Credential management in distributed computing system

    公开(公告)号:US11997190B2

    公开(公告)日:2024-05-28

    申请号:US17616303

    申请日:2020-04-22

    Abstract: A computing node in a distributed information security system, wherein the computing node is adapted to communicate with a subset of clients of the distributed information security system, wherein the computing node provides at least one cryptographic service for the clients of the subset, wherein the computing node is provisioned with a plurality of keys for use by said at least one cryptographic service, wherein the computing node is adapted to associate a key from the plurality of keys to a service request for a client according to a deterministic process based on one or more data associated with the client. A distributed information security system comprising a plurality of such nodes is also described, together with a method of providing a cryptographic service at such a computing node.

    Method and system for secure authentication of user and mobile device without secure elements

    公开(公告)号:US11334890B2

    公开(公告)日:2022-05-17

    申请号:US14558189

    申请日:2014-12-02

    Abstract: A method for generating payment credentials in a payment transaction includes: storing, in a memory, at least a single use key associated with a transaction account; receiving, by a receiving device, a personal identification number; identifying, by a processing device, a first session key; generating, by the processing device, a second session key based on at least the stored single use key and the received personal identification number; generating, by the processing device, a first application cryptogram based on at least the first session key; generating, by the processing device, a second application cryptogram based on at least the second session key; and transmitting, by a transmitting device, at least the first application cryptogram and second application cryptogram for use in a payment transaction.

    Cryptographic authentication and tokenized transactions

    公开(公告)号:US11301844B2

    公开(公告)日:2022-04-12

    申请号:US16325084

    申请日:2017-08-11

    Abstract: A cryptographic method of performing a tokenised transaction between a payment offering party and a payment accepting party is described. The tokenised transaction is mediated by a transaction scheme. The payment accepting party is provided with a merchant identity and a merchant certificate associated with that identity by the transaction scheme provider. The payment accepting party provides the merchant identity and transaction seed data to the payment offering party. The payment offering party validates the merchant identity and uses the merchant identity and the transaction seed data to generate a cryptogram for the tokenised transaction. The payment offering party provides the cryptogram to the payment accepting party for transmission to the transaction scheme provider for authorisation of the tokenised transaction. A suitable user computing device and merchant computing device for acting as payment offering party and payment accepting party respectively are also described.

    System and method for end-to-end key management

    公开(公告)号:US10956904B2

    公开(公告)日:2021-03-23

    申请号:US15218842

    申请日:2016-07-25

    Abstract: Provided are a system and method for managing encryption keys used by a payment application on a mobile device. The method includes executing a mobile payment application in a user domain of the mobile device, where the user domain is an operating environment in which applications are executed and accessed by a user, importing a plurality of encryption keys for use by the mobile payment application into a system domain of the mobile device, where the system domain is a more secure operating environment controlled by an operating system, encrypting payment information of the mobile payment application in the system domain using one or more of the imported keys while executing the mobile payment application in the user domain, and transmitting the encrypted payment information to a merchant.

    Security for mobile applications
    25.
    发明授权

    公开(公告)号:US10909531B2

    公开(公告)日:2021-02-02

    申请号:US14712343

    申请日:2015-05-14

    Abstract: A mobile computing device has at least one processor and at least one memory together providing a first execution environment and a second execution environment logically isolated from the first execution environment. The following approach is taken to manage data items for an application executing the first execution environment. A trust relationship is established between a trust client in the second execution environment and a remote trusted party and the trust client receives one or more data items from the remote trusted party. On executing the application in the first execution environment, the trust client provides the data items or further data items derived therefrom to the application. Provision of these data items may be conditional upon a user authentication process. A suitable mobile computing device is also described.

    Method and system for computing code management platform
    28.
    发明授权
    Method and system for computing code management platform 有权
    计算代码管理平台的方法和系统

    公开(公告)号:US09218479B2

    公开(公告)日:2015-12-22

    申请号:US14463054

    申请日:2014-08-19

    CPC classification number: G06F21/44 H04L63/08 H04L63/0876 H04L63/18

    Abstract: A method for authenticating a computing device includes: storing an account profile, the profile including data related to a service account including an alphanumeric code; generating a session identifier and a seed value; computing a first hash using the session identifier; computing a second hash using the session identifier and the alphanumeric code; computing a third hash using the second hash and a utilized seed value; transmitting the session identifier to a computing device via a first communication protocol; transmitting the session identifier and first hash to a remote notification service for transmission to the computing device via a second communication protocol; receiving a fourth hash and the session identifier from the computing device via the first communication protocol; validating the fourth hash based on a comparison of the fourth hash and the computed third hash; and transmitting a validation result to the computing device based on the validation step.

    Abstract translation: 用于认证计算设备的方法包括:存储帐户简档,所述简档包括与包括字母数字代码的服务帐户相关的数据; 生成会话标识符和种子值; 使用会话标识符计算第一散列; 使用会话标识符和字母数字代码来计算第二散列; 使用所述第二散列和所使用的种子值来计算第三散列; 经由第一通信协议将会话标识符发送到计算设备; 将所述会话标识符和第一散列发送到远程通知服务,以经由第二通信协议传输到所述计算设备; 经由第一通信协议从计算设备接收第四散列和会话标识符; 基于第四散列和所计算的第三散列的比较来验证第四散列; 以及基于所述验证​​步骤将验证结果发送到所述计算设备。

    METHODS AND SYSTEMS FOR CONDUCTING REMOTE POINT OF SALE TRANSACTIONS
    29.
    发明申请
    METHODS AND SYSTEMS FOR CONDUCTING REMOTE POINT OF SALE TRANSACTIONS 审中-公开
    导致销售交易的远程点的方法和系统

    公开(公告)号:US20140101036A1

    公开(公告)日:2014-04-10

    申请号:US14050974

    申请日:2013-10-10

    Abstract: Systems, methods, apparatus and computer program code are provided for operating a mobile device to conduct a transaction which include obtaining, by a mobile device operating a mobile payment application, a transaction payload from a merchant, extracting a payment gateway identifier from the transaction payload and establishing a secure communication channel with a payment gateway identified by the payment gateway identifier, receiving, from the payment gateway, item data associated with the transaction, the item data obtained by the payment gateway from the merchant, and receiving, from a user operating the mobile device, a confirmation to complete the transaction using a payment account associated with the user and transmitting the confirmation to the payment gateway with payment account credentials associated with the payment account.

    Abstract translation: 提供了系统,方法,装置和计算机程序代码,用于操作移动设备进行交易,其包括由操作移动支付应用的移动设备从商家获取交易有效载荷,从交易有效载荷中提取支付网关标识符 以及与所述支付网关标识符识别的支付网关建立安全通信信道,从所述支付网关接收与所述交易相关联的项目数据,由所述支付网关从所述商家获得的所述项目数据,以及从用户操作 所述移动设备使用与所述用户相关联的支付账户来完成所述交易的确认,并且使用与所述支付账户相关联的支付帐户凭证将所述确认发送到所述支付网关。

Patent Agency Ranking