IP Library Granted Patent US 12,646,063
Granted Patent B2
US 12,646,063 · App. 17/869,778 · Granted Jun 2, 2026

Split secret cryptography based security in IoT implemented payment transactions or credentials

Inventors: Ajay Sinha (Maharashtra, IN); Lalit Manchanda (Haryana, IN); Naveen Kumar Gupta (Maharashtra, IN); Bhargav Jagdishchandra Modi (Gujarat, IN)
Assignee: MASTERCARD INTERNATIONAL INCORPORATED
G06Q20/401G06Q20/308G06Q2220/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,646,063
App. No.
17/869,778
Granted
Jun 2, 2026
Kind
B2
Abstract

The invention provides methods, systems and computer program products for securely provisioning an internet-of-things (IoT) device for implementing an electronic payment transaction. The invention comprises (i) retrieving a first credential element from the client device, and a second credential element from a router, (ii) generating payment credential data by applying split secret cryptography based reconstruction to the first credential element and the second credential element, (iii) retrieving a unique identifier associated with the IoT device, (iv) generating a combined data element comprising the payment credential data and the unique identifier associated with the IoT device, (v) applying split secret cryptography based splitting to the combined data element to generate a first verifiable secure element and a second verifiable secure element, (vi) storing the first verifiable secure element and the retrieved unique identifier within the router, and (vii) storing the second verifiable secure element within the IoT device.

Claims (43)

1 . A method for securely provisioning an internet-of-things (IoT) device, the method comprising:

applying, by a client device, split secret cryptography-based splitting to a payment credential to create a first credential element and a second credential element from the payment credential;

storing, by the client device, the first credential element in a memory within the client device;

storing the second credential element in a memory of a router coupled in communication with the client device;

retrieving the first credential element from the memory within the client device;

fetching the second credential element from the router that is coupled in communication with each of the client device and an IoT device;

regenerating, by the client device, the payment credential by applying split secret cryptography-based reconstruction to the retrieved first credential element and the fetched second credential element;

fetching, by the client device, from the IoT device, a unique identifier associated with the IoT device;

generating, by the client device, a combined data element comprising the regenerated payment credential and the fetched unique identifier associated with the IoT device;

applying, by the client device, split secret cryptography-based splitting to the combined data element to generate a first verifiable secure element and a second verifiable secure element;

storing, by the client device, in the memory of the router, the first verifiable secure element and the retrieved unique identifier;

mapping, by the client device, the first verifiable secure element and the fetched unique identifier to each other;

storing, by the client device, the second verifiable secure element in a memory within the IoT device; and then,

in response to initiation of a payment workflow at the IoT device:

transmitting, by the IoT device, to the router, payment transaction data, the second verifiable secure element stored within the memory of the IoT device, and the unique identifier associated with the IoT device;

identifying, by the router, a first verifiable secure element associated with the received unique identifier associated with the IoT device, from among data stored within the memory of the router;

regenerating, by the router, the combined data element by applying split secret cryptography-based reconstruction to both of the identified first verifiable secure element and the second verifiable secure element received from the IoT device;

extracting, by the router, from the regenerated combined data element, the payment credential; and

initiating, by the router, an electronic payment transaction based on the payment transaction data received from the IoT device and the payment credential extracted from the regenerated combined data element.

2 . The method of claim 1 , further comprising deleting from the client device one or more of the regenerated payment credential, the combined data element, the first verifiable secure element, and the second verifiable secure element.

3 . The method of claim 1 , further comprising authenticating, by the router, the IoT device by comparing the unique identifier associated with the IoT device that has been received from the IoT device, with a unique identifier extracted from the regenerated combined data element.

4 . A system for securely provisioning an internet-of-things (IoT) device for implementing an electronic payment transaction, the system comprising:

a router; and

a client device coupled in communication with the router, wherein the client device is configured, by first executable instructions, to:

apply a split secret cryptography-based splitting to a payment credential, to create a first credential element and a second credential element from the payment credential;

store the first credential element in a memory within the client device;

store the second credential element in a memory of the router;

retrieve the first credential element from the memory within the client device and the second credential element from the memory of the router;

regenerate the payment credential by applying split secret cryptography-based reconstruction to the retrieved first credential element and the retrieved second credential element;

retrieve a unique identifier associated with an IoT device;

generate a combined data element comprising the regenerated payment credential and the retrieved unique identifier associated with the IoT device;

apply split secret cryptography-based splitting to the combined data element to generate a first verifiable secure element and a second verifiable secure element;

store the first verifiable secure element and the retrieved unique identifier in the memory of the router;

map the first verifiable secure element and the retrieved unique identifier to each other; and

store the second verifiable secure element in a memory within the IoT device; and

wherein the router is configured, by second executable instructions, in response to an instruction initiating a payment workflow at the IoT device, to:

receive, from the IoT device, payment transaction data, the second verifiable secure element stored within the memory of the IoT device, and the unique identifier associated with the IoT device;

identify a first verifiable secure element associated with the received unique identifier associated with the IoT device, from among data stored within the memory of the router;

regenerate the combined data element by applying split secret cryptography-based reconstruction to both of the identified first verifiable secure element and the second verifiable secure element received from the IoT device;

extract the payment credential from the regenerated combined data element; and

initiate the electronic payment transaction based on the payment transaction data received from the IoT device and the payment credential extracted from the regenerated combined data element.

5 . The system as claimed in claim 4 , wherein the client device is configured, by the first executable instructions, to delete one or more of the regenerated payment credential, the combined data element, the first verifiable secure element and the second verifiable secure element.

6 . The system of claim 4 , wherein the router is configured, by the second executable instructions, to authenticate the IoT device by comparing the unique identifier associated with the IoT device that has been received from the IoT device, with a unique identifier extracted from the regenerated combined data element.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2023
From: SINHA, AJAY; MANCHANDA, LALIT; GUPTA, NAVEEN KUMAR; MODI, BHARGAV JAGDISHCHANDRA
To: MASTERCARD INTERNATIONAL INCORPORATED
Reel/Frame 064042/0013 →
Priority Claims (1)
IN 202111032858 · Jul 21, 2021 · national
Continuity (1)
Related Publication 20230024789A1 · Jan 26, 2023
References Cited (5)
US 11057210B1 · Sierra · 2021 [cited by examiner]
US 20020071565A1 · Kurn · 2002 [cited by examiner]
US 20190035018A1 · Nolan · 2019 [cited by examiner]
US 20210327002A1 · Becher · 2021 [cited by examiner]
US 20220321339A1 · Yedluri · 2022 [cited by examiner]