IP Library Granted Patent US 12,063,212
Granted Patent B1
US 12,063,212 · App. 18/533,978 · Granted Aug 13, 2024

Secure token driven conditional routing of proceeds

Inventors: Matthew William Janiga (South San Francisco, CA); Karen Elizabeth Brinkley (San Francisco, CA); Vincent Michael Cogan (San Francisco, CA); Brian David Krausz (San Francisco, CA)
Assignee: Stripe, Inc.
H04L63/083G06Q20/00G06Q20/02G06Q20/4014G06Q20/4097H04L9/3271H04L63/08H04L63/0807
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,063,212
App. No.
18/533,978
Granted
Aug 13, 2024
Kind
B1
Abstract

Methods and systems for secure token driven conditional routing of proceeds are described. A request to initiate routing of data between remote systems is received by a server computer system, where the request includes an incomplete set of parameters. A validation challenge and a challenge response defined by a first remote computing system are received, and a token that references the first remote computing system and the incomplete parameter set is generated. A validation may then be performed for a second remote computing system using the validation challenge and the challenge response defined by the first remote computing system. The incomplete set of parameters may then be completed by the second remote computing system when the challenge is validated to enable the routing of data according to the complete set of parameters referenced by the token.

Claims (72)

1. A computer-implemented method performed by a server computer system for processing a routing of data between a first remote computing system and a second remote computing system, comprising:

receiving, by an interface of the server computer system from the first remote computing system, a request to initiate the routing of data between the first remote computing system and the second remote computing system, the request comprising an incomplete set of parameters;

receiving, by the interface of the server computer system, a validation challenge and a challenge response defined by the first remote computing system;

generating, by a processing system of the server computer system, a token for the routing of data, the token referencing at least the first remote computing system and the incomplete set of parameters, and the token decipherable at the server computer system and indecipherable to the first remote computing system and the second remote computing system;

performing, by the server computer system, a validation of the second remote computing system based on the validation challenge and the challenge response defined by the first remote computing system;

in response to a successful validation of the second remote computing system, receiving, by the interface of the server computer system, a second set of parameters from the second remote computing system, wherein the incomplete set of parameters and the second set of parameters form a complete set of parameters referenced by the token; and

processing, by the server computer system, the routing of data between the first remote computing system and the second remote computing system using the complete set of parameters referenced by the token.

2. The method of claim 1 , wherein the interface comprises an application programming interface (API) request interface, and wherein the request to initiate the routing of data between the first remote computing system and the second remote computing system, the validation challenge and the challenge response, and the second set of parameters are received as API messages transmitted to the API request interface over a communications network.

3. The method of claim 1 , further comprising:

generating a randomly generated identifier that references the complete set of parameters;

transmitting, by the server computer system to the first remote computing system, the randomly generated identifier that references the complete set of parameters;

performing the processing, by the server computer system, of the routing of data between the first remote computing system and the second remote computing system in response to receiving the randomly generated identifier with the request to perform the processing of the routing of data.

4. The method of claim 3 , further comprising:

accessing the complete set of parameters referenced by the randomly generated identifier in response to the receipt of the randomly generated identifier;

verifying one or more of the complete set of parameters are satisfied by one or more corresponding current parameters associated with the routing of data being processed between the first remote computing system and the second remote computing system; and

completing the processing of the routing of data between the first remote computing system and the second remote computing system in response to the verification of the one or more of the complete set of parameters are satisfied by the one or more corresponding current parameters.

5. The method of claim 3 , wherein the randomly generated identifier comprises a pointer or link to a data storage location of a data store where the complete set of parameters are stored by the server computer system, and the pointer and link are the token.

6. The method of claim 3 , wherein the randomly generated identifier is stored in an object or file, and the object or file comprises the token.

7. The method of claim 1 , wherein performing the validation of the second remote computing system, comprises:

generating, in a Graphical User Interface (GUI) rendered on a display of the second remote computing system, the validation challenge comprised in the token;

receiving a challenge response from the second remote computing system generated by the GUI; and

validating an identity of the second remote computing system when the challenge response received from the second remote computing system matches the validation response defined by the first remote computing system.

8. The method of claim 1 , wherein the request to initiate the routing of data comprises a request to generate the token, further comprising:

analyzing, by an analytics engine of the server computer system, one or more fraud detection parameters associated with the request to generate the token;

detecting, by the analytics engine, whether the determined risk of fraud satisfies a fraud detection threshold;

rejecting the request to generate the token when the determined risk of fraud fails to satisfy the fraud detection threshold; and

accepting the request to generate the token when the determined risk of fraud satisfied the fraud detection threshold.

9. The method of claim 8 , wherein the one or more fraud detection parameters associated with the request to generate the token comprise: one or more of a total number of tokens requested by the first remote computing system over a period of time, a total number of routings of data processed by the server computer system for the first remote computing system, whether one of the incomplete set of parameters deviates from an expected value of a parameter.

10. A non-transitory machine-readable medium, having instructions stored thereon, which when executed by a processing system of a server computer system, cause the server computer system to perform operations for processing a routing of data between a first remote computing system and a second remote computing system, the operations comprising:

receiving, by an interface of the server computer system from the first remote computing system, a request to initiate the routing of data between the first remote computing system and the second remote computing system, the request comprising an incomplete set of parameters;

receiving, by the interface of the server computer system, a validation challenge and a challenge response defined by the first remote computing system;

generating a token for the routing of data, the token referencing at least the first remote computing system and the incomplete set of parameters, and the token decipherable at the server computer system and indecipherable to the first remote computing system and the second remote computing system;

performing a validation of the second remote computing system based on the validation challenge and the challenge response defined by the first remote computing system;

in response to a successful validation of the second remote computing system, receiving, by the interface of the server computer system, a second set of parameters from the second remote computing system, wherein the incomplete set of parameters and the second set of parameters form a complete set of parameters referenced by the token; and

processing the routing of data between the first remote computing system and the second remote computing system using the complete set of parameters referenced by the token.

