CL2016001353A1 - Methods and systems for the secure authentication of a user and a mobile device without security elements and that generate payment credentials in a payment transaction. - Google Patents

Methods and systems for the secure authentication of a user and a mobile device without security elements and that generate payment credentials in a payment transaction.

Info

Publication number
CL2016001353A1
CL2016001353A1 CL2016001353A CL2016001353A CL2016001353A1 CL 2016001353 A1 CL2016001353 A1 CL 2016001353A1 CL 2016001353 A CL2016001353 A CL 2016001353A CL 2016001353 A CL2016001353 A CL 2016001353A CL 2016001353 A1 CL2016001353 A1 CL 2016001353A1
Authority
CL
Chile
Prior art keywords
mobile
user
generate
payment transaction
mobile computer
Prior art date
Application number
CL2016001353A
Other languages
Spanish (es)
Inventor
Mehdi Collinge
Axel Emilie Jean Charles Cateland
Patrick Smets
Original Assignee
Mastercard International Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Mastercard International Inc filed Critical Mastercard International Inc
Publication of CL2016001353A1 publication Critical patent/CL2016001353A1/en

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3829Payment protocols; Details thereof insuring higher security of transaction involving key management
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/322Aspects of commerce using mobile devices [M-devices]
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/20Point-of-sale [POS] network systems
    • G06Q20/204Point-of-sale [POS] network systems comprising interface for record bearing medium or carrier for electronic funds transfer or payment credit
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/327Short range or proximity payments by means of M-devices
    • G06Q20/3274Short range or proximity payments by means of M-devices using a pictured code, e.g. barcode or QR-code, being displayed on the M-device
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3823Payment protocols; Details thereof insuring higher security of transaction combining multiple encryption tools for a transaction

Abstract

UN MÉTODO PARA GENERAR CREDENCIALES DE PAGO EN UNA TRANSACCIÓN DE PAGO, QUE INCLUYE ALMACENAR, EN UNA MEMORIA DE UN DISPOSITIVO DE COMPUTACIÓN MÓVIL, POR LO MENOS UNA LLAVE DE UN SOLO USO ASOCIADA CON UNA CUENTA DE TRANSACCIONES RECIBIR, MEDIANTE UN DISPOSITIVO DE RECEPCIÓN DEL DISPOSITIVO DE COMPUTACIÓN MÓVIL, UN NÚMERO DE IDENTIFICACIÓN PERSONAL INGRESADO POR UN USUARIO DEL DISPOSITIVO DE COMPUTACIÓN MÓVIL IDENTIFICAR, MEDIANTE UN DISPOSITIVO DE PROCESAMIENTO DEL DISPOSITIVO DE COMPUTACIÓN MÓVIL, UNA PRIMERA LLAVE DE SESIÓN GENERAR, MEDIANTE EL DISPOSITIVO DE PROCESAMIENTO DEL DISPOSITIVO DE COMPUTACIÓN MÓVIL, UNA SEGUNDA LLAVE DE SESIÓN BASÁNDOSE EN POR LO MENOS LA LLAVE DE UN SOLO USO ALMACENADA Y EL NÚMERO DE IDENTIFICACIÓN PERSONAL RECIBIDO GENERAR, MEDIANTE EL DISPOSITIVO DE PROCESAMIENTO DEL DISPOSITIVO DE COMPUTACIÓN MÓVIL, UN PRIMER CRIPTOGRAMA DE APLICACIÓN BASÁNDOSE EN POR LO MENOS LA PRIMERA LLAVE DE SESIÓN GENERAR, MEDIANTE EL DISPOSITIVO DE PROCESAMIENTO DEL DISPOSITIVO DE COMPUTACIÓN MÓVIL, UN SEGUNDO CRIPTOGRAMA DE APLICACIÓN BASÁNDOSE EN POR LO MENOS LA SEGUNDA LLAVE DE SESIÓN Y TRANSMITIR, MEDIANTE UN DISPOSITIVO DE TRANSMISIÓN DEL DISPOSITIVO DE COMPUTACIÓN MÓVIL, POR LO MENOS EL PRIMER CRIPTOGRAMA DE APLICACIÓN Y EL SEGUNDO CRIPTOGRAMA DE APLICACIÓN A UNA ENTIDAD EXTERNA PARA UTILIZARSE EN VALIDAR Y PROCESAR UNA TRANSACCIÓN DE PAGO. SISTEMA QUE REALIZA DICHO MÉTODO.A METHOD FOR GENERATING PAYMENT CREDENTIALS IN A PAYMENT TRANSACTION, INCLUDING STORAGE, IN A MEMORY OF A MOBILE COMPUTER DEVICE, AT LEAST ONE WRENCH OF A SINGLE USE ASSOCIATED WITH A TRANSACTION ACCOUNT RECEIVED, BY A RECEIPT OF A RECEIPT MOBILE COMPUTATION DEVICE, A PERSONAL IDENTIFICATION NUMBER ENTERED BY A USER OF THE MOBILE COMPUTATION DEVICE IDENTIFY, THROUGH A PROCESSING DEVICE OF THE MOBILE COMPUTER DEVICE, A FIRST KEY OF DISPOSAL SETTLEMENT DISPOSAL, DISPOSAL SETTLEMENT A SECOND SESSION KEY BASED ON AT LEAST ONE STORED USE KEY AND RECEIVED PERSONAL IDENTIFICATION NUMBER GENERATE, THROUGH THE MOBILE COMPUTER DEVICE PROCESSING DEVICE, A FIRST CRIPTOGRAM BASED ON THE BASE APPLICATION. SESSION GENERATE THROUGH THE PROCE DEVICE SETTING UP THE MOBILE COMPUTATION DEVICE, A SECOND APPLICATION CRIPTOGRAM BASED ON AT LEAST THE SECOND SESSION KEY AND TRANSMIT, BY MEANS OF A TRANSMISSION DEVICE OF THE MOBILE COMPUTER DEVICE, AT LEAST THE FIRST APPLICATION OF CRIPT TO AN EXTERNAL ENTITY TO BE USED TO VALIDATE AND PROCESS A PAYMENT TRANSACTION. SYSTEM THAT PERFORM SUCH METHOD.

