IP Library › Granted Patent US 11,538,042
Granted Patent B2
US 11,538,042 · App. 17/370,008 · Granted Dec 27, 2022

Systems and methods for preventing identity fraud of electronic transaction device

Inventors: Daren Lee Pickering (London, GB); Jonathan Stewart Vokes (London, GB); Nicholas Telford-Reed (London, GB)
Assignee: Worldpay Limited
G06Q20/405G06K19/145G06K19/18G06Q20/3278G06Q20/341G06Q20/382
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,538,042
App. No.
17/370,008
Granted
Dec 27, 2022
Kind
B2
Abstract

Tamper-proofing and secure identity validation techniques in a transaction processing system and secure electronic payment techniques are disclosed. A tamper-proof transaction processing device is provided and comprises at least two different strength adhesives to secure parts of the device together and a housing comprising at least a first and second protective layer. An electronic component comprising a secure element chip storing unique information relating to the chip is located between the first and second protective layer in the housing. In another aspect, a transaction processing system includes a payment instrument that is configured to approve only negative value and/or zero value transaction requests. Another aspect provides an identity card checking system and method where the identity card is brought into proximity of a data processing device and identity information is displayed on the screen of the data processing device for the period of time while the card is in proximity.

Claims (71)

1. An identity card checking method comprising:

initiating an identity check when a payment instrument including identity information of a registered owner of the payment instrument is brought into close proximity of a data processing device;

displaying the identity information of the registered owner of the payment instrument on a display of the data processing device; and

removing the identity information of the registered owner of the payment instrument from the display based on a location of the payment instrument.

2. The method of claim 1 , wherein the identity information includes an image of the register owner of the payment instrument; and

wherein the location of the payment instrument is not in close proximity to the data processing device.

3. The method of claim 1 , wherein the method further comprises:

receiving a first data package generated by the payment instrument;

generating an identity request data package based on the first data package; and

transmitting the identity request data package to a server;

wherein the first data package and the identity request data package include at least a unique identifier associated with the payment instrument.

4. The method of claim 3 , wherein the unique identifier is at least one of a PAN associated with the payment instrument or a tokenized PAN associated with the payment instrument.

5. The method of claim 1 , wherein the method further comprises:

transmitting a read request to the payment instrument, the read request indicating that the data processing device requires information relating to the identity of a user of the payment instrument;

receiving the identification information from the server, the identification information including an image of a registered user of the payment instrument; and

updating the display of the data processing device with at least an image of a registered user of the payment instrument when the payment instrument and the data processing device are communicatively coupled.

6. The method of claim 3 , wherein the identity request data package includes an encrypted first data package and a public key of the data processing device, the encrypted first data package being encrypted using a prior public key of the server.

7. The method of claim 6 , wherein the method further comprises:

decrypting the identity request data package using a private key paired with the prior public key of the server;

obtaining information of the registered owner of the payment instrument based on the information in the first data package;

encrypting the information of the registered owner of the payment instrument using the public key of the data processing device;

transmitting the encrypted information of the registered owner as a card owner information package to the data processing device; and

decrypting the encrypted card owner information package using the private key paired with the public key of the data processing device used to encrypt the card owner information.

8. A system comprising:

one or more computer readable media storing instructions for performing an identity card checking; and

one or more processors configured to execute the instructions to perform operations comprising:

initiating an identity check when a payment instrument including identity information of a registered owner of the payment instrument is brought into close proximity of a data processing device;

displaying the identity information of the registered owner of the payment instrument on a display of the data processing device; and

removing the identity information of the registered owner of the payment instrument from the display based on a location of the payment instrument.

9. The system of claim 8 , wherein the identity information includes an image of the register owner of the payment instrument; and

wherein the location of the payment instrument is not in close proximity to the data processing device.

10. The system of claim 8 , the operations further comprising:

receiving a first data package generated by the payment instrument;

generating an identity request data package based on the first data package; and

transmitting the identity request data package to a server;

wherein the first data package and the identity request data package include at least a unique identifier associated with the payment instrument.

