IP Library Granted Patent US 12,450,601
Granted Patent B2
US 12,450,601 · App. 18/513,168 · Granted Oct 21, 2025

Derived unique token per transaction

Inventors: Phillip H. Griffin (Raleigh, NC); Jeffrey J. Stapleton (O'Fallon, MO)
Assignee: Wells Fargo Bank, N.A.
G06Q20/385G06F21/6263G06Q20/12G06Q20/3829G06Q20/4012H04L9/3213
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,450,601
App. No.
18/513,168
Granted
Oct 21, 2025
Kind
B2
Abstract

Example implementations include a method for using tokens between two entities including a client device and a server, by generating, by a first one-way function of the client device, a first intermediate value from a transaction count corresponding to a number of transactions involving an original data, the first intermediate value being unique to a first verification transaction at a server, generating, by a second one-way function of the client device, a second intermediate value from the first intermediate value, the second intermediate value being unique to a second verification transaction at the server, sending, by the client device, a first token based on the first intermediate value to the server to execute the first verification transaction, and sending, by the client device, a second token based on the second intermediate value to the server to execute the second verification transaction.

Claims (50)

1. A method for using tokens between two entities comprising a client device and a server, the method comprising:

generating, by a first one-way function of a client device, a first intermediate value from a number of transactions, the first intermediate value corresponding to a first verification transaction at a server;

generating, by a second one-way function of the client device, a second intermediate value from the first intermediate value, the second intermediate value corresponding to a second verification transaction at the server;

causing, by the client device and based on the first intermediate value, the server to execute the first verification transaction; and

causing, by the client device and based on the second intermediate value, the server to execute the second verification transaction.

2. The method of claim 1 , further comprising:

generating, by a first verification function of the client device, a first token from the first intermediate value.

3. The method of claim 2 , further comprising:

encrypting the first token.

4. The method of claim 3 , further comprising:

deleting, by the client device, the first intermediate value after the generating the second intermediate value.

5. The method of claim 2 , further comprising:

generating, by the client device, a first digital signature associated with the first token from a private key associated with the client device.

6. The method of claim 1 , further comprising:

generating, by a second verification function of the client device, a second token from the second intermediate value.

7. The method of claim 6 , further comprising:

encrypting the second token.

8. The method of claim 6 , further comprising:

generating, by the client device, a second digital signature associated with the second token from the private key.

9. The method of claim 1 , wherein the number of transactions corresponds to an original data that comprises one or more of a payment card number, a financial account number, a password, a social security number, a name, an address, an email address, any Personally Identifiable Information (PII), a security object, and a seed for key-generation.

10. The method of claim 9 , further comprising:

deleting, by the client device, the original data after the generating the first intermediate value.

11. The method of claim 1 , wherein the number of transactions corresponds to an original data that comprises one or more of a payment card number, a financial account number, a password, a social security number, a name, an address, an email address, any Personally Identifiable Information (PII), a security object, and a seed for key-generation.

12. A client device, comprising:

a network interface; and

a processing circuit configured to:

generate, by a first one-way function of a client device, a first intermediate value from a number of transactions, the first intermediate value corresponding to a first verification transaction at a server;

generate, by a second one-way function of the client device, a second intermediate value from the first intermediate value, the second intermediate value corresponding to a second verification transaction at the server;

cause, by the client device and based on the first intermediate value, the server to execute the first verification transaction; and

cause, by the client device and based on the second intermediate value, the server to execute the second verification transaction.

13. The device of claim 12 , wherein the processing circuit is further configured to:

generate, by a first verification function of the client device, a first token from the first intermediate value.

14. The device of claim 13 , wherein the processing circuit is further configured to:

encrypt the first token.

15. The device of claim 13 , wherein the processing circuit is further configured to:

generate, by the client device, a first digital signature associated with the first token from a private key associated with the client device.

16. The device of claim 12 , wherein the processing circuit is further configured to:

generate, by a second verification function of the client device, a second token from the second intermediate value.

17. The device of claim 16 , wherein the processing circuit is further configured to:

encrypt the second token.

18. The device of claim 16 , wherein the processing circuit is further configured to:

generate, by the client device, a second digital signature associated with the second token from the private key.

19. A server, comprising:

a network interface; and

a processing circuit configured to:

receive, at the server, a first token based on a first intermediate value, the first intermediate value being based on a number of transactions, the first intermediate value corresponding to a first verification transaction at the server, and the first intermediate value being generated by a first one-way function of the client device;

receive, at the server, a second token based on the second intermediate value, the second intermediate value being based on the first intermediate value, the second intermediate value corresponding to a second verification transaction at the server, and the second intermediate value being generated by a second one-way function of the client device;

execute a first verification transaction based on the first token; and

execute a second verification transaction based on the second token.

