IP Library › Granted Patent US 12,518,283
Granted Patent B2
US 12,518,283 · App. 17/959,198 · Granted Jan 6, 2026

Systems and methods for enhanced transaction authentication

Inventors: Sahar Mor, Jr. (San Francisco, CA); Abhishek Kulgod (San Francisco, CA); Ryan Drapeau (Seattle, WA)
Assignee: Stripe, Inc.
G06Q20/4016G06Q20/34
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,518,283
App. No.
17/959,198
Granted
Jan 6, 2026
Kind
B2
Abstract

A method and apparatus for authenticating a transaction are described. The method may include: receiving, at an authentication device, an electronic transaction request as part of authenticating a card-originated transaction between a merchant and a consumer; determining, based on characteristics of the electronic transaction request, a risk value associated with the electronic transaction request; selecting a first identification value or a second identification value based on a comparison of the risk value to a risk threshold, wherein the first identification value indicates that the risk value exceeds the risk threshold and the second identification value indicates that the risk value does not exceed the risk threshold; generating a communication to transmit to an authorization device, the communication comprising a first data field having the selected first identification value or the selected second identification value; and transmitting the communication to the authorization device.

Claims (63)

1 . A method comprising:

storing, by a computing system, a transaction processing system, a fraud detection system comprising a risk calculation engine, and an authorization API in bidirectional communication over the network with an authorization system, wherein the risk calculation engine comprises at least one machine learning model and the transaction processing system is in communication with a merchant system over a network;

executing, by the computing system, the fraud detection system;

receiving, by the computing system via the transaction processing system, and over the network, a transaction request from the merchant system, wherein the transaction request comprises first transaction information, and sending, via the transaction processing system, the first transaction information to the executing fraud detection system;

retrieving, by the computing system, from the authorization system, based on the transaction request, and via the authorization API, second transaction information;

by the computing system, and via the executing fraud detection system:

accessing the second transaction information;

receiving from the transaction processing system the first transaction information;

executing the risk calculation engine and calculating, via the executing calculation engine and utilizing the at least one machine learning model, a risk value for the transaction request based on the first transaction information and the second transaction information;

generating, by the computing system, an authorization request based on the transaction request and transmitting, by the computing system, the authorization request to the authorization system over the network utilizing an ISO protocol;

transmitting, by the computing system via the authorization API, and utilizing a non-ISO protocol, the risk value to the authorization system;

receiving, by the computing system, over the network, and from the authorization system, an authorization decision;

determining, by the computing system, whether to approve or deny the transaction request based, at least, on the received authorization decision; and

transmitting, by the computing system, over the network, a resulting approval or denial determination to the merchant system.

2 . The method according to claim 1 , wherein the ISO protocol comprises a first data field that corresponds to a merchant identification associated with the transaction request.

3 . The method according to claim 1 , wherein executing the risk calculation engine and calculating, via the executing calculation engine and utilizing the at least one machine learning model comprises: selecting, by the executing calculation engine, the at least one machine learning model based on the first transaction information.

4 . The method according to claim 3 , wherein executing the risk calculation engine and calculating, via the executing calculation engine and utilizing the at least one machine learning model further comprises: applying, via the executing calculation engine, the at least one machine learning model to the first transaction information to calculate the risk value.

5 . The method according to claim 1 ,

wherein the second transaction information comprises one or more of an internet protocol (IP) address associated with the transaction request, an email associated with the transaction request, a phone number associated with the transaction request, billing information associated with the transaction request, shipping information associated with the transaction request, or an indication whether a scanned image of a card associated with the transaction request was received.

6 . The method according to claim 1 , wherein the ISO protocol is an ISO 8583 protocol.

7 . A non-transitory computer readable storage medium including instructions that, when executed by a processing device, causes the processing device to perform operations comprising:

storing a transaction processing system, a fraud detection system comprising a risk calculation engine, and an authorization API in bidirectional communication over the network with an authorization system, wherein the risk calculation engine comprises at least one machine learning model and the transaction processing system is in communication with a merchant system over a network;

executing the fraud detection system;

receiving, via the transaction processing system, and over the network, a transaction request from the merchant system, wherein the transaction request comprises first transaction information, and sending, via the transaction processing system, the first transaction information to the executing fraud detection system;

retrieving, from the authorization system, based on the transaction request, and via the authorization API, second transaction information;

via the executing fraud detection system:

accessing the second transaction information;

receiving from the transaction processing system the first transaction information;

executing the risk calculation engine and calculating, via the executing calculation engine and utilizing the at least one machine learning model, a risk value for the transaction request based on the first transaction information and the second transaction information;

generating an authorization request based on the transaction request and transmitting the authorization request to the authorization system over the network utilizing an ISO protocol;

transmitting, via the authorization API, and utilizing a non-ISO protocol, the risk value to the authorization system;

receiving, over the network, and from the authorization system, an authorization decision;

determining whether to approve or deny the transaction request based, at least, on the received authorization decision; and

transmitting, over the network, a resulting approval or denial determination to the merchant system.

