IP Library Granted Patent US 12,236,427
Granted Patent B2
US 12,236,427 · App. 18/317,575 · Granted Feb 25, 2025

Systems and methods for automated validation for proprietary security implementations

Inventor: Amie Jackson (Denver, CO)
Assignee: Worldpay, LLC
G06Q20/4012G06Q20/401G06Q30/0203
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,236,427
App. No.
18/317,575
Granted
Feb 25, 2025
Kind
B2
Abstract

Systems and methods are disclosed for automated validation for proprietary security implementations. One method includes: receiving, from each of a plurality of merchants, a list of security service providers used by the merchant; enabling connection with the each of the security service providers of the received list of security service providers used by the merchant; receiving, from each of the listed security service provider with connection enabled, security service information as it pertains to the merchant of the plurality of merchants; generating a security service profile for each merchant of the plurality of merchants, based on the received security service information from each security service provider of the received list of security service providers of the merchant; and outputting the security service profile of the merchant of the plurality of merchants to an electronic storage medium.

Claims (95)

1. A computer-implemented method of automated validation for proprietary security implementations, the method comprising:

receiving, by a communication interface of a centralized server, a list of security service providers associated with one or more merchants;

enabling, by a portal of the centralized server, a connection with each of the security service providers associated with the one or more merchants;

receiving, by the centralized server, security service information associated with the one or more merchants from a security service provider with connection enabled, the security service provider with connection enabled listed on the list of security service providers;

generating, by a processor of the centralized server, a security service profile for a merchant of the one or more merchants that comprises an assessment of an extent to which the received security service information meets a payment cards industry data security standard (PCI DSS);

storing, by the processor of the centralized server, the security service profile of the merchant of the one or more merchants to an electronic storage medium;

interfering, by the processor of the centralized server, with a payment transaction process involving the merchant of the one or more merchants to prevent an unsecured transaction, based on the assessment of the security service profile of the merchant indicating that the received security service information does not meet the PCI DSS; and

providing, by the processor of the centralized server, a portal allowing an interface for communication with various end users.

2. The method of claim 1 , further comprising,

identifying a questionnaire and/or report pertaining to the PCI DSS of the merchant, wherein the questionnaire and/or report is produced by a source for the data security standards;

receiving from the source for the PCI DSS, the identified questionnaire and/or report;

determining data fields from the received questionnaire and/or report that needs entries;

retrieving, from the electronic storage medium, the security service profile of the merchant;

populating at least some of the determined data fields of the received questionnaire and/or report using the retrieved security service profile of the merchant, to complete or partially complete the questionnaire and/or report; and

transmitting a completed or partially completed questionnaire and/or report to one or more of the merchant or to the source of the PCI DSS.

3. The method of claim 2 , further comprising, prior to identifying a questionnaire and/or report pertaining to the PCI DSS of the merchant,

receiving a request, from the merchant to complete or partially complete the identified questionnaire and/or report pertaining to data security standards of a merchant.

4. The method of claim 2 , wherein the identifying a questionnaire and/or report pertaining to the PCI DSS of the merchant is based on a category of one or more categories which the merchant belongs to, the one or more categories comprising one or more of:

card-not-present merchants that outsource cardholder data functions to third party service providers;

E-commerce merchants who outsource cardholder data functions to third party service providers, and who have website(s) that do not directly receive cardholder data;

merchants using imprint machines or standalone dial-out machines with no electronic cardholder data storage;

merchants using only standalone, PTS-approved payment terminals with an IP connection to a payment processor with no electronic cardholder data storage;

merchants having no electronic cardholder data storage, and who manually enter a single transaction at a time via a keyboard into an Internet-based, virtual payment terminal solution that is provided and hosted by a third-party service provider;

merchants with payment application systems connected to the Internet, no electronic cardholder data storage;

merchants using hardware payment terminals included in and managed via a point to point encryption solution, with no electronic cardholder data storage;

merchants not included in the one or more categories; and

security service providers.

5. The method of claim 4 , wherein the questionnaire and/or report is continually stored on the centralized server via an engine of the centralized server.

