IP Library Granted Patent US 10,089,631
Granted Patent B2
US 10,089,631 · App. 14/661,870 · Granted Oct 2, 2018

System and method of neutralizing mobile payment

Inventors: Sharath Lakshman Kumar (Bangalor, IN); Mahesh Malatesh Chitragar (Bangalore, IN); Vishwanatha Salian (Bangalore, IN); Stephen Prasad (Karnataka, IN)
Assignee: CA, Inc.
G06Q20/407G06Q20/354G06Q20/36G06Q20/405
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,089,631
App. No.
14/661,870
Granted
Oct 2, 2018
Kind
B2
Abstract

A method for preventing mobile payment is described. The method comprises receiving an authorization request at an issuer system from a payment module on a mobile device. The authorization request may be based on sensitive data on the mobile device. The issuer system determines whether the mobile device is missing. The issuer system sends a neutralization trigger to the mobile device, and in response to receiving the neutralization trigger, the payment module is disabled.

Claims (40)

1. A method, comprising:

receiving, at an issuer system, an authorization request from a payment module, wherein the authorization request is based on a limited use key on a mobile device, and wherein the authorization request originates from a contactless transaction between the payment module on the mobile device and a merchant terminal, wherein the merchant terminal communicates with the mobile device via electromagnetic induction;

determining whether the mobile device is missing;

encrypting a neutralization trigger prior to transmitting the neutralization trigger to the mobile device;

transmitting, from the issuer system via the merchant terminal, the neutralization trigger to the mobile device;

wherein the limited use key is camouflaged with a user PIN;

wherein the limited use key is used to generate a dynamic CVV number; and

wherein the neutralization trigger disables the payment module on the mobile device by deleting the limited use key on the mobile device.

2. The method of claim 1 , wherein the mobile device is offline when receiving the neutralization trigger.

3. The method of claim 1 , wherein disabling the payment module comprises deleting the sensitive data on the payment module.

4. The method of claim 1 , wherein the neutralization trigger is an Application Protocol Data Unit command.

5. The method of claim 1 , wherein the limited use key is a one-time key associated with a credit card account.

6. The method of claim 1 , wherein the neutralization trigger is operable to block the payment module from transmitting information.

7. A computer configured to access a storage device, the computer comprising:

a processor; and

a non-transitory, computer-readable storage medium storing computer-readable instructions that when executed by the processor cause the computer to perform:

receiving, at an issuer system, an authorization request from a payment module, wherein the authorization request is based on a limited use key on a mobile device, and wherein the authorization request originates from a contactless transaction between the payment module on the mobile device and a merchant terminal, wherein the merchant terminal communicates with the mobile device via electromagnetic induction;

determining whether the mobile device is missing;

encrypting a neutralization trigger prior to transmitting the neutralization trigger to the mobile device;

transmitting, from the issuer system via the merchant terminal, the neutralization trigger to the mobile device;

wherein the limited use key is camouflaged with a user PIN;

wherein the limited use key is used to generate a dynamic CVV number; and

wherein the neutralization trigger is operable to quarantine sensitive information on the mobile device, and disable the payment module on the mobile device by deleting the limited use key on the mobile device.

8. The computer of claim 7 , wherein the mobile device is offline when receiving the neutralization trigger.

9. The computer of claim 8 , wherein disabling the payment module comprises preventing use of the payment module.

10. The computer of claim 7 , wherein the neutralization trigger is an Application Protocol Data Unit command.

11. The computer of claim 7 , wherein the limited use key is a one-time key associated with a credit card account.

12. The computer of claim 7 , wherein the neutralization trigger is operable to block the payment module from transmitting information.

13. A computer program product comprising:

a computer-readable storage medium having computer-readable program code embodied therewith, the computer-readable program code comprising:

computer-readable program code configured to receive, at an issuer system, an authorization request from a payment module, based on a limited use key on a mobile device, the authorization request based on sensitive data on a mobile device, and wherein the authorization request originates from a contactless transaction between the payment module on the mobile device and a merchant terminal, wherein the merchant terminal communicates with the mobile device via electromagnetic induction;

computer-readable program code configured to determine whether the mobile device is missing;

computer-readable program code configured to encrypt a neutralization trigger prior to transmitting the neutralization trigger to the mobile device;

computer-readable program code configured to transmit, from the issuer system via the merchant terminal, the neutralization trigger to the mobile device wherein the neutralization trigger is operable to delete sensitive information data on the mobile device and disable the payment module on the mobile device by deleting the limited use key on the mobile device;

wherein the limited use key is used to generate a dynamic CVV number; and

wherein the limited use key is camouflaged with a user PIN.

14. The computer program product of claim 13 , wherein the mobile device is offline when receiving the neutralization trigger.

15. The computer program product of claim 14 , wherein disabling the payment module comprises deleting the sensitive data on the payment module.

16. The computer program product of claim 13 , wherein the limited use key is a one-time key associated with a credit card account.

17. The computer program product of claim 13 , wherein the neutralization trigger is operable to block the payment module from transmitting information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2015
From: KUMAR, SHARATH LAKSHMAN; CHITRAGAR, MAHESH MALATESH; SALIAN, VISHWANATHA; PRASAD, STEPHEN
To: CA, INC.
Reel/Frame 035195/0447 →
Continuity (1)
Related Publication 20160275513A1 · Sep 22, 2016