IP Library › Granted Patent US 12,634,138
Granted Patent B2
US 12,634,138 · App. 18/769,845 · Granted May 19, 2026

Token management system and method

Inventors: Raul Leyva (Round Rock, TX); Pinesh Roy (Foster City, CA)
Assignee: Visa International Service Asoociation
H04L9/3213H04L9/3073
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,138
App. No.
18/769,845
Filed
Jul 11, 2024
Granted
May 19, 2026
Kind
B2
Art Unit
2495
USPC
713/159
Abstract

A method is disclosed. The method includes transmitting, by a service provider computer to a token service computer, a token request message comprising a service provider identifier associated with the service provider computer, and a token requestor identifier associated with a token requestor of a plurality of token requestors operatively coupled to a service provider computer. In response to transmitting the token request message, receiving, by the service provider computer from the token service computer, a token. The method also includes transmitting, by the service provider computer to the token requestor, the token.

Claims (82)

1 . A method comprising:

receiving, by a service provider computer from a first token requestor computer, a first communication regarding a request for a first token, the first communication being encrypted with a first token requestor cryptographic key (CK 1 ) of a first token requestor cryptographic key pair (CK 1 , CK 1 ′) to form an encrypted first communication, wherein the service provider computer respectively stores cryptographic keys of cryptographic key pairs for a plurality of token requestor computers including the first token requestor computer and a second token requestor computer;

decrypting, by the service provider computer using a corresponding first token requestor cryptographic key (CK 1 ′) of the first token requestor cryptographic key pair (CK 1 , CK 1 ′), the encrypted first communication;

generating, by the service provider computer, a first token request message comprising a service provider identifier associated with the service provider computer, and a first token requestor identifier associated with a first token requestor;

encrypting, by the service provider computer, the first token request message with an encryption super key (ESK) to form an encrypted first token request message;

transmitting, by the service provider computer to a token service computer, the encrypted first token request message, wherein the token service computer decrypts the encrypted first token request message with another encryption super key (ESK′) corresponding to the encryption super key (ESK) in a encryption super key pair (ESK, ESK′);

in response to transmitting the encrypted first token request message, receiving, by the service provider computer from the token service computer, a first token response message including the first token encrypted with the another encryption super key (ESK′) to form an encrypted first token response message;

decrypting, by the service provider computer using the encryption super key (ESK), the encrypted first token response message to form the first token response message;

encrypting, by the service provider computer using the corresponding first token requestor cryptographic key (CK 1 ′), the first token response message to form another encrypted first token response message;

transmitting, by the service provider computer to the first token requestor computer, the another encrypted first token response message comprising the first token, wherein the first token requestor computer decrypts the another encrypted first token response message using the first token requestor cryptographic key (CK 1 ) to obtain the first token;

receiving, by the service provider computer from the second token requestor computer, a second communication regarding a request for a second token, the second communication being encrypted with a second token requestor cryptographic key (CK 2 ) of a second token requestor cryptographic key pair (CK 2 , CK 2 ′) to form an encrypted second communication;

decrypting, by the service provider computer using a corresponding second token requestor cryptographic key (CK 2 ′) of the second token requestor cryptographic key pair (CK 2 , CK 2 ′), the encrypted second communication;

generating, by the service provider computer, a second token request message comprising the service provider identifier associated with the service provider computer, and a second token requestor identifier associated with a second token requestor;

encrypting, by the service provider computer, the second token request message with the encryption super key (ESK) to form an encrypted second token request message;

transmitting, by the service provider computer to the token service computer, the encrypted second token request message, wherein the token service computer decrypts the encrypted second token request message with the another encryption super key (ESK″ corresponding to the encryption super key (ESK) in the encryption super key pair (ESK, ESK′);

in response to transmitting the encrypted second token request message, receiving, by the service provider computer from the token service computer, an encrypted second token response message including the second token encrypted with the another encryption super key (ESK′);

decrypting, by the service provider computer using the encryption super key (ESK), the encrypted second token response message to form the second token response message;

encrypting, by the service provider computer using the corresponding second token requestor cryptographic key (CK 2 ′), the second token response message to form another second encrypted response message; and

transmitting, by the service provider computer to the second token requestor computer, the another encrypted second token response message comprising the second token, wherein the second token requestor computer decrypts the encrypted second token response message using the second token requestor cryptographic key (CK 2 ) to obtain the second token.

