IP Library › Granted Patent US 12,170,730
Granted Patent B2
US 12,170,730 · App. 17/714,427 · Granted Dec 17, 2024

Unique token authentication verification value

Inventors: Michael Cassin (Foster City, CA); Christian Flurscheim (Concord, CA); Christopher Jones (Greenbrae, CA)
Assignee: Visa International Service Association
H04L9/3213G06Q20/12G06Q20/14G06Q20/3672G06Q20/3674G06Q20/385H04L63/062H04L63/08H04L9/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,170,730
App. No.
17/714,427
Filed
Apr 6, 2022
Granted
Dec 17, 2024
Kind
B2
Art Unit
2435
USPC
726/9
Abstract

Embodiments of the invention are directed to systems and methods for validating transactions using a cryptogram. One embodiment of the invention is directed to a method of processing a remote transaction initiated by a communication device provisioned with a token. The method comprises receiving, by a service provider computer, from an application on the communication device, a request for a token authentication cryptogram, wherein the token authentication cryptogram includes encrypted user exclusive data. The service provider computer may generate the token authentication cryptogram to include the user exclusive data. The service provider computer may send the token authentication cryptogram to the application, where the token authentication cryptogram can be used to validate the transaction, and the user exclusive data is extracted from the token authentication cryptogram during validation.

Claims (32)

1. A method, comprising:

providing by a resource provider computer to a service provider computer, a token request message for a token authentication cryptogram, wherein the service provider computer generates the token authentication cryptogram by encrypting at least user exclusive data;

receiving, by the resource provider computer from the service provider computer, the token authentication cryptogram; and

transmitting, by the resource provider computer, an authorization request message comprising a token, an amount, and the token authentication cryptogram to a transaction processing computer, wherein the transaction processing computer decrypts the token authentication cryptogram to obtain the user exclusive data and performs an additional analysis using the user exclusive data, wherein the token is a substitute for a credential.

2. The method of claim 1 , wherein the user exclusive data comprises at least one of: a resource provider identifier, user preference information, or a user identifier.

3. The method of claim 1 , wherein the service provider computer generates the token authentication cryptogram by also encrypting the token.

4. The method of claim 1 , further comprising:

receiving, by the resource provider computer from a user device comprising an application, a checkout request.

5. The method of claim 1 , wherein the authorization request message is transmitted to an authorizing entity computer via the transaction processing computer.

6. The method of claim 5 , wherein the transaction processing computer decrypts the token authentication cryptogram to obtain the user exclusive data.

7. The method of claim 6 , wherein the resource provider computer is a merchant computer.

8. The method of claim 7 , wherein the additional analysis is a fraud analysis.

9. The method of claim 1 , wherein the token authentication cryptogram further encrypts the token and a transaction type indicator.

10. The method of claim 1 , wherein the token authentication cryptogram is a hashed value.

11. The method of claim 1 , wherein the token is format preserving.

12. The method of claim 1 , further comprising:

receiving, by the resource provider computer, an authorization response message from an authorizing entity computer.

13. The method of claim 1 , wherein an authorizing entity computer holds an account associated with the credential.

14. The method of claim 1 , wherein the user exclusive data comprises user preferences.

15. A computing device comprising,

a processor, and

a computer readable medium coupled to the processor, the computer readable medium comprising code for causing the processor to perform operations comprising:

providing to a service provider computer, a token request message for a token authentication cryptogram, wherein the service provider computer generates the token authentication cryptogram by encrypting at least user exclusive data;

receiving, from the service provider computer, the token authentication cryptogram; and

transmitting, an authorization request message comprising a token, an amount, and the token authentication cryptogram to a transaction processing computer, wherein the transaction processing computer decrypts the token authentication cryptogram to obtain the user exclusive data and performs an additional analysis using the user exclusive data, wherein the token is a substitute for a credential.

16. The computing device of claim 15 , wherein the computing device is a resource provider computer, and wherein the operations further comprise:

receiving, by the resource provider computer, an authorization response message from an authorizing entity computer.

17. The computing device of claim 15 , wherein the token authentication cryptogram further includes the token in encrypted form.

18. The computing device of claim 15 , wherein the user exclusive data is different from transaction data of the authorization request message.

19. The computing device of claim 15 , wherein the token authentication cryptogram is formed using a symmetric key.

20. The computing device of claim 15 , wherein the operations further comprise further comprise:

receiving, from a user device comprising an application, a checkout request.

Continuity (4)
Continuation 16431532 · Jun 4, 2019
Continuation 15632223 · Jun 23, 2017
Provisional Application 62354340 · Jun 24, 2016
Related Publication 20220231851A1 · Jul 21, 2022