IP Library › Granted Patent US 12,256,009
Granted Patent B2
US 12,256,009 · App. 18/212,779 · Granted Mar 18, 2025

Method, system, and computer program product for network bound proxy re-encryption and PIN translation

Inventors: Sivanarayana Gaddam (Santa Clara, CA); Gaven James Watson (Palo Alto, CA); Pratyay Mukherjee (Sunnyvale, CA); Rohit Sinha (Bokaro Steel, IN)
Assignee: Visa International Service Association
H04L9/3226G06Q20/027G06Q20/108G06Q20/202G06Q20/206G06Q20/3823G06Q20/3829G06Q20/385G06Q20/4012H04L9/0819H04L9/0869H04L9/30H04L63/0471H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,256,009
App. No.
18/212,779
Granted
Mar 18, 2025
Kind
B2
Abstract

A method, system, and computer program product generate, with a payment network, a first value (a) and a second value (g a ), the second value (g a ) based on the first value (a) and a generator value (g); generate, with the payment network, a plurality of random merchant numbers (m i ) for a respective plurality of merchant banks; determine, with the payment network, a merchant product (M) based on a product of the plurality of random merchant numbers (m i ); generate, with the payment network, a public key (pk i ) based on the second value (g a ), the merchant product (M), and the random merchant number (m i ) and a random key (rk i ) based on the merchant product (M) and the random merchant number (m i ) for each respective merchant bank; and communicate, with the payment network, the public key (pk i ) and the random key (rk i ) to at least one respective merchant bank.

Claims (97)

1. A computer-implemented method, comprising:

generating, with at least one point-of-sale (POS) terminal, a random number (r) for a transaction message (m) associated with a transaction, wherein the transaction message (m) contains sensitive data, and wherein the sensitive data comprises an identification number associated with a user;

generating, with the at least one POS terminal, a first ciphertext associated with the transaction, the first ciphertext comprising:

(i) a first ciphertext value associated with the transaction message (m), the first ciphertext value encrypted based on the random number (r), a generator value (g), and the transaction message (m); and

ii) a second ciphertext value associated with the random number (r), the second ciphertext value encrypted based on the random number (r) and a terminal public key;

communicating, with the POS terminal, the first ciphertext to at least one payment gateway;

re-encrypting, with the at least one payment gateway, the second ciphertext value based on a terminal random key to transform the second ciphertext value to a re-encrypted second ciphertext value based on a second value (g a ), a merchant product (M), and the random number (r);

communicating, with the at least one payment gateway, the re-encrypted second ciphertext value and the first ciphertext value to at least one respective merchant bank of a plurality of merchant banks;

re-encrypting, with the at least one respective merchant bank of the plurality of merchant banks, the re-encrypted second ciphertext value to transform the re-encrypted second ciphertext value to a second re-encrypted second ciphertext value;

communicating, with the at least one respective merchant bank, the second re-encrypted second ciphertext value and the first ciphertext value to a payment network;

decrypting, with the payment network, the first ciphertext value to form the transaction message (m) based on the second re-encrypted second ciphertext value, the merchant product (M), a random merchant number (m i ), and the first ciphertext value;

communicating, with the payment network, the transaction message (m) associated with the transaction to a consumer bank;

verifying, with the consumer bank, the identification number associated with the user; and

in response to verifying the identification number, authorizing, with the consumer bank, the transaction.

2. The computer-implemented method of claim 1 , further comprising:

generating, with the payment network, a first value (a) and the second value (g a ), the second value (g a ) generated based on the first value (a) and the generator value (g);

generating, with the payment network, a plurality of random merchant numbers (m i ) for a respective plurality of merchant banks;

determining, with the payment network, the merchant product (M) based on a product of the plurality of random merchant numbers (m i ) for the respective plurality of merchant banks;

generating, with the payment network, a public key (pk i ) based on the second value (g a ), the merchant product (M), and the random merchant number (m i ) and a random key (rk i ) based on the merchant product (M) and the random merchant number (m i ) for each respective merchant bank of the plurality of merchant banks; and

communicating, with the payment network, the public key (pk i ) and the random key (rk i ) to the at least one respective merchant bank.

