×

Pre-generation of session keys for electronic transactions and devices that pre-generate session keys for electronic transactions

  • US 10,460,314 B2
  • Filed: 07/10/2013
  • Issued: 10/29/2019
  • Est. Priority Date: 07/10/2013
  • Status: Active Grant
First Claim
Patent Images

1. A method of securing a transaction between a user terminal and a transaction terminal, comprising:

  • generating, using a processing circuit of the user terminal, a plurality of session cryptographic keys from a master cryptographic key on the user terminal and based on a plurality of possible values of a transaction counter;

    securing the plurality of session cryptographic keys, wherein said securing comprises;

    deleting the master cryptographic key from the user terminal after generating the plurality of session cryptographic keys to prevent regeneration of the plurality of session cryptographic keys; and

    encrypting, using the processing circuit of the user terminal, the plurality of session cryptographic keys to provide a plurality of encrypted session cryptographic keys;

    storing the plurality of encrypted session cryptographic keys and one of the plurality of possible values of the transaction counter in the user terminal;

    generating, using the processing circuit of the user terminal after deleting the master cryptographic key from the user terminal, a cryptogram that is based on a first one of the plurality of encrypted session cryptographic keys and based on transaction data for the transaction;

    transmitting the cryptogram to the transaction terminal over a computer network between the transaction terminal and the user terminal;

    updating the transaction counter; and

    deleting the first one of the plurality of encrypted session cryptographic keys from the user terminal after generating the cryptogram.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×