Token management system and method
A method is disclosed. The method includes transmitting, by a service provider computer to a token service computer, a token request message comprising a service provider identifier associated with the service provider computer, and a token requestor identifier associated with a token requestor of a plurality of token requestors operatively coupled to a service provider computer. In response to transmitting the token request message, receiving, by the service provider computer from the token service computer, a token. The method also includes transmitting, by the service provider computer to the token requestor, the token.
1 . A method comprising:
receiving, by a service provider computer from a first token requestor computer, a first communication regarding a request for a first token, the first communication being encrypted with a first token requestor cryptographic key (CK 1 ) of a first token requestor cryptographic key pair (CK 1 , CK 1 ′) to form an encrypted first communication, wherein the service provider computer respectively stores cryptographic keys of cryptographic key pairs for a plurality of token requestor computers including the first token requestor computer and a second token requestor computer;
decrypting, by the service provider computer using a corresponding first token requestor cryptographic key (CK 1 ′) of the first token requestor cryptographic key pair (CK 1 , CK 1 ′), the encrypted first communication;
generating, by the service provider computer, a first token request message comprising a service provider identifier associated with the service provider computer, and a first token requestor identifier associated with a first token requestor;
encrypting, by the service provider computer, the first token request message with an encryption super key (ESK) to form an encrypted first token request message;
transmitting, by the service provider computer to a token service computer, the encrypted first token request message, wherein the token service computer decrypts the encrypted first token request message with another encryption super key (ESK′) corresponding to the encryption super key (ESK) in a encryption super key pair (ESK, ESK′);
in response to transmitting the encrypted first token request message, receiving, by the service provider computer from the token service computer, a first token response message including the first token encrypted with the another encryption super key (ESK′) to form an encrypted first token response message;
decrypting, by the service provider computer using the encryption super key (ESK), the encrypted first token response message to form the first token response message;
encrypting, by the service provider computer using the corresponding first token requestor cryptographic key (CK 1 ′), the first token response message to form another encrypted first token response message;
transmitting, by the service provider computer to the first token requestor computer, the another encrypted first token response message comprising the first token, wherein the first token requestor computer decrypts the another encrypted first token response message using the first token requestor cryptographic key (CK 1 ) to obtain the first token;
receiving, by the service provider computer from the second token requestor computer, a second communication regarding a request for a second token, the second communication being encrypted with a second token requestor cryptographic key (CK 2 ) of a second token requestor cryptographic key pair (CK 2 , CK 2 ′) to form an encrypted second communication;
decrypting, by the service provider computer using a corresponding second token requestor cryptographic key (CK 2 ′) of the second token requestor cryptographic key pair (CK 2 , CK 2 ′), the encrypted second communication;
generating, by the service provider computer, a second token request message comprising the service provider identifier associated with the service provider computer, and a second token requestor identifier associated with a second token requestor;
encrypting, by the service provider computer, the second token request message with the encryption super key (ESK) to form an encrypted second token request message;
transmitting, by the service provider computer to the token service computer, the encrypted second token request message, wherein the token service computer decrypts the encrypted second token request message with the another encryption super key (ESK″ corresponding to the encryption super key (ESK) in the encryption super key pair (ESK, ESK′);
in response to transmitting the encrypted second token request message, receiving, by the service provider computer from the token service computer, an encrypted second token response message including the second token encrypted with the another encryption super key (ESK′);
decrypting, by the service provider computer using the encryption super key (ESK), the encrypted second token response message to form the second token response message;
encrypting, by the service provider computer using the corresponding second token requestor cryptographic key (CK 2 ′), the second token response message to form another second encrypted response message; and
transmitting, by the service provider computer to the second token requestor computer, the another encrypted second token response message comprising the second token, wherein the second token requestor computer decrypts the encrypted second token response message using the second token requestor cryptographic key (CK 2 ) to obtain the second token.
2 . The method of claim 1 , wherein the token service computer comprises a database comprising a table mapping the service provider identifier with the first token requestor identifier.
3 . The method of claim 1 , wherein the token service computer comprises a database comprising a table mapping of the service provider identifier with a plurality of token requestor identifiers, wherein each token requestor identifier in the plurality of token requestor identifiers is associated with a token requestor in a plurality of token requestors.