6. The method of claim 2 , wherein:

the questionnaire includes a self assessment questionnaire (SAQ) provided by the PCI DSS; and

the report includes the report on compliance (ROC) provided by the PCI DSS.

7. The method of claim 1 , wherein the security service information comprises one or more of:

available tools, products, or services offered by the security service provider that increases data security when implemented by the merchant;

the tools, the products, or the services offered by the security service provider that are already being used being provided to the merchant;

configuration or implementation settings of the merchant for the tools, the products, or the services offered by security service provider and implemented by the merchant; and

data security risk assessment of the merchant based on the tools, the products or the services produced by the security service provider and implemented by the merchant.

8. The method of claim 1 , wherein the security service profile for each merchant comprises one or more of:

a first list of security service providers of a first merchant of the one or more merchants;

a second list of security service providers of a second merchant of the one or more merchants;

a list of tools, products, or services offered by the security service providers of and/or implemented by one of the first merchant and the second merchant;

a list of system components owned or used by one of the first merchant and the second merchant that store, process, or transmit cardholder data; and

the assessment of an extent to which the tools, the products, or the services implemented by the one of the first merchant and the second merchant meets the PCI DSS of the list of system components owned or used by the merchant that store, process, or transmit the cardholder data.

9. The method of claim 1 , wherein the merchant is a security service provider.

10. A system for automated validation for proprietary security implementations, the system comprising:

a data storage device storing instructions for automated validation for proprietary security implementations; and

a processor configured to execute the instructions to perform a method including:

receiving, by a communication interface of a centralized server, a list of security service providers associated with one or more merchants;

enabling, by a portal of the centralized server, a connection with each of the security service providers associated with the one or more merchants;

receiving, by the centralized server, security service information associated with the one or more merchants from a security service provider with connection enabled, the security service provider with connection enabled listed on the list of security service providers;

generating, by a processor of the centralized server, a security service profile for a merchant of the one or more merchants that comprises an assessment of an extent to which the received security service information meets a payment cards industry data security standard (PCI DSS);

storing, by the processor of the centralized server, the security service profile of the merchant of the one or more merchants to an electronic storage medium;

interfering, by the processor of the centralized server, with a payment transaction process involving the merchant of the one or more merchants to prevent an unsecured transaction, based on the assessment of the security service profile of the merchant indicating that the received security service information does not meet the PCI DSS; and

providing, by the processor of the centralized server, a portal allowing an interface for communication with various end users.

11. The system of claim 10 , further comprising,

system components owned or used by each of the one or more merchants that store, process, or transmit cardholder data;

security service providers that offer tools, products, or services to merchants to comply with the PCI DSS; and

a source for the PCI DSS.

12. The system of claim 10 , wherein the processor is further configured for:

identifying a questionnaire and/or report pertaining to the PCI DSS of a merchant of the one or more merchants, wherein the questionnaire and/or report is produced by a source for the PCI DSS;

receiving from the source for the PCI DSS, the identified questionnaire and/or report;

determining data fields from the received questionnaire and/or report that needs entries;

retrieving, from the electronic storage medium, the security service profile of the merchant;

populating at least some of the determined data fields of the received questionnaire and/or report using the retrieved security service profile of the merchant, to complete or partially complete the questionnaire and/or report; and

transmitting a completed or partially completed questionnaire and/or report to one or more of the merchant or to the source of the PCI DSS.

13. The system of claim 12 , wherein the processor is further configured for, prior to identifying a questionnaire and/or report pertaining to the PCI DSS of a merchant of the one or more merchants, receiving a request, from a merchant to complete or partially complete the identified questionnaire and/or report pertaining to data security standards of a merchant.

14. The system of claim 13 , wherein the questionnaire and/or report is continually stored on the centralized server via an engine of the centralized server.

15. The system of claim 12 , wherein:

the questionnaire includes a self assessment questionnaire (SAQ) provided by the PCI DSS; and

the report includes the report on compliance (ROC) provided by the PCI DSS.

