IP Library › Granted Patent US 11,138,605
Granted Patent B2
US 11,138,605 · App. 14/314,742 · Granted Oct 5, 2021

Online authentication in access transactions

Inventors: Christian Aabye (Foster City, CA); Eric Schindewolf (Danville, CA)
Assignee: VISA INTERNATIONAL SERVICE ASSOCIATION
G06Q20/401G06Q20/027G06Q20/3674G06Q20/3821G06Q20/4016
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,138,605
App. No.
14/314,742
Filed
Jun 25, 2014
Granted
Oct 5, 2021
Kind
B2
Art Unit
3685
USPC
705/50
Abstract

Embodiments of the invention are directed to access transactions. A gate access device may interact with a payment card such as a credit card. The gate access device may generate and transmit a first authorization request message to a payment processing network computer. The first authorization request message does not include an amount for the transaction, but only contains identification information. A first authorization response message is transmitted back to the gate access device. At a later point in time, a second authorization request message containing the transaction amount is transmitted from the gate access device to the issuer, and a response is received from the issuer.

Claims (50)

1. A method comprising:

reading, by a gate access device, an account identifier and a cryptogram from a portable consumer device associated with a user that is conducting an access transaction;

determining, a transaction amount to be associated with the access transaction;

determining, by the gate access device, that the account identifier is not on a black list or on a white list;

in response to determining that the account identifier is not on the black list or on the white list, generating, by the gate access device or an access host computer coupled to the gate access device, a first authorization request message comprising the account identifier, the cryptogram, and a first transaction amount data field, the first transaction amount data field indicating that the first authorization request message is for authentication by virtue of being empty or including a value of zero;

transmitting, by the gate access device or the access host computer, to a payment processing computer, the first authorization request message;

receiving, by the gate access device or the access host computer, from the payment processing computer, a first authorization response message comprising an authentication result, the authentication result including a fraud score;

determining, by the gate access device, that the authentication result is positive, the authentication result being positive when the fraud score is less than a threshold value;

in response to determining that the authentication result is positive, actuating, by the gate access device, a gate device such that the user can physically enter a restricted physical area;

in response to determining that the authentication result is not positive, preventing actuating the gate device such that the user cannot physically enter the restricted physical area;

generating, by the gate access device or the access host computer after actuating the gate device, a second authorization request message comprising the account identifier and a second transaction amount data field, the second transaction amount data field including the transaction amount for the access transaction;

transmitting, by the gate access device or the access host computer, to the payment processing computer, the second authorization request message comprising the account identifier and the transaction amount for the access transaction; and

receiving, by the gate access device or the access host computer, from the payment processing computer, a second authorization response message, wherein the second authorization response message indicates that the access transaction is authorized.

2. The method of claim 1 wherein the access transaction is a transit transaction, and wherein the first authorization request message passes to the payment processing computer through an acquirer computer.

3. The method of claim 1 wherein the user is allowed to enter the restricted physical area within a predetermined amount of time after reading the account identifier.

4. The method of claim 3 wherein the predetermined amount of time is 300 milliseconds, 500 milliseconds, or 1 second.

5. The method of claim 1 wherein the portable consumer device is an open-loop payment card.

6. The method of claim 1 wherein the payment processing computer does not transmit the first authorization request message to an issuer computer, and wherein the payment processing computer does not authorize the access transaction.

7. The method of claim 1 wherein the payment processing computer generates the fraud score based on transaction data for previous transactions that were conducted using the account identifier, and that were conducted at other merchants.

8. The method of claim 1 wherein the payment processing computer generates the fraud score based on transaction data for previous transactions that were conducted with the account identifier, and that were not access transactions.

9. The method of claim 1 wherein the second authorization response message is received from the payment processing computer via an acquirer computer.

10. The method of claim 1 wherein the payment processing computer is associated with a payment processing network.

11. The method of claim 1 wherein the payment processing computer processes transactions between multiple merchant computers and multiple issuer computers.

12. The method of claim 1 , wherein the access transaction is a first access transaction, and further comprising:

adding the account identifier to the white list based on the second authorization response message;

reading, by the gate access device, the account identifier from the portable consumer device for a second access transaction;

determining by the gate access device that the account identifier is on the white list;

causing the gate access device to allow the user to enter the restricted physical area based on determining the account identifier is on the white list;

generating, by the gate access device or the access host computer, a third authorization request message comprising the account identifier and a second amount for the second access transaction;

transmitting, to the payment processing computer, the third authorization request message comprising the account identifier and the second amount for the second access transaction, wherein the payment processing computer transmits the third authorization request message to an issuer computer, wherein the issuer computer authorizes the second access transaction based on the account identifier and the second amount, and wherein the issuer computer generates a third authorization response message and transmits the third authorization response message to the payment processing computer; and

receiving, from the payment processing computer, the third authorization response message, wherein the third authorization response message indicates that the second access transaction is authorized.

