IP Library › Granted Patent US 12,316,764
Granted Patent B2
US 12,316,764 · App. 18/044,202 · Granted May 27, 2025

Token failsafe system and method

Inventors: Barbara Patterson (South San Francisco, CA); Anjana Surin (Foster City, CA)
Assignee: Visa International Service Association
H04L9/3213H04L9/3297
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,316,764
App. No.
18/044,202
Granted
May 27, 2025
Kind
B2
Abstract

A method comprises a token requestor computer transmitting a first authorization request message comprising a token and first cryptogram for authorization of an interaction to a server computer. The token requestor computer receives a first authorization response message comprising a response code from the server computer, then generates a cryptogram request message comprising the token or a token identifier and the response code. The token requestor computer transmits the cryptogram request message to a token provider computer, which generates a second cryptogram. The token requestor computer receives the second cryptogram and credential and generates a second authorization request message comprising the second cryptogram and the credential. The token requestor computer transmits the second authorization request message to the server computer. A second authorization response message is received from the server computer in response to the second authorization request message. The second authorization response message indicates whether the interaction is authorized.

Claims (52)

1. A method comprising:

transmitting, by a token requestor computer, a first authorization request message comprising a token and a first cryptogram for authorization of an interaction between a user and a resource provider to a server computer, wherein the token is associated with a credential;

receiving, by the token requestor computer, a first authorization response message comprising a response code from the server computer;

responsive to receiving the first authorization response message, generating, by the token requestor computer, a cryptogram request message comprising the token or a token identifier associated with the token and the response code;

transmitting, by the token requestor computer, the cryptogram request message to a token provider computer, wherein the token provider computer generates a second cryptogram, and provides the second cryptogram and the credential to the token requestor computer;

receiving, by the token requestor computer, the second cryptogram and the credential from the token provider computer;

generating, by the token requestor computer, a second authorization request message comprising the second cryptogram and the credential;

transmitting, by the token requestor computer, the second authorization request message to the server computer for the interaction; and

receiving a second authorization response message from the server computer in response to the second authorization request message, the second authorization response message indicating whether the interaction is authorized.

2. The method of claim 1 , wherein the server computer is an authorizing entity computer, wherein after transmitting the first authorization request message, the authorizing entity computer determines that the interaction is declined after evaluating at least the token and the first cryptogram, and generates an authorization response message comprising the response code, wherein the authorization response message is received from the authorizing entity computer, and wherein transmitting the second authorization request message to the server computer for the interaction comprises: transmitting, by the token requestor computer, the second authorization request message to a network processing computer, which determines that the second cryptogram is valid, and then transmits the second authorization request message comprising the credential to the authorizing entity computer, wherein the authorizing entity computer determines whether or not to authorize the interaction based on at least the credential.

3. The method of claim 2 , wherein after the network processing computer provides the second authorization request message to the authorizing entity computer, the network processing computer monitors subsequent interactions for the second cryptogram, wherein if a subsequent authorization request includes the second cryptogram, the network processing computer declines the subsequent authorization request.

4. The method of claim 2 , wherein the token requestor computer is integrated with a resource provider computer.

5. The method of claim 2 , wherein the cryptogram request message comprises an authorization flag that indicates that the interaction is declined.

6. The method of claim 5 , wherein the credential is a first credential, and wherein the token provider computer generates the second cryptogram based on the authorization flag that indicates that the interaction is declined and a second credential, wherein the first credential is associated with the second credential.

7. The method of claim 1 , wherein the response code indicates a reason why the interaction is declined.

8. The method of claim 1 further comprising:

prior to transmitting the first authorization request message, requesting, by the token requestor computer, the token from the token provider computer; and

receiving, by the token requestor computer, the token and the first cryptogram from the token provider computer.

9. The method of claim 8 further comprising:

after receiving the token and the first cryptogram, generating, by the token requestor computer, the first authorization request message comprising the token and the first cryptogram.

10. A token requestor computer comprising:

a processor; and

a computer-readable medium coupled to the processor, the computer-readable medium comprising code executable by the processor for implementing a method comprising:

transmitting a first authorization request message comprising a token and a first cryptogram for authorization of an interaction between a user and a resource provider to a server computer, wherein the token is associated with a credential;

receiving a first authorization response message comprising a response code from the server computer;

responsive to receiving the first authorization response message, generating, by the token requestor computer, a cryptogram request message comprising the token or a token identifier associated with the token and the response code;

transmitting the cryptogram request message to a token provider computer, wherein the token provider computer generates a second cryptogram, and provides the second cryptogram and the credential to the token requestor computer;

receiving the second cryptogram and the credential from the token provider computer;

generating a second authorization request message comprising the second cryptogram and the credential;

transmitting the second authorization request message to the server computer for the interaction; and

receiving a second authorization response message from the server computer in response to the second authorization request message, the second authorization response message indicating whether the interaction is authorized.

11. The token requestor computer of claim 10 , wherein the server computer is an authorizing entity computer, wherein after transmitting the first authorization request message, the authorizing entity computer determines that the interaction is declined after evaluating at least the token and the first cryptogram, and generates an authorization response message comprising the response code, wherein the authorization response message is received from the authorizing entity computer, and wherein transmitting the second authorization request message to the server computer for the interaction comprises:

transmitting the second authorization request message to the network processing computer, which determines that the second cryptogram is valid, and then transmits the second authorization request message comprising the credential to the authorizing entity computer, wherein the authorizing entity computer determines whether or not to authorize the interaction based on at least the credential.

12. The token requestor computer of claim 10 , wherein the server computer is a location access computer, the credential is a user identifier or user biometric data, the interaction is a location access interaction to access a secure location, and the resource provider is a location access provider, and wherein if the second authorization response message indicates that the location access interaction is authorized, the user is granted access to the secure location.