3. The computer-implemented method of claim 2 , further comprising:

generating, with the at least one respective merchant bank of the plurality of merchant banks, a plurality of random payment gateway numbers (p i ) for a respective plurality of payment gateways; and

generating, with the at least one respective merchant bank of the plurality of merchant banks, a payment gateway public key based on the second value (g a ), the merchant product (M), and the random payment gateway number (p i ) and a payment gateway random key based on the random payment gateway number (p i ) for each respective payment gateway of the plurality of payment gateways.

4. The computer-implemented method of claim 3 , further comprising:

generating, with the at least one respective merchant bank of the plurality of merchant banks, a plurality of terminal numbers (t i ) for a respective plurality of POS terminals; and

generating, with the at least one respective merchant bank of the plurality of merchant banks, the terminal public key based on the second value (g a ), the merchant product (M), the random payment gateway number (p i ), and the terminal number (t i ) and the terminal random key based on the random payment gateway number (p i ) and the terminal number (t i ) for each respective POS terminal of the respective plurality of POS terminals.

5. The computer-implemented method of claim 4 , further comprising:

communicating, with the at least one respective merchant bank of the plurality of merchant banks, the terminal public key and the terminal random key to the at least one payment gateway; and

communicating, with the at least one payment gateway, the terminal public key to the at least one POS terminal.

6. The computer-implemented method of claim 1 , wherein the merchant product (M) comprises a result of multiplication of the plurality of random merchant numbers (m i ).

7. A system comprising:

at least one point-of-sale (POS) terminal including one or more processors, wherein the at least one POS terminal is programmed and/or configured to:

generate a random number (r) for a transaction message (m) associated with a transaction, wherein the transaction message (m) contains sensitive data, and wherein the sensitive data comprises an identification number associated with a user;

generate a first ciphertext associated with the transaction, the first ciphertext comprising:

(i) a first ciphertext value associated with the transaction message (m), the first ciphertext value encrypted based on the random number (r), a generator value (g), and the transaction message (m); and

ii) a second ciphertext value associated with the random number (r), the second ciphertext value encrypted based on the random number (r) and a terminal public key; and

communicate the first ciphertext to at least one payment gateway;

the at least one payment gateway including one or more processors, wherein the at least one payment gateway is programmed and/or configured to:

re-encrypt the second ciphertext value based on a terminal random key to transform the second ciphertext value to a re-encrypted second ciphertext value based on a second value (g a ), a merchant product (M), and the random number (r); and

communicate the re-encrypted second ciphertext value and the first ciphertext value to at least one respective merchant bank of a plurality of merchant banks;

the at least one respective merchant bank of a plurality of merchant banks including one or more processors, wherein the at least one respective merchant bank of the plurality of merchant banks is programmed and/or configured to:

re-encrypt the re-encrypted second ciphertext value to transform the re-encrypted second ciphertext value to a second re-encrypted second ciphertext value; and

communicate the second re-encrypted second ciphertext value and the first ciphertext value to at least one payment network;

the at least one payment network including one or more processors, wherein the at least one payment network is programmed and/or configured to:

decrypt the first ciphertext value to form the transaction message (m) based on the second re-encrypted second ciphertext value, the merchant product (M), the random merchant number (m i ), and the first ciphertext value; and

communicate the transaction message (m) associated with the transaction to at least one consumer bank; and

the at least one consumer bank including one or more processors, wherein the at least one consumer bank is programmed and/or configured to:

verify the identification number associated with the user; and

in response to verifying the identification number, authorize the transaction.

8. The system of claim 7 , wherein the at least one payment network is

further programmed and/or configured to:

generate a first value (a) and the second value (g a ), the second value (g a ) generated based on the first value (a) and the generator value (g);

generate a plurality of random merchant numbers (m i ) for a respective plurality of merchant banks;

determine the merchant product (M) based on a product of the plurality of random merchant numbers (m i ) for the respective plurality of merchant banks;

generate a public key (pk i ) based on the second value (g a ), the merchant product (M), and the random merchant number (m i ) and a random key (rk i ) based on the merchant product (M) and the random merchant number (m i ) for each respective merchant bank of the plurality of merchant banks; and

communicate the public key (pk i ) and the random key (rk i ) to at least one respective merchant bank of the plurality of merchant banks.

