IP Library Granted Patent US 12,598,069
Granted Patent B2
US 12,598,069 · App. 18/761,652 · Granted Apr 7, 2026

Monitoring in distributed computing system

Inventors: Cristian Radu (Beauvechain, BE); Mehdi Collinge (Mont-Sainte-Aldegonde, BE); Omar Laazimani (London, GB)
Assignee: MASTERCARD INTERNATIONAL INCORPORATED
H04L9/32G06F9/5072G06F9/546G06F11/3006H04L9/3242H04L63/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,598,069
App. No.
18/761,652
Granted
Apr 7, 2026
Kind
B2
Abstract

A method is described of monitoring a service performed at a computing node. The computing node is one of a plurality of computing nodes in a distributed computing system. Each computing node is adapted to perform at least one service for clients. A monitoring process is adapted to monitor a service process performing the process. In the method, the monitoring process monitors the service process on performance of the service. The monitoring service then provides monitoring information to a monitoring process for another service process. A suitable computing node for performing the service is described, as is a coordinated monitoring service for supporting multiple monitoring services.

Claims (61)

1 . A method of monitoring a first service performed at a computing node, wherein the computing node is one of a plurality of computing nodes in a distributed computing system, wherein each node is adapted to perform at least one service for clients, wherein a first monitoring process is adapted to monitor a first service process performing the first service, the method comprising:

monitoring the first service process for expected use of the first service;

capturing a first execution trace relating to use of the first service for a first transaction, wherein the first execution trace relates to generation of a credential;

storing the first execution trace in a first transaction database associated with the first service;

providing monitoring information between the first monitoring process and a second monitoring process for a second service process, wherein the first service process comprises generation of the credential and the second service process comprises validation of the credential, and wherein the credential includes a transaction-related challenge, a cryptogram, and an identifier for a requesting party; and

determining, based on the transaction-related challenge, whether the credential has been misused;

wherein the monitoring information provided between the first monitoring process and the second monitoring process includes the transaction-related challenge and an indication of credential misuse.

2 . The method of claim 1 , wherein the first execution trace includes the transaction-related challenge and the cryptogram.

3 . The method of claim 2 , further comprising:

checking the first execution trace against any records gathered relating to a particular card/token for the first transaction; and

storing a current generation service execution as a new record if no records relating to the particular card/token for the first transaction are located.

4 . The method of claim 1 , further comprising:

capturing a second execution trace relating to use of a second service for the first transaction, wherein the second execution trace relates to validation of the credential; and

storing the second execution trace in a second transaction database associated with the second service.

5 . The method of claim 4 , wherein the second execution trace includes the transaction-related challenge and the cryptogram.

6 . The method of claim 5 , further comprising:

receiving transaction credentials relating to a second transaction;

detecting a replay attack based on matching the transaction credentials relating to the second transaction with the transaction-related challenge and the cryptogram in the second execution trace.

7 . A computing node to monitor a first service performed in a distributed information security system, the computing node comprising:

a hardware security module (HSM) to store a plurality of keys, wherein the computing node is one of a plurality of computing nodes in a distributed computing system, wherein each node is adapted to perform at least one service for clients, wherein a first monitoring process is adapted to monitor a first service process performing the first service;

wherein the computing node is adapted to:

monitor the first service process for expected use of the first service;

capture a first execution trace relating to use of the first service for a first transaction, wherein the first execution trace relates to generation of a credential;

store the first execution trace in a first transaction database associated with the first service;

provide monitoring information between the first monitoring process and a second monitoring process for a second service process, wherein the first service process comprises generation of the credential and the second service process comprises validation of the credential, and wherein the credential includes a transaction-related challenge, a cryptogram, and an identifier for a requesting party; and

determine, based on the transaction-related challenge, whether the credential has been misused;

wherein the monitoring information provided between the first monitoring process and the second monitoring process includes the transaction-related challenge and an indication of credential misuse.

8 . The computing node of claim 7 , wherein the first execution trace includes the transaction-related challenge and the cryptogram.

9 . The computing node of claim 8 , wherein the computing node is further adapted to:

check the first execution trace against any records gathered relating to a particular card/token for the first transaction; and

store a current generation service execution as a new record if no records relating to the particular card/token for the first transaction are located.

10 . The computing node of claim 8 , wherein the computing node is further adapted to:

capture a second execution trace relating to use of a second service for the first transaction, wherein the second execution trace relates to validation of the credential; and

store the second execution trace in a second transaction database associated with the second service.

11 . The computing node of claim 10 , wherein the second execution trace includes the transaction-related challenge and the cryptogram.

12 . The computing node of claim 11 , wherein the computing node is further adapted to:

receive transaction credentials relating to a second transaction;

detecting a replay attack based on matching the transaction credentials relating to the second transaction with the transaction-related challenge and the cryptogram in the second execution trace.

