Systems and methods for end-to-end encryption compliance
Patent Information
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- VERIFONE INC
- Filing Date
- 2024-06-12
- Publication Date
- 2026-04-22
AI Technical Summary
Conventional payment systems face challenges in maintaining end-to-end encryption compliance, particularly as the number of payment card types increases, leading to burdensome maintenance of lookup tables on point of interaction devices and potential payment errors due to incorrect handling of encrypted or unencrypted card information.
A cloud-based encryption system that receives card data, determines the appropriate encryption compliance protocol based on decrypted data, and transmits card information accordingly, eliminating the need for point of interaction devices to make these determinations and simplifying encryption protocol management.
Ensures end-to-end encryption compliance by centrally managing encryption protocols, reducing the risk of payment errors and simplifying maintenance across various payment card types, thereby enhancing the security and efficiency of payment transactions.
Smart Images

Figure US2024033609_19122024_PF_FP_ABST
Abstract
Description
SYSTEMS AND METHODS FOR END-TO-END ENCRYPTION COMPLIANCECross-Reference to Related Applications
[0001] This application claims priority to U.S. Provisional Patent Application Serial No. 63 / 507,857, filed on June 13, 2023, and entitled “Systems and Methods for End-to-End Encryption Compliance”, the entire disclosure of which is incorporated herein by reference.Field of the Disclosure
[0002] The present disclosure relates generally to payment systems, and more particularly to systems and methods for ensuring end-to-end encryption compliance in connection with payment systems.Background
[0003] The transmission of information between payment systems (including a point of interaction or point of sale device) and end payment arbiters must be performed under secure protocols to be with compliant established standard-setting organization rules. These security requirements include, among other things, point-to-point encryption (P2PE) for certain types of information, such as certain types of card information collected from payment cards. Not all card information should be encrypted, and if certain information is mistakenly handled, could lead to payment errors such as declined payments.Summary of the Disclosure
[0004] According to an embodiment, a method for end-to-end encryption compliance is provided. The method can include performance of the following steps on a cloud-based encryption system comprising at least one computer processor and memory storing an encryption compliance database: (i) receiving card data for completing a transaction, wherein at least a portion of the card data is encrypted card data; (ii) transmitting, to an encryption key holder, at least the portion of the card data that is encrypted card data; (iii) receiving, from the encryption key holder, decrypted card data, wherein the decrypted card data includes the encrypted card data that has been decrypted by the encryption key holder; (iv) identifying, using the encryption compliance database, an encryption compliance protocol for the received card data based on the decrypted card data received from the encryption key holder; and (v) transmitting the card data in accordance with the encryption compliance protocol to a payment application module.
[0005] In an aspect, the card data may be received from a cryptography routing device via at least one first secure connection. The at least one first secure connection may include one or more of a wired and wireless communications network connection.
[0006] In an aspect, the method may also include performance of the following steps at the cryptography routing device: (i) receiving, from at least one card reading device, the card data including the encrypted card data; (ii) determining, based on the received card data, whether to transmit the received card data to the cloud-based encryption system or the payment application module; and (iii) transmitting the received card data to the cloud-based encryption system and / or the payment application module.
[0007] In an aspect, determining whether to transmit the card data to the cloud-based encryption system or the payment application module may include: (i) determining whether the received card data includes encrypted and / or unencrypted card information; and (ii) if the received card data includes encrypted card information, transmitting the received card data to the cloud-based encryption system.
[0008] In an aspect, the method may also include performance of the following steps at the at least one card reading device: (i) receiving, via a card reader of the at least one card reading device, card data from a payment card; (ii) encrypting, via a cryptographic processor of the at least one card reading device, at least a portion of the card data received from the payment card; and (iii) transmitting, to the cryptography routing device, the card data including at least the encrypted portion of the card data.
[0009] In an aspect, the cryptographic processor of the at least one card reading device may be configured to encrypt at least a portion of the card data received from the payment card using one or more secure encryption protocols including VeriShield Crypto Library (VCL) and / or AES.
[0010] In an aspect, the at least one card reading device may include instructions to not encrypt one or more types of card information.
[0011] In an aspect, the card reader of the at least one card reading device may be at least one of a magnetic stripe reader, an EMV reader, and a contactless reader.
[0012] In an aspect, at least the portion of the card data that is encrypted card data may be transmitted to the encryption key holder via at least one second secure connection. The at least one second secure connection may include one or more of a wired and wireless communications network connection.
[0013] In an aspect, the encryption key holder may be configured to determine which encryption algorithms are used by the cryptographic processor of the at least one card reading device to encrypt the card data received. The encryption key holder may be configured to store one or more encryption keys necessary to decrypt at least a portion of the encrypted card data.
[0014] In an aspect, the encryption key holder may be a third-party encryption service provider.
[0015] In an aspect, the encryption key holder may be a financial institution associated with the type of card data received.
[0016] In an aspect, the method may also include performance of the following steps at the payment application module: (i) receiving, in accordance with the encryption compliance protocol, the card data from the cloud-based encryption system; and (ii) transmitting the card data received to an end payment arbiter for completing the transaction, wherein the card data is transmitted to the end payment arbiter in accordance with the encryption compliance protocol identified by the cloud-based encryption system .
[0017] In an aspect, the encryption compliance database may include a plurality of rules for handling different types of payment cards based on one or more identifiers present in the card data, the plurality of rules including instructions for transmitting one or more types of card information in an encrypted format when identified, one or more types of card information in an unencrypted format when identified, and / or a combination thereof.
