| CPC G06Q 20/3829 (2013.01) [G06Q 20/322 (2013.01); G06Q 20/3278 (2013.01); G07F 7/127 (2013.01); H04L 9/083 (2013.01); H04L 9/3263 (2013.01); H04L 2209/56 (2013.01)] | 20 Claims |

|
1. A user device for conducting a payment transaction with a point-of-sale terminal, the user device comprising a payment application, and wherein the payment application received a session key from a remote entity, the session key being different from a Master Key, and the session key generated using the Master Key, whereby the user device comprises code executable by a processor in the user device, to perform an authorization process, the authorization process comprising the steps of:
receiving a request for an application cryptogram;
generating the application cryptogram using the received session key; and transmitting the generated application cryptogram to the point-of-sale terminal, wherein the application cryptogram is subsequently verified and the payment transaction is authorized.
|