(19)
(11) EP 0 138 320 A3

(12) EUROPEAN PATENT APPLICATION

(88) Date of publication A3:
19.02.1986 Bulletin 1986/08

(43) Date of publication A2:
24.04.1985 Bulletin 1985/17

(21) Application number: 84305480

(22) Date of filing: 10.08.1984
(84) Designated Contracting States:
DE FR GB SE

(30) Priority: 02.09.1983 US 529161

(71) Applicant: VISA U.S.A. Inc.
 ()

(72) Inventor:
  • Campbell, Carl Merritt
     ()

   


(54) Cryptographic key management system


(57) A central host computer (20) is connected to a plurality of transaction card issuing institutions (e.g. banks) 24 and to a plurality of transaction terminals (22). The host (20) generates a master key which is distributed to all terminals (22), and generates a plurality of secondary keys, one for each issuer (24), each secondary key being generated by encryption of data identifying the respective issuer (24). The issuer (24) places the data identifying itself (BIN) on each card it issues. Also authorization information is encrypted under the respective secondary key and placed on the card. The authorization information can include anticounterfeiting digits or a personal identification number (PIN). When the card is applied to a transaction terminal (22), the encrypted information is read by the terminal, and also the respective secondary key is derived by the terminal (22) by encryption of the issuer identifying data (BIN) under the master key. The secondary key', thus derived is used by the terminal (22) to permit off-line analysis of the encrypted authorization information on the card by comparison with data entered manually at the terminal (22) by the card owner, and/ or with non-encrypted data on the card.







Search report