[0018] According to another embodiment of the present disclosure, a cloud-based encryption system is provided. The cloud-based encryption system may include: (A) one or more computer processors; (B) a memory storing an encryption compliance database and machine-readable instructions that, when executed by the one or more computer processors, cause the one or more computer processors to perform the following operations: (i) receive card data for completing a transaction, wherein at least a portion of the card data is encrypted card data; (ii) transmit, to an encryption keyholder, at least the portion of the card data that is encrypted card data; (iii) receive, from the encryption key holder, decrypted card data, wherein the decrypted card data includes encrypted card data that has been decrypted by the encryption key holder; (iv) identify, using the encryption compliance database, an encryption compliance protocol for the received card data based on the decrypted card data received from the encryption key holder; and (v) transmit the card data in accordance with the encryption compliance protocol to a payment application module.
[0019] In an aspect, the card data may be received by the cloud-based encryption system (102) from a cryptography routing device via at least one first secure connection.
[0020] In an aspect, at least the portion of the card data that is encrypted card data may be transmitted to the encryption key holder via at least one second secure connection.
[0021] In an aspect, the encryption compliance database may include a plurality of rules for handling different types of payment cards based on one or more identifiers present in the card data, the plurality of rules including instructions for transmitting one or more types of card information in an encrypted format when identified, one or more types of card information in an unencrypted format when identified, and / or a combination thereof.
[0022] According to yet another embodiment of the present disclosure, a system configured to operate a cloud-based cryptography service for completing payment transactions is provided. The system may include: (A) one or more card reading devices configured to receive and encrypt card data from a payment card, the one or more card reading devices being in secure communication with a cryptography routing device; and (B) a cloud-based encryption system in communication with the cryptography routing device and a payment application module. The cryptography routing device may be configured to: (i) receive, from at least one card reading device, card data for completing a transaction, wherein at least a portion of the card data is encrypted card data; (ii) determine, based on the received card data, whether to transmit the received card data to the cloud-based encryption system or the payment application module; and (iii) transmit the received card data to the cloud-based encryption system. The cloud-based encryption system may be configured to: (i) receive the card data from the cloud-based encryption system via at least one first secure connection; (ii) identify, using the encryption compliance database, an encryption compliance protocol for the received card data; and (iii) transmit, to the payment application module, the received card data in accordance with the encryption compliance protocol identified. The payment application module may be configured to: (i) receive, in accordance with the encryption compliance protocol, the card data from the cloud-based encryption system; and (ii) transmit the received card data to an end payment arbiter for completing the transaction, wherein the card data is transmitted to the end payment arbiter in accordance with the encryption compliance protocol identified by the cloudbased encryption system.
[0023] In an aspect, each of the one or more card reading devices may include a card reader and a cryptographic processor such that each of the one or more card reading devices is configured to: (i) receive, via the card reader of the corresponding card reading device, carddata from a payment card; (ii) encrypt, via the cryptographic processor of the corresponding card reading device, at least a portion of the card data received from the payment card; and (iii) transmit, to the cryptography routing device, the card data including at least the encrypted portion of the card data.
[0024] It should be appreciated that all combinations of the foregoing concepts and additional concepts discussed in greater detail below (provided such concepts are not mutually inconsistent) are contemplated as being part of the inventive subject matter disclosed herein. In particular, all combinations of claimed subject matter appearing at the end of this disclosure are contemplated as being part of the inventive subject matter disclosed herein. It should also be appreciated that terminology explicitly employed herein that also may appear in any disclosure incorporated by reference should be accorded a meaning most consistent with the particular concepts disclosed herein.
[0025] These and other aspects of the various embodiments will be apparent from and elucidated with reference to the embodiment s) described hereinafter.Brief Description of the Drawings
[0026] FIG. 1 is a diagram illustrating a system configured to operate a cloud-based cryptography service according to aspects of the present disclosure.
[0027] FIG. 2 is a flowchart illustrating a method for ensuring end-to-end encryption compliance according to aspects of the present disclosure.
[0028] FIG. 3 is a block diagram illustrating a card reading device according to aspects of the present disclosure.
[0029] FIG. 4 is a block diagram illustrating a cloud-based encryption system according to aspects of the present disclosure.
[0030] FIG. 5 is a block diagram illustrating a cryptography routing device according to aspects of the present disclosure.Detailed Description
[0031] The present disclosure relates is directed to systems and methods for ensuring end- to-end encryption compliance in connection with payment systems. More specifically, the systems and methods described herein provide for the simplified management of encryption compliance protocols via the use of a cloud-based encryption system.
[0032] It should be appreciated that the transmission of information between payment systems (including a point of interaction or point of sale device) and end payment arbiters must be performed under secure protocols to be compliant with established standard-setting organization rules. These security requirements include, among other things, point-to-point encryption (P2PE) for certain types of information, such as certain types of card information collected from payment cards. However, not all card information should be encrypted, and if certain information is mistakenly handled, could lead to payment errors such as declined payments.
[0033] In conventional systems, the determination of whether to pass along encrypted information or unencrypted information is made by the point of interaction device. As the number of types of payment cards (e.g., debit cards, credit cards, fleet cards, loyalty cards, gift cards, etc.) is ever increasing, the maintenance of the lookup table on the point of interaction becomes increasingly burdensome.
[0034] Accordingly, provided herein are systems and methods that ensure end-to-end encryption compliance that eliminates the need for the point of interaction device to make such determinations by using a cloud-based encryption system that can be more readily maintained and updated.
[0035] With reference to FIG. 1, a system 100 configured to operate a cloud-based encryption system 102 is illustrated according to various aspects of the present disclosure. In embodiments, the system 100 includes one or more card reading devices 108, 110 configured to receive and encrypt card data from a payment card and the cloud-based encryption system 102. The cloud-based encryption system 102 and the one or more card reading devices 108, 110 may be in secure communication with a cryptography routing device 106, as shown in FIG. 1. In particular embodiments, the system 100 may include the cryptography routing device 106, which may be a separate device from the cryptography system 102 as described in more detail below.
