Contacts for misdirected payments and user authentication
In one embodiment, a method includes receiving, by a payment service system (PSS), a payment request from a payment application executing on a device of a sender. The payment request includes a recipient identifier corresponding to a recipient. The sender and recipient have financial accounts associated with the PSS. The method includes determining a similarity score based on a comparison of contact records associated with the device of the sender and contact records associated with a device of the recipient. The method includes, responsive to determining that the similarity score does not satisfy a threshold similarity score, transmitting a confirmation request to the device of the sender to confirm an identity of the recipient. The method includes receiving, from the device of the sender, an approval response to the confirmation request. The method includes, authorizing a payment transaction associated with the payment request based on the approval response.
1 . A computer-implemented method comprising:
receiving first hash values for encrypted contact records stored in association with an account of a sender associated with a payment service system (PSS);
receiving, by the PSS and from a payment application executing on a device of the sender, a payment request including a recipient identifier for a recipient, wherein the recipient has an account associated with the PSS;
performing a first authentication process by generating a similarity score based on the first hash values for the encrypted contact records stored in association with the account of the sender and one or more second hash values for encrypted contact records stored in association with the recipient identifier to determine that the similarity score fails to meet a threshold value;
responsive to determining that the similarity score fails to meet the threshold value, initiating, by the PSS, a second authentication process, wherein the second authentication process is different than the first authentication process and the second authentication process includes sending a confirmation request to the device of the sender to confirm the recipient, wherein the confirmation request prompts the sender to input details of the recipient; and
authorizing, by the PSS, a payment transaction associated with the payment request based at least in part upon receiving a positive confirmation of the recipient from the device of the sender.
2 . The computer-implemented method of claim 1 , wherein the details of the recipient include at least a portion of a phone number associated with the recipient.
3 . The computer-implemented method of claim 2 , wherein the at least a portion of the phone number is provided by the sender in response to the confirmation request.
4 . The computer-implemented method of claim 1 , wherein the details of the recipient include one of: a name of the recipient, a picture of the recipient, or bank account details of the recipient.
5 . The computer-implemented method of claim 1 , wherein:
the similarity score is an initial similarity score that compares the first hash values for the encrypted contact records stored in association with the account of the sender with the one or more second hash values for the encrypted contact records associated with the recipient identifier; and
performing the first authentication process further includes generating a supplemental similarity score based on a comparison of the one or more second hash values for the encrypted contact records associated with the recipient identifier with one or more third hash values for a contacts list of one or more of the encrypted contact records associated with the recipient identifier.
6 . The computer-implemented method of claim 1 , wherein the similarity score is based on:
a number of matches between the encrypted contact records stored in association with the account of the sender and the encrypted contact records associated with the recipient identifier, or
a summation of weighted values of a number of most frequently employed contacts from the encrypted contact records stored in association with the account of the sender and the encrypted contact records associated with the recipient identifier.
7 . The computer-implemented method of claim 1 , wherein the encrypted contact records of the sender are stored on the device of the sender.
8 . The computer-implemented method of claim 1 , wherein the encrypted contact records of the sender are stored at the PSS.
9 . The computer-implemented method of claim 1 , further comprising:
receiving, at the PSS and from the device of the sender, a notification of the first authentication process being performed on the device of the sender, wherein the initiating the second authentication process is in response to receiving the notification.
10 . The computer-implemented method of claim 1 , wherein the first authentication process is performed by the PSS.
11 . The computer-implemented method of claim 1 , wherein the confirmation request is a message sent to the device of the sender.
12 . The computer-implemented method of claim 11 , wherein the positive confirmation of the recipient is in response to the message.
13 . One or more non-transitory computer-readable media comprising computer-readable instructions, which when executed by one or more processors of a payment service system (PSS), cause the one or more processors of the PSS to:
receive first hash values for encrypted contact records stored in association with an account of a sender associated with the PSS;
receive, from a payment application executing on a device of the sender, a payment request including a recipient identifier for a recipient, wherein the recipient has an account associated with the PSS;
perform a first authentication process by generating a similarity score based on the first hash values for the encrypted contact records stored in association with the account of the sender and one or more second hash values for encrypted contact records stored in association with the recipient identifier to determine that the similarity score fails to meet a threshold value;
responsive to determining that the similarity score fails to meet the threshold value, initiate a second authentication process, wherein the second authentication process is different than the first authentication process and the second authentication process includes sending a confirmation request to the device of the sender to confirm the recipient, wherein the confirmation request prompts the sender to input details of the recipient; and
authorize a payment transaction associated with the payment request based at least in part upon receiving a positive confirmation of the recipient from the device of the sender.
14 . The one or more non-transitory computer-readable media of claim 13 , wherein the details of the recipient include at least a portion of a phone number associated with the recipient.
15 . The one or more non-transitory computer-readable media of claim 14 , wherein the at least a portion of the phone number is provided by the sender in response to the confirmation request.
16 . The one or more non-transitory computer-readable media of claim 13 , wherein the details of the recipient include one of: a name of the recipient, a picture of the recipient, or bank account details of the recipient.
17 . A system comprising:
one or more processors; and
one or more memories, coupled to the one or more processors and having computer-readable instructions stored thereon, which when executed by one or more processors of the system, cause the system to:
receive first hash values for encrypted contact records stored in association with an account of a sender associated with a payment service system (PSS);
receive, from a payment application executing on a device of a sender, a payment request including a recipient identifier for a recipient, wherein the recipient has an account associated with the PSS;
perform a first authentication process by generating a similarity score based on the first hash values for the encrypted contact records stored in association with the account of the sender and one or more second hash values for encrypted contact records stored in association with the recipient identifier to determine that the similarity score fails to meet a threshold value;
responsive to determining that the similarity score fails to meet the threshold value, initiate a second authentication process, wherein the second authentication process is different than the first authentication process and the second authentication process includes sending a confirmation request to the device of the sender to confirm the recipient, wherein the confirmation request prompts the sender to input details of the recipient; and
authorize a payment transaction associated with the payment request based at least in part upon receiving a positive confirmation of the recipient from the device of the sender.
18 . The system of claim 17 , wherein the details of the recipient include at least a portion of a phone number associated with the recipient.
19 . The system of claim 18 , wherein the at least a portion of the phone number is provided by the sender in response to the confirmation request.
20 . The system of claim 17 , wherein the details of the recipient include one of: a name of the recipient, a picture of the recipient, or bank account details of the recipient.