IP Library › Granted Patent US 12,223,502
Granted Patent B2
US 12,223,502 · App. 16/443,169 · Granted Feb 11, 2025

Instant digital issuance

Inventors: Vijay Royyuru (Norristown, PA); Benjamin Rewis, Sr. (Oakland, CA); Lanny Byers (Ridgfield, CT); Renee Goodheart (Midland Park, NJ); Cindy White (Hockessin, DE); Kelly Urban (Omaha, NE); Skyler Fox (Park Ridge, NJ)
Assignee: FIRST DATA CORPORATION
G06Q20/401G06Q2220/00H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,223,502
App. No.
16/443,169
Granted
Feb 11, 2025
Kind
B2
Abstract

Described herein are techniques for facilitating push provisioning of a user payment source into a user's digital wallet without the user having a physical card. The techniques allow an issuer to provide a button in an issuer's mobile application for the user to simply push the button to request that the payment source be imported into the user's digital pay wallet. In this way, the payment source information is “pushed” into the pay wallet. Using push provisioning, the user need not enter any physical card information. The described techniques generate a chain of trust that can be used to ensure that a user, through an issuer and using an encryption gateway, authorizes a token service provider to provision the payment source into the user's digital wallet.

Claims (78)

1. One or more non-transitory computer-readable media comprising computer-readable instructions stored thereon that when executed by one or more processors causes the one or more processors to perform a process for provisioning instant digital access to a user payment source using a mobile device pay wallet comprising:

receiving, at a gateway encryption service, from an issuer mobile application server, user information for a user and account information for provisioning the user payment source;

transmitting, by the gateway encryption service, the user information and the account information to a gateway lookup service to request primary account number data for the user payment source from an issuing host platform;

receiving, at the gateway lookup service, from the issuing host platform, the primary account number data comprising an account number for the user payment source;

encrypting, by the gateway encryption service, the primary account number data to generate encrypted provision data by:

identifying a first set of encryption requirements associated with a token service provider, wherein the first set of encryption requirements include a type of encryption algorithm and a minimum length of an encryption key;

identifying, by the gateway encryption service, an encryption key from a plurality of encryption keys stored in a database using the primary account number data, the encryption key set with token service provider information;

identifying, by the gateway encryption service, a second set of encryption requirements for the mobile device pay wallet using wallet data from the mobile device pay wallet;

ensuring that the encryption key complies with the combination of the first set of encryption requirements and the second set of encryption requirements; and

applying the encryption key set by the token service provider to the primary account number data based on an encryption algorithm and a minimum length of the encryption key identified from the first set of encryption requirements;

transmitting, by the gateway encryption service, the encrypted provision data to the issuer mobile application server.

2. The one or more non-transitory computer-readable media of claim 1 ,

wherein identifying the encryption key comprises:

identifying an issuer using the primary account number data, wherein provision requests for issuers that use the token service provider have data that is encrypted with the encryption key; and

searching the database for the encryption key using the issuer.

3. The one or more non-transitory computer-readable media of claim 1 , wherein encrypting the primary account number data further comprises:

identifying a validation key from a plurality of validation keys using the primary account number data; and

signing, using the validation key, the encrypted provision data.

4. The one or more non-transitory computer-readable media of claim 1 , wherein the user payment source is a credit card or debit card.

5. The one or more non-transitory computer-readable media of claim 1 , wherein the user information for the user and the account information for the user payment source comprise one or more of a name of the user, a digital wallet data of the user, or an issuer nonce.

6. The one or more non-transitory computer-readable media of claim 1 , wherein the primary account number data comprises one or more of a sixteen-digit primary account number of the user payment source, an address of the user, or a nickname of the user payment source.

7. The one or more non-transitory computer-readable media of claim 1 , wherein the one or more processors further execute computer-readable instructions for:

receiving, at an issuer mobile application using a software development kit, a list of accounts for the user, wherein the user payment source is selected from the list of accounts.

