IP Library Granted Patent US 12705609
Granted Patent B2
US 12705609 · App. 18/838,762 · Granted Aug 11, 2026

System, method, and computer program product for secure data distribution

Inventors: Bartlomiej Piotr Prokop (Belfast, GB); Bryan Carroll (Livermore, CA); Rhidian Desmond Thomas John (Helen's Bay, GB); Julie Nicholl (Bangor, GB)
Assignee: Visa International Service Association
G06Q20/3829G06Q20/401H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12705609
App. No.
18/838,762
Granted
Aug 11, 2026
Kind
B2
Abstract

A method, system, and computer program product is provided for secure data distribution. The system includes at least one processor programmed or configured to receive, from a first system, a data capture request, generate a data capture object including a plurality of orchestration rules and a first public key, digitally sign the data capture object with a second private key corresponding to a second public key, transmit the data capture object to the first system, receive encrypted user data including user data encrypted with the first public key, generate a transient token based on the user data and the plurality of orchestration rules, and distribute the transient token to each party of the plurality of parties by transmitting the transient token to the first system via a device.

Claims (41)

1 . A computer-implemented method, comprising:

receiving, by at least one processor from a first system, a data capture request comprising a plurality of keys and identifying a device in communication with the first system, the plurality of keys comprising a key for each party of a plurality of parties;

generating, with the at least one processor, a data capture object comprising a plurality of orchestration rules and a first public key, the first public key corresponding to a first private key;

digitally signing, with the at least one processor, the data capture object with a second private key corresponding to a second public key;

transmitting, with the at least one processor, the data capture object to the first system;

receiving encrypted user data comprising user data encrypted with the first public key, at least a portion of the user data input from a device;

generating, with the at least one processor, a transient token based on the user data and the plurality of orchestration rules; and

distributing, with the at least one processor, the transient token to each party of the plurality of parties by transmitting the transient token to the first system via the device, the transient token configured to, based on the plurality of orchestration rules, cause the first system to transmit the transient token to each party of the plurality of parties based on a corresponding key of the plurality of keys.

2 . The method of claim 1 , wherein the first system comprises a merchant system webpage, and wherein the user data is input into a frame or window on the merchant system webpage hosted by a system external to the merchant system webpage.

3 . The method of claim 1 , wherein transmitting the transient token to the first system via the device comprises passing the transient token from the device to the first system via a web browser executing on the device.

4 . The method of claim 1 , wherein a payment gateway comprises the at least one processor.

5 . The method of claim 1 , wherein the data capture request is received via an Application Programming Interface (API).

6 . The method of claim 1 , wherein the first system comprises a merchant system, and wherein the plurality of parties comprises a payment processor, the merchant system, and at least one of the following: a fraud service system, a loyalty provider system, an issuer system, an authentication service provider system, or any combination thereof.

7 . The method of claim 1 , wherein the device comprises a user device, and wherein the encrypted user data is generated by the first system.

8 . A system comprising at least one processor programmed or configured to:

receive, from a first system, a data capture request comprising a plurality of keys and identifying a device in communication with the first system, the plurality of keys comprising a key for each party of a plurality of parties;

generate a data capture object comprising a plurality of orchestration rules and a first public key, the first public key corresponding to a first private key;

digitally sign the data capture object with a second private key corresponding to a second public key;

transmit the data capture object to the first system;

receive encrypted user data comprising user data encrypted with the first public key, at least a portion of the user data input from a device;

generate a transient token based on the user data and the plurality of orchestration rules; and

distribute the transient token to each party of the plurality of parties by transmitting the transient token to the first system via the device, the transient token configured to, based on the plurality of orchestration rules, cause the first system to transmit the transient token to each party of the plurality of parties based on a corresponding key of the plurality of keys.

9 . The system of claim 8 , wherein the first system comprises a merchant system webpage, and wherein the user data is input into a frame or window on the merchant system webpage hosted by a system external to the merchant system webpage.

10 . The system of claim 8 , wherein transmitting the transient token to the first system via the device comprises passing the transient token from the device to the first system via a web browser executing on the device.

11 . The system of claim 8 , wherein a payment gateway comprises the at least one processor.

12 . The system of claim 8 , wherein the data capture request is received via an Application Programming Interface (API).

13 . The system of claim 8 , wherein the first system comprises a merchant system, and wherein the plurality of parties comprises a payment processor, the merchant system, and at least one of the following: a fraud service system, a loyalty provider system, an issuer system, an authentication service provider system, or any combination thereof.

14 . A computer program product comprising at least one non-transitory computer-readable medium including program instructions that, when executed by at least one processor, causes the at least one processor to:

receive, from a first system, a data capture request comprising a plurality of keys and identifying a device in communication with the first system, the plurality of keys comprising a key for each party of a plurality of parties;

generate a data capture object comprising a plurality of orchestration rules and a first public key, the first public key corresponding to a first private key;

digitally sign the data capture object with a second private key corresponding to a second public key;

transmit the data capture object to the first system;

receive encrypted user data comprising user data encrypted with the first public key, at least a portion of the user data input from a device;

generate a transient token based on the user data and the plurality of orchestration rules; and

distribute the transient token to each party of the plurality of parties by transmitting the transient token to the first system via the device, the transient token configured to, based on the plurality of orchestration rules, cause the first system to transmit the transient token to each party of the plurality of parties based on a corresponding key of the plurality of keys.

15 . The computer program product of claim 14 , wherein the first system comprises a merchant system webpage, and wherein the user data is input into a frame or window on the merchant system webpage hosted by a system external to the merchant system webpage.

16 . The computer program product of claim 14 , wherein transmitting the transient token to the first system via the device comprises passing the transient token from the device to the first system via a web browser executing on the device.

17 . The computer program product of claim 14 , wherein a payment gateway comprises the at least one processor.

18 . The computer program product of claim 14 , wherein the data capture request is received via an Application Programming Interface (API).

19 . The computer program product of claim 14 , wherein the first system comprises a merchant system, and wherein the plurality of parties comprises a payment processor, the merchant system, and at least one of the following: a fraud service system, a loyalty provider system, an issuer system, an authentication service provider system, or any combination thereof.

20 . The computer program product of claim 14 , wherein the device comprises a user device, and wherein the encrypted user data is generated by the first system.