13 . A computing node to monitor a first service performed in a distributed information security system, the computing node comprising:

a hardware security module (HSM) to store a plurality of keys, wherein the computing node is one of a plurality of computing nodes in a distributed computing system, wherein each node is adapted to perform at least one service for clients, wherein a first monitoring process is adapted to monitor a first service process performing the first service;

wherein the computing node is adapted to:

monitor the first service process for expected use of the first service;

provide monitoring information between the first monitoring process and a second monitoring process for a second service process, wherein the first service process comprises generation of a credential and the second service process comprises validation of the credential, and wherein the credential includes a transaction-related challenge, a cryptogram, and an identifier for a requesting party; and

determine, based on the transaction-related challenge, whether the credential has been misused;

wherein the monitoring information provided between the first monitoring process and the second monitoring process includes the transaction-related challenge and an indication of credential misuse.

14 . The computing node of claim 13 , wherein the computing node is further adapted to implement a remedial action in response to determining, based on use of the transaction-related challenge, that the credential has been misused.

15 . The computing node of claim 14 , wherein the remedial action includes one or more of precluding generation of credentials for transactions involving the requesting party or precluding validation of credentials for transactions involving the requesting party.

16 . The computing node of claim 14 , wherein the transaction-related challenge includes a transaction counter.

17 . The computing node of claim 13 , wherein misuse of the credential is determined to involve a replay attack.

18 . The computing node of claim 13 , wherein the computing node is further adapted to:

receive a second credential, wherein the second credential includes a second transaction-related challenge, a second cryptogram, and an identifier for a second requesting party;

determine that the second credential was not generated by the first service process; and

implement a remedial action in response to determining that the second credential was not generated by the first service process;

wherein the monitoring information provided between the first monitoring process and the second monitoring process includes a validation failure outcome.

19 . The computing node of claim 18 , wherein the remedial action includes precluding generation of credentials for transactions involving the second requesting party.

20 . The computing node of claim 15 , wherein the computing node is further adapted to:

assess statistics relating to generated transaction credentials and validated transaction credentials for a particular card or token during a key list validity period, wherein assessing the statistics includes to:

compare a counter for successful transaction credential generations with a counter for successful transaction credential validations; and

compare lists of validated transaction-related challenges; and

based on assessing the statistics, report disputed transactions via an escalation message to a coordinated monitoring process for implementing a second remedial action,

wherein the coordinated monitoring process is associated with multiple service processes, and wherein the second remedial action includes blocking the particular card or token.

