IP Library › Granted Patent US 12,393,934
Granted Patent B2
US 12,393,934 · App. 15/791,146 · Granted Aug 19, 2025

Method of retaining transaction context

Inventors: Brian Sullivan (London, GB); David Wilson (London, GB); David Harbige (London, GB)
Assignee: VISA EUROPE LIMITED
G06Q20/3821G06Q20/38215G06Q20/3829G06Q20/389G06Q20/40G06Q20/4018G06Q20/409
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,393,934
App. No.
15/791,146
Granted
Aug 19, 2025
Kind
B2
Abstract

Methods of transaction authentication are provided. In one such method, at least one first transaction has been conducted, the or each first transaction generating data including first data comprising authentication data and second data identifying the or each first transaction, wherein a given first transaction is between a merchant and a card holder. A cryptographically signed and/or encrypted token corresponding to the given first transaction and comprising a characteristic of the first transaction has been generated using at least said second data. The cryptographically signed and/or encrypted token has been transmitted to the merchant. The method comprises receiving, from the merchant, data corresponding to a second transaction and in the event that the data corresponding to the second transaction includes the cryptographically signed and/or encrypted token, responsively authenticating the cryptographically signed and/or encrypted token, whereby to determine an authenticated association between the second transaction and a given first transaction.

Claims (45)

1. A method of transaction authentication, the method comprising:

receiving, from a merchant in a first transaction, first data comprising authentication data and second data identifying the first transaction and including a characteristic of the first transaction, the characteristic of the first transaction comprising a transaction identifier or a time and date of the first transaction, and data identifying a specific authentication process in which the merchant authenticates a card holder, wherein the first transaction is between the merchant and the card holder, wherein the merchant is unauthorized to store the first data;

responsive to receiving the first data and the second data, generating a cryptographically signed token corresponding to the first transaction by cryptographically signing the second data such that the cryptographically signed token comprises cryptographically signed (1) the characteristic of the first transaction comprising the transaction identifier or the time and date of the first transaction, and (2) data identifying the specific authentication process;

transmitting the cryptographically signed token to the merchant, the merchant thereafter storing the cryptographically signed token;

receiving, from the merchant, data corresponding to a second transaction and the cryptographically signed token, wherein the data corresponding to the second transaction is devoid of the first data and any additional authentication data;

authenticating the cryptographically signed token by cryptographically validating the cryptographically signed token using a public key of a public key certificate, wherein a successful authentication of the cryptographically signed token confers confidence that the first transaction has genuinely occurred and was successfully authenticated since the cryptographically signed token was generated using data identifying the specific authentication process associated with the first transaction, thereby

determining that an authenticated association exists between the second transaction and the first transaction based on the successful authentication of the cryptographically signed token using the public key; and

authorizing the second transaction when the authenticated association exists between the second transaction and the first transaction.

2. The method of claim 1 , further comprising:

transmitting data indicative of a result of the authentication of the cryptographically signed token to a payment card issuer.

3. The method of claim 2 , wherein the second transaction comprises a resubmission of the first transaction.

4. The method of claim 1 , further comprising:

transmitting data indicative of said determined authenticated association to a payment card issuer.

5. The method of claim 1 , wherein the first transaction is an EMV transaction and the authentication data is EMV authentication data.

6. The method of claim 1 , wherein the first transaction is a card-not-present transaction.

7. The method of claim 6 , wherein the authentication data comprises a card security code.

8. The method of claim 1 wherein at least the second transaction is one of a series of recurring transactions, each of the series of recurring transactions occurring in accordance with a pre-determined schedule.

9. The method of claim 1 , wherein the first transaction comprises authorization for a subsequent transaction or transactions including at least the second transaction, and in which at least one of a number, timing, and monetary amount of said subsequent transaction or transactions was unknown when the first transaction was conducted.

10. The method of claim 1 , wherein the characteristic of the first transaction is the transaction identifier.

11. The method of claim 1 , wherein the characteristic of the first transaction is the time and date of the first transaction.

