Methods, systems, and computer program products for securely rendering sensitive data
By converting sensitive data into non-text visual elements and encrypting them, the security threat of displaying sensitive data in plaintext is resolved, achieving secure rendering and protection.
Patent Information
- Application Number
- CN202080060628.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-08-30
- Filing Date
- 2020-08-31
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2040-08-31
AI Technical Summary
In existing technologies, when sensitive data is displayed in plaintext, it is vulnerable to security threats such as screen capture, malicious scripts, malicious browser plugins, and session hijacking.
Sensitive data is converted into non-textual visual elements, such as images or video frames, and then transmitted to the receiver for rendering after encryption and watermark embedding, ensuring data security.
It effectively prevents sensitive data from being identified and copied by malicious attackers, while allowing authorized users to view it normally, thus improving the security of data display.
Smart Images

Figure CN114424200B_ABST
Abstract
Description
[0001] Cross-referencing related applications
[0002] This application claims priority to Indian Provisional Patent Application No. 201941034973, filed on August 30, 2019, the full disclosure of which is incorporated herein by reference. Technical Field
[0003] The subject matter of this disclosure relates in general to methods, systems, and products for rendering sensitive data, and in some specific embodiments or aspects to methods, systems, and computer program products for securely rendering sensitive data using image and / or video frames. Background Technology
[0004] In some cases, it may be necessary to display certain sensitive data to users (e.g., account identifier, main account number (PAN), card number, payment card number, token, etc.). For example, at least one user (e.g., transaction service provider, issuer, customer, merchant, acquirer, etc.) may need to review records that include sensitive data, such as for verification, security audits, fraud audits, customer support, audits, record keeping, etc.
[0005] However, when sensitive data is displayed in plain text (e.g., plain text, Hypertext Markup Language (HTML) etc.), such displays may pose certain security threats, such as screen capture, malicious / exotic scripts (e.g., JavaScripts, etc.), malicious browser plugins, account takeover, session hijacking, clipboard hijacking, etc. Summary of the Invention
[0006] Therefore, one objective of the subject matter currently being disclosed is to provide methods, systems, and computer program products for securely rendering sensitive data.
[0007] According to a non-limiting embodiment, a method for securely rendering sensitive data is provided. In some non-limiting embodiments, a method for securely rendering sensitive data may include receiving account identifier data associated with at least one account identifier. The account identifier data may be converted into at least one non-text visual element. The at least one non-text visual element may be transmitted to at least one receiver.
[0008] In some non-limiting embodiments, at least one receiver may render at least one non-text visual element.
[0009] In some non-limiting embodiments, at least one non-text visual element may include an image. Alternatively, at least one non-text visual element may include video comprising at least one frame.
[0010] In some non-limiting embodiments, at least one non-text visual element may be encrypted to form at least one encrypted non-text visual element. Alternatively, transmitting at least one non-text visual element may include transmitting at least one encrypted non-text visual element to at least one receiver. In some non-limiting embodiments, at least one key may be exchanged with at least one receiver. In some non-limiting embodiments, exchanging at least one key may include embedding at least one key in at least one non-text visual element.
[0011] In some non-limiting embodiments, at least one watermark may be embedded in at least one non-text visual element. In some non-limiting embodiments, at least one watermark may include a digital copy of a handwritten signature. Alternatively or additionally, embedding at least one watermark may include modifying at least one pixel of at least one non-text visual element based on the watermark. In some non-limiting embodiments, modifying at least one pixel may include modifying multiple pixels such that the watermark (e.g., a digital copy of a handwritten signature) is imperceptible to a human user.
[0012] According to a non-limiting embodiment, a system for securely rendering sensitive data is provided. In some non-limiting embodiments, the system for securely rendering sensitive data may include a user device, a hardware security module (HSM), and a server. The server may be configured to receive a request to display an account identifier from the user device; retrieve account identifier data associated with the account identifier from the HSM; convert the account identifier data into at least one non-text visual element; and / or transmit at least one non-text visual element to the user device.
[0013] In some non-limiting embodiments, the server may include a media converter. Alternatively, converting account identifier data may involve the server using a media converter to convert the account identifier data into at least one non-textual visual element.
[0014] In some non-limiting embodiments, the user device may include a browser and a renderer. Alternatively, the user device may be configured to render at least one non-text visual element using a renderer; and / or to display at least one non-text visual element using a browser.
[0015] In some non-limiting embodiments, the server may be further configured to exchange at least one key with the user device; and / or encrypt at least one non-text visual element based on at least one key to form at least one encrypted non-text visual element. Alternatively, transmitting at least one non-text visual element may include transmitting at least one encrypted non-text visual element to the user device. In some non-limiting embodiments, the user device may be further configured to: decrypt at least one encrypted non-text visual element based on at least one key to form at least one decrypted non-text visual element. Alternatively, displaying at least one non-text visual element may include displaying at least one decrypted non-text visual element.
[0016] In some non-limiting embodiments, the user device may be configured to: receive a digital copy of the handwritten signature; and / or transmit the digital copy of the handwritten signature to a server. Alternatively, the server may be further configured to: receive a digital copy of the handwritten signature from the user device; and / or embed the digital copy of the handwritten signature in at least one non-text visual element as a watermark. In some non-limiting embodiments, transmitting at least one non-text visual element may include transmitting at least one non-text visual element in which the watermark is embedded to the user device.
[0017] In some non-limiting embodiments, embedding a digital copy of a handwritten signature as a watermark may include modifying at least one pixel of at least one non-textual visual element based on the digital copy of the handwritten signature. Alternatively, modifying at least one pixel may include modifying multiple pixels such that the digital copy of the handwritten signature is imperceptible to a human user.
[0018] According to a non-limiting embodiment, a computer program product for securely rendering sensitive data is provided. The computer program product may include at least one non-transitory computer-readable medium comprising one or more instructions that, when executed by at least one processor, cause the at least one processor to receive account identifier data associated with at least one account identifier; convert the account identifier data into at least one non-textual visual element; and / or transmit the at least one non-textual visual element to at least one receiver.
[0019] In some non-limiting embodiments, at least one non-textual visual element may include at least one of an image, a video including at least one frame, any combination thereof, etc.
[0020] In some non-limiting embodiments, when executed by at least one processor, the instructions may further cause the at least one processor to perform the following operations: exchange at least one key with at least one receiver; and / or encrypt at least one non-textual visual element based on at least one key to form at least one encrypted non-textual visual element. Alternatively or additionally, transmitting at least one non-textual visual element may include transmitting at least one encrypted non-textual visual element to at least one receiver.
[0021] In some non-limiting embodiments, the instructions, when executed by at least one processor, may further cause the at least one processor to perform the following operation: embedding at least one watermark into at least one non-text visual element. Alternatively or additionally, embedding at least one watermark may include modifying at least one pixel of the at least one non-text visual element based on the at least one watermark. In some non-limiting embodiments, modifying at least one pixel may include modifying multiple pixels such that the at least one watermark is imperceptible to a human user.
[0022] Other embodiments are described in the following numbered clauses:
[0023] Article 1: A computer-implemented method comprising: receiving, with at least one processor, account identifier data associated with at least one account identifier; converting, with the at least one processor, the account identifier data into at least one non-textual visual element; and transmitting, with the at least one processor, the at least one non-textual visual element to at least one receiver.
[0024] Article 2: According to the method described in Article 1, wherein the at least one receiver renders the at least one non-text visual element.
[0025] Article 3: In any of the preceding methods, the at least one non-textual visual element includes an image.
[0026] Article 4: In any of the preceding methods, the at least one non-textual visual element comprises video, the video comprising at least one frame.
[0027] Article 5: The method according to any one of the preceding articles further includes: encrypting the at least one non-textual visual element with the at least one processor to form at least one encrypted non-textual visual element, wherein transmitting the at least one non-textual visual element includes transmitting the at least one encrypted non-textual visual element to the at least one receiver.
[0028] Article 6: The method according to any of the preceding articles further includes: exchanging at least one key with the at least one receiver and the at least one processor.
[0029] Article 7: The method according to any of the preceding articles, wherein exchanging the at least one key includes embedding the at least one key in the at least one non-textual visual element.
[0030] Article 8: The method according to any of the preceding articles further includes: embedding at least one watermark into the at least one non-text visual element using the at least one processor.
