IP Library Granted Patent US 12,659,145
Granted Patent B2
US 12,659,145 · App. 18/799,815 · Granted Jun 16, 2026

Derived unique key for pre-shared key (DUK-PSK)

Inventors: Jeffrey J. Stapleton (O'Fallon, MO); Peter Bordow (Fountain Hills, AZ)
Assignee: Wells Fargo Bank, N.A.
H04L9/0861H04L63/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,659,145
App. No.
18/799,815
Granted
Jun 16, 2026
Kind
B2
Abstract

The arrangements disclosed herein relate to systems, apparatus, methods, and non-transitory computer readable media for receiving, by a client from a terminal, an External Pre-Shared Key (EPKS) package comprising a transaction key, wherein the transaction key is derived by the terminal using an Initial Key (IK) and a counter, sending, by the client to a server, a first message comprising the TID and the counter, receiving, by the client from the server, a second message in response to the first message, determining, by the client, a session key using the EPKS package, and communicating by the client with the server via a communication session using the session key.

Claims (61)

1 . A method, comprising:

receiving, by a server from a client, a first message comprising a Terminal Identifier (TID) identifying a terminal associated with the client and a counter;

providing, by the server to a host, the TID and the counter;

receiving, by the server from the host, an External Pre-Shared Key (EPKS) package comprising a transaction key, wherein the transaction key is derived by the host using the TID and the counter;

determining, by the server, a session key using the EPKS package; and

communicating by the server with the client via a communication session using the session key, wherein the host provides the TID and a Base Derivation Key (BDK) to a Key Injection Facility (KIF), and the KIF derives an Initial Key (IK) using the BDK.

2 . The method of claim 1 , wherein the communication session is using an Internet Engineering Task Force (IETF) protocol.

3 . The method of claim 2 , wherein the IETF protocol comprises at least one of Transport Layer Security (TLS), Extensible Authentication Protocol (EAP), Internet Key Exchange (IKE), Datagram Transport Layer Security (DTLS), or Cryptographic Message Syntax (CMS).

4 . The method of claim 1 , wherein the KIF provides the TID and Initial Key (IK) to the terminal.

5 . A method, comprising:

receiving, by a server from a client, a first message comprising a Terminal Identifier (TID) identifying a terminal associated with the client and a counter;

providing, by the server to a host, the TID and the counter;

receiving, by the server from the host, an External Pre-Shared Key (EPKS) package comprising a transaction key, wherein the transaction key is derived by the host using the TID and the counter;

determining, by the server, a session key using the EPKS package; and

communicating by the server with the client via a communication session using the session key

receiving, by the server from the client, a ciphertext TK (test), wherein the ciphertext TK (test) is generated by the client or the terminal by encrypting a plaintext test using the transaction key (TK); and

providing, by the server, the ciphertext to the host, wherein

the host verifies the transaction key derived by the host in response to successfully decrypting the ciphertext using the transaction key derived by the host.

6 . A method, comprising:

receiving, by a server from a client, a first message comprising a Terminal Identifier TID) identifying a terminal associated with the client and a counter;

providing, by the server to a host, the TID and the counter;

receiving, by the server from the host, an External Pre-Shared Key (EPKS) package comprising a transaction key, wherein the transaction key is derived by the host using the TID and the counter;

determining, by the server, a session key using the EPKS package; and

communicating by the server with the client via a communication session using the session key, wherein

the first message comprises a first indicator indicating Pre-Shared Key (PSK); and

the method further comprises sending, by the server to the client, a second indicator indicating the PSK.

7 . A method, comprising:

receiving, by a client from a terminal, an External Pre-Shared Key (EPKS) package comprising a transaction key TK, wherein the transaction key is derived by the terminal using an Initial Key (IK) and a counter;

sending, by the client to a server, a first message comprising the TID and the counter;

receiving, by the client from the server, a second message in response to the first message;

determining, by the client, a session key using the EPKS package; and

communicating by the client with the server via a communication session using the session key, wherein the host provides the TID and a Base Derivation Key (BDK) to a Key Injection Facility (KIF), and the KIF derives an Initial Key (IK) using the BDK.

8 . The method of claim 7 , wherein the communication session is using an Internet Engineering Task Force (IETF) protocol.

