IP Library Granted Patent US 10,496,998
Granted Patent B1
US 10,496,998 · App. 15/980,175 · Granted Dec 3, 2019

Generating a random verification code for a transaction

Inventors: Joshua Edwards (Philadelphia, PA); Abdelkadar M'Hamed Benkreira (Washington, DC); Michael Mossoba (Arlington, VA)
Assignee: Capital One Services, LLC
G06Q20/4018G06F7/582G06Q20/382
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,496,998
App. No.
15/980,175
Granted
Dec 3, 2019
Kind
B1
Abstract

A device receives, from a user device, a request to generate a verification code for a transaction associated with a user of the user device, and receives user profile information associated with a transaction card to be used for the transaction. The device generates a random verification code for the transaction based on the request and the user profile information, and authenticates the random verification code, based on the user profile information, to generate an authenticated random verification code. The device provides the authenticated random verification code to the user device, and receives transaction information, including the authenticated random verification code, from a merchant device associated with the transaction. The device validates the transaction based on the transaction information, and provides, to the merchant device associated with the transaction, information indicating that the transaction is validated.

Claims (123)

1. A device, comprising:

one or more memories; and

one or more processors configured to:

receive, from an application associated with a user device, a request to generate a verification code for a transaction associated with a user of the user device,

wherein the verification code is a card verification value (CVV), and

wherein the request is received based on a user selection of a command that causes the user device to request generation of the verification code;

receive user profile information associated with a transaction card to be used for the transaction;

generate, based on the request and using a random number generator, a random verification code for the transaction based on the request and the user profile information;

authenticate the random verification code, based on the user profile information, to generate an authenticated random verification code;

update a dynamically updatable record associated with an account of the user to associate the authenticated random verification code with the account;

provide the authenticated random verification code to the user device, wherein providing the authenticated random verification code to the user device comprises:

providing the authenticated random verification code to the user device via the application to cause the application to populate, with the authenticated random verification code, a transaction form associated with the transaction;

receive transaction information, including the authenticated random verification code, from a merchant device associated with the transaction;

validate the transaction based on the authenticated random verification code and the updated record; and

provide, to the merchant device associated with the transaction, information indicating that the transaction is validated.

2. The device of claim 1 , wherein the user profile information includes one or more of:

information identifying the transaction card,

information identifying the account,

information indicating that the verification code is to be used for the transaction,

information indicating that the verification code is to be used for a particular time period, or

information indicating the particular time period.

3. The device of claim 1 , wherein

the random number generator includes one or more of:

a pseudorandom number generator,

a hardware random number generator,

a cryptographically-secure pseudorandom number generator, or

a random number generator that uses external entropy.

4. The device of claim 1 , wherein:

the user device is a mobile device, and

the application is a mobile device application associated with the mobile device; and

wherein the one or more processors, when providing the authenticated random verification code to the user device, are configured to:

provide the authenticated random verification code to the mobile device via the mobile device application or a text message.

5. The device of claim 1 , wherein:

the user device is a computer device, and

the application is a browser application associated with the computer device; and

wherein the one or more processors, when providing the authenticated random verification code to the user device, are configured to:

provide the authenticated random verification code to the computer device via the browser application, a browser extension, a browser plugin, or an email.

6. The device of claim 1 , wherein the user device is a mobile device,

wherein the one or more processors, when receiving, are configured to:

receive the request from a call initiated by the mobile device; and

wherein the one or more processors, when providing the authenticated random verification code to the user device, are configured to:

provide the authenticated random verification code to the mobile device via an interactive voice response to the call.

7. The device of claim 1 , wherein:

the user device is a smart device,

wherein the one or more processors, when receiving the request, are configured to:

receive the request from the smart device based on a voice command provided to the smart device; and

wherein the one or more processors, when providing the authenticated random verification code to the user device, are configured to:

provide the authenticated random verification code to the smart device via a voice response.

8. A non-transitory computer-readable medium storing instructions, the instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the one or more processors to:

receive user profile information associated with generating a verification code for a transaction card to be used for a transaction,

the transaction and the transaction card being associated with a user of a user device,

the user profile information including one or more of:

information identifying the transaction card,

information identifying an account associated with the transaction card,

information indicating that the verification code is to be used for the transaction,

information indicating that the verification code is to be used for a particular time period, or

information indicating the particular time period;

receive, from an application associated with the user device, a request to generate the verification code for the transaction,

wherein the verification code is a card verification value (CVV), and

wherein the request is received based on a user selection of a command that causes the user device to request generation of the verification code;

generate, based on the request and using a random number generator, a random verification code for the transaction based on the request and the user profile information;

authenticate the random verification code, based on the user profile information, to generate an authenticated random verification code;

update a dynamically updatable record associated with the account to associate the authenticated random verification code with the account;

provide the authenticated random verification code to the user device, wherein providing the authenticated random verification code to the user device comprises:

providing the authenticated random verification code to the user device via the application to cause the application to populate, with the authenticated random verification code, a transaction form associated with the transaction;

receive transaction information, including the authenticated random verification code, from a merchant device associated with the transaction;

validate the transaction based on the authenticated random verification code and the updated record;

provide, to the merchant device associated with the transaction, information indicating that the transaction is validated; and

provide, to the user device, information confirming that the transaction is complete.

