IP Library › Granted Patent US 12,711,494
Granted Patent B2
US 12,711,494 · App. 18/376,861 · Granted Aug 18, 2026

Systems and methods for processing mobile payments by provisoning credentials to mobile devices without secure elements

Inventors: Mehdi Collinge (Mont-Sainte-Aldegonde, BE); Susan Thompson (Nantwich, GB); Patrik Smets (Nijlen, BE); David Anthony Roberts (Warrington, GB); Michael Christopher Ward (Somerset, GB)
Assignee: MASTERCARD INTERNATIONAL INCORPORATED
G06Q20/3823G06Q20/322G06Q20/385G06Q20/4012G06Q20/405
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,711,494
App. No.
18/376,861
Granted
Aug 18, 2026
Kind
B2
Abstract

A method for generating and provisioning payment credentials to a mobile device lacking a secure element includes: generating a card profile associated with a payment account, wherein the card profile includes at least payment credentials corresponding to the associated payment account and a profile identifier; provisioning, to a mobile device lacking a secure element, the generated card profile; receiving, from the mobile device, a key request, wherein the key request includes at least a mobile identification number (PIN) and the profile identifier; using the mobile PIN; generating a single use key, wherein the single use key includes at least the profile identifier, an application transaction counter, and a generating key for use in generating a payment cryptogram valid for a single financial transaction; and transmitting the generated single use key to the mobile device.

Claims (34)

1 . A method for generating and provisioning payment credentials to a mobile device without the use of a secure element (SE), comprising:

storing, in a database, at least a storage key, a plurality of dynamic card validation code keys, and an application transaction counter associated with a mobile application program;

provisioning, to the mobile device, at least the storage key, an authentication component, and static payment credentials, wherein the static payment credentials are associated with a payment account;

receiving, from the mobile device, a chip authentication program (CAP) token;

validating, by a validation device, the authenticity of the received CAP token;

generating, by a processing device, a session key unpredictable number (KS UN );

generating, by the processing device, a cloud unpredictable number (UN CLOUD );

identifying, by the processing device, an encrypted payload based on a derived dynamic card validation code key (KD CVC3 ), wherein the encrypted payload includes at least a dynamic card validation code key of the plurality of dynamic card validation code keys, the KS UN , and the application transaction counter;

transmitting, by a transmitting device, the encrypted payload to the mobile device for use in generating a dynamic card validation code for use in a financial transaction; and

transmitting, by the transmitting device, at least the KS UN , UN CLOUD , and application transaction counter to an issuer associated with the payment account for use in validating the generated dynamic card validation code used in the financial transaction.

2 . The method of claim 1 , wherein

the KD CVC3 is genuine if the received CAP token is successfully validated, and

the KD CVC3 is fake if the received CAP token is unsuccessfully validated.

3 . The method of claim 1 , wherein validating the authenticity of the CAP token includes validating the authenticity of the CAP token based on at least the provisioned authentication component and an additional credential received from the mobile device.

4 . The method of claim 3 , wherein the additional credential is at least one of: a gesture, a password, a passcode, and a biometric identifier.

5 . The method of claim 1 , wherein validating the authenticity of the CAP token includes validating the authenticity of the CAP token based on at least the application transaction counter.

6 . The method of claim 1 , wherein the encrypted payload is encrypted using at least the storage key.

7 . A system for generating and provisioning payment credentials to a mobile device without the use of a secure element (SE), the system comprising one or more processors and a non-transitory memory storing instructions that, when executed by the one or more processors, cause the one or more processors to:

store, in a database, at least a storage key, a plurality of dynamic card validation code keys, and an application transaction counter associated with a mobile application program;

provision, to the mobile device, at least the storage key, an authentication component, and static payment credentials, wherein the static payment credentials are associated with a payment account;

receive, from the mobile device, a chip authentication program (CAP) token generated based on at least the static payment credentials;

validate the authenticity of the received CAP token;

generate a session key unpredictable number (KS UN );

generate a cloud unpredictable number (UN CLOUD );

identify an encrypted payload based on a derived dynamic card validation code key (KD CVC3 ), wherein the encrypted payload includes at least a dynamic card validation code key of the plurality of dynamic card validation code keys, the KS UN , and the application transaction counter;

transmit the encrypted payload to the mobile device for use in generating a dynamic card validation code for use in a financial transaction; and

transmit at least the KS UN , UN CLOUD , and application transaction counter to an issuer associated with the payment account for use in validating the generated dynamic card validation code used in the financial transaction.