CL2016001353A 2013-12-02 2016-06-02 Methods and systems for the secure authentication of a user and a mobile device without security elements and that generate payment credentials in a payment transaction. CL2016001353A1 (en)

Applications Claiming Priority (5)

Application Number Priority Date Filing Date Title
US201361910819P 2013-12-02 2013-12-02
US201461951842P 2014-03-12 2014-03-12
US201461955716P 2014-03-19 2014-03-19
US201461979132P 2014-04-14 2014-04-14
US201461980784P 2014-04-17 2014-04-17

Publications (1)

Publication Number Publication Date
CL2016001353A1 true CL2016001353A1 (en) 2017-05-12

Family

ID=53274011

Family Applications (1)

Application Number Title Priority Date Filing Date
CL2016001353A CL2016001353A1 (en) 2013-12-02 2016-06-02 Methods and systems for the secure authentication of a user and a mobile device without security elements and that generate payment credentials in a payment transaction.

Country Status (16)

Country Link
EP (1) EP3077972A4 (en)
JP (2) JP6353537B2 (en)
KR (2) KR101809221B1 (en)
CN (1) CN106062799B (en)
AU (1) AU2014357381B2 (en)
BR (1) BR112016012527A2 (en)
CA (1) CA2932346C (en)
CL (1) CL2016001353A1 (en)
HK (1) HK1227146A1 (en)
IL (1) IL245965B (en)
MX (1) MX361793B (en)
NZ (1) NZ720688A (en)
RU (1) RU2663319C2 (en)
SG (1) SG10201800179UA (en)
UA (1) UA115500C2 (en)
WO (1) WO2015084755A1 (en)

