Visa Inc.
Methods for secure credential provisioning

Last updated:

Abstract:

Embodiments can provide methods for securely provisioning sensitive credential data, such as a limited use key (LUK) onto a user device. In some embodiments, the credential data can be encrypted using a separate storage protection key and decrypted only at the time of a transaction to generate a cryptogram for the transaction. Thus, end-to-end protection can be provided during the transit and storage of the credential data, limiting the exposure of the credential data only when the credential data is required, thereby reducing the risk of compromise of the credential data.

Status:
Grant
Type:

Utility

Filling date:

10 Sep 2019

Issue date:

14 Dec 2021