Token Requestor Master Keys for Low-Latency Cryptogram Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in generating transaction cryptograms efficiently and securely without relying on remote secure servers, leading to increased transaction latency and security risks.

Innovation Solution

Implementing token-requestor-based key management, where a processor computer generates a master key for token requestors, allowing them to locally produce cryptograms using derived keys, ensuring secure and efficient transaction validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If TAW is generated on a remote secure server, then security is maintained, but transaction latency increases

Engineering Contradiction:
ImprovesecurityVSAvoidtransaction latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the TAW generation capability from the remote secure server and places it locally on the token requestor's device. The TAW is generated using a key stored in a secure element on the token requestor's device, eliminating the need to fetch TAW from a remote server and thus reducing transaction latency while maintaining security through the secure element.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The token requestor's device performs self-service by generating its own TAW locally using the stored key in the secure element. This eliminates dependency on remote server operations for TAW generation, reducing transaction latency while the secure element ensures the key and generated TAW remain protected.

Inventive Principle:
Principle #25Self-service

2Loss of time

If TAW is generated locally without secure element, then transaction latency is reduced, but security is compromised

Engineering Contradiction:
Improvetransaction latencyVSAvoidsecurity
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent introduces a secure element as an intermediary component on the token requestor's device. This secure element securely stores the key and performs secure cryptographic operations for TAW generation, enabling local TAW generation (reducing latency) while maintaining security through the secure element's protected environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If master key is shared with token requestor, then local cryptogram generation is enabled, but key security risks increase

Engineering Contradiction:
Improvelocal cryptogram generationVSAvoidkey security risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by restricting the master key to a specific secure location (secure element) on the token requestor's device. The key is stored and used only within the protected secure element environment, enabling local cryptogram generation while mitigating security risks through the secure element's isolated and protected operational context.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3837804B1Token keys to generate cryptograms for token interactions
Publication Date: 2025.12.31 VISA INTERNATIONAL SERVICE ASSOCIATION
  • EP3837804B1 patent drawingFigure 1
  • EP3837804B1 patent drawingFigure 2
  • EP3837804B1 patent drawingFigure 3

AI summary

Techniques are described for managing master keys for token requestors to use in generating cryptograms such as TAVVs. A processor computer generates a first master key for a token requestor, the first master key being generated based on (a) a second master key managed by the processor computer and (b) an identifier of the token requestor. The processor computer transmits, to a token requestor computer corresponding to the token requestor, the first master key. The processor computer receives, from the token requestor computer, a request for a token. Responsive to receiving the request for the token, the processor computer transmits the token to the token requestor computer; and receives, from the token requestor computer, an authorization request message comprising the token and a cryptogram generated by the token requestor computer using the first master key and the token.