IP Library › Granted Patent US 11,694,187
Granted Patent B2
US 11,694,187 · App. 16/503,142 · Granted Jul 4, 2023

Constraining transactional capabilities for contactless cards

Inventors: Jeffrey Rule (Chevy Chase, MD); Paul Moreton (Glen Allen, VA); Wayne Lutz (Fort Washington, MD)
Assignee: Capital One Services, LLC
G06Q20/352G06K19/0723G06Q20/202G06Q20/3224G06Q20/3829G06Q20/409G06Q20/4018H04L9/088G06Q2220/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,694,187
App. No.
16/503,142
Granted
Jul 4, 2023
Kind
B2
Abstract

Systems, methods, articles of manufacture, and computer-readable media. A communications interface may receive an indication that a server preauthorized a transaction. The communications interface may receive, from a point of sale device, an indication to pay for the transaction. The contactless card may determine, based on rules stored in the memory, that the location of the mobile device is within one or more locations the contactless card is permitted for use. The contactless card may generate transaction data comprising: indications of an account number and an expiration date of the contactless card, and the indication of the preauthorization. The contactless card may transmit the transaction data to the POS device as payment for the transaction. The server may authorize payment for the transaction using at least a portion of the transaction data based at least in part on identifying the indication of the preauthorization in the transaction data.

Claims (90)

1. A non-transitory computer-readable storage medium storing executable computer-readable program code that when executed by a processor causes the processor to perform the steps of:

receiving a request from an account application of a mobile device, the request comprising encrypted data and location data, the location data associated with the mobile device;

decrypting the encrypted data using a cryptographic algorithm and a key, wherein the key is associated with a contactless card;

determining, based on one or more rules associated with an account and the decryption of the encrypted data, that the location data is within a threshold distance of one or more locations the contactless card is permitted for use;

preauthorizing a transaction based on the decryption of the encrypted data and the determination that the location data is within the threshold distance of the one or more locations the contactless card is permitted for use;

selecting a first level of preauthorization for the transaction from a plurality of levels of preauthorization based on the decryption of the encrypted data and the determination that the location data is within the threshold distance of the one or more locations the contactless card is permitted for use;

storing an indication of the preauthorization for the transaction, the indication comprising: (i) the first level of preauthorization, (ii) a timestamp of the preauthorization, and (iii) the location data, wherein the indication of the preauthorization is one of a plurality of indications of preauthorization, wherein each indication of preauthorization is for a respective transaction of a plurality of transactions including the transaction, wherein each indication of preauthorization further comprises a unique identifier of the respective indication of preauthorization;

transmitting, to the account application, the indication of the preauthorization for the transaction;

receiving, from a point of sale (POS) device, transaction data comprising: (i) an indication of an account number of the contactless card, (ii) an indication of an expiration date of the contactless card, and (iii) the indication of the preauthorization of the transaction, wherein the indication of the preauthorization of the transaction is received by the POS device from the contactless card, wherein the transaction data comprises an EMV payload;

identifying the indication of the preauthorization of the transaction in a first field of the EMV payload;

identifying the indication of the account number, the indication of the expiration date, and an indication of a card verification value (CVV) in one or more other fields of the EMV payload;

determining that the unique identifier of the indication of the preauthorization of the transaction in the EMV payload matches the unique identifier of the stored indication of the preauthorization for the transaction; and

approving the transaction based at least in part on the determination that the unique identifier of the indication of the preauthorization of the transaction in the EMV payload matches the unique identifier of the stored indication of the preauthorization for the transaction.

2. The non-transitory computer-readable storage medium of claim 1 , the computer-readable program code that when executed by the processor to cause the processor to perform the steps of:

comparing the unique identifier of the stored indication of the preauthorization of the transaction to the unique identifier of the indication of the preauthorization of the transaction in the first field of the EMV payload; and

determining, based on the comparison, that the unique identifier of the stored indication of the preauthorization of the transaction matches the unique identifier of the indication of the preauthorization of the transaction in the first field of the EMV payload.

3. The non-transitory computer-readable storage medium of claim 2 , the computer-readable program code that when executed by the processor to cause the processor to perform the step of:

prior to storing the indication of the preauthorization for the transaction, selecting a second level of preauthorization of the plurality of levels of preauthorization for the transaction based on: (i) completion of multi-factor authentication for the account and (ii) the one or more rules,

wherein the stored indication of the preauthorization for the transaction comprises the second level of preauthorization.

4. The non-transitory computer-readable storage medium of claim 3 , the non-transitory computer-readable storage medium the computer-readable program code that when executed by the processor to cause the processor to perform the steps of:

determining, that the location data is within the threshold distance of a location of the POS device; and

transmitting an indication of approval for the transaction to the POS device.