8. The one or more non-transitory computer-readable media of claim 1 , wherein the one or more processors further execute computer-readable instructions for:

receiving, at an issuer mobile application using a software development kit, the encrypted provision data;

generating, by the software development kit, a request to provision the user payment source in the mobile pay wallet of the user using the encrypted provision data; and

receiving, by the software development kit, a result of the request to provision the user payment source in the mobile device pay wallet.

9. The one or more non-transitory computer-readable media of claim 1 , wherein the one or more processors further execute computer-readable instructions for:

receiving from the issuer mobile application server, an issuer nonce indicating that the user was authenticated by the issuer mobile application server;

wherein encrypting the primary account number data comprises encrypting the issuer nonce along with the primary account number data.

10. The one or more non-transitory computer-readable media of claim 9 , wherein the one or more processors further execute computer-readable instructions for:

receiving, at the token service provider, the encrypted primary account number data with the issuer nonce;

decrypting, by the token service provider, the encrypted primary account number data and the issuer nonce using the encryption key;

validating, by the token service provider, a signature of the primary account number data with a validation key; and

in response to validating the signature, transmitting, by the token service provider, a provision request comprising the issuer nonce.

11. The one or more non-transitory computer-readable media of claim 1 , wherein the one or more processors further execute computer-readable instructions for:

receiving, by a software development kit, an indication from an issuer mobile application to add the user payment source to the pay wallet, the indication being sent responsive to the issuer mobile application receiving the encrypted provision data from the issuer mobile application server;

transmitting, by the software development kit, the encrypted provision data to a pay wallet upon receiving the indication;

receiving, by the software development kit, a message from the pay wallet in response to transmitting the encrypted provision data to the pay wallet, the message indicating whether the user payment source was successfully provisioned to the pay wallet or not; and

transmitting, by the software development kit, the message to the issuer mobile application for displaying a notification to the user indicating whether the user payment source was provisioned or not.

12. A gateway system comprising:

one or more processors, and

one or more memories having stored thereon computer-readable instructions that, when executed by the one or more processors, cause the one or more processors to:

receive, by a gateway encryption service, from an issuer mobile application server, user information for a user and account information for a payment source of the user;

transmit, by the gateway encryption service, the user information and the account information to a gateway lookup service;

receive, at the gateway lookup service, from an issuing host platform, primary account number data comprising an account number for the payment source;

transmit, by the gateway lookup service, the primary account number data to the gateway encryption service;

encrypt, by the gateway encryption service, the primary account number data using an encryption key associated with a token service provider to generate encrypted provision data,

wherein the encrypting comprises:

identifying

a first set of encryption requirements associated with a token service provider, wherein the first set of encryption requirements include a type of encryption algorithm and a minimum length of an encryption key;

identifying, by the gateway encryption service, an encryption key from a plurality of encryption keys stored in a database using the primary account number data, the encryption key set with token service provider information;

identifying, by the gateway encryption service, a second set of encryption requirements for the mobile device pay wallet using wallet data from the mobile device pay wallet;

ensuring that the encryption key complies with the combination of the first set of encryption requirements and the second set of encryption requirements; and

applying the encryption key set by the token service provider to the primary account number data based on an encryption algorithm and a minimum length of the encryption key identified from the first set of encryption requirements; and

transmitting the encrypted provision data to the issuer mobile application server.

13. The gateway system of claim 12 , wherein

identifying the encryption key comprises:

identifying an issuer using the primary account number data, wherein provision requests for issuers that use the token service provider have data that is encrypted with the encryption key; and

searching the database for the encryption key using the issuer.

14. The gateway system of claim 12 , wherein the user information for the user and the account information for the payment source of the user comprises one or more of a name of the user, a digital wallet data of the user, or an issuer nonce.

15. The gateway system of claim 12 , wherein the primary account number data comprises one or more of a sixteen-digit primary account number of the payment source, an address of the user, or a nickname of the payment source.

