IP Library › Granted Patent US 12,206,675
Granted Patent B2
US 12,206,675 · App. 18/411,018 · Granted Jan 21, 2025

Pre-authorization access request screening

Inventors: Andrew John Bruno Naumann Zu Koenigsbrueck (Princeton, NJ); Ali Chamseddine (London, GB); Cory Howard Siddens (Mountain View, CA); Benjamin Scott Boding (Mountain View, CA)
Assignee: Visa International Service Association
H04L63/102G06F21/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,206,675
App. No.
18/411,018
Granted
Jan 21, 2025
Kind
B2
Abstract

Systems and methods are described for pre-authentication access request screening. A server computer may receive a request for access to a resource comprising access data. The server computer may transmit, to an authentication computer, an authentication request message comprising at least a subset of the access data and receive an authentication response message comprising authentication data. The server computer may determine an access score based on the authentication data. Alternatively, the server computer may determine the access score based on the access data without using/receiving authorization data. The server computer may generate an access indicator based on the access score. The server computer may prepare and transmit an authorization request message comprising the access indicator to an authorization computer. The authorization computer may approve or decline the access to the resource based on the access indicator.

Claims (60)

1. A method comprising:

receiving, by a server computer from a requesting device, a request for access to a resource to a user device, the request comprising access data;

determining, by the server computer, an access score based on the access data;

identifying a first threshold value corresponding to access requests that should be approved;

identifying a second threshold value corresponding to access requests that should be declined;

comparing the access score to the first threshold value and the second threshold value; and

determining that the access score exceeds the first threshold value and the second threshold value;

generating, by the server computer, an access indicator based on the access score;

preparing, by the server computer, an authorization request message comprising the access indicator; and

transmitting, by the server computer to an authorization computer, the authorization request message comprising the access indicator,

wherein the authorization computer approves or declines the access to the resource to the user device based on the access indicator comprised in the authorization request message.

2. The method of claim 1 , wherein the access indicator comprises a flag indicating that the server computer has approved the access request.

3. The method of claim 1 , further comprising:

receiving, by the server computer from an authentication computer, authentication data.

4. The method of claim 3 , wherein the server computer further uses at least a subset of the authentication data for determining the access score.

5. The method of claim 3 , wherein: the authorization computer further uses the authentication data for determining whether to approve or decline the access to the resource.

6. The method of claim 3 , wherein: the authentication data comprises an authentication code indicating an authentication result and an authentication cryptogram; and

the authorization request message further comprises the authentication code and the authentication cryptogram.

7. The method of claim 3 , wherein: the authentication data comprises supplemental data; and

the authorization request message further comprises the supplemental data.

8. The method of claim 3 , further comprising:

analyzing, by the server computer, the access data in comparison to a plurality of exemptions, wherein if one or more of the plurality of exemptions applies to the access data, authorization is not required; and

based on the access data, determining, by the server computer, that no exemptions apply to the access request.

9. The method of claim 1 , wherein the access indicator is transmitted in an open data field of the authorization request message.

10. The method of claim 1 , further comprising:

analyzing, by the server computer, the access data in comparison to a plurality of exemptions, wherein if one or more of the plurality of exemptions applies to the access data, authorization is not required;

based on the access data, determining, by the server computer, that one or more exemptions apply to the access request; and

based on the determination, transmitting the authorization request message without executing authorization operations.

11. A server computer comprising:

a processor; and

a non-transitory computer-readable medium coupled to the processor, the non-transitory computer-readable medium comprising code, executable by the processor, to implement operations comprising:

determining an access score based on access data obtained from a request for access to a resource to a user device;

identifying a first threshold value corresponding to access requests that should be approved;

identifying a second threshold value corresponding to access requests that should be declined;

comparing the access score to the first threshold value and the second threshold value; and

determining that the access score exceeds the first threshold value and the second threshold value;

generating an access indicator based on the access score;

preparing an authorization request message comprising the access indicator; and

transmitting, to an authorization computer, the authorization request message comprising the access indicator,

wherein the authorization computer approves or declines the access to the resource to the user device based on the access indicator comprised in the authorization request message.

