IP Library Granted Patent US 12,380,431
Granted Patent B2
US 12,380,431 · App. 17/750,718 · Granted Aug 5, 2025

Systems, methods and computer program products for asynchronous authentication of digital wallet based payment transactions

Inventors: Vijin Venugopalan (Singapore, SG); Aishwarya Namjoshi (Mumbai, IN); Saket Bhardwaj (Mumbai, IN)
Assignee: Mastercard International Incorporated
G06Q20/3674G06Q20/401G06Q20/409H04L63/0838
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,380,431
App. No.
17/750,718
Granted
Aug 5, 2025
Kind
B2
Abstract

The invention provides systems, methods and computer program products for asynchronous authentication of digital wallet based payment transactions. The invention enables secure authentication of contactless payment card based payment transactions that have been implemented through contactless communication between a payor device and a payment terminal device using near-field-communication. In various embodiments, the invention provides methods, systems, servers, and computer program products for authentication of a contactless communication protocol based digital wallet payment transaction, as substantially described herein.

Claims (104)

1. A method, comprising:

receiving at a payment network validation server from a payment terminal device:

transaction data corresponding to a payment transaction that has been initiated through contactless communication between a payor device and the payment terminal device; and

chip data corresponding to an integrated circuit chip that is implemented within a payment card associated with the payment transaction;

receiving at the payment network validation server from the payor device:

a request for initiating payor authentication; and

a first set of data associated with the payment transaction;

responding, by the payment network validation server, to the request for initiating payor authentication by:

generating a first one-time-password (OTP); and

transmitting to an issuer server associated with the payment card:

the first OTP; and

the first set of data associated with the payment transaction;

thereafter receiving, at the payment network validation server from the payor device, a second set of data associated with the payment transaction, the second set of data comprising a second OTP; and

transmitting, by the payment network validation server, an authentication decision to the issuer server, wherein the authentication decision is based on:

a first validation decision based on a comparison between (i) data from the transaction data and chip data received by the payment network validation server from the payment terminal device; and (ii) data from the first set of data received by the payment network validation server from the payor device; and

a second validation decision based on a comparison between the first OTP generated by the payment network validation server and the second OTP received by the payment network validation server from the payor device, wherein

the payment network validation server is configured for independent network communication with the payor device via a data network and the payment terminal device via an acquirer server.

2. The method as claimed in claim 1 , wherein the issuer server is configured for independent network communication with the payor device distinct from network communication with the payment network validation server; and

wherein the issuer server is configured to:

implement the payment transaction in response to determining that the authentication decision is a positive authentication decision; and

reject the payment transaction in response to determining that the authentication decision is a negative authentication decision.

3. The method as claimed in claim 1 , wherein receiving at the payment network validation server from the payment terminal device comprises:

receiving at the acquirer server from the payment terminal device the transaction data and the chip data, wherein the acquirer server is configured for network communication with the payment network validation server; and

transmitting from the acquirer server to the payment network validation server the transaction data and the chip data, wherein:

the acquirer server is configured for independent network communication with the payment network validation server distinct from network communication with the payor device; and

wherein:

the transaction data received at the payment network validation server from the payment terminal device comprises any one or more of a merchant identifier associated with an intended payee, a merchant category code associated with a payee, a currency associated with the payment transaction, and a payee name; and

the chip data comprises a chip identifier associated with the payment card.

4. The method as claimed in claim 1 , wherein:

the first set of data received from the payor device includes any one or more of a payor digital wallet identifier, a payor digital wallet name, a payment card identifier associated with the payment card, a transaction amount and merchant data; and

the transaction amount and the merchant data have been received at the payor device from the payment terminal device.

5. The method as claimed in claim 4 , wherein the merchant data received at the payor device from the payment terminal device comprises any one or more of a merchant identifier associated with an intended payee, a merchant category code associated with a payee, a currency associated with the payment transaction, and a payee name.

6. The method as claimed in claim 1 , wherein:

the second OTP has been transmitted to the payor device from the issuer server over a first communication network of a first type; and

wherein the second set of data is received from the payor device over a second communication network of a second type, wherein the second type is different from the first type.