20. The server of claim 19 , wherein the number of transactions corresponds to an original data that comprises one or more of a payment card number, a financial account number, a password, a social security number, a name, an address, an email address, any Personally Identifiable Information (PII), a security object, and a seed for key-generation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 25, 2025
From: GRIFFIN, PHILLIP H.; STAPLETON, JEFFREY J.
To: WELLS FARGO BANK, N.A.
Reel/Frame 072378/0960 →
Continuity (4)
Continuation 17379509 · Jul 19, 2021
Continuation 16439325 · Jun 12, 2019
Continuation 15600512 · May 19, 2017
Related Publication 20240086909A1 · Mar 14, 2024
References Cited (52)
US 6128391A · Denno et al. · 2000 [cited by applicant]
US 7319987B1 · Hoffman et al. · 2008 [cited by applicant]
US 7353388B1 · Gilman et al. · 2008 [cited by applicant]
US 7526652B2 · Ziegler · 2009 [cited by applicant]
US 7548621B1 · Smith · 2009 [cited by examiner]
US 8737623B2 · Hart · 2014 [cited by applicant]
US 9106633B2 · Carnes · 2015 [cited by applicant]
US 9191208B2 · Yagisawa · 2015 [cited by applicant]
US 9461973B2 · Barnett et al. · 2016 [cited by applicant]
US 10326803B1 · Haney · 2019 [cited by applicant]
US 10581611B1 · Osborn et al. · 2020 [cited by applicant]
US 10679212B2 · Hayhow et al. · 2020 [cited by applicant]
US 11050555B2 · Liu · 2021 [cited by applicant]
US 20020198848A1 · Michener · 2002 [cited by examiner]
US 20030188158A1 · Kocher · 2003 [cited by applicant]
US 20040044739A1 · Ziegler · 2004 [cited by applicant]
US 20080040285A1 · Wankmueller · 2008 [cited by examiner]
US 20080189214A1 · Mueller et al. · 2008 [cited by applicant]
US 20080208758A1 · Spiker et al. · 2008 [cited by applicant]
US 20100125509A1 · Kranzley · 2010 [cited by examiner]
US 20110307710A1 · McGuire et al. · 2011 [cited by applicant]
US 20120191615A1 · Schibuk · 2012 [cited by applicant]
US 20130168450A1 · Von Mueller et al. · 2013 [cited by applicant]
US 20130198519A1 · Marien · 2013 [cited by applicant]
US 20130254117A1 · Von Mueller et al. · 2013 [cited by applicant]
US 20140108172A1 · Weber et al. · 2014 [cited by applicant]
US 20140164254A1 · Dimmick · 2014 [cited by applicant]
US 20140258132A1 · Swamy et al. · 2014 [cited by applicant]
US 20150019442A1 · Hird · 2015 [cited by examiner]
US 20150046340A1 · Dimmick · 2015 [cited by applicant]
US 20150142665A1 · Dicker · 2015 [cited by examiner]
US 20150142670A1 · Zloth et al. · 2015 [cited by applicant]
US 20150199682A1 · Kalgi et al. · 2015 [cited by applicant]
US 20150270961A1 · Barnett et al. · 2015 [cited by applicant]
US 20150332283A1 · Witchey · 2015 [cited by examiner]
US 20150339664A1 · Wong · 2015 [cited by examiner]
US 20160020906A1 · Nolte et al. · 2016 [cited by applicant]
US 20160027017A1 · Chitragar · 2016 [cited by examiner]
US 20160063781A1 · Whytock et al. · 2016 [cited by applicant]
US 20160125376A1 · Beatty et al. · 2016 [cited by applicant]
US 20160189136A1 · Mercille · 2016 [cited by applicant]
US 20160203496A1 · Guerrero et al. · 2016 [cited by applicant]
US 20160330027A1 · Ebrahimi · 2016 [cited by applicant]
US 20170147975A1 · Natarajan et al. · 2017 [cited by applicant]
US 20190188703A1 · Murray · 2019 [cited by applicant]
US 20190243961A1 · Ollivier · 2019 [cited by applicant]
US 20190312720A1 · Liu · 2019 [cited by applicant]
Brier et al., “A Forward-Secure Symmetric-Key Derivation Protocol How to Improve Classical DUKPT”, ASIACRYTP 2010, LNCS 6477, pp. 250-267. [cited by applicant]
Herrero-Collantes, Miguel, and Juan Carlos Garcia-Escartin. “Quantum random number generators.” Reviews of Modern Physics 89.1 (2017): 015004. (Year: 2017). [cited by applicant]
MagTek Mobile Payment Devices are Now iPhone 7 Ready, PRWeb ebooks, Seal Beach, CA; Sep. 12, 2016. http://www.prweb.com/releases/2016/09/prweb13676398.htm; 2 pages. [cited by applicant]
Saha et al., “Applicability of DUKPT Key Management Scheme to Cloud Wallet and other Mobile Payments”, International Journal of Computer Applications, Dec. 2014, 6 pages. [cited by applicant]
Sitek, Albert; “One-Time Code Cardholder Verification Method in Electronic Funds Transfer Transactions”, Annales UMCS Informatica A1 XIV, 2 (2014), pp. 46-59. [cited by applicant]