[0036] In embodiments, each of the one or more card reading devices 108, 110 may be configured to receive and encrypt card data from a plurality of different types of payment cards. In some examples, the card reading device 108, 110 may be a point of sale device 108 or a point of interaction device 110. As shown in FIG. 3, the card reading devices 108, 110 include one or more card readers. For example, in particular embodiments, the card reading devices 108, 110 may include a magnetic stripe reader 302 and a magnetic stripe driver 304 for reading magnetic stripe data (e.g., Track I and Track II data) of payment cards, an EMV reader 306 andan EMV driver for reading and processing EMV data from an EMV-enabled (i.e., chip enabled) payment card, a contactless reader 310 and a contactless driver for reading and processing contactless data from a contactless-enabled payment card, and / or the like. In further embodiments, the payment card may be presented via an electronic device (e.g., smartphone, Internet of Things (loT) appliance, etc.), a fob, and / or the like.
[0037] As further shown in FIG. 3, each of the card reading devices 108, 110 may include one or more cryptographic processors 314 configured to encrypt all or at least a portion of the card data received from the payment card. In embodiments, the cryptographic processor 314 of the card reading devices 108, 110 may be configured to encrypt all or at least a portion of the card data received from the payment card using one or more secure encryption protocols, including but not limited to VeriShield Crypto Library (VCL) and / or AES. That is, according to certain aspects of the present disclosure, the card reading devices 108, 110 may include instructions to not encrypt certain kinds of payment information (e.g., fleet card data), and therefore only a portion of the card information received by the point of sale device 108 and / or the point of interaction device 110 may be encrypted. In other embodiments, all of the card information received from the point of sale device 108 and / or the point of interaction device 110 may be encrypted.
[0038] In embodiments, the card reading devices 108, 110 may include one or more types of volatile and / or non-volatile memory 318, as well as an operating system 320 adapted to control the operations of the card reading device 108, 110. In still further embodiments, each card reading device 108, 110 may include a communications unit 322 configured to allow the card reading device 108, 110 to send and receive digital signals (e.g., instructions and / or data). As described in more detail below, the communications unit 322 may enable secure connections between the card reading devices 108, 110 and at least the cryptography routing device 106.
[0039] In embodiments, the system 100 may include a cloud-based encryption sub-system 102 comprising one or more computer processors, an encryption compliance database 104, and a memory storing the encryption compliance database 104 and machine-readable instructions that, when executed by the one or more computer processors, cause the one or more computer processors to perform the methods described herein.
[0040] For example, with reference to FIG. 4, the cloud-based encryption sub-system 102 can include one or more processors 402 and a computer-readable memory 404 interconnected and / or in communication via a system bus 406 containing conductive circuit pathways throughwhich instructions (e.g., machine-readable signals) may travel to effectuate communication, tasks, storage, and the like. The cloud -based encryption sub-system 102 can be connected to a power source (not shown), which can include an internal power supply and / or an external power supply. In embodiments, the cloud-based encryption sub-system 102 can also include one or more additional components, such as a user interface 408, a display 410, an input / output (I / O) interface 412, a networking unit 414, and the like, including combinations thereof. As shown, each of these components may be interconnected and / or in communication via the system bus 406, for example.
[0041] In embodiments, the one or more processors 402 can include one or more high-speed data processors adequate to execute the program components described herein and / or perform one or more operations of the methods described herein. The one or more processors 402 may include a microprocessor, a multi-core processor, a multithreaded processor, an ultra-low voltage processor, an embedded processor, and / or the like, including combinations thereof. The one or more processors 402 can include multiple processor cores on a single die and / or may be a part of a system on a chip (SoC) in which the processor 402 and other components are formed into a single integrated circuit, or a single package. That is, the one or more processors 402 may be a single processor, multiple independent processors, or multiple processor cores on a single die.
[0042] In embodiments, the user interface 408 may be configured to receive various forms of input from a user associated with the cloud-based encryption sub-system 102. The user interface 408 can include, but is not limited to, one or more of a keyboard, keypad, trackpad, trackball(s), capacitive keyboard, controller (e.g., a gaming controller), computer mouse, computer stylus / pen, a voice input device, and / or the like, including combinations thereof.
[0043] In embodiments, the display device 410 may be configured to display information, including text, graphs, and / or the like. The display device 410 can include, but is not limited to, a liquid crystal display (LCD), a light-emitting diode (LED) display, a touch screen or other touch-enabled display, a foldable display, a projection display, and so on, or combinations thereof.
[0044] In embodiments, the input / output (I / O) interface 412 may be configured to connect and / or enable communication with one or more peripheral devices (not shown), including but not limited to additional machine-readable memory devices, diagnostic equipment, and other attachable devices. The I / O interface 412 may include one or more I / O ports that provide aphysical connection to the one or more peripheral devices. In some embodiments, the I / O interface 412 may include one or more serial ports.
[0045] In embodiments, the networking unit 414 may include one or more types of networking interfaces that facilitate wired and / or wireless communication between the cloudbased encryption sub-system 102 and one or more external devices. That is, the networking unit 414 may operatively connect the cloud-based encryption sub-system 102 to one or more types of communications networks 416, which can include a direction interconnection, the Internet, a local area network (“LAN”), a metropolitan area network (“MAN”), a wide area network (“WAN”), a wired or Ethernet connection, a wireless connection, a cellular network, and similar types of communications networks, including combinations thereof. In some embodiments, the cloud-based encryption sub-system 102 may communicate with one or more remote / cloud-based servers and / or cloud-based services, such as the encryption key holder 114 and / or the cryptography routing device 106, via the communications network 416.
[0046] In embodiments, the memory 404 can be variously embodied in one or more forms of machine accessible and machine-readable memory. In some embodiments, the memory 404 includes a storage device (not shown), which can include, but is not limited to, a non-transitory storage medium, a magnetic disk storage, an optical disk storage, an array of storage devices, a solid-state memory device, and / or the like, as well as combinations thereof. The memory 404 may also include one or more other types of memory, such as dynamic random-access memory (DRAM), static random-access memory (SRAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), Flash memory, and / or the like, as well as combinations thereof. In embodiments, the memory 404 may include one or more types of transitory and / or non-transitory memory.
