fails to match a local first cryptographic code by comparing the local first cryptographic code to the transmitted first cryptographic code;

in response to the determining:

retrieve the second data for input to the second cryptographic function, wherein the second data is generated independently from the transaction data;

generate a local second cryptographic code using the second cryptographic function;

authenticate the transmitted second cryptographic code by comparing the local second cryptographic code to the transmitted second cryptographic code;

determine, based on the comparing, whether the local second cryptographic code matches the transmitted second cryptographic code; and

authenticate the transaction in response to the transmitted second cryptographic code matching the local second cryptographic code, and denying the transaction in response to the transmitted second cryptographic code failing to match the local second cryptographic code;

receive a reply message from the issuer host system in response to the transmitting, wherein the reply message indicates authentication of only one of the first cryptographic code or the second cryptographic code; and

complete or terminate the transaction based on the reply message.

9 . The payment application system of claim 8 , further comprising a transponder configured to retrieve the transaction data from the point-of-sale (POS) terminal via a near field communication (NFC) channel.

10 . The payment application system of claim 8 , wherein the first cryptographic code is an integrity Message Authentication Code (MAC) and wherein the second cryptographic code is an authentication Message Authentication Code (MAC).

11 . The payment application system of claim 8 , wherein the transaction data includes an identifier of a product that has been scanned for purchase.

12 . The payment application system of claim 8 , wherein the second data includes data obtained by the issuer host system independently from the transaction data received from the payment application system.

13 . The payment application system of claim 8 , wherein the second data includes a transaction counter.

14 . The payment application system of claim 8 , wherein the first cryptographic function and the second cryptographic function apply symmetric cryptographic operations.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2021
From: SILVESTRE, CARLOS EDUARDO OLIVEIRA DO VALLE; LUPTON, JONATHAN WARD
To: AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.
Reel/Frame 057586/0795 →
Continuity (2)
Continuation 16312871 · Jul 1, 2016
Related Publication 20220051244A1 · Feb 17, 2022
References Cited (31)
US 7478434B1 · Hinton et al. · 2009 [cited by applicant]
US 7596530B1 · Glasberg · 2009 [cited by applicant]
US 7624283B2 · Bade et al. · 2009 [cited by applicant]
US 10565570B2 · Chan · 2020 [cited by examiner]
US 20020095567A1 · Royer · 2002 [cited by examiner]
US 20080120504A1 · Kirkup et al. · 2008 [cited by applicant]
US 20080301436A1 · Yao · 2008 [cited by examiner]
US 20080301461A1 · Coulier et al. · 2008 [cited by applicant]
US 20100228668A1 · Hogan · 2010 [cited by examiner]
US 20110258452A1 · Coulier et al. · 2011 [cited by applicant]
US 20120150742A1 · Poon et al. · 2012 [cited by applicant]
US 20130254117A1 · von Mueller et al. · 2013 [cited by applicant]
US 20140040628A1 · Fort et al. · 2014 [cited by applicant]
US 20140189335A1 · Liu et al. · 2014 [cited by applicant]
US 20140189359A1 · Marien et al. · 2014 [cited by applicant]
US 20150100497A1 · de Jong et al. · 2015 [cited by applicant]
US 20150112869A1 · Radu et al. · 2015 [cited by applicant]
US 20150170114A1 · Klingen · 2015 [cited by applicant]
US 20150170144A1 · Palma Lizana et al. · 2015 [cited by applicant]
US 20160180343A1 · Poon et al. · 2016 [cited by applicant]
US 20190172064A1 · Silvestre et al. · 2019 [cited by applicant]
WO WO9964995A1 · 1999 [cited by applicant]
WO WO9967766A2 · 1999 [cited by applicant]
WO WO0199070A2 · 2001 [cited by examiner]
WO WO2010116310A1 · 2010 [cited by applicant]
WO WO2015063495A1 · 2015 [cited by applicant]
WO WO2016092318A1 · 2016 [cited by applicant]
WO WO2017012086A1 · 2017 [cited by applicant]
WO WO2018228732A1 · 2018 [cited by applicant]
International Search Report and Written Opinion dated Sep. 16, 2016 in PCT Application No. PCT/US2016/040803. [cited by applicant]
International Preliminary Report on Patentability dated Jun. 1, 2017 in PCT Application No. PCT/US2016/040803. [cited by applicant]