2 . The method of claim 1 , wherein the token service computer comprises a database comprising a table mapping the service provider identifier with the first token requestor identifier.

3 . The method of claim 1 , wherein the token service computer comprises a database comprising a table mapping of the service provider identifier with a plurality of token requestor identifiers, wherein each token requestor identifier in the plurality of token requestor identifiers is associated with a token requestor in a plurality of token requestors.

4 . The method of claim 3 , wherein after the encrypted first token request message is transmitted to the token service computer, the token service computer generates and stores the first token in the database, wherein in the database the first token is mapped to the service provider identifier and the first token requestor identifier.

5 . The method of claim 1 , wherein the first token is 16 digits long.

6 . The method of claim 1 , wherein the the first token requestor cryptographic key pair and the second token requestor cryptographic key pair are each symmetric key pairs.

7 . The method of claim 1 , wherein the first token request message further comprises a credential of the first token requestor.

8 . The method of claim 1 , wherein the first token request message comprises a reference to a credential.

9 . The method of claim 1 , wherein the first token requestor is a resource provider, and wherein the first token is used to execute an interaction between a user and the resource provider.

10 . A service provider computer comprising:

a processor; and

a non-transitory computer readable medium, comprising instructions, that when executed by the processor, cause the processor to perform a method comprising:

receiving, from a first token requestor computer, a first communication regarding a request for a first token, the first communication being encrypted with a first token requestor cryptographic key (CK 1 ) of a first token requestor cryptographic key pair (CK 1 , CK 1 ′) to form an encrypted first communication, wherein the service provider computer respectively stores cryptographic keys of cryptographic key pairs for a plurality of token requestor computers including the first token requestor computer and a second token requestor computer;

decrypting, using a corresponding first token requestor cryptographic key (CK 1 ′) of the first token requestor cryptographic key pair (CK 1 , CK 1 ′), the encrypted first communication;

generating a first token request message comprising a service provider identifier associated with the service provider computer, and a first token requestor identifier associated with a first token requestor;

encrypting the first token request message with an encryption super key (ESK) to form an encrypted first token request message;

transmitting to a token service computer the encrypted first token request message comprising the service provider identifier associated with the service provider computer, and a token requestor identifier associated with a token requestor of a plurality of token requestors operatively coupled to the service provider computer, wherein the token service computer decrypts the encrypted first token request message with another encryption super key (ESK′) corresponding to the encryption super key (ESK) in a encryption super key pair (ESK, ESK′);

in response to transmitting the encrypted first token request message, receiving from the token service computer a first token response message including the first token encrypted with the another encryption super key (ESK′) to form an encrypted first token response message;

decrypting, by the service provider computer using the encryption super key (ESK), the encrypted first token response message to form the first token response message;

encrypting, by the service provider computer using the corresponding first token requestor cryptographic key (CK 1 ′), the first token response message to form another encrypted first token response message;

transmitting to the first token requestor computer, the another encrypted first token response message comprising the first token, wherein the first token requestor computer decrypts the another encrypted first token response message using the first token requestor cryptographic key (CK 1 ) to obtain the first token;

receiving, from the second token requestor computer, a second communication regarding a request for a second token, the second communication being encrypted with a second token requestor cryptographic key (CK 2 ) of a second token requestor cryptographic key pair (CK 2 , CK 2 ′) to form an encrypted second communication;

decrypting, using a corresponding second token requestor cryptographic key (CK 2 ′) of the second token requestor cryptographic key pair (CK 2 , CK 2 ′), the encrypted second communication;

generating a second token request message comprising the service provider identifier associated with the service provider computer, and a second token requestor identifier associated with a second token requestor;

encrypting the second token request message with the encryption super key (ESK) to form an encrypted second token request message;

transmitting, to the token service computer, the encrypted second token request message, wherein the token service computer decrypts the encrypted second token request message with the another encryption super key (ESK′) corresponding to the encryption super key (ESK) in the encryption super key pair (ESK, ESK′);

in response to transmitting the encrypted second token request message, receiving, from the token service computer, an encrypted second token response message including the second token encrypted with the another encryption super key (ESK′);

decrypting, using the encryption super key (ESK), the encrypted second token response message to form the second token response message;

encrypting, using the corresponding second token requestor cryptographic key (CK 2 ′), the second token response message to form another second encrypted response message; and

transmitting, to the second token requestor computer, the another encrypted second token response message comprising the second token, wherein the second token requestor computer decrypts the encrypted second token response message using the second token requestor cryptographic key (CK 2 ) to obtain the second token.

