WO2010141501A2

Purchase transaction system with encrypted payment card data

Abstract

Systems and methods are provided for securing payment card information. A user may present a payment card such as a credit card to point-of-sale equipment. The point-of-sale equipment may encrypt the payment card information. An encryption algorithm may be used that takes as inputs a first part of the payment card information, a tweak formed by a second part of the payment card information, and an encryption key. The encrypted payment card information may be conveyed to a gateway over a communications network. The gateway may identify which encryption algorithm was used in encrypting the payment card information and may re-encrypt the payment card information using a format preserving encryption algorithm. A network-based service may be used to remotely perform functions for the gateway.

WO2010141501A2, drawing sheet 1
Sheet 1 of 5

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

20 claims: 20 independent, 0 dependent

  1. 1
    What is Claimed is:1. A computer-implemented method for securing payment card data in a system having at least one point of sale terminal and at least one payment card transaction processing gateway, the method comprising: with the point of sale terminal, obtaining payment card data associated with a payment card of a user during a purchase transaction;and with the point of sale terminal, encrypting the payment card data using an encryption algorithm that takes as inputs a first part of the payment card data, a tweak formed from a second part of the payment card data, and a terminal key.
  2. 2
    The computer-implemented method defined in claim 1, further comprising:at a key server, deriving an intermediate key from a master key;at the key server, deriving the terminal key from the intermediate key;and providing the terminal key from the key server to the point of sale terminal.
  3. 3
    The computer-implemented method defined in claim 1, further comprising:at a key server, deriving an intermediate key from a master key;and providing the intermediate key from the key server to the payment card transaction processing gateway;and at the payment card transaction processing gateway, deriving the terminal key from the intermediate key.
  4. 4
    The computer-implemented method defined in claim 1, further comprising:at the point of sale terminal, generating the terminal key, wherein the terminal key comprises a random terminal key;and providing the terminal key from the point of sale terminal to the payment card transaction processing gateway.
  5. 5
    The computer-implemented method defined in claim 5, further comprising:sending the encrypted payment card data and the tweak from the point of sale terminal to the payment card transaction processing gateway;and with the payment card transaction processing gateway, decrypting the encrypted payment card data using the tweak and the terminal key.
  6. 6
    The computer-implemented method defined in claim 5, further comprising:with the payment card transaction processing gateway, encrypting the payment card data that has been decrypted.
  7. 7
    The computer-implemented method defined in claim 1, wherein the at least one point of sale terminal comprises a plurality of point of sale terminals, the method further comprising:at the payment card transaction processing gateway, receiving encrypted payment card data from the plurality of point of sale terminals.
  8. 8
    The computer-implemented method defined in claim 1, wherein the payment card data comprises a 16- digit primary account number, wherein the first part of the payment card data is the last 10 digits of the 16- digit primary account number, the method further comprising :at the point of sale terminal, forming the tweak from the second part of the payment card data.
  9. 9
    The computer-implemented method defined in claim 1, wherein the second part of the payment card data is the first 6 digits of the 16-digit primary account number, the method further comprising:at the point of sale terminal, forming the tweak from the second part of the payment card data.
  10. 10
    The computer-implemented method defined in claim 1, wherein encrypting the payment card data comprises encrypting the payment card data using a format preserving encryption algorithm.
  11. 11
    The computer-implemented method defined in claim 1, wherein the terminal key comprises a symmetric key, the method further comprising:providing the encrypted payment card data and the tweak from the point of sale terminal to the payment card transaction processing gateway.
  12. 12
    The computer-implemented method defined in claim 11, wherein the system has a network service having a decryption engine, the method further comprising:at the network service, receiving the encrypted payment card data from the payment card transaction processing gateway;and with the decryption engine in the network service, decrypting the encrypted payment card data.
  13. 13
    A computer-implemented method for securing payment card data in a system having a plurality of point of sale terminals and at least one payment card transaction processing gateway, the method comprising:with the plurality of point of sale terminals, obtaining the payment card data during purchase transactions;with the plurality of point of sale terminals, encrypting the payment card data using a plurality of respective encryption algorithms, each of which produces respective encrypted data using a different encryption algorithm format;with the payment card transaction processing gateway, receiving the encrypted payment card data from the plurality of point of sale terminals;and with the payment card transaction processing gateway, identifying each of the different encryption algorithm formats used in encrypting the payment card data;and with the payment card transaction processing gateway, decrypting the payment data using a plurality of decryption algorithms that respectively correspond to the different encryption algorithm formats.
  14. 14
    The computer-implemented method defined in claim 13, further comprising:with the payment card transaction processing gateway, encrypting the payment card data that has been decrypted using the plurality of decryption algorithms using a single encryption algorithm.
  15. 15
    The computer-implemented method defined in claim 14, wherein encrypting the payment card data that has been decrypted comprises:with the payment card transaction processing gateway, encrypting a first portion of a payment card number while leaving a second portion of the payment card number unencrypted;and with the payment card transaction processing gateway, storing the encrypted first portion and the second portion in a database.
  16. 16
    The computer-implemented method defined in claim 13, wherein each encryption algorithm format has a different encryption algorithm identifier, the method further comprising:with the payment card transaction processing gateway, receiving the different encryption algorithm identifiers from the plurality of point of sale terminals .
  17. 17
    A computer-implemented method for securing payment card data in a system having at least one point of sale terminal, at least one payment card transaction processing gateway, and a network service having a decryption engine, the method comprising:with the point of sale terminal, obtaining the payment card data associated with a payment card of a user during a purchase transaction;with the point of sale terminal, encrypting the payment card data using a format preserving encryption algorithm;at the payment card transaction processing gateway, receiving the encrypted payment card data from the point of sale terminal;at the network service, receiving the encrypted payment card data from the payment card transaction processing gateway, and with the decryption engine at the network service, decrypting the encrypted payment card data.
  18. 18
    The computer-implemented method defined in claim 17, further comprising:at the network service, sending the decrypted payment card data to the payment card transaction processing gateway through a secure link in a communications network.
  19. 19
    The computer-implemented method defined in claim 17, wherein the network service comprises a key management service, the method further comprising:with the key management service at the network service, receiving a terminal key from a key server, wherein decrypting the encrypted payment data comprises decrypting the encrypted payment data using the terminal key.
  20. 20
    The computer-implemented method defined in claim 17, wherein the at least one point of sale terminal comprises a plurality of point of sale terminals each having a different respective encryption algorithm, wherein the method further comprising:at the network service, identifying which of the different encryption algorithms was used to encrypt the encrypted payment card data;and decrypting the encrypted payment card data using a decryption algorithm associated with that encryption algorithm.
Independent claims20