×

Token security on a communication device

  • US 9,942,043 B2
  • Filed: 04/23/2015
  • Issued: 04/10/2018
  • Est. Priority Date: 04/23/2014
  • Status: Active Grant
First Claim
Patent Images

1. A communication device comprising:

  • a processor; and

    a non-transitory computer readable medium coupled to the processor and implementing an application that performs operations for enhancing security of storing a token on the communication device, the operations including;

    sending, to a token request computer, a request for the token, wherein the token is a substitute for an account identifier associated with an account of the user, and the account identifier is not computationally derivable from the token;

    receiving from the token requester computer;

    a session key encrypted with a hash value derived from user authentication data that authenticates a user of the communication device; and

    the token encrypted with the session key;

    storing the session key encrypted with the hash value and the token encrypted with the session key in a memory of the communication device, wherein the encrypted session key and the encrypted token are automatically deleted from the communication device when power to the communication device is interrupted; and

    subsequent to storing the encrypted session key and the encrypted token on the communication device;

    receiving user authentication data on a user interface of the communication device to initiate a transaction via the application;

    computing the hash value from the received user authentication data;

    decrypting the encrypted session key using the hash value;

    decrypting the encrypted token using the decrypted session key;

    temporarily storing the decrypted token on the communication device;

    initiating the transaction using the decrypted token instead of the account identifier; and

    removing the decrypted token from the communication device, wherein the decrypted token is removed from the communication device upon detecting that the application is no longer active.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×