11 . The service provider computer of claim 10 , wherein the first token is 16 digits long.

12 . The service provider computer of claim 10 , wherein the plurality of token requestors is a plurality of resource providers.

13 . The service provider computer of claim 10 , wherein the encrypted first token request message further comprises a credential associated with the first token requestor.

14 . The service provider computer of claim 10 , wherein the encrypted first token request message comprises a reference to a credential.

15 . The service provider computer of claim 10 , wherein the encrypted first token request message comprises a primary account number.

16 . A system comprising:

a service provider computer comprising,

a processor, and

a non-transitory computer readable medium, comprising instructions, that when executed by the processor, cause the processor to perform a method comprising,

receiving, from a first token requestor computer, a first communication regarding a request for a first token, the first communication being encrypted with a first token requestor cryptographic key (CK 1 ) of a first token requestor cryptographic key pair (CK 1 , CK 1 ′) to form an encrypted first communication, wherein the service provider computer respectively stores cryptographic keys of cryptographic key pairs for a plurality of token requestor computers including the first token requestor computer and a second token requestor computer,

decrypting, using a corresponding first token requestor cryptographic key (CK 1 ′) of the first token requestor cryptographic key pair (CK 1 , CK 1 ′), the encrypted first communication,

generating a first token request message comprising a service provider identifier associated with the service provider computer, and a first token requestor identifier associated with a first token requestor,

encrypting the first token request message with an encryption super key (ESK) to form an encrypted first token request message,

transmitting to a token service computer the encrypted first token request message comprising the service provider identifier associated with the service provider computer, and a token requestor identifier associated with a token requestor of a plurality of token requestors operatively coupled to the service provider computer, wherein the token service computer decrypts the encrypted first token request message with another encryption super key (ESK′) corresponding to the encryption super key (ESK) in a encryption super key pair (ESK, ESK′),

in response to transmitting the encrypted first token request message, receiving from the token service computer a first token response message including the first token encrypted with the another encryption super key (ESK′) to form an encrypted first token response message,

decrypting, by the service provider computer using the encryption super key (ESK), the encrypted first token response message to form the first token response message,

encrypting, by the service provider computer using the corresponding first token requestor cryptographic key (CK 1 ′), the first token response message to form another encrypted first token response message,

transmitting to the first token requestor computer, the another encrypted first token response message comprising the first token, wherein the first token requestor computer decrypts the another encrypted first token response message using the first token requestor cryptographic key (CK 1 ) to obtain the first token,

receiving, from the second token requestor computer, a second communication regarding a request for a second token, the second communication being encrypted with a second token requestor cryptographic key (CK 2 ) of a second token requestor cryptographic key pair (CK 2 , CK 2 ′) to form an encrypted second communication,

decrypting, using a corresponding second token requestor cryptographic key (CK 2 ′) of the second token requestor cryptographic key pair (CK 2 , CK 2 ′), the encrypted second communication,

generating a second token request message comprising the service provider identifier associated with the service provider computer, and a second token requestor identifier associated with a second token requestor,

encrypting the second token request message with the encryption super key (ESK) to form an encrypted second token request message,

transmitting, to the token service computer, the encrypted second token request message, wherein the token service computer decrypts the encrypted second token request message with the another encryption super key (ESK′) corresponding to the encryption super key (ESK) in the encryption super key pair (ESK, ESK′),

in response to transmitting the encrypted second token request message, receiving, from the token service computer, an encrypted second token response message including the second token encrypted with the another encryption super key (ESK′),

decrypting, using the encryption super key (ESK), the encrypted second token response message to form the second token response message,

encrypting, using the corresponding second token requestor cryptographic key (CK 2 ′), the second token response message to form another second encrypted response message, and

transmitting, to the second token requestor computer, the another encrypted second token response message comprising the second token, wherein the second token requestor computer decrypts the encrypted second token response message using the second token requestor cryptographic key (CK 2 ) to obtain the second token; and

the token service computer in communication with the service provider computer.

17 . The system of claim 16 , further comprising:

the first token requestor computer in communication with the service provider computer.