[0031] Article 9: In any of the preceding methods, the at least one watermark comprises a digital copy of a handwritten signature, and embedding the at least one watermark comprises modifying at least one pixel of the at least one non-textual visual element based on the watermark.
[0032] Article 10: The method according to any of the preceding articles, wherein modifying the at least one pixel includes modifying multiple pixels such that the digital copy of the handwritten signature cannot be perceived by a human user.
[0033] Article 11: A system comprising: a user device; a hardware security module (HSM); and a server including a media converter, the server being configured to: receive a request from the user device to display an account identifier; retrieve account identifier data associated with the account identifier from the HSM; convert the account identifier data into at least one non-textual visual element; and transmit the at least one non-textual visual element to the user device using at least one processor.
[0034] Article 12: The system according to Article 11, wherein the user device includes a browser and a renderer, and wherein the user device is configured to: render the at least one non-text visual element with the renderer; and display the at least one non-text visual element as rendered with the browser.
[0035] Article 13: The system according to Article 11 or Article 12, wherein: the server is further configured to: exchange at least one key with the user device; and encrypt the at least one non-text visual element based on the at least one key to form at least one encrypted non-text visual element, wherein transmitting the at least one non-text visual element includes transmitting the at least one encrypted non-text visual element to the user device; and the user device is further configured to: decrypt the at least one encrypted non-text visual element based on the at least one key to form at least one decrypted non-text visual element, wherein displaying the at least one non-text visual element includes displaying the at least one decrypted non-text visual element.
[0036] Article 14: A system according to any one of Articles 11 to 13, wherein: the user device is configured to: receive a digital copy of a handwritten signature; and transmit the digital copy of the handwritten signature to the server; and the server is further configured to: receive the digital copy of the handwritten signature from the user device; and embed the digital copy of the handwritten signature as a watermark in the at least one non-text visual element, wherein transmitting the at least one non-text visual element includes transmitting the at least one non-text visual element in which the watermark is embedded to the user device.
[0037] Article 15: A system according to any one of Articles 11 to 14, wherein embedding the digital copy of the handwritten signature as the watermark includes modifying at least one pixel of the at least one non-textual visual element based on the digital copy of the handwritten signature, and wherein modifying the at least one pixel includes modifying multiple pixels such that the digital copy of the handwritten signature is imperceptible to a human user.
[0038] Article 16: A computer program product comprising at least one non-transient computer-readable medium, the at least one non-transient computer-readable medium comprising one or more instructions, the one or more instructions, when executed by at least one processor, causing the at least one processor to perform the following operations: receiving account identifier data associated with at least one account identifier; converting the account identifier data into at least one non-textual visual element; and transmitting the at least one non-textual visual element to at least one receiver.
[0039] Article 17: The computer program product pursuant to Article 16, wherein the at least one non-textual visual element comprises at least one of an image, a video comprising at least one frame, any combination thereof, etc.
[0040] Article 18: A computer program product according to Article 16 or Article 17, wherein the instructions, when executed by the at least one processor, further cause the at least one processor to perform the following operations: exchange at least one key with the at least one receiver; and encrypt the at least one non-textual visual element based on the at least one key to form at least one encrypted non-textual visual element, wherein transmitting the at least one non-textual visual element includes transmitting the at least one encrypted non-textual visual element to the at least one receiver.
[0041] Article 19: A computer program product according to any one of Articles 16 to 18, wherein the instructions, when executed by the at least one processor, further cause the at least one processor to perform the following operations: embedding at least one watermark in the at least one non-text visual element, wherein embedding the at least one watermark includes modifying at least one pixel of the at least one non-text visual element based on the at least one watermark.
[0042] Article 20: A computer program product according to any one of Articles 16 to 19, wherein modifying the at least one pixel includes modifying multiple pixels such that the at least one watermark is imperceptible to a human user.
[0043] These and other features and characteristics of the subject matter, as well as the operational methods and functions of the associated structural elements and combinations of parts, and the economics of manufacture, will become more apparent upon consideration of the following description and appended claims with reference to the accompanying drawings, all of which form part of this specification, wherein like reference numerals denote corresponding parts in the figures. However, it should be clearly understood that the drawings are for illustrative and descriptive purposes only and are not intended to be a definition of limitation on the disclosed subject matter. Unless the context clearly specifies otherwise, the singular forms “a” and “described” as used in this specification and claims include plural indicators. Attached Figure Description
[0044] Additional advantages and details of the disclosed subject matter are explained in more detail below with reference to exemplary embodiments illustrated in the accompanying drawings, in which:
[0045] Figure 1 A diagram showing a non-limiting implementation of an environment in which the methods, systems, and / or computer program products described herein can be carried out based on the principles of the currently disclosed subject matter;
[0046] Figure 2 yes Figure 1 A diagram of a non-limiting embodiment of components of one or more devices;
[0047] Figure 3 This is a flowchart of a non-restrictive implementation of a process for securely rendering sensitive data based on the principles of the currently disclosed subject matter;
[0048] Figure 4 It is based on the principles of the currently publicly available topic. Figure 3 The diagram illustrates a non-limiting exemplary implementation of a non-limiting scheme of the process;
[0049] Figure 5A and Figure 5B It is based on the principles of the currently publicly available topic. Figure 3The diagram illustrates a non-limiting exemplary embodiment of a non-limiting implementation of the process; and
[0050] Figure 6 It is based on the principles of the currently publicly available topic. Figure 3 The diagram shows a non-limiting exemplary implementation of a non-limiting embodiment of the process. Detailed Implementation
[0051] For descriptive purposes, the terms “end,” “upper,” “lower,” “right,” “left,” “vertical,” “horizontal,” “top,” “bottom,” “lateral,” “longitudinal,” and their derivatives are intended to refer to the orientation of the disclosed subject matter as shown in the accompanying drawings. However, it should be understood that the disclosed subject matter may take various alternative variations and sequences of steps, except where explicitly specified otherwise. It should also be understood that the specific apparatus and processes shown in the drawings and described in the following specification are merely exemplary embodiments or aspects of the disclosed subject matter. Therefore, unless otherwise indicated, specific dimensions and other physical characteristics associated with the embodiments or aspects disclosed herein should not be considered limiting.
[0052] The aspects, components, elements, structures, actions, steps, functions, instructions, etc., used herein should not be construed as critical or essential unless explicitly stated otherwise. Furthermore, as used herein, the article “a” is intended to include one or more items and is interchangeable with “one or more” and “at least one.” Additionally, as used herein, the term “set” is intended to include one or more items (e.g., related items, unrelated items, combinations of related and unrelated items, etc.) and is interchangeable with “one or more” or “at least one.” Where only one item is desired, the term “a” or similar language is used. Furthermore, as used herein, the terms “having” and similar expressions are intended to be open-ended terms. Additionally, unless explicitly stated otherwise, the phrase “based on” is intended to mean “at least partially based on.”
[0053] As used herein, the terms "communication" and "transmission" can refer to the receiving, accepting, sending, transmitting, or providing of information (e.g., data, signals, messages, instructions, commands, etc.). For one unit (e.g., a device, system, component of a device or system, or a combination thereof) to communicate with another unit means that the first unit is able to receive information directly or indirectly from and / or send information to the other unit. This can refer to a direct or indirect connection that is inherently wired and / or wireless (e.g., a direct communication connection, an indirect communication connection, etc.). Furthermore, although the transmitted information may be modified, processed, relayed, and / or routed between the first and second units, the two units can also communicate with each other. For example, the first unit can communicate with the second unit even if it passively receives information and does not actively send information to the second unit. As another example, the first unit can communicate with the second unit if at least one intermediate unit (e.g., a third unit located between the first and second units) processes information received from the first unit and transmits the processed information to the second unit. In some non-limiting embodiments or aspects, a message may refer to a network packet (e.g., a data packet, etc.) that includes data. It should be understood that many other arrangements are possible.
[0054] As used herein, the terms “issuer institution,” “portable financial device issuer,” “issuer,” or “issuer bank” may refer to one or more entities that provide customers with accounts for conducting transactions (e.g., payment transactions) (e.g., initiating credit and / or debit payments). For example, an issuer institution may provide customers with an account identifier, such as a primary account number (PAN), that uniquely identifies one or more accounts associated with said customer. The account identifier may be embodied in a portable financial device, such as a physical financial instrument (e.g., a payment card), and / or may be electronic and used for electronic payments. The terms “issuer institution” and “issuer institution system” may also refer to one or more computer systems operated by or on behalf of an issuer institution, such as a server computer executing one or more software applications. For example, an issuer institution system may include one or more authorization servers for authorizing transactions.
