Variant card
Aspects of the disclosure relate to generating digital variant cards to share established credit limits without an issuing organizations intervention or dependencies. The generated variant cards may share a portion of an authorized users credit limit. The variant cards may be tied to sub user devices. Tokenization may be used in digital variant card generation. Variant cards may include use of a dynamic card verification values to authenticate variant card transactions.
1 . A computer-implemented method for generating and managing digital variant cards for sub-users, the method comprising:
receiving, by a processor of a distributed card computing platform (DCCP), a request from an authorized user through a mobile application to generate one or more digital variant cards for one or more sub-users;
determining, by the processor of the DCCP, contract conditions defined by secure application programming interface (API) contracts for each digital variant card, the contract conditions comprising:
a portion of a credit limit of the authorized user to be shared with a respective sub- user,
a specific device of the respective sub-user identified by a device identifier, one or more merchant identifiers specifying one or more merchants where a respective digital variant card can be used,
a maximum transaction amount for each transaction,
a total number of transactions allowed for the respective digital variant card,
a validity period defined by a start date and an end date,
a geographic restriction specifying that the respective digital variant card can only be used for domestic transactions or within a specific geographic area, and
specific days of week during which the respective digital variant card is valid;
embedding, by the processor of the DCCP, the contract conditions as executable contract parameters directly into a token request;
transmitting, by the processor of the DCCP via an API service layer of the DCCP, the token request to a payment card network service provider (PCNSP) system;
receiving, by the processor of the DCCP, a token identifier (ID) from the PCNSP system, the token ID incorporating the embedded executable contract parameters;
generating, by the processor of the DCCP, a digital variant card for each sub-user associated with a respective token ID and linked to an original payment card of the authorized user such that the digital variant card shares the determined portion of the credit limit;
provisioning, by the processor of the DCCP, each digital variant card on its respective associated sub-user device via a secure communication channel by binding the each digital variant card to its designated device identifier using token-based binding and tokenization;
performing, by a processor of the PCNSP system in communication with the DCCP, real- time network-level enforcement of the embedded executable contract parameters by:
generating a per-transaction dynamic card verification value (CVV) via a dynamic CVV generation API,
routing a digital variant card information including the per-transaction dynamic CVV from the specific sub-user device through a retailer purchase processing apparatus, a payment processor, and an acquirer financial institution,
evaluating, using a rules-based engine, transaction details directly against the contract conditions embedded in the token ID to verify compliance with the contract conditions,
determining an original primary account number of the original payment card from the token ID,
transmitting the original primary account number to an original payment card issuer for verification,
receiving the verification from the original payment card issuer, and
forwarding an authorization message to the acquirer financial institution based on the verification for routing the authorization message to the payment processor and the retailer purchase processing apparatus;
monitoring, by the processor of the DCCP through the API service layer, transactions performed with the each digital variant card and delivering real-time alerts of the transactions to the authorized user via the mobile application;
enabling, by the processor of the DCCP, the authorized user to block or remove any of the digital variant cards in real time through the mobile application;
synchronizing, by the processor of the DCCP, credit usage across the digital variant cards in real time via API aggregation of token data to ensure the credit usage does not exceed the credit limit of the original payment card; and
consolidating, by the processor of the DCCP, bill payments for all transactions made with the digital variant cards and the original payment card into a single billing statement by:
receiving transaction information and statement information forwarded from the original payment card issuer through the mobile application,
displaying monthly bills via the mobile application, and
enabling bill payment to the original payment card issuer from the mobile application; and
performing the generating, provisioning, monitoring, synchronizing, and consolidating steps in real-time without intervention from the issuing financial institution of the original payment card while the DCCP communicates with user devices and the via one or more networks selected from: wired networks, wireless networks, and cellular networks.
2 . A distributed payment card processing system for generating and managing digital variant cards for sub-users using secure tokenization and runtime technical authentication comprising:
a distributed card computing platform (DCCP), a payment card network service provider (PCNSP) system, one or more sub-user devices, point-of-sale terminals, and automated teller machines in communication via one or more networks selected from: wired networks, wireless networks, and cellular networks, the system further comprising:
the DCCP hosted in a data center comprising:
a presentation layer that interacts with users, systems, and system administrators,
an application programming interface (API) layer including an API gateway, an API engine, and services that communicate with external token provider APIs and dynamic card verification value (CVV) APIs as well as institutional internal systems and APIs,
a business layer for conducting payment transactions, and a data layer for handling and storing various data formats and content,
at least one processor, and
a non-transitory memory storing computer-executable instructions that, when executed by the at least one processor, configure the DCCP to:
receive a request from an authorized user through a mobile application to generate one or more digital variant cards for one or more sub-users;
determine contract conditions defined by secure API contracts for each digital variant card, the contract conditions comprising:
a portion of a credit limit of the authorized user to be shared with a respective sub-user,
a specific device of the respective sub-user identified by a device identifier,
one or more merchant identifiers specifying one or more merchants where a respective digital variant card can be used,
a maximum transaction amount for each transaction,
a total number of transactions allowed for the respective digital variant card,
a validity period defined by a start date and an end date,
a geographic restriction specifying that the respective digital variant card can only be used for domestic transactions or within a specific geographic area, and
specific days of week during which the respective digital variant card is valid;
embed the contract conditions as executable contract parameters directly into a token request;
transmit, via an API service layer, the token request to the PCNSP system;
receive a token identifier (ID) from the PCNSP system, the token ID incorporating the embedded executable contract parameters;
generate a digital variant card for each sub-user associated with a respective token ID and linked to an original payment card of the authorized user such that the digital variant card shares the determined portion of the credit limit;
provision each digital variant card on its respective associated sub-user device via a secure communication channel by binding the each digital variant card to its designated device identifier using token-based binding and tokenization;
monitor, through the API service layer, transactions performed with the each digital variant card and deliver real-time alerts of the transactions to the authorized user via the mobile application;
enable the authorized user to block or remove any of the digital variant cards in real time through the mobile application;
synchronize credit usage across the digital variant cards in real time via API aggregation of token data to ensure the credit usage does not exceed the credit limit of the original payment card; and
consolidate bill payments for all transactions made with the digital variant cards and the original payment card into a single billing statement by:
receiving transaction information and statement information forwarded from the original payment card issuer through the mobile application,
displaying monthly bills via the mobile application, and
enabling bill payment to the original payment card issuer from the mobile application;
the PCNSP system comprising:
at least one processor, and
a memory storing executable instructions that, when executed by the at least one processor, configure the PCNSP system to:
generate token IDs that incorporate the embedded executable contract parameters;
generate a per-transaction dynamic CVV via a dynamic CVV generation API;
route a digital variant card information including the per-transmission dynamic CVV from the specific sub-user device through a retailer purchase processing apparatus, a payment processor, and an acquirer financial institution;
evaluate, using a rules-based engine, transaction details directly against the contract conditions embedded in the token ID to verify compliance with the contract conditions;
determine an original primary account number of the original payment card from the token ID;
transmit the original primary account number to an original payment card issuer for verification;
receive the verification from the original payment card issuer; and
forward an authorization message to the acquirer financial institution based on the verification for routing the authorization message to the payment processor and the retailer purchase processing apparatus;
the one or more sub-user devices configured to store and use provisioned digital variant cards bound to specific device identifiers using token-based device binding; and
the point-of-sale terminals and the automated teller machines configured to:
process transactions using digital variant cards,
verify dynamic CVVs provided by the PCNSP system, and
transmit transaction requests for authorization.