IP Library › Granted Patent US 11,449,853
Granted Patent B2
US 11,449,853 · App. 16/319,575 · Granted Sep 20, 2022

System, method, and computer program product for mobile device transactions

Inventors: Venkata Naga Pradeep Kumar Kaja (Foster City, CA); Vijayaraju Konkathi (Union City, CA)
Assignee: Visa International Service Association
G06Q20/3227G06Q20/202G06Q20/322G06Q20/3821G06Q20/3827G06Q20/3829G06Q20/40145H04L9/3231G06Q2220/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,449,853
App. No.
16/319,575
Granted
Sep 20, 2022
Kind
B2
Abstract

Provided is a system, method, and computer program product for conducting a transaction with a mobile device. The method includes generating, on the mobile device, a limited use key based at least partially on at least one biometric input from a user, receiving, on the mobile device, transaction data from a point-of-sale system via a direct wireless communication with the mobile device, the transaction data corresponding to a transaction between the user and a merchant, generating, on the mobile device, a cryptogram based at least partially on the limited use key and the transaction data, and communicating, from the mobile device, the cryptogram to the point-of-sale system via the direct wireless communication.

Claims (63)

1. A computer-implemented method for conducting a transaction with a mobile device, comprising:

generating, by the mobile device, a limited use key based at least partially on at least one biometric input from a user by hashing the at least one biometric input, wherein the mobile device generates the limited use key while offline, and wherein data associated with the at least one biometric input is stored on a data storage device;

receiving, by the mobile device, transaction data from a point-of-sale system via a wireless communication with the mobile device, the transaction data corresponding to a transaction between the user and a merchant, wherein the transaction data comprises at least one user identifier and a token corresponding to an account identifier;

generating, by the mobile device, a cryptogram based at least partially on the limited use key, the token corresponding to the account identifier, and a device identifier of the mobile device by hashing at least the limited use key and the token corresponding to the account identifier, wherein the mobile device generates the cryptogram while offline;

communicating, by the mobile device, the cryptogram to the point-of-sale system via the wireless communication;

receiving, by a transaction processing system, the cryptogram and the transaction data from the point-of-sale system;

identifying, by the transaction processing system, the user based on the at least one user identifier;

searching, by the transaction processing system, the data storage device for data associated with the at least one biometric input from the user;

retrieving, by the transaction processing system, stored biometric data associated with the user and used by the mobile device to generate the limited use key from the data storage device;

generating, by the transaction processing system, a recreated limited use key based on stored biometric data associated with the user;

generating, by the transaction processing system, a recreated cryptogram based at least partially on the recreated limited use key and the transaction data corresponding to the transaction between the user and the merchant;

comparing, by the transaction processing system, the recreated cryptogram and the cryptogram received from the mobile device;

determining, by the transaction processing system, whether the recreated cryptogram matches the cryptogram received from the mobile device; and

in response to determining that the recreated cryptogram matches the cryptogram received by the point-of-sale system from the mobile device, generating an authorization request message and communicating the authorization request message to an issuer system.

2. The computer-implemented method of claim 1 , wherein the transaction data comprises a transaction time, and wherein the cryptogram is generated based at least partially on the transaction time.

3. The computer-implemented method of claim 1 , wherein the at least one biometric input comprises at least one of the following: a spoken word or phrase, a fingerprint, a retina, an iris, a face, or any combination thereof.

4. The computer-implemented method of claim 1 , further comprising authenticating the transaction using the cryptogram.

5. The computer-implemented method of claim 1 , further comprising:

generating, by the mobile device, an account registration message comprising the at least one biometric input; and

communicating, by the mobile device, the account registration message to the issuer system, wherein the account registration message is generated and communicated prior to generating the limited use key.

6. A system for conducting a transaction with a mobile device, comprising:

a mobile device including at least one processor programmed or configured to:

generate a limited use key based at least partially on at least one biometric input from a user by hashing the at least one biometric input, wherein the limited use key is generated while offline, and wherein data associated with the at least one biometric input is stored on a data storage device;

receive transaction data from a point-of-sale system via a wireless communication with the mobile device, the transaction data corresponding to a transaction between the user and a merchant, wherein the transaction data comprises at least one user identifier and a token corresponding to an account identifier;

generate a cryptogram based at least partially on the limited use key, the token corresponding to the account identifier, and a device identifier of the mobile device by hashing at least the limited use key and the token corresponding to the account identifier, wherein the cryptogram is generated while offline; and