Priority Claims (1)
EP 19206982 · Nov 4, 2019 · regional
Continuity (2)
Continuation 17088079 · Nov 3, 2020
Related Publication 20250007713A1 · Jan 2, 2025
References Cited (91)
US 7571230B2 · Gissel et al. · 2009 [cited by applicant]
US 8463894B2 · Chen · 2013 [cited by applicant]
US 9787697B2 · Betz et al. · 2017 [cited by applicant]
US 10038619B2 · Mercuri · 2018 [cited by applicant]
US 10078571B2 · Altman et al. · 2018 [cited by applicant]
US 10313117B1 · Carlough et al. · 2019 [cited by applicant]
US 10467422B1 · Roth et al. · 2019 [cited by applicant]
US 10812319B1 · Prakash et al. · 2020 [cited by applicant]
US 11777712B2 · Androulaki et al. · 2023 [cited by applicant]
US 12052361B2 · Radu et al. · 2024 [cited by applicant]
US 20020198848A1 · Michener · 2002 [cited by applicant]
US 20030023864A1 · Muttik et al. · 2003 [cited by applicant]
US 20030036886A1 · Stone · 2003 [cited by applicant]
US 20040019565A1 · Goringe et al. · 2004 [cited by applicant]
US 20040255163A1 · Swimmer et al. · 2004 [cited by applicant]
US 20050013293A1 · Sahita · 2005 [cited by applicant]
US 20060156380A1 · Gladstone et al. · 2006 [cited by applicant]
US 20060179296A1 · Bartlett et al. · 2006 [cited by applicant]
US 20070118483A1 · Hill et al. · 2007 [cited by applicant]
US 20080167003A1 · Wang et al. · 2008 [cited by applicant]
US 20080307088A1 · Chen · 2008 [cited by applicant]
US 20090048953A1 · Hazel et al. · 2009 [cited by applicant]
US 20100325265A1 · Schuster · 2010 [cited by examiner]
US 20110126059A1 · Klein · 2011 [cited by examiner]
US 20120158925A1 · Shen · 2012 [cited by examiner]
US 20120254965A1 · Parker · 2012 [cited by examiner]
US 20130031042A1 · Dehnie et al. · 2013 [cited by applicant]
US 20140046998A1 · Dain et al. · 2014 [cited by applicant]
US 20140229729A1 · Roth et al. · 2014 [cited by applicant]
US 20140359280A1 · Saboor et al. · 2014 [cited by applicant]
US 20140359281A1 · Saboori et al. · 2014 [cited by applicant]
US 20150026786A1 · Alexander · 2015 [cited by applicant]
US 20150135279A1 · Hayat · 2015 [cited by applicant]
US 20150163121A1 · Mahaffey et al. · 2015 [cited by applicant]
US 20150178724A1 · Ngo et al. · 2015 [cited by applicant]
US 20160148202A1 · McCormack et al. · 2016 [cited by applicant]
US 20160149873A1 · Dickinson et al. · 2016 [cited by applicant]
US 20160149923A1 · Zhang et al. · 2016 [cited by applicant]
US 20160323362A1 · Srinivasaiah et al. · 2016 [cited by applicant]
US 20160378629A1 · Gwozdz · 2016 [cited by applicant]
US 20170026371A1 · Holtmanns et al. · 2017 [cited by applicant]
US 20170083860A1 · Sriram et al. · 2017 [cited by applicant]
US 20170331802A1 · Keshava et al. · 2017 [cited by applicant]
US 20170339178A1 · Mahaffey · 2017 [cited by examiner]
US 20180041336A1 · Keshava et al. · 2018 [cited by applicant]
US 20180075262A1 · Auh · 2018 [cited by applicant]
US 20180109508A1 · Wall et al. · 2018 [cited by applicant]
US 20180240110A1 · Smets et al. · 2018 [cited by applicant]
US 20190098039A1 · Gates et al. · 2019 [cited by applicant]
US 20190108511A1 · Dunjic et al. · 2019 [cited by applicant]
US 20190158594A1 · Shadmon et al. · 2019 [cited by applicant]
US 20190236592A1 · Arora · 2019 [cited by applicant]
US 20190253434A1 · Biyani et al. · 2019 [cited by applicant]
US 20200394648A1 · Blackshear et al. · 2020 [cited by applicant]
US 20210067550A1 · Paine · 2021 [cited by applicant]
US 20210133067A1 · Radu · 2021 [cited by examiner]
US 20230318816A1 · Nakazawa et al. · 2023 [cited by applicant]
CA 2944361A1 · 2015 [cited by applicant]
CN 1567755A · 2005 [cited by applicant]
CN 106462544A · 2017 [cited by applicant]
CN 106462601A · 2017 [cited by applicant]
CN 106464500A · 2017 [cited by applicant]
CN 108959038A · 2018 [cited by examiner]
CN 109154885A · 2019 [cited by applicant]
CN 109413062A · 2019 [cited by applicant]
CN 109542725A · 2019 [cited by examiner]
CN 105391744B · 2019 [cited by examiner]
CN 108446947B · 2021 [cited by applicant]
EP 2965465A1 · 2016 [cited by applicant]
EP 2780832B1 · 2016 [cited by applicant]
EP 2965465B1 · 2018 [cited by applicant]
EP 3358867A1 · 2018 [cited by applicant]
EP 3364363A1 · 2018 [cited by applicant]
EP 3416118A1 · 2018 [cited by applicant]
EP 3432248A1 · 2019 [cited by applicant]
EP 3748525A1 · 2020 [cited by applicant]
EP 3748526A1 · 2020 [cited by applicant]
RU 97119182A · 1999 [cited by applicant]
RU 2686818C1 · 2019 [cited by applicant]
WO 200008806A1 · 2000 [cited by applicant]
WO 2008082587A1 · 2008 [cited by applicant]
WO 2012004891A1 · 2012 [cited by applicant]
WO 2013155912A1 · 2013 [cited by applicant]
WO 2014135195A1 · 2014 [cited by applicant]
WO 2018031856A1 · 2018 [cited by applicant]
WO 2018050229A1 · 2018 [cited by applicant]
WO WO2019071926A1 · 2019 [cited by examiner]
International Search Report and Written Opinion for International Patent Application No. PCT/US2020/053193, mailed Dec. 29, 2020, 11 pages. [cited by applicant]
Extended European Search Report for European Patent Application No. 19206982.1, mailed Feb. 10, 2020, 7 pages. [cited by applicant]
Office Action for European Patent Application No. 19206982.1, Mailed May 3, 2024, 5 pages. [cited by applicant]
Rajeev Kumar Sing, “Generating unique IDs in a distributed environment at high scale. I CalliCoder”, Jul. 8, 2018, XP055564378, 15 pages, Retrieved from the Internet: URL:https//www.callicoder.com/distributed-uniqued-se… [cited by applicant]