IP Library › Granted Patent US 12,500,874
Granted Patent B2
US 12,500,874 · App. 17/863,873 · Granted Dec 16, 2025

Secure and accurate provisioning system and method

Inventor: Madhuri Chandoor (San Jose, CA)
Assignee: Visa International Service Association
H04L63/0478H04L9/14H04L63/0435H04L63/0807H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,500,874
App. No.
17/863,873
Granted
Dec 16, 2025
Kind
B2
Abstract

A method and system for provisioning credentials is disclosed. The method includes receiving an encrypted data packet including a first passcode and credentials in encrypted form, and a second passcode. The second passcode is compared to a first passcode. If the passcodes match, then a server computer can transmit a token associated with the credentials to a service provider computer.

Claims (30)

1 . A method comprising:

receiving, by a service provider computer from an authorizing computer, an encrypted data packet comprising credentials and a first passcode, the encrypted data packet is generated by encrypting an encryption result using the first passcode, wherein the encryption result is generated by encrypting the credentials and the first passcode using a first key of a first key set, wherein the first passcode is generated by the authorizing computer upon receiving a request for service from a user device;

receiving, by the service provider computer, a second passcode from the user device, wherein the second passcode is generated by the authorizing computer along with the first passcode upon receiving the request for service from the user device and thereafter sent by the authorizing computer to the user device;

transmitting, by the service provider computer, the second passcode and the encrypted data packet to a processing computer, to cause the processing computer to decrypt the encrypted data packet by first using the second passcode, and subsequently a second key of the first key set to obtain the credentials and the first passcode, compare the first passcode to the second passcode, and in response to a match of the first passcode and the second passcode, provide access data associated with the credentials to the service provider computer; and

receiving, by the service provider computer from the processing computer, the access data associated with the credentials.

2 . The method of claim 1 , wherein the encrypted data packet is a double encrypted data packet.

3 . The method of claim 1 , wherein the access data comprises a token.

4 . The method of claim 1 , wherein

the first key and the second key are symmetric keys.

5 . A service provider computer comprising:

a processor; and

a computer readable medium, coupled to the processor, the computer readable medium comprising code, executable by the processor to implement a method including:

receiving, from an authorizing computer, an encrypted data packet comprising credentials and a first passcode, the encrypted data packet is generated by encrypting an encryption result using the first passcode, wherein the encryption result is generated by encrypting the credentials and the first passcode using a first key of a first key set, wherein the first passcode is generated by the authorizing computer upon receiving a request for service from a user device;

receiving a second passcode from the user device, wherein the second passcode is generated by the authorizing computer along with the first passcode upon receiving the request for service from the user device and thereafter sent by the authorizing computer to the user device;

transmitting the second passcode and the encrypted data packet to a processing computer, to cause the processing computer to decrypt the encrypted data packet by first using the second passcode, and subsequently a second key of the first key set to obtain the credentials and the first passcode, compare the first passcode to the second passcode, and in response to a match of the first passcode and the second passcode, provide access data associated with the credentials to the service provider computer; and

receiving, from the processing computer, the access data associated with the credentials.

6 . The service provider computer of claim 5 , wherein the encrypted data packet is a double encrypted data packet.

7 . The service provider computer of claim 5 , wherein the access data comprises a token.

8 . The service provider computer of claim 5 , wherein

the first key and the second key are symmetric keys.

9 . A method comprising:

receiving, by a processing computer, from a service provider computer, an encrypted data packet comprising credentials and a first passcode in an encrypted form, and a second passcode, the encrypted data packet is generated by encrypting an encryption result using the first passcode, wherein the encryption result is generated by encrypting the credentials and the first passcode using a first key of a first key set, wherein the first passcode is generated by an authorizing computer upon receiving a request for service from a user device and sent by the authorizing computer to the service provider computer, wherein the second passcode is generated by the authorizing computer along with the first passcode upon receiving the request for service from the user device and sent by the authorizing computer to the user device, and wherein the second passcode is thereafter sent by the user device to the service provider computer;

decrypting, by the processing computer, the encrypted data packet by first using the second passcode, and subsequently a second key of the first key set to obtain the credentials and the first passcode;

comparing, by the processing computer, the first passcode to the second passcode;

determining, by the processing computer that the first passcode and the second passcode match; and

transmitting, by the processing computer, access data associated with the credentials to the service provider computer.

10 . The method of claim 9 , wherein the service provider computer is a Web server computer that operates a Website.

11 . The method of claim 9 , wherein the encrypted data packet is double encrypted data packet.

12 . The method of claim 11 , wherein the decrypting the double encrypted data packet further comprises decrypting the double encrypted data packet with the second passcode to form a single encrypted data packet, and then decrypting the single encrypted data packet with the second key.

13 . The method of claim 11 , wherein the access data comprises a token.

Continuity (3)
Continuation 16645755
Provisional Application 62557315 · Sep 12, 2017
Related Publication 20220353253A1 · Nov 3, 2022
References Cited (33)
US 5091939A · Cole et al. · 1992 [cited by applicant]
US 7958544B2 · Chen et al. · 2011 [cited by applicant]
US 8224852B2 · Falk et al. · 2012 [cited by applicant]
US 8385544B2 · Kobayashi · 2013 [cited by applicant]
US 9166777B2 · Cheung · 2015 [cited by examiner]
US 9722974B1 · Fuller · 2017 [cited by examiner]
US 9729520B2 · Barton · 2017 [cited by examiner]
US 9979546B2 · Van Someren · 2018 [cited by examiner]
US 10299118B1 · Karachiwala · 2019 [cited by examiner]
US 10776479B2 · Chatterton · 2020 [cited by examiner]
US 20030172272A1 · Ehlers · 2003 [cited by examiner]
US 20040187018A1 · Owen · 2004 [cited by examiner]
US 20070043681A1 · Morgan · 2007 [cited by examiner]
US 20080015986A1 · Wright · 2008 [cited by examiner]
US 20080222696A1 · Nicodemus · 2008 [cited by examiner]
US 20090100032A1 · Jones et al. · 2009 [cited by applicant]
US 20090172402A1 · Tran · 2009 [cited by examiner]
US 20110202984A1 · Hird et al. · 2011 [cited by applicant]
US 20130166918A1 · Shahbazi · 2013 [cited by examiner]
US 20150039908A1 · Lee et al. · 2015 [cited by applicant]
US 20150082032A1 · Bruce et al. · 2015 [cited by applicant]
US 20150113283A1 · Corella · 2015 [cited by examiner]
US 20150341335A1 · Camenisch et al. · 2015 [cited by applicant]
US 20160048833A1 · Huxham · 2016 [cited by examiner]
US 20160261411A1 · Yau · 2016 [cited by examiner]
US 20160308678A1 · Bhatnagar · 2016 [cited by applicant]
US 20170331817A1 · Votaw · 2017 [cited by examiner]
US 20190182230A1 · Wong · 2019 [cited by examiner]
WO 2016161398 · 2016 [cited by applicant]
U.S. Appl. No. 16/645,755 , “Non-Final Office Action”, filed Nov. 24, 2021, 11 pages. [cited by applicant]
U.S. Appl. No. 16/645,755 , “Notice of Allowance”, filed Apr. 18, 2022, 9 pages. [cited by applicant]
PCT/US2018/050606 , “International Preliminary Report on Patentability”, Mar. 26, 2020, 11 pages. [cited by applicant]
PCT/US2018/050606 , “International Search Report and Written Opinion”, Jan. 9, 2019, 14 pages. [cited by applicant]