[0047] The cloud-based encryption sub-system 102 can be configured by software components stored in the memory 404 to perform one or more processes of the methods described herein. More specifically, the memory 404 can be configured to store an encryption compliance protocol database 104 as well as computer-readable instructions 422 that, when executed by the one or more processors 402, causes the cloud-based encryption sub-system 102 to ensure encryption compliance for card data received. The computer-readable instructions 222 and / or the database 104 stored in the memory 404 may form an encryption compliance package 424 that may be incorporated into, loaded from, loaded onto, or otherwise operatively available to and from the cloud-based encryption sub-system 102. Thus, in some embodiments, the encryption compliance package 224 and / or one or more individual softwarepackages may be stored in a local storage device of the memory 404. However, in other embodiments, the encryption compliance package 224 and / or one or more individual software packages may be loaded onto and / or updated from a remote server or service via the communications network 416.
[0048] In particular embodiments, the machine-readable instructions 422 of the encryption compliance package 424 may cause the one or more processors 402 to perform one or more of the following operations: (i) receive card data for completing a transaction, wherein at least a portion of the card data is encrypted card data; (ii) transmit, to an encryption key holder 114, at least the portion of the card data that is encrypted card data; (iii) receive, from the encryption key holder 114, decrypted card data, wherein the decrypted card data includes the encrypted card data that has been decrypted by the encryption key holder 114; (iv) identify, using the encryption compliance database 104, an encryption compliance protocol for the received card data based on the decrypted card data received from the encryption key holder 114; and (v) transmit the card data in accordance with the encryption compliance protocol to a payment application module 112.
[0049] The cloud-based encryption sub-system 102 may also include an operating system component 426, which may be stored in the memory 404. The operating system component 426 may be an executable program facilitating the operation of the cloud-based encryption subsystem 102. Typically, the operating system component 426 can facilitate access of the I / O interface 412, network interface 414, the user interface 408, and the display 410, and can communicate or control other components of the cloud-based encryption sub-system 102.
[0050] In embodiments, the system 100 can include a cryptography routing device 106 that is configured to receive card data from, for example, one or more card reading devices 108, 110. As described herein, the one or more card reading devices 108, 110 may be located remotely from the cryptography routing device 106 and may be in secure communication with the cryptography routing device 106 via one or more secured wireless and / or wired connections.
[0051] As shown in FIG. 1, once the cryptography routing device 106 receives card information from the card reading device(s) 108, 110, the cryptography routing device 106 may determine whether to pass that information to the cloud-based encryption sub-system 102 or to a payment application module 112. For example, if the card information received by the cryptography routing device 106 includes unencrypted (i.e., “clear”) data, then that information may be passed directly to the payment application module 112. Otherwise, the cryptographyrouting device 106 will pass the encrypted card information to the cloud-based encryption system 102.
[0052] At the cloud-based encryption system 102, the cloud-based encryption system 102 will establish a secure connection with an encryption key holder 114. In embodiments, the encryption key holder 114 is aware of the encryption algorithm(s) used by the point of sale device 108 and / or the point of interaction device 110 to encrypt the card data, and possesses the encryption keys necessary to decrypt at least a portion of the card data. In particular embodiments, the encryption key holder 114 can be a third-party encryption service provider (e.g., a P2PE encryption provider), or can be one or more financial institutions 116 associated with the particular type of card information received.
[0053] In embodiments, the encryption key holder 114 can decrypt all or some of the card data received from the card reading devices 108, 110 and return decrypted card data to the cloud-based encryption system 102 via the secure connection. In some embodiments, only a portion or a subset of the card data may be decrypted, while another portion or subset of the card data remains encrypted. For example, in some embodiments, the encryption key holder 114 may return only card data that is not “protected card information” (PCI) under industry standards in the clear (i.e., decrypted). In embodiments, the decrypted portion of the card data includes an identifier associated with an aspect of the payment information, including but not limited to, the payment card type or the issuing financial institution.
[0054] The cloud-based encryption system 102 may then identify, using an encryption compliance database 104, an encryption compliance protocol for handling the card data received from the card reading device(s) 108, 110. For example, the decrypted card data may be examined by the cloud-based encryption system 102 to determine one or more identifiers (e.g., the first six numbers of a payment card, etc.) in the decrypted card data. These identifiers can indicate whether the card data includes specific types of protected or unprotected card information. In some embodiments, the encryption compliance database 104 may include a plurality of rules for handling different types of payment cards, such as loyalty cards, secondary payment cards, attendant cards, primary payment cards, and / or the like. Using the various identifiers, the encryption compliance database 104 may be used by the cloud-based encryption system 102 to search for an appropriate encryption compliance protocol. That is, encryption compliance database 104 may include rules for determining whether certain card information must be transmitted in an encrypted format, in an unencrypted format, or some combination thereof.
[0055] The cloud-based encryption system 102 may then transmit the card data received from the card reading device(s) 108, 110 to a payment application module 112 in accordance with the encryption compliance protocol. As described herein, the card data may be entirely encrypted, or may include some more of unencrypted and / or decrypted card data. In some embodiments, the cloud-based encryption system 102 may route the card data to the payment application module 112 via the cryptography routing device 106. In other embodiments, the cloud-based encryption system 102 may route the card data directly to the payment application module 112. In still further embodiments, the cryptography routing device 106 may be operated on the same device as the payment application module 112 such that the cloud-based encryption system 102 routes the card data to both the cryptography routing device 106 and the payment application module 112.
[0056] In embodiments, the payment application module 112 may then transmit the card data received from the received from the card reading device(s) 108, 110 to an end payment arbiter 116, 118, 120 in accordance with the encryption compliance protocol identified by the cloud-based encryption system 102. For example, protected card holder data may be transmitted in an encrypted format from the payment application module 112 to the acquirer 116 in accordance with acquirer-specific specifications. In further embodiments, the encrypted card data received from the point of sale device 108 and / or the point of interaction device 110 may include non-protected card data, which is decrypted by the encryption key holder 114 and can be transmitted to the corresponding entity 118, 120 in the clear (i.e., without encryption) according to the particular compliance protocol.
