Multi-path communication of electronic device secure element data for online payments
Systems, methods, and computer-readable media for communicating electronic device secure element data over multiple paths for online payments are provided. In one example embodiment, a method includes, inter alia, at a commercial entity subsystem, receiving, from an electronic device, device transaction data that includes credential data indicative of a payment credential on the electronic device for funding a transaction with a merchant subsystem, accessing a transaction identifier, deriving a transaction key based on transaction key data that includes the accessed transaction identifier, transmitting, to one of the merchant subsystem and the electronic device, merchant payment data that includes a first portion of the credential data and the accessed transaction identifier, and sharing, with a financial institution subsystem using the transaction key, commercial payment data that includes a second portion of the credential data that is different than the first portion of the credential data. Additional embodiments are also provided.
1 . A device comprising:
a memory; and
at least one processor configured to:
receive, from a first subsystem via an online resource, potential transaction data corresponding to a transaction between the device and the first subsystem;
generate, on a secure element of the device, secure cryptographic data using at least a portion of token data and a shared secret between the device and a second subsystem;
transmit, to a third subsystem, device transaction data that comprises the secure cryptographic data;
receive, from the third subsystem, first subsystem data that comprises a transaction identifier associated with the device transaction data; and
transmit, to the first subsystem via the online resource, another first subsystem data that comprises the transaction identifier and the token data to perform the transaction.
2 . The device of claim 1 , wherein:
the device transaction data further comprises a portion of the potential transaction data; and
the portion of the potential transaction data comprises at least one of:
an identifier of the first subsystem; and
a currency of a transaction to be funded.
3 . The device of claim 1 , wherein the token data comprises:
a primary account number; and
an expiry date of the primary account number.
4 . The device of claim 1 , wherein the online resource comprises at least one of a web page or an application.
5 . The device of claim 1 , wherein the token data is stored on the secure element.
6 . The device of claim 1 , wherein the secure cryptographic data is generated on the secure element of the device.
7 . The device of claim 1 , further comprising:
the secure element separate from the memory and the at least one processor.
8 . A method comprising:
receiving, by a device and from a first subsystem via an online resource, potential transaction data;
generating, on a secure element of the device, secure cryptographic data using at least a portion of token data and a shared secret between the device and a second subsystem;
transmitting, to a third subsystem, device transaction data that comprises the secure cryptographic data;
receiving, from the third subsystem, first subsystem data that comprises a transaction identifier associated with the device transaction data; and
transmitting, to the first subsystem via the online resource, second another first subsystem data that comprises the transaction identifier and the token data.
9 . The method of claim 8 , wherein:
the device transaction data further comprises a portion of the potential transaction data; and
the portion of the potential transaction data comprises at least one of:
an identifier of the first subsystem; and
a currency of a transaction to be funded.
10 . The method of claim 8 , wherein the token data comprises:
a primary account number; and
an expiry date of the primary account number.
11 . The method of claim 8 , wherein the online resource comprises at least one of a web page or an application.
12 . The method of claim 8 , wherein the token data is stored on the secure element.
13 . The method of claim 8 , wherein the secure cryptographic data is generated on the secure element of the device.
14 . The method of claim 8 , wherein the transmitting, to the third subsystem, the device transaction data bypasses the first subsystem.
15 . A non-transitory machine-readable medium comprising instructions that, when executed by one or more processors of a device, cause the one or more processors to perform operations comprising:
receiving, by the device and from a first subsystem via an online resource, potential transaction data;
generating, on a secure element of the device, secure cryptographic data using at least a portion of token data and a shared secret between the device and a second subsystem;
transmitting, to a third subsystem, device transaction data that comprises the secure cryptographic data;
receiving, from the third subsystem, first subsystem data that comprises a transaction identifier associated with the device transaction data; and
transmitting, to the first subsystem via the online resource, another first subsystem data that comprises the transaction identifier and the token data.
16 . The non-transitory machine-readable medium of claim 15 , wherein:
the device transaction data further comprises a portion of the potential transaction data; and
the portion of the potential transaction data comprises at least one of:
an identifier of the first subsystem; and
a currency of a transaction to be funded.
17 . The non-transitory machine-readable medium of claim 15 , wherein the token data comprises:
a primary account number; and
an expiry date of the primary account number.
18 . The non-transitory machine-readable medium of claim 15 , wherein the online resource comprises at least one of a web page or an application.
19 . The non-transitory machine-readable medium of claim 15 , wherein the token data is stored on the secure element.
20 . The device of claim 1 , wherein the secure cryptographic data is communicated to the second subsystem via the third subsystem without being communicated through the first subsystem.