IP Library › Granted Patent US 12,235,939
Granted Patent B2
US 12,235,939 · App. 17/669,128 · Granted Feb 25, 2025

Authentication system with message conversion

Inventors: Mark Allen Nelsen (Oakland, CA); Craig O'Connell (San Mateo, CA); Karl Newland (Foster City, CA); Douglas Fisher (Mountain View, CA)
Assignee: VISA INTERNATIONAL SERVICE ASSOCIATION
G06F21/31G06Q20/3224G06Q20/40G06Q20/4016
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,235,939
App. No.
17/669,128
Granted
Feb 25, 2025
Kind
B2
Abstract

A server computing device receives authentication request messages formatted according to a first message format from a party via a computing device of a user involved in a transaction, translates the messages into modified authentication request messages formatted according to a second message format, and transmits the modified authentication request messages to an authorization computer. The server computing device may augment the modified authentication request messages by including data gathered from the received authentication request messages describing the user, user's computing device, and/or network path between the server computing device and user's computing device, as well as risk scores generated based upon the received authentication request message. Additionally, the server computing device receives messages formatted according to the second message format from the authorization computer and translates them into messages formatted according to the first message format to be sent to the user's computing device.

Claims (45)

1. A method comprising:

receiving, by an authorization server computer, a modified transaction authentication request message formatted according to a second International Organization for Standardization (ISO) 8583 message format from a server computing device, wherein the server computing device generates the modified authentication request message based upon a transaction authentication request message formatted according to a first Hypertext Transfer Protocol (HTTP) message format from a computing device of a user, and wherein the server computing device generates and transmits the modified authentication request message by:

receiving, at the server computing device from the computing device of the user, during a transaction with a merchant server computer, over a communications network, the transaction authentication request message for the transaction in the HTTP message format comprising HTTP fields, the transaction authentication request message including both authentication information and authorization information comprising a device identifier of the computing device of the user, a merchant identifier, a merchant location, a card verification value, and a transaction amount;

translating, by the server computing device, the transaction authentication request message to the ISO 8583 message format comprising ISO 8583 fields, by

(i) extracting, using an information collection submodule in the server computing device, the authentication information and the authorization information from the transaction authentication request message in the Hypertext Transfer Protocol (HTTP) message format,

(ii) accessing, using a format conversion submodule in the server computing device, correlations between the ISO 8583 fields and the HTTP fields from a message format database, and

iii) based on the field correlations, generating, using a message generation submodule in the server computing device, the modified transaction authentication request message by inserting the authentication information and the authorization information collected using the information collection submodule and one or more of a geolocation value that identifies a geographic location of the computing device of the user, a feature identifier that identifies characteristics of the computing device of the user, or a network address of the computing device of the user into the ISO 8583 fields to form the modified transaction authentication request message, and

transmitting, by the server computing device to the authorization server computer, the modified transaction authentication request message in the ISO 8583 message format; and

initiating, by the authorization server computer, an authentication process with the user using the computing device.

2. The method of claim 1 , further comprising:

generating, by the authorization server computer, an authentication response message formatted according to the second message format; and

sending, by the authorization server computer, the authentication response message to the server computing device, wherein the server computing device generates a modified authentication response message formatted according to the first message format.

3. The method of claim 1 , wherein the modified authentication request message comprises a risk assessment value.

4. The method of claim 1 , further comprising:

generating, by the authorization server computer, a challenge request message in the ISO 8583 message format requesting authentication of the user;

transmitting, by the authorization server computer to the server computing device, the challenge request message; and

receiving, by the authorization server computer from the server computing device, a modified challenge response message in the ISO 8583 message format, wherein the server computing device sent a modified challenge request message in the HTTP message format to the computing device of the user and converted a received challenge response message in the HTTP message format to the modified challenge response message in the ISO 8583 message format.

5. The method of claim 1 , further comprising:

determining, by the authorization server computer, based on receiving the modified authentication request message, an authorization result;

generating, by the authorization server computer, an authorization response message in the ISO 8583 message format comprising the authorization result; and

transmitting, by the authorization server computer to the server computing device, the authorization response message in the ISO 8583 format.

6. An authorization server computer comprising:

a set of one or more processors; and

a non-transitory computer readable storage medium coupled with the set of processors and storing instructions that, when executed by the set of processors, causes the set of processors to perform a method comprising:

receiving a modified transaction authentication request message formatted according to a second International Organization for Standardization (ISO) 8583 message format from a server computing device, wherein the server computing device generates the modified transaction authentication request message based upon a transaction authentication request message formatted according to a first Hypertext Transfer Protocol (HTTP) message format from a computing device of a user, and wherein the server computing device generates and transmits the modified transaction authentication request message by:

receiving, from the computing device of the user, during a transaction with a merchant server computer, over a communications network, the transaction authentication request message for the transaction in the HTTP message format comprising HTTP fields, the transaction authentication request message including both authentication information and authorization information comprising a device identifier of the computing device of the user, a merchant identifier, a merchant location, a card verification value, and a transaction amount;

translating the transaction authentication request message to the ISO 8583 message format comprising ISO 8583 fields, by

(i) extracting, using an information collection submodule in the server computing device, the authentication information and the authorization information from the transaction authentication request message in the Hypertext Transfer Protocol (HTTP) message format,

(ii) accessing, using a format conversion submodule in the server computing device, correlations between the ISO 8583 fields and the HTTP fields from a message format database, and

(iii) based on the field correlations, generating, using a message generation submodule in the server computing device, the modified transaction authentication request message by inserting the authentication information and the authorization information collected using the information collection submodule and one or more of a geolocation value that identifies a geographic location of the computing device of the user, a feature identifier that identifies characteristics of the computing device of the user, or a network address of the computing device of the user into the ISO 8583 fields to form the modified transaction authentication request message, and

transmitting, to an authorization computer, the modified transaction authentication request message in the ISO 8583 message format; and

initiating an authentication process with the user using the computing device.

