IP Library Granted Patent US 10,439,813
Granted Patent B2
US 10,439,813 · App. 15/090,473 · Granted Oct 8, 2019

Authentication and fraud prevention architecture

Inventor: Eric Vortriede (Mountain Center, CA)
Assignee: VISA INTERNATIONAL SERVICE ASSOCIATION
H04L9/321H04L9/3226H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,439,813
App. No.
15/090,473
Granted
Oct 8, 2019
Kind
B2
Abstract

Embodiments of the invention are directed to authentication and authorization methods. The authentication process can involve a user device interacting with an access device that is within a proximity of the user device to help ensure that the user device is near a location of the access device. The access device can assist with the authentication, either at the access device or via a communications network to an authentication computer. For example, embodiments can provide mechanisms for authentication of a user device at an access device before the user device is authenticated and authorized access to a building.

Claims (64)

1. A method of authentication using an access device that stores an access device identifier, the method comprising:

receiving, at the access device from an authentication computer or a registration computer, the access device identifier, wherein the access device identifier uniquely identifies the access device to the authentication computer,

wherein a user device stores a user device identifier that identifies the user device to the authentication computer,

wherein a user device credential is registered with the authentication computer,

wherein the user device receives the access device identifier while the user device is at a location of the access device, and

wherein the user device generates a user device cryptogram of the access device identifier;

receiving, at the access device from the user device, (i) the user device identifier, (ii) the user device cryptogram of the access device identifier, and (iii) the user device credential while the user device is at the location of the access device;

generating an access device cryptogram using at least the user device credential;

generating, by the access device, an authentication request message using the user device cryptogram, wherein the authentication request message includes the user device identifier and the access device cryptogram; and

transmitting, by the access device for receipt by the authentication computer, the authentication request message for determining an authentication by the authentication computer, wherein the authentication computer determines the authentication of the user device using the user device identifier, the access device identifier, and the access device cryptogram.

2. The method of claim 1 , wherein the access device cryptogram is the user device cryptogram.

3. The method of claim 1 , wherein the user device cryptogram is a hash-based message authentication code (HMAC) of data comprising the access device identifier and the user device credential.

4. The method of claim 3 , wherein the user device generates the user device cryptogram in response to receiving the user device credential at an input of the user device.

5. The method of claim 1 , further comprising:

receiving, at the access device, an access device credential; and

generating the access device cryptogram as a hash-based message authentication code (HMAC) of the access device credential and the user device cryptogram in the authentication request message.

6. The method of claim 5 , further comprising:

receiving a prompt from the user device; and

providing the prompt, wherein the access device credential is received in response to the prompt.

7. The method of claim 1 , further comprising:

receiving a response message from the authentication computer, wherein the response message indicates a positive or negative authentication of the user device; and

generating an authorization signal to provide access to the user device.

8. The method of claim 7 , wherein the authorization signal is sent to a door mechanism to provide entry to a restricted location upon receipt of a positive authentication.

9. The method of claim 1 , wherein the user device cryptogram is received from the user device by:

scanning a user device displayed quick response (QR) code with a scanning component of the access device.

10. The method of claim 1 , wherein the user device cryptogram is received from the user device at the access device by an near field communication (NFC) exchange between the user device and the access device.

11. The method of claim 1 , further comprising:

providing, by the access device, the access device identifier to the user device, wherein the access device identifier is provided to the user device using a near field communication (NFC) message.

12. The method of claim 1 , further comprising:

providing, by the access device, a second authentication prompt; and

receiving, by the access device, an access device credential in response to displaying the second authentication prompt, wherein the access device receives the access device credential while the user device is at the location of the access device.

13. The method of claim 12 , wherein the second authentication prompt is displayed at the access device.

14. The method of claim 12 , wherein the second authentication prompt initiates a wireless response.

15. The method of claim 12 , wherein the access device credential is information provided to the access device relating to a user.

16. An access device comprising:

a memory that stores an access device identifier;

one or more processors; and

a computer readable medium storing a plurality of instructions for controlling the one or more processors to perform:

receiving, from an authentication computer or a registration computer, the access device identifier, wherein the access device identifier uniquely identifies the access device to the authentication computer,

wherein a user device stores a user device identifier that identifies the user device to the authentication computer,

wherein a user device credential is registered with the authentication computer,

wherein the user device receives the access device identifier while the user device is at a location of the access device, and

wherein the user device generates a user device cryptogram of the access device identifier,

receiving, from the user device, (i) the user device identifier, (ii) the user device cryptogram of the access device identifier, and (iii) the user device credential while the user device is at the location of the access device,

generating an access device cryptogram using at least the user device credential,

generating an authentication request message using the user device cryptogram, wherein the authentication request message includes the user device identifier, and the access device cryptogram; and

transmitting, for receipt by the authentication computer, the authentication request message for determining an authentication by the authentication computer, wherein the authentication computer determines the authentication of the user device using the user device identifier, the access device identifier, and the access device cryptogram.

17. The access device of claim 16 , wherein the user device cryptogram is a hash-based message authentication code (HMAC).

18. The access device of claim 16 , wherein the access device cryptogram is the user device cryptogram.

19. The access device of claim 16 , wherein the plurality of instructions control the one or more processors to further perform:

receiving an access device credential; and

generating the access device cryptogram as a hash-based message authentication code (HMAC) of the access device credential and the user device cryptogram in the authentication request message.

20. The access device of claim 19 , wherein the plurality of instructions control the one or more processors to further perform:

receiving a prompt from the user device; and

providing the prompt, wherein the access device credential is received in response to the prompt.

21. The access device of claim 16 , wherein the plurality of instructions control the one or more processors to further perform:

receiving a response message from the authentication computer, wherein the response message indicates a positive or negative authentication of the user device; and

generating an authorization signal to provide access to the user device.

22. The access device of claim 21 , wherein the authorization signal is sent to a door mechanism to provide entry to a restricted location upon receipt of a positive authentication.

23. The access device of claim 16 , wherein the user device cryptogram is received from the user device by:

scanning a user device displayed quick response (QR) code with a scanning component of the access device.

24. The access device of claim 16 , wherein the user device cryptogram is received from the user device at the access device by an near field communication (NFC) exchange between the user device and the access device.

25. The access device of claim 16 , wherein the plurality of instructions control the one or more processors to further perform:

providing, by the access device, the access device identifier to the user device, wherein the access device identifier is provided to the user device using a near field communication (NFC) message.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 25, 2016
From: VORTRIEDE, ERIC
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 038815/0317 →
Continuity (2)
Provisional Application 62142263 · Apr 2, 2015
Related Publication 20160294556A1 · Oct 6, 2016