IP Library Granted Patent US 9,922,322
Granted Patent B2
US 9,922,322 · App. 15/004,705 · Granted Mar 20, 2018

Cloud-based transactions with magnetic secure transmission

Inventors: Christian Flurscheim (Walnut Creek, CA); Christian Aabye (Foster City, CA)
Assignee: Visa International Service Association
G06Q20/3821G06Q20/32G06Q20/322G06Q20/327G06Q20/3278G06Q20/382G06Q20/3829G06Q20/401H04L9/0869H04L63/0838G06Q2220/00H04L63/0428H04L2209/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,922,322
App. No.
15/004,705
Granted
Mar 20, 2018
Kind
B2
Abstract

Techniques for enhancing the security of a communication device when conducting a transaction using the communication device may include using a limited-use key (LUK) to generate a transaction cryptogram, and transmitting a token instead of a real account identifier and the transaction cryptogram to an access device to conduct the transaction. The token and the transaction cryptogram can be transmitted to a magnetic stripe reader by generating an emulated magnetic signal. The LUK may be associated with a set of one or more limited-use thresholds that limits usage of the LUK, and the transaction can be authorized based on at least whether usage of the LUK has exceeded the set of one or more limited-use thresholds.

Claims (43)

1. A method for enhancing security of a communication device when conducting a transaction using the communication device, the method comprising:

receiving, from a remote computer, a token that is provisioned for conducting transactions;

receiving, by the communication device, a limited-use key (LUK) that is associated with a set of one or more limited-use thresholds that limits usage of the LUK;

requesting, by an application executing in an applications environment of the communication device, a transaction cryptogram from a trusted execution environment of the communication device;

generating, by the trusted execution environment of the communication device, a transaction cryptogram using the LUK;

providing the transaction cryptogram to a magnetic stripe transmission driver executing in the trusted execution environment, wherein the providing is performed by a crypto engine within the trusted execution environment communicating the transaction cryptogram to the magnetic stripe transmission driver;

generating, by an inductive coil controlled by the magnetic stripe transmission driver, an emulated magnetic signal representing data that includes the transaction cryptogram and the token instead of a real account identifier;

wherein the inductive coil for generating the emulated magnetic signal representing the data further provides function for wireless charging of the communication device;

transmitting the emulated magnetic signal to a magnetic stripe reader of an access device using the inductive coil of the communication device instead of a magnetic stripe to conduct the transaction; and

wherein the transaction is authorized based on at least whether the usage of the LUK is within the set of one or more limited-use thresholds.

2. The method of claim 1 , wherein the token is also usable for conducting contactless reader transactions.

3. The method of claim 1 , wherein the emulated magnetic signal is generated in response to receiving user input on the communication device to initiate the transaction with the access device.

4. The method of claim 1 , wherein the emulated magnetic signal is generated in response to receiving user input on the communication device to initiate the transaction, and without detecting a contactless transceiver in proximity to the communication device when the user input is received.

5. The method of claim 1 , wherein the transaction cryptogram is generated by encrypting at least a transaction counter value with the LUK.

6. The method of claim 5 , wherein the transaction cryptogram is generated by encrypting the transaction counter value and a predetermined static string with the LUK.

7. The method of claim 5 , wherein the transaction counter value is incremented for each magnetic stripe reader transaction conducted by a mobile application of the communication device.

8. The method of claim 5 , wherein the transaction counter value is incremented for each magnetic stripe reader transaction and each contactless reader transaction conducted by a mobile application of the communication device.

9. The method of claim 1 , wherein the LUK is generated by encrypting a key index that includes at least one of:

time information indicating when the LUK is generated; and

a replenishment counter value indicating a number of times the LUK has been replenished.

10. A communication device comprising:

an inductive coil;

a processor; and

a memory coupled to the processor and storing a mobile application that performs operations for enhancing security of the communication device when conducting transactions using the communication device, the operations including:

receiving a token that is provisioned for conducting transactions;

receiving a limited-use key (LUK) that is associated with a set of one or more limited-use thresholds that limits usage of the LUK;

requesting a transaction cryptogram from a trusted execution environment of the communication device;

generating a transaction cryptogram using the LUK, the transaction cryptogram being generated in the trusted execution environment of the communication device;

providing the transaction cryptogram to a magnetic stripe transmission driver executing in the trusted execution environment, wherein the providing is performed by a crypto engine within the trusted execution environment communicating the transaction cryptogram to the magnetic stripe transmission driver;

generating, by the inductive coil controlled by the magnetic stripe transmission driver, an emulated magnetic signal representing data that includes the transaction cryptogram and the token instead of a real account identifier;

wherein the inductive coil for generating the emulated magnetic signal representing the data further provides function for wireless charging of the communication device;

transmitting the emulated magnetic signal to a magnetic stripe reader of an access device using the inductive coil of the communication device instead of a magnetic stripe to conduct the transaction; and

wherein the transaction is authorized based on at least whether the usage of the LUK is within the set of one or more limited-use thresholds.

11. The communication device of claim 10 , wherein the token is also usable for conducting contactless reader transactions.

12. The communication device of claim 10 , wherein the emulated magnetic signal is generated in response to receiving user input on the communication device to initiate the transaction with the access device.

13. The communication device of claim 10 , wherein the emulated magnetic signal is generated in response to receiving user input on the communication device to initiate the transaction, and without detecting a contactless transceiver in proximity to the communication device when the user input is received.

14. The communication device of claim 10 , wherein the transaction cryptogram is generated by encrypting at least a transaction counter value with the LUK.

15. The communication device of claim 14 , wherein the transaction cryptogram is generated by encrypting the transaction counter value and a predetermined static string with the LUK.

16. The communication device of claim 14 , wherein the transaction counter value is incremented for each magnetic stripe reader transaction conducted by the mobile application of the communication device.

17. The communication device of claim 14 , wherein the transaction counter value is incremented for each magnetic stripe reader transaction and each contactless reader transaction conducted by the mobile application of the communication device.

18. The communication device of claim 10 , wherein the LUK is generated by encrypting a key index that includes at least one of:

time information indicating when the LUK is generated; and

a replenishment counter value indicating a number of times the LUK has been replenished.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 16, 2016
From: FLURSCHEIM, CHRISTIAN; AABYE, CHRISTIAN
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 037742/0965 →
Continuity (7)
Continuation In Part 14577837 · Dec 19, 2014
Provisional Application 62106442 · Jan 22, 2015
Provisional Application 61918643 · Dec 19, 2013
Provisional Application 61941227 · Feb 18, 2014
Provisional Application 61982169 · Apr 21, 2014
Provisional Application 61983635 · Apr 24, 2014
Related Publication 20160140545A1 · May 19, 2016