IP Library Granted Patent US 11,847,643
Granted Patent B2
US 11,847,643 · App. 17/516,189 · Granted Dec 19, 2023

Secure remote payment transaction processing using a secure element

Inventors: Igor Karpenko (Sunnyvale, CA); Oleg Makhotin (Paris, FR); Kiushan Pirzadeh (Foster City, CA); Glenn Powell (Fremont, CA); John Sheets (San Francisco, CA); Erick Wong (Menlo Park, CA)
Assignee: Visa International Service Association
G06Q20/3829G06Q20/3227G06Q20/3278G06Q20/38215G06Q20/401G06Q20/409
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,847,643
App. No.
17/516,189
Granted
Dec 19, 2023
Kind
B2
Abstract

Embodiments of the present invention are directed to methods, apparatuses, computer readable media and systems for securely processing remote transactions. One embodiment of the invention is directed to a method of processing a remote transaction initiated by a mobile device. The method comprises receiving, by a mobile payment application on a secure memory of the mobile device, transaction data from a transaction processor application on the mobile device. The method further comprises validating that the transaction processor application is authentic and in response to validating the transaction processor application, providing encrypted payment credentials to the transaction processor application. The transaction processor application further initiates a payment transaction with a transaction processor server computer using the encrypted payment credentials.

Claims (40)

1. A method comprising:

receiving, by a certificate authority computer from a remote transaction application on a mobile device comprising a secure element comprising a payment credential, a merchant certificate status request of a merchant certificate for a transaction conducted between a merchant associated with the merchant certificate and a user operating the mobile device;

determining, by the certificate authority computer, a status of the merchant certificate;

generating, by the certificate authority computer, a merchant certificate status response;

transmitting, by the certificate authority computer, the merchant certificate status response to the remote transaction application on the mobile device;

after the remote transaction application on the mobile device receives the merchant certificate status response, receiving, by a processing network computer, an authorization request message for the transaction and comprising the payment credential from a merchant computer operated by the merchant after the merchant computer receives the payment credential from the secure element on the mobile device;

transmitting, by the processing network computer, the authorization request message to an issuer computer;

receiving, by the processing network computer, an authorization response message from the issuer computer; and

transmitting, by the processing network computer, the authorization response message to the merchant computer.

2. The method of claim 1 , wherein the remote transaction application is a digital wallet application.

3. The method of claim 1 , wherein the remote transaction application is in communication with the merchant computer via a merchant application, the merchant application and the remote transaction application being on the mobile device.

4. The method of claim 1 , wherein the remote transaction application is in communication with the merchant computer via a merchant application.

5. The method of claim 1 , wherein the status of the merchant certificate is determined using a certificate identifier associated with the merchant certificate.

6. The method of claim 1 , wherein the remote transaction application signs transaction data for the transaction after the merchant certificate status response is received by the remote transaction application.

7. The method of claim 1 , wherein the remote transaction application signs transaction data for the transaction after the merchant certificate status response is received by the remote transaction application, and provides the signed transaction data and the merchant certificate to a mobile payment application, which validates the signed transaction data and uses a public key of the merchant certificate to encrypt the payment credential used in the transaction.

8. The method of claim 1 , wherein the remote transaction application signs transaction data for the transaction after the merchant certificate status response is received by the remote transaction application, and provides the signed transaction data and the merchant certificate to a mobile payment application, which validates the signed transaction data and uses a public key of the merchant certificate to encrypt the payment credential used in the transaction and provides the encrypted payment credential to the merchant computer.

9. The method of claim 8 , wherein the merchant computer decrypts the encrypted payment credential and includes the payment credential in the authorization request message.

10. The method of claim 1 , wherein the authorization request message comprises a transaction amount for the transaction.

11. The method of claim 1 , wherein the authorization request message is received via an acquirer computer.

12. The method of claim 1 , wherein the authorization request message comprises a transaction amount and is received via an acquirer computer.

13. A system comprising:

a mobile device comprising a remote transaction application and a secure element comprising a payment credential;

a certificate authority computer comprising a first processor, and a first computer readable medium comprising code, executable by the first processor to perform operations including:

receiving, from the remote transaction application on the mobile device, a merchant certificate status request of a merchant certificate for a transaction conducted between a merchant associated with the merchant certificate and a user operating the mobile device, determining a status of the merchant certificate, generating a merchant certificate status response, and transmitting the merchant certificate status response to the remote transaction application on the mobile device; and

a processing network computer comprising a second processor, and a second computer readable medium, the second computer readable medium comprising code, executable by the second processor, for implementing operations including:

after the remote transaction application on the mobile device receives the merchant certificate status response, receiving an authorization request message for the transaction and comprising the payment credential from a merchant computer operated by the merchant after the merchant computer receives the payment credential from the secure element on the mobile device,

transmitting the authorization request message to an issuer computer,

receiving an authorization response message from the issuer computer, and

transmitting the authorization response message to the merchant computer.

14. The system of claim 13 , wherein the processing network computer is in a payment processing network.

15. The system of claim 13 , wherein

the mobile device is a mobile phone.

16. The system of claim 13 , further comprising:

the merchant computer.

17. The system of claim 13 , further comprising:

the mobile device, wherein the mobile device is a mobile phone.

18. The system of claim 13 , further comprising:

the mobile device, wherein the mobile device comprises the remote transaction application.

19. The system of claim 13 , wherein the status of the merchant certificate is determined using a certificate identifier associated with the merchant certificate.

20. The system of claim 13 , wherein the certificate authority computer and the processing network computer are operated by a same entity.

Continuity (4)
Continuation 15471800 · Mar 28, 2017
Continuation 14461227 · Aug 15, 2014
Provisional Application 61866514 · Aug 15, 2013
Related Publication 20220051237A1 · Feb 17, 2022
Cited By (1)
US 12,396,413