13. The method of claim 1 , wherein the first authorization request message is formatted as an ISO 8583 message, and wherein the second authorization request message is formatted as an ISO 8583 message.

14. The method of claim 1 , wherein the first authorization request message is not a standard authorization request message, and wherein the payment processing computer does not transmit the first authorization request message to an issuer computer because the first authorization request message is not a standard authorization request message.

15. A gate access device comprising:

a processor;

a reader coupled to the processor;

a gate device coupled to the processor; and

a non-transitory computer readable medium coupled to the processor, the non-transitory computer readable medium comprising code executable by the processor for implementing a method comprising:

reading, by the reader, an account identifier and a cryptogram from a portable consumer device associated with a user that is conducting an access transaction;

determining that the account identifier is not on a black list or on a white list;

in response to determining that the account identifier is not on the black list or on the white list, generating a first authorization request message comprising the account identifier, the cryptogram, and a first transaction amount data field, the first transaction amount data field indicating that the first authorization request message is for authentication by virtue of being empty or including a value of zero;

transmitting, to a payment processing computer, the first authorization request message;

receiving, from the payment processing computer, a first authorization response message comprising an authentication result, the authentication result including a fraud score;

determining, by the gate access device, that the authentication result is positive, the authentication result being positive when the fraud score is less than a threshold value;

in response to determining that the authentication result is positive, actuating the gate device such that the user can physically enter a restricted physical area;

generating, after actuating the gate device, a second authorization request message comprising the account identifier and a second transaction amount data field, the second transaction amount data field including an amount for the access transaction;

transmitting to the payment processing computer, the second authorization request message comprising the account identifier and the amount for the access transaction; and

receiving from the payment processing computer, a second authorization response message, wherein the second authorization response message indicates that the access transaction is authorized.

16. The gate access device of claim 15 wherein the access transaction is a transit transaction.

17. The gate access device of claim 16 wherein the reader is a contactless reader.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2014
From: AABYE, CHRISTIAN; SCHINDEWOLF, ERIC
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 033186/0701 →
Continuity (2)
Provisional Application 61842230 · Jul 2, 2013
Related Publication 20150012434A1 · Jan 8, 2015
Cited By (91)
US 12,260,393 US 12,288,205 US 12,288,206 US 12,307,457 US 12,450,591 US 12,489,625 US 12,489,747 US 12,493,679 US 12,493,868 US 12,493,869 US 12,494,915 US 12,495,042 US 12,499,433 US 12,505,432 US 12,505,448 US 12,505,450 US 12,506,514 US 12,511,365 US 12,511,638 US 12,511,640 US 12,511,654 US 12,513,123 US 12,519,652 US 12,520,136 US 12,524,768 US 12,526,149 US 12,530,674 US 12,530,937 US 12,532,170 US 12,536,392 US 12,536,522 US 12,536,523 US 12,536,525 US 12,541,667 US 12,548,009 US 12,561,669 US 12,561,673 US 12,567,057 US 12,567,060 US 12,567,069 US 12,574,235 US 12,574,243 US 12,579,532 US 12,580,752 US 12,580,767 US 12,591,875 US 12,591,876 US 12,591,877 US 12,591,885 US 12,592,819 US 12,592,828 US 12,596,545 US 12,596,780 US 12,597,012 US 12,603,163 US 12,603,883 US 12,614,053 US 12,615,154 US 12,621,155 US 12,621,642 US 12,626,241 US 12,626,242 US 12,639,710 US 12,646,062 US 12,646,370 US 12,647,271 US 12,657,572 US 12,658,976 US 12,670,494 US 12,675,766 US 12,675,790 US 12,676,938 US 12,682,371 US 12,683,796 US 12,688,493 US 12,688,508 US 12,694,393 US 12,694,394 US 12,699,998 US 12,701,141 US 12,706,904 US 12,707,270 US 12,718,038 US 12,726,358 US 12,730,991 US 12,731,115 US 12,732,373 US 12,737,750 US 12,743,690 US 12,749,068 US 12,749,073