IP Library Granted Patent US 10,339,524
Granted Patent B2
US 10,339,524 · App. 13/563,534 · Granted Jul 2, 2019

Systems and methods for multi-merchant tokenization

Inventors: Michelle K. Plomske (Durango, CO); Charles E. Watts (Durango, CO); Matthew D. Ozvat (Durango, CO)
Assignee: Worldpay, LLC
G06Q20/38215
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,339,524
App. No.
13/563,534
Granted
Jul 2, 2019
Kind
B2
Abstract

Systems and methods for multi-merchant tokenization may include receiving a transaction from a point of sale terminal of a merchant, validating the merchant ID against merchant logs, and generating a token for the transaction. The token includes a primary account number, expiration, and a group ID. Additionally, the system provides the primary account number to a payment system and receives a response back. The response is then output back to the merchant along with the token. In subsequent transactions, the system may receive the token from a one point of sale terminal of the merchant. The system validates the merchant ID against merchant logs and ensures the merchant is configured for tokenization. The token is decrypted and the group ID is compared to the merchant ID in the merchant logs. When they match, the primary account number is provided to the payment system for approval.

Claims (54)

1. A method for multi-merchant tokenization at a tokenization and payment management system, wherein the tokenization and payment management system comprises a payment service module, an encryption service module, and a hardware security module, the method comprising:

receiving, by the payment service module, a transaction from a point of sale terminal of a merchant and forwarding, by the payment service module, the transaction to the encryption service module, wherein the transaction includes an amount, a merchant ID, and an encrypted portion comprising a primary account number;

validating, by the encryption service module, the merchant ID, wherein the validating comprises comparing the merchant ID with a stored database of terminal IDs;

correlating, by the encryption service module, the merchant ID with one or more group IDs among a plurality of group IDs;

in response to the encryption service module validating the merchant ID,

forwarding, by the encryption service module, the encrypted portion of the transaction to the hardware security module,

retrieving, by the hardware security module, the primary account number from the encrypted portion of the transaction by decrypting the encrypted portion of the transaction, and

generating, by the hardware security module, an encrypted token, wherein the generating comprises:

tokenizing an expiration date, a group ID among the one or more group IDs, and the retrieved primary account number; and

encrypting the tokenized expiration date, group ID, and primary account number;

providing, by the payment service module, the retrieved primary account number to a payment system;

receiving, by the payment service module, a response from the payment system;

storing, by the hardware security module, a decryption key corresponding to the encrypted token and transmitting, by the hardware security module, the encrypted token to the payment service module; and

outputting, by the payment service module, the response and the encrypted token to the point of sale terminal.

2. The method of claim 1 , wherein the transaction further includes a frequency element, and

wherein when the frequency element is a recurring frequency element the tokenization and payment management system sets the encrypted token expiration to a period allowing for multiple repeated transactions.

3. The method of claim 1 , wherein the group ID enables only particular merchants to redeem the token.

4. The method of claim 3 , further comprising associating merchants to the group ID.

5. The method of claim 1 , further comprising querying a database for merchant configuration.

6. The method of claim 5 , further comprising declining the transaction if the merchant configuration does not match the transaction.

7. The method of claim 5 , further comprising updating the database for changes in merchant configuration.

8. The method of claim 1 , further comprising:

receiving the encrypted token from at least one point of sale terminal of the merchant;

validating the merchant ID against merchant logs, wherein the validation ensures the merchant is configured for tokenization;

decrypting the encrypted token;

comparing the group ID to the merchant ID in the merchant logs;

providing the primary account number to a payment system;

receiving a second response from the payment system; and

outputting the second response to the point of sale terminal.