4 . The method of claim 3 , wherein after the encrypted first token request message is transmitted to the token service computer, the token service computer generates and stores the first token in the database, wherein in the database the first token is mapped to the service provider identifier and the first token requestor identifier.
5 . The method of claim 1 , wherein the first token is 16 digits long.
6 . The method of claim 1 , wherein the the first token requestor cryptographic key pair and the second token requestor cryptographic key pair are each symmetric key pairs.
7 . The method of claim 1 , wherein the first token request message further comprises a credential of the first token requestor.
8 . The method of claim 1 , wherein the first token request message comprises a reference to a credential.
9 . The method of claim 1 , wherein the first token requestor is a resource provider, and wherein the first token is used to execute an interaction between a user and the resource provider.
10 . A service provider computer comprising:
a processor; and
a non-transitory computer readable medium, comprising instructions, that when executed by the processor, cause the processor to perform a method comprising:
receiving, from a first token requestor computer, a first communication regarding a request for a first token, the first communication being encrypted with a first token requestor cryptographic key (CK 1 ) of a first token requestor cryptographic key pair (CK 1 , CK 1 ′) to form an encrypted first communication, wherein the service provider computer respectively stores cryptographic keys of cryptographic key pairs for a plurality of token requestor computers including the first token requestor computer and a second token requestor computer;
decrypting, using a corresponding first token requestor cryptographic key (CK 1 ′) of the first token requestor cryptographic key pair (CK 1 , CK 1 ′), the encrypted first communication;
generating a first token request message comprising a service provider identifier associated with the service provider computer, and a first token requestor identifier associated with a first token requestor;
encrypting the first token request message with an encryption super key (ESK) to form an encrypted first token request message;
transmitting to a token service computer the encrypted first token request message comprising the service provider identifier associated with the service provider computer, and a token requestor identifier associated with a token requestor of a plurality of token requestors operatively coupled to the service provider computer, wherein the token service computer decrypts the encrypted first token request message with another encryption super key (ESK′) corresponding to the encryption super key (ESK) in a encryption super key pair (ESK, ESK′);
in response to transmitting the encrypted first token request message, receiving from the token service computer a first token response message including the first token encrypted with the another encryption super key (ESK′) to form an encrypted first token response message;
decrypting, by the service provider computer using the encryption super key (ESK), the encrypted first token response message to form the first token response message;
encrypting, by the service provider computer using the corresponding first token requestor cryptographic key (CK 1 ′), the first token response message to form another encrypted first token response message;
transmitting to the first token requestor computer, the another encrypted first token response message comprising the first token, wherein the first token requestor computer decrypts the another encrypted first token response message using the first token requestor cryptographic key (CK 1 ) to obtain the first token;
receiving, from the second token requestor computer, a second communication regarding a request for a second token, the second communication being encrypted with a second token requestor cryptographic key (CK 2 ) of a second token requestor cryptographic key pair (CK 2 , CK 2 ′) to form an encrypted second communication;
decrypting, using a corresponding second token requestor cryptographic key (CK 2 ′) of the second token requestor cryptographic key pair (CK 2 , CK 2 ′), the encrypted second communication;
generating a second token request message comprising the service provider identifier associated with the service provider computer, and a second token requestor identifier associated with a second token requestor;
encrypting the second token request message with the encryption super key (ESK) to form an encrypted second token request message;
transmitting, to the token service computer, the encrypted second token request message, wherein the token service computer decrypts the encrypted second token request message with the another encryption super key (ESK′) corresponding to the encryption super key (ESK) in the encryption super key pair (ESK, ESK′);
in response to transmitting the encrypted second token request message, receiving, from the token service computer, an encrypted second token response message including the second token encrypted with the another encryption super key (ESK′);
decrypting, using the encryption super key (ESK), the encrypted second token response message to form the second token response message;
encrypting, using the corresponding second token requestor cryptographic key (CK 2 ′), the second token response message to form another second encrypted response message; and
transmitting, to the second token requestor computer, the another encrypted second token response message comprising the second token, wherein the second token requestor computer decrypts the encrypted second token response message using the second token requestor cryptographic key (CK 2 ) to obtain the second token.
11 . The service provider computer of claim 10 , wherein the first token is 16 digits long.
