IP Library › Granted Patent US 11,775,959
Granted Patent B2
US 11,775,959 · App. 15/621,577 · Granted Oct 3, 2023

Transaction authorization

Inventor: Nicolas David Mackie (London, GB)
Assignee: Visa Europe Limited
G06Q20/352G06Q20/20G06Q20/3224G06Q20/3278G06Q20/354G06Q20/382
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,775,959
App. No.
15/621,577
Granted
Oct 3, 2023
Kind
B2
Abstract

Methods, apparatus and computer programs for authorizing transactions are described. A server system receives, from a first computing device, verification information relating to a verification process for verifying a user associated with the first computing device. A verification status associated with the user is set in a memory of the server system, based on the verification information. The server system receives an authorization request for a payment transaction from a payment terminal, the request including an identifier associated with the user, and having been provided to the payment terminal by a payment device different from the first computing device. Responsive to receipt of the authorization request, the verification status associated with the user is identified, and a determination as to whether to authorize the payment transaction is made at least partly on the basis of the identified verification status.

Claims (40)

1. A method of authorizing a payment transaction, the method comprising:

verifying, by a first computing device, a user by: (i) capturing biometric data via a biometric sensor, and (ii) comparing the biometric data captured by the biometric sensor to registered biometric data, the first computing device being a smartphone;

determining, by the first computing device that the first computing device is in a short range communication with a payment device comprising an account number associated with the user;

receiving, at a server system, from the first computing device comprising a memory storing the account number of an account held by the user, a verification message comprising the account number, a first indication that the first computing device verified the user, and a second indication that the first computing device determined that the first computing device is within the short range communication with the payment device comprising the account number associated with the user, the payment device being in form of a card and the second indication produced in response to a signal received by the first computing device from the payment device, which is proximate to the first computing device, wherein the first computing device and the payment device are operated by the user and are separate from a payment terminal;

responsive to receiving the verification message and based on the first indication and the second indication, determining, by the server system, that the first computing device is within the short range communication of the payment device associated with the user, and that the user was verified by the first computing device;

setting, by the server system, a verification status associated with the user to be authorized in a memory of the server system, based on determining that the first computing device is proximate to and within the short range communication of the payment device, and that the user was verified by the first computing device;

determining, by the server system, a number of transactions that have been authorized upon the verification status being set to authorized;

responsive to the number of transactions that have been authorized exceeding a threshold value of transactions, resetting, by the server system, the verification status as being unauthorized;

receiving, at the server system, an authorization request comprising the account number to authorize the payment transaction, the authorization request being received from the payment terminal after detecting the payment device, and receiving the account number from the payment device, the authorization request including a cardholder verification method (CVM) field indicating that the user was verified and that verification has been performed, wherein the payment terminal is a POS terminal;

responsive to receipt of the authorization request, identifying, at the server system, the verification status associated with the user by analyzing the CVM field included in the authorization request; and

determining, at the server system, whether to authorize the payment transaction based on the verification status and the number of transactions that have been authorized being lower than the threshold value of transactions, wherein the payment transaction does not comprise a verification process to verify the user.

2. The method of claim 1 , wherein the authorization request is an EMV-compliant message and the CVM field is a card transaction qualifiers (CTQ) field.

3. The method of claim 1 , wherein the server system is further configured to reset the verification status as being unauthorized in response to a predefined transaction total being reached.

4. The method of claim 1 , wherein the payment transaction comprises a contactless payment transaction, the payment terminal comprises a contactless payment terminal and the payment device comprises a contactless payment device.

5. The method of claim 1 , wherein the signal is an NFC signal.

6. The method of claim 1 , further comprising:

sending, by the server system, a message indicating whether the payment transaction is authorized to the payment terminal.

7. The method of claim 1 , wherein the server system determines whether to authorize the payment transaction based on a comparison of a value of the payment transaction with a predetermined threshold value.

8. The method of claim 1 , wherein the card is a payment card.

9. The method of claim 1 , wherein the short range communication is a Bluetooth communication.

10. The method of claim 9 , wherein the verification message is a Short Message Service (SMS) message.

11. The method of claim 1 , wherein the verification message comprises verification information from a software application held on the first computing device.

12. The method of claim 1 , wherein the server system comprises an issuer host.

13. A system comprising:

a processor; and

a non-transitory computer readable medium, the non-transitory computer readable medium comprising code, executable by the processor to cause the system to:

verify, by a first computing device, a user by: (i) capturing biometric data via a biometric sensor, and (ii) comparing the biometric data captured by the biometric sensor to registered biometric data, the first computing device being a smartphone;

determine, by the first computing device that the first computing device is in a short range communication with a payment device comprising an account number associated with the user;

receive, at a server system, a verification message from the first computing device comprising a memory storing the account number of an account held by the user, the first computing device different from the payment device associated with the user, the verification message comprising the account number, a first indication that the first computing device verified the user, and a second indication that the first computing device determined that the first computing device is within the short range communication with the payment device comprising the account number and associated with the user, the payment device being in form of a card and the second indication produced in response to a signal received by the first computing device from the payment device, which is proximate to the first computing device, wherein the first computing device and the payment device are operated by the user and are separate from a payment terminal;

responsive to receiving the verification message and based on the first indication and the second indication, determine, by the server system, that the first computing device is within the short range communication of the payment device associated with the user, and that the user was verified by the first computing device;

set, by the server system, a verification status associated with the user to be authorized in a memory of the server system, based on determining that the first computing device is proximate to and within the short range communication of the payment device, and that the user was verified by the first computing device;

determine, by the server system, a number of transactions that have been authorized upon the verification status being set to authorized;

responsive to the number of transactions that have been authorized exceeding a threshold value of transactions, reset, by the server system, the verification status as being unauthorized;

receive, from the payment terminal, an authorization request comprising the account number to authorize a payment transaction, the authorization request being received from the payment terminal after detecting the payment device, and receiving the account number from the payment device, the authorization request including a cardholder verification method (CVM) field indicating that the user was verified and that verification has been performed, wherein the payment terminal is a POS terminal;

responsive to receipt of the authorization request, identify, at the server system, the verification status associated with the user by analyzing the CVM field included in the authorization request; and

determine, by the server system, whether to authorize the payment transaction based on the verification status and the number of transactions that have been authorized being lower than the threshold value of transactions, wherein the payment transaction does not comprise a verification process to verify the user.

14. The system of claim 13 , wherein the server system is an issuer host system.

15. The method of claim 1 , wherein the verification status is valid for only a predetermined amount of time.

16. The method of claim 1 , wherein the authorization request is received through an acquirer host computer.

17. The method of claim 1 , wherein the signal is an RF signal.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2017
From: MACKIE, NICOLAS DAVID
To: VISA EUROPE LIMITED
Reel/Frame 043175/0756 →
Priority Claims (1)
GB 1422395 · Dec 16, 2014 · national
Continuity (2)
Continuation PCTGB2015054022 · Dec 16, 2015
Related Publication 20170278094A1 · Sep 28, 2017