9. The system of claim 8 , wherein the at least one respective merchant bank of the plurality of merchant banks is further programmed and/or configured to:

generate a plurality of random payment gateway numbers (p i ) for a respective plurality of payment gateways; and

generate a payment gateway public key based on the second value (g a ), the merchant product (M), and the random payment gateway number (p i ) and a payment gateway random key based on the random payment gateway number (p i ) for each respective payment gateway of the plurality of payment gateways.

10. The system of claim 9 , wherein the respective merchant bank of the plurality of merchant banks is further programmed and/or configured to:

generate a plurality of terminal numbers (t i ) for a respective plurality of POS terminals; and

generate the terminal public key based on the second value (g a ), the merchant product (M), the random payment gateway number (p i ), and the terminal number (t i ) and the terminal random key based on the random payment gateway number (p i ) and the terminal number (t i ) for each respective POS terminal of the plurality of POS terminals.

11. The system of claim 10 , wherein the at least one respective merchant bank of the plurality of merchant banks is further programmed and/or configured to:

communicate the terminal public key and the terminal random key to the at least one payment gateway, and

wherein the at least one payment gateway is further programmed and/or configured to:

communicate the terminal public key to the at least one POS terminal.

12. The system of claim 7 , wherein the merchant product (M) comprises a result of multiplication of the plurality of random merchant numbers (m i ).

13. A computer program product comprising at least one non-transitory computer-readable medium including program instructions that, when executed by at least one processor, cause the at least one processor to:

generate, with at least one point-of-sale (POS) terminal, a random number (r) for a transaction message (m) associated with a transaction, wherein the transaction message (m) contains sensitive data, and wherein the sensitive data comprises an identification number associated with a user;

generate, with the at least one POS terminal, a first ciphertext associated with the transaction, the first ciphertext comprising:

(i) a first ciphertext value associated with the transaction message (m), the first ciphertext value encrypted based on the random number (r), a generator value (g), and the transaction message (m); and

ii) a second ciphertext value associated with the random number (r), the second ciphertext value encrypted based on the random number (r) and a terminal public key;

communicate, with the POS terminal, the first ciphertext to at least one payment gateway;

re-encrypt, with the at least one payment gateway, the second ciphertext value based on a terminal random key to transform the second ciphertext value to a re-encrypted second ciphertext value based on a second value (g a ), a merchant product (M), and the random number (r);

communicate, with the at least one payment gateway, the re-encrypted second ciphertext value and the first ciphertext value to at least one respective merchant bank of a plurality of merchant banks;

re-encrypt, with the at least one respective merchant bank of the plurality of merchant banks, the re-encrypted second ciphertext value to transform the re-encrypted second ciphertext value to a second re-encrypted second ciphertext value;

communicate, with the at least one respective merchant bank, the second re-encrypted second ciphertext value and the first ciphertext value to a payment network;

decrypt, with the payment network, the first ciphertext value to form the transaction message (m) based on the second re-encrypted second ciphertext value, the merchant product (M), a random merchant number (m i ), and the first ciphertext value;

communicate, with the payment network, the transaction message (m) associated with the transaction to a consumer bank;

verify, with the consumer bank, the identification number associated with the user; and

in response to verifying the identification number, authorize, with the consumer bank, the transaction.

