IP Library Granted Patent US 8,688,589
Granted Patent B2
US 8,688,589 · App. 13/797,246 · Granted Apr 1, 2014

Method and system for utilizing authorization factor pools

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,688,589
App. No.
13/797,246
Granted
Apr 1, 2014
Kind
B2
Abstract

One embodiment of the present disclosure provides a system and associated processes for sharing cardholder data (CHD) between a merchant that utilizes tokenization and a second merchant that may or may not utilize tokenization. In one embodiment, the merchant, or an employee of the merchant, can use the system and associated processes to reacquire CHD from a tokenization provider system. In one embodiment, the merchant identifies to the tokenization provider system a desire to share CHD, which is associated with a token, with a second merchant. The merchant and/or the tokenization provider system can then invite the second merchant to register with the tokenization provider system. Once registered with the tokenization provider system, the second merchant can access any CHD that the merchant associated with the second merchant.

Claims (38)

1. A method of sharing a token associated with cardholder data (CHD) to enable the sharing of the CHD between users, the method comprising:

receiving, by a token access system implemented in a computing system comprising one or more processors, an identity of a token associated with CHD of a cardholder and an identity of a second merchant from a first merchant;

determining, by the token access system, from a plurality of tokenization provider systems a tokenization provider system that generated the token wherein the determination is performed by using the identity of the token;

accessing, by the token access system, an authorization factor pool associated with the determined tokenization provider system from a database storing a plurality of authorization pools, wherein each of the tokenization provider systems is associated with a different authorization factor pool from the plurality of authorization factor pools;

generating, by the token access system, an authorization factor using the accessed authorization factor pool;

associating, by the token access system, the authorization factor with the token and the second merchant;

transmitting, by the token access system, the authorization factor to the second merchant;

receiving, by the token access system, the authorization factor from the second merchant;

determining, by the token access system, a corresponding authorization factor pool based on the authorization factor received from the second merchant and determining a corresponding tokenization provider system based on the determined corresponding authorization pool;

sending, by the token access system, the identity of the token to the determined corresponding tokenization provider system;

receiving, by the token access system, information of the token from the determined corresponding tokenization provider system, wherein the information is at least one of the token and the CHD of the cardholder; and

providing, by the token access system, the information of the token to the second merchant.

2. The method of claim 1 , wherein each of the authorization factor pools comprises a set of unique authorization factors that are unique to each authorization factor pool from the plurality of authorization factor pools.

3. The method of claim 1 , wherein each of the authorization factor pools comprises a unique algorithm for generating authorization factors that is unique to each authorization factor pool from the plurality of authorization factor pools.

4. The method of claim 3 , wherein said generating the authorization factor comprises generating the authorization factor using the unique algorithm for the authentication factor pool.

5. The method of claim 1 , wherein said associating the authorization factor with the token includes setting an expiration for the authorization factor.

6. The method of claim 5 , wherein the expiration is based on a time.

7. The method of claim 5 , wherein the expiration is based on a number of accesses to the token using the authorization factor.

8. A system for sharing a token associated with cardholder data (CHD) to enable the sharing of the CHD between users, the system comprising:

a processor, and

a memory device storing computer executable instructions which, when executed by the processor causes the processor to perform a method comprising:

receiving, by a token access system implemented in a computing system comprising one or more processors, an identity of a token associated with CHD of a cardholder and an identity of a second merchant from a first merchant;

determining, by the token access system, from a plurality of tokenization provider systems a tokenization provider system that generated the token wherein the determination is performed by using the identity of the token;

accessing, by the token access system, an authorization factor pool associated with the determined tokenization provider system from a database storing a plurality of authorization pools, wherein each of the tokenization provider systems is associated with a different authorization factor pool from the plurality of authorization factor pools;

generating, by the token access system, an authorization factor using the accessed authorization factor pool;

associating, by the token access system, the authorization factor with the token and the second merchant;

transmitting, by the token access system, the authorization factor to the second merchant;

receiving, by the token access system, the authorization factor from the second merchant;

determining, by the token access system, a corresponding authorization factor pool based on the authorization factor received from the second merchant and determining a corresponding tokenization provider system based on the determined corresponding authorization pool;

sending, by the token access system, the identity of the token to the determined corresponding tokenization provider system;

receiving, by the token access system, information of the token from the determined corresponding tokenization provider system, wherein the information is at least one of the token and the CHD of the cardholder; and

providing, by the token access system, the information of the token to the second merchant.

9. The system of claim 8 , wherein each of the authorization factor pools comprises a set of unique authorization factors that are unique to each authorization factor pool from the plurality of authorization factor pools.

10. The system of claim 8 , wherein each of the authorization factor pools comprises a unique algorithm for generating authorization factors that is unique to each authorization factor pool from the plurality of authorization factor pools.

11. The system of claim 10 , wherein said generating the authorization factor comprises generating the authorization factor using the unique algorithm for the authentication factor pool.

12. The system of claim 8 , wherein said associating the authorization factor with the token includes setting an expiration for the authorization factor.

13. The system of claim 12 , wherein the expiration is based on a time.

14. The system of claim 12 , wherein the expiration is based on a number of accesses to the token using the authorization factor.

Assignments (5)
ASSIGNMENT OF SECURITY INTEREST IN IP COLLATERAL (REEL/FRAME 044591/0445) Recorded Sep 10, 2024
From: UBS AG CAYMAN ISLANDS BRANCH (AS SUCCESSOR ADMINISTRATIVE AGENT AND COLLATERAL AGENT TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH)
To: GOLDMAN SACHS BANK USA
Reel/Frame 068920/0306 →
RELEASE OF SECOND LIEN SECURITY INTEREST Recorded Jul 14, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: SHIFT4 CORPORATION; MERCHANT-LINK, LLC
Reel/Frame 053201/0235 →
SECOND LIEN SECURITY AGREEMENT Recorded Dec 4, 2017
From: SHIFT4 CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS ADMINISTRATIVE AGENT
Reel/Frame 044666/0780 →
FIRST LIEN SECURITY AGREEMENT Recorded Dec 1, 2017
From: SHIFT4 CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS ADMINISTRATIVE AGENT
Reel/Frame 044591/0445 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2013
From: CRONIC, KEVIN JAMES; SOMMERS, STEVEN MARK; ODER, JOHN DAVID, II; ODER, JOHN DAVID; CALANDRELLI, STEVEN; FRIED, JEREMY B.
To: SHIFT4 CORPORATION
Reel/Frame 030760/0971 →