IP Library › Granted Patent US 8,341,086
Granted Patent B2
US 8,341,086 · App. 13/300,127 · Granted Dec 25, 2012

End-to-end secure payment processes

Assignee: ProPay, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,341,086
App. No.
13/300,127
Granted
Dec 25, 2012
Kind
B2
Abstract

Systems and method for performing secure electronic payment transactions to allow merchants to perform payment processing such that the merchant payment system is not required to store data specific to a particular payment device.

Claims (24)

1. A method for a payment processing transaction comprising:

at a secure storage device not controlled by a merchant and not actively connected to a secure payment system,

capturing from a payment device unencrypted payment device data and customer identification data,

encrypting the unencrypted payment device data, and

storing the encrypted payment device data; and

at a merchant payment system,

establishing a connection between the secure storage device and the secure payment system,

using a client application on the merchant payment system to read the stored encrypted payment device data from the secure storage device to generate a first payment processing request including the customer identification data and the encrypted payment device data without storing the encrypted payment device data at the merchant payment system such that the encrypted payment device data is not visible to the merchant,

submitting the first payment processing request to the secure payment system,

receiving a unique identifier associated with a customer account that was generated in response to the first payment processing request,

submitting a second payment processing request to the secure payment system such that the merchant is required to identify the unique identifier of the customer account and not unencrypted payment device data or encrypted payment device data of the payment device,

receiving a status from the secure payment system that the second payment processing request is approved, declined, or has experienced an instance of process failure, and

deleting the stored encrypted payment device data from the secure storage device.

2. The method as recited in claim 1 , wherein encrypting the unencrypted payment device data includes using an algorithm that produces encrypted payment data that the secure payment system can decrypt.

3. The method as recited in claim 1 , wherein encrypting the unencrypted payment device data includes using an algorithm that produces encrypted payment device data that a payment authorizing network can decrypt.

4. A method for a merchant to perform a payment processing transaction comprising:

at a merchant payment system,

establishing a connection between a secure payment system and a secure storage device storing encrypted payment device data,

using a client application on the merchant payment system to read the stored encrypted payment device data from the secure storage device to generate a first payment processing request including customer identification data and the encrypted payment device data without storing the encrypted payment device data at the merchant payment system such that the encrypted payment device data is not visible to the merchant,

submitting the first payment processing request to the secure payment system,

receiving a unique identifier associated with a customer account that was generated in response to the first payment processing request,

submitting a second payment processing request to the secure payment system such that the merchant is required to identify the unique identifier of the customer account and not unencrypted payment device data or encrypted payment device data of the payment device,

receiving a status from the secure payment system that the second payment processing request is approved, declined, or has experienced an instance of process failure, and

after receiving the status from the secure payment system that the second payment processing request is approved, declined, or has experienced an instance of process failure, deleting the stored encrypted payment device data from the secure storage device.

Continuity (2)
Continuation 12185706 · Aug 4, 2008
Related Publication 20120072354A1 · Mar 22, 2012