14. The computer program product of claim 13 , wherein the instructions further cause the at least one processor to:

generate, with the payment network, a first value (a) and the second value (g a ), the second value (g a ) generated based on the first value (a) and the generator value (g);

generate, with the payment network, a plurality of random merchant numbers (m i ) for a respective plurality of merchant banks;

determine, with the payment network, the merchant product (M) based on a product of the plurality of random merchant numbers (m i ) for the respective plurality of merchant banks;

generate, with the payment network, a public key (pk i ) based on the second value (g a ), the merchant product (M), and the random merchant number (m i ) and a random key (rk i ) based on the merchant product (M) and the random merchant number (m i ) for each respective merchant bank of the plurality of merchant banks; and

communicate, with the payment network, the public key (pk i ) and the random key (rk i ) to the at least one respective merchant bank of the plurality of merchant banks.

15. The computer program product of claim 14 , wherein the instructions further cause the at least one processor to:

generate, with the at least one respective merchant bank of the plurality of merchant banks, a plurality of random payment gateway numbers (p i ) for a respective plurality of payment gateways; and

generate, with the at least one respective merchant bank of the plurality of merchant banks, a payment gateway public key based on the second value (g a ), the merchant product (M), and the random payment gateway number (p i ) and a payment gateway random key based on the random payment gateway number (p i ) for each respective payment gateway of the plurality of payment gateways.

16. The computer program product of claim 15 , wherein the instructions further cause the at least one processor to:

generate, with the at least one respective merchant bank of the plurality of merchant banks, a plurality of terminal numbers (t i ) for a respective plurality of POS terminals; and

generate, with the at least one respective merchant bank of the plurality of merchant banks, the terminal public key based on the second value (g a ), the merchant product (M), the random payment gateway number (p i ), and the terminal number (t i ) and the terminal random key based on the random payment gateway number (p i ) and the terminal number (t i ) for each respective POS terminal of the plurality of POS terminals.

17. The computer program product of claim 16 , wherein the instructions further cause the at least one processor to:

communicate, with the at least one respective merchant bank of the plurality of merchant banks, the terminal public key and the terminal random key to the at least one payment gateway; and

communicate, with the at least one payment gateway, the terminal public key to the at least one POS terminal.