9. The non-transitory computer-readable medium of claim 8 , wherein

the random number generator includes one or more of:

a pseudorandom number generator,

a hardware random number generator,

a cryptographically-secure pseudorandom number generator, or

a random number generator that uses external entropy.

10. The non-transitory computer-readable medium of claim 8 , wherein the user device is a mobile device, and

wherein the one or more instructions, that cause the one or more processors to provide the authenticated random verification code to the user device, cause the one or more processors to:

provide the authenticated random verification code to the mobile device via a mobile device application or a text message application associated with the mobile device.

11. The non-transitory computer-readable medium of claim 8 , wherein the user device is a computer device, and

wherein the one or more instructions, that cause the one or more processors to provide the authenticated random verification code to the user device, cause the one or more processors to:

provide the authenticated random verification code to the computer device via a browser application, a browser extension, a browser plugin, or an email associated with the computer device.

12. The non-transitory computer-readable medium of claim 8 , wherein the user device is a mobile device, and

wherein the one or more instructions, that cause the one or more processors to provide the authenticated random verification code to the user device, cause the one or more processors to:

provide the authenticated random verification code to the mobile device via an interactive voice response to a call with the mobile device.

13. The non-transitory computer-readable medium of claim 8 , wherein the user device is a smart device, and

wherein the one or more instructions, that cause the one or more processors to provide the authenticated random verification code to the user device, cause the one or more processors to:

provide the authenticated random verification code to the smart device via a voice response to a voice command provided to the smart device.

14. A method comprising:

receiving, by a transaction device and from an application associated with a user device, a request to generate a verification code for a transaction associated with a user of the user device,

wherein the verification code is a card verification value (CVV), and

wherein the request is received based on a user selection of a command that causes the user device to request generation of the verification code;

receiving, by the transaction device, user profile information associated with a transaction card to be used for the transaction;

generating, by the transaction device, based on the request, and using a random number generator, a random verification code for the transaction based on the request and the user profile information;

authenticating, by the transaction device and based on the user profile information, the random verification code, to generate an authenticated random verification code;

updating, by the transaction device, a dynamically updatable record associated with an account of the user to associate the authenticated random verification code with the account;

providing, by the transaction device, the authenticated random verification code to the user device,

wherein providing the authenticated random verification code to the user device comprises:

providing the authenticated random verification code to the user device via the application to cause the application to populate, with the authenticated random verification code, a transaction form associated with the transaction;

receiving, by the transaction device, transaction information, including the authenticated random verification code, from a merchant device associated with the transaction;

validating, by the transaction device, the transaction based on the authenticated random verification code and the updated record; and

providing, by the transaction device and to the merchant device associated with the transaction, information indicating that the transaction is validated.

15. The method of claim 14 , wherein the user profile information includes information indicating that the random verification code is valid for the transaction for a particular time period, and

wherein validating the transaction further comprises:

validating the transaction based on the particular time period having not yet elapsed.

16. The method of claim 14 , wherein the user device is a mobile device, and

wherein receiving the request to generate the verification code comprises:

receiving the request from a mobile device application associated with the mobile device.

17. The method of claim 14 , wherein the user device is a computer device, and

wherein receiving the request to generate the verification code comprises:

receiving the request from a browser application associated with the computer device.

18. The method of claim 14 , wherein the user device is a mobile device, and

wherein receiving the request to generate the verification code comprises:

receiving the request from a call initiated by the mobile device.

19. The method of claim 14 , wherein the user device is a smart device, and

wherein receiving the request to generate the verification code comprises:

receiving the request from the smart device based on a voice command provided to the smart device.

20. The method of claim 14 , wherein the user profile information includes one or more of:

information identifying the transaction card,

information identifying the account,

information indicating that the verification code is to be used for the transaction,

information indicating that the verification code is to be used for a particular time period, or

information indicating the particular time period.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 15, 2018
From: EDWARDS, JOSHUA; BENKREIRA, ABDELKADAR M'HAMED; MOSSOBA, MICHAEL
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 045810/0008 →
Cited By (1)
US 12,373,843