IP Library Granted Patent US 11,017,389
Granted Patent B2
US 11,017,389 · App. 16/217,407 · Granted May 25, 2021

Systems, methods and computer program products for OTP based authorization of electronic payment transactions

Inventors: Gaurav K. Patni (Pune, IN); Ketan Shrikant Joshi (Pune, IN)
Assignee: MASTERCARD INTERNATIONAL INCORPORATED
G06Q20/385G06Q20/40G06Q20/4014H04L63/0838
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,017,389
App. No.
16/217,407
Granted
May 25, 2021
Kind
B2
Abstract

The invention provides methods, systems and computer program products for one-time-password (OTP) based payment authentication. The invention comprises receiving one or more specified transaction parameters corresponding to a specified transaction and generating at an authentication server, an OTP for authorizing a transaction payment corresponding to the specified transaction. The generated OTP is associated with the one or more specified transaction parameters, and may be transmitted to a user for subsequent use to authenticate identity of the user for executing the specified transaction.

Claims (43)

1. A method for one-time-password (OTP) based payment authentication, comprising:

receiving, by an authentication server, one or more specified transaction parameters corresponding to a specified transaction;

generating, by the authentication server, before commencement of the specified transaction, a first OTP for authorizing a transaction payment corresponding to the specified transaction, the first OTP expiring within a predefined time limit;

storing, by the authentication server, an association of the first OTP with the one or more specified transaction parameters within a non-transitory memory;

transmitting, by the authentication server, before commencement of the specified transaction, the first OTP via a network for provision to a user;

receiving, by the authentication server, a second OTP input by the user subsequent to commencement of the specified transaction and one or more detected transaction parameters corresponding to the commenced specified transaction;

retrieving, by the authentication server, the first OTP based on the one or more detected transaction parameters and the stored association between the first OTP and the one or more specified transaction parameters; and

authorizing, by the authentication server, the transaction payment responsive to a determination of a match between the first OTP and the second OTP.

2. The method as claimed in claim 1 , wherein the specified transaction parameters include information identifying a payment card or payment account intended to be used for the transaction payment, and wherein the first OTP is transmitted to a target device or target electronic account associated with the identified payment card or payment account.

3. The method as claimed in claim 1 , wherein the specified transaction parameters or the detected transaction parameters include any one or more of a merchant identifier, identifier corresponding to an item, article or service, transaction type, transaction amount, one or more dates for transaction execution, one or more times for transaction execution, a device identifier associated with a device through which the transaction request is received, and information identifying a payment card or payment account for enabling the transaction payment.

4. The method as claimed in claim 3 wherein the information identifying the payment card or payment account includes one or more of a unique identifier associated with the payment card or payment account, issuer bank information, payment network information, validity information, card verification value (CVV) number, card holder or account holder identity information, issuer bank identifier, issue date and expiry date associated with the payment card or payment account.

5. The method as claimed in claim 1 , wherein the one or more specified transaction parameters are received at the authentication server prior to initiation of the specified transaction or prior to initiation of a network session for execution of the specified transaction.

6. The method as claimed in claim 2 , wherein the first OTP is transmitted to the target device or target electronic account prior to initiation of the specified transaction or prior to initiation of a network session for execution of the specified transaction.

7. The method as claimed in claim 2 , wherein generating the first OTP comprises deducting a transaction amount corresponding to the specified transaction from an available credit associated with the payment card or payment account.

8. The method as claimed in claim 7 , wherein deducting the transaction amount comprises deducting the transaction amount from the available credit associated with the payment card or payment account prior to initiation of the specified transaction or prior to initiation of a network session for execution of the specified transaction.

9. A computer implemented system for one-time-password (OTP) based payment authentication, comprising:

a processor implemented authentication server programmed to:

receive one or more specified transaction parameters corresponding to a specified transaction;

generate, before commencement of the specified transaction, a first OTP for authorizing a transaction payment corresponding to the specified transaction, the first OTP expiring within a predefined time limit;

store an association of the first OTP with the one or more specified transaction parameters within a database that is communicatively coupled with said authentication server;

transmit, before commencement of the specified transaction, the first OTP via a network for provision to a user;

receive a second OTP input by the user subsequent to commencement of the specified transaction;

receive one or more detected transaction parameters corresponding to the commenced specified transaction;

retrieve the first OTP based on the one or more detected transaction parameters and the stored association between the first OTP and the one or more specified transaction parameters; and

authorize the transaction payment responsive to a determination of a match between the first OTP and the second OTP.