18. The computer program product of claim 14 , wherein the merchant product (M) comprises a result of multiplication of the plurality of random merchant numbers (m i ).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 22, 2023
From: GADDAM, SIVANARAYANA; WATSON, GAVEN JAMES; MUKHERJEE, PRATYAY; SINHA, ROHIT
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 064026/0236 →
Continuity (4)
Continuation 17421608
Provisional Application 62929344 · Nov 1, 2019
Provisional Application 62790163 · Jan 9, 2019
Related Publication 20230353366A1 · Nov 2, 2023
References Cited (84)
US 5781632A · Odom · 1998 [cited by examiner]
US 6760711B1 · Gillett et al. · 2004 [cited by applicant]
US 8954740B1 · Moscaritolo et al. · 2015 [cited by applicant]
US 8990121B1 · Guise et al. · 2015 [cited by applicant]
US 10134038B2 · Baig · 2018 [cited by applicant]
US 10616183B2 · Syngkon et al. · 2020 [cited by applicant]
US 11182779B2 · Srivastava et al. · 2021 [cited by applicant]
US 11195173B2 · Enright · 2021 [cited by examiner]
US 11736295B2 · Gaddam · 2023 [cited by examiner]
US 11756029B2 · Abouelenin · 2023 [cited by applicant]
US 20100161494A1 · Slater · 2010 [cited by applicant]
US 20140050318A1 · Hayashi et al. · 2014 [cited by applicant]
US 20150019443A1 · Sheets · 2015 [cited by examiner]
US 20150142670A1 · Zloth et al. · 2015 [cited by applicant]
US 20150200917A1 · Fugii et al. · 2015 [cited by applicant]
US 20150271153A1 · Rohloff et al. · 2015 [cited by applicant]
US 20150302397A1 · Kalgi · 2015 [cited by applicant]
US 20160321638A1 · Cheng et al. · 2016 [cited by applicant]
US 20170061403A1 · Reisgies et al. · 2017 [cited by applicant]
US 20170286958A1 · Herman · 2017 [cited by applicant]
US 20180254892A1 · Egorov et al. · 2018 [cited by applicant]
US 20180254901A1 · Egorov · 2018 [cited by examiner]
US 20180270048A1 · Bar-El et al. · 2018 [cited by applicant]
US 20190139039A1 · Chawan et al. · 2019 [cited by applicant]
US 20220270088A1 · Gaddam et al. · 2022 [cited by applicant]
CN 108830587A · 2018 [cited by applicant]
CN 104094302B · 2018 [cited by applicant]
CN 109525401A · 2019 [cited by applicant]
GB 2549118A · 2017 [cited by applicant]
GB 2551775A · 2018 [cited by applicant]
WO 9829983A1 · 1998 [cited by applicant]
WO 2012147869A1 · 2012 [cited by applicant]
WO 2013056104A1 · 2013 [cited by applicant]
WO 2017078626A1 · 2017 [cited by applicant]
WO 2018096559A1 · 2018 [cited by applicant]
WO 2018208787A1 · 2018 [cited by applicant]
WO 2018222811A1 · 2018 [cited by applicant]
“A Guide to EMV Chip Technology”, EMVCo, 2014, 36 pages, retrieved from https://www.emvco.com/wp-content/uploads/2017/05/A_Guide_to_EMV_Chip_Technology_v2.0_20141120122132753.pdf. [cited by applicant]
“ANSI X9.24-1-2017 Retail Financial Services Symmetric Key Management Part 1: Using Symmetric Techniques”, Approved American National Standard (ANSI), 2017, 48 pages, retrieved from https://webstore.ansi.org/standards/a… [cited by applicant]
Ateniese et al., “Improved Proxy Re-encryption Schemes with Applications to Secure Distributed Storage”, ACM Transactions on Information and System Security, 2006, 25 pages, vol. 9, No. 1, retrieved from https://spqrlab… [cited by applicant]
“Bc-java: Bouncy Castle Java Distribution (Mirror)”, GitHub, 2019, 4 pages, retrieved from https://github.com/bcgit/bc-java/tree/cfe16b873f5e41b64e4c3c1a79f64d6795aeff8b. [cited by applicant]
Bellare et al., “Authenticated Encryption: Relations among Notions and Analysis of the Generic Composition Paradigm”, Journal of Cryptology, 2008, 23 pages, retrieved from https://link.springer.com/content/pdf/10.1007/s… [cited by applicant]
Bellare et al., “Encode-Then-Encipher Encryption: How to Exploit Nonces or Redundancy in Plaintexts for Efficient Cryptography”, ASIACRYPT, 2000, 14 pages, retrieved from https://link.springer.com/content/pdf/10.1007%2F… [cited by applicant]
Berkman et al., “The Unbearable Lightness of PIN Cracking”, 2007, 15 pages, retrieved from http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.216.4564&rep=rep1&type=pdf. [cited by applicant]