16. The system of claim 10 , wherein the security service information comprises one or more of:

available tools, products, or services offered by the security service provider that increases data security when implemented by the merchant;

the tools, the products, or the services offered by the security service provider that are already being used being provided to the merchant;

configuration or implementation settings of the merchant for the tools, the products, or the services offered by security service provider and implemented by the merchant; and

data security risk assessment of the merchant based on the tools, the products or the services produced by the security service provider and implemented by the merchant.

17. The system of claim 10 , wherein the security service profile for a merchant of the one or more merchants comprises one or more of:

the list of security service providers of the merchant;

a list of tools, products, or the services offered by the security service providers of the merchant, and implemented by the merchant;

a list of system components owned or used by the merchant that store, process, or transmit cardholder data; and

the assessment of an extent to which the tools, the products, or the services implemented by the merchant meet the PCI DSS of the list of system components owned or used by the merchant that store, process, or transmit the cardholder data.

18. The system of claim 10 , wherein one or more of the one or more merchants is a security service provider.

19. A non-transitory machine-readable medium storing instructions that, when executed by a processor, cause the processor to perform a method for automated validation for proprietary security implementations, the method including:

receiving, by a communication interface of a centralized server, a list of security service providers associated with one or more merchants;

enabling, by a portal of the centralized server, a connection with each of the security service providers associated with the one or more merchants;

receiving, by the centralized server, security service information associated with the one or more merchants from a security service provider with connection enabled, the security service provider with connection enabled listed on the list of security service providers;

generating, by a processor of the centralized server, a security service profile for a merchant of the one or more merchants that comprises an assessment of an extent to which the received security service information meets a payment cards industry data security standard (PCI DSS);

storing, by the processor of the centralized server, the security service profile of the merchant of the one or more merchants to an electronic storage medium;

interfering, by the processor of the centralized server, with a payment transaction process involving the merchant of the one or more merchants to prevent an unsecured transaction, based on the assessment of the security service profile of the merchant indicating that the received security service information does not meet the PCI DSS; and

providing, by the processor of the centralized server, a portal allowing an interface for communication with various end users.

20. The non-transitory machine-readable medium of claim 19 , further comprising:

identifying a questionnaire and/or report pertaining to the PCI DSS of a merchant of the one or more merchants, wherein the questionnaire and/or report is produced by a source for the PCI DSS;

receiving from the source for the PCI DSS, the identified questionnaire and/or report;

determining data fields from the received questionnaire and/or report that needs entries;

retrieving, from the electronic storage medium, the security service profile of the merchant;

populating at least some of the determined data fields of the received questionnaire and/or report using the retrieved security service profile of the merchant, to complete or partially complete the questionnaire and/or report; and

transmitting a completed or partially completed questionnaire and/or report to one or more of the merchant or to the source of the PCI DSS.