7. The authorization server computer of claim 6 , further comprising:

generating a transaction authentication response message formatted according to the second message format; and

sending the transaction authentication response message to the server computing device, wherein the server computing device generates a modified transaction authentication response message formatted according to the first message format.

8. The authorization server computer of claim 6 , wherein the modified transaction authentication request message comprises a risk assessment value.

9. The authorization server computer of claim 6 , the method further comprising:

generating a challenge request message in the ISO 8583 message format requesting authentication of the user;

transmitting, to the server computing device, the challenge request message; and

receiving, from the server computing device, a modified challenge response message in the ISO 8583 message format, wherein the server computing device sent a modified challenge request message in the HTTP message format to the user computing device of the user and converted a received challenge response message in the HTTP message format to the modified challenge response message in the ISO 8583 message format.

10. The authorization server computer of claim 6 , the method further comprising:

determining, based on receiving the modified transaction authentication request message, an authorization result;

generating an authorization response message in the ISO 8583 message format comprising the authorization result; and

transmitting, to the server computing device, the authorization response message in the ISO 8583 format.

11. The authorization server computer of claim 6 , wherein the authorization server computer is an issuer computer that issued an account of the user.

Continuity (3)
Division 14814073 · Jul 30, 2015
Provisional Application 62031084 · Jul 30, 2014
Related Publication 20220164799A1 · May 26, 2022
References Cited (41)
US 8688543B2 · Dominguez · 2014 [cited by applicant]
US 11282082B2 · Nelsen et al. · 2022 [cited by applicant]
US 20030200184A1 · Dominguez · 2003 [cited by examiner]
US 20040254848A1 · Golan et al. · 2004 [cited by applicant]
US 20060271496A1 · Balasubramanian et al. · 2006 [cited by applicant]
US 20070143227A1 · Kranzley et al. · 2007 [cited by applicant]
US 20080154770A1 · Rutherford et al. · 2008 [cited by applicant]
US 20100114776A1 · Weller · 2010 [cited by examiner]
US 20100211938A1 · Singh · 2010 [cited by examiner]
US 20110112954A1 · Bruesewitz et al. · 2011 [cited by applicant]
US 20110258118A1 · Ciruea · 2011 [cited by applicant]
US 20120018506A1 · Hammad et al. · 2012 [cited by applicant]
US 20120144461A1 · Rathbun · 2012 [cited by examiner]
US 20120221468A1 · Kumnick · 2012 [cited by examiner]
US 20130254110A1 · Royyuru et al. · 2013 [cited by applicant]
US 20130254112A1 · Hammad · 2013 [cited by applicant]
US 20140156535A1 · Jabbour · 2014 [cited by examiner]
US 20140164253A1 · Dominguez · 2014 [cited by applicant]
US 20140279477A1 · Sheets · 2014 [cited by applicant]
US 20150120559A1 · Fisher · 2015 [cited by applicant]
US 20150120560A1 · Fisher · 2015 [cited by applicant]
US 20150220890A1 · Seshadri · 2015 [cited by examiner]
US 20160034900A1 · Nelsen et al. · 2016 [cited by applicant]
CN 106575400A · 2017 [cited by applicant]
EP 3175409 · 2017 [cited by applicant]
WO 2016019163A1 · 2016 [cited by applicant]
Ron White, How Computers Work, Oct. 15, 2003, Paul Boger, Illustrated by Timothy Edward Downs, 7th Edition (Year: 2003). [cited by applicant]
Extended European Search Report, mailed Nov. 29, 2017, in EP Application No. 15828186.5, 8 pages. [cited by applicant]
International Search Report and Written Opinion mailed Oct. 27, 2015 in PCT/US2015/042948, 13 pages. [cited by applicant]
Final Office Action, mailed Mar. 17, 2020, U.S. Appl. No. 14/814,073, 23 pages. [cited by applicant]
Final Office Action, mailed Jan. 7, 2019, U.S. Appl. No. 14/814,073, 24 pages. [cited by applicant]
Final Office Action, mailed Mar. 10, 2021, U.S. Appl. No. 14/814,073, 30 pages. [cited by applicant]
Non-Final Office Action, mailed Jun. 15, 2018, U.S. Appl. No. 14/814,073, 18 pages. [cited by applicant]
Non-Final Office Action, mailed Sep. 5, 2019, U.S. Appl. No. 14/814,073, 21 pages. [cited by applicant]
Non-Final Office Action, mailed Aug. 31, 2020, U.S. Appl. No. 14/814,073, 28 pages. [cited by applicant]
Notice of Allowance, mailed Nov. 10, 2021, U.S. Appl. No. 14/814,073, 18 pages. [cited by applicant]
Restriction Requirement, mailed Mar. 29, 2018, U.S. Appl. No. 14/814,073, 6 Pages. [cited by applicant]
Office Action, mailed Feb. 22, 2017, Chinese Patent Application No. CN201580041565.7, 2 pages. [cited by applicant]
Office Action, mailed Feb. 22, 2019, European Patent Application No. EP15828186.5, 7 pages. [cited by applicant]
Summons to Attend Oral Proceedings, mailed Jun. 15, 2020, European Patent Application EP15828186.5, 12 pages. [cited by applicant]
International Preliminary Report on Patentability, mailed Feb. 9, 2017, International Patent Application No. PCT/US2015/042948, 8 pages. [cited by applicant]