IP Library Granted Patent US 12,341,875
Granted Patent B2
US 12,341,875 · App. 18/598,621 · Granted Jun 24, 2025

Efficient authentic communication system and method

Inventors: Brian Sullivan (Amersham, GB); Dinah Sloan (San Jose, CA); Christian Aabye (Redwood City, CA); Hao Ngo (San Jose, CA); Yuexi Chen (Foster City, CA); Fahimeh Rezaei (Mountain View, CA)
Assignee: Visa International Service Association
H04L9/0825H04L9/0869H04L9/3263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,341,875
App. No.
18/598,621
Granted
Jun 24, 2025
Kind
B2
Abstract

A method is disclosed. The method comprises transmitting, by an access device to a communication device, a resource provider certificate and an access device certificate. Then, establishing a secure channel between the access device and the communication device using data from the resource provider certificate and the access device certificate. Then, transmitting to or receiving data from the communication device using the secure channel.

Claims (49)

1. A communication device comprising:

a processor;

a memory device; and

a computer-readable medium coupled to the processor, the computer-readable medium comprising code executable by the processor for implementing a method comprising:

receiving, from an access device, a resource provider certificate and an access device certificate;

establishing a secure channel between the access device and the communication device using data from the resource provider certificate and the access device certificate; and

transmitting to or receiving data from the access device using the secure channel,

wherein before the secure channel is established, the method further comprises:

determining a resource provider public key using data in the resource provider certificate;

determining an access device public key using data in the access device certificate and the resource provider public key; and

deriving a first session key using the access device public key and a communication device private key, wherein the first session key is used to form the secure channel.

2. The communication device of claim 1 , wherein before the secure channel is established, the access device:

receives a communication device public key; and

determines a second session key corresponding to the first session key using an access device private key and the communication device public key.

3. The communication device of claim 2 , wherein the communication device public key is a blinded public key.

4. The communication device of claim 3 , wherein the first and second session key are also each determined using an unpredictable number and a random number.

5. The communication device of claim 1 , wherein the access device:

receives, from a resource provider computer, the resource provider certificate and the access device certificate.

6. The communication device of claim 1 , wherein the access device and the communication device form the secure channel without authenticating each other.

7. The method of claim 1 , wherein the method further comprises:

providing at least one certificate to the access device, wherein the access device:

verifies the at least one certificate, thereby verifying the authenticity of data received from the communication device.

8. A method comprising:

transmitting, by a resource provider computer to a certificate authority computer, certificate request values;

receiving, by the resource provider computer from the certificate authority computer, a resource provider certificate;

creating, by the resource provider computer, an access device certificate;

generating, by the resource provider computer, an access device public key and an access device private key; and

transmitting, by the resource provider computer to an access device, the access device certificate, the resource provider certificate, the access device public key and the access device private key, wherein the access device public key is derived using a resource provider public key associated with the resource provider computer.

9. The method of claim 8 , wherein the certificate request values comprise a first elliptic curve cryptography point and a resource provider identifier, wherein the certificate authority computer:

generates the resource provider certificate using at least the certificate request values.

10. The method of claim 8 , wherein the resource provider computer creates more than one access device certificate for more than one access device.

11. A resource provider computer comprising:

a processor;

a memory device; and

a computer-readable medium coupled to the processor, the computer-readable medium comprising code executable by the processor for implementing a method comprising:

transmitting, to a certificate authority computer, certificate request values;

receiving, from the certificate authority computer, a resource provider certificate;

creating an access device certificate;

generating an access device public key and an access device private key; and

transmitting, to an access device, the access device certificate, the resource provider certificate, the access device public key and the access device private key, wherein the access device public key is derived using a resource provider public key associated with the resource provider computer.

12. The resource provider computer of claim 11 , wherein the resource provider computer is a merchant computer.

13. The resource provider computer of claim 11 , wherein the certificate request values comprise a first elliptic curve cryptography point and a resource provider identifier, wherein the certificate authority computer:

generates the resource provider certificate using at least the certificate request values.