8 . The system of claim 7 , wherein

the KD CVC3 is genuine if the received CAP token is successfully validated, and

the KD CVC3 is fake if the received CAP token is unsuccessfully validated.

9 . The system of claim 7 , further comprising instructions causing the one or more processors to validate the authenticity of the CAP token based on at least the provisioned authentication component and an additional credential received from the mobile device.

10 . The system of claim 9 , wherein the additional credential is at least one of: a gesture, a password, a passcode, and a biometric identifier.

11 . The system of claim 7 , further comprising instructions causing the one or more processors to validate the authenticity of the CAP token based on at least the application transaction counter.

12 . The system of claim 7 , further comprising instructions causing the one or more processors to encrypt the encrypted payload using at least the storage key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2023
From: COLLINGE, MEHDI; THOMPSON, SUSAN; SMETS, PATRIK; ROBERTS, DAVID ANTHONY; WARD, MICHAEL CHRISTOPHER
To: MASTERCARD INTERNATIONAL INCORPORATED
Reel/Frame 065130/0022 →
Continuity (7)
Division 16682357 · Nov 13, 2019
Division 13827042 · Mar 14, 2013
Provisional Application 61762098 · Feb 7, 2013
Provisional Application 61735383 · Dec 10, 2012
Provisional Application 61635248 · Apr 18, 2012
Provisional Application 61619095 · Apr 2, 2012
Related Publication 20240029062A1 · Jan 25, 2024
References Cited (57)
US 6226415B1 · Wilson et al. · 2001 [cited by applicant]
US 6226744B1 · Murphy et al. · 2001 [cited by applicant]
US 7059517B2 · Hopkins · 2006 [cited by applicant]
US 7849014B2 · Erikson · 2010 [cited by examiner]
US 8064597B2 · Gehrmann · 2011 [cited by examiner]
US 8682802B1 · Kannanari · 2014 [cited by examiner]
US 9536243B2 · Khan · 2017 [cited by applicant]
US 10057763B2 · Redberg · 2018 [cited by applicant]
US 11605070B2 · D'agostino · 2023 [cited by applicant]
US 20020152180A1 · Turgeon · 2002 [cited by applicant]
US 20020153424A1 · Li · 2002 [cited by applicant]
US 20060165060A1 · Dua · 2006 [cited by examiner]
US 20070260544A1 · Wankmueller · 2007 [cited by examiner]
US 20080040285A1 · Wankmueller · 2008 [cited by applicant]
US 20080051122A1 · Fisher · 2008 [cited by applicant]
US 20080110983A1 · Ashfield · 2008 [cited by examiner]
US 20090055893A1 · Manessis et al. · 2009 [cited by applicant]
US 20090132813A1 · Schibuk · 2009 [cited by examiner]
US 20090173782A1 · Muscato · 2009 [cited by examiner]
US 20100125516A1 · Wankmueller · 2010 [cited by examiner]
US 20100174919A1 · Ito · 2010 [cited by applicant]
US 20100185545A1 · Royyuru et al. · 2010 [cited by applicant]
US 20100211507A1 · Aabye · 2010 [cited by examiner]
US 20100332391A1 · Khan · 2010 [cited by applicant]
US 20110042457A1 · Lu · 2011 [cited by examiner]
US 20110060913A1 · Hird · 2011 [cited by examiner]
US 20110140834A1 · Kiliccote · 2011 [cited by examiner]
US 20110208658A1 · Makhotin · 2011 [cited by examiner]
US 20110265159A1 · Ronda · 2011 [cited by examiner]
US 20110276496A1 · Neville et al. · 2011 [cited by applicant]
US 20120066504A1 · Hird · 2012 [cited by examiner]
