IP Library Granted Patent US 12,169,839
Granted Patent B2
US 12,169,839 · App. 17/632,889 · Granted Dec 17, 2024

Computer-implemented method, system, and computer program product for authenticating a transaction

Inventor: Gurpreet Singh Bhasin (Fremont, CA)
Assignee: Visa International Service Association
G06Q20/4015G06Q20/3224G06Q20/3226G06Q20/389
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,169,839
App. No.
17/632,889
Granted
Dec 17, 2024
Kind
B2
Abstract

A computer-implemented method, system, and computer program product is provided for authenticating a transaction. The method includes: receiving, on a mobile device associated with a user, a request from an authentication system, the request associated with a transaction requested by the user; obtaining, with the mobile device from a portable payment device, account data via radio frequency communication; obtaining, with the mobile device, mobile device location data including at least one of the following: GPS location data, telephone carrier location data, wireless network location data, or any combination thereof; encrypting, with the mobile device, at least a portion of the account data and the mobile device location data, resulting in at least one encrypted data packet; and transmitting, with the mobile device to the authentication system, the at least one encrypted data packet.

Claims (44)

1. A computer-implemented method for authenticating a card-not-present transaction, comprising:

storing, by a mobile device comprising a memory, a graphical user interface (GUI), and a global positioning system (GPS) receiver, account data for a payment device of a user in the memory;

transmitting, by the mobile device, a transaction request message to a merchant system, wherein the transaction request comprises the account data from the memory and an Internet Protocol (IP) address;

receiving, by an authentication system, a transaction initiation message from the merchant system, wherein the transaction initiation message comprises the transaction request and based on the received transaction initiation message, transmitting, by the authentication system, a challenge to the mobile device, wherein the challenge comprises a public key, and the transmitting the challenge further comprises displaying, on the GUI, a prompt for obtaining an account number from the payment device via an NFC connection with the payment device;

receiving, by the mobile device, the challenge and in response to the received challenge:

receiving, by the mobile device, and based on the displayed prompt, the account number from the payment device via the NFC connection with the payment device;

obtaining, by the mobile device, via the GPS receiver, location data; and

generating, by the mobile device, an encrypted data packet, by encrypting the account number and the location data using the public key;

transmitting, by the mobile device, the generated encrypted data packet to the authentication system;

decrypting, by the authentication system, the encrypted data packet using a private key corresponding to the public key, and determining, by the authentication system, that the account number from the decrypted encrypted data matches the account data;

determining, by the authentication system, that a distance between a location of the IP address and a location of the mobile device according to the location data from the decrypted encrypted data is less than a threshold; and

based on determining that the distance is less than the threshold and that the account number from the decrypted encrypted data matches the account data, authenticating, by the authentication system, the transaction.

2. A system for authenticating a card-not-present transaction, comprising:

a mobile device comprising at least one first processor, a global positioning system (GPS) receiver, and a first memory storing executable instructions that when executed by the at least one first processor causes the at least one first processor to perform operations of:

storing a graphical user interface (GUI) and account data for a payment device of a user in the first memory;

transmitting a transaction request to a merchant system, wherein the transaction request comprises the account data from the first memory and an Internet Protocol (IP) address;

an authentication system comprising at least one second processor and a second memory storing executable instructions that when executed by the at least one second processor causes the at least one second processor to perform operations of:

receiving a transaction initiation message from the merchant system, wherein the transaction initiation message comprises the transaction request and based on the received transaction initiation message, transmitting a challenge to the mobile device, wherein the challenge comprises a public key, and the transmitting the challenge further comprises displaying, on the GUI, a prompt for obtaining an account number from the payment device via an NFC connection with the payment device;

the first memory storing executable instructions that when executed by the at least one first processor causes the at least one first processor to further perform the operations of:

receiving the challenge and in response to the received challenge:

receiving, and based on the displayed prompt, the account number from the payment device via the NFC connection with the payment device;

obtaining, via the GPS receiver, location data; and

generating an encrypted data packet, by encrypting the account number and the location data using the public key;

transmitting the generated encrypted data packet to the authentication system;

the second memory storing executable instructions that when executed by the at least one second processor causes the at least one second processor to further perform the operations of:

decrypting the encrypted data packet using a private key corresponding to the public key, and determining that the account number from the decrypted encrypted data matches the account data;

determining that a distance between a location of the IP address and a location of the mobile device according to the location data from the decrypted encrypted data is less than a threshold; and

based on determining that the distance is less than the threshold and that the account number from the decrypted encrypted data matches the account data, authenticating the transaction.

3. A computer program product for authenticating a card-not-present transaction comprising:

a first non-transitory computer-readable medium of a mobile device, wherein the mobile device comprises a first memory, at least one first processor, and a global positioning system (GPS) receiver, storing executable instructions that when executed by the at least one first processor, causes the at least one first processor to perform the operations of:

storing a graphical user interface (GUI) and account data for a payment device of a user in the first memory;

transmitting a transaction request to a merchant system, wherein the transaction request comprises the account data from the first memory and an Internet Protocol (IP) address;

a second non-transitory computer-readable medium of an authentication system, which comprises at least one second processor, storing executable instructions that when executed by the at least one second processor, causes the at least one second processor to perform the operations of:

receiving a transaction initiation message from the merchant system, wherein the transaction initiation message comprises the transaction request and based on the received transaction initiation message, transmitting a challenge to the mobile device, wherein the challenge comprises a public key, and the transmitting the challenge further comprises displaying, on the GUI, a prompt for obtaining an account number from the payment device via an NFC connection with the payment device;

the first non-transitory computer-readable medium of a mobile device, storing executable instructions that when executed by the at least one first processor, causes the at least one first processor to further perform the operations of:

receiving the challenge and in response to the received challenge:

receiving, and based on the displayed prompt, the account number from the payment device via the NFC connection with the payment device;

obtaining, via the GPS receiver, location data; and

generating an encrypted data packet, by encrypting the account number and the location data using the public key;

transmitting the generated encrypted data packet to the authentication system;

the second non-transitory computer-readable medium of an authentication system, which comprises at least one second processor, storing executable instructions that when executed by the at least one second processor, causes the at least one second processor to further perform the operations of:

decrypting the encrypted data packet using a private key corresponding to the public key, and determining that the account number from the decrypted encrypted data matches the account data;

determining that a distance between a location of the IP address and a location of the mobile device according to the location data from the decrypted encrypted data is less than a threshold; and

based on determining that the distance is less than the threshold and that the account number from the decrypted encrypted data matches the account data, authenticating the transaction.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2022
From: BHASIN, GURPREET SINGH
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 058888/0925 →
Continuity (1)
Related Publication 20220270096A1 · Aug 25, 2022