IP Library Granted Patent US 9,294,268
Granted Patent B2
US 9,294,268 · App. 14/286,881 · Granted Mar 22, 2016

System and method for variable length encryption

Inventors: Clay von Mueller (San Diego, CA); Mihir Bellare (San Diego, CA); Scott R. Yale (La Mesa, CA); Patrick K. Hazel (Rancho Santa Fe, CA); Paul Elbridge Catinella (San Diego, CA)
Assignee: VeriFone, Inc.
H04L9/0822G06Q20/12G06Q20/3823G06Q20/38215H04L9/0625H04L9/0866H04L9/3226H04L9/3234H04L9/3247G06Q2220/00H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,294,268
App. No.
14/286,881
Granted
Mar 22, 2016
Kind
B2
Abstract

Systems and methods for performing a secure transaction provided. In one embodiment, the method includes: reading data on a command token, reading data on a token; encrypting the token data with a key; encrypting an authentication data with a clear text token data; and transmitting the encrypted authentication data with the encrypted token data to a remote device.

Claims (32)

1. A method of encrypting token data at a token reader comprising a processor, the method comprising the token reader:

receiving clear text token data from a token;

selecting a symbol set corresponding to the clear text token data, wherein the symbol set is an arbitrary string symbol set comprising a plurality of members, wherein each of the plurality of members represents a data element in the clear text token data;

defining a first portion and a second portion of the clear text token data;

generating an encryption mask based on encrypting the second portion of the clear text token data using a key; and

encrypting the clear text data by applying the encryption mask to the first portion using a modulo operation while not encrypting the second portion, thereby resulting in encrypted token data comprising an encrypted first portion and an unencrypted second portion;

wherein the encrypted token data has the same format and length as the clear text token data, and uses the same symbol set as the clear text token data.

2. The method of claim 1 , wherein the modulo operation is a modulo addition.

3. The method of claim 1 , wherein the modulo operation is a modulo subtraction.

4. The method of claim 1 , wherein the clear text token data comprises a primary account number (PANS).

5. The method of claim 4 , wherein the clear text token data comprises discretionary data.

6. The method of claim 1 , wherein the arbitrary string symbol set comprises 26 characters that represent letters of an alphabet and wherein the modulo operation is a modulo 26 operation.

7. The method of claim 1 , wherein encrypting the second portion using the key involves a multi-alphabet string cipher.

8. The method of claim 1 , further comprising the token reader transmitting the encrypted token data to a remote device over a network.

9. The method of claim 8 , wherein the network is a public network.

10. The method of claim 1 , wherein the token reader is a point-of-sale terminal and the clear text token data comprises bank card data.

11. The method of claim 1 , further comprising the token reader translating the first portion of the clear text token data prior to encrypting the first portion of the token data, and wherein encrypting the first portion of the clear text token data comprises encrypting the translated first portion of the clear text token data by applying the encryption mask.

12. The method of claim 11 , wherein translating the first portion of the clear text token data comprises substitution.

13. The method of claim 1 , wherein the received clear text token data is clear text token data from a bank card, and wherein the first portion of the clear text token data comprises a portion of an account number, and the second portion of the clear text token data comprises a bank identification number.

14. The method of claim 13 , wherein the encryption mask is created by encrypting the bank identification number.

15. A method of decrypting encrypted token data at a secure transaction device comprising a network interface coupled to a transaction processing network, the method comprising the secure transaction device:

receiving encrypted token data over the transaction processing network;

selecting a symbol set used to encrypt clear text token data to encrypted token data, wherein the symbol set is an arbitrary string symbol set comprising a plurality of members, wherein each of the plurality of members represents a data element in the clear text token data;

defining a first portion and a second portion of the encrypted token data, where the encrypted token data comprises an encrypted first portion and an unencrypted second portion;

generating an encryption mask based on encrypting the second portion of the encrypted token data using a key; and

decrypting the encrypted token data by applying the encryption mask to the first portion using a modulo operation, thereby resulting in clear text token data comprising a decrypted first portion and an unencrypted second portion;

wherein the encrypted token data has the same format and length as the clear text token data, and uses the same symbol set as the clear text token data.

16. The method of claim 15 , wherein the modulo operation is a modulo addition.

17. The method of claim 15 , wherein the modulo operation is a modulo subtraction.

18. The method of claim 15 , wherein the modulo operation is complementary to a second modulo operation used during the encryption of the clear text token data to encrypted token data.

19. The method of claim 15 , wherein the received clear text token data is clear text token data from a bank card, and wherein the decrypted first portion of the clear text token data comprises a portion of an account number, and the unencrypted second portion of the clear text token data comprises a bank identification number.

20. The method of claim 19 , wherein the encryption mask is generated by encrypting the bank identification number.

Assignments (8)
ASSIGNMENT OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT R/F 046920-0784 Recorded Apr 28, 2025
From: UBS AG, STAMFORD BRANCH, AS SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS ASSIGNOR
To: BARCLAYS BANK PLC, AS ASSIGNEE
Reel/Frame 071095/0667 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 46920/0817 Recorded May 10, 2019
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: VERIFONE SYSTEMS, INC.; VERIFONE, INC.; HYPERCOM CORPORATION
Reel/Frame 049150/0190 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 23, 2018
From: VERIFONE, INC.; HYPERCOM CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH AS COLLATERAL AGENT
Reel/Frame 046920/0784 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Aug 23, 2018
From: VERIFONE, INC.; HYPERCOM CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH AS COLLATERAL AGENT
Reel/Frame 046920/0817 →
RELEASE (R033282F0757) Recorded Aug 21, 2018
From: JPMORGAN CHASE BANK, N.A.
To: VERIFONE, INC.; HYPERCOM CORPORATION; GLOBAL BAY MOBILE TECHNOLOGIES, INC.
Reel/Frame 046864/0909 →
CHANGE OF ADDRESS Recorded May 30, 2016
From: VERIFONE, INC.
To: VERIFONE, INC.
Reel/Frame 038845/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 6, 2014
From: VON MUELLER, CLAY; BELLARE, MIHIR; YALE, SCOTT R.; HAZEL, PATRICK K.; CATINELLA, PAUL ELBRIDGE
To: VERIFONE, INC.
Reel/Frame 033480/0501 →
SECURITY INTEREST Recorded Jul 9, 2014
From: VERIFONE, INC.; HYPERCOM CORPORATION; GLOBAL BAY MOBILE TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 033282/0757 →
Continuity (4)
Division 13081450 · Apr 6, 2011
Continuation In Part 11550387 · Oct 17, 2006
Continuation In Part 12481504 · Jun 9, 2009
Related Publication 20140344580A1 · Nov 20, 2014