14. The resource provider computer of claim 11 , wherein the resource provider computer creates more than one access device certificate for more than one access device.

15. The resource provider computer of claim 11 , wherein the access device is a POS terminal.

16. The resource provider computer of claim 11 , wherein the resource provider computer is operated by a resource provider that provides resources to a user.

17. The resource provider computer of claim 11 , wherein the certificate request values comprise a resource provider identifier.

18. The resource provider computer of claim 11 , wherein the certificate request values comprise an elliptic curve cryptography point.

19. The resource provider computer of claim 11 , wherein the certificate request values comprise a merchant identifier and an ECC (elliptic curve cryptography) point derived from a random number.

Continuity (2)
Continuation 17288441
Related Publication 20240214186A1 · Jun 27, 2024
References Cited (30)
US 8549300B1 · Kumar et al. · 2013 [cited by applicant]
US 8850208B1 · Parkinson · 2014 [cited by applicant]
US 20040030887A1 · Harrisville-Wolff et al. · 2004 [cited by applicant]
US 20120233457A1 · Zaverucha · 2012 [cited by examiner]
US 20130268771A1 · Blankenbeckler · 2013 [cited by examiner]
US 20140052993A1 · Isozaki · 2014 [cited by examiner]
US 20140289130A1 · Savolainen et al. · 2014 [cited by applicant]
US 20140337234A1 · Tang et al. · 2014 [cited by applicant]
US 20150200774A1 · Le Saint · 2015 [cited by applicant]
US 20150372811A1 · Le Saint et al. · 2015 [cited by applicant]
US 20160065370A1 · Le Saint · 2016 [cited by applicant]
US 20170093851A1 · Allen · 2017 [cited by examiner]
US 20170221056A1 · Karpenko et al. · 2017 [cited by applicant]
US 20170228726A1 · Bohanan et al. · 2017 [cited by applicant]
US 20170338965A1 · Gaddam · 2017 [cited by examiner]
US 20230097712A1 · Sullivan et al. · 2023 [cited by applicant]
CN 101729244A · 2010 [cited by applicant]
CN 105960776A · 2016 [cited by applicant]
“Digital Signature Standard (DSS)”, Federal Information Processing Standards Publication 186-4, Jul. 2013, 130 pages. [cited by applicant]
U.S. Appl. No. 17/288,441 , “Corrected Notice of Allowability”, filed Dec. 15, 2023, 2 pages. [cited by applicant]
U.S. Appl. No. 17/288,441 , “Non-Final Office Action”, filed Jun. 23, 2023, 23 pages. [cited by applicant]
U.S. Appl. No. 17/288,441 , “Notice of Allowance”, filed Oct. 3, 2023, 11 pages. [cited by applicant]
U.S. Appl. No. 17/288,441 , “Notice of Allowance”, filed Jan. 26, 2024, 12 pages. [cited by applicant]
Campagna, “SEC 4: Elliptic Curve Qu-Vanstone Implicit Certificate Scheme (ECQV)”, Certicom Research, Version 1.0, Jan. 24, 2013, 32 pages. [cited by applicant]
CN201880099142.4 , “Office Action”, Oct. 8, 2023, 16 pages. [cited by applicant]
EP18938937.2 , “Extended European Search Report”, Oct. 7, 2021, 11 pages. [cited by applicant]
PCT/US2018/057973 , “International Preliminary Report on Patentability”, May 14, 2021, 10 pages. [cited by applicant]
PCT/US2018/057973 , “International Search Report and Written Opinion”, Jul. 1, 2019, 13 pages. [cited by applicant]
SG11202104170P “Written Opinion”, Feb. 28, 2023, 10 pages. [cited by applicant]
CN201880099142.4 , “Office Action”, Apr. 12, 2024, 5 pages. [cited by applicant]