[0057] In embodiments, the end payment arbiter 116 can be a financial institution, bank, and / or the like. In other embodiments, the end payment arbiter can be a loyalty program provider 118 and / or a secondary payment provider 120. Although certain examples of end payment arbiters 116, 118, 120 are described, it should be appreciated that these are not exhaustive and may include other types of organizations supporting financial transactions.
[0058] As described herein, the cryptography routing device 106 can be a separate device from the cloud-based encryption system 102. Additionally, as mentioned above, the cryptography routing device 106 may include the payment application module 112. For example, with reference to FIG. 5, the cryptography routing device 106 can include one or more processors 502 and a computer-readable memory 504 interconnected and / or in communication via a system bus 506 containing conductive circuit pathways through which instructions (e.g., machine-readable signals) may travel to effectuate communication, tasks,storage, and the like. The cryptography routing device 106 can be connected to a power source (not shown), which can include an internal power supply and / or an external power supply. In embodiments, the cryptography routing device 106 can also include one or more additional components, such as a user interface 508, a display 510, an input / output (I / O) interface 512, a networking unit 514, and the like, including combinations thereof. As shown, each of these components may be interconnected and / or in communication via the system bus 506, for example.
[0059] In embodiments, the one or more processors 502 can include one or more high-speed data processors adequate to execute the program components described herein and / or perform one or more operations of the methods described herein. The one or more processors 502 may include a microprocessor, a multi-core processor, a multithreaded processor, an ultra-low voltage processor, an embedded processor, and / or the like, including combinations thereof. The one or more processors 502 can include multiple processor cores on a single die and / or may be a part of a system on a chip (SoC) in which the processor 502 and other components are formed into a single integrated circuit, or a single package. That is, the one or more processors 502 may be a single processor, multiple independent processors, or multiple processor cores on a single die.
[0060] In embodiments, the user interface 508 may be configured to receive various forms of input from a user associated with the cryptography routing device 106. The user interface 508 can include, but is not limited to, one or more of a keyboard, keypad, trackpad, trackball(s), capacitive keyboard, controller (e.g., a gaming controller), computer mouse, computer stylus / pen, a voice input device, and / or the like, including combinations thereof.
[0061] In embodiments, the display device 510 may be configured to display information, including text, graphs, and / or the like. The display device 510 can include, but is not limited to, a liquid crystal display (LCD), a light-emitting diode (LED) display, a touch screen or other touch-enabled display, a foldable display, a projection display, and so on, or combinations thereof.
[0062] In embodiments, the input / output (I / O) interface 512 may be configured to connect and / or enable communication with one or more peripheral devices (not shown), including but not limited to additional machine-readable memory devices, diagnostic equipment, and other attachable devices. The I / O interface 512 may include one or more I / O ports that provide a physical connection to the one or more peripheral devices. In some embodiments, the I / O interface 512 may include one or more serial ports.
[0063] In embodiments, the networking unit 514 may include one or more types of networking interfaces that facilitate wired and / or wireless communication between the cryptography routing device 106 and one or more external devices. That is, the networking unit 214 may operatively connect the cryptography routing device 106 to one or more types of communications networks 516, which can include a direction interconnection, the Internet, a local area network (“LAN”), a metropolitan area network (“MAN”), a wide area network (“WAN”), a wired or Ethernet connection, a wireless connection, a cellular network, and similar types of communications networks, including combinations thereof. In some embodiments, the cryptography routing device 106 may communicate with one or more remote / cloud-based servers and / or cloud-based services, such as cloud-based encryption sub-system 102, one or more card reading devices 108, 110, and / or a payment application module 112 via the communications network 516.
[0064] In embodiments, the memory 504 can be variously embodied in one or more forms of machine accessible and machine-readable memory. In some embodiments, the memory 504 includes a storage device (not shown), which can include, but is not limited to, a non-transitory storage medium, a magnetic disk storage, an optical disk storage, an array of storage devices, a solid-state memory device, and / or the like, as well as combinations thereof. The memory 504 may also include one or more other types of memory, such as dynamic random-access memory (DRAM), static random-access memory (SRAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), Flash memory, and / or the like, as well as combinations thereof. In embodiments, the memory 504 may include one or more types of transitory and / or non-transitory memory.
[0065] The cryptography routing device 106 can be configured by software components stored in the memory 504 to perform one or more processes of the methods described herein. More specifically, the memory 504 can be configured to store data / information (not shown) and computer-readable instructions 222 that, when executed by the one or more processors 202, causes the cryptography routing device 106 to perform the following operations: (i) receive, from at least one card reading device 108, 110, card data including encrypted card data; (ii) determine, based on the received card data, whether to transmit the received card data to the cloud-based encryption system 102 and / or the payment application module 112; (iii) transmit the received card data to the cloud-based encryption system 102 and / or the payment application module 112. In embodiments, the cryptography routing device 106 includes the payment application module 112, and as such, may be further configured to perform thefollowing operations: (i) receive, in accordance with the encryption compliance protocol identified by the cloud-based encryption system 102, the card data; and (ii) transmit the card data to an end payment arbiter 116, 118, 120 for completing a transaction, wherein the card data is transmitted in accordance with the encryption compliance protocol identified by the cloud-based encryption system 102.
[0066] The data, the computer-readable instructions 222, and optionally the payment application module 112 stored in the memory 204 may form a cryptography routing package 524 that may be incorporated into, loaded from, loaded onto, or otherwise operatively available to and from the cryptography routing device 106. Thus, in some embodiments, the cryptography routing package 524 and / or one or more individual software packages may be stored in a local storage device of the memory 504. However, in other embodiments, the cryptography routing package 524 and / or one or more individual software packages may be loaded onto and / or updated from a remote server or service.