10. The computer implemented system as claimed in claim 9 , wherein the specified transaction parameters include information identifying a payment card or payment account intended to be used for the transaction payment, and wherein the first OTP is transmitted to a target device or target electronic account associated with the identified payment card or payment account.

11. The computer implemented system as claimed in claim 9 , wherein the specified transaction parameters or the detected transaction parameters include any one or more of a merchant identifier, identifier corresponding to an item, article or service, transaction type, transaction amount, one or more dates for transaction execution, one or more times for transaction execution, a device identifier associated with a device through which the transaction request is received, and information identifying a payment card or payment account for enabling the transaction payment.

12. The computer implemented system as claimed in claim 11 wherein the information identifying the payment card or payment account includes one or more of a unique identifier associated with the payment card or payment account, issuer bank information, payment network information, validity information, card verification value (CVV) number, card holder or account holder identity information, issuer bank identifier, issue date and expiry date associated with the payment card or payment account.

13. The computer implemented system as claimed in claim 9 , wherein the one or more specified transaction parameters are received at the authentication server prior to initiation of the specified transaction or prior to initiation of a network session for execution of the specified transaction.

14. The computer implemented system as claimed in claim 10 , wherein the first OTP is transmitted to the target device or target electronic account prior to initiation of the specified transaction or prior to initiation of a network session for execution of the specified transaction.

15. The computer implemented system as claimed in claim 10 , wherein to generate the first OTP, the authentication server is further programmed to deduct a transaction amount corresponding to the specified transaction from an available credit associated with the payment card or payment account.

16. The computer implemented system as claimed in claim 15 , wherein the transaction amount is deducted from available credit associated with the payment card or payment account prior to initiation of the specified transaction or prior to initiation of a network session for execution of the specified transaction.

17. A non-transitory computer-readable medium comprising instructions that, when executed by a processor, cause the processor to:

receive one or more specified transaction parameters corresponding to a specified transaction;

generate, before commencement of the specified transaction, a first OTP for authorizing a transaction payment corresponding to the specified transaction, the first OTP expiring within a predefined time limit;

store an association of the first OTP with the one or more specified transaction parameters within a non-transitory memory;

transmit, before commencement of the specified transaction, the first OTP via a network for provision to a user;

receive a second OTP input by the user subsequent to commencement of the specified transaction and one or more detected transaction parameters corresponding to the commenced specified transaction;

retrieve the first OTP based on the one or more detected transaction parameters and the stored association between the first OTP and the one or more specified transaction parameters; and

authorize the transaction payment responsive to a determination of a match between the first OTP and the second OTP.

18. The non-transitory computer-readable medium of claim 17 , wherein the specified transaction parameters include information identifying a payment card or payment account intended to be used for the transaction payment, and wherein the first OTP is transmitted to a target device or target electronic account associated with the identified payment card or payment account.

19. The non-transitory computer-readable medium of claim 18 , wherein to generate the first OTP, the instructions when executed by the processor further cause the processor to: deduct a transaction amount corresponding to the specified transaction from an available credit associated with the payment card or payment account.

20. The non-transitory computer-readable medium of claim 19 , wherein to deduct the transaction amount, the instructions when executed by the processor further cause the processor to: deduct the transaction amount from the available credit associated with the payment card or payment account prior to initiation of the specified transaction or prior to initiation of a network session for execution of the specified transaction.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2018
From: PATNI, GAURAV K.
To: MASTERCARD INTERNATIONAL INCORPORATED
Reel/Frame 047753/0921 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2018
From: PATNI, GAURAV K.; JOSHI, KETAN SHRIKANT
To: MASTERCARD INTERNATIONAL INCORPORATED
Reel/Frame 047757/0168 →
Continuity (1)
Related Publication 20190213585A1 · Jul 11, 2019