7. The method as claimed in claim 6 , wherein:

the first communication network comprises a public switched terminal network; and

the second communication network comprises an internet protocol based data network.

8. The method as claimed in claim 1 , wherein:

the authentication decision is a positive authentication decision in response to each of the first validation decision and the second validation decision comprising a positive match; or

the authentication decision is a negative authentication decision in response to either of the first validation decision and the second validation decision comprising a match failure.

9. A system for authentication of a contactless communication protocol based digital wallet payment transaction, comprising a processor implemented payment network validation server, wherein the processor implemented payment network validation server is configured to:

receive first network communication via an acquirer server from a payment terminal device comprising:

transaction data corresponding to a payment transaction that has been initiated through contactless communication between a payor device and the payment terminal device; and

chip data corresponding to an integrated circuit chip that is implemented within a payment card associated with the payment transaction;

receive second network communication via a data network from the payor device comprising:

a request for initiating payor authentication; and

a first set of data associated with the payment transaction, wherein the payment network validations server is configured to receive the first network communication and second network communications on distinct network paths;

respond to the request for initiating payor authentication by:

generating a first one-time-password (OTP); and

transmitting to an issuer server associated with the payment card:

the first OTP; and

the first set of data associated with the payment transaction;

thereafter receive from the payor device a second set of data associated with the payment transaction, the second set of data comprising a second OTP; and

transmit an authentication decision to the issuer server, wherein the authentication decision is based on:

a first validation decision based on a comparison between (i) data from the transaction data and chip data received by the payment network validation server from the payment terminal device and (ii) data from the first set of data received by the payment network validation server from the payor device; and

a second validation decision based on a comparison between the first OTP generated by the payment network validation server and the second OTP received by the payment network validation server from the payor device.

10. The system of claim 9 , wherein the issuer server is configured to:

implement the payment transaction in response to determining that the authentication decision is a positive authentication decision; and

reject the payment transaction in response to determining that the authentication decision is a negative authentication decision.

11. The system of claim 9 , wherein:

the transaction data received at the payment network validation server from the payment terminal device comprises any one or more of a merchant identifier associated with an intended payee, a merchant category code associated with a payee, a currency associated with the payment transaction, and a payee name;

the chip data comprises a chip identifier associated with the payment card.

12. The system of claim 9 , wherein:

the first set of data received from the payor device includes any one or more of a payor digital wallet identifier, a payor digital wallet name, a payment card identifier associated with the payment card, a transaction amount and merchant data; and

the transaction amount and the merchant data have been received at the payor device from the payment terminal device.

13. The system of claim 9 , wherein:

the second OTP has been transmitted to the payor device from the issuer server over a first communication network of a first type; and

wherein the second set of data is received from the payor device over a second communication network of a second type, wherein the second type is different from the first type.

14. The system of claim 9 , wherein:

the authentication decision is a positive authentication decision in response to each of the first validation decision and the second validation decision comprising a positive match; or

the authentication decision is a negative authentication decision in response to either of the first validation decision and the second validation decision comprising a match failure.

15. A computer program product for authentication of a contactless communication protocol based digital wallet payment transaction, comprising a non-transitory computer readable medium having a computer readable program code embodied therein, the computer readable program code comprising instructions for implementing within a payment network validation server, the steps of:

receiving from a payment terminal device via an acquirer server:

transaction data corresponding to a payment transaction that has been initiated through contactless communication between a payor device and the payment terminal device; and

chip data corresponding to an integrated circuit chip that is implemented within a payment card associated with the payment transaction;

receiving from the payor device via a data network:

a request for initiating payor authentication; and

a first set of data associated with the payment transaction;

responding to the request for initiating payor authentication by:

generating a first one-time-password (OTP); and

transmitting to an issuer server associated with the payment card:

the first OTP; and

the first set of data associated with the payment transaction;

thereafter receiving from the payor device a second set of data associated with the payment transaction, the second set of data comprising a second OTP; and

transmitting an authentication decision to the issuer server, wherein the authentication decision is based on:

a first validation decision based on a comparison between (i) data from the transaction data and chip data received by the payment network validation server from the payment terminal device and (ii) data from the first set of data received by the payment network validation server from the payor device; and

a second validation decision based on a comparison between the first OTP generated by the payment network validation server and the second OTP received by the payment network validation server from the payor device, wherein

the payment network validation server is configured to receive the chip data and the transaction data received from the payment terminal device and the request and the first set of data received from the payor device on independent network paths.