Biswas et al., “Privacy-Preserving Outsourced Profiling”, Commerce and Enterprise Computing (CEC), 2010 IEEEE 12th Conference On, Nov. 10, 2010, pp. 136-143. [cited by applicant]
Blaze et al., “Divertible Protocols and Atomic Proxy Cryptography”, 18 pages, retrieved from https://link.springer.com/content/pdf/10.1007%2FBFb0054122.pdf. [cited by applicant]
Brown, “Standards for Efficient Cryptography, SEC 2: Recommended Elliptic Curve Domain Parameters”, Certicom Corp., 2010, 37 pages, retrieved from https://www.secg.org/sec2-v2.pdf. [cited by applicant]
Canetti et al., “Chosen-Ciphertext Secure Proxy Re-Encryption”, ACM Digital Library, 2007, 22 pages, retrieved from https://eprint.iacr.org/2007/171.pdf. [cited by applicant]
Centenaro et al., “Type-based Analysis of PIN Processing APIs”, In Proceedings of 14th European Symposium on Research in Computer Security, ResearchGate, 2009, 17 pages, https://www.researchgate.net/publication/22163208… [cited by applicant]
Chandran et al., “Re-encryption, Functional Re-encryption, and Multi-hop Re-encryption: A Framework for Achieving Obfuscation-Based Security and Instantiations from Lattices”, 2014, 18 pages, retrieved from https://link… [cited by applicant]
“Chip technology helps reduce counterfeit fraud by 76 percent”, Visa, 2019, 8 pages, retrieved from https://usa.visa.com/visa-everywhere/blog/bdp/2019/05/28/chip-technology-helps-1559068467332.html. [cited by applicant]
Cohen, “What about Bob? The Inadequacy of CPA Security for Proxy Reencryption”, MIT, 2018, 37 pages, https://eprint.iacr.org/2017/785.pdf. [cited by applicant]
Cramer et al., “A Practical Public Key Cryptosystem Provably Secure against Adaptive Chosen Ciphertext Attack”, 13 pages, retrieved from https://link.springer.com/content/pdf/10.1007%2FBFb0055717.pdf. [cited by applicant]
Debit Card Interchange Fees and Routing; Proposed Rule, 75 Fed. Reg. 81722 (Dec. 28, 2010). [cited by applicant]
“dropwizard: A damn simple library for building production-ready RESTful web services”, GitHub, 2019, 3 pages, retrieved from https://github.com/dropwizard/dropwizard/tree/59633f0fae56612b0b6d7cefe25423a85c9832ea. [cited by applicant]
“EMV at the pump”, Visa, 4 pages, retrieved from https://web.archive.org/web/20190501204359/https://usa.visa.com/visa-everywhere/security/emv-at-the-pump.html. [cited by applicant]
“EMV in the U.S.: Putting It Into Perspective for Merchants and Financial Institutions”, First Data, 2011, 19 pages, retrieved from https://www.firstdata.com/downloads/thought-leadership/EMV_US.pdf. [cited by applicant]
“EMV Integrated Circuit Card Specifications for Payment Systems, Book 2, Security and Key Management, Version 4.3”, EMVCo, 2011, 174 pages, retrieved from https://www.emvco.com/wp-content/uploads/2017/05/EMV_v4.3_Book_2… [cited by applicant]
“EMV News”, Visa, 2017, 3 pages, retrieved from https://usa.visa.com/dam/VCOM/regional/na/us/run-your-business/documents/emv-newsletter-oct2017.pdf. [cited by applicant]
Fuchsbauer et al., “Adaptively Secure Proxy Re-encryption”, 49 pages, retrieved from https://eprint.iacr.org/2018/426.pdf. [cited by applicant]
Gamal et al., “A Public Key Cryptosystem and a Signature Scheme Based on Discrete Logarithms”, Advances in Cryptology, 1985, 9 pages, retrieved from https://link.springer.com/content/pdf/10.1007%2F3-540-39568-7_2.pdf. [cited by applicant]
Gentry, “Fully Homomorphic Encryption Using Ideal Lattices”, 2009, 10 pages, retrieved from http://www.cs.cmu.edu/˜odonnell/hits09/gentry-homomorphic-encryption.pdf. [cited by applicant]
Green et al., “Identity-Based Proxy re-Encryption”, in Applied Cryptograph and Network Security, Springer Berlin Heidelberg, Jan. 1, 2007, 21 pages. [cited by applicant]
“ISO 8583-1 Financial transaction card originated messages—Interchange message specifications—Part 1: Messages, data elements and code values”, International Standard, 2003, 204 pages, retrieved from https://www.iso.org… [cited by applicant]
“ISO 9564-1 Financial services—Personal Identification Number (PIN) management and security—Part 1: Basic principles and requirements for PINs in card-based systems”, International Standard, 2017, 40 pages, retrieved fr… [cited by applicant]