Families Citing this family (23)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
AU2014357343B2 (en) 2013-12-02 2017-10-19 Mastercard International Incorporated Method and system for secure tranmission of remote notification service messages to mobile devices without secure elements
CN111523884B (en) * 2014-04-14 2023-05-30 万事达卡国际股份有限公司 Method and system for generating advanced storage keys in mobile devices without secure elements
US10614442B2 (en) 2014-12-03 2020-04-07 Mastercard International Incorporated System and method of facilitating cash transactions at an ATM system without an ATM card using mobile
US10248947B2 (en) * 2015-06-29 2019-04-02 Oberthur Technologies of America Corp. Method of generating a bank transaction request for a mobile terminal having a secure module
US11120436B2 (en) * 2015-07-17 2021-09-14 Mastercard International Incorporated Authentication system and method for server-based payments
SG10201508945YA (en) 2015-10-29 2017-05-30 Mastercard International Inc Method and system for cardless use of an automated teller machine (atm)
US10496982B2 (en) * 2016-02-03 2019-12-03 Accenture Global Solutions Limited Secure contactless card emulation
EP3446274A1 (en) * 2016-04-18 2019-02-27 Bancontact Payconiq Company Method and device for authorizing mobile transactions
WO2017184840A1 (en) 2016-04-21 2017-10-26 Mastercard International Incorporated Method and system for contactless transactions without user credentials
CN109716374B (en) * 2016-09-04 2023-12-29 万事达卡国际公司 Method and system for card-less ATM transactions via mobile device
EP3340094B1 (en) * 2016-12-22 2021-04-28 Mastercard International Incorporated Method for renewal of cryptographic whiteboxes under binding of new public key and old identifier
WO2018136914A1 (en) * 2017-01-23 2018-07-26 Mastercard International Incorporated Method and system for authentication via a trusted execution environment
EP3364329B1 (en) 2017-02-21 2023-07-26 Mastercard International Incorporated Security architecture for device applications
EP3364352A1 (en) 2017-02-21 2018-08-22 Mastercard International Incorporated Determining legitimate conditions at a computing device
EP3364363A1 (en) 2017-02-21 2018-08-22 Mastercard International Incorporated Transaction cryptogram
CN107274183B (en) * 2017-03-21 2020-05-22 中国银联股份有限公司 Transaction verification method and system
US11468444B2 (en) * 2017-12-18 2022-10-11 Mastercard International Incorporated Method and system for bypassing merchant systems to increase data security in conveyance of credentials
KR101972599B1 (en) * 2018-06-19 2019-04-25 김승훈 Apparatus and Method for Processing Session Key and Recording Medium Recording Program thereof
US10581611B1 (en) * 2018-10-02 2020-03-03 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
EP3640878B1 (en) * 2018-10-17 2023-06-21 Swatch Ag Method and system for activating a portable contactless payment object
US11803827B2 (en) 2019-11-01 2023-10-31 Mastercard International Incorporated Method and system for enabling cardless transactions at an ATM for any institutional entity
CN111901109B (en) * 2020-08-04 2022-10-04 华人运通(上海)云计算科技有限公司 White-box-based communication method, device, equipment and storage medium
CN113421084B (en) * 2021-05-26 2023-03-24 歌尔股份有限公司 Bus card processing method, device, equipment and readable storage medium

Family Cites Families (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP4183823B2 (en) * 1999-02-10 2008-11-19 富士通株式会社 Data verification device, data verification system, and data verification program storage medium
US7249093B1 (en) * 1999-09-07 2007-07-24 Rysix Holdings, Llc Method of and system for making purchases over a computer network
JP2004086599A (en) * 2002-08-27 2004-03-18 Toppan Printing Co Ltd Credit card information management device, management method, and program thereof
US7873572B2 (en) * 2004-02-26 2011-01-18 Reardon David C Financial transaction system with integrated electronic messaging, control of marketing data, and user defined charges for receiving messages
CA2649305C (en) * 2006-04-10 2014-05-06 Trust Integration Services B.V. Arrangement of and method for secure data transmission
US8713655B2 (en) * 2008-04-21 2014-04-29 Indian Institute Of Technology Method and system for using personal devices for authentication and service access at service outlets
US20120143752A1 (en) * 2010-08-12 2012-06-07 Mastercard International, Inc. Multi-commerce channel wallet for authenticated transactions
US8746553B2 (en) * 2010-09-27 2014-06-10 Mastercard International Incorporated Purchase Payment device updates using an authentication process
KR20120110926A (en) * 2011-03-30 2012-10-10 주식회사 비즈모델라인 Method and system for card payment using program identity, smart phone
US20120317628A1 (en) * 2011-06-09 2012-12-13 Yeager C Douglas Systems and methods for authorizing a transaction
US10515359B2 (en) * 2012-04-02 2019-12-24 Mastercard International Incorporated Systems and methods for processing mobile payments by provisioning credentials to mobile devices without secure elements
US9171302B2 (en) * 2012-04-18 2015-10-27 Google Inc. Processing payment transactions without a secure element