[0055] As used herein, the term "account identifier" may include one or more types of identifiers (e.g., PAN, card number, payment card number, token, etc.) associated with a user account. In some non-limiting embodiments or aspects, an issuing authority may provide a user with an account identifier (e.g., PAN, token, etc.) that uniquely identifies one or more accounts associated with the user. The account identifier may be embodied in a physical financial instrument (e.g., portable financial instrument, payment card, credit card, debit card, etc.) and / or may be electronic information transmitted to the user enabling the user to make electronic payments. In some non-limiting embodiments or aspects, the account identifier may be an original account identifier, wherein the original account identifier is provided to the user when an account associated with the account identifier is created. In some non-limiting embodiments or aspects, the account identifier may be an account identifier provided to the user after the original account identifier has been provided to the user (e.g., a supplementary account identifier). For example, if the original account identifier is forgotten, stolen, etc., a supplementary account identifier may be provided to the user. In some non-limiting embodiments or aspects, the account identifier may be associated directly or indirectly with an issuing authority, such that the account identifier may be a token mapped to a PAN or other type of account identifier. Account identifiers can be any combination of alphanumeric characters, symbols, and / or symbols. The issuing entity can be associated with a Bank Identification Number (BIN) that uniquely identifies the issuing entity.
[0056] As used herein, the term "payment token" or "token" may refer to an identifier used as an alternative or replacement identifier for an account identifier, such as a PAN. A token may be associated with a PAN or other account identifier in one or more data structures (e.g., one or more databases, etc.) such that the token can be used to conduct transactions (e.g., payment transactions) without the direct use of the account identifier, such as the PAN. In some examples, an account identifier, such as a PAN, may be associated with multiple tokens for different individuals, different uses, and / or different purposes. For example, a payment token may include a string of numeric and / or alphanumeric characters that can be used as a replacement for the original account identifier. For example, the payment token "4900 0000 0000 0001" may be used in place of the PAN "4147 0900 0000 1234". In some non-limiting embodiments or aspects, the payment token may be "reserved format" and may have a numerical format consistent with account identifiers used in existing payment processing networks (e.g., the ISO 8583 Financial Transaction Message Format). In some non-limiting embodiments or aspects, a payment token may replace a PAN for initiating, authorizing, settling, or resolving payment transactions, or represent the original credential in other systems where the original credential is typically provided. In some non-limiting embodiments or aspects, a token value may be generated such that the original PAN or other account identifier may not be computably recoverable from the token value (e.g., using a one-way hash or other cryptographic function). Furthermore, in some non-limiting embodiments or aspects, the token format may be configured to allow an entity receiving a payment token to identify it as a payment token and to recognize the entity issuing the token.
[0057] As used herein, the term “providing” can refer to a process that enables a device to use resources or services. For example, providing may involve enabling a device to use an account to perform a transaction. Alternatively or additionally, providing may include adding provisioning data associated with account data (e.g., a payment token representing an account) to the device.
[0058] As used herein, the term "token requester" may refer to an entity attempting to implement tokenization according to embodiments or aspects of the subject matter of this disclosure. For example, a token requester may initiate a request to tokenize a PAN by submitting a token request message to a token service provider. Alternatively or concurrently, once the requester has received a payment token in response to the token request message, the token requester may no longer need to store the PAN associated with the token. In some non-limiting embodiments or aspects, the requester may be an application, apparatus, process, or system configured to perform actions associated with the token. For example, the requester may request registration with a network token system, request token generation, token activation, token deactivation, token exchange, other token lifecycle management related processes, and / or any other token-related processes. In some non-limiting embodiments or aspects, the requester may connect to the network token system via any suitable communication network and / or protocol (e.g., using HTTPS, SOAP, and / or XML interfaces, etc.). For example, token requesters may include card-on-file merchants, acquirers, acquirer processors, payment gateways operating on behalf of merchants, payment enablers (e.g., original equipment manufacturers, mobile network operators, etc.), digital wallet providers, issuers, third-party wallet providers, payment processing networks, etc. In some non-limiting embodiments or aspects, a token requester may request tokens for multiple domains and / or channels. Alternatively, a token service provider within the tokenization ecosystem may uniquely register and identify a token requester. For example, during token requester registration, the token service provider may formally process the token requester's application to participate in the token service system. In some non-limiting embodiments or aspects, the token service provider may collect information about the nature of the requester and the associated use of the token to verify and formally approve the token requester and establish appropriate domain restriction controls. Alternatively, a token requester identifier may be assigned to a successfully registered token requester, and this token requester identifier may also be entered and maintained within a token vault. In some non-limiting embodiments or aspects, a token requester identifier may be revoked, and / or a new token requester identifier may be assigned to a token requester. In some non-limiting embodiments or aspects, this information may be reported and audited by the token service provider.
[0059] As used herein, the term "token service provider" can refer to an entity that includes one or more server computers in a token service system, which generates, processes, and maintains payment tokens. For example, a token service provider may include or communicate with a token vault storing generated tokens. Alternatively, the token vault may maintain a one-to-one mapping between tokens and PANs represented by the tokens. In some non-limiting embodiments or aspects, a token service provider is able to reserve an authorized BIN as a token BIN to issue tokens that can be submitted to a PAN by the token service provider. In some non-limiting embodiments or aspects, various entities in the tokenization ecosystem may assume the role of a token service provider. For example, payment networks and issuers or their agents may become token service providers by implementing token services according to non-limiting embodiments or aspects of the subject matter of this disclosure. Alternatively, a token service provider may provide reports or data outputs to reporting tools regarding approved, pending, or rejected token requests, including any assigned token requester IDs. A token service provider may provide data outputs associated with token-based transactions to reporting tools and applications, and may present tokens and / or PANs in the report outputs as needed. In some non-limiting embodiments or aspects, the EMVCo standards organization may publish specifications defining how a tokenization system can operate. For example, such specifications may be informational, but they are not intended to limit any currently disclosed subject matter.
[0060] As used herein, the term "token vault" may refer to a repository that maintains established token-to-PAN mappings. For example, a token vault may also maintain other attributes of token requesters, which may be determined at registration and / or used by the token service provider to apply domain restrictions or other controls during transaction processing. In some non-limiting embodiments or aspects, the token vault may be part of a token service system. For example, the token vault may be provided as part of a token service provider. Alternatively, the token vault may be a remote repository accessible to the token service provider. In some non-limiting embodiments or aspects, the token vault may be protected by strong underlying physical and logical security due to the sensitive nature of the data mappings stored and managed therein. Alternatively, the token vault may be operated by any suitable entity, including payment networks, issuers, clearinghouses, other financial institutions, transaction service providers, etc.
[0061] As used herein, the term "merchant" may refer to one or more entities (e.g., an operator of a retail business that provides goods and / or services and / or access to goods and / or services to users (e.g., customers, consumers, the merchant's customers, etc.) based on transactions (e.g., payment transactions). As used herein, the term "merchant system" may refer to one or more computer systems operated by or on behalf of the merchant, such as a server computer executing one or more software applications. As used herein, the term "product" may refer to one or more goods and / or services offered by the merchant.
[0062] As used herein, “point-of-sale (POS) device” can refer to one or more devices that a merchant can use to initiate a transaction (e.g., a payment transaction), participate in a transaction, and / or process a transaction. For example, a POS device may include one or more computers, peripheral devices, card readers, near-field communication (NFC) receivers, radio frequency identification (RFID) receivers and / or other contactless transceivers or receivers, contact-based receivers, payment terminals, computers, servers, input devices, etc.
[0063] As used herein, a “point-of-sale (POS) system” can refer to one or more computers and / or peripheral devices used by a merchant to conduct transactions. For example, a POS system may include one or more POS devices, and / or other similar devices that can be used to conduct payment transactions. A POS system (e.g., a merchant POS system) may also include one or more server computers programmed or configured to process online payment transactions via web pages, mobile applications, etc.
[0064] As used herein, the term "transaction service provider" can refer to an entity that receives transaction authorization requests from merchants or other entities and, in some cases, provides payment guarantees through an agreement between the transaction service provider and the issuing institution. In some non-limiting embodiments or aspects, the transaction service provider may include credit card companies, debit card companies, etc. As used herein, the term "transaction service provider system" may also refer to one or more computer systems operated by or on behalf of the transaction service provider, such as a transaction processing server executing one or more software applications. The transaction processing server may include one or more processors and, in some non-limiting embodiments or aspects, may be operated by or on behalf of the transaction service provider.