5. The non-transitory computer-readable storage medium of claim 3 , the computer-readable program code that when executed by the processor to cause the processor to perform the steps of the steps of:

receiving a current time associated with the transaction;

determining a time difference between the current time and the timestamp of the preauthorization; and

determining, based on the one or more rules associated with the account, that the time difference is within a threshold amount of time, wherein the transaction is further approved based on the determination that the time difference is within the threshold amount of time.

6. The non-transitory computer-readable storage medium of claim 1 , the computer-readable program code that when executed by the processor to cause the processor to perform the steps of:

receiving, from the POS device, an indication of an amount of the transaction; and

determining, based on the one or more rules associated with the account, that the amount of the transaction is less than a maximum spend amount.

7. A method, comprising:

receiving, by a server, a request from an account application of a mobile device, the request comprising encrypted data and location data, the location data associated with the mobile device;

decrypting, by the server, the encrypted data using a cryptographic algorithm and a key, wherein the key is associated with a contactless card;

determining, by the server based on one or more rules associated with an account and the decryption of the encrypted data, that the location data received is within a threshold distance of one or more locations the contactless card is permitted for use;

preauthorizing, by the server, a transaction based on the decryption of the encrypted data and the determination that the location data is within the threshold distance of the one or more locations the contactless card is permitted for use;

selecting, by the server, a first level of preauthorization for the transaction from a plurality of levels of preauthorization based on the decryption of the encrypted data and the determination that the location data is within the threshold distance of the one or more locations the contactless card is permitted for use;

storing, by the server, an indication of the preauthorization for the transaction, the indication comprising: (i) the first level of preauthorization, (ii) a timestamp of the preauthorization, and (iii) the location data, wherein the indication of the preauthorization is one of a plurality of indications of preauthorization, wherein each indication of pre authorization is for a respective transaction of a plurality of transactions including the transaction, wherein each indication of preauthorization further comprises a unique identifier of the respective indication of preauthorization;

transmitting, by the server to the account application, the indication of the preauthorization for the transaction;

receiving, by the server from a point of sale (POS) device, transaction data comprising: (i) an indication of an account number of the contactless card, (ii) an indication of an expiration date of the contactless card, and (iii) the indication of the preauthorization of the transaction, wherein the indication of the preauthorization of the transaction is received by the POS device from the contactless card, wherein the transaction data comprises an EMV payload;

identifying, by the server, the indication of the preauthorization of the transaction in a first field of the EMV payload;

identifying, by the server, the indication of the account number, the indication of the expiration date, and an indication of a card verification value (CVV) in one or more other fields of the EMV payload;

determining, by the server, that the unique identifier of the indication of the pre authorization of the transaction in the EMV payload matches the unique identifier of the stored indication of the preauthorization for the transaction; and

approving the transaction by the server based at least in part on the determination that the unique identifier of the indication of the preauthorization of the transaction in the EMV payload matches the unique identifier of the stored indication of the preauthorization for the transaction.

8. The method of claim 7 , wherein the plurality of levels of preauthorization are distinct from the account number of the contactless card.

9. The method of claim 8 , wherein approving the transaction further comprises:

comparing, by the server, the unique identifier of the stored indication of the preauthorization of the transaction to the unique identifier of the indication of the preauthorization of the transaction in the first field of the EMV payload;

determining, by the server based on the comparison, that the unique identifier of the stored indication of the preauthorization of the transaction matches the unique identifier of the indication of the preauthorization of the transaction in the first field of the EMV payload;

comparing, by the server, the first level of authorization of the stored indication of the preauthorization of the transaction to the first level of authorization of the indication of the preauthorization of the transaction in the first field of the EMV payload; and

determining, by the server based on the comparison, that the first level of authorization of the stored indication of the preauthorization of the transaction matches the first level of authorization of the indication of the preauthorization of the transaction in the first field of the EMV payload.

10. The method of claim 9 , further comprising:

prior to storing the indication of the preauthorization for the transaction, selecting, by the server, a second level of preauthorization of the plurality of levels of preauthorization for the transaction based on: (i) completion of multi-factor authentication for the account and (ii) the one or more rules; and

storing the indication of the preauthorization in a memory of the contactless card,

wherein the stored indication of the preauthorization for the transaction comprises the second level of preauthorization.

11. The method of claim 9 , wherein the server receives the EMV payload and location data describing a location of the POS device from the POS device, the method further comprising:

determining, by the server, that the location data is within the threshold distance of the location of the POS device; and

transmitting an indication of approval for the transaction to the POS device.

