IP Library › Granted Patent US 10,361,856
Granted Patent B2
US 10,361,856 · App. 15/632,223 · Granted Jul 23, 2019

Unique token authentication cryptogram

Inventors: Michael Cassin (Foster City, CA); Christian Flurscheim (Walnut Creek, CA); Christopher Jones (Greenbrae, CA)
Assignee: Visa International Service Association
H04L9/3213G06Q20/12G06Q20/14G06Q20/3672G06Q20/3674G06Q20/385H04L63/062H04L63/08H04L9/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,361,856
App. No.
15/632,223
Filed
Jun 23, 2017
Granted
Jul 23, 2019
Kind
B2
Art Unit
2435
USPC
726/9
Abstract

Embodiments of the invention are directed to systems and methods for validating transactions using a cryptogram. One embodiment of the invention is directed to a method of processing a remote transaction initiated by a communication device provisioned with a token. The method comprises receiving, by a service provider computer, from an application on the communication device, a request for a token authentication cryptogram, wherein the token authentication cryptogram includes encrypted user exclusive data. The service provider computer may generate the token authentication cryptogram to include the user exclusive data. The service provider computer may send the token authentication cryptogram to the application, where the token authentication cryptogram can be used to validate the transaction, and the user exclusive data is extracted from the token authentication cryptogram during validation.

Claims (34)

1. A method of processing a transaction initiated by a communication device provisioned with a token, the method comprising:

receiving, by a service provider computer, from an application operating on the communication device, a token request message for a token authentication cryptogram;

generating, by the service provider computer, the token authentication cryptogram derived from user exclusive data, wherein the token authentication cryptogram is generated by encrypting at least the user exclusive data utilizing a triple data encryption algorithm; and

sending, by the service provider computer to the application, the token authentication cryptogram, wherein the token authentication cryptogram can be used to validate the transaction, and the user exclusive data subsequently is extracted from the token authentication cryptogram during validation by a processing computer which then uses the user exclusive data for additional analysis.

2. The method of claim 1 , wherein the user exclusive data comprises at least one of: a resource provider identifier, user preference information, or a user identifier.

3. The method of claim 1 , wherein the token authentication cryptogram is sent to the application utilizing a token response message.

4. The method of claim 1 , wherein the application is hosted by a resource provider computer.

5. The method of claim 1 , wherein receipt of the token authentication cryptogram causes the application to transmit the token authentication cryptogram in an authorization request message to a transaction processing computer.

6. The method of claim 1 , wherein content of the user exclusive data is specified by the service provider computer.

7. A method of processing a transaction initiated by a communication device, the method comprising:

sending, by a service provider computer, to a token provider computer, a token request message for a token authentication cryptogram, wherein the token request message comprises user exclusive data;

receiving, by the service provider computer, from the token provider computer, a token and the token authentication cryptogram, the token authentication cryptogram derived from the user exclusive data, wherein the token authentication cryptogram is generated by encrypting at least the user exclusive data utilizing a triple data encryption algorithm; and

sending, by the service provider computer to the communication device, the token and the token authentication cryptogram, wherein the token authentication cryptogram can be used to validate the transaction, and the user exclusive data is subsequently extracted from the token authentication cryptogram during validation by a processing computer which then uses the user exclusive data for additional analysis.

8. The method of claim 7 , wherein the user exclusive data comprises at least one of: a resource provider identifier, user preference information, or a user identifier.

9. The method of claim 7 , wherein the token and the token authentication cryptogram is sent to the communication device utilizing a token response message.

10. The method of claim 7 , wherein the token and the token authentication cryptogram is sent to an application operating on the communication device.

11. The method of claim 10 , wherein the application is hosted by a resource provider computer.

12. The method of claim 11 , wherein receipt of the token authentication cryptogram causes the application to transmit the token authentication cryptogram in an authorization request message to a transaction processing computer.

13. The method of claim 7 , wherein content of the user exclusive data is specified by the service provider computer.

14. A service provider computer comprising,

a processor, and

a computer readable medium coupled to the processor, the computer readable medium comprising code for causing the processor to perform operations comprising:

sending, to a server computer, a request for a token authentication cryptogram, wherein the request comprises user exclusive data;

receiving, from the server computer, a token and the token authentication cryptogram derived from the user exclusive data, wherein the token authentication cryptogram is generated by encrypting at least the user exclusive data utilizing a triple data encryption algorithm; and

sending, to an application operating on a user device, the token and the token authentication cryptogram with transaction data, wherein the token authentication cryptogram can be used to validate the transaction data, and the user exclusive data is subsequently extracted from the token authentication cryptogram during validation by a processing computer when then uses the user exclusive data for additional analysis.

15. The service provider computer of claim 14 , wherein the user exclusive data comprises at least one of: a resource provider identifier, user preference information, or a user identifier.

16. The service provider computer of claim 14 , wherein the token authentication cryptogram is requested utilizing a token request message.

17. The service provider computer of claim 14 , wherein the token authentication cryptogram is sent to the application in a token response message.

18. The method of claim 1 , wherein the token authentication cryptogram further encrypts the token and a transaction type indicator.

19. The method of claim 1 , further comprising:

receiving, by the processing computer, an authorization request message comprising the token and the token authentication cryptogram;

extracting, by the processing computer, the user exclusive data; and

performing, by the processing computer, the additional analysis on the user exclusive data.

20. The method of claim 1 , wherein the additional analysis comprises performing a fraud analysis on the user exclusive data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 9, 2018
From: CASSIN, MICHAEL; FLURSCHEIM, CHRISTIAN; JONES, CHRISTOPHER
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 044578/0571 →
Continuity (2)
Provisional Application 62354340 · Jun 24, 2016
Related Publication 20170373852A1 · Dec 28, 2017
Cited By (5)
US 12,219,061 US 12,314,374 US 12,475,456 US 12,634,138 US 12,705,618