[0065] As used herein, the term "acquiring party" can refer to an entity licensed and approved by a transaction service provider to initiate transactions (e.g., payment transactions) using a portable financial device associated with the transaction service provider. As used herein, the term "acquiring party system" can also refer to one or more computer systems, computer devices, etc., operated by or on behalf of the acquiring party. Transactions initiated by the acquiring party can include payment transactions (e.g., purchases, Original Credit Transactions (OCT), Account Funds Transactions (AFT), etc.). In some non-limiting embodiments or aspects, the acquiring party may be authorized by the transaction service provider to contract with merchants or service providers to initiate transactions using the transaction service provider's portable financial device. The acquiring party may contract with payment service providers to enable them to sponsor merchants. The acquiring party may monitor the compliance of payment service providers in accordance with transaction service provider regulations. The acquiring party may conduct due diligence on payment service providers and ensure appropriate due diligence is performed before contracting with sponsored merchants. The acquiring party may be responsible for all transaction service provider programs operated or sponsored by the acquiring party. The acquiring party may be responsible for the actions of its payment service provider, merchants sponsored by the payment service provider, etc. In some non-limiting embodiments or aspects, the acquiring party may be a financial institution, such as a bank.
[0066] As used herein, the terms “e-wallet,” “e-wallet mobile application,” and “digital wallet” can refer to one or more electronic devices and / or one or more software applications configured to initiate and / or conduct transactions (e.g., payment transactions, electronic payment transactions, etc.). For example, an e-wallet may include an application and server-side software and / or database executed by a user device (e.g., a mobile device) for maintaining and providing transaction data to the user device. As used herein, the term “e-wallet provider” can include an entity that provides and / or maintains e-wallets and / or e-wallet mobile applications for users (e.g., customers). Examples of e-wallet providers include, but are not limited to, those mentioned above. and In some non-limiting examples, a financial institution (e.g., an issuing institution) may be an e-wallet provider. As used herein, the term "e-wallet provider system" may refer to one or more computer systems, computer devices, servers, server groups, etc., operated by or on behalf of an e-wallet provider.
[0067] As used herein, the term "portable financial device" can refer to payment cards (e.g., credit or debit cards), gift cards, smart cards, smart media, payroll cards, healthcare cards, wristbands, machine-readable media containing account information, keychain devices or pendants, RFID transponders, retailer discount or membership cards, cellular phones, e-wallet mobile applications, personal digital assistants (PDAs), pagers, security cards, computers, access cards, wireless terminals, transponders, etc. In some non-limiting embodiments or aspects, a portable financial device may include volatile or non-volatile memory to store information (e.g., account identifiers, account holder's name, etc.).
[0068] As used herein, the term "payment gateway" can refer to an entity and / or a payment processing system operated by or on behalf of such an entity (e.g., a merchant service provider, payment service provider, payment servicer, payment servicer contracted with an acquirer, payment aggregator, etc.) that provides payment services (e.g., transaction service provider payment services, payment processing services, etc.) to one or more merchants. Payment services may be associated with the use of portable financial devices managed by a transaction service provider. As used herein, the term "payment gateway system" can refer to one or more computer systems, computer devices, servers, server clusters, etc., operated by or on behalf of a payment gateway, and / or the payment gateway itself. The term "payment gateway mobile application" can refer to one or more electronic devices and / or one or more software applications configured to provide payment services for transactions (e.g., payment transactions, electronic payment transactions, etc.).
[0069] As used herein, the terms "client" and "client device" can refer to one or more client-side devices or systems (e.g., at a remote location of a transaction service provider) used to initiate or facilitate a transaction (e.g., a payment transaction). As examples, "client device" can refer to one or more POS devices used by a merchant, one or more acquiring host computers used by an acquiring party, one or more mobile devices used by a user, etc. In some non-limiting embodiments or aspects, a client device can be an electronic device configured to communicate with one or more networks and initiate or facilitate transactions. For example, a client device can include one or more computers, laptops, tablets, mobile devices, cellular phones, wearable devices (e.g., watches, glasses, lenses, clothing, etc.), PDAs, etc. Furthermore, "client" can also refer to an entity (e.g., a merchant, acquiring party, etc.) that owns, utilizes, and / or operates a client device for initiating transactions (e.g., for initiating a transaction with a transaction service provider).
[0070] As used herein, the term "server" may refer to one or more computing devices (e.g., processors, storage devices, similar computer components, etc.) that communicate with client devices and / or other computing devices via a network (e.g., a public network, the Internet, a private network, etc.) and, in some examples, facilitate communication between other servers and / or client devices. It should be understood that various other arrangements are possible. As used herein, the term "system" may refer to one or more computing devices or a combination of computing devices (e.g., processors, servers, client devices, software applications, components of these computing devices, etc.). References to "device," "server," "processor," etc., as used herein may refer to a previously stated device, server, or processor, a different server or processor, and / or a combination of servers and / or processors, stated to perform a prior step or function. For example, as used in the specification and claims, a first server or first processor stated to perform a first step or a first function may refer to the same or different server or the same or different processor stated to perform a second step or a second function.
[0071] Non-limiting embodiments or aspects of the disclosed subject matter relate to systems, methods, and computer program products for securely rendering sensitive data, including but not limited to securely rendering sensitive data using non-textual visual elements (e.g., at least one of images, video frames, etc.). For example, non-limiting embodiments or aspects of the disclosed subject matter provide rendering of sensitive data using at least one non-textual visual element (e.g., visual display, etc.), which can prevent malicious attacks (e.g., screen scraping, malicious / exotic scripts (e.g., JavaScript, etc.), malicious browser plugins, account takeover, session hijacking, clipboard hijacking, etc.) while still allowing authorized users to view the sensitive data. For example, because the sensitive data is not displayed in plaintext (e.g., plain text, HTML, etc.), malicious attackers may find it difficult to identify, copy, distribute, etc., such sensitive data.
[0072] For illustrative purposes, while the subject matter disclosed herein relates to methods, systems, and computer program products for securely rendering sensitive data (e.g., account identifiers), those skilled in the art will recognize that the disclosed subject matter is not limited to illustrative embodiments. For example, the methods, systems, and computer program products described herein can be used with a variety of settings, such as securely rendering sensitive data (e.g., Social Security numbers, personally identifiable information, contact information, healthcare information, tax information, confidential information, privileged information, trade secret information, etc.) in any suitable setting.
[0073] For reference Figure 1 , Figure 1This is a diagram of a non-limiting embodiment of an environment 100 in which the systems, products, and / or methods described herein can be implemented. Figure 1 As shown, environment 100 includes transaction service provider system 102, issuer system 104, customer device 106, merchant system 108, acquirer system 110, and network 112.
[0074] Transaction service provider system 102 may include one or more devices capable of receiving and / or transmitting information to issuer system 104, client device 106, merchant system 108, and / or acquirer system 110 via network 112. For example, transaction service provider system 102 may include computing devices, such as servers (e.g., transaction processing servers), server clusters, and / or other similar devices. In some non-limiting embodiments or aspects, transaction service provider system 102 may be associated with the transaction service provider described herein. In some non-limiting embodiments or aspects, transaction service provider system 102 may communicate with a data storage device, which may be local or remote to transaction service provider system 102. In some non-limiting embodiments or aspects, transaction service provider system 102 is capable of receiving information from the data storage device, storing information in the data storage device, transmitting information to the data storage device, or searching for information stored in the data storage device.
[0075] Issuer system 104 may include one or more devices capable of receiving and / or transmitting information to transaction service provider system 102, customer device 106, merchant system 108, and / or acquiring system 110 via network 112. For example, issuer system 104 may include computing devices, such as servers, server clusters, and / or other similar devices. In some non-limiting embodiments or aspects, issuer system 104 may be associated with the issuer institution described herein. For example, issuer system 104 may be associated with an issuer institution that issues credit accounts, debit accounts, credit cards, debit cards, etc., to users associated with customer device 106.