8 . The non-transitory computer readable storage medium according to claim 7 , wherein the ISO protocol comprises a first data field that corresponds to a merchant identification associated with the transaction request.

9 . The non-transitory computer readable storage medium according to claim 7 , wherein executing the risk calculation engine and calculating, via the executing calculation engine and utilizing the at least one machine learning model comprises: selecting, by the executing calculation engine, the at least one machine learning model based on the first transaction information.

10 . The non-transitory computer readable storage medium according to claim 9 , wherein executing the risk calculation engine and calculating, via the executing calculation engine and utilizing the at least one machine learning model further comprises: applying, via the executing calculation engine, the at least one machine learning model to the first transaction information to calculate the risk value.

11 . The non-transitory computer readable storage medium according to claim 7 ,

wherein the second transaction information comprises one or more of an internet protocol (IP) address associated with the transaction request, an email associated with the transaction request, a phone number associated with the transaction request, billing information associated with the transaction request, shipping information associated with the transaction request, or an indication whether a scanned image of a card associated with the transaction request was received.

12 . The non-transitory computer readable storage medium according to claim 7 , wherein the ISO protocol is an ISO 8583 protocol.

13 . A commerce platform system, comprising:

a processor; and

a memory storing executable instructions,

that when executed by the processor, causes the processor to perform operations of:

storing a transaction processing system, a fraud detection system comprising a risk calculation engine, and an authorization API in bidirectional communication over the network with an authorization system, wherein the risk calculation engine comprises at least one machine learning model and the transaction processing system is in communication with a merchant system over a network;

executing the fraud detection system;

receiving, via the transaction processing system, and over the network, a transaction request from the merchant system, wherein the transaction request comprises first transaction information, and sending, via the transaction processing system, the first transaction information to the executing fraud detection system;

retrieving, from the authorization system, based on the transaction request, and via the authorization API, second transaction information;

via the executing fraud detection system:

accessing the second transaction information;

receiving from the transaction processing system the first transaction information;

executing the risk calculation engine and calculating, via the executing calculation engine and utilizing the at least one machine learning model, a risk value for the transaction request based on the first transaction information and the second transaction information;

generating an authorization request based on the transaction request and transmitting the authorization request to the authorization system over the network utilizing an ISO protocol;

transmitting, via the authorization API, and utilizing a non-ISO protocol, the risk value to the authorization system;

receiving, over the network, and from the authorization system, an authorization decision;

determining whether to approve or deny the transaction request based, at least, on the received authorization decision; and

transmitting, over the network, a resulting approval or denial determination to the merchant system.

14 . The commerce platform system according to claim 13 , wherein the ISO protocol comprises a first data field that corresponds to a merchant identification associated with the transaction request.

15 . The commerce platform system according to claim 13 , wherein executing the risk calculation engine and calculating, via the executing calculation engine and utilizing the at least one machine learning model comprises: selecting, by the executing calculation engine, the at least one machine learning model based on the first transaction information.

16 . The commerce platform system according to claim 15 , wherein executing the risk calculation engine and calculating, via the executing calculation engine and utilizing the at least one machine learning model further comprises: applying, via the executing calculation engine, the at least one machine learning model to the first transaction information to calculate the risk value.

17 . The commerce platform system according to claim 13 ,

wherein the second transaction information comprises one or more of an internet protocol (IP) address associated with the transaction request, an email associated with the transaction request, a phone number associated with the transaction request, billing information associated with the transaction request, shipping information associated with the transaction request, or an indication whether a scanned image of a card associated with the transaction request was received by the commerce platform system.

18 . The commerce platform system according to claim 13 , wherein the ISO protocol is an ISO 8583 protocol.

Assignments (2)
CHANGE OF NAME Recorded Mar 6, 2026
From: STRIPE, INC.
To: STRIPE, LLC
Reel/Frame 075033/0690 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2022
From: MOR, SAHAR; KULGOD, ABHISHEK; DRAPEAU, RYAN
To: STRIPE, INC.
Reel/Frame 061306/0646 →
Continuity (1)
Related Publication 20240112192A1 · Apr 4, 2024
References Cited (9)
US 10977652B1 · Twilley · 2021 [cited by examiner]
US 20150310434A1 · Cheung · 2015 [cited by examiner]
US 20150347965A1 · Wardman · 2015 [cited by examiner]
US 20190392450A1 · Gosset · 2019 [cited by examiner]
US 20200236105A1 · Doshi · 2020 [cited by examiner]
US 20220215392A1 · Wied · 2022 [cited by examiner]
American Express retreived Oct. 4, 2022. “Amex for Developers”, 57 pages. https://developer.americanexpress.com/products/enhanced-authorization-v2/resources#readme. [cited by applicant]
DEVEXCHANGE; retreived Oct. 4, 2022. “Enhanced Decisioning Data”, 22 pages. https://developer.capitalone.com/documentation/enhanced-decisioning-data. [cited by applicant]
Wikipedia, retreived Oct. 4, 2022. “ISO 8583” website, 28 pages. https://en.wikipedia.org/wiki/ISO_8583. [cited by applicant]