IP Library Granted Patent US 10,846,677
Granted Patent B2
US 10,846,677 · App. 16/245,813 · Granted Nov 24, 2020

System and method for secure detokenization

Inventors: Christian Andreas McMahon (Annapolis, MD); Michael Paul Ryan (Cedar Park, TX); Ketul Mayurbhai Shah (Glen Burnie, MD)
Assignee: MERCHANT LINK, LLC
G06Q20/206G06Q20/40H04L63/0807H04L63/123
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,846,677
App. No.
16/245,813
Granted
Nov 24, 2020
Kind
B2
Abstract

A system for accessing protected data comprising a token retriever system operating on a processor and configured to receive a token from a user and to transmit a request including the token to a detokenization system over a data communications medium. The detokenization system configured to receive the token, to verify that the request has been received from an authorized source, and to transmit a response to the request that includes an account number associated with the token. The token retriever system is configured to receive the account number and to display the account number for a predetermined period of time.

Claims (47)

1. A system for accessing protected data comprising:

a token retriever system operating on a first processor and configured to receive a token from a user and to transmit a request including the token to a detokenization system over a data communications medium;

the detokenization system operating on a second processor and configured to receive the token, to verify that the request has been received from an authorized source, and to transmit a response to the request that includes an account number associated with the token; and

wherein the token retriever system is configured to receive the account number and to display the account number for a predetermined period of time.

2. The system of claim 1 wherein the token retriever system is configured to receive an access device and to determine whether the access device is associated with an authorized user.

3. The system of claim 1 wherein the detokenization system further comprises a limit system configured to limit a number of detokenization procedures from the token retriever system within a predetermined period of time.

4. The system of claim 1 wherein the detokenization system further comprises a terminal management system configured to interface with the token retriever system and to authenticate the token retriever system.

5. The system of claim 1 wherein the detokenization system further comprises a terminal management system configured to interface with the token retriever system and to replace a security certificate at the token retriever system.

6. The system of claim 1 wherein the detokenization system further comprises a terminal management system configured to interface with the token retriever system and to determine a state of operation of the token retriever system.

7. The system of claim 1 wherein the detokenization system further comprises a security access system configured to interface with the token retriever system and an access device and to determine whether the access device is associated with an authorized user.

8. The system of claim 1 wherein the token retriever system further comprises a first security access system configured to interface with an access device and to determine whether the access device is associated with an authorized user, and the detokenization system further comprises a second security access system configured to interface with the first security access system and the access device and to determine whether the access device is associated with an authorized user.

9. A method for accessing protected data comprising:

receiving a token from a user at a token retriever system operating on a first processor;

transmitting a request including the token from the token retriever system to a detokenization system over a data communications medium;

receiving the token at the detokenization system;

verifying that the request has been received from an authorized source;

transmitting a response to the request that includes an account number associated with the token; and

receiving the account number at the token retriever system; and

displaying the account number for a predetermined period of time.

10. The method of claim 9 further comprising:

receiving an access device at the token retriever system; and

determining whether the access device is associated with an authorized user.

11. The method of claim 9 further comprising limiting a number of detokenization procedures from the token retriever system within a predetermined period of time.

12. The method of claim 9 further comprising interfacing with the token retriever system using a terminal management system to authenticate the token retriever system.

13. The method of claim 9 further comprising interfacing with the token retriever system to replace a security certificate at the token retriever system.

14. The method of claim 9 further comprising interfacing with the token retriever system to determine a state of operation of the token retriever system.

15. The method of claim 9 further comprising interfacing with the token retriever system and an access device to determine whether the access device is associated with an authorized user.

16. The method of claim 9 further comprising:

interfacing with an access device at a detokenization system to determine whether the access device is associated with an authorized user; and

interfacing with the detokenization system and the access device and to determine whether the access device is associated with the authorized user.

17. In a system for accessing protected data having a token retriever system operating on a first processor and configured to receive a token from a user and to transmit a request including the token to a detokenization system over a data communications medium, the detokenization system operating on a second processor and configured to receive the token, to verify that the request has been received from an authorized source, and to transmit a response to the request that includes an account number associated with the token, and wherein the token retriever system is configured to receive the account number and to display the account number for a predetermined period of time, wherein the token retriever system is configured to receive an access device and to determine whether the access device is associated with an authorized user, wherein the detokenization system further comprises a limit system configured to limit a number of detokenization procedures from the token retriever system within a predetermined period of time, wherein the detokenization system further comprises a terminal management system configured to interface with the token retriever system and to authenticate the token retriever system, wherein the terminal management system is configured to interface with the token retriever system and to replace a security certificate at the token retriever system, wherein the terminal management system configured to interface with the token retriever system and to determine a state of operation of the token retriever system, wherein the detokenization system further comprises a security access system configured to interface with the token retriever system and the access device and to determine whether the access device is associated with an authorized user, wherein the token retriever system further comprises a first security access system configured to interface with the access device and to determine whether the access device is associated with an authorized user, and the detokenization system further comprises a second security access system configured to interface with the first security access system and the access device and to determine whether the access device is associated with an authorized user, a method for accessing protected data comprising:

receiving a token from a user at a token retriever system operating on a first processor;

transmitting a request including the token from the token retriever system to a detokenization system over a data communications medium;

receiving the token at the detokenization system;

verifying that the request has been received from an authorized source;

transmitting a response to the request that includes an account number associated with the token;

receiving the account number at the token retriever system;

displaying the account number for a predetermined period of time;

receiving an access device at the token retriever system;

determining whether the access device is associated with an authorized user;

limiting a number of detokenization procedures from the token retriever system within a predetermined period of time;

interfacing with the token retriever system using a terminal management system to authenticate the token retriever system;

interfacing with the token retriever system to replace a security certificate at the token retriever system;

interfacing with the token retriever system to determine a state of operation of the token retriever system;

interfacing with the token retriever system and the access device to determine whether the access device is associated with an authorized user;

interfacing with the access device at a detokenization system to determine whether the access device is associated with the authorized user; and

interfacing with the detokenization system and the access device and to determine whether the access device is associated with the authorized user.

Assignments (2)
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT SUPPLEMENT Recorded Sep 10, 2024
From: MERCHANT-LINK, LLC
To: GOLDMAN SACHS BANK USA
Reel/Frame 068920/0583 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2019
From: MCMAHON, CHRISTIAN ANDREAS; RYAN, MICHAEL PAUL; SHAH, KETUL MAYURBHAI
To: MERCHANT LINK, LLC
Reel/Frame 047969/0697 →