16. The computer program product of claim 15 , wherein the issuer server is configured to:

implement the payment transaction in response to determining that the authentication decision is a positive authentication decision; and

reject the payment transaction in response to determining that the authentication decision is a negative authentication decision.

17. The computer program product of claim 15 , wherein:

the transaction data received at the payment network validation server from the payment terminal device comprises any one or more of a merchant identifier associated with an intended payee, a merchant category code associated with a payee, a currency associated with the payment transaction, and a payee name;

the chip data comprises a chip identifier associated with the payment card.

18. The computer program product of claim 15 , wherein:

the first set of data received from the payor device includes any one or more of a payor digital wallet identifier, a payor digital wallet name, a payment card identifier associated with the payment card, a transaction amount and merchant data; and

the transaction amount and the merchant data have been received at the payor device from the payment terminal device.

19. The computer program product of claim 15 , wherein:

the second OTP has been transmitted to the payor device from the issuer server over a first communication network of a first type; and

wherein the second set of data is received from the payor device over a second communication network of a second type, wherein the second type is different from the first type.

20. The computer program product of claim 15 , wherein:

the authentication decision is a positive authentication decision in response to each of the first validation decision and the second validation decision comprising a positive match; or

the authentication decision is a negative authentication decision in response to either of the first validation decision and the second validation decision comprising a match failure.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 23, 2022
From: VENUGOPALAN, VIJIN; NAMJOSHI, AISHWARYA; BHARDWAJ, SAKET
To: MASTERCARD INTERNATIONAL INCORPORATED
Reel/Frame 059989/0513 →
Priority Claims (1)
IN 202111023158 · May 24, 2021 · national
Continuity (1)
Related Publication 20220374873A1 · Nov 24, 2022
References Cited (165)
US 6000832A · Franklin · 1999 [cited by applicant]
US 6327578B1 · Linehan · 2001 [cited by applicant]
US 6434238B1 · Chaum et al. · 2002 [cited by applicant]
US 7027773B1 · McMillin · 2006 [cited by applicant]
US 7357309B2 · Ghosh · 2008 [cited by applicant]
US 7657748B2 · Gentry · 2010 [cited by applicant]
US 8720771B2 · MacKinnon · 2014 [cited by applicant]
US 9195984B1 · Spector · 2015 [cited by examiner]
US 9262651B2 · Paulsen · 2016 [cited by applicant]
US 9595030B2 · Ekselius · 2017 [cited by applicant]
US 9674892B1 · Li · 2017 [cited by applicant]
US 9741036B1 · Grassadonia · 2017 [cited by applicant]
US 9774401B1 · Borrill · 2017 [cited by applicant]
US 10496856B2 · Palermo · 2019 [cited by applicant]
US RE47894E · Wang · 2020 [cited by applicant]
US 10706400B1 · Puffer et al. · 2020 [cited by applicant]
US 10902423B2 · Radu et al. · 2021 [cited by applicant]
US 10963871B2 · Safak et al. · 2021 [cited by applicant]