Also Published As

Publication number Publication date
WO2015084755A1 (en) 2015-06-11
IL245965A0 (en) 2016-07-31
KR101809221B1 (en) 2017-12-14
MX2016007217A (en) 2016-12-09
NZ720688A (en) 2017-09-29
SG10201800179UA (en) 2018-02-27
MX361793B (en) 2018-12-17
KR102025816B1 (en) 2019-09-26
AU2014357381A1 (en) 2016-06-16
KR20170139689A (en) 2017-12-19
BR112016012527A2 (en) 2017-08-08
UA115500C2 (en) 2017-11-10
KR20160091418A (en) 2016-08-02
CA2932346A1 (en) 2015-06-11
CN106062799B (en) 2022-04-29
CN106062799A (en) 2016-10-26
AU2014357381B2 (en) 2017-03-23
IL245965B (en) 2022-05-01
JP6353537B2 (en) 2018-07-04
EP3077972A1 (en) 2016-10-12
JP2017504871A (en) 2017-02-09
JP2018164281A (en) 2018-10-18
CA2932346C (en) 2018-09-04
RU2663319C2 (en) 2018-08-03
HK1227146A1 (en) 2017-10-13
EP3077972A4 (en) 2017-08-09

Similar Documents

Publication Publication Date Title
CL2016001353A1 (en) Methods and systems for the secure authentication of a user and a mobile device without security elements and that generate payment credentials in a payment transaction.
CL2016001351A1 (en) Method and system for the secure transmission of messages from the remote transmission service to mobile devices without security features
CL2018002363A1 (en) Determination of a common secret for the secure exchange of information and deterministic and hierarchical cryptographic keys.
BR112017002747A2 (en) computer implemented method, and, computer system.
TR201902104T4 (en) Systems and methods for secure communication.
BR112017003018A2 (en) secure provision of an authentication credential
CU20180116A7 (en) SYSTEMS AND METHODS TO PROVIDE A MULTIFACTORIAL PERSONAL IDENTITY VERIFICATION BASED ON A BLOCK CHAIN
EP3627843A3 (en) Systems and methods for performing transport i/o
WO2015187640A3 (en) System and method for secure review of audit logs
PH12018501578A1 (en) Credit payment method and apparatus based on mobile terminal p2p
MY189090A (en) Method and apparatus of barcode-based mobile payment and service processing
UA117951C2 (en) Method and system for generating an advanced storage key in a mobile device without secure elements
BR112012022938A2 (en) methods and system
WO2016073047A3 (en) Environment-aware security tokens
IN2014DE03249A (en)
BR112018073935A2 (en) method, user device, and authorization computer.
JP2016522468A5 (en)
SG2013042429A (en) Method for receiving an electronic receipt of an electronic payment transaction into a mobile device
CL2014002816A1 (en) User authentication method, which includes receiving a user request to initiate authentication session, accessing a memory stored record associated with the user, generating a security matrix, transmitting the matrix to the user, receiving from the user an orderly sequence of values of code selected from the matrix, validate the received sequence, generate an authentication result; apparatus; system
NZ629125A (en) Credential management system
GB2562923A (en) Data security system with encryption
SG11201900367SA (en) Method and device for providing and obtaining graphic code information, and terminal
MX2018000737A (en) Multi-mode payment systems and methods.
BR112013001728A2 (en) methods for encrypting a value entered in a user device, for verifying a value communicated to an authentication system via a communications network, and for communicating a value entered in a user device to an authentication system via a communications network, user device, system, software, and computer readable medium.
WO2016190918A3 (en) Multiple protocol transaction encryption