11. The system of claim 10 , wherein the unique identifier is at least one of a PAN associated with the payment instrument or a tokenized PAN associated with the payment instrument.

12. The system of claim 8 , the operations further comprising:

transmitting a read request to the payment instrument, the read request indicating that the data processing device requires information relating to the identity of a user of the payment instrument;

receiving the identification information from the server, the identification information including an image of a registered user of the payment instrument; and

updating the display of the data processing device with at least an image of a registered user of the payment instrument when the payment instrument and the data processing device are communicatively coupled.

13. The system of claim 10 , wherein the identity request data package includes an encrypted first data package and a public key of the data processing device, the encrypted first data package being encrypted using a prior public key of the server.

14. The system of claim 13 , the operations further comprising:

decrypting the identity request data package using a private key paired with the prior public key of the server;

obtaining information of the registered owner of the payment instrument based on the information in the first data package;

encrypting the information of the registered owner of the payment instrument using the public key of the data processing device;

transmitting the encrypted information of the registered owner as a card owner information package to the data processing device; and

decrypting the encrypted card owner information package using the private key paired with the public key of the data processing device used to encrypt the card owner information.

15. A non-transitory computer-readable medium storing instructions for performing an identity card checking, the instructions, when executed by one or more processors, causing the one or more processors to perform operations comprising:

initiating an identity check when a payment instrument including identity information of a registered owner of the payment instrument is brought into close proximity of a data processing device;

displaying the identity information of the registered owner of the payment instrument on a display of the data processing device; and

removing the identity information of the registered owner of the payment instrument from the display based on a location of the payment instrument.

16. The non-transitory computer-readable medium of claim 15 , the operations further comprising:

receiving a first data package generated by the payment instrument;

generating an identity request data package based on the first data package; and

transmitting the identity request data package to a server;

wherein the first data package and the identity request data package include at least a unique identifier associated with the payment instrument.

17. The non-transitory computer-readable medium of claim 16 , wherein the identity information includes an image of the register owner of the payment instrument;

wherein the location of the payment instrument is not in close proximity to the data processing device; and

wherein the unique identifier is at least one of a PAN associated with the payment instrument or a tokenized PAN associated with the payment instrument.

18. The non-transitory computer-readable medium of claim 15 , the operations further comprising:

transmitting a read request to the payment instrument, the read request indicating that the data processing device requires information relating to the identity of a user of the payment instrument;

receiving the identification information from the server, the identification information including an image of a registered user of the payment instrument; and

updating the display of the data processing device with at least an image of a registered user of the payment instrument when the payment instrument and the data processing device are communicatively coupled.

19. The non-transitory computer-readable medium of claim 16 , wherein the identity request data package includes an encrypted first data package and a public key of the data processing device, the encrypted first data package being encrypted using a prior public key of the server.

20. The non-transitory computer-readable medium of claim 19 , the operations further comprising:

decrypting the identity request data package using a private key paired with the prior public key of the server;

obtaining information of the registered owner of the payment instrument based on the information in the first data package;

encrypting the information of the registered owner of the payment instrument using the public key of the data processing device;

transmitting the encrypted information of the registered owner as a card owner information package to the data processing device; and

decrypting the encrypted card owner information package using the private key paired with the public key of the data processing device used to encrypt the card owner information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2021
From: PICKERING, DAREN LEE; VOKES, JONATHAN STEWART; TELFORD-REED, NICHOLAS
To: WORLDPAY LIMITED
Reel/Frame 057021/0473 →
Priority Claims (1)
GB 1601393 · Jan 26, 2016 · national
Continuity (3)
Continuation 16863076 · Apr 30, 2020
Division 15417067 · Jan 26, 2017
Related Publication 20210334806A1 · Oct 28, 2021
Cited By (1)
US 12,662,012