12 . The service provider computer of claim 10 , wherein the plurality of token requestors is a plurality of resource providers.
13 . The service provider computer of claim 10 , wherein the encrypted first token request message further comprises a credential associated with the first token requestor.
14 . The service provider computer of claim 10 , wherein the encrypted first token request message comprises a reference to a credential.
15 . The service provider computer of claim 10 , wherein the encrypted first token request message comprises a primary account number.
16 . A system comprising:
a service provider computer comprising,
a processor, and
a non-transitory computer readable medium, comprising instructions, that when executed by the processor, cause the processor to perform a method comprising,
receiving, from a first token requestor computer, a first communication regarding a request for a first token, the first communication being encrypted with a first token requestor cryptographic key (CK 1 ) of a first token requestor cryptographic key pair (CK 1 , CK 1 ′) to form an encrypted first communication, wherein the service provider computer respectively stores cryptographic keys of cryptographic key pairs for a plurality of token requestor computers including the first token requestor computer and a second token requestor computer,
decrypting, using a corresponding first token requestor cryptographic key (CK 1 ′) of the first token requestor cryptographic key pair (CK 1 , CK 1 ′), the encrypted first communication,
generating a first token request message comprising a service provider identifier associated with the service provider computer, and a first token requestor identifier associated with a first token requestor,
encrypting the first token request message with an encryption super key (ESK) to form an encrypted first token request message,
transmitting to a token service computer the encrypted first token request message comprising the service provider identifier associated with the service provider computer, and a token requestor identifier associated with a token requestor of a plurality of token requestors operatively coupled to the service provider computer, wherein the token service computer decrypts the encrypted first token request message with another encryption super key (ESK′) corresponding to the encryption super key (ESK) in a encryption super key pair (ESK, ESK′),
in response to transmitting the encrypted first token request message, receiving from the token service computer a first token response message including the first token encrypted with the another encryption super key (ESK′) to form an encrypted first token response message,
decrypting, by the service provider computer using the encryption super key (ESK), the encrypted first token response message to form the first token response message,
encrypting, by the service provider computer using the corresponding first token requestor cryptographic key (CK 1 ′), the first token response message to form another encrypted first token response message,
transmitting to the first token requestor computer, the another encrypted first token response message comprising the first token, wherein the first token requestor computer decrypts the another encrypted first token response message using the first token requestor cryptographic key (CK 1 ) to obtain the first token,
receiving, from the second token requestor computer, a second communication regarding a request for a second token, the second communication being encrypted with a second token requestor cryptographic key (CK 2 ) of a second token requestor cryptographic key pair (CK 2 , CK 2 ′) to form an encrypted second communication,
decrypting, using a corresponding second token requestor cryptographic key (CK 2 ′) of the second token requestor cryptographic key pair (CK 2 , CK 2 ′), the encrypted second communication,
generating a second token request message comprising the service provider identifier associated with the service provider computer, and a second token requestor identifier associated with a second token requestor,
encrypting the second token request message with the encryption super key (ESK) to form an encrypted second token request message,
transmitting, to the token service computer, the encrypted second token request message, wherein the token service computer decrypts the encrypted second token request message with the another encryption super key (ESK′) corresponding to the encryption super key (ESK) in the encryption super key pair (ESK, ESK′),
in response to transmitting the encrypted second token request message, receiving, from the token service computer, an encrypted second token response message including the second token encrypted with the another encryption super key (ESK′),
decrypting, using the encryption super key (ESK), the encrypted second token response message to form the second token response message,
encrypting, using the corresponding second token requestor cryptographic key (CK 2 ′), the second token response message to form another second encrypted response message, and
transmitting, to the second token requestor computer, the another encrypted second token response message comprising the second token, wherein the second token requestor computer decrypts the encrypted second token response message using the second token requestor cryptographic key (CK 2 ) to obtain the second token; and
the token service computer in communication with the service provider computer.
17 . The system of claim 16 , further comprising:
the first token requestor computer in communication with the service provider computer.
18 . The system of claim 17 , further comprising:
the second token requestor computer in communication with the service provider computer.
19 . The system of claim 17 , wherein the encrypted first token request message further comprises a first credential associated with the first token requestor.
20 . The system of claim 19 , wherein the first credential is a credit card number.