US 11074564B2 · Gurunathan et al. · 2021 [cited by applicant]
US 11080697B2 · Lakka et al. · 2021 [cited by applicant]
US 11080713B2 · Kohli · 2021 [cited by applicant]
US 11093938B2 · Parekh · 2021 [cited by applicant]
US 11107078B2 · Mariappan et al. · 2021 [cited by applicant]
US 11157896B2 · Nwokolo et al. · 2021 [cited by applicant]
US 11301865B2 · Tang · 2022 [cited by applicant]
US 11544781B2 · Dogin · 2023 [cited by applicant]
US 20040019571A1 · Hurwitz · 2004 [cited by applicant]
US 20060049258A1 · Pikivi · 2006 [cited by applicant]
US 20060219776A1 · Finn · 2006 [cited by applicant]
US 20060283960A1 · Top · 2006 [cited by applicant]
US 20070022058A1 · Labrou et al. · 2007 [cited by applicant]
US 20070125840A1 · Law et al. · 2007 [cited by applicant]
US 20080071681A1 · Khalid · 2008 [cited by applicant]
US 20090048971A1 · Hathaway et al. · 2009 [cited by applicant]
US 20090104888A1 · Cox · 2009 [cited by applicant]
US 20110022521A1 · Collinge et al. · 2011 [cited by applicant]
US 20110178884A1 · Teicher et al. · 2011 [cited by applicant]
US 20110184867A1 · Varadarajan · 2011 [cited by applicant]
US 20110215159A1 · Jain · 2011 [cited by applicant]
US 20110238573A1 · Varadarajan · 2011 [cited by examiner]
US 20120036360A1 · Bassu et al. · 2012 [cited by applicant]
US 20120084836A1 · Mahaffey et al. · 2012 [cited by applicant]
US 20120116902A1 · Cardina et al. · 2012 [cited by applicant]
US 20130212007A1 · Mattsson · 2013 [cited by applicant]
US 20130212025A1 · Tanner · 2013 [cited by applicant]
US 20130262296A1 · Thomas et al. · 2013 [cited by applicant]
US 20130297508A1 · Belamant · 2013 [cited by applicant]
US 20140040139A1 · Brudnicki · 2014 [cited by applicant]
US 20140061302A1 · Hammad · 2014 [cited by applicant]
US 20140138435A1 · Khalid · 2014 [cited by applicant]
US 20140189359A1 · Marien · 2014 [cited by applicant]
US 20140191031A1 · Paulsen · 2014 [cited by applicant]
US 20140258135A1 · Park · 2014 [cited by applicant]
US 20140279556A1 · Priebatsch et al. · 2014 [cited by applicant]
US 20140358777A1 · Gueh · 2014 [cited by applicant]
US 20150032627A1 · Dill et al. · 2015 [cited by applicant]
US 20150032636A1 · Wedekind · 2015 [cited by applicant]
US 20150046339A1 · Wong · 2015 [cited by applicant]
US 20150112870A1 · Nagasundaram et al. · 2015 [cited by applicant]
US 20150137949A1 · Rofougaran et al. · 2015 [cited by applicant]
US 20150142673A1 · Nelsen et al. · 2015 [cited by applicant]
US 20150262180A1 · Hambleton · 2015 [cited by applicant]
US 20150269566A1 · Gaddam et al. · 2015 [cited by applicant]
US 20150294305A1 · Wang · 2015 [cited by applicant]
US 20150302390A1 · Huxham et al. · 2015 [cited by applicant]
US 20150310425A1 · Cacioppo · 2015 [cited by applicant]
US 20160065370A1 · Le Saint · 2016 [cited by examiner]
US 20160071095A1 · Foerster et al. · 2016 [cited by applicant]
US 20160117715A1 · Gross et al. · 2016 [cited by applicant]
US 20160217467A1 · Smets et al. · 2016 [cited by applicant]
US 20160224971A1 · Aabye · 2016 [cited by applicant]
US 20160307186A1 · Noe · 2016 [cited by applicant]
US 20170091758A1 · Kim et al. · 2017 [cited by applicant]
US 20170178090A1 · Sarin · 2017 [cited by applicant]
US 20170330181A1 · Ortiz · 2017 [cited by applicant]
US 20170330184A1 · Sabt · 2017 [cited by examiner]
US 20170344974A1 · Britt · 2017 [cited by applicant]
