CA2932346C

Method and system for secure authentication of user and mobile device without secure elements

Abstract

A method for generating payment credentials in a payment transaction includes: storing, in a memory, at least a single use key associated with a transaction account; receiving, by a receiving device, a personal identification number; identifying, by a processing device, a first session key; generating, by the processing device, a second session key based on at least the stored single use key and the received personal identification number; generating, by the processing device, a first application cryptogram based on at least the first session key; generating, by the processing device, a second application cryptogram based on at least the second session key; and transmitting, by a transmitting device, at least the first application cryptogram and second application cryptogram for use in a payment transaction.

CA2932346C, drawing sheet 1
Sheet 1 of 18

Term

8.2 yearsleft in the term

Expires 2 December 2034.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

24 claims: 4 independent, 20 dependent

  1. 1
    CA 029323« 2016-03-31 WO 2015/084755 PCT/US2014/067992 -48WHAT IS CLAIMED IS:1. A method for generating payment credentials in a payment transaction, comprising: storing, in a memory, at least a single use key associated with a transaction account;receiving, by a receiving device, a personal identification number;identifying, by a processing device, a first session key;generating, by the processing device, a second session key based on at least the stored single use key and the received personal identification number;generating, by the processing device, a first application cryptogram based on at least the first session key;generating, by the processing device, a second application cryptogram based on at least the second session key;and transmitting, by a transmitting device, at least the first application cryptogram and second application cryptogram for use in a payment transaction,
  2. 7
    8. A method for generating payment credentials in a payment transaction, comprising:storing, in a memory, at least a card master key associated with a transaction account;generating, by a processing device, a first session key based on at least the stored card master key;generating, by the processing device, a second session key;generating, by the processing device, a first application cryptogram based on at least the first session key;generating, by the processing device, a second application cryptogram based on at least the second session key;and transmitting, by a transmitting device, at least the first application cryptogram and second application cryptogram for use in a payment transaction.
  3. 8
    9. The method of claim 8, further comprising:storing, in the memory, a transaction account sequence number associated with the transaction account, wherein the first session key is further based on the stored transaction account sequence number. CA 029323« 2016-05-31 WO 2015/084755 PCT/US2014/067992 - 5010. The method of claim 8, further comprising: storing, in the memory, a second card master key associated with the transaction account, wherein the second session key is based on at least the stored second card master key.
  4. 11
    13. The method of claim 11, wherein the result of the validation is transmitted to a financial institution associated with the transaction account.
  5. 12
    14. A system for generating payment credentials in a payment transaction, comprising:a memory configured to store at least a single use key associated with a transaction account;a receiving device configured to receive a personal identification number;a processing device configured to identify a first session key, generate a second session key based on at least the stored single use key and the received personal identification number, CA 029323« 2016-05-31 WO 2015/084755 PCT/US2014/067992 - 51 generate a first application cryptogram based on at least the first session key, and generate a second application cryptogram based on at least the second session key;and a transmitting device configured to transmit at least the first application cryptogram and second application cryptogram for use in a payment transaction.
  6. 14
    16. The system of claim 14, wherein the memory is further configured to store an application transaction counter, and identifying the first session key includes generating, by the processing device, the first session key based on at least the stored application transaction counter.
  7. 19
    21. A system for generating payment credentials in a payment transaction, comprising:a memory configured to store at least a card master key associated with a transaction account;a processing device configured to generate a first session key based on at least the stored card master key, generate a second session key, generate a first application cryptogram based on at least the first session key, and generate a second application cryptogram based on at least the second session key;and a transmitting device configured to transmit at least the first application cryptogram and second application cryptogram for use in a payment transaction.
  8. 21
    23. The system of claim 21, wherein the memory is further configured to store a second card master key associated with the transaction account, and the second session key is based on at least the stored second card master
  9. 24
    26. The system of claim 24, wherein the result of the validation is transmitted to a financial institution associated with the transaction account.