12. The method of claim 1 , wherein the characteristic of the first transaction further includes data regarding channels in which subsequent transactions can occur without further authentication.

13. The method of claim 1 , wherein the first data is received from the merchant via an acquirer bank.

14. The method of claim 13 , wherein the acquirer bank validates details of the first transaction.

15. The method of claim 1 , wherein the characteristic of the first transaction further comprises data identifying the merchant.

16. The method of claim 1 , wherein the authentication process comprises a chip and PIN authentication process.

17. The method of claim 1 , wherein the authentication data comprises a card security code.

18. A non-transitory computer-readable storage medium comprising a set of computer-readable instructions stored thereon, which, when executed by at least one processor cause the at least one processor to perform a method comprising:

receiving, from a merchant in a first transaction, first data comprising authentication data and second data identifying the first transaction and including a characteristic of the first transaction, the characteristic of the first transaction comprising a transaction identifier or a time and date of the first transaction, and data identifying a specific authentication process in which the merchant authenticates a card holder, wherein the first transaction is between the merchant and the card holder, wherein the merchant is unauthorized to store the first data;

responsive to receiving the first data and the second data, generating a cryptographically signed token corresponding to the first transaction by cryptographically signing the second data such that the cryptographically signed token comprises cryptographically signed (1) the characteristic of the first transaction comprising the transaction identifier or the time and date of the first transaction, and (2) data identifying the specific authentication process;

transmitting the cryptographically signed token to the merchant, the merchant thereafter storing the cryptographically signed token;

receiving, from the merchant, data corresponding to a second transaction and the cryptographically signed token, wherein the data corresponding to the second transaction is devoid of the first data and any additional authentication data;

authenticating the cryptographically signed token by cryptographically validating the cryptographically signed token using a public key of a public key certificate, wherein a successful authentication of the cryptographically signed token confers confidence that the first transaction has genuinely occurred and was successfully authenticated since the cryptographically signed token was generated using data identifying the specific authentication process associated with the first transaction, thereby

determining that an authenticated association exists between the second transaction and the first transaction based on a successful authentication of the cryptographically signed token using the public key; and

authorizing the second transaction when the authenticated association exists between the second transaction and the first transaction.

19. Apparatus comprising:

at least one processor; and

at least one memory including computer program instructions

executable by the at least one processor, to perform a method comprising:

receiving, from a merchant in a first transaction, first data comprising authentication data and second data identifying the first transaction and including a characteristic of the first transaction, the characteristic of the first transaction comprising a transaction identifier or a time and date of the first transaction, and data identifying a specific authentication process in which the merchant authenticates a card holder, wherein the first transaction is between the merchant and the card holder, wherein the merchant is unauthorized to store the first data;

responsive to receiving the first data and the second data, generating a cryptographically signed token corresponding to the first transaction by cryptographically signing the second data such that the cryptographically signed token comprises cryptographically signed (1) the first characteristic of the first transaction comprising the transaction identifier or the time and date of the first transaction, and (2) data identifying the specific authentication process;

transmitting the cryptographically signed token to the merchant, the merchant thereafter storing the cryptographically signed token;

receiving, from the merchant, data corresponding to a second transaction and the cryptographically signed token, wherein the data corresponding to the second transaction is devoid of the first data and any additional authentication data;

authenticating the cryptographically signed token by cryptographically validating the cryptographically signed token using a public key of a public key certificate, wherein a successful authentication of the cryptographically signed token confers confidence that the first transaction has genuinely occurred and was successfully authenticated since the cryptographically signed token was generated using data identifying the specific authentication process associated with the first transaction, thereby

determining that an authenticated association exists between the second transaction and the first transaction based on a successful authentication of the cryptographically signed token using the public key; and

