Token Requestor Master Keys for Low-Latency Cryptogram Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in generating transaction cryptograms efficiently and securely without relying on remote secure servers, leading to increased transaction latency and security risks.
Innovation Solution
Implementing token-requestor-based key management, where a processor computer generates a master key for token requestors, allowing them to locally produce cryptograms using derived keys, ensuring secure and efficient transaction validation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If TAW is generated on a remote secure server, then security is maintained, but transaction latency increases
Solution Approach 1:
The patent extracts the TAW generation capability from the remote secure server and places it locally on the token requestor's device. The TAW is generated using a key stored in a secure element on the token requestor's device, eliminating the need to fetch TAW from a remote server and thus reducing transaction latency while maintaining security through the secure element.
Solution Approach 2:
The token requestor's device performs self-service by generating its own TAW locally using the stored key in the secure element. This eliminates dependency on remote server operations for TAW generation, reducing transaction latency while the secure element ensures the key and generated TAW remain protected.
2Loss of time
If TAW is generated locally without secure element, then transaction latency is reduced, but security is compromised
Solution Approach 1:
The patent introduces a secure element as an intermediary component on the token requestor's device. This secure element securely stores the key and performs secure cryptographic operations for TAW generation, enabling local TAW generation (reducing latency) while maintaining security through the secure element's protected environment.
3Ease of operation
If master key is shared with token requestor, then local cryptogram generation is enabled, but key security risks increase
Solution Approach 1:
The patent applies local quality by restricting the master key to a specific secure location (secure element) on the token requestor's device. The key is stored and used only within the protected secure element environment, enabling local cryptogram generation while mitigating security risks through the secure element's isolated and protected operational context.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Techniques are described for managing master keys for token requestors to use in generating cryptograms such as TAVVs. A processor computer generates a first master key for a token requestor, the first master key being generated based on (a) a second master key managed by the processor computer and (b) an identifier of the token requestor. The processor computer transmits, to a token requestor computer corresponding to the token requestor, the first master key. The processor computer receives, from the token requestor computer, a request for a token. Responsive to receiving the request for the token, the processor computer transmits the token to the token requestor computer; and receives, from the token requestor computer, an authorization request message comprising the token and a cryptogram generated by the token requestor computer using the first master key and the token.