11. The non-transitory machine-readable medium of claim 10 , wherein the interface comprises an application programming interface (API) request interface, and wherein the request to initiate the routing of data between the first remote computing system and the second remote computing system, the validation challenge and the challenge response, and the second set of parameters are received as API messages transmitted to the API request interface over a communications network.

12. The non-transitory machine-readable medium of claim 10 , further comprising:

generating a randomly generated identifier that references the complete set of parameters;

transmitting, by the server computer system to the first remote computing system, the randomly generated identifier that references the complete set of parameters;

performing the processing, by the server computer system, of the routing of data between the first remote computing system and the second remote computing system in response to receiving the randomly generated identifier with the request to perform the processing of the routing of data.

13. The non-transitory machine-readable medium of claim 12 , further comprising:

accessing the complete set of parameters referenced by the randomly generated identifier in response to the receipt of the randomly generated identifier;

verifying one or more of the complete set of parameters are satisfied by one or more corresponding current parameters associated with the routing of data being processed between the first remote computing system and the second remote computing system; and

completing the processing of the routing of data between the first remote computing system and the second remote computing system in response to the verification of the one or more of the complete set of parameters are satisfied by the one or more corresponding current parameters.

14. The non-transitory machine-readable medium of claim 10 , wherein the request to initiate the routing of data comprises a request to generate the token, further comprising:

analyzing, by an analytics engine of the server computer system, one or more fraud detection parameters associated with the request to generate the token;

detecting, by the analytics engine, whether the determined risk of fraud satisfies a fraud detection threshold;

rejecting the request to generate the token when the determined risk of fraud fails to satisfy the fraud detection threshold; and

accepting the request to generate the token when the determined risk of fraud satisfies the fraud detection threshold.

15. A server computer system for processing a routing of data between a first remote computing system and a second remote computing system, comprising:

a memory storing instructions; and

a processing system, coupled with the memory, and configured to execute the instructions causing the server computer system to perform operations, comprising:

receiving, by an interface of the server computer system from the first remote computing system, a request to initiate the routing of data between the first remote computing system and the second remote computing system, the request comprising an incomplete set of parameters;

receiving, by the interface of the server computer system, a validation challenge and a challenge response defined by the first remote computing system;

generating a token for the routing of data, the token referencing at least the first remote computing system and the incomplete set of parameters, and the token decipherable at the server computer system and indecipherable to the first remote computing system and the second remote computing system;

performing a validation of the second remote computing system based on the validation challenge and the challenge response defined by the first remote computing system;

in response to a successful validation of the second remote computing system, receiving, by the interface of the server computer system, a second set of parameters from the second remote computing system, wherein the incomplete set of parameters and the second set of parameters form a complete set of parameters referenced by the token; and

processing the routing of data between the first remote computing system and the second remote computing system using the complete set of parameters referenced by the token.

16. The server computer system of claim 15 , wherein the interface comprises an application programming interface (API) request interface, and wherein the request to initiate the routing of data between the first remote computing system and the second remote computing system, the validation challenge and the challenge response, and the second set of parameters are received as API messages transmitted to the API request interface over a communications network.

17. The server computer system of claim 15 , wherein the processing system is further configured to perform operations, comprising:

generating a randomly generated identifier that references the complete set of parameters;

transmitting, by the server computer system to the first remote computing system, the randomly generated identifier that references the complete set of parameters;

performing the processing, by the server computer system, of the routing of data between the first remote computing system and the second remote computing system in response to receiving the randomly generated identifier with the request to perform the processing of the routing of data.

18. The server computer system of claim 17 , wherein the processing system is further configured to perform operations, comprising:

accessing the complete set of parameters referenced by the randomly generated identifier in response to the receipt of the randomly generated identifier;

verifying one or more of the complete set of parameters are satisfied by one or more corresponding current parameters associated with the routing of data being processed between the first remote computing system and the second remote computing system; and

completing the processing of the routing of data between the first remote computing system and the second remote computing system in response to the verification of the one or more of the complete set of parameters are satisfied by the one or more corresponding current parameters.

19. The server computer system of claim 15 , wherein the request to initiate the routing of data comprises a request to generate the token, and the processing system is further configured to perform operations, comprising:

analyzing, by an analytics engine of the server computer system, one or more fraud detection parameters associated with the request to generate the token;

detecting, by the analytics engine, whether the determined risk of fraud satisfies a fraud detection threshold;

rejecting the request to generate the token when the determined risk of fraud fails to satisfy the fraud detection threshold; and

accepting the request to generate the token when the determined risk of fraud satisfies the fraud detection threshold.

Assignments (2)
CHANGE OF NAME Recorded Mar 6, 2026
From: STRIPE, INC.
To: STRIPE, LLC
Reel/Frame 075020/0639 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2024
From: JANIGA, MATTHEW WILLIAM; BRINKLEY, KAREN ELIZABETH; COGAN, VINCENT MICHAEL; KRAUSZ, BRIAN DAVID
To: STRIPE, INC.
Reel/Frame 066244/0089 →
Continuity (1)
Continuation 15357754 · Nov 21, 2016