16. The gateway system of claim 12 , wherein for encrypting the primary account number data, the one or more processors further execute computer-readable instructions to:

identify a validation key from a plurality of validation keys using the primary account number data; and

sign, using the validation key, the encrypted provision data.

17. The gateway system of claim 12 , wherein the payment source is a credit card or debit card.

18. The gateway system of claim 12 , wherein the one or more processors further execute computer-readable instructions to receive a list of accounts for the user, wherein the payment source is selected from the list of accounts.

19. The gateway system of claim 12 , wherein the one or more processors further execute computer-readable instructions to:

receive, at an issuer mobile application using a software development kit, the encrypted provision data;

generate, by the software development kit, a request to provision the payment source in a mobile device pay wallet of the user using the encrypted provision data; and

receive, by the software development kit, a result of the request to provision the payment source in the mobile device pay wallet.

20. The gateway system of claim 12 , wherein the one or more processors further execute computer-readable instructions to:

receive from the issuer mobile application server an issuer nonce indicating that the user was authenticated by the issuer mobile application server, wherein encrypting the primary account number data comprises encrypting the issuer nonce along with the primary account number data.

21. The gateway system of claim 12 , wherein the one or more processors further execute computer-readable instructions to:

receive, by a software development kit, an indication from an issuer mobile application to add the user payment source to the pay wallet, the indication being sent responsive to the issuer mobile application receiving the encrypted provision data from the issuer mobile application server;

transmit, by the software development kit, the encrypted provision data to a pay wallet upon receiving the indication;

receive, by the software development kit, a message from the pay wallet in response to transmitting the encrypted provision data to the pay wallet, the message indicating whether the user payment source was successfully provisioned to the pay wallet or not; and

