IP Library Granted Patent US 11,710,125
Granted Patent B1
US 11,710,125 · App. 15/925,161 · Granted Jul 25, 2023

Systems and methods for automated validation for proprietary security implementations

Inventor: Amie Jackson (Denver, CO)
Assignee: Worldpay, LLC
G06Q20/4012G06Q20/401G06Q30/0203
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,710,125
App. No.
15/925,161
Granted
Jul 25, 2023
Kind
B1
Abstract

Systems and methods are disclosed for automated validation for proprietary security implementations. One method includes: receiving, from each of a plurality of merchants, a list of security service providers used by the merchant; enabling connection with the each of the security service providers of the received list of security service providers used by the merchant; receiving, from each of the listed security service provider with connection enabled, security service information as it pertains to the merchant of the plurality of merchants; generating a security service profile for each merchant of the plurality of merchants, based on the received security service information from each security service provider of the received list of security service providers of the merchant; and outputting the security service profile of the merchant of the plurality of merchants to an electronic storage medium.

Claims (96)

1 . A computer-implemented method of automated validation for proprietary security implementations, the method comprising:

receiving, by a centralized server, a first list of security service providers from a first merchant and a second list of security service providers from a second merchant, the first list of security service providers and the second list of security service providers received via a communication interface of the centralized server;

enabling, by a portal of the centralized server, a connection with the each of the security service providers of the received first list of security service providers and the received second list of security service providers via the communication interface;

receiving, by the centralized server, security service information from a security service provider with connection enabled, the security service provider with connection enabled listed on one of the first list of security service providers and the second list of security service providers, the received security service information pertaining to one of the first merchant and the second merchant;

generating, by a processor of the centralized server, a security service profile for a merchant of the first merchant and the second merchant that comprises an assessment of an extent to which the tools, products, or services implemented by one of the first merchant and the second merchant meets a payment cards industry data security standard (PCI DSS) of a list of system components owned or used by the merchant that store, process, or transmit cardholder data, based on the received security service information from the security service provider with connection enabled;

storing, by the processor of the centralized server, the security service profile of the merchant to an electronic storage medium;

interfering, by the processor of the centralized server, with a payment transaction process involving the merchant to prevent an unsecured transaction, based on the assessment of the security service profile of the merchant indicating that one or more of the tools, the products, or the services implemented by the merchant does not meet the PCI DSS of the list of system components owned or used by the merchant that store, process, or transmit the cardholder data; and

providing, by the processor of the centralized server, a portal allowing an interface for communication with various end users,

wherein the security service information comprises one or more of:

available tools, products, or services offered by the security service provider that increases data security when implemented by the merchant;

the tools, the products, or the services offered by the security service provider that are already being used being provided to the merchant;

configuration or implementation settings of the merchant for the tools, the products, or the services offered by security service provider and implemented by the merchant; and

data security risk assessment of the merchant based on the tools, the products or the services produced by the security service provider and implemented by the merchant.

2 . The method of claim 1 , further comprising,

identifying a questionnaire and/or report pertaining to the PCI DSS of the merchant, wherein the questionnaire and/or report is produced by a source for the data security standards;

receiving from the source for the PCI DSS, the identified questionnaire and/or report;

determining data fields from the received questionnaire and/or report that needs entries;

retrieving, from the electronic storage medium, the security service profile of the merchant;

populating at least some of the determined data fields of the received questionnaire and/or report using the retrieved security service profile of the merchant, to complete or partially complete the questionnaire and/or report; and

transmitting a completed or partially completed questionnaire and/or report to one or more of the merchant or to the source of the PCI DSS.

3 . The method of claim 1 , wherein the security service profile for each merchant comprises one or more of:

the first list of security service providers of the first merchant;

the second list of security service providers of the second merchant;

a list of the tools, the products, or the services offered by the security service providers of and/or implemented by one of the first merchant and the second merchant;

the list of the system components owned or used by one of the first merchant and the second merchant that store, process, or transmit the cardholder data; and

the assessment of an extent to which the tools, the products, or the services implemented by the one of the first merchant and the second merchant meets the PCI DSS of the list of system components owned or used by the merchant that store, process, or transmit the cardholder data.

4 . The method of claim 2 , further comprising, prior to identifying a questionnaire and/or report pertaining to the PCI DSS of the merchant,

receiving a request, from the merchant to complete or partially complete the identified questionnaire and/or report pertaining to data security standards of a merchant.