12. The server computer of claim 11 , the operations further comprising:

receiving authentication data, wherein the server computer further uses at least a subset of the authentication data for determining the access score.

13. The server computer of claim 12 , wherein the server computer further uses at least a subset of the authentication data for determining the access score.

14. A method comprising:

receiving, by a server computer from a requesting device, a request for access to a resource to a user device, the request comprising access data;

transmitting, by the server computer to an authentication computer, an authentication request message comprising at least a subset of the access data;

receiving, by the server computer from the authentication computer, an authentication response message comprising authentication data corresponding to a level of authentication of the user device by the authentication computer, wherein the authentication computer generated the authentication data based on the access data;

determining, by the server computer, an access score based on the authentication data and the access data;

analyzing, by the server computer, the access data in comparison to a plurality of exemptions, wherein if one or more of the plurality of exemptions applies to the access data, authorization is not required; and

based on the access data, determining, by the server computer, that no exemptions apply to the access request; and

determining, by the server computer based on the access score, whether to transmit an authorization request message to an authorization computer.

15. The method of claim 14 , further comprising:

generating an access indicator based on the access score; and

transmitting the access indicator to the authorization computer,

wherein the authorization computer approves or declines the access to the resource based on the access indicator.

16. The method of claim 15 , wherein the access indicator is transmitted in an open data field of the authorization request message.

17. The method of claim 15 , wherein the access indicator comprises a flag indicating that the server computer has approved the access request.

18. The method of claim 15 , further comprising:

transmitting the access score to the authorization computer,

wherein the authorization computer approves or declines the access to the resource based on the access score.

Continuity (3)
Continuation 17263527
Provisional Application 62712909 · Jul 31, 2018
Related Publication 20240154969A1 · May 9, 2024
References Cited (23)
US 8601531B1 · Zolfonoon · 2013 [cited by examiner]
US 9367844B1 · Hu et al. · 2016 [cited by applicant]
US 9996837B2 · Siddens et al. · 2018 [cited by applicant]
US 10389731B2 · DiAcetis · 2019 [cited by examiner]
US 11368433B1 · Clemons · 2022 [cited by examiner]
US 11677547B1 · McDonald · 2023 [cited by examiner]
US 20030074580A1 · Knouse et al. · 2003 [cited by applicant]
US 20050144452A1 · Lynch et al. · 2005 [cited by applicant]
US 20070106582A1 · Baker et al. · 2007 [cited by applicant]
US 20110016534A1 · Jakobsson · 2011 [cited by examiner]
US 20150089585A1 · Novack · 2015 [cited by applicant]
US 20150227936A1 · Bruesewitz et al. · 2015 [cited by applicant]
US 20170076518A1 · Patterson et al. · 2017 [cited by applicant]
US 20180137504A1 · Goldenberg et al. · 2018 [cited by applicant]
US 20180204215A1 · Hu et al. · 2018 [cited by applicant]
US 20200007536A1 · Piel · 2020 [cited by examiner]
US 20210144134A1 · Kurylko · 2021 [cited by examiner]
WO 2007134433A1 · 2007 [cited by applicant]
Notice of Allowance, mailed Oct. 12, 2023, for U.S. Appl. No. 17/263,527, 17 pages. [cited by applicant]
Extended European Search Report, mailed Jul. 20, 2021, for EP Patent Application No. EP19843962.2, 7 pages. [cited by applicant]
International Preliminary Report on Patentability, mailed Feb. 11, 2021, for International Patent Application No. PCT/US2019/012547, 6 pages. [cited by applicant]
International Search Report and Written Opinion, mailed May 1, 2019, for International Patent Application No. PCT/US2019/012547, 10 pages. [cited by applicant]
Notice of Decision to Grant, mailed Nov. 15, 2023, for Singapore Patent Application No. SG11202100775X,, 4 pages. [cited by applicant]