IP Library › Granted Patent US 12,210,658
Granted Patent B2
US 12,210,658 · App. 18/458,803 · Granted Jan 28, 2025

Executing entity-specific cryptographic code in a cryptographic

Inventors: Wael Ibrahim (San Diego, CA); Manish K. Deliwala (Chandler, AZ); Manik Biswas (Burgess Hill, GB); Subrahmanyam Venakata Vishnuvajhala (Phoenix, AZ); Andrew Lei (Brooklyn, NY)
Assignee: American Express Travel Related Services Company, Inc.
G06F21/72G06F21/602H04L9/3234
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,210,658
App. No.
18/458,803
Granted
Jan 28, 2025
Kind
B2
Abstract

Disclosed are various embodiments for executing entity-specific cryptographic code in a cryptographic coprocessor. In one embodiment, an exemplary method comprises transmitting, from an entity service to a client device, a key identifier and encrypted code that implements a cryptographic algorithm, wherein the encrypted code further includes an encryption key, wherein the key identifier identifies a particular root key that is associated with the entity service and is stored with a cryptographic coprocessor of the client device; receiving, by the entity service from the client device, a cryptogram that includes information encrypted using the cryptographic algorithm and the encryption key; and decrypting, by the entity service, the cryptogram using the encryption key.

Claims (20)

1. A system comprising: a computing device comprising a processor, a memory, and a cryptographic coprocessor; and machine-readable instructions stored in the memory that, when executed by the processor, cause the computing device to at least: transmit, from an entity service to a client device, a key identifier and encrypted code that implements a cryptographic algorithm, wherein the encrypted code further includes an encryption key, wherein the key identifier identifies a particular root key for decrypting the encrypted code that is associated with the entity service and is stored within a cryptographic coprocessor of the client device; receive, by the entity service from the client device, a cryptogram that includes information encrypted using the cryptographic algorithm and the encryption key; and decrypt, by the entity service, the cryptogram using the encryption key.

2. The system of claim 1 , wherein the information encrypted using the cryptographic algorithm and the encryption key includes a payment transaction, wherein the machine-readable instructions further cause the computing device to process the payment transaction after being decrypted using the encryption key.

3. The system of claim 1 , wherein a digital signature is transmitted with the encrypted code to the client device, wherein the digital signature verifies an authenticity of the encrypted code.

4. The system of claim 3 , wherein a header of the digital signature includes the key identifier.

5. The system of claim 1 , wherein the encryption key comprises a symmetric encryption key.

6. The system of claim 1 , wherein the encryption key comprises an asymmetric encryption key.

7. The system of claim 1 , wherein the machine-readable instructions further cause the computing device to transmit encrypted data to the client device before transmitting the encrypted code to the client device, wherein the encrypted data is encrypted using the cryptographic algorithm and the encryption key.

8. The system of claim 1 , wherein the machine-readable instructions further cause the computing device to transmit encrypted data to the client device after transmitting the encrypted code to the client device, wherein the encrypted data is encrypted using the cryptographic algorithm and the encryption key.

9. The system of claim 1 , wherein the encryption key comprises a root key that is associated with an entity that generated the encrypted code, wherein the entity provides the entity service.

10. A method comprising: transmitting, from an entity service to a client device, a key identifier and encrypted code that implements a cryptographic algorithm, wherein the encrypted code further includes an encryption key, wherein the key identifier identifies a particular root key for decrypting the encrypted code that is associated with the entity service and is stored within a cryptographic coprocessor of the client device; receiving, by the entity service from the client device, a cryptogram that includes information encrypted using the cryptographic algorithm and the encryption key; and decrypting, by the entity service, the cryptogram using the encryption key.

11. The method of claim 10 , wherein the information encrypted using the cryptographic algorithm and the encryption key includes a payment transaction, the method further comprising processing the payment transaction after being decrypted using the encryption key.

12. The method of claim 10 , wherein a digital signature is transmitted with the encrypted code to the client device, wherein the digital signature verifies an authenticity of the encrypted code.

13. The method of claim 12 , wherein a header of the digital signature includes the key identifier.

14. The method of claim 10 , wherein the encryption key comprises a symmetric encryption key.

15. The method of claim 10 , wherein the encryption key comprises an asymmetric encryption key.

16. The method of claim 10 , further comprising transmitting encrypted data to the client device before transmitting the encrypted code to the client device, wherein the encrypted data is encrypted using the cryptographic algorithm and the encryption key.

17. The method of claim 10 , further comprising transmitting encrypted data to the client device after transmitting the encrypted code to the client device, wherein the encrypted data is encrypted using the cryptographic algorithm and the encryption key.

18. The method of claim 10 , wherein the encryption key comprises a root key that is associated with an entity that generated the encrypted code, wherein the entity provides the entity service.

19. A non-transitory computer-readable medium comprising machine-readable instructions that, when executed by a computing device, cause the computing device to at least: transmit, from an entity service to a client device, a key identifier and encrypted code that implements a cryptographic algorithm, wherein the encrypted code further includes an encryption key, wherein the key identifier identifies a particular root key for decrypting the encrypted code that is associated with the entity service and is stored within a cryptographic coprocessor of the client device; receive, by the entity service from the client device, a cryptogram that includes information encrypted using the cryptographic algorithm and the encryption key; and decrypt, by the entity service, the cryptogram using the encryption key.

20. The non-transitory computer-readable medium of claim 19 , wherein the information encrypted using the cryptographic algorithm and the encryption key includes a payment transaction, wherein the machine-readable instructions further cause the computing device to process the payment transaction after being decrypted using the encryption key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2023
From: IBRAHIM, WAEL; DELIWALA, MANISH K.; BISWAS, MANIK; VISHNUVAJHALA, SUBRAHMANYAM VENAKATA; LEI, ANDREW
To: AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.
Reel/Frame 065305/0244 →
Continuity (4)
Continuation 17749998 · May 20, 2022
Continuation 16668973 · Oct 30, 2019
Provisional Application 62914275 · Oct 11, 2019
Related Publication 20240232441A1 · Jul 11, 2024
References Cited (21)
US 7657033B2 · Fiske · 2010 [cited by applicant]
US 8010802B2 · Kang et al. · 2011 [cited by applicant]
US 8756417B1 · Gardner · 2014 [cited by examiner]
US 10735190B1 · Khare · 2020 [cited by examiner]
US 20070205258A1 · Self · 2007 [cited by examiner]
US 20090319800A1 · Kang et al. · 2009 [cited by applicant]
US 20110131420A1 · Ali et al. · 2011 [cited by applicant]
US 20130118555A1 · Samuels · 2013 [cited by applicant]
US 20150302397A1 · Kalgi · 2015 [cited by applicant]
US 20160352509A1 · Wu et al. · 2016 [cited by applicant]
US 20160381010A1 · Bhandari · 2016 [cited by examiner]
US 20170010875A1 · Martinez · 2017 [cited by examiner]
US 20170250803A1 · Zhang et al. · 2017 [cited by applicant]
US 20170270528A1 · Prakash · 2017 [cited by examiner]
EP 1834438 · 2016 [cited by applicant]
JP 2001125481A2 · 2001 [cited by applicant]
JP 2001338271A · 2001 [cited by applicant]
JP 2004519050A · 2004 [cited by applicant]
KR 1020090059602 · 2009 [cited by applicant]
Written Opinion mailed on Jan. 15, 2024 for Singapore Patent Application No. 11202203365Q. [cited by applicant]
Notice to Submit Response in KR application No. 10-2022-7013092 dates Oct. 15, 2024. [cited by applicant]