发明名称 SYSTEM AND METHOD FOR SECURE VERIFICATION OF ELECTRONIC TRANSACTIONS
摘要 <p>There is provided a system and method for secure verification of electronic transactions, and in particular secure processing of personal identification numbers when third party processors are involved. In an embodiment, a variable length PIN associated with a credit card or debit card is encrypted, then hashed using a one-way hash algorithm before it is passed along to and stored by a third party processor. The encrypted-hashed PIN always remains in an encrypted form while in the hands of the third party processor. At the third party processor, secure cryptographic hardware is used to store the one-way hash algorithm. Encrypted PIN values received for verification (e.g. from a retail point-of-sale terminal) are converted and hashed using the one-way hash algorithm, and the resulting hashed-encrypted value is compared against the hashed-encrypted PIN values previously stored at the third party processor. As the PIN has a variable length, and the third party processor has no access to the hash algorithm, the encrypted PIN values are highly resistant to reverse engineering or decryption.</p>
申请公布号 WO2009039600(A1) 申请公布日期 2009.04.02
申请号 WO2007CA01710 申请日期 2007.09.25
申请人 INTERNATIONAL BUSINESS MACHINES COPORATION;IBM CANADA LTD.;NACHTIGALL, ERNIE 发明人 NACHTIGALL, ERNIE
分类号 G06Q20/00;G07F7/10 主分类号 G06Q20/00
代理机构 代理人
主权项
地址