[0067] The cryptography routing device 106 may also include an operating system component 526, which may be stored in the memory 504. The operating system component 526 may be an executable program facilitating the operation of the cryptography routing device 106. Typically, the operating system component 526 can facilitate access of the I / O interface 512, network interface 514, the user interface 508, and the display 510, and can communicate or control other components of the cryptography routing device 106.
[0068] With reference to FIG. 2, a flowchart illustrating a method 200 for end-to-end encryption compliance is provided according to various aspects of the present disclosure. As shown, the method 200 can include: in a step 210, receiving card data at a cloud-based encryption system 102 comprising at least one computer processor and memory storing an encryption compliance database 104, wherein the card data includes encrypted card data; in a step 220, transmitting at least a portion of the encrypted card data from the cloud-based encryption system 102 to an encryption key holder 114 via a secure connection; in a step 230, receiving decrypted card data at the cloud-based encryption system 102 from the encryption key holder 114 via the secure connection; in a step 240, identifying an encryption compliance protocol for the card data based on the decrypted card data received and the encryption compliance database 104; and in a step 250, transmitted the card data to a payment application module 112 in accordance with the encryption compliance protocol. In some embodiments, the method 200 may also include, in a step 260, transmitting the card data from the paymentapplication module 112 to an end payment arbiter 116, 118, 120 in accordance with the encryption compliance protocol.
[0069] In particular embodiments, the method 200 can further include performance of one or more of the following operations at the cryptography routing device 106: (i) receiving, from at least one card reading device 108, 110, card data including encrypted card data; (ii) determining, based on the received card data, whether to transmit the received card data to the cloud-based encryption system 102 or the payment application module 112; and (iii) transmitting the received card data to the cloud-based encryption system 102 and / or the payment application module 112. In certain embodiments, determining whether to transmit the card data to the cloud-based encryption system 102 or the payment application module 112 may include: (i) determining whether the received card data includes encrypted and / or unencrypted (i.e., clear) card information; and (ii) if the received card data includes encrypted card information, then transmitting the received card data to the cloud-based encryption system 102.
[0070] In further embodiments, the method 200 can include performance of one or more of the following operations at the at least one card reading device 108, 110: (i) receiving, via a card reader of the at least one card reading device 108, 110, card data from a payment card; (ii) encrypting, via a cryptographic processor 314 of the at least one card reading device 108, 110, at least a portion of the card data received from the payment card; and (iii) transmitting, to the cryptography routing device 106, the card data including at least the encrypted portion of the card data. In some embodiments, the cryptographic processor 314 of the at least one card reading device 108, 110 can be configured to encrypt at least a portion of the card data received from the payment card using one or more secure encryption protocols including VeriShield Crypto Library (VCL), AES, and / or the like. In particular embodiments, the at least one card reading device 108, 110 may include instructions to not encrypt one or more types of card information, such as fleet card information.
[0071] As described herein, the various computer systems may include one or more computer processors, machine-readable memory, interface buses, and / or system buses that contain conductive circuit pathways through which instructions (e.g., machine-readable signals) may travel to effectuate communication, tasks, storage and the like. Each of the one or more processors may include a high-speed data processor adequate to execute the operations described herein and / or various specialized processing units. In some examples, one or more of the processors may be a single processor, multiple processors, or multiple processor coreson a single die. In some examples, an interface bus may include a network interface configured to connect one component or device to a communications network, which can include a direct interconnection, the Internet, a local area network (“LAN”), a metropolitan area network (“MAN”), a wide area network (“WAN”), a wired or Ethernet connection, a wireless connection, and similar types of communications networks, including combinations thereof. In certain examples, the memory described herein can be variously embodied in one or more forms of machine-accessible and machine-readable memory, and can include, but is not limited to, a non-transitory storage medium, a magnetic disk storage, an optical disk storage, an array of storage devices, a solid-state memory device, and the like, including combinations thereof. According to another embodiment, certain memory components can be distributed remotely, such as in various cloud computing applications, among other configurations.
[0072] All definitions, as defined and used herein, should be understood to control over dictionary definitions, definitions in documents incorporated by reference, and / or ordinary meanings of the defined terms.
[0073] The indefinite articles “a” and “an,” as used herein in the specification and in the claims, unless clearly indicated to the contrary, should be understood to mean “at least one.”
[0074] The phrase “and / or,” as used herein in the specification and in the claims, should be understood to mean “either or both” of the elements so conjoined, i.e., elements that are conjunctively present in some cases and disjunctively present in other cases. Multiple elements listed with “and / or” should be construed in the same fashion, i.e., “one or more” of the elements so conjoined. Other elements can optionally be present other than the elements specifically identified by the “and / or” clause, whether related or unrelated to those elements specifically identified.
[0075] As used herein in the specification and in the claims, “or” should be understood to have the same meaning as “and / or” as defined above. For example, when separating items in a list, “or” or “and / or” shall be interpreted as being inclusive, i.e., the inclusion of at least one, but also including more than one, of a number or list of elements, and, optionally, additional unlisted items. Only terms clearly indicated to the contrary, such as “only one of’ or “exactly one of,” or, when used in the claims, “consisting of,” will refer to the inclusion of exactly one element of a number or list of elements. In general, the term “or” as used herein shall only be interpreted as indicating exclusive alternatives (i.e. “one or the other but not both”) when preceded by terms of exclusivity, such as “either,” “one of,” “only one of,” or “exactly one of.”
[0076] As used herein in the specification and in the claims, the phrase “at least one,” in reference to a list of one or more elements, should be understood to mean at least one element selected from any one or more of the elements in the list of elements, but not necessarily including at least one of each and every element specifically listed within the list of elements and not excluding any combinations of elements in the list of elements. This definition also allows that elements can optionally be present other than the elements specifically identified within the list of elements to which the phrase “at least one” refers, whether related or unrelated to those elements specifically identified.
