IP Library Granted Patent US 12,052,252
Granted Patent B2
US 12,052,252 · App. 18/458,311 · Granted Jul 30, 2024

Systems and methods for third-party interoperability in secure network transactions using tokenized data

Inventor: Brant Peterson (Denver, CO)
Assignee: Worldpay, LLC
H04L63/10H04L63/08G06F21/1014G06Q50/26
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,052,252
App. No.
18/458,311
Granted
Jul 30, 2024
Kind
B2
Abstract

Embodiments include methods and systems for enabling third-party data service interoperability, comprising receiving, from an electronic data server, a request for a low-value token, the low-value token being associated with a subset of sensitive data associated with a user; providing the low-value token to the electronic data server; receiving a request for the subset of sensitive data, from a third-party data service server, the request comprising the low-value token; de-tokenizing the low-value token to obtain the subset of sensitive data; providing the subset of sensitive data to the third-party data service server; receiving, from an electronic data server, the low-value token and a transaction authorization request; determining, based on the low-value token and authorization request, an authorization response; and providing the authorization response to the electronic data server.

Claims (55)

1. A method for maintaining electronic transaction data security with a third-party service, comprising:

receiving, by a transaction processor server from a user browser, a request for a low-value token, the request comprising a high-value token, the high-value token being associated with a set of sensitive data associated with a user;

generating, by the transaction processor server, the low-value token by tokenizing at least a subset of the sensitive data of the user;

receiving, by the transaction processor server from a third-party service server at a first time, the low-value token subsequent to transmitting the low-value token to the user browser;

validating, by the transaction processor server, the third-party service server as a trusted requestor for detokenization;

receiving, by the transaction processor server from a merchant processor, an authorization request using the low-value token; and

providing, by the transaction processor server to the merchant processor in response to receiving the authorization request, the high-value token associated with the set of the sensitive data of the user.

2. The method of claim 1 , further comprising:

receiving, by the transaction processor server from an electronic data server at a second time, the low-value token, the authorization request, and third-party service data;

determining, by the transaction processor server, whether to authorize an electronic transaction based on at least one of the low-value token, the authorization request, and the third-party service data; and

providing, by the transaction processor server to the electronic data server, a transaction authorization response based on the determination.

3. The method of claim 2 , wherein the transaction authorization response is provided with a high-value token, the high-value token being associated with the sensitive data of the user and being usable by the electronic data server to execute subsequent electronic transactions.

4. The method of claim 2 , wherein the third-party service data is 3-D Secure response data.

5. The method of claim 1 , wherein the low-value token is a limited-use token configured to obtain a subset of the sensitive data of the user.

6. The method of claim 1 , wherein the third-party service server performs a fraud check based on the subset of the sensitive data of the user.

7. The method of claim 1 , wherein the subset of the sensitive data comprises a personal account number (PAN).

8. A system for maintaining electronic transaction data security with a third-party service, the system comprising:

a data storage device storing instructions; and

one or more processors configured to execute the instructions to perform a method comprising:

receiving, by a transaction processor server from a user browser, a request for a low-value token, the request comprising a high-value token, the high-value token being associated with a set of sensitive data associated with a user;

generating, by the transaction processor server, the low-value token by tokenizing at least a subset of the sensitive data of the user;

receiving, by the transaction processor server from a third-party service server at a first time, the low-value token subsequent to transmitting the low-value token to the user browser;

validating, by the transaction processor server, the third-party service server as a trusted requestor for detokenization;

receiving, by the transaction processor server from a merchant processor, an authorization request using the low-value token; and

providing, by the transaction processor server to the merchant processor in response to receiving the authorization request, the high-value token associated with the set of the sensitive data of the user.

9. The system of claim 8 , wherein the method further comprises:

receiving, by the transaction processor server from an electronic data server at a second time, the low-value token, a transaction authorization request, and third-party service data;

determining, by the transaction processor server, whether to authorize an electronic transaction based on at least one of the low-value token, the transaction authorization request, and the third-party service data; and

providing, by the transaction processor server to the electronic data server, a transaction authorization response based on the determination.