5 . The method of claim 2 , wherein the identifying a questionnaire and/or report pertaining to the PCI DSS of the merchant is based on a category of one or more categories which the merchant belongs to, the one or more categories comprising one or more of:

card-not-present merchants that outsource cardholder data functions to third party service providers;

E-commerce merchants who outsource cardholder data functions to third party service providers, and who have website(s) that do not directly receive cardholder data;

merchants using imprint machines or standalone dial-out machines with no electronic cardholder data storage;

merchants using only standalone, PTS-approved payment terminals with an IP connection to a payment processor with no electronic cardholder data storage;

merchants having no electronic cardholder data storage, and who manually enter a single transaction at a time via a keyboard into an Internet-based, virtual payment terminal solution that is provided and hosted by a third-party service provider;

merchants with payment application systems connected to the Internet, no electronic cardholder data storage;

merchants using hardware payment terminals included in and managed via a point to point encryption solution, with no electronic cardholder data storage;

merchants not included in the one or more categories; and

security service providers.

6 . The method of claim 2 , wherein:

the questionnaire includes a self assessment questionnaire (SAQ) provided by the PCI DSS; and

the report includes the report on compliance (ROC) provided by the PCI DSS.

7 . The method of claim 1 , wherein the merchant is a security service provider.

8 . A system for automated validation for proprietary security implementations, the system comprising:

a data storage device storing instructions for automated validation for proprietary security implementations; and

a processor configured to execute the instructions to perform a method including:

receiving, by a centralized server, from each of a plurality of merchants, a first list of security service providers from used by the a first merchant and a second list of security service providers from a second merchant, the first list of security service providers and the second list of security service providers received via a communication interface of the centralized server;

enabling, by a portal of the centralized server, a connection with the each of the security service providers of the received first list of security service providers and the received second list of security service providers via the communication interface used by the merchant;

receiving, by the centralized server, security service information from each of the listed a security service provider with connection enabled, the security service provider with connection enabled listed on one of the first list of security service providers and the second list of security service providers, the received security service information as it pertains pertaining to one of the first merchant and the second merchant of the plurality of merchants;

generating, by a processor of the centralized server, a security service profile for each one of the first merchant and the second merchant of the plurality of merchants that comprises an assessment of an extent to which tools, products, or services implemented by one of the first merchant and the second merchant meets a payment cards industry data security standard (PCI DSS) of the list of system components owned or used by the merchant that store, process, or transmit cardholder data, based on the received security service information from each the security service provider with connection enabled of the received list of security service providers of the merchant;

storing, by the processor of the centralized server, the security service profile for each one of the first merchant and the second merchant of the plurality of merchants to an electronic storage medium; and

interfering, by the centralized server, with a payment transaction process involving the merchant to prevent an unsecured transaction, based on the assessment of the security service profile of the merchant indicating that one or more of the tools, the products, or the services implemented by the merchant does not meet the PCI DSS of the list of system components owned or used by the merchant that store, process, or transmit the cardholder data,

wherein the security service information comprises one or more of:

available tools, products, or services offered by the security service provider that increases data security when implemented by the merchant;

the tools, the products, or the services offered by the security service provider that are already being used being provided to the merchant;

configuration or implementation settings of the merchant for the tools, the products, or the services offered by security service provider and implemented by the merchant; and

data security risk assessment of the merchant based on the tools, the products or the services produced by the security service provider and implemented by the merchant.

9 . The system of claim 8 , further comprising,

the system components owned or used by each of a plurality of merchants that store, process, or transmit the cardholder data;

security service providers that offer the tools, the products, or the services to merchants to comply with the PCI DSS; and

a source for the PCI DSS.

10 . The system of claim 8 , wherein the processor is further configured for:

identifying a questionnaire and/or report pertaining to the PCI DSS of a merchant of the plurality of merchants, wherein the questionnaire and/or report is produced by a source for the PCI DSS;

receiving from the source for the PCI DSS, the identified questionnaire and/or report;

determining data fields from the received questionnaire and/or report that needs entries;

retrieving, from the electronic storage medium, the security service profile of the merchant;

populating at least some of the determined data fields of the received questionnaire and/or report using the retrieved security service profile of the merchant, to complete or partially complete the questionnaire and/or report; and

transmitting a completed or partially completed questionnaire and/or report to one or more of the merchant or to the source of the PCI DSS.