Jayasinghe et al., “Enhancing EMV Online PIN Verification”, 10 pages, retrieved from https://pure.royalholloway.ac.uk/portal/files/26543055/Enhancing_EMV_OPV.pdf. [cited by applicant]
“Leveldb: LevelDB is a fast key-value storage library written at Google that provides an ordered mapping from string keys to string values”, GitHub, 2019, 7 pages, retrieved from https://github.com/google/leveldb/tree/9… [cited by applicant]
Libert et al., “Unidirectional Chosen-Ciphertext Secure Proxy Re-Encryption”, 19 pages, retrieved from http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.626.2726&rep=rep1&type=pdf. [cited by applicant]
Mannan et al., “Reducing Threats from Flawed Security APIs: The Banking PIN Case”, 2009, 13 pages, retrieved from https://people.scs.carleton.ca/˜mmannan/publications/saltedpin-cose.pdf. [cited by applicant]
Mannan et al., “Weighing Down “The Unbearable Lightness of PIN Cracking””, 2008, 5 pages, retrieved from http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.216.4564&rep=rep1&type=pdf. [cited by applicant]
Myers et al., “Efficient Hybrid Proxy Re-Encryption for Practical Revocation and Key Rotation”, 69 pages, retrieved from https://eprint.iacr.org/2017/833.pdf. [cited by applicant]
Myers et al., “Practical Revocation and Key Rotation”, Advances in Biometrics: International Conference, Springer International Publishing AG, 2007, pp. 157-178. [cited by applicant]
“New PCI Software-Based PIN Entry on COTS Standard”, PCI Security Standards Council, 2018, 5 pages, retrieved from https://blog.pcisecuritystandards.org/new-pci-software-pin-entry-on-cots-standard. [cited by applicant]
“Operational Performance Data”, Visa, 2018, 5 pages, retrieved from https://s1.q4cdn.com/050606653/files/doc_financials/2018/q4/Visa-Inc.-Q4-2018-Operational-Performance-Data.pdf. [cited by applicant]
“Payment Card Industry (PCI) Hardware Security Module (HSM) Security Requirements”, PCI Security Standards Council, 2009, 26 pages, retrieved from https://www.pcisecuritystandards.org/documents/PCI%20HSM%20Security%20Re… [cited by applicant]
“Payment Card Industry (PCI) Pin Security Requirements”, PCI, 2014, 101 pages, retrieved from https://www.pcisecuritystandards.org/documents/PCI_PIN_Security_Requirements_v2.pdf. [cited by applicant]
“PCI Security Standards Council Publishes Security Requirements for Software-Based PIN Entry on Cots Devices New PCI Standard to Drive Development of Secure Software-Based PIN Entry Solutions for EMV Contact and Contact… [cited by applicant]
Sela, “ODA for Transactions: What to Know for U.S. Payment Infrastructures”, B2, 2017, 4 pages, retrieved from https://b2ps.com/company/newsroom/article/oda-for-transactions-what-to-know-for-us-payment-infrastructures/. [cited by applicant]
Steel, “Formal Analysis of PIN Block Attacks”, ScienceDirect, 2006, 14 pages, retrieved from https://www.sciencedirect.com/science/article/pii/S0304397506005810. [cited by applicant]
Van Den Breekel et al., “EMV in a nutshell”, 2016, 37 pages, retrieved from https://www.cs.ru.nl/˜erikpoll/papers/EMVtechreport.pdf. [cited by applicant]
“Visa Chip Card Update: Jun. 2017”, Visa, 2017, 1 page, retrieved from https://usa.visa.com/dam/VCOM/global/visa-everywhere/documents/visa-chip-stats-infographic-jun17.pdf. [cited by applicant]
“Visa Fact Sheet”, Visa, 2018, 1 page, retrieved from https://web.archive.org/web/20181202125512/https://usa.visa.com/dam/VCOM/download/corporate/media/visanet-technology/aboutvisafactsheet.pdf. [cited by applicant]
“Visa Minimum U.S. Online Only Terminal Configuration”, Visa, 2017, 5 pages, retrieved from https://usa.visa.com/dam/VCOM/regional/na/us/run-your-business/documents/visa-minimum-us-online-only-terminal-configuration.pdf. [cited by applicant]
“Visa Recommended Practices for EMV Chip Implementation in the U.S.”, Visa, 2012, 10 pages, retrieved from https://technologypartner.visa.com/Download.aspx?id=153. [cited by applicant]
Cited By (1)
US 12,554,601