Assignments (6)
RELEASE OF SECURITY INTERESTS RECORDED AT REEL/FRAMES 066626/0655, 066625/0426, 066625/0347, AND 066625/0276 Recorded Jan 12, 2026
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: WORLDPAY, LLC; WORLDPAY ISO AND ECOMMERCE, LLC; PAYMETRIC, LLC; WORLDPAY US, LLC
Reel/Frame 074314/0622 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT R/F 066624/0719 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: WORLDPAY, LLC
Reel/Frame 074315/0412 →
SECURITY INTEREST Recorded Feb 19, 2024
From: WORLDPAY, LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066624/0719 →
SECURITY INTEREST Recorded Feb 19, 2024
From: WORLDPAY, LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 066626/0655 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2023
From: JACKSON, AMIE
To: VANTIV, LLC
Reel/Frame 063650/0209 →
CHANGE OF NAME Recorded May 16, 2023
From: VANTIV, LLC
To: WORLDPAY, LLC
Reel/Frame 063650/0339 →
Continuity (2)
Continuation 15925161 · Mar 19, 2018
Related Publication 20230306426A1 · Sep 28, 2023
References Cited (54)
US 7519557B1 · Lee · 2009 [cited by examiner]
US 7908168B2 · Walker · 2011 [cited by examiner]
US 7970701B2 · Lewis · 2011 [cited by examiner]
US 8261342B2 · Newman · 2012 [cited by examiner]
US 8296244B1 · Heroux · 2012 [cited by examiner]
US 8600873B2 · Fisher · 2013 [cited by examiner]
US 8850512B2 · Price · 2014 [cited by examiner]
US 9043897B2 · Newman · 2015 [cited by examiner]
US 9058607B2 · Ganti · 2015 [cited by examiner]
US 9531886B2 · Wong · 2016 [cited by examiner]
US 10492102B2 · Raleigh · 2019 [cited by examiner]
US 10609031B2 · Bender · 2020 [cited by examiner]
US 10643002B1 · Veselov · 2020 [cited by examiner]
US 10706155B1 · Veselov · 2020 [cited by examiner]
US 10848514B2 · Christian · 2020 [cited by examiner]
US 10887330B2 · Christian · 2021 [cited by examiner]
US 11082452B2 · Yadav · 2021 [cited by examiner]
US 20070157316A1 · Devereux · 2007 [cited by examiner]
US 20080147548A1 · Jiang · 2008 [cited by examiner]
US 20090099857A1 · Lee · 2009 [cited by examiner]
US 20100004986A1 · Walker · 2010 [cited by examiner]
US 20100043068A1 · Varadhan · 2010 [cited by examiner]
US 20100125524A1 · Liang · 2010 [cited by examiner]
US 20100305993A1 · Fisher · 2010 [cited by examiner]
US 20110078032A1 · Johnson · 2011 [cited by examiner]
US 20110078034A1 · Hayhow · 2011 [cited by examiner]
US 20110126189A1 · Galvin · 2011 [cited by examiner]
US 20110276468A1 · Lewis · 2011 [cited by examiner]
US 20120158541A1 · Ganti · 2012 [cited by examiner]
US 20130055398A1 · Li · 2013 [cited by examiner]
US 20130073844A1 · Shimada · 2013 [cited by examiner]
US 20130080329A1 · Royyuru · 2013 [cited by examiner]
US 20130247133A1 · Price · 2013 [cited by examiner]
US 20140258136A1 · Ellis · 2014 [cited by examiner]
US 20140337969A1 · Li · 2014 [cited by examiner]
US 20160034898A1 · Ghosh · 2016 [cited by examiner]
US 20160127539A1 · Sharma · 2016 [cited by examiner]
US 20160127549A1 · Sharma · 2016 [cited by examiner]
US 20160127808A1 · Wong · 2016 [cited by examiner]
US 20170078922A1 · Raleigh · 2017 [cited by examiner]
US 20170251013A1 · Kirti · 2017 [cited by examiner]
US 20180053157A1 · Roffey · 2018 [cited by examiner]
US 20180285944A1 · Groarke · 2018 [cited by examiner]
US 20190166125A1 · Bender · 2019 [cited by examiner]
US 20200106797A1 · Christian · 2020 [cited by examiner]
US 20200120144A1 · Yadav · 2020 [cited by examiner]
US 20200204574A1 · Christian · 2020 [cited by examiner]
US 20200396259A1 · Schory · 2020 [cited by examiner]
CA 2826680A1 · 2012 [cited by examiner]
CA 2946224A1 · 2015 [cited by examiner]
WO WO2004104528A1 · 2004 [cited by examiner]
Amazon Web Service. “PCI Compliance”. (Dec. 7, 2010). Retrieved online Oct. 6, 2024. https://aws.amazon.com/compliance/pci-dss-level-1-faqs/ (Year: 2010). [cited by examiner]
Security Standards Council. “Tokenization Product Security Guidelines—Irreversible and Reversible Tokens.” (Apr. 2015). Retrieved online Oct. 6, 2024. https://www.pcisecuritystandards.org/documents/Tokenization_Product_… [cited by examiner]
Microsoft Dynamics. “Implementation Guide for PCI Compliance.” (Feb. 2012). Retrieved online Oct. 6, 2024. https://download.microsoft.com/download/F/3/0/F30958AA-EEF7-423E-A53E-A1F72935BB5C/PCI%20Implementation%20Guide.… [cited by examiner]