IP Library Granted Patent US 9,785,941
Granted Patent B2
US 9,785,941 · App. 15/607,440 · Granted Oct 10, 2017

Tokenization in mobile environments

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,785,941
App. No.
15/607,440
Granted
Oct 10, 2017
Kind
B2
Abstract

Data can be protected in mobile and payment environments through various tokenization operations. A mobile device can tokenize communication data based on device information and session information associated with the mobile device. A payment terminal can tokenize payment information received at the payment terminal during a transaction based on transaction information associated with the transaction. Payment data tokenized first a first set of token tables and according to a first set of tokenization parameters by a first payment entity can be detokenized or re-tokenized with a second set of token tables and according to a second set of tokenization parameters. Payment information can be tokenized and sent to a mobile device as a token card based on one or more selected use rules, and a user can request a transaction based on the token card. The transaction can be authorized if the transaction satisfies the selected use rules.

Claims (37)

1. A method for tokenizing data, comprising:

providing, by a mobile device to a central security system communicatively coupled to each of a plurality of mobile devices via a network, information to be tokenized and an identification of one or more use rules;

receiving, by the mobile device from the central security system, a token card from the central security system, the token card generated by the central security system by querying a token table selected at least part based on the identified one or more use rules with a portion of the information and replacing the portion of the information with a token value mapped to a value of the portion of the information by the selected token table;

receiving, at the mobile device, a request to use the token card in an interaction by a user of the mobile device, the mobile device configured to display a representation of the token card in response to receiving the request; and

in response to receiving a selection of the displayed representation of the token card, providing, by the mobile device, the token card to a central processing system configured to authorize the use of the token card in the interaction in response to the identified one or more use rules being satisfied by the interaction.

2. The method of claim 1 , wherein the information is associated with a user account.

3. The method of claim 1 , wherein the information is associated with an identity of the user.

4. The method of claim 1 , wherein the information is associated with the interaction.

5. The method of claim 1 , wherein the specified use rules comprise a rule specifying a geographic region.

6. The method of claim 1 , wherein the specified use rules comprise a rule specifying a business.

7. The method of claim 1 , wherein the token table is identified by the one or more use rules.

8. The method of claim 7 , where an identity of the token table is included within metadata corresponding to the one or more use rules.

9. The method of claim 1 , wherein the displayed representation of the token card comprises a display of description text associated with the token card entered by a user at the central security system.

10. The method of claim 1 , wherein determining if the identified one or more use rules are satisfied by the interaction comprises, for each use rule:

identifying an interaction restriction associated with each use rule; and

determining if the interaction exceeds the interaction restriction.

11. The method of claim 1 , wherein the network is configured to authorize the interaction.

12. The method of claim 11 , wherein authorizing the interaction comprises:

sending, from the network, an authorization request to the mobile device;

receiving, at the mobile device, an authorization in response to the authorization request; and

sending, from the mobile device, the authorization to the network.

13. The method of claim 12 , wherein receiving an authorization comprises receiving user credentials at the mobile device.

14. A system for tokenizing data, comprising:

a mobile device comprising a hardware processor and a non-transitory computer-readable storage medium storing executable instructions that, when executed, perform steps comprising:

providing, by the mobile device to a central security system communicatively coupled to each of a plurality of mobile devices via a network, information to be tokenized and an identification of one or more use rules;

receiving, by the mobile device from the central security system, a token card from the central security system, the token card generated by the central security system by querying a token table selected at least part based on the identified one or more use rules with a portion of the information and replacing the portion of the information with a token value mapped to a value of the portion of the information by the selected token table;

receiving, at the mobile device, a request to use the token card in an interaction by a user of the mobile device, the mobile device configured to display a representation of the token card in response to receiving the request; and

in response to receiving a selection of the displayed representation of the token card, providing, by the mobile device, the token card to a central processing system configured to authorize the use of the token card in the interaction in response to the identified one or more use rules being satisfied by the interaction.

15. The system of claim 14 , wherein the information is associated with one or more of: a user account, an identity of the user, and the interaction.

16. The system of claim 14 , wherein the specified use rules comprise a rule specifying one or more of: a geographic region, a business, a time, and a date.

17. A non-transitory computer-readable storage medium storing executable computer instructions that, when executed by a hardware processor, perform steps for tokenizing data comprising:

providing, by a mobile device to a central security system communicatively coupled to each of a plurality of mobile devices via a network, information to be tokenized and an identification of one or more use rules;

receiving, by the mobile device from the central security system, a token card from the central security system, the token card generated by the central security system by querying a token table selected at least part based on the identified one or more use rules with a portion of the information and replacing the portion of the information with a token value mapped to a value of the portion of the information by the selected token table;

receiving, at the mobile device, a request to use the token card in an interaction by a user of the mobile device, the mobile device configured to display a representation of the token card in response to receiving the request; and

in response to receiving a selection of the displayed representation of the token card, providing, by the mobile device, the token card to a central processing system configured to authorize the use of the token card in the interaction in response to the identified one or more use rules being satisfied by the interaction.

18. The non-transitory computer-readable storage medium of claim 17 , wherein the information is associated with one or more of: a user account, an identity of the user, and the interaction.

19. The non-transitory computer-readable storage medium of claim 17 , wherein the specified use rules comprise a rule specifying one or more of: a geographic region, a business, a time, and a date.

Assignments (3)
SECURITY INTEREST Recorded Aug 2, 2024
From: PROTEGRITY USA, INC.; PROTEGRITY LIMITED HOLDING, LLC; PROTEGRITY US HOLDING, LLC; PROTEGRITY CORPORATION; KAVADO, LLC
To: CANADIAN IMPERIAL BANK OF COMMERCE
Reel/Frame 068326/0020 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: PROTEGRITY CORPORATION
To: PROTEGRITY US HOLDING, LLC
Reel/Frame 067566/0462 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2017
From: MATTSSON, ULF; ROZENBERG, YIGAL
To: PROTEGRITY CORPORATION
Reel/Frame 043296/0139 →