US 20180005231A1 · Grassadonia et al. · 2018 [cited by applicant]
US 20180047016A1 · Sarin · 2018 [cited by applicant]
US 20180232734A1 · Smets et al. · 2018 [cited by applicant]
US 20180349907A1 · Dixon · 2018 [cited by applicant]
US 20190026716A1 · Anbukkarasu · 2019 [cited by applicant]
US 20190034929A1 · Tang et al. · 2019 [cited by applicant]
US 20190066097A1 · Mackie · 2019 [cited by applicant]
US 20190075094A1 · Clarke · 2019 [cited by applicant]
US 20190108462A1 · Deloo · 2019 [cited by applicant]
US 20190147449A1 · Cole · 2019 [cited by applicant]
US 20190188696A1 · Carpenter et al. · 2019 [cited by applicant]
US 20190196935A1 · Edwards · 2019 [cited by applicant]
US 20190205575A1 · Gardiner et al. · 2019 [cited by applicant]
US 20190213585A1 · Patni · 2019 [cited by examiner]
US 20190228408A1 · Sing · 2019 [cited by applicant]
US 20190253434A1 · Biyani et al. · 2019 [cited by applicant]
US 20190318345A1 · Kallugudde · 2019 [cited by applicant]
US 20190362339A1 · Gurunathan et al. · 2019 [cited by applicant]
US 20190392411A1 · Jain et al. · 2019 [cited by applicant]
US 20200019961A1 · Silvestre · 2020 [cited by applicant]
US 20200027086A1 · Rao et al. · 2020 [cited by applicant]
US 20200160325A1 · Kim et al. · 2020 [cited by applicant]
US 20200219090A1 · Zarakas et al. · 2020 [cited by applicant]
US 20200265420A1 · Hamdan et al. · 2020 [cited by applicant]
US 20200302441A1 · Collinge et al. · 2020 [cited by applicant]
US 20200410483A1 · Dill et al. · 2020 [cited by applicant]
US 20210012322A1 · Manchanda · 2021 [cited by examiner]
US 20210065156A1 · Kadiwala et al. · 2021 [cited by applicant]
US 20210217005A1 · Mehrhoff et al. · 2021 [cited by applicant]
US 20210287211A1 · Aabye et al. · 2021 [cited by applicant]
US 20220051231A1 · Laracey · 2022 [cited by applicant]
US 20220122081A1 · Wagner et al. · 2022 [cited by applicant]
CN 101192295A · 2008 [cited by applicant]
EP 0919945A2 · 1999 [cited by applicant]
EP 2189934A2 · 2010 [cited by applicant]
EP 2390817A · 2011 [cited by applicant]
EP 3618403A1 · 2020 [cited by applicant]
JP 2008129890A · 2008 [cited by applicant]
JP 2008204248A · 2008 [cited by applicant]
KR 101236544B1 · 2013 [cited by applicant]
KR 1020140008668A · 2014 [cited by applicant]
KR 101502460B1 · 2015 [cited by applicant]
KR 101679783B1 · 2016 [cited by applicant]
KR 20160140216A · 2016 [cited by applicant]
KR 20170058903A · 2017 [cited by applicant]
WO 1997046964A1 · 1997 [cited by applicant]
WO 2001099070A2 · 2001 [cited by applicant]
WO 2003038719A1 · 2003 [cited by applicant]
WO 2008059465A2 · 2008 [cited by applicant]
WO 2010070539A1 · 2010 [cited by applicant]
WO 2010099352A1 · 2010 [cited by applicant]
WO 2010133096A1 · 2010 [cited by applicant]
WO 2013050296A1 · 2013 [cited by applicant]
WO 2013155627A1 · 2013 [cited by applicant]
WO 2016123309A1 · 2016 [cited by applicant]
WO 2016161000A1 · 2016 [cited by applicant]
WO 2017007935A1 · 2017 [cited by applicant]
WO 2018031856A1 · 2018 [cited by applicant]
WO 2019136044A1 · 2019 [cited by applicant]
WO 2019161003A1 · 2019 [cited by applicant]
WO 2020243286A · 2020 [cited by applicant]
PCT International Search Report, Application No. PCT/GB2017/051818, dated Sep. 1, 2017, 2 pp. [cited by applicant]
EP Communication pursuant to Article 94 (3) EPC; 19184252.5, Aug. 25, 2022, pp. 1-7. [cited by applicant]