communicate the cryptogram to the point-of-sale system via the wireless communication; and

at least one server computer in communication with the point-of-sale system, the at least one server computer including at least one processor programmed or configured to:

receive the cryptogram and the transaction data from the point-of-sale system;

identify the user based on the at least one user identifier;

search the data storage device for data associated with the at least one biometric input from the user;

retrieve stored biometric data associated with the user and used by the mobile device to generate the limited use key from the data storage device;

generate a recreated limited use key based on stored biometric data associated with the user;

generate a recreated cryptogram based at least partially on the recreated limited use key and the transaction data corresponding to the transaction between the user and the merchant;

compare the recreated cryptogram and the cryptogram received from the mobile device;

determine whether the recreated cryptogram matches the cryptogram received from the mobile device; and

in response to determining that the recreated cryptogram matches the cryptogram received by the point-of-sale system from the mobile device, generate an authorization request message and communicate the authorization request message to an issuer system.

7. The system of claim 6 , wherein the transaction data comprises a transaction time, and wherein the cryptogram is generated based at least partially on the transaction time.

8. The system of claim 6 , wherein the at least one biometric input comprises at least one of the following: a spoken word or phrase, a fingerprint, a retina, an iris, a face, or any combination thereof.

9. The system of claim 6 , wherein the at least one server computer authenticates the transaction using the cryptogram.

10. The system of claim 6 , wherein the at least one processor of the at least one server computer is further programmed or configured to:

generate an account registration message comprising the at least one biometric input; and

communicate the account registration message to the issuer system, wherein the account registration message is generated and communicated prior to generating the limited use key.

11. A computer program product for conducting a transaction with a mobile device, comprising:

a first non-transitory computer-readable medium including program instructions that, when executed by at least one mobile device processor, cause the at least one mobile device processor to perform operations comprising:

generating a limited use key based at least partially on at least one biometric input from a user by hashing the at least one biometric input, wherein the limited use key is generated while offline, and wherein data associated with the at least one biometric input is stored on a data storage device;

receiving transaction data from a point-of-sale system via a wireless communication with the point-of-sale system, the transaction data corresponding to a transaction between the user and a merchant, wherein the transaction data comprises at least one user identifier and a token corresponding to an account identifier;

generating a cryptogram based at least partially on the limited use key, the token corresponding to the account identifier, and a device identifier of the mobile device by hashing at least the limited use key and the token corresponding to the account identifier, wherein the cryptogram is generated while offline; and

communicating the cryptogram to the point-of-sale system via the wireless communication; and

a second non-transitory computer-readable medium including program instructions that, when executed by at least one processor of a server computer in communication with the point-of-sale system, cause the at least one processor of the server computer to perform operations comprising:

receiving the cryptogram and the transaction data from the point-of-sale system;

identifying the user based on the at least one user identifier;

searching the data storage device for data associated with the at least one biometric input from the user;

retrieving stored biometric data associated with the user and used by the mobile device to generate the limited use key from the data storage device;

generating a recreated limited use key based on stored biometric data associated with the user;

generating a recreated cryptogram based at least partially on the recreated limited use key and the transaction data corresponding to the transaction between the user and the merchant;

comparing the recreated cryptogram and the cryptogram received from the mobile device;

determining whether the recreated cryptogram matches the cryptogram received from the mobile device; and

in response to determining that the recreated cryptogram matches the cryptogram received by the point-of-sale system from the mobile device, generate an authorization request message and communicate the authorization request message to an issuer system.

12. The computer program product of claim 11 , wherein the transaction data comprises a transaction time, and wherein the cryptogram is generated based at least partially on the transaction time.

13. The computer program product of claim 11 , wherein the at least one biometric input comprises at least one of the following: a spoken word or phrase, a fingerprint, a retina, an iris, a face, or any combination thereof.

14. The computer program product of claim 11 , wherein the program instructions further cause the mobile device processor to:

generate an account registration message comprising the at least one biometric input; and

communicate the account registration message to the issuer system, wherein the account registration message is generated and communicated prior to generating the limited use key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2019
From: KAJA, VENKATA NAGA PRADEEP KUMAR; KONKATHI, VIJAYARAJU
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 048090/0285 →
Continuity (1)
Related Publication 20200193410A1 · Jun 18, 2020
Cited By (1)
US 12,493,879