Device and systems for provisioning and verifying tokens with strong identity and strong authentication
Tokens are used for payment systems. The tokens are references or proxies to actual payment credit card or banking card numbers to improve security. However, verification of these tokens are often limited and rigid systems and are prone fraud. An improved token framework system is provided to allow for different entities to provision and verify the tokens using strong identity and strong authentication at the device level. For example, biometric identity and verification using the mobile device is used to authenticate the tokens during provisioning and subsequent transactions.
1 . A system comprising:
a user device, a website server, a token service provider, and a (Fast Identity Online (FIDO) service server,
the token service provider server storing thereon a look-up table comprising Uniform Resource Locators (URLs) and tokens;
the website server configured to provide a webpage for display on the user device for a transaction, the webpage comprising a checkout plugin that is configured to receive payment information;
the checkout plugin configured to transmit a find authentication service instruction including a given token to the token service provider, the given token bound to the user device and is a proxy to a Primary Account Number (PAN);
responsive to receiving the find authentication service instruction, the token service provider configured to search the look-up table using the given token to obtain a given authentication URL that corresponds to the given token, and to transmit the given authentication URL to the checkout plugin;
responsive to receiving the given authentication URL, the checkout plugin transmitting the given token to the FIDO service provider that is addressed at the given authentication URL;
the FIDO service provider transmitting a FIDO challenge to the user device, via the checkout plugin;
the user device initiating a FIDO authentication using the FIDO challenge by digitally signing the FIDO challenge using a FIDO private key for generating a FIDO challenge response, and providing the FIDO challenge response to the FIDO service provider;
the FIDO service provider authenticating the FIDO challenge response by using a FIDO public key that corresponding to the FIDO private key;
responsive to the FIDO service provider authenticating the FIDO challenge response, the FIDO service provider obtains a token authentication verification value (TAVV) and transmits the TAVV to the website server; and
the website server is configured to transmit the TAVV, the token and transaction data for the transaction into an electronic payment network to complete the transaction.
2 . The system of claim 1 , wherein, during a registration process, the FIDO service provider is configured to send the given authentication URL to connect with the user device, and after successfully receiving from the user device a FIDO registration response, the FIDO registration response including a FIDO public key, the FIDO service provider binds a FIDO public key with the token.
3 . The system of claim 2 , wherein, during the registration process, the token or a token reference, or both, are stored in association with the given authentication URL.
4 . The system of claim 1 , wherein the checkout plugin comprises an iframe within the webpage.
5 . The system of claim 1 , wherein the FIDO authentication comprises the user device executing a biometric scan.