12. The method of claim 7 , wherein approving the transaction further comprises:

receiving, by the server, a current time associated with the transaction;

determining a time difference between the current time and the timestamp of the preauthorization;

determining, by the server based on the one or more rules associated with the account, that the time difference is within a threshold amount of time;

receiving, by the server from the POS device, an indication of an amount of the transaction; and

determining, by the server based on the one or more rules associated with the account, that the amount of the transaction is less than a maximum spend amount associated with the contactless card.

13. An apparatus, comprising:

a processor circuit; and

a memory storing instructions which when executed by the processor circuit, cause the processor circuit to perform the steps of:

receiving a request from an account application of a mobile device, the request comprising encrypted data and location data, the location data associated with the mobile device;

decrypting the encrypted data using a cryptographic algorithm and a key, wherein the key is associated with a contactless card;

determining, based on one or more rules associated with an account and the decryption of the encrypted data, that the location data is within a threshold distance of one or more locations the contactless card is permitted for use;

preauthorizing a transaction based on the decryption of the encrypted data and the determination that the location data is within the threshold distance of the one or more locations the contactless card is permitted for use;

selecting a first level of preauthorization for the transaction from a plurality of levels of preauthorization based on the decryption of the encrypted data and the determination that the location data is within the threshold distance of the one or more locations the contactless card is permitted for use;

storing an indication of the preauthorization for the transaction, the indication comprising: (i) the first level of preauthorization, (ii) a timestamp of the preauthorization, and (iii) the location data, wherein the indication of the preauthorization is one of a plurality of indications of preauthorization, wherein each indication of preauthorization is for a respective transaction of a plurality of transactions including the transaction, wherein each indication of preauthorization further comprises a unique identifier of the respective indication of preauthorization;

transmitting, to the account application, the indication of the pre authorization for the transaction;

receiving, from a point of sale (POS) device, transaction data comprising: (i) an indication of an account number of the contactless card, (ii) an indication of an expiration date of the contactless card, and (iii) the indication of the preauthorization of the transaction, wherein the indication of the preauthorization of the transaction is received by the POS device from the contactless card, wherein the transaction data comprises an EMV payload;

identifying the indication of the preauthorization of the transaction in a first field of the EMV payload;

identifying the indication of the account number, the indication of the expiration date, and an indication of a card verification value (CVV) in one or more other fields of the EMV payload;

determining that the unique identifier of the indication of the preauthorization of the transaction in the EMV payload matches the unique identifier of the stored indication of the pre authorization for the transaction; and

approving the transaction based at least in part on the determination that the unique identifier of the indication of the preauthorization of the transaction in the EMV payload matches the unique identifier of the stored indication of the pre authorization for the transaction.

14. The apparatus of claim 13 , the memory storing instructions which when executed by the processor circuit, cause the processor circuit to perform the steps of:

comparing the unique identifier of the stored indication of the preauthorization of the transaction to the unique identifier of the indication of the preauthorization of the transaction in the first field of the EMV payload; and

determining, based on the comparison, that the unique identifier of the stored indication of the preauthorization of the transaction matches the unique identifier of the indication of the preauthorization of the transaction in the first field of the EMV payload.

15. The apparatus of claim 14 , the memory storing instructions which when executed by the processor circuit, cause the processor circuit to perform the step of:

prior to storing the indication of the preauthorization for the transaction, selecting a second level of preauthorization of the plurality of levels of preauthorization for the transaction based on: (i) completion of multi-factor authentication for the account and (ii) the one or more rules,

wherein the stored indication of the preauthorization for the transaction comprises the second level of preauthorization.

16. The apparatus of claim 15 , the memory storing instructions which when executed by the processor circuit, cause the processor circuit to, prior to transmitting an indication of approval for the transaction to the POS device, perform the step of:

determining that the location data is within the threshold distance of a location of the POS device.

17. The apparatus of claim 15 , the memory storing instructions which when executed by the processor circuit, cause the processor circuit to perform the steps of:

receiving a current time associated with the transaction;

determining a time difference between the current time and the time stamp of the preauthorization; and

determining, based on the one or more rules associated with the account, that the time difference is within a threshold amount of time, wherein the transaction is further approved based on the determination that the time difference is within the threshold amount of time.

18. The method of claim 7 , wherein decrypting the encrypted data comprises:

determining, by the server, that a customer identifier yielded by decrypting the encrypted data matches a customer identifier associated with the account.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 3, 2019
From: RULE, JEFFREY; MORETON, PAUL; LUTZ, WAYNE
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 049667/0028 →
Continuity (1)
Related Publication 20210004803A1 · Jan 7, 2021