IP Library › Granted Patent US 11,915,243
Granted Patent B2
US 11,915,243 · App. 17/489,463 · Granted Feb 27, 2024

Validation identity tokens for transactions

Inventor: Duane Cash (Mountain View, CA)
Assignee: Visa International Service Association
G06Q20/40145G06Q20/385G06Q20/3829G06Q20/4016H04L63/08H04L63/0807H04L63/0861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,915,243
App. No.
17/489,463
Granted
Feb 27, 2024
Kind
B2
Abstract

A user initiates a transaction by providing identification data at an access device. Certain elements of a validation identity token, such validation keys, may be distributed among several remote server computers. After the elements are retrieved during the transaction, the validation identity token may be generated using the retrieved elements. The validation identity token may indicate whether the user is authenticated. No single entity can possess all elements utilized to generate the validation identity token, which mitigates risk of the validation identity token being compromised. In some embodiments, the validation identity token may be a chromatic identity token, which may indicate validity by color.

Claims (39)

1. A method comprising:

receiving, by a server computer, a request message comprising a validation identity token precursor, the validation identity token precursor being generated using first identification data comprising biometric information of a user, the first identification data being obtained during a payment transaction;

retrieving, by the server computer, a first validation key, wherein the first validation key is configured to be used to form at least part of a first validation identity token;

including, by the server computer, the first validation key and the validation identity token precursor in the request message;

sending, by the server computer, the request message to one or more remote server computers respectively storing second validation keys configured to be used to form at least part of the first validation identity token, the one or more remote server computers including an authorization computer;

receiving, by the server computer, a response message comprising a plurality of validation keys including the second validation keys and the first validation key; and

sending, by the server computer, the response message to an access device, wherein the user is authenticated by comparing the first validation identity token with a second validation identity token, the first validation identity token being generated using the plurality of validation keys and the validation identity token precursor, the second validation identity token being generated using second authentication data comprising biometric information of the user obtained during an enrollment of the user, and determining that a difference between the first validation identity token and the second validation identity token is within a threshold.

2. The method of claim 1 , wherein the first identification data further comprises an account identifier.

3. The method of claim 1 , wherein the plurality of validation keys are chromatic keys, the first validation identity token is a chromatic identity token, and the second validation identity token is a chromatic identity token.

4. The method of claim 1 , wherein the validation identity token precursor is a chromatic identity token precursor, the plurality of validation keys are chromatic keys, the first validation identity token is a chromatic identity token, and the second validation identity token is a chromatic identity token.

5. The method of claim 1 , wherein the request message is an authorization request message.

6. The method of claim 1 , wherein the request message is received from the access device.

7. A server computer comprising:

a processor; and

a computer-readable medium coupled to the processor, the computer-readable medium comprising code, executable by the processor, for performing a method including:

receiving a request message comprising a validation identity token precursor, the validation identity token precursor being generated using first identification data comprising biometric information of a user, the first identification data being obtained during a payment transaction;

retrieving a first validation key, wherein the first validation key is configured to be used to form at least part of a first validation identity token;

including the first validation key and the validation identity token precursor in the request message;

sending the request message to one or more remote server computers respectively storing second validation keys configured to be used to form at least part of the first validation identity token, the one or more remote server computers including an authorization computer;

receiving a response message comprising a plurality of validation keys including the second validation keys and the first validation key; and

sending the response message to an access device, wherein the user is authenticated by comparing the first validation identity token with a second validation identity token, the first validation identity token being generated using the plurality of validation keys and the validation identity token precursor, the second validation identity token being generated using second authentication data comprising biometric information of the user obtained during an enrollment of the user, and determining that a difference between the first validation identity token and the second validation identity token is within a threshold.

8. The server computer of claim 7 , wherein the plurality of validation keys are chromatic keys, the first validation identity token is a chromatic identity token, and the second validation identity token is a chromatic identity token.

9. The server computer of claim 7 , wherein the validation identity token precursor is a chromatic identity token precursor, the plurality of validation keys are chromatic keys, the first validation identity token is a chromatic identity token, and the second validation identity token is a chromatic identity token.

10. The server computer of claim 7 , wherein the request message is an authorization request message.

11. The server computer of claim 7 , wherein the request message is an authorization request message comprising a transaction amount.

12. The server computer of claim 7 , wherein the computer-readable medium comprises a validation key retrieval module, a user information retrieval module, and a transaction processing module.

13. The server computer of claim 7 , wherein the first identification data further comprises a primary account number.

14. A system comprising:

an authorization computer; and

a server computer comprising:

a processor; and

a computer-readable medium coupled to the processor, the computer-readable medium comprising code, executable by the processor, for performing a method including:

receiving a request message comprising a validation identity token precursor, the validation identity token precursor being generated using first identification data comprising biometric information of a user, the first identification data being obtained during a payment transaction,

retrieving a first validation key, wherein the first validation key is configured to be used to form at least part of a first validation identity token,

including the first validation key and the validation identity token precursor in the request message,

sending the request message to one or more remote server computers respectively storing second validation keys configured to be used to form at least part of the first validation identity token,

receiving a response message comprising a plurality of validation keys including the second validation keys and the first validation key, and

sending the response message to an access device, wherein the user is authenticated by comparing the first validation identity token with a second validation identity token, the first validation identity token being generated using the plurality of validation keys and the validation identity token precursor, the second validation identity token being generated using second authentication data comprising biometric information of the user obtained during an enrollment of the user, and determining that a difference between the first validation identity token and the second validation identity token is within a threshold,

wherein the authorization computer is included in the one or more remote server computers.

Continuity (3)
Division 15013825 · Feb 2, 2016
Provisional Application 62111520 · Feb 3, 2015
Related Publication 20220020031A1 · Jan 20, 2022
Cited By (2)
US 12,198,138 US 12,725,157