Capital One OTP Card Master Key Distribution Enables Independent Cryptogram Generation
Summary
USPTO granted Capital One Services, LLC Patent US12592828B2 for a system enabling independent cryptogram generation during OTP card manufacturing and verification. The invention allows personalization HSMs and validation HSMs to independently derive shared secrets without network communication, decoupling the card personalization and validation workflows. The patent lists 20 claims covering the cryptographic key distribution method.
What changed
USPTO issued Patent US12592828B2 to Capital One Services, LLC on March 31, 2026, covering a system and method for parallel manufacture and verification of one-time-password authentication cards. The patent describes a novel encryption approach using a third master key that enables manufacturing HSMs and validation HSMs to independently derive shared secret values for cryptogram generation and validation without requiring network communication between the two entities. The patent (20 claims, CPC: H04L 9/14, H04L 9/3242) names inventors Kevin Osborn and Srinivasa Chigurupati.
This patent grant does not create compliance obligations for other entities. However, organizations developing OTP authentication systems or hardware security module integrations should review the patent claims to assess potential licensing implications or to ensure their implementations do not infringe on the protected methods. No immediate action is required unless the organization has products using similar cryptographic key distribution techniques for payment or authentication cards.
Source document (simplified)
System and method for parallel manufacture and verification of one-time-password authentication cards
Grant US12592828B2 Kind: B2 Mar 31, 2026
Assignee
Capital One Services, LLC
Inventors
Kevin Osborn, Srinivasa Chigurupati
Abstract
The disclosed system and method are directed to a novel implementation of encryption service provision which obviates a need for network communication between a card manufacturing/personalization entity and a validation entity during the card personalization phase. The proposed solution decouples the operation flow associated with personalization of an OTP card (as carried out by a manufacturing HSM) and the validation of an OTP card cryptogram (as carried out by a distinct validation HSM). This is accomplished by the generation and distribution of a third master key which enables the personalization and the validation HSMs to independently derive the shared secret value used in generation and validation of a transaction cryptogram associated with an OTP card operation.
CPC Classifications
H04L 9/14 H04L 9/3242 H04L 9/085 H04L 9/3234 H04L 9/3228
Filing Date
2023-01-06
Application No.
18094238
Claims
20
Named provisions
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Telecom & Technology alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when ChangeBridge: Patent Grants - Networking (H04L) publishes new changes.