- 专利标题: METHODS FOR SECURE CRYPTOGRAM GENERATION
-
申请号: US15723001申请日: 2017-10-02
-
公开(公告)号: US20180026787A1公开(公告)日: 2018-01-25
- 发明人: Eric Le Saint , James Gordon , Roopesh Joshi
- 申请人: Eric Le Saint , James Gordon , Roopesh Joshi
- 主分类号: H04L9/32
- IPC分类号: H04L9/32 ; H04L9/08 ; H04L29/06
摘要:
Embodiments of the invention introduce efficient methods for securely generating a cryptogram by a user device, and validating the cryptogram by a server computer. A secure communication can be conducted whereby a user device provides a cryptogram without requiring the user device to persistently store an encryption key or other sensitive data used to generate the cryptogram. The user device and server computer can mutually authenticate and establish a shared secret. Using the shared secret, the server computer can derive a session key and transmit key derivation parameters encrypted using the session key to the user device. The user device can derive the session key using the shared secret, decrypt the encrypted key derivation parameters, and store the key derivation parameters. Key derivation parameters and the shared secret can be used to generate a single use cryptogram key, which can be used to generate a cryptogram for conducting secure communications.
公开/授权文献
- US10389533B2 Methods for secure cryptogram generation 公开/授权日:2019-08-20
信息查询