Card Lifecycle Encryption with Double Signature Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems for electronic payment transactions and online banking face security challenges in performing certain operations, such as card lifecycle actions, due to difficulties in verifying security measures through online communications, leading to restrictions on in-person or telephonic communications only.

Innovation Solution

The implementation of a card lifecycle encryption system that uses encryption and double signature validation to securely perform card lifecycle actions by providing an encryption key set to an issuing system server and a client device, validating signatures, and decrypting messages to verify identities and contents of request messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional online communication systems are used for card lifecycle actions, then ease of operation is improved, but security is worsened due to inability to verify security measures

Engineering Contradiction:
Improveonline banking operationsVSAvoidsecurity verification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces cryptographic intermediaries (encryption keys, digital signatures, and certificates) that mediate between the online communication channel and security verification. These intermediaries enable secure card lifecycle actions over online communications by providing verifiable security measures without requiring in-person interaction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If additional security measures are implemented for card lifecycle actions, then security is improved, but device complexity is worsened

Engineering Contradiction:
Improvesecurity measuresVSAvoidsystem infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary security setup where encryption keys and digital certificates are pre-configured in the system infrastructure before card lifecycle actions occur. This preliminary action establishes security frameworks that automatically validate transactions without adding real-time complexity to individual operations.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If encryption and double signature validation are implemented, then security is improved, but loss of time is worsened due to additional validation steps

Engineering Contradiction:
Improvesecurity validationVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary validation of digital signatures and encryption keys before the actual card lifecycle action processing. By validating security credentials in advance and caching verification results, the system reduces the time penalty of security measures during critical transaction processing.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230153788A1Performing card lifecycle actions for card accounts utilizing encryption and double signature validation
Publication Date: 2023.05.18 MARQETA INC
  • US20230153788A1 patent drawing
  • US20230153788A1 patent drawing
  • US20230153788A1 patent drawing

AI summary

This disclosure describes methods, non-transitory computer readable storage media, and systems that utilize encryption and double signature validation to perform card lifecycle actions for card accounts. In connection with a request to perform a card lifecycle action (e.g., setting a personal identification number) for a card account, the disclosed system provides an encryption key set to an issuing system server that issued the request. The disclosed system receives an encrypted request message from the issuing system server encrypted utilizing the encryption key set provided to the issuing system server and signed by the issuing system server and a client device. Additionally, the disclosed system validates that the signatures from the encrypted request message correspond to the issuing system server and the client device of the user. The disclosed system also decrypts the encrypted request message and performs the card lifecycle action based on data in the decrypted request message.