Techniques for securely communicating sensitive data
Systems and methods are disclosed for securely communicating sensitive such as an identifier. An encrypted value may be generated utilizing at least a portion of the identifier, a dynamic value, and an encryption key. An obfuscated identifier may be generated using at least a portion of the unencrypted identifier and a portion of the encrypted value. The obfuscated identifier and the encrypted value may be provided in a message to inhibit potential fraudsters from obtaining the identifier.
1 . A computer-implemented method, comprising:
obtaining, by a device, a unique derivation key;
obtaining, by the device, a dynamic value;
concatenating an identifier and the dynamic value to generate a concatenated value;
generating an encrypted identifier based on encrypting the concatenated value by inputting the unique derivation key and the identifier into an encryption algorithm, the identifier being a 16-digit primary account identifier;
generating, by the device, an obfuscated identifier based at least in part on a portion of the identifier and a portion of the encrypted identifier, the obfuscated identifier maintaining routing information of the 16-digit primary account identifier;
providing, by the device, the obfuscated identifier to an access device, causing the access device to populate a first data field of an authorization request message with the obfuscated identifier prior to transmitting the authorization request message to a central server computer, the first data field being previously associated with identifying primary account identifiers, wherein populating the first data field with the obfuscated identifier maintains the ability to utilize checksum algorithm-based error checking for the first data field; and
providing, by the device, the encrypted identifier to the access device, causing the access device to populate a second data field of the authorization request message with the encrypted identifier prior to transmitting the authorization request message to the central server computer, wherein populating the second data field with the encrypted identifier instead of the first data field reduces an ability of a nefarious actor to identify the 16-digit primary account identifier from the authorization request message or to track the 16-digit primary account identifier across authorization request messages.
2 . The computer-implemented method of claim 1 , wherein the obfuscated identifier and the encrypted identifier are provided to the access device in a message, and wherein the computer-implemented method further comprises:
generating a modified counter value in response to providing the message comprising the obfuscated identifier and the encrypted identifier; and
storing the modified counter value.
3 . The computer-implemented method of claim 2 , further comprising:
generating, by the device, a subsequent encrypted identifier utilizing the identifier, the modified counter value, and the unique derivation key;
storing, by the device, the subsequent encrypted identifier;
generating, by the device, a subsequent obfuscated identifier based at least in part on the portion of the identifier and a portion of the subsequent encrypted identifier; and
providing, by the device, a subsequent message comprising at least the subsequent obfuscated identifier and the subsequent encrypted identifier.
4 . The computer-implemented method of claim 1 , wherein the portion of the obfuscated identifier comprises a right-most seven digits of the encrypted identifier.
5 . The computer-implemented method of claim 1 , wherein the dynamic value comprises at least one of: a counter, a date, a time, or a transaction value.
6 . The computer-implemented method of claim 1 , wherein providing the obfuscated identifier and the encrypted identifier causes the central server computer to perform operations comprising:
deriving the unique derivation key utilizing a master derivation key and a portion of the obfuscated identifier;
generating a decrypted value from the encrypted identifier of the authorization request message utilizing the unique derivation key;
modifying the authorization request message to include at least a portion of the decrypted value; and
transmitting the modified authorization request message to an authorization computer for authorization.
7 . The computer-implemented method of claim 1 , further comprising calculating a Luhn checksum value based at least in part on the obfuscated identifier, wherein the authorization request message further comprises the Luhn checksum value.
8 . The computer-implemented method of claim 1 , wherein the unique derivation key obtained is derived during a personalization process associated with the device.
9 . The computer-implemented method of claim 1 , wherein the encrypted identifier is decrypted using a second unique derivation key that is derived from eight left-most digits of the obfuscated identifier that is populated in the first data field, the second unique derivation key being derived using a corresponding encryption algorithm that utilizes a master derivation key as a first input and the eight left-most digits of the obfuscated identifier as a second input.
10 . A computing device, comprising:
one or more processors; and
one or more memories storing computer-executable instructions, wherein executing the computer-executable instructions by the one or more processors, causes the computing device to:
obtain a unique derivation key;
obtain a dynamic value;
concatenate an identifier and the dynamic value to generate a concatenated value;
generate an encrypted identifier based on encrypting the concatenated value by inputting the unique derivation key and the identifier into an encryption algorithm, the identifier being a 16-digit primary account identifier;
generate an obfuscated identifier based at least in part on a portion of the identifier and a portion of the encrypted identifier, the obfuscated identifier maintaining routing information of the 16-digit primary account identifier;
provide the obfuscated identifier to an access device, causing the access device to populate a first data field of an authorization request message with the obfuscated identifier prior to transmitting the authorization request message to a central server computer, the first data field being previously associated with identifying primary account identifiers, wherein populating the first data field with the obfuscated identifier maintains the ability to utilize checksum algorithm-based error checking for the first data field; and
provide the encrypted identifier to the access device, causing the access device to populate a second data field of the authorization request message with the encrypted identifier prior to transmitting the authorization request message to the central server computer, wherein populating the second data field with the encrypted identifier instead of the first data field reduces an ability of a nefarious actor to identify the 16-digit primary account identifier from the authorization request message or to track the 16-digit primary account identifier across authorization request messages.
11 . The computing device of claim 10 , wherein the obfuscated identifier and the encrypted identifier are provided to the access device in a message, and wherein the computing device is further configured to:
generate a modified counter value in response to providing the message comprising the obfuscated identifier and the encrypted identifier; and
store the modified counter value.
12 . The computing device of claim 11 , wherein the computing device is further configured to:
generate a subsequent encrypted identifier utilizing the identifier, the modified counter value, and the unique derivation key;
store the subsequent encrypted identifier;
generate a subsequent obfuscated identifier based at least in part on the portion of the identifier and a portion of the subsequent encrypted identifier; and
provide a subsequent message comprising at least the subsequent obfuscated identifier and the subsequent encrypted identifier.
13 . The computing device of claim 10 , wherein the portion of the obfuscated identifier comprises a right-most seven digits of the encrypted identifier.
14 . The computing device of claim 10 , wherein the dynamic value comprises at least one of: a counter, a date, a time, or a transaction value.
15 . The computing device of claim 10 , wherein providing the obfuscated identifier and the encrypted identifier causes the central server computer to perform operations comprising:
deriving the unique derivation key utilizing a master derivation key and a portion of the obfuscated identifier;
generating a decrypted value from the encrypted identifier of the authorization request message utilizing the unique derivation key;
modifying the authorization request message to include at least a portion of the decrypted value; and
transmitting the modified authorization request message to an authorization computer for authorization.
16 . The computing device of claim 10 , wherein the computing device is further configured to calculate a Luhn checksum value based at least in part on the obfuscated identifier, wherein the authorization request message further comprises the Luhn checksum value.