[0077] It should also be understood that, unless clearly indicated to the contrary, in any methods claimed herein that include more than one step or act, the order of the steps or acts of the method is not necessarily limited to the order in which the steps or acts of the method are recited.
[0078] In the claims, as well as in the specification above, all transitional phrases such as “comprising,” “including,” “carrying,” “having,” “containing,” “involving,” “holding,” “composed of,” and the like are to be understood to be open-ended, i.e., to mean including but not limited to. Only the transitional phrases “consisting of’ and “consisting essentially of’ shall be closed or semi-closed transitional phrases, respectively.
[0079] The above-described examples of the described subject matter can be implemented in any of numerous ways. For example, some aspects can be implemented using hardware, software or a combination thereof. When any aspect is implemented at least in part in software, the software code can be executed on any suitable processor or collection of processors, whether provided in a single device or computer or distributed among multiple device s / computers .
[0080] The present disclosure can be implemented as a system, a method, and / or a computer program product at any possible technical detail level of integration. The computer program product can include a computer readable storage medium (or media) having computer readable program instructions thereon for causing a processor to carry out aspects of the present disclosure.
[0081] The computer readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device. The computer readable storage medium can be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of morespecific examples of the computer readable storage medium includes the following: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanically encoded device such as punch-cards or raised structures in a groove having instructions recorded thereon, and any suitable combination of the foregoing. A computer readable storage medium, as used herein, is not to be construed as being transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission media (e.g., light pulses passing through a fiber-optic cable), or electrical signals transmitted through a wire.
[0082] Computer readable program instructions described herein can be downloaded to respective computing / processing devices from a computer readable storage medium or to an external computer or external storage device via a network, for example, the Internet, a local area network, a wide area network and / or a wireless network. The network can comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and / or edge servers. A network adapter card or network interface in each computing / processing device receives computer readable program instructions from the network and forwards the computer readable program instructions for storage in a computer readable storage medium within the respective computing / processing device.
[0083] Computer readable program instructions for carrying out operations of the present disclosure can be assembler instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine dependent instructions, microcode, firmware instructions, statesetting data, configuration data for integrated circuitry, or either source code or object code written in any combination of one or more programming languages, including an object oriented programming language such as Smalltalk, C++, or the like, and procedural programming languages, such as the “C” programming language or similar programming languages. The computer readable program instructions can execute entirely on the user’s computer, partly on the user's computer, as a stand-alone software package, partly on the user’s computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using anInternet Service Provider). In some examples, electronic circuitry including, for example, programmable logic circuitry, field-programmable gate arrays (FPGA), or programmable logic arrays (PLA) can execute the computer readable program instructions by utilizing state information of the computer readable program instructions to personalize the electronic circuitry, in order to perform aspects of the present disclosure.
[0084] Aspects of the present disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to examples of the disclosure. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer readable program instructions.
[0085] The computer readable program instructions can be provided to a processor of a, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. These computer readable program instructions can also be stored in a computer readable storage medium that can direct a computer, a programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer readable storage medium having instructions stored therein comprises an article of manufacture including instructions which implement aspects of the function / act specified in the flowchart and / or block diagram or blocks.
[0086] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus, or other device to produce a computer implemented process, such that the instructions which execute on the computer, other programmable apparatus, or other device implement the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0087] The flowchart and block diagrams in the Figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various examples of the present disclosure. In this regard, each block in the flowchart or block diagrams can represent a module, segment, or portion of instructions, which comprises one or more executable instructions for implementing the specified logical function(s). In some alternative implementations, the functions noted in theblocks can occur out of the order noted in the Figures. For example, two blocks shown in succession can, in fact, be executed substantially concurrently, or the blocks can sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flowchart illustration, and combinations of blocks in the block diagrams and / or flowchart illustration, can be implemented by special purpose hardware-based systems that perform the specified functions or acts or carry out combinations of special purpose hardware and computer instructions.
[0088] Other implementations are within the scope of the following claims and other claims to which the applicant can be entitled.
[0089] While various examples have been described and illustrated herein, those of ordinary skill in the art will readily envision a variety of other means and / or structures for performing the function and / or obtaining the results and / or one or more of the advantages described herein, and each of such variations and / or modifications is deemed to be within the scope of the examples described herein. More generally, those skilled in the art will readily appreciate that all parameters, dimensions, materials, and configurations described herein are meant to be exemplary and that the actual parameters, dimensions, materials, and / or configurations will depend upon the specific application or applications for which the teachings is / are used. Those skilled in the art will recognize or be able to ascertain using no more than routine experimentation, many equivalents to the specific examples described herein. It is, therefore, to be understood that the foregoing examples are presented by way of example only and that, within the scope of the appended claims and equivalents thereto, examples can be practiced otherwise than as specifically described and claimed. Examples of the present disclosure are directed to each individual feature, system, article, material, kit, and / or method described herein. In addition, any combination of two or more such features, systems, articles, materials, kits, and / or methods, if such features, systems, articles, materials, kits, and / or methods are not mutually inconsistent, is included within the scope of the present disclosure.
Claims
CLAIMSWhat is claimed is:
1. A method for end-to-end encryption compliance, comprising: on a cloud-based encryption system comprising at least one computer processor and memory storing an encryption compliance database: receiving card data for completing a transaction, wherein at least a portion of the card data is encrypted card data; transmitting, to an encryption key holder, at least the portion of the card data that is encrypted card data; receiving, from the encryption key holder, decrypted card data, wherein the decrypted card data includes the encrypted card data that has been decrypted by the encryption key holder; identifying, using the encryption compliance database, an encryption compliance protocol for the received card data based on the decrypted card data received from the encryption key holder; and transmitting the card data in accordance with the encryption compliance protocol to a payment application module.
2. The method for end-to-end encryption compliance of claim 1, wherein the card data is received from a cryptography routing device via at least one first secure connection, the at least one first secure connection comprising one or more of a wired and wireless communications network connection.