[0076] Client device 106 may include one or more devices capable of receiving and / or transmitting information to transaction service provider system 102, issuer system 104, merchant system 108, and / or acquirer system 110 via network 112. Alternatively, each client device 106 may include devices capable of receiving and / or transmitting information to other client devices 106 via network 112, another network (e.g., ad hoc network, local network, private network, virtual private network, etc.), and / or any other suitable communication technology. For example, client device 106 may include client devices, etc. In some non-limiting embodiments or aspects, client device 106 may or may not be able to receive information via short-range wireless communication connections (e.g., NFC communication connections, RFID communication connections, Bluetooth® communication connections, Zigbee® communication connections, etc.) (e.g., from merchant system 108 or from another client device 106), and / or transmit information via short-range wireless communication connections (e.g., to merchant system 108).
[0077] Merchant system 108 may include one or more devices capable of receiving and / or transmitting information to transaction service provider system 102, issuer system 104, client device 106, and / or acquirer system 110 via network 112. Merchant system 108 may also include devices capable of receiving information from client device 106 via network 112, a communication connection with client device 106 (e.g., NFC, RFID, Bluetooth, Zigbee, etc.), and / or transmitting information to client device 106 via network 112, the communication connection, etc. In some non-limiting embodiments or aspects, merchant system 108 may include computing devices, such as servers, server groups, client devices, client device groups, and / or other similar devices. In some non-limiting embodiments or aspects, merchant system 108 may be associated with the merchant described herein. In some non-limiting embodiments or aspects, merchant system 108 may include one or more client devices. For example, merchant system 108 may include client devices that allow the merchant to transmit information to transaction service provider system 102. In some non-limiting embodiments or aspects, merchant system 108 may include one or more devices, such as computers, computer systems, and / or peripheral devices, that can be used by the merchant to conduct payment transactions with users. For example, merchant system 108 may include POS devices and / or POS systems.
[0078] Acquiring system 110 may include one or more devices capable of receiving and / or transmitting information to transaction service provider system 102, issuer system 104, client device 106, and / or merchant system 108 via network 112. For example, acquiring system 110 may include computing devices, servers, server clusters, etc. In some non-limiting embodiments or aspects, acquiring system 110 may be associated with the acquiring party described herein.
[0079] Network 112 may include one or more wired and / or wireless networks. For example, network 112 may include cellular networks (e.g., Long Term Evolution (LTE) networks, third-generation (3G) networks, fourth-generation (4G) networks, fifth-generation (5G) networks, Code Division Multiple Access (CDMA) networks, etc.), Public Land Mobile Networks (PLMN), Local Area Networks (LAN), Wide Area Networks (WAN), Metropolitan Area Networks (MAN), Telephone Networks (e.g., Public Switched Telephone Network (PSTN)), Private Networks (e.g., Private Networks Associated with Transaction Service Providers), Ad Hoc Networks, Intranets, the Internet, Fiber-based Networks, Cloud Computing Networks, etc., and / or combinations of these or other types of networks.
[0080] Provided as an example Figure 1 The number and arrangement of systems, devices, and / or networks are shown. Additional systems, devices, and / or networks, fewer systems, devices, and / or networks, different systems, devices, and / or networks may exist, and / or may be combined with... Figure 1 The systems, devices, and / or networks shown are arranged in different ways. Furthermore, implementation can be carried out within a single system and / or device. Figure 1 Two or more systems or devices shown in the document, or Figure 1 The single system or device shown may be implemented as multiple distributed systems or devices. Alternatively, a group of systems (e.g., one or more systems) and / or a group of devices (e.g., one or more devices) of environment 100 may perform one or more functions described as being performed by another group of systems or devices of environment 100.
[0081] Now for reference Figure 2 , Figure 2 This is a diagram illustrating example components of device 200. Device 200 may correspond to one or more devices of transaction service provider system 102, one or more devices of issuer system 104, customer device 106, one or more devices of merchant system 108, and / or one or more devices of acquirer system 110. In some non-limiting embodiments or aspects, transaction service provider system 102, issuer system 104, customer device 106, merchant system 108, and / or acquirer system 110 may include at least one device 200 and / or at least one component of device 200. Figure 2 As shown, device 200 may include bus 202, processor 204, memory 206, storage component 208, input component 210, output component 212, and communication interface 214.
[0082] Bus 202 may include components that enable communication between components of device 200. In some non-limiting embodiments or aspects, processor 204 may be implemented in hardware, software, or a combination of hardware and software. For example, processor 204 may include processors (e.g., central processing unit (CPU), graphics processing unit (GPU), accelerated processing unit (APU), etc.), microprocessors, digital signal processors (DSPs), and / or any processing component that can be programmed to perform a function (e.g., field-programmable gate array (FPGA), application-specific integrated circuit (ASIC), etc.). Memory 206 may include random access memory (RAM), read-only memory (ROM), and / or another type of dynamic or static storage device (e.g., flash memory, magnetic memory, optical memory, etc.) that stores information and / or instructions for use by processor 204.
[0083] Storage component 208 may store information and / or software associated with the operation and use of device 200. For example, storage component 208 may include hard disk (e.g., magnetic disk, optical disk, magneto-optical disk, solid-state disk, etc.), compressed optical disk (CD), digital versatile optical disk (DVD), floppy disk, cassette tape, magnetic tape and / or another type of computer-readable medium, and corresponding drives.
[0084] Input component 210 may include components that allow device 200 to receive information, such as via user input (e.g., touchscreen display, keyboard, keypad, mouse, button, switch, microphone, camera, etc.). Alternatively, input component 210 may include sensors for sensing information (e.g., Global Positioning System (GPS) component, accelerometer, gyroscope, actuator, etc.). Output component 212 may include components that provide output information from device 200 (e.g., display, speaker, one or more light-emitting diodes (LEDs), etc.).
[0085] Communication interface 214 may include transceiver components (e.g., transceiver, separate receiver and transmitter, etc.) that enable device 200 to communicate with other devices, for example, via a wired connection, a wireless connection, or a combination of wired and wireless connections. Communication interface 214 may allow device 200 to receive information from another device and / or provide information to another device. For example, communication interface 214 may include an Ethernet interface, an optical interface, a coaxial interface, an infrared interface, a radio frequency (RF) interface, a universal serial bus (USB) interface, a Wi-Fi® interface, a Bluetooth® interface, a Zigbee® interface, a cellular network interface, etc.
[0086] Apparatus 200 can perform one or more processes described herein. Apparatus 200 can perform these processes based on software instructions stored in a computer-readable medium, such as memory 206 and / or storage component 208, executed by processor 204. Computer-readable medium (e.g., non-transient computer-readable medium) is defined herein as a non-transient memory device. A non-transient memory device includes memory space located within a single physical storage device or memory space distributed across multiple physical storage devices.
[0087] Software instructions may be read from another computer-readable medium or from another device into memory 206 and / or storage component 208 via communication interface 214. When executed, the software instructions stored in memory 206 and / or storage component 208 may cause processor 204 to perform one or more processes described herein. Alternatively or additionally, hard-wired circuitry may be used in place of or in combination with the software instructions to perform one or more processes described herein. Therefore, the embodiments or aspects described herein are not limited to any particular combination of hardware circuitry and software.
[0088] Provided as an example Figure 2 The number and arrangement of components are shown. In some non-limiting embodiments or aspects, with Figure 2 Compared to those shown, device 200 may include additional components, fewer components, different components, or components arranged in a different manner. Alternatively, a set of components (e.g., one or more components) of device 200 may perform one or more functions described as being performed by another set of components of device 200.
[0089] Now for reference Figure 3 , Figure 3This is a flowchart of a non-limiting embodiment of a process 300 for securely rendering sensitive data. In some non-limiting embodiments, one or more steps of process 300 may be performed (e.g., wholly, partially, and / or similarly) by transaction service provider system 102 (e.g., one or more devices of transaction service provider system 102). In some non-limiting embodiments, one or more steps of process 300 may be performed (e.g., wholly, partially, etc.) by another system, device, group of systems, or group of devices separate from or including transaction service provider system 102, such as issuer system 104 (e.g., one or more devices of issuer system 104), client device 106, merchant system 108 (e.g., one or more devices of merchant system 108), acquiring system 110 (e.g., one or more devices of acquiring system 110), etc. In some non-limiting embodiments, a web server may be the same as, similar to, and / or part of transaction service provider system 102. Alternatively or alternatively, the web server may be the same as, similar to, and / or part of another system, device, group of systems, or group of devices that are separate from or include the transaction service provider system 102, such as issuer system 104 (e.g., one or more devices of issuer system 104). In some non-limiting embodiments, the user device may be the same as, similar to, and / or part of the client device 106. Alternatively or alternatively, the user device may be the same as, similar to, and / or part of another system, device, group of systems, or group of devices that are separate from or include the client device 106, such as issuer system 104 (e.g., one or more devices of issuer system 104), merchant system 108 (e.g., one or more devices of merchant system 108).