EP 19187159.9 European Summons to attend oral proceedings pursuant to Rule 115 (1) dated Jul. 29, 2022, pp. 1-10. [cited by applicant]
PCT International Search Report and Written Opinion; PCT/US2020-039521; Oct. 14, 2020. [cited by applicant]
EPO Office Action; EP 19187159.9; Jun. 8, 2021. [cited by applicant]
EPO Search Report; EP 19187159.9; Apr. 17, 2020. [cited by applicant]
Yingjiu, et al.; A Security-Enhanced One-Time Payment Scheme for Credit Card; 14th International Workshop on Research Issues on Data Engineering; Web Services for E-Commerce and E-Government Applications (RIDE'04); IEEE… [cited by applicant]
EMV MasterCard Contactless Transaction Flow, EMV Level 2 Kernels, https://www.level2kernel.com/emv-mastercard-contactless-transaction.html, 2021, pp. 1-3. [cited by applicant]
EMV Overview—Elavon Developer Portal, https://developer.elavon.com/na/docs/viaconex/1.0.0/emv-integration-guide/3_emv_overview, 2022, pp. 1-33. [cited by applicant]
EMV, https://en.wikipedia.org/wiki/EMV, Wikipedia, Jan. 18, 2022 (last edited), pp. 1-26. [cited by applicant]
Tokenization (data security), https://en.wikipedia.org/wiki/Tokenization_(data_security), Wikipedia, Jan. 8, 2022 (last edited), pp. 1-8. [cited by applicant]
EMV Integrated Circuit Card Specifications for Payment Systems, Book 4 Cardholder, Attendant, and Acquirer Interface Requirements, Nov. 2011, pp. 1-154, EMC Version 4.3 Book 4. [cited by applicant]
A Guide to EMV Chip Technology, Nov. 2014, pp. 1-36, Version 2.0, EMVCo, LLC. [cited by applicant]
Field 55: ICC Data, Elavon Developer Portal, https://developer-eu.elavon.com/docs/eisop/field-descriptions/field-55-icc-data, 2021, pp. 1-11. [cited by applicant]
Terminal verification results, https://en.wikipedia.org/wiki/Terminal_verification_results, Wikipedia, Dec. 12, 2021 (last edited), pp. 1-3. [cited by applicant]
Smart card application protocol data unit, https://en.wikipedia.org/wiki/Smart_card_application_protocol_data_unit, Wikipedia, Aug. 24, 2021 (last edited), pp. 1-3. [cited by applicant]
O. Ogundele, et al.; “The Implementation of a Full EMV Smartcard for a Point-of-Sale Transaction,” World Congress on Internet Security (WorldCIS-2012), Guelph, ON, Canada, 2012, pp. 28-35. [cited by applicant]
EMVco Payment Account Reference (PAR): A Primer, Version 1.1, Secure Technology Alliance, Apr. 30, 2018, pp. 1-20. [cited by applicant]
PCT/SG2022/050327 Search Report and Written Opinion dated Dec. 23, 2022, pp. 1-20. [cited by applicant]
PCT/US2022/049771 International Search Report and Written Opinion dated Mar. 20, 2023, pp. 1-19. [cited by applicant]
PCT/US2020/0402061 International Search Report and Written Opinion dated Oct. 21, 2020. [cited by applicant]
PCT/US2021/018344 International Search Report and Written Opinion dated May 27, 2021, pp. 1-11. [cited by applicant]
EP 20159634.3 Extended European Search Report dated Jul. 30, 2020, pp. 1-8. [cited by applicant]
PCT/US2021/042321 International Search Report and Written Opinion dated Nov. 11, 2021, pp. 1-11. [cited by applicant]
GB 2012833.6 Search Report dated Jan. 27, 2021, pp. 1-2. [cited by applicant]
PCT International Search Report and Written Opinion; PCT/US2021/047077; Dec. 14, 2021. [cited by applicant]
SG10202204968V Written Opinion dated Jan. 23, 2025, pp. 1-26. [cited by applicant]