10. The system of claim 9 , wherein the transaction authorization response is provided with a high-value token, the high-value token being associated with the sensitive data of the user and being usable by the electronic data server to execute subsequent electronic transactions.

11. The system of claim 9 , wherein the third-party service data is 3-D Secure response data.

12. The system of claim 8 , wherein the method further comprises:

receiving, by the transaction processor server from the third-party service server at a second time, the low-value token and a transaction authorization request;

determining, by the transaction processor server, whether to authorize an electronic transaction based on at least one of the low-value token and the transaction authorization request; and

providing, by the transaction processor server to the electronic data server, a transaction authorization response based on the determination.

13. The system of claim 8 , wherein the third-party service server performs a fraud check based on the subset of the sensitive data of the user.

14. The system of claim 8 , wherein the subset of the sensitive data comprises a personal account number (PAN).

15. A non-transitory computer-readable medium storing instructions that, when executed by a transaction processor server, cause the transaction processor server to perform a method for maintaining electronic transaction data security with a third-party service, the method comprising:

receiving, by a transaction processor server from a user browser, a request for a low-value token, the request comprising a high-value token, the high-value token being associated with a set of sensitive data associated with a user;

generating, by the transaction processor server, the low-value token by tokenizing at least a subset of the sensitive data of the user;

receiving, by the transaction processor server from a third-party service server at a first time, the low-value token subsequent to transmitting the low-value token to the user browser;

validating, by the transaction processor server, the third-party service server as a trusted requestor for detokenization;

receiving, by the transaction processor server from a merchant processor, an authorization request using the low-value token; and

providing, by the transaction processor server to the merchant processor in response to receiving the authorization request, the high-value token associated with the set of the sensitive data of the user.

16. The computer-readable medium of claim 15 , wherein the method further comprises:

receiving, by the transaction processor server from an electronic data server at a second time, the low-value token, a transaction authorization request, and third-party service data;

determining, by the transaction processor server, whether to authorize an electronic transaction based on at least one of the low-value token, the transaction authorization request, and the third-party service data; and

providing, by the transaction processor server to the electronic data server, a transaction authorization response based on the determination.

17. The computer-readable medium of claim 16 , wherein the transaction authorization response is provided with a high-value token, the high-value token being associated with the sensitive data of the user and being usable by the electronic data server to execute subsequent electronic transactions.

18. The computer-readable medium of claim 16 , wherein the third-party service data is 3-D Secure response data.

19. The computer-readable medium of claim 15 , wherein the method further comprises:

receiving, by the transaction processor server from the third-party service server at a second time, the low-value token and a transaction authorization request;

determining, by the transaction processor server, whether to authorize an electronic transaction based on at least one of the low-value token and the transaction authorization request; and

providing, by the transaction processor server to the electronic data server, a transaction authorization response based on the determination.

20. The computer-readable medium of claim 15 , wherein the third-party service server performs a fraud check based on the subset of the sensitive data of the user.

Assignments (6)
RELEASE OF SECURITY INTERESTS RECORDED AT REEL/FRAMES 066626/0655, 066625/0426, 066625/0347, AND 066625/0276 Recorded Jan 12, 2026
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: WORLDPAY, LLC; WORLDPAY ISO AND ECOMMERCE, LLC; PAYMETRIC, LLC; WORLDPAY US, LLC
Reel/Frame 074314/0622 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT R/F 066624/0719 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: WORLDPAY, LLC
Reel/Frame 074315/0412 →
SECURITY INTEREST Recorded Feb 19, 2024
From: WORLDPAY, LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066624/0719 →
SECURITY INTEREST Recorded Feb 19, 2024
From: WORLDPAY, LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 066626/0655 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2023
From: PETERSON, BRANT
To: VANTIV, LLC
Reel/Frame 064766/0172 →
CHANGE OF NAME Recorded Aug 31, 2023
From: VANTIV, LLC
To: WORLDPAY, LLC
Reel/Frame 064790/0126 →
Continuity (4)
Continuation 17382726 · Jul 22, 2021
Continuation 16517008 · Jul 19, 2019
Continuation 15368093 · Dec 2, 2016
Related Publication 20230412599A1 · Dec 21, 2023