US 20120074219A1 · Burdett · 2012 [cited by applicant]
US 20120078735A1 · Bauer · 2012 [cited by applicant]
US 20120144203A1 · Albisu · 2012 [cited by applicant]
US 20120191612A1 · Spodak · 2012 [cited by examiner]
US 20120240195A1 · Weiss · 2012 [cited by applicant]
US 20120272056A1 · Ganesan · 2012 [cited by examiner]
US 20130212019A1 · Mattsson · 2013 [cited by examiner]
US 20140297438A1 · Dua · 2014 [cited by applicant]
US 20150254645A1 · Bondesen · 2015 [cited by applicant]
US 20160119312A1 · Armstrong · 2016 [cited by applicant]
GB 2506591A · 2014 [cited by applicant]
WO 2010081218A1 · 2010 [cited by applicant]
WO 2014048990A1 · 2014 [cited by applicant]
WO 2014049136A1 · 2014 [cited by applicant]
M. Alzomai and A. Jøsang, “The Mobile Phone as a Multi OTP Device Using Trusted Computing,” 2010 Fourth International Conference on Network and System Security, Melbourne, VIC, Australia, 2010, pp. 75-82, doi: 10.1109/N… [cited by examiner]
N. Waraporn, M. Sithiyavanich, H. Jiarawattanasawat and N. Pakchai, “Virtual Credit Cards on Mobile for M-Commerce Payment,” 2009 IEEE International Conference on e-Business Engineering, Macau, China, 2009, pp. 241-246,… [cited by examiner]
V. Alimi and M. Pasquet, “Post-Distribution Provisioning and Personalization of a Payment Application on a UICC-Based Secure Element,” 2009 International Conference on Availability, Reliability and Security, Fukuoka, Ja… [cited by examiner]
European Search Report issued by the European Patent Office on Oct. 29, 2015 in corresponding European Patent Application No. 13772978.6 filed on Mar. 21, 2013 (9 pages). [cited by applicant]
Examination Report No. 1 for standard patent application issued on Oct. 16, 2018, by the Australian Patent Office in corresponding Australian Patent Application No. 2017216488. (5 pages). [cited by applicant]
First Examination Report issued by the Australian Patent Office on Apr. 29, 2016 in corresponding Australian Patent Application No. 2013243805 filed on Mar. 21, 2013 (4 pages). [cited by applicant]
International Search Report (PCT/ISA/210) and the Written Opinion of the International Searching Authority (PCT/ISA/237) dated May 16, 2013, issued in corresponding International Application No. PCT/US2013/033322. (11 p… [cited by applicant]
Stig Frode M0lsnes et al., “Localized Credentials for Server Assisted Mobile Wallet”, Proceedings 2001 International Conference on Computer Networks and Mobile Computing, IEEE, 2001, 9 pages. [cited by applicant]
Office Action {Communication pursuant to Article 94{3) EPC) issued May 28, 2021, by the European Patent Office in corresponding European Patent Application No. 19203530.1-1231, (6 pages). [cited by applicant]
The extended European Search Report issued Jan. 24, 2020, by the European Patent Office in corresponding European Patent Application No. 19203530.1-1231, (10 pages). [cited by applicant]
He, Li-Sha. “An Asymmetrical End-to-End Mobile Payment Protocol for Mobile Commerce.” Order No. 11012342 the University of Manchester (United Kingdom), 2004. Ann Arbor: ProQuest. Web. Jun. 22, 2023. (Year: 2004). [cited by applicant]
Non-Final Office Action issued in corresponding U.S. Appl. No. 18/376,861, 32 pages. [cited by applicant]