IP Library › Granted Patent US 11,151,561
Granted Patent B2
US 11,151,561 · App. 16/312,871 · Granted Oct 19, 2021

Systems and methods for validating transmissions over communication channels

Inventors: Carlos Eduardo Oliveira Do Valle Silvestre (East Sussex, GB); Jonathan Ward Lupton (West Sussex, GB)
Assignee: American Express Travel Related Services Company, Inc.
G06Q20/401G06Q20/3278G06Q20/3823H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,151,561
App. No.
16/312,871
Granted
Oct 19, 2021
Kind
B2
Abstract

An authentication system may receive an authentication MAC, an integrity MAC, and data transmitted from a payment application and a payment terminal. A local integrity MAC may be generated using the data as an input to a first cryptographic operation. The system may compare the local integrity MAC to the received integrity MAC to authenticate the received integrity MAC. A local authentication MAC may be generated using a second cryptographic operation and compare the local authentication MAC to the received authentication MAC. The system may authenticate the payment application in response to a successful authentication of at least one of the received authentication MAC or the received integrity MAC.

Claims (37)

1. A method comprising:

receiving, by a processor, an authentication MAC, an integrity MAC, and transaction data transmitted from a payment application and a payment terminal, wherein the integrity MAC is generated from the transaction data using a cryptography key stored in the payment application and the authentication MAC is generated independently from the transaction data;

generating, by the processor, a local integrity MAC using the transaction data as an input to a first cryptographic operation using a copy of the cryptography key accessible by the processor;

determining, by the processor, that the received integrity MAC fans to match the local integrity MAC by comparing the local integrity MAC to the received integrity MAC;

retrieving, by the processor, an input to a second cryptographic operation, wherein the input to the second cryptographic operation is generated independently from the transaction data received by the processor from the payment application and the payment terminal;

generating, by the processor, a local authentication MAC using the second cryptographic operation;

authenticating, by the processor, the received authentication MAC in response to the received integrity MAC failing to match the local integrity MAC by comparing the local authentication MAC to the received authentication MAC to determine that the local authentication MAC matches the received authentication MAC; and

authenticating, by the processor, the payment application in response to authenticating the received authentication MAC.

2. The method of claim 1 , wherein the input to the second cryptographic operation comprises data replicable at the issuer host.

3. The method of claim 1 , wherein the first cryptographic operation comprises an authentication encryption mode.

4. The method of claim 1 , further comprising approving a transaction in response to a successful authentication of the authentication MAC.

5. The method of claim 1 , wherein the authentication MAC and the integrity MAC are transmitted from the payment application, to the payment terminal, through a payment network, and to the processor.

6. A computer-based system comprising:

a processor;

a tangible, non-transitory memory configured to communicate with the processor, the tangible, non-transitory memory having instructions stored thereon that, in response to execution by the processor, cause the processor to perform operations comprising:

receiving, by the processor, an authentication MAC, an integrity MAC, and transaction data transmitted from a payment application and a payment terminal, wherein the integrity MAC is generated from the transaction data using a cryptography key stored in the payment application and the authentication MAC is generated independently from the transaction data;

generating, by the processor, a local integrity MAC using the transaction data as an input to a first cryptographic operation using a copy of the cryptography key accessible by the processor;

determining, by the processor, that the received integrity MAC fails to match the local integrity MAC by comparing the local integrity MAC to the received integrity MAC;

retrieving, by the processor, an input to a second cryptographic operation, wherein the input to the second cryptographic operation is generated independently from the transaction data received by the processor from the payment application and the payment terminal;

generating, by the processor, a local authentication MAC using the second cryptographic operation;

authenticating, by the processor, the received authentication MAC in response to the received integrity MAC failing to match the local integrity MAC by comparing the local authentication MAC to the received authentication MAC to determine that the local authentication MAC matches the received authentication MAC; and

authenticating, by the processor, the payment application in response to authenticating the received authentication MAC.

7. The computer-based system of claim 6 , wherein the input to the second cryptographic operation comprises data replicable at the issuer host.

8. The computer-based system of claim 6 , wherein the first cryptographic operation comprises an authentication encryption mode.

9. The computer-based system of claim 6 , further comprising approving a transaction in response to a successful authentication of the authentication MAC.

10. The computer-based system of claim 6 , wherein the authentication MAC, the integrity MAC, and the transaction data are transmitted from the payment application, to the payment terminal, through a payment network, and to the processor.

11. An article of manufacture including a non-transitory, tangible computer readable storage medium having instructions stored thereon that, in response to execution by a processor, cause the processor to perform operations comprising:

receiving, by the processor, an authentication MAC, an integrity MAC, and transaction data transmitted from a payment application and a payment terminal, wherein the integrity MAC is generated from the transaction data using a cryptography key stored in the payment application and the authentication MAC is generated independently from the transaction data;

generating, by the processor, a local integrity MAC using the transaction data as an input to a first cryptographic operation using a copy of the cryptography key accessible by the processor;

determining, by the processor, that the received integrity MAC fails to match the local integrity MAC by comparing the local integrity MAC to the received integrity MAC;

retrieving, by the processor, an input to a second cryptographic operation, wherein the input to the second cryptographic operation is generated independently from the transaction data received by the processor from the payment application and the payment terminal;

generating, by the processor, a local authentication MAC using the second cryptographic operation;

authenticating, by the processor, the received authentication MAC in response to the received integrity MAC failing to match the local integrity MAC by comparing the local authentication MAC to the received authentication MAC to determine that the local authentication MAC matches the received authentication MAC; and

authenticating, by the processor, the payment application in response to authenticating the received authentication MAC.

12. The article of claim 11 , wherein the input to the second cryptographic operation may comprise data replicable at the issuer host.

13. The article of claim 11 , wherein the first cryptographic operation comprises an authentication encryption mode.

14. The article of claim 11 , further comprising approving a transaction in response to a successful authentication of the authentication MAC.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2020
From: SILVESTRE, CARLOS EDUARDO OLIVEIRA DO VALLE; LUPTON, JONATHAN WARD
To: AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.
Reel/Frame 051858/0858 →
Continuity (1)
Related Publication 20190172064A1 · Jun 6, 2019