IP Library › Granted Patent US 10,922,672
Granted Patent B2
US 10,922,672 · App. 15/431,235 · Granted Feb 16, 2021

Authentication systems and methods using location matching

Inventors: Jalpesh Chitalia (San Francisco, CA); Ansar Ansari (San Ramon, CA)
Assignee: Visa International Service Association
G06Q20/3224G01S19/13G06Q20/3276G06Q20/385G07C9/28H04L9/3213H04W4/023G07C2209/63H04W4/80H04W12/00503
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,922,672
App. No.
15/431,235
Granted
Feb 16, 2021
Kind
B2
Abstract

According to some embodiments of the invention, an authentication method is provided. Transaction data for a transaction is received at a communication device from an access device or a resource provider. The transaction data comprises a location of the access device. A location of the communication device is determined by the communication device. It is determined whether a distance between the location of the access device and the location of the communication device is within a predetermined threshold. The transaction is not authorized if the distance between the location of the access device and the location of the communication device is not within a predetermined threshold.

Claims (33)

1. A method of conducting a transaction between a user and a resource provider, the method comprising:

reading, at a communication device of the user, a QR code comprising transaction data for the transaction from an access device associated with the resource provider, the transaction data comprising a location of the access device and a first time at which the location of the access device was determined;

obtaining, at the communication device, sensitive information associated with the user;

determining, by a component of the communication device, a location of the communication device and a second time at which the location of the communication device was determined;

calculating, by a distance module on the communication device, a distance between the location of the access device and the location of the communication device, and determining an indicator of whether the distance is less than a predetermined distance threshold;

calculating, by the communication device, a time difference between the first time and the second time;

when the distance is less than the predetermined distance threshold and the time difference is less than a predetermined timing threshold, transmitting, by the communication device, the transaction data, the indicator of whether the distance is less than the predetermined distance threshold, and the sensitive information to an application server computer, the application server computer transmitting, to a token server computer, a request for a token, the request comprising the transaction data; and wherein the access device transmits the transaction data to a resource provider computer, the resource provider computer obtaining the token utilizing the transaction data, wherein the transaction is processed by the resource provider computer, at least in part, using the transaction data and the token in lieu of the sensitive information.

2. The method of claim 1 ,

wherein the application server computer hosts a digital wallet application operating at the communication device.

3. The method of claim 1 ,

wherein the application server computer transmits the request for the token to the token server computer based at least in part on receiving the indicator.

4. The method of claim 1 , further comprising:

receiving, by the communication device, a selection of the sensitive information from a list of sensitive information, the selection being received via a digital wallet application operating at the communication device.

5. The method of claim 1 , wherein the communication device is a mobile phone and the transaction is a transaction for the user of the communication device to access a building.

6. The method of claim 1 , wherein the transaction data is received utilizing a visual sensor of the communication device.

7. The method of claim 6 , wherein the location of the access device is embedded in the QR code.

8. A communication device comprising:

a processor; and

a memory coupled to the processor, the memory storing instructions, which when executed by the processor, cause the communication device to perform operations including:

reading a QR code comprising transaction data for a transaction from an access device associated with a resource provider, the transaction data comprising a location of the access device and a first time at which the location of the access device was determined;

obtaining sensitive information associated with a user;

determining, by a component of the communication device, a location of the communication device and a second time at which the location of the communication device was determined;

calculating, by a distance module, a distance between the location of the access device and the location of the communication device, and determining an indicator of whether the distance is less than a predetermined distance threshold;

calculating, by the communication device, a time difference between the first time and the second time;

when the distance is less than the predetermined distance threshold and the time difference is less than a predetermined timing threshold, transmitting the transaction data, the indicator of whether the distance is less than the predetermined distance threshold, and the sensitive information to an application server computer, the application server computer transmitting, to a token server computer, a request for a token, the request comprising the transaction data; and wherein the access device transmits the transaction data to a resource provider computer, the resource provider computer obtaining the token utilizing the transaction data, wherein the transaction is processed by the resource provider computer, at least in part, using the transaction data and the token in lieu of the sensitive information.

9. The communication device of claim 8 , wherein the operations further include:

transmitting the location of the access device, the location of the communication device, and the transaction data to the application server computer, the application server computer hosting a digital wallet application operating at the communication device.

10. The communication device of claim 8 , wherein the communication device is a mobile phone.

11. The communication device of claim 8 , wherein the operations further include:

receiving a selection of the sensitive information from a list of sensitive information, the selection being received via a digital wallet application operating at the communication device.

12. The communication device of claim 8 , wherein the location of the access device is embedded in the QR code.

13. The method of claim 1 ,

wherein processing the transaction data ceases when the time difference between the first time and the second time exceeds the predetermined timing threshold.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 28, 2017
From: CHITALIA, JALPESH; ANSARI, ANSAR
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 043696/0608 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2017
From: CHITALIA, JALPESH; ANSARI, ANSAR
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 043355/0171 →
Continuity (2)
Provisional Application 62294471 · Feb 12, 2016
Related Publication 20170236113A1 · Aug 17, 2017
Cited By (4)
US 12,301,575 US 12,367,492 US 12,423,672 US 12,711,343