IP Library Granted Patent US 12694433
Granted Patent B2
US 12694433 · App. 17/827,891 · Granted Jul 28, 2026

Systems and methods for facilitating card verification over a network

Inventors: Nitesh Singhal (Sunnyvale, CA); Parijat Sinha (San Jose, CA); Nitin Agarwal (Adyar, IN); Muthukumar Murugesan (Thiruvottriyur, IN)
Assignee: PayPal, Inc.
G06Q30/0609G06F21/34G06Q20/12G06Q20/40G06Q20/409G06Q30/06G06Q30/0635G06Q40/12H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12694433
App. No.
17/827,891
Granted
Jul 28, 2026
Kind
B2
Abstract

A system and method for facilitating electronic commerce over a network, according to one or more embodiments, includes communicating with a user via a user device and an issuer of payment media via an issuer device over the network, the payment media being issued to the user by the issuer, receiving user instruction over the network to link the payment media to a user account related to the user, prompting the user over the network to input a secure password known only by the issuer and the user, receiving the secure password from the user over the network, verifying that the payment media is owned by the user over the network via a secure protocol, returning a response to the user related to verification of the payment media, and storing payment media verification information.

Claims (47)

1 . A method, comprising:

maintaining, by a service provider computer system, a particular user account for a user;

determining, by the service provider computer system, to link a transaction instrument to the particular user account of the user so that the transaction instrument is usable by the user in transactions between the user and merchants;

before completing a first transaction between the user and a first merchant using the transaction instrument and in response to the determining to link the transaction instrument to the particular user account, the service provider computer system verifying whether the user is authorized to use the transaction instrument in transactions, wherein the verifying the authorization of the user is based on;

i) a verification of enrollment, via an authentication system, of the transaction instrument with an authentication protocol for providing authentication credentials associated with the transaction instrument, and

ii) a validation of authentication credentials of the user via an issuer system, wherein the authentication system is operated by a different entity than the issuer system, and wherein the validation of authentication credentials includes the service provider computer system issuing a request to the authentication system to indicate whether the user has provided valid authentication credentials to the issuer system;

in response to verifying that the user is authorized to use the transaction instrument, the service provider computer system linking the transaction instrument with the particular user account;

after the linking, the service provider computer system completing the first transaction using the linked transaction instrument; and

completing, by the service provider computer system, a second, subsequent transaction between the user and a second merchant using the linked transaction instrument.

2 . The method of claim 1 , wherein the verification of enrollment comprises the service provider computer system communicating with the authentication system to obtain a confirmation of enrollment and issuer information about the issuer system.

3 . The method of claim 2 , wherein the issuer information includes a uniform resource locator (URL) for the issuer system, and wherein the validation of authentication credentials comprises the service provider computer system redirecting, using the URL, a user device of the user to the issuer system to validate the authentication credentials of the user.

4 . The method of claim 1 , wherein the verification of enrollment comprises the service provider computer system obtaining an issuer identifier from the issuer system as part of the verification of enrollment.

5 . The method of claim 1 , wherein the verification of enrollment comprises the service provider computer system providing, to the authentication system, a username of the user and an indication of the transaction instrument.

6 . The method of claim 1 , further comprising:

in response to the linking of the transaction instrument with the particular user account, the service provider computer system sending a message to the user via a user device to notify the user that the transaction instrument is linked to the particular user account.

7 . The method of claim 1 , further comprising:

performing, by the service provider computer system, a risk assessment regarding the user and the transaction instrument, wherein the verifying whether the user is authorized to use the transaction instrument is performed further in response to the risk assessment.

8 . The method of claim 1 , further comprising:

performing, by the service provider computer system, a login process to log in the user to access the particular user account; and

after performing the login process, the service provider computer system receiving a link request from the user to link the transaction instrument to the particular user account, wherein the determining to link the transaction instrument is based on the link request.

9 . A service provider server, the server comprising:

a non-transitory memory storing instructions; and

a processor configured to execute the instructions to cause the server to:

initiate, as part of processing a first transaction between a user and a first merchant, an addition of a transaction instrument to a particular user account of the user so that the transaction instrument is usable by the user in transactions between the user and merchants;

before completing the first transaction using the transaction instrument and in response to the initiation to add the transaction instrument to the particular user account, verify that the user is authorized to use the transaction instrument in transactions, wherein the verifying the authorization of the user comprises communicating with an authentication system to:

i) verify enrollment of the transaction instrument via an authentication protocol for providing authentication credentials associated with the transaction instrument, and

ii) validate provision of authentication credentials of the user via an issuer system, the authentication system being separate from the issuer system; and

in response to verifying that the user is authorized to use the transaction instrument, add the transaction instrument to the particular user account;

after adding the transaction instrument to the particular user account, complete the first transaction using the added transaction instrument; and

complete a second, subsequent transaction between the user and a second merchant using the added transaction instrument.

10 . The server of claim 9 , wherein the verification of enrollment comprises communicating with the authentication system to obtain a confirmation of enrollment and issuer information about the issuer system.

11 . The server of claim 10 , wherein the issuer information includes a uniform resource locator (URL) for the issuer system.

12 . The server of claim 9 , wherein execution of the instructions further causes the server to communicate, as part of the validation of the authentication credentials, with the authentication system to verify that the user has provided valid authentication credentials to the issuer system.

13 . The server of claim 9 , wherein execution of the instructions further causes the server to provide, as part of the verification of enrollment, a username of the user and an indication of the transaction instrument to the authentication system.

14 . A non-transitory computer readable medium having program instructions stored thereon that are executable by a service provider computer system to perform operations comprising:

determining to add a transaction instrument to a particular user account of a user as part of processing a first transaction associated with the particular user account and a first merchant;

before completing the first transaction using the transaction instrument, initiating an addition of the transaction instrument to the particular user account of the user so that the transaction instrument is usable by the user in transactions involving the particular user account and merchants;

in response to the initiation to add the transaction instrument to the particular user account, verifying that the user is authorized to use the transaction instrument, wherein the verifying the authorization of the user comprises communicating with an authentication system to;

i) verify enrollment of the transaction instrument via an authentication protocol for providing authentication credentials associated with the transaction instrument, and

ii) validate provision of authentication credentials of the user via an issuer system, the authentication system being separate from the issuer system; and

in response to verifying that the user is authorized to use the transaction instrument, adding the transaction instrument to the particular user account;

after the adding, completing the first transaction using the added transaction instrument; and

completing a second, subsequent transaction associated with the particular user account and a second merchant using the added transaction instrument.

15 . The non-transitory computer readable medium of claim 14 , wherein the verification of enrollment comprises communicating with the authentication system to obtain a confirmation of enrollment and issuer information about the issuer system.

16 . The non-transitory computer readable medium of claim 15 , wherein the issuer information includes a uniform resource locator (URL) for the issuer system.

17 . The non-transitory computer readable medium of claim 14 , wherein the operations further comprise communicating, as part of the validation of the authentication credentials, with the authentication system to verify that the user has provided valid authentication credentials to the issuer system.

18 . The non-transitory computer readable medium of claim 14 , wherein the operations further comprise providing, as part of the verification of enrollment, a username of the user and an indication of the transaction instrument to the authentication system.