9 . The method of claim 8 , wherein the IETF protocol comprises at least one of Transport Layer Security (TLS), Extensible Authentication Protocol (EAP), Internet Key Exchange (IKE), Datagram Transport Layer Security (DTLS), or Cryptographic Message Syntax (CMS).

10 . The method of claim 7 , wherein the KIF provides the IK to the terminal which uses the IK to derive the TK and provides the TK to the client in the EPKS package, and the client never receives the IK.

11 . The method of claim 7 , wherein communicating by the server with the client via a communication session using the session key comprises generating and verifying, using the session key, a Hash-based Message Authentication Code (HMAC) or a Message Authentication Code (MAC).

12 . A method, comprising:

receiving, by a client from a terminal, an External Pre-Shared Key (EPKS) package comprising a transaction key TK, wherein the transaction key is derived by the terminal using an Initial Key (IK) and a counter;

sending, by the client to a server, a first message comprising the TID and the counter;

receiving, by the client from the server, a second message in response to the first message;

determining, by the client, a session key using the EPKS package; and

communicating by the client with the server via a communication session using the session key

generating, by the client, a ciphertext TK (test) by encrypting a plaintext test using the transaction key TK;

providing, by the client to the server, the ciphertext TK (test), wherein the server provides the ciphertext TK (test) to the host, and the host verifies the transaction key TK derived by the host in response to successfully decrypting the ciphertext TK (test) using the transaction key TK derived by the host.

13 . A method, comprising:

receiving, by a client from a terminal, an External Pre-Shared Key (EPKS) package comprising a transaction key TK, wherein the transaction key is derived by the terminal using an Initial Key (IK) and a counter;

sending, by the client to a server, a first message comprising the TID and the counter;

receiving, by the client from the server, a second message in response to the first message;

determining, by the client, a session key using the EPKS package; and

communicating by the client with the server via a communication session using the session key, wherein

the first message comprises a first indicator indicating Pre-Shared Key (PSK); and

the method further comprises sending, by the server to the client, a second indicator indicating the PSK.

14 . At least one non-transitory processor-readable medium comprising processor-readable instructions, such that, when executed in one or more processors of a client, causes the one or more processors to:

receive, from a terminal, an External Pre-Shared Key (EPKS) package comprising a transaction key, wherein the transaction key is derived by the terminal using an Initial Key (IK) and a counter;

send, to a server, a first message comprising the TID and the counter;

receive, from the server, a second message in response to the first message;

determine a session key using the EPKS package; and

communicate with the server via a communication session using the session key, wherein the host provides the TID and a Base Derivation Key (BDK) to a Key Injection Facility (KIF), and the KIF derives an Initial Key (IK) using the BDK.

15 . The non-transitory processor-readable medium of claim 14 , wherein the communication session uses an Internet Engineering Task Force (IETF) protocol.

16 . The non-transitory processor-readable medium of claim 14 , wherein the one or more processors is further configured to generate a ciphertext by encrypting a plaintext using the transaction key, wherein the first message further comprises the ciphertext, wherein the server provides the ciphertext to the host, and the host verifies a transaction key derived by the host in response to successfully decrypting the ciphertext using the transaction key derived by the host.

17 . The non-transitory processor-readable medium of claim 14 , wherein the KIF provides the IK to the terminal.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 4, 2024
From: STAPLETON, JEFFREY J.; BORDOW, PETER
To: WELLS FARGO BANK, N.A.
Reel/Frame 068485/0930 →
Continuity (1)
Related Publication 20260046121A1 · Feb 12, 2026
References Cited (10)
US 5336870A · Hughes · 1994 [cited by examiner]
US 5745576A · Abraham · 1998 [cited by examiner]
US 10326803B1 · Haney · 2019 [cited by examiner]
US 10757573B2 · Guertler · 2020 [cited by examiner]
US 12256013B2 · Rule · 2025 [cited by examiner]
US 20090158032A1 · Costa · 2009 [cited by examiner]
US 20100121701A1 · Nguyen · 2010 [cited by examiner]
US 20180167751A1 · Vendelbo · 2018 [cited by examiner]
US 20250350454A1 · Kolekar · 2025 [cited by examiner]
“The EAP-PSK Protocol: A Pre-Shared Key Extensible Authentication Protocol (EAP) Method”; F. Bersani, H. Tschofenig ; France Telecom R&D Category:; Siemens Networks GmbH & Co KG; Jan. 2007 pp. 1-64. [cited by examiner]