3. The method for end-to-end encryption compliance of claim 2, further comprising: at the cryptography routing device: receiving, from at least one card reading device, the card data including the encrypted card data; determining, based on the received card data, whether to transmit the received card data to the cloud-based encryption system or the payment application module; and transmitting the received card data to the cloud-based encryption system and / or the payment application module.
4. The method for end-to-end encryption compliance of claim 3, determining whether to transmit the card data to the cloud-based encryption system or the payment application module includes: determining whether the received card data includes encrypted and / or unencrypted card information; and if the received card data includes encrypted card information, transmitting the received card data to the cloud-based encryption system.
5. The method for end-to-end encryption compliance of claim 3, further comprising: at the at least one card reading device: receiving, via a card reader of the at least one card reading device, card data from a payment card; encrypting, via a cryptographic processor of the at least one card reading device, at least a portion of the card data received from the payment card; and transmitting, to the cryptography routing device, the card data including at least the encrypted portion of the card data.
6. The method for end-to-end encryption compliance of claim 5, wherein cryptographic processor of the at least one card reading device is configured to encrypt at least a portion of the card data received from the payment card using one or more secure encryption protocols including VeriShield Crypto Library (VCL) and / or AES.
7. The method for end-to-end encryption compliance of claim 5, wherein the at least one card reading device includes instructions to not encrypt one or more types of card information.
8. The method for end-to-end encryption compliance of claim 5, wherein the card reader of the at least one card reading device is at least one of a magnetic stripe reader, an EMV reader, and a contactless reader.
9. The method for end-to-end encryption compliance of claim 1, wherein at least the portion of the card data that is encrypted card data is transmitted to the encryption key holder via at least one second secure connection, the at least one second secure connection comprising one or more of a wired and wireless communications network connection.
10. The method for end-to-end encryption compliance of claim 5, wherein the encryption key holder is configured to determine which encryption algorithms are used by the cryptographic processor of the at least one card reading device to encrypt the card data received, and wherein the encryption key holder is configured to store one or more encryption keys necessary to decrypt at least a portion of the encrypted card data.
11. The method for end-to-end encryption compliance of claim 10, wherein the encryption key holder is a third-party encryption service provider.
12. The method for end-to-end encryption compliance of claim 10, wherein the encryption key holder is a financial institution associated with the type of card data received.
13. The method for end-to-end encryption compliance of claim 1, further comprising: at the payment application module: receiving, in accordance with the encryption compliance protocol, the card data from the cloud-based encryption system; and transmitting the card data received to an end payment arbiter for completing the transaction, wherein the card data is transmitted to the end payment arbiter in accordance with the encryption compliance protocol identified by the cloud-based encryption system.
14. The method for end-to-end encryption compliance of claim 1, wherein the encryption compliance database comprises a plurality of rules for handling different types of payment cards based on one or more identifiers present in the card data, the plurality of rules including instructions for transmitting one or more types of card information in an encrypted format when identified, one or more types of card information in an unencrypted format when identified, and / or a combination thereof.
15. A cloud-based encryption system, comprising: one or more computer processors; a memory storing an encryption compliance database and machine-readable instructions that, when executed by the one or more computer processors, cause the one or more computer processors to perform the following operations:receive card data for completing a transaction, wherein at least a portion of the card data is encrypted card data; transmit, to an encryption keyholder, at least the portion of the card data that is encrypted card data; receive, from the encryption key holder, decrypted card data, wherein the decrypted card data includes encrypted card data that has been decrypted by the encryption key holder; identify, using the encryption compliance database, an encryption compliance protocol for the received card data based on the decrypted card data received from the encryption key holder; and transmit the card data in accordance with the encryption compliance protocol to a payment application module.
16. The cloud-based encryption system of claim 15, wherein the card data is received by the cloud-based encryption system from a cryptography routing device via at least one first secure connection.
17. The cloud-based encryption system of claim 16, wherein at least the portion of the card data that is encrypted card data is transmitted to the encryption key holder via at least one second secure connection.
18. The cloud-based encryption system of claim 15, wherein the encryption compliance database comprises a plurality of rules for handling different types of payment cards based on one or more identifiers present in the card data, the plurality of rules including instructions for transmitting one or more types of card information in an encrypted format when identified, one or more types of card information in an unencrypted format when identified, and / or a combination thereof.
19. A system configured to operate a cloud-based cryptography service for completing payment transactions, the system comprising: one or more card reading devices configured to receive and encrypt card data from a payment card, the one or more card reading devices being in secure communication with a cryptography routing device;a cloud-based encryption system in communication with the cryptography routing device and a payment application module; wherein the cryptography routing device is configured to: receive, from at least one card reading device, card data for completing a transaction, wherein at least a portion of the card data is encrypted card data; determine, based on the received card data, whether to transmit the received card data to the cloud-based encryption system or the payment application module; and transmit the received card data to the cloud-based encryption system; wherein the cloud-based encryption system is configured to: receive the card data from the cloud-based encryption system via at least one first secure connection; identify, using the encryption compliance database, an encryption compliance protocol for the received card data; and transmit, to the payment application module, the received card data in accordance with the encryption compliance protocol identified; and wherein the payment application module is configured to: receive, in accordance with the encryption compliance protocol, the card data from the cloud-based encryption system; and transmit the received card data to an end payment arbiter for completing the transaction, wherein the card data is transmitted to the end payment arbiter in accordance with the encryption compliance protocol identified by the cloud-based encryption system.
20. The system of claim 19, wherein each of the one or more card reading devices comprises a card reader and a cryptographic processor such that each of the one or more card reading devices is configured to: receive, via the card reader of the corresponding card reading device, card data from a payment card; encrypt, via the cryptographic processor of the corresponding card reading device, at least a portion of the card data received from the payment card; and transmit, to the cryptography routing device, the card data including at least the encrypted portion of the card data.