11 . The system of claim 8 , wherein the security service profile for a merchant of the first merchant and the second merchant comprises one or more of:

the list of security service providers of the merchant;

a list of the tools, the products, or the services offered by the security service providers of the merchant, and implemented by the merchant;

the list of system components owned or used by the merchant that store, process, or transmit the cardholder data; and

the assessment of an extent to which the tools, the products, or the services implemented by the merchant meet the PCI DSS of the list of system components owned or used by the merchant that store, process, or transmit the cardholder data.

12 . The system of claim 10 , wherein the processor is further configured for, prior to identifying a questionnaire and/or report pertaining to the PCI DSS of a merchant of the first merchant and the second merchant, receiving a request, from a merchant to complete or partially complete the identified questionnaire and/or report pertaining to data security standards of a merchant.

13 . The system of claim 10 , wherein:

the questionnaire includes a self assessment questionnaire (SAQ) provided by the PCI DSS; and

the report includes the report on compliance (ROC) provided by the PCI DSS.

14 . The system of claim 8 , wherein one or more of the first merchant and the second merchant is a security service provider.

15 . A non-transitory machine-readable medium storing instructions that, when executed by a processor, cause the processor to perform a method for automated validation for proprietary security implementations, the method including:

receiving, by a centralized server, a first list of security service providers from a first merchant and a second list of security service providers from a second merchant, the first list of security service providers and the second list of security service providers received via a communication interface of the centralized server;

enabling, by a portal of the centralized server, a connection with the each of the security service providers of the received first list of security service providers and the received second list of security service providers via the communication interface used by the merchant;

receiving, by the centralized server, security service information from a security service provider with connection enabled, the security service provider with connection enabled listed on one of the first list of security service providers and the second list of security service providers, the received security service information pertaining to one of the first merchant and the second merchant;

generating, by a processor of the centralized server, a security service profile for a merchant of the first merchant and the second merchant that comprises an assessment of an extent to which tools, products, or services implemented by one of the first merchant and the second merchant meets a payment cards industry data security standard (PCI DSS) of the list of system components owned or used by the merchant that store, process, or transmit cardholder data, based on the received security service information from the security service provider with connection enabled;

storing, by the processor of the centralized server, the security service profile of the merchant to an electronic storage medium; and

interfering, by the processor of the centralized server, with a payment transaction process involving the merchant to prevent an unsecured transaction, based on the assessment of the security service profile of the merchant indicating that one or more of the tools, the products, or the services implemented by the merchant does not meet the PCI DSS of the list of system components owned or used by the merchant that store, process, or transmit the cardholder data

wherein the security service information comprises one or more of:

available tools, products, or services offered by the security service provider that increases data security when implemented by the merchant;

the tools, the products, or the services offered by the security service provider that are already being used being provided to the merchant;

configuration or implementation settings of the merchant for the tools, the products, or the services offered by security service provider and implemented by the merchant; and

data security risk assessment of the merchant based on the tools, the products or the services produced by the security service provider and implemented by the merchant.

16 . The non-transitory machine-readable medium of claim 15 , further comprising,

identifying a questionnaire and/or report pertaining to the PCI DSS of a merchant, wherein the questionnaire and/or report is produced by a source for the PCI DSS;

receiving from the source for the data security standards, the identified questionnaire and/or report;

determining data fields from the received questionnaire and/or report that needs entries;

retrieving, from the electronic storage medium, the security service profile of the merchant;

populating at least some of the determined data fields of the received questionnaire and/or report using the retrieved security service profile of the merchant, to complete or partially complete the questionnaire and/or report; and

transmitting a completed or partially completed questionnaire and/or report to one or more of the merchant or to the source of the PCI DSS.

Assignments (6)
RELEASE OF SECURITY INTERESTS RECORDED AT REEL/FRAMES 066626/0655, 066625/0426, 066625/0347, AND 066625/0276 Recorded Jan 12, 2026
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: WORLDPAY, LLC; WORLDPAY ISO AND ECOMMERCE, LLC; PAYMETRIC, LLC; WORLDPAY US, LLC
Reel/Frame 074314/0622 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT R/F 066624/0719 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: WORLDPAY, LLC
Reel/Frame 074315/0412 →
SECURITY INTEREST Recorded Feb 19, 2024
From: WORLDPAY, LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066624/0719 →
SECURITY INTEREST Recorded Feb 19, 2024
From: WORLDPAY, LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 066626/0655 →
CHANGE OF NAME Recorded Aug 6, 2018
From: VANTIV, LLC
To: WORLDPAY, LLC
Reel/Frame 046723/0234 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 19, 2018
From: JACKSON, AMIE
To: VANTIV, LLC
Reel/Frame 045277/0186 →