transmit, by the software development kit, the message to the issuer mobile application for displaying a notification to the user indicating whether the user payment source was provisioned or not.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 9, 2020
From: ROYYURU, VIJAY; REWIS, BENJAMIN, SR.; BYERS, LANNY; GOODHEART, RENEE; WHITE, CINDY; URBAN, KELLY; FOX, SKYLER
To: FIRST DATA CORPORATION
Reel/Frame 051464/0708 →
Continuity (2)
Provisional Application 62686369 · Jun 18, 2018
Related Publication 20190385164A1 · Dec 19, 2019
References Cited (68)
US 5883810A · Franklin et al. · 1999 [cited by applicant]
US 6456984B1 · Demoff et al. · 2002 [cited by applicant]
US 10146803B2 · Kilby et al. · 2018 [cited by applicant]
US 10460312B1 · Kurani et al. · 2019 [cited by applicant]
US 10467622B1 · Rule et al. · 2019 [cited by applicant]
US 20050173520A1 · Jaros et al. · 2005 [cited by applicant]
US 20080052225A1 · Walker et al. · 2008 [cited by applicant]
US 20090259560A1 · Bachenheimer · 2009 [cited by applicant]
US 20100123003A1 · Olsen et al. · 2010 [cited by applicant]
US 20130144776A1 · Webster et al. · 2013 [cited by applicant]
US 20130151400A1 · Makhotin · 2013 [cited by examiner]
US 20140316826A1 · Nicoara et al. · 2014 [cited by applicant]
US 20140344153A1 · Raj et al. · 2014 [cited by applicant]
US 20150032625A1 · Dill et al. · 2015 [cited by applicant]
US 20150046338A1 · Laxminarayanan et al. · 2015 [cited by applicant]
US 20150073996A1 · Makhotin · 2015 [cited by examiner]
US 20150088756A1 · Makhotin · 2015 [cited by examiner]
US 20150140982A1 · Postrel · 2015 [cited by applicant]
US 20150269566A1 · Gaddam · 2015 [cited by examiner]
US 20150327072A1 · Powell · 2015 [cited by examiner]
US 20150332262A1 · Lingappa · 2015 [cited by examiner]
US 20150356560A1 · Shastry et al. · 2015 [cited by applicant]
US 20160036790A1 · Shastry · 2016 [cited by examiner]
US 20160071094A1 · Krishnaiah et al. · 2016 [cited by applicant]
US 20160078434A1 · Huxham · 2016 [cited by examiner]
US 20160094991A1 · Powell · 2016 [cited by examiner]
US 20160119296A1 · Laxminarayanan · 2016 [cited by examiner]
US 20160140545A1 · Flurscheim · 2016 [cited by examiner]
US 20160173483A1 · Wong · 2016 [cited by examiner]
US 20160260096A1 · Lacoss-Arnold · 2016 [cited by examiner]
US 20160267445A1 · Nano · 2016 [cited by applicant]
US 20160267455A1 · Rewis et al. · 2016 [cited by applicant]
US 20160292673A1 · Chandrasekaran · 2016 [cited by examiner]
US 20160321652A1 · Dimmick et al. · 2016 [cited by applicant]
US 20160328707A1 · Wagner · 2016 [cited by examiner]
US 20160364721A1 · Deliwala · 2016 [cited by examiner]
US 20170032362A1 · Lahkar et al. · 2017 [cited by applicant]
US 20170200165A1 · Laxminarayanan et al. · 2017 [cited by applicant]
US 20180068297A1 · Goodman et al. · 2018 [cited by applicant]
US 20180253718A1 · Khan et al. · 2018 [cited by applicant]
US 20180253727A1 · Ortiz et al. · 2018 [cited by applicant]
US 20180276657A1 · Cho et al. · 2018 [cited by applicant]
US 20190066095A1 · Spector et al. · 2019 [cited by applicant]
US 20190066096A1 · Wouters et al. · 2019 [cited by applicant]
US 20190066102A1 · Powell · 2019 [cited by examiner]
US 20190108514A1 · Pendse · 2019 [cited by examiner]
US 20190385164A1 · Royyuru et al. · 2019 [cited by applicant]
US 20200082371A1 · Laracey · 2020 [cited by applicant]
US 20200118205A1 · Bloy et al. · 2020 [cited by applicant]
US 20200320516A1 · Royyuru et al. · 2020 [cited by applicant]
US 20210117965A1 · Venot et al. · 2021 [cited by applicant]
EP 3292499A1 · 2018 [cited by examiner]
EP 3292499B1 · 2020 [cited by examiner]
KR 101814133 · 2018 [cited by applicant]
KR 101814134 · 2018 [cited by applicant]
WO 2015107442A1 · 2015 [cited by applicant]
WO WO2016178780A1 · 2016 [cited by applicant]
WO WO2017160877A1 · 2017 [cited by applicant]
International Search Report and Written Opinion mailed Sep. 10, 2019 in related foreign application No. PCT/US2019/037654, 7 pgs. [cited by applicant]
Extended European Search Report dated Jun. 28, 2021, EP Patent Application No. 207828989, 10 pages. [cited by applicant]
Extended European Search Report dated Nov. 12, 2021, EP Patent Application No. 19823010.4, 9 pages. [cited by applicant]
International Search Report and Written Opinion dated Jun. 29, 2020, International Application No. PCT/US2020/026352, 10 pages. [cited by applicant]
International Search Report and Written Opinion dated Feb. 11, 2022, International Patent No. PCT/US2021/033110, 13 pages. [cited by applicant]
Non-Final Office Action on U.S. Appl. No. 17/100,909 Dtd Feb. 16, 2023. [cited by applicant]
Office Action and Search Report issued in connection with United Arab Emirates Appl. No. P2001240/2021 dated Sep. 5, 2023. [cited by applicant]
International Preliminary Report on Patentability issued in connection with PCT Appl. No. PCT/US2021/033110 dated Nov. 21, 2023. [cited by applicant]
Office Action and Search Report issued in connection with United Arab Emirates Appl. No. P6001807/2020 dated Nov. 27, 2023. [cited by applicant]
Office Action issued in connection with Colombia Appl. No. NC2023/0015584 dated Nov. 30, 2023. [cited by applicant]