9. A tokenization and payment management system for multi-merchant tokenization, the system comprising:

a payment service module configured to:

receive a transaction from a point of sale terminal of a merchant, wherein the transaction includes an amount, a merchant ID, and an encrypted portion comprising a primary account number;

an encryption service module configured to:

receive the transaction from the payment service module,

validate the merchant ID, wherein the validating comprises comparing the merchant ID with a stored database of terminal IDs, and

correlate the merchant ID with one or more group IDs among a plurality of group IDs; and

a hardware security module, including a processor, configured to:

in response to the encryption service module validating the merchant ID,

receive the encrypted portion of the transaction from the encryption service module,

retrieve the primary account number from the encrypted portion of the transaction by decrypting the encrypted portion of the transaction, and

generate an encrypted token, wherein the generating comprises tokenizing an expiration date, a group ID among the one or more group IDs, and the retrieved primary account number, and encrypting the tokenized expiration date, group ID, and primary account number; and

store a decryption key corresponding to the encrypted token and transmit the encrypted token to the payment service module; and

wherein the payment service module is further configured to provide the retrieved primary account number to a payment system, receive a response from the payment system, and output the response and the encrypted token to the point of sale terminal.

10. The system of claim 9 , wherein the group ID enables only particular merchants to redeem the encrypted token.

11. The system of claim 10 , further comprising a database associating merchants to the group ID.

12. The system of claim 9 , wherein the encryption service module is further configured to query a database for merchant configuration.

13. The system of claim 12 , wherein the encryption service module is further configured to decline the transaction if the merchant configuration does not match the transaction.

14. The system of claim 12 , further comprising at least one application configured to update the database for changes in merchant configuration.

15. The system of claim 9 , wherein:

the payment service module is further configured to receive the encrypted token from at least one point of sale terminal of the merchant;

the encryption service module is further configured to validate the merchant ID against merchant logs, wherein the validation ensures the merchant is configured for tokenization;

the hardware security module is further configured to decrypt the token;

the encryption service module is further configured to compare the group ID to the merchant ID in the merchant logs; and

the payment service module is further configured to provide the primary account number to a payment system, receive a second response from the payment system, and output the second response to the point of sale terminal.

Assignments (9)
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT R/F 066624/0719 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: WORLDPAY, LLC
Reel/Frame 074315/0412 →
RELEASE OF SECURITY INTERESTS RECORDED AT REEL/FRAMES 066626/0655, 066625/0426, 066625/0347, AND 066625/0276 Recorded Jan 12, 2026
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: WORLDPAY, LLC; WORLDPAY ISO AND ECOMMERCE, LLC; PAYMETRIC, LLC; WORLDPAY US, LLC
Reel/Frame 074314/0622 →
SECURITY INTEREST Recorded Feb 19, 2024
From: WORLDPAY, LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066624/0719 →
SECURITY INTEREST Recorded Feb 19, 2024
From: WORLDPAY, LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 066626/0655 →
CHANGE OF NAME Recorded Aug 6, 2018
From: VANTIV, LLC
To: WORLDPAY, LLC
Reel/Frame 046723/0234 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2017
From: MML 1 LLC
To: VANTIV, LLC
Reel/Frame 043007/0234 →
RELEASE OF SECURITY INTEREST Recorded Jun 13, 2014
From: DEUTSCHE BANK TRUST COMPANY AMERICAS, AS ADMINISTRATIVE AGENT
To: MERCURY PAYMENT SYSTEMS, LLC
Reel/Frame 033161/0952 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2012
From: PLOMSKE, MICHELLE K.; WATTS, CHARLES E.; OZVAT, MATTHEW D.
To: MML 1 LLC
Reel/Frame 029131/0998 →
PATENT SECURITY AGREEMENT Recorded Aug 30, 2012
From: MERCURY PAYMENT SYSTEMS, LLC
To: DEUTSCHE BANK TRUST COMPANY AMERICAS, AS ADMINISTRATIVE AGENT
Reel/Frame 028885/0240 →
Continuity (1)
Related Publication 20140040144A1 · Feb 6, 2014
Cited By (1)
US 12,321,929