authorizing the second transaction based upon the authenticated association exists between the second transaction and the first transaction.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2018
From: SULLIVAN, BRIAN; WILSON, DAVID; HARBIGE, DAVID
To: VISA EUROPE LIMITED
Reel/Frame 045684/0713 →
Priority Claims (1)
GB 1507047 · Apr 24, 2015 · national
Continuity (2)
Continuation PCTGB2016051033 · Apr 13, 2016
Related Publication 20180047019A1 · Feb 15, 2018
References Cited (43)
US 7577585B2 · Horrocks et al. · 2009 [cited by applicant]
US 7983987B2 · Kranzley et al. · 2011 [cited by applicant]
US 9866392B1 · Campagna · 2018 [cited by examiner]
US 10242368B1 · Poole · 2019 [cited by examiner]
US 20020161721A1 · Yuan · 2002 [cited by examiner]
US 20030061171A1 · Gilbert · 2003 [cited by examiner]
US 20050119942A1 · Horrocks et al. · 2005 [cited by applicant]
US 20050156026A1 · Ghosh · 2005 [cited by examiner]
US 20050240522A1 · Kranzley et al. · 2005 [cited by applicant]
US 20050256806A1 · Tien · 2005 [cited by examiner]
US 20090265262A1 · Chaudhari · 2009 [cited by examiner]
US 20100049619A1 · Beck · 2010 [cited by examiner]
US 20110087537A1 · Hanafi · 2011 [cited by examiner]
US 20110161233A1 · Tieken · 2011 [cited by applicant]
US 20110258123A1 · Dawkins et al. · 2011 [cited by applicant]
US 20120259782A1 · Hammad · 2012 [cited by applicant]
US 20130018793A1 · Wong · 2013 [cited by examiner]
US 20130110722A1 · Boding · 2013 [cited by examiner]
US 20130144792A1 · Nilsson · 2013 [cited by examiner]
US 20130311313A1 · Laracey · 2013 [cited by examiner]
US 20140006284A1 · Faith et al. · 2014 [cited by applicant]
US 20140032409A1 · Rosano · 2014 [cited by examiner]
US 20140040144A1 · Plomske · 2014 [cited by examiner]
US 20140040145A1 · Ozvat · 2014 [cited by examiner]
US 20140040148A1 · Ozvat · 2014 [cited by applicant]
US 20140108641A1 · Cheung · 2014 [cited by examiner]
US 20140143144A1 · Ducharme · 2014 [cited by applicant]
US 20140143146A1 · Passanha et al. · 2014 [cited by applicant]
US 20140351147A1 · Castrechini · 2014 [cited by examiner]
US 20150032626A1 · Dill et al. · 2015 [cited by applicant]
US 20150254639A1 · Radu · 2015 [cited by examiner]
US 20150324736A1 · Sheets et al. · 2015 [cited by applicant]
US 20160125402A1 · Lee · 2016 [cited by examiner]
US 20160267480A1 · Metral · 2016 [cited by examiner]
KR 102014005230A · 2014 [cited by applicant]
WO 2011031804A1 · 2011 [cited by applicant]
WO 2015054697 · 2015 [cited by applicant]
Hany Harb et al., SecureSMSPay: Secure SMS Mobile Payment Model, Nov. 25, 2008, IEEE, pp. 1-7 (Year: 2008) [cited by examiner]
United Kingdom Search Report issued Oct. 16, 2015 on related British Application No. GB 1507047.7, filed Apr. 24, 2015. [cited by applicant]
International Search Report issued Jul. 26, 2016 on related PCT Application No. PCT/GB2016/051033, filed Apr. 13, 2016. [cited by applicant]
EESR, EP22152639, May 31, 2022, 8 pages. [cited by applicant]
KR Appln. No. 10-2017-7034122; Notice of Reasons for Rejection; Jan. 16, 2023; 13 pages. [cited by applicant]
Application No. 22152639.5 , European Examination Report, Mailed On Mar. 25, 2025, 9 pages. [cited by applicant]