Integration of verification tokens with mobile communication devices
A method is disclosed. The method includes receiving, by a computer from a portable device via an NFC interaction, a cryptogram, the cryptogram based at least upon a primary account number. The method includes generating, by the computer, a request for dynamic account information, the request comprising the cryptogram, and transmitting, by the computer to a validation entity computer over a communications network comprising the Internet or a cellular phone network. The request comprises the cryptogram. The validation entity computer validates the cryptogram. The method also includes responsive to the validation entity computer validating the cryptogram, receiving, by the computer from the validation entity computer, the dynamic account information over the communications network.
1 . A method comprising:
receiving, by a validation entity computer from a computer over a communications network comprising the Internet or a cellular phone network, a request for dynamic account information, the request comprising a cryptogram, the cryptogram based at least upon a primary account number, the receiving of the request for the dynamic account information occurring after and in response to a portable device interacting with the computer via near field communications to provide the cryptogram to the computer, the portable device being in the form of a card;
validating, by the validation entity computer, the cryptogram; and
in response to validating the cryptogram, providing, by the validation entity computer, the dynamic account information over the communications network, the dynamic account information comprising a dynamic account number.
2 . The method of claim 1 , wherein the cryptogram is formed using a counter value.
3 . The method of claim 1 , wherein the cryptogram is formed using a dynamic value.
4 . The method of claim 1 , wherein the cryptogram is formed using transaction information.
5 . The method of claim 1 , wherein the computer is a mobile phone or a laptop computer.
6 . The method of claim 1 , wherein the dynamic account information is subsequently used to conduct a transaction.
7 . The method of claim 1 , further comprising:
performing a series of validation checks before transmitting the dynamic account information over the communications network.
8 . The method of claim 1 , wherein the dynamic account information is transmitted to the computer.
9 . The method of claim 1 , wherein the card is a credit card, or a debit card.
10 . The method of claim 1 , wherein the cryptogram is received by the validation entity computer from the computer in a message, the message encrypted with a first cryptographic key on the computer, and decrypted with a second cryptographic key on the validation entity computer.
11 . A validation entity computer comprising:
a processor; and
a computer readable medium coupled to the processor, the computer readable medium comprising code, executable by the processor, for performing operations comprising:
receiving, from a computer over a communications network comprising the Internet or a cellular phone network, a request for dynamic account information, the request comprising a cryptogram, the cryptogram based at least upon a primary account number, the receiving of the request for the dynamic account information occurring after and in response to a portable device interacting with the computer via near field communications to provide the cryptogram to the computer, the portable device being in the form of a card;
validating the cryptogram; and
in response to validating the cryptogram, providing the dynamic account information over the communications network, the dynamic account information comprising a dynamic account number.
12 . The validation entity computer of claim 11 , wherein the cryptogram is formed using a dynamic value.
13 . The validation entity computer of claim 12 , wherein the dynamic value is a counter value.
14 . A method comprising:
receiving, by a computer from a portable device via an NFC interaction, a cryptogram, the cryptogram based at least upon a primary account number;
responsive to receiving the cryptogram, generating, by the computer, a request for dynamic account information, the request comprising the cryptogram;
transmitting, by the computer to a validation entity computer over a communications network comprising the Internet or a cellular phone network, the request comprising the cryptogram, wherein the validation entity computer validates the cryptogram; and
responsive to the validation entity computer validating the cryptogram, receiving, by the computer from the validation entity computer, the dynamic account information over the communications network, the dynamic account information comprising a dynamic account number.
15 . The method of claim 14 , wherein the cryptogram is formed using a dynamic value.
16 . The method of claim 14 , wherein the computer is a laptop computer.
17 . The method of claim 14 , wherein the computer is a smart phone.
18 . The method of claim 14 , wherein the portable device is in the form of a card.
19 . The method of claim 14 , wherein the communications network comprises the Internet.
20 . The method of claim 16 , wherein the computer comprises an NFC reader.