[0090] like Figure 3 As shown, at step 302, process 300 may include receiving at least one account identifier. For example, a web server (e.g., transaction service provider system 102) may receive account identifier data associated with at least one account identifier. In some non-limiting embodiments, the web server may retrieve the account identifier from a database (e.g., the transaction database of transaction service provider system 102, etc.).
[0091] In some non-limiting embodiments, the account identifier may include a primary account (PAN) as described herein. In some non-limiting embodiments, the account identifier data may include the PAN (e.g., in plain text). Alternatively or alternatively, the account identifier data may include an encrypted PAN (e.g., encrypted using a key, etc.). In some non-limiting embodiments, the web server may transmit the encrypted PAN to a security system (e.g., the Hardware Security Module (HSM) of the Transaction Service Provider System 102, etc.). Alternatively or alternatively, the security system (e.g., the HSM) may transmit the PAN (e.g., in plain text, unencrypted, etc.) to the web server (e.g., in response to receiving an encrypted PAN from the web server).
[0092] In some non-limiting embodiments, the web server may receive authorization data from the user's device (e.g., before receiving and / or retrieving the account identifier). For example, authorization data may include identification data (e.g., username, email address, user number, any combination thereof, etc.), password data (e.g., password, passcode, personal identification number (PIN), one-time password (OTP) (e.g., temporary one-time password (TOTP)), any combination thereof, etc.), biometric data (e.g., fingerprint data associated with a fingerprint, facial image data associated with a user's facial image, any combination thereof, etc.), any combination thereof, etc. In some non-limiting embodiments, the web server may verify the authorization data. For example, the web server may verify that the identification data corresponds to the password data and / or biometric data. Alternatively or additionally, if the authorization data is verified, the web server may determine that the user of the user device is an authorized user.
[0093] In some non-limiting embodiments, the web server may receive a request to display an account identifier from the user's device (e.g., before receiving and / or retrieving the account identifier). Alternatively, the web server may receive (e.g., retrieve) the account identifier (e.g., associated account identifier data) in response to receiving a request from the user device.
[0094] like Figure 3 As shown, at step 304, process 300 may include converting the account identifier into at least one non-textual visual element. For example, a web server (e.g., transaction service provider system 102) may convert account identifier data (e.g., PAN (e.g., in plain text, unencrypted, etc.)) into at least one non-textual visual element.
[0095] In some non-limiting embodiments, at least one non-textual visual element may include at least one of an image, a video including at least one frame (e.g., multiple frames (e.g., a series of frames, a sequence of frames, etc.), any combination thereof, etc.
[0096] like Figure 3 As shown, at step 306, process 300 may include embedding at least one watermark into at least one non-text visual element. For example, a web server (e.g., transaction service provider system 102) may embed at least one watermark into one or more non-text visual elements.
[0097] In some non-limiting embodiments, one or more watermarks may include at least a portion of user-associated identifying data (e.g., username, email address, user number, any combination thereof, etc.). Alternatively, one or more watermarks may include a digital copy of the user's handwritten signature.
[0098] In some non-limiting embodiments, embedding one or more watermarks may include a web server modifying at least one pixel of one or more non-text visual elements based on the watermark. For example, modifying at least one pixel may include modifying multiple pixels. In some non-limiting embodiments, one or more pixels may be modified such that a human user (e.g., a user of a user device) can perceive (e.g., view, etc.) the watermark. Alternatively, one or more pixels may be modified such that one or more watermarks may not be perceptible to a human user (e.g., a user of a user device) (e.g., view, easily view, etc.).
[0099] In some non-limiting embodiments, a user device (e.g., client device 106, a device of issuer system 104, etc.) may receive a digital copy of the handwritten signature (e.g., as input to the user device from its user). Alternatively, the user device may transmit the digital copy of the handwritten signature to a web server. In some non-limiting embodiments, the web server may receive the digital copy of the handwritten signature from the user device. Alternatively, the web server may embed the digital copy of the handwritten signature as a watermark in one or more non-textual visual elements, as described herein.
[0100] like Figure 3 As shown, at step 308, process 300 may include encrypting at least one non-textual visual element. For example, a web server (e.g., transaction service provider system 102) may encrypt one or more non-textual visual elements to form at least one encrypted non-textual visual element.
[0101] In some non-limiting implementations, the web server may exchange at least one key with a user device (e.g., client device 106, device of issuer system 104, etc.). For example, one or more keys may include any suitable key (e.g., asymmetric key, symmetric key, session key, public key, private key, public-private key pair, key, etc.). Alternatively, the web server and user device may use any suitable key exchange protocol (e.g., public key certificates, handshake protocols, Transport Layer Security (TLS) handshake, etc.) to exchange keys.
[0102] In some non-limiting embodiments, exchanging one or more keys may include embedding one or more keys in at least one non-textual visual element (e.g., one or more encrypted non-textual visual elements). For example, the user device and the web server may each generate a random number array (e.g., one or more identical seed values using the same random number generation algorithm), and the web server may use the random number array as an index to embed the key in the (encrypted) non-textual visual element. Alternatively, the web server may transmit one or more (encrypted) non-textual visual elements (e.g., in which the key is embedded) to the user device, and the user device may use the random number array as an index to extract the key from the one or more (encrypted) non-textual visual elements. Alternatively, the user device may store one or more keys and / or use one or more keys to decrypt one or more encrypted non-textual visual elements.
[0103] In some non-limiting implementations, the server may encrypt one or more non-textual visual elements based on one or more keys to form at least one encrypted non-textual visual element, as described herein.
[0104] like Figure 3 As shown, at step 310, process 300 may include transmitting at least one non-textual visual element. For example, a web server (e.g., transaction service provider system 102) may transmit one or more non-textual visual elements to a user device (e.g., client device 106, device of issuer system 104, etc.).
[0105] In some non-limiting embodiments, transmitting one or more non-text visual elements may include transmitting one or more non-text visual elements, in which a watermark is embedded, to a web server on a user device. Alternatively, transmitting one or more non-text visual elements may include the web server transmitting one or more encrypted non-text visual elements to the user device. For example, the web server may transmit one or more encrypted non-text visual elements, in which a watermark is embedded, to the user device.
[0106] In some non-limiting embodiments, the user device may render and / or display at least one non-text visual element. For example, the user device may include a browser and a renderer. Alternatively, the user device may use a renderer to render one or more non-text visual elements. Alternatively, the user device may use a browser to display one or more non-text visual elements (e.g., as rendered).
[0107] In some non-limiting embodiments, the user device may decrypt one or more encrypted non-text visual elements (e.g., based on one or more keys exchanged with a web server, etc.) to form at least one decrypted non-text visual element. Alternatively, displaying one or more non-text visual elements may include the user device rendering and / or displaying one or more decrypted non-text visual elements. In some non-limiting embodiments, one or more decrypted non-text visual elements may (or may not) include an embedded watermark.
[0108] For reference Figure 4 , Figure 4 is with Figure 3 The diagram shows an exemplary embodiment 400 of a non-limiting embodiment related to process 300. (See figure for example.) Figure 4 As shown, implementation 400 may include a browser 406a, a streaming renderer 406b, a cryptographic system 406c, a web gateway 402a, a web application 402b, a transaction database 402c, an HSM 402d, and / or a media converter 402e. In some non-limiting implementations, the browser 406a, streaming renderer 406b, and / or cryptographic system 406c may be connected to a user device (e.g., as referenced herein). Figure 3 The client device 106, issuer system 104 (e.g., one or more devices of issuer system 104), and / or merchant system 108 (e.g., one or more devices of merchant system 108) are the same as, similar to, and / or part of it. In some non-limiting embodiments, the web gateway 402a, web application 402b, transaction database 402c, HSM 402d, and / or media converter 402e may be the same as the web server (e.g., as referenced herein). Figure 3 The same as, similar to, and / or part of the transaction service provider system 102 (e.g., one or more devices of the issuer system 104), issuer system 104 (e.g., one or more devices of the issuer system 104), etc.
