US2015235211A1PendingUtilityA1

System and method for account identifier obfuscation

Assignee: HURRY SIMONPriority: Apr 5, 2006Filed: Apr 30, 2015Published: Aug 20, 2015
Est. expiryApr 5, 2026(expired)· nominal 20-yr term from priority
H04L 9/12H04L 2209/80G06Q 20/40975H04L 2209/04G06Q 20/3823H04L 2209/56G06Q 20/3829H04L 9/3234
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method is disclosed. The method includes generating an obfuscated portion using a dynamic cryptogram unique to a transaction, where the dynamic cryptogram is determined using a uniquely derived key. The method also includes replacing a middle portion of the account identifier with the obfuscated portion to form an obfuscated account identifier.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for obfuscating an account identifier comprising:
 identifying, by a computing device, a first end portion of the account identifier;   identifying, by the computing device, a middle portion of the account identifier, wherein the middle portion of the account identifier excludes the first end portion of the account identifier and further excludes a second end portion of the account identifier;   identifying, by the computing device, the second end portion of the account identifier;   generating, by the computing device for a financial transaction, a dynamic cryptogram;   generating, by the computing device, an obfuscated portion of the account identifier using the generated dynamic cryptogram;   creating, by the computing device, an obfuscated account identifier using at least the first end portion of the account identifier, the second end portion of the account identifier, and the generated obfuscated portion; and   transmitting, by the computing device to another device, the created obfuscated account identifier for the financial transaction.   
     
     
         2 . The method of  claim 1 , wherein the first end portion of the account identifier comprises a bank identification number and wherein the second end portion of the account identifier comprises five characters or fewer. 
     
     
         3 . The method of  claim 1  further comprising:
 changing, using the computing device, a check digit of the obfuscated account identifier from a first value to a second value, wherein the check digit is exclusive of the first end portion, the second end portion, and the obfuscated portion. 
 
     
     
         4 . The method of  claim 3 , wherein the first value is transmitted along with the created obfuscated account identifier for the financial transaction to the another device. 
     
     
         5 . The method of  claim 3 , wherein the second value is selected so that a first checksum result of the obfuscated account identifier including the changed check digit matches a second checksum result of the account identifier. 
     
     
         6 . The method of  claim 1 , wherein the dynamic cryptogram is generated based upon a variable transaction counter value, and wherein the method further comprises changing the variable transaction counter value. 
     
     
         7 . The method of  claim 1 , wherein said generating the obfuscated portion comprises:
 converting the middle portion to hexadecimal digits; and   generating a raw value by performing a bitwise Exclusive-OR (XOR) operation using at least some of the hexadecimal digits and at least some of the dynamic cryptogram.   
     
     
         8 . The method of  claim 7 , further comprising:
 responsive to determining that the raw value exceeds a first constant, transmitting, by the computing device, a flag value along with the created obfuscated account identifier for the financial transaction; and   subtracting, using the computing device, a second constant from the raw value to form the obfuscated portion.   
     
     
         9 . The method of  claim 1 , wherein the computing device is a mobile phone. 
     
     
         10 . The method of  claim 1 , wherein the computing device is an access device of a merchant. 
     
     
         11 . The method of  claim 1 , wherein the created obfuscated account identifier is communicated within an authorization request message for authorizing the financial transaction. 
     
     
         12 . A non-transitory computer readable medium having instructions embodied thereon that when executed by a processor causes the processor to obfuscate an account identifier by performing operations comprising:
 identifying a first end portion of the account identifier;   identifying a middle portion of the account identifier, wherein the middle portion of the account identifier excludes the first end portion of the account identifier and further excludes a second end portion of the account identifier;   identifying the second end portion of the account identifier;   generating, for a financial transaction, a dynamic cryptogram;   generating an obfuscated portion of the account identifier using the generated dynamic cryptogram;   creating an obfuscated account identifier using at least the first end portion of the account identifier, the second end portion of the account identifier, and the generated obfuscated portion; and   transmitting the created obfuscated account identifier to another device for the financial transaction.   
     
     
         13 . A method for determining an account identifier from an obfuscated account identifier comprising:
 receiving, by a computing device for a financial transaction, the obfuscated account identifier;   identifying, by the computing device, a first end portion of the obfuscated account identifier;   identifying, by the computing device, an obfuscated middle portion of the obfuscated account identifier, wherein the obfuscated middle portion of the obfuscated account identifier excludes the first end portion of the obfuscated account identifier and further excludes a second end portion of the obfuscated account identifier;   identifying, by the computing device, the second end portion of the obfuscated account identifier;   generating, by the computing device for the financial transaction, a dynamic cryptogram;   generating, by the computing device, a middle portion of the account identifier using the generated dynamic cryptogram; and   generating, by the computing device, the account identifier by replacing the obfuscated middle portion of the obfuscated account identifier with the generated middle portion.   
     
     
         14 . The method of  claim 13 , wherein said identifying the obfuscated middle portion comprises determining, by the computing device, which digits of a plurality of digits of the obfuscated account identifier comprise the obfuscated portion of the obfuscated account identifier. 
     
     
         15 . The method of  claim 13 , wherein the dynamic cryptogram is generated based upon a variable transaction counter value, and wherein the method further comprises changing, by the computing device, the variable transaction counter value. 
     
     
         16 . The method of  claim 13 , wherein said generating the middle portion of the account identifier comprises:
 converting, by the computing device, the obfuscated middle portion to hexadecimal digits; and   generating, by the computing device, a raw value by performing a bitwise Exclusive-OR (XOR) operation using at least some of the generated dynamic cryptogram and at least some of the converted hexadecimal digits.   
     
     
         17 . The method of  claim 16 , further comprising:
 determining, by the computing device, that a flag value was received along with the obfuscated account identifier; and   responsive to said determining that the flag value was received, adding, by the computing device, a fixed value to the raw value to form the middle portion.   
     
     
         18 . The method of  claim 16 , further comprising:
 determining, by the computing device, that a check digit was received along with the obfuscated account identifier; and   combining, by the computing device, the raw value with the stored check digit.   
     
     
         19 . The method of  claim 13 , further comprising:
 responsive to a determination that the generated account identifier is invalid, generating, by the computing device, a fraud alert.   
     
     
         20 . A non-transitory computer readable medium having instructions embodied thereon that when executed by a processor of a computing device causes the processor to determine an account identifier from an obfuscated account identifier by performing operations comprising:
 receiving the obfuscated account identifier for a financial transaction;   identifying a first end portion of the obfuscated account identifier;   identifying an obfuscated middle portion of the obfuscated account identifier, wherein the obfuscated middle portion of the obfuscated account identifier excludes the first end portion of the obfuscated account identifier and further excludes a second end portion of the obfuscated account identifier;   identifying the second end portion of the obfuscated account identifier;   generating, for the financial transaction, a dynamic cryptogram;   generating a middle portion of the account identifier using the generated dynamic cryptogram; and   generating the account identifier by replacing the obfuscated middle portion of the obfuscated account identifier with the generated middle portion.

Join the waitlist — get patent alerts

Track US2015235211A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.