18 . The system of claim 17 , further comprising:

the second token requestor computer in communication with the service provider computer.

19 . The system of claim 17 , wherein the encrypted first token request message further comprises a first credential associated with the first token requestor.

20 . The system of claim 19 , wherein the first credential is a credit card number.

Continuity (3)
Division 17783610
Provisional Application 62947712 · Dec 13, 2019
Related Publication 20240364522A1 · Oct 31, 2024
References Cited (43)
US 9105027B2 · Hammad et al. · 2015 [cited by applicant]
US 10062079B2 · Kumnick et al. · 2018 [cited by applicant]
US 10361856B2 · Cassin et al. · 2019 [cited by applicant]
US 10496986B2 · Narayan et al. · 2019 [cited by applicant]
US 10817875B2 · Makhotin et al. · 2020 [cited by applicant]
US 11093936B2 · Dill et al. · 2021 [cited by applicant]
US 11329822B2 · Cassin et al. · 2022 [cited by applicant]
US 20150032625A1 · Dill · 2015 [cited by examiner]
US 20150032626A1 · Dill · 2015 [cited by examiner]
US 20150046338A1 · Laxminarayanan · 2015 [cited by examiner]
US 20150127547A1 · Powell · 2015 [cited by examiner]
US 20160180333A1 · Leyva · 2016 [cited by examiner]
US 20160232513A1 · Purves · 2016 [cited by examiner]
US 20170272253A1 · Lavender · 2017 [cited by examiner]
US 20170357964A1 · Subrahmanyam et al. · 2017 [cited by applicant]
US 20170373852A1 · Cassin et al. · 2017 [cited by applicant]
US 20180006821A1 · Kinagi · 2018 [cited by examiner]
US 20180018666A1 · Solanki et al. · 2018 [cited by applicant]
US 20180268405A1 · Lopez · 2018 [cited by applicant]
US 20190288844A1 · Cassin et al. · 2019 [cited by applicant]
US 20190385185A1 · Shiffert et al. · 2019 [cited by applicant]
US 20210344672A1 · Drechsler et al. · 2021 [cited by applicant]
US 20220231851A1 · Cassin et al. · 2022 [cited by applicant]
US 20220376914A1 · Leyva et al. · 2022 [cited by applicant]
US 20230216679A1 · Tomar · 2023 [cited by applicant]
US 20240364522A1 · Leyva · 2024 [cited by examiner]
AU 2016203811A1 · 2016 [cited by applicant]
AU 2020256366B2 · 2021 [cited by applicant]
CN 105580038A · 2016 [cited by applicant]
CN 109328445A · 2019 [cited by applicant]
EP 3910908A1 · 2021 [cited by applicant]
Cloudflare, “How Does SSL Work? | SSL Certificates and TLS”, Nov. 21, 2019, www.cloudflare.com/learning/ssl/how-does-ssl-work/, accessed via web.archive.org on Oct. 3, 2025, p. 1-6. (Year: 2019). [cited by examiner]
U.S. Appl. No. 17/783,610 , “Non-Final Office Action”, Oct. 5, 2023, 12 pages. [cited by applicant]
U.S. Appl. No. 17/783,610 , “Notice of Allowability”, Apr. 23, 2024, 2 pages. [cited by applicant]
U.S. Appl. No. 17/783,610 , “Notice of Allowability”, Apr. 25, 2024, 2 pages. [cited by applicant]
U.S. Appl. No. 17/783,610 , “Notice of Allowance”, Apr. 12, 2024, 5 pages. [cited by applicant]
CN202080085543.1 , “Notice of Decision to Grant”, Feb. 6, 2024, 4 pages. [cited by applicant]
CN202080085543.1 , “Office Action”, Jul. 25, 2023, 8 pages. [cited by applicant]
EP20900540.4 , “Extended European Search Report”, Dec. 21, 2022, 15 pages. [cited by applicant]
EP20900540.4 , “Office Action”, Apr. 12, 2024, 5 pages. [cited by applicant]
PCT/US2020/064616 , “International Preliminary Report on Patentability”, Jun. 23, 2022, 9 pages. [cited by applicant]
PCT/US2020/064616 , “International Search Report and Written Opinion”, Mar. 15, 2021, 13 pages. [cited by applicant]
SG11202250122G , “Written Opinion”, Jan. 8, 2025, 9 pages. [cited by applicant]