[0109] In some non-limiting embodiments, browser 406a may transmit authorization data to web gateway 402a, as described herein. Alternatively or alternatively, web gateway 402a and / or web application 402b may verify the authorization data, as described herein. Alternatively or alternatively, browser 406a may transmit a request to display an account identifier to web gateway 402a, as described herein. In some non-limiting embodiments, web gateway 402a may transmit the request to web application 402b.
[0110] In some non-limiting embodiments, web gateway 402a and / or web application 402b may retrieve account identifiers from transaction database 402c, as described herein. For example, web application 402b may retrieve an encrypted PAN (e.g., encrypted using a secret key, etc.) from transaction database 402c (e.g., based on a request from browser 406a). Alternatively or alternatively, web application 402b may transmit the encrypted PAN to HSM 402d. Alternatively or alternatively, HSM 402d may transmit the PAN (e.g., in plain text, unencrypted, etc.) to web application 402b (e.g., in response to receiving an encrypted PAN from web application 402b).
[0111] In some non-limiting embodiments, web application 402b may transmit the PAN (e.g., in plain text, unencrypted, etc.) to web gateway 402a. Alternatively, web gateway 402a may transmit the PAN to media converter 402e. In some non-limiting embodiments, media converter 402e may convert the PAN into at least one non-text visual element (e.g., video, which includes at least one frame (e.g., multiple frames, etc.), as described herein. Alternatively, media converter 402e may transmit one or more non-text visual elements (e.g., frames) to web gateway 402a. In some non-limiting embodiments, web gateway 402a may encrypt one or more non-text visual elements (e.g., frames) and / or embed a watermark in one or more non-text visual elements, as described herein.
[0112] In some non-limiting embodiments, web gateway 402a may transmit one or more non-text visual elements (e.g., frames) to a user device (e.g., cryptographic system 406c and / or its streaming renderer 406b). In some non-limiting embodiments, web gateway 402a may exchange at least one key with the user device (e.g., its cryptographic system 406c), as described herein. In some non-limiting embodiments, cryptographic system 406c may (e.g., based on the exchanged one or more keys) decrypt one or more non-text visual elements, as described herein. Alternatively or additionally, streaming renderer 406b may render one or more non-text visual elements (e.g., decrypted, etc.), as described herein. In some non-limiting embodiments, browser 406a may display one or more non-text visual elements (e.g., rendered, etc.), as described herein. Alternatively or additionally, the displayed non-text visual elements may (or may not) include an embedded watermark, as described herein.
[0113] Now for reference Figure 5A and Figure 5B , Figure 5A and Figure 5B is with Figure 3 The diagram shows an exemplary implementation 500 of a non-limiting embodiment related to process 300. (See figure for example.) Figure 5A and Figure 5B As shown, implementation 500 may include a browser 506a, a renderer 506b, a cryptographic system 506c, a web server 502b, a transaction application programming interface (API) / database 502c, an HSM 502d, a media converter 502e, a security API / system 502f, and / or other APIs / databases 502g. In some non-limiting implementations, the browser 506a, renderer 506b, and cryptographic system 506c may interact with a user device (e.g., as referenced herein). Figure 3 The client device 106, issuer system 104 (e.g., one or more devices of issuer system 104) and / or merchant system 108 (e.g., one or more devices of merchant system 108) are the same as, similar to, and / or part of it. Additionally or alternatively, browser 506a may be the same as or similar to browser 406a, renderer 506b may be the same as or similar to stream renderer 406b, and / or cryptographic system 506c may be the same as or similar to cryptographic system 406c. In some non-limiting embodiments, web server 502b, transaction API / database 502c, HSM 502d, media converter 502e, security API / system 502f, and / or other API / database 502g may be the same as the web server (e.g., as referenced herein). Figure 3The transaction service provider system 102 (e.g., one or more devices of the issuer system 104), the issuer system 104 (e.g., one or more devices of the issuer system 104), etc., are the same as, similar to, and / or part of it. Additionally or alternatively, the web server 502b may be the same as or similar to the web gateway 402a and / or the web application 402b, the transaction API / database 502c may be the same as or similar to the transaction database 402c, the HSM 502d may be the same as or similar to the HSM 402d, and / or the media converter 502e may be the same as or similar to the media converter 402e.
[0114] In some non-limiting embodiments, browser 506a may transmit authorization data to web server 502b, as described herein. Alternatively or alternatively, web server 502b may verify the authorization data, as described herein. Alternatively or alternatively, browser 506a may transmit a request to display an account identifier (e.g., PAN) to web server 502b, as described herein.
[0115] In some non-limiting embodiments, web server 502b may retrieve an account identifier from transaction API / database 502c, as described herein. For example, web server 502b may retrieve an encrypted PAN (e.g., encrypted using a secret key, etc.) from transaction API / database 502c (e.g., based on a request from browser 506a). Alternatively or concurrently, web server 502b may transmit a request for an unencrypted PAN (e.g., in plain text, etc.) to media converter 502e, and requests from web server 502b may include an encrypted PAN.
[0116] In some non-limiting embodiments, media converter 502e may transmit requests for unencrypted and / or encrypted PANs to secure API / system 502f. Alternatively, secure API / system 502f may transmit requests for unencrypted and / or encrypted PANs to HSM 502d. In some non-limiting embodiments, HSM 502d may transmit the PAN (e.g., in plaintext, unencrypted, etc.) to secure API / system 502f, which may then transmit the PAN to media converter 502e.
[0117] In some non-limiting embodiments, the media converter 502e can convert the PAN into at least one non-textual visual element (e.g., an image, video including at least one frame (e.g., multiple frames, etc.), as described herein. Alternatively or additionally, the media converter 502e can transmit one or more non-textual visual elements (e.g., frames) to the web server 502b. In some non-limiting embodiments, the web server 502b can encrypt one or more non-textual visual elements (e.g., frames) and / or embed a watermark into one or more non-textual visual elements, as described herein.
[0118] In some non-limiting embodiments, web server 502b may transmit one or more non-text visual elements (e.g., frames) to a user device (e.g., cryptographic system 506c and / or its renderer 506b). In some non-limiting embodiments, web server 502b may exchange at least one key with the user device (e.g., its cryptographic system 506c), as described herein. In some non-limiting embodiments, cryptographic system 506c may (e.g., based on the exchanged one or more keys) decrypt one or more non-text visual elements, as described herein. Alternatively or additionally, renderer 506b may render one or more non-text visual elements (e.g., decrypted, etc.), as described herein. In some non-limiting embodiments, browser 506a may display one or more non-text visual elements (e.g., rendered, etc.), as described herein. Alternatively or additionally, the displayed non-text visual elements may (or may not) include an embedded watermark, as described herein.
[0119] In some non-limiting embodiments, the user device and / or its web browser 506a may include a signature panel 506aa. Alternatively or additionally, the signature panel 506aa may receive a digital copy of the handwritten signature (e.g., as input from a user to the user device and / or its web browser 506aa), as described herein. Alternatively or additionally, the user device and / or signature panel 506aa may transmit a digital copy of the handwritten signature to a web server 502b, as described herein. In some non-limiting embodiments, the web server 502b may receive a digital copy of the handwritten signature, as described herein. Alternatively or additionally, the web server 502b may embed a digital copy of the handwritten signature as a watermark in one or more non-text visual elements, as described herein.
[0120] For reference Figure 6 , Figure 6 is with Figure 3 The diagram shows an exemplary embodiment 600 of a non-limiting embodiment related to process 300. (See figure for example.) Figure 6As shown, implementation 600 may include user device 606 and / or web server 602. In some non-limiting implementations, user device 606 may be connected to a user device (e.g., as referenced herein). Figure 3 The client device 106, the issuer system 104 (e.g., one or more devices of the issuer system 104), and / or the merchant system 108 (e.g., one or more devices of the merchant system 108) are the same as, similar to, and / or part of the client device 106, the issuer system 104 (e.g., one or more devices of the issuer system 104), and / or the merchant system 108 (e.g., one or more devices of the merchant system 108). In some non-limiting embodiments, the web server 602 may be the same as a web server (e.g., as referenced herein). Figure 3 The same as, similar to, and / or part of the transaction service provider system 102 (e.g., one or more devices of the issuer system 104), issuer system 104 (e.g., one or more devices of the issuer system 104), etc.
[0121] In some non-limiting embodiments, web server 602 may exchange at least one key with user device 606, as described herein. For example, exchanging one or more keys may include embedding one or more keys in at least one non-textual visual element (e.g., one or more encrypted non-textual visual elements).
[0122] In some non-limiting embodiments, user device 606 and web server 602 may each generate a random number array. For example, user device 606 and web server 602 may each generate the same random number array using the same seed value from the same random number generation algorithm. In some non-limiting embodiments, one or more seed values may be generated by each of user device 606 and web server 602 using a shared key. Alternatively, the shared key may be dynamically generated by web server 602. For example, web server 602 may use a hash function to combine a key encryption key (KEK) with the user's identification information (e.g., username, etc.) from user device 606 to provide the shared key. Alternatively, web server 602 may use any suitable key exchange protocol (e.g., public key certificates, handshake protocols, Transport Layer Security (TLS) handshakes, etc.) to transmit the shared key to user device 606. In some non-limiting embodiments, user device 606 and web server 602 may each use the shared key to generate TOTP. Alternatively, TOTP may be used as one or more seed values. For example, user device 606 and web server 602 can each resolve TOTP into multiple seed values (e.g., three seed values X, Y, and Z).
[0123] In some non-limiting embodiments, user device 606 and web server 602 may each use one or more seed values (e.g., three seed values X, Y, and Z, etc.) as input to the same random number generation algorithm, thereby providing the same array of random numbers. For example, user device 606 and web server 602 may each use the following random number generation algorithms:
[0124] Algorithm 1:
[0125]
[0126]
[0127] In some non-limiting implementations, α, β, and γ can be optional constants, for example, their respective ranges can be specified in Algorithm 1. Alternatively, for each call to the function PSR in Algorithm 1, a tuple of 3 numbers can be added to the random number array. Alternatively, the resulting random number array can have an optional number N of tuples (e.g., 44 tuples, as shown in Algorithm 1). For example, 44 can be the number of characters that can be embedded in the payload of a key (e.g., a Base64-encoded key, etc.).
[0128] In some non-limiting implementations, web server 602 may use an array of random numbers as an index to embed the key into one or more (encrypted) non-text visual elements. For example, embedding may include hiding information within the (encrypted) non-text visual elements. For illustrative purposes, an array of N random numbers (e.g., a tuple of random numbers) can be obtained from the algorithm described above. Alternatively, these random numbers may be used as an index indicating the position of each of the N characters of the key within one or more (encrypted) non-text visual elements (e.g., a Base64-encoded encrypted video string). For example, the random numbers may be integers and / or in the range (0, FILE_SIZE), where FILE_SIZE is the size of the encrypted video string, and this can be achieved using rounding and / or mod functions. For illustrative purposes, if the length of the Base64-encoded encrypted video string is 66,000 characters, the probability of finding a 44-character key by brute force is -289,484. In some non-limiting embodiments, web server 602 may transmit one or more (encrypted) non-textual visual elements (e.g., in which one or more keys are embedded) to user device 606.
[0129] In some non-limiting embodiments, user device 606 may use a random number array as an index to extract a key from one or more (encrypted) non-textual visual elements. For example, as described herein, user device 606 may, for instance, use one or more seed values and algorithms used by web server 602 to generate the same random number array as generated by web server 602. Alternatively or alternatively, user device 606 may iterate through the random number array (e.g., in reverse order, back to the beginning, etc.) and use each random number as an index to identify the corresponding character of the key within the encrypted video string. Alternatively or alternatively, these characters may be extracted by user device 606. In some non-limiting embodiments, after extraction, the key may be used to decrypt the encrypted video. For example, user device 606 may store one or more keys and / or use one or more keys to decrypt one or more encrypted non-textual visual elements.
[0130] Although the disclosed subject matter has been described in detail for illustrative purposes based on embodiments or aspects currently considered to be most practical and preferred, it should be understood that such details are for the purposes described only, and the disclosed subject matter is not limited to the disclosed embodiments or aspects, but rather is intended to cover modifications and equivalent arrangements within the spirit and scope of the appended claims. For example, it should be understood that the currently disclosed subject matter is intended to contemplate, as far as possible, that one or more features of any embodiment can be combined with one or more features of any other embodiment.
Claims
1. A computer-implemented method, comprising: Use at least one processor to receive account identifier data associated with at least one account identifier; The account identifier data is converted into at least one non-text visual element using the at least one processor; The at least one processor embeds at least one watermark into the at least one non-text visual element, wherein the at least one watermark comprises a digital copy of a handwritten signature, and wherein embedding the at least one watermark comprises modifying a plurality of pixels of the at least one non-text visual element based on the watermark, such that the digital copy of the handwritten signature is imperceptible to a human user. After embedding at least one watermark into the at least one non-text visual element, the at least one non-text visual element is transmitted to at least one receiver using the at least one processor.
2. The method of claim 1, wherein the at least one receiver renders the at least one non-text visual element.
3. The method of claim 1, wherein the at least one non-textual visual element comprises an image.
4. The method of claim 1, wherein the at least one non-textual visual element comprises video, and the video comprises at least one frame.
5. The method of claim 1, further comprising: The at least one processor is used to encrypt the at least one non-textual visual element to form at least one encrypted non-textual visual element. Transmitting the at least one non-text visual element includes transmitting the at least one encrypted non-text visual element to the at least one receiver.
6. The method according to claim 5, further comprising: The at least one processor exchanges at least one key with the at least one receiver.
7. The method of claim 6, wherein exchanging the at least one key comprises embedding the at least one key in the at least one non-textual visual element.
8. A system for securely rendering sensitive data, comprising: User equipment; Hardware security module; as well as The server is configured as follows: Receive a request to display the account identifier from the user device; Retrieve account identifier data associated with the account identifier from the hardware security module; The account identifier data is converted into at least one non-text visual element, and at least one watermark is embedded in the at least one non-text visual element using the at least one processor, wherein the at least one watermark includes a digital copy of a handwritten signature, and wherein embedding the at least one watermark includes modifying a plurality of pixels of the at least one non-text visual element based on the watermark, such that the digital copy of the handwritten signature cannot be perceived by a human user. as well as After embedding at least one watermark into the at least one non-text visual element, the at least one non-text visual element is transmitted to the user device.
9. The system of claim 8, wherein the user device includes a browser and a renderer, and wherein the user device is configured to: Render the at least one non-text visual element using the renderer; and Display the at least one non-text visual element as rendered in the browser.
10. The system according to claim 9, wherein: The server is further configured as follows: Exchange at least one key with the user device; and The at least one non-text visual element is encrypted based on the at least one key to form at least one encrypted non-text visual element. The transmission of the at least one non-text visual element includes transmitting the at least one encrypted non-text visual element to the user device; and The user equipment is further configured to: Based on the at least one key, the at least one encrypted non-text visual element is decrypted to form at least one decrypted non-text visual element. Displaying the at least one non-text visual element includes displaying the at least one decrypted non-text visual element.
11. The system according to claim 8, wherein: The user equipment is configured to: Receive the digital copy of the handwritten signature; and The digital copy of the handwritten signature is transmitted to the server; and The server is further configured as follows: Receive the digital copy of the handwritten signature from the user device.
12. A computer program product comprising at least one non-transitory computer-readable medium containing one or more instructions, said one or more instructions causing said at least one processor to perform the following operations when executed by said at least one processor: Receive account identifier data associated with at least one account identifier; The account identifier data is converted into at least one non-text visual element, and at least one watermark is embedded in the at least one non-text visual element using the at least one processor, wherein, The at least one watermark includes a digital copy of a handwritten signature, and embedding the at least one watermark includes modifying a plurality of pixels of the at least one non-text visual element based on the watermark, such that the digital copy of the handwritten signature cannot be perceived by a human user. as well as After embedding at least one watermark into the at least one non-text visual element, the at least one non-text visual element is transmitted to at least one receiver.
13. The computer program product of claim 12, wherein the at least one non-textual visual element comprises at least one of an image, a video comprising at least one frame, or any combination thereof.
14. The computer program product of claim 12, wherein the instructions, when executed by the at least one processor, further cause the at least one processor to perform the following operations: Exchange at least one key with the at least one receiver; and The at least one non-text visual element is encrypted based on the at least one key to form at least one encrypted non-text visual element. Transmitting the at least one non-text visual element includes transmitting the at least one encrypted non-text visual element to the at least one receiver.
Citation Information
Patent Citations
Digital anti-fake method
CN1421814A
Method and device for electronically capturing a handwritten signature using embedding technique
US20110179289A1
Split mobile payment system
US20130124412A1