13. The token requestor computer of claim 10 , wherein the response code indicates a reason why the interaction is declined of an incorrect cryptogram, an incorrect token, or a missing data field.

14. The token requestor computer of claim 10 , wherein the method further comprises:

after transmitting the second authorization request message, removing the credential from memory.

15. The token requestor computer of claim 10 , wherein the credential is a first credential, wherein the cryptogram request message comprises an authorization flag that indicates that the interaction is declined, and wherein the token provider computer generates the second cryptogram based on the authorization flag and a second credential, wherein the first credential is associated with the second credential.

16. The token requestor computer of claim 15 , wherein the first credential is a primary account number and wherein the second credential is a verification value.

17. A method comprising:

receiving, by a token provider computer from a token requestor computer, a cryptogram request message comprising a token or a token identifier associated with the token and a response code;

determining, by the token provider computer, whether or not to provide a cryptogram to the token requestor computer based on the response code;

generating, by the token provider computer, the cryptogram;

generating, by the token provider computer, a cryptogram response message comprising the cryptogram and a credential; and

providing, by the token provider computer, the cryptogram response message to the token requestor computer, wherein the token provider computer transmits an authorization request message comprising the cryptogram and the credential to a server computer for an interaction and receives an authorization response message from the server computer in response to the authorization request message, the authorization response message indicating whether the interaction is authorized.

18. The method of claim 17 , wherein the cryptogram request message further comprises an authorization flag, wherein the cryptogram is generated based on the authorization flag, and wherein the response code indicates a reason why the interaction is declined, the method comprising:

retrieving, by the token provider computer, the credential associated with the token identified by the token identifier from a database.

19. The method of claim 17 , wherein the cryptogram is a second cryptogram, wherein the authorization request message is a second authorization request message, wherein the authorization response message is a second authorization response message, the method further comprising:

receiving, by the token provider computer, a request for the token from the token requestor computer; and

providing, by the token provider computer, the token and a first cryptogram associated with the token to the token requestor computer, wherein the token requestor computer provides a first authorization request message comprising the token, the first cryptogram, and interaction data to the server computer, wherein the server computer declines the interaction and provides a first authorization response message comprising the token, the response code, and the interaction data to the token requestor computer.

20. The method of claim 19 further comprising:

prior to generating the second cryptogram, verifying, by the token provider computer, that a time between providing the token and the first cryptogram and receiving the second cryptogram request message is less than a predefined timeframe.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2023
From: PATTERSON, BARBARA; SURIN, ANJANA
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 062907/0652 →
Continuity (1)
Related Publication 20230318832A1 · Oct 5, 2023
References Cited (46)
US 8661252B2 · Chandwani · 2014 [cited by examiner]
US 9602508B1 · Mahaffey · 2017 [cited by examiner]
US 9819665B1 · Machani · 2017 [cited by examiner]
US 20100318812A1 · Auradkar · 2010 [cited by examiner]
US 20110270757A1 · Hammad · 2011 [cited by examiner]
US 20120143772A1 · Abadir · 2012 [cited by examiner]
US 20130227291A1 · Ahmed · 2013 [cited by examiner]
US 20130346753A1 · Boysen · 2013 [cited by examiner]
US 20140195807A1 · Bar-El · 2014 [cited by examiner]
US 20140223178A1 · Islam · 2014 [cited by examiner]
US 20160065571A1 · Hoyos · 2016 [cited by examiner]
US 20160156598A1 · Alonso Cebrian · 2016 [cited by examiner]
US 20160232527A1 · Patterson · 2016 [cited by applicant]
US 20160253651A1 · Park et al. · 2016 [cited by applicant]
US 20170124558A1 · Molnar · 2017 [cited by examiner]
US 20170337549A1 · Wong · 2017 [cited by examiner]
US 20170346807A1 · Blasi · 2017 [cited by examiner]
US 20190020478A1 · Girish et al. · 2019 [cited by applicant]
US 20190026450A1 · Egner · 2019 [cited by examiner]
US 20190028478A1 · Love · 2019 [cited by examiner]
US 20190109713A1 · Clark · 2019 [cited by examiner]
US 20190228144A1 · Kermes · 2019 [cited by examiner]
US 20190334718A1 · Li · 2019 [cited by examiner]
US 20190372958A1 · Dunjic · 2019 [cited by examiner]
US 20200053072A1 · Glozman · 2020 [cited by examiner]
US 20200067922A1 · Avetisov · 2020 [cited by examiner]
US 20200077246A1 · Mars · 2020 [cited by examiner]
US 20200104841A1 · Osborn · 2020 [cited by examiner]
US 20200160325A1 · Kim et al. · 2020 [cited by applicant]
US 20200274708A1 · Vijayanarayanan · 2020 [cited by examiner]
US 20200320211A1 · Moore · 2020 [cited by examiner]
US 20200322148A1 · McGough · 2020 [cited by examiner]
US 20210004786A1 · Mossler · 2021 [cited by examiner]
US 20210099297A1 · Mane · 2021 [cited by examiner]
US 20210273804A1 · Khan · 2021 [cited by examiner]
US 20210288973A1 · Dimble · 2021 [cited by examiner]
US 20210344492A1 · Goodsitt · 2021 [cited by examiner]
US 20210392136A1 · Modi · 2021 [cited by examiner]
US 20220021751A1 · Devine · 2022 [cited by examiner]
KR 20150130545A · 2015 [cited by applicant]
WO 2020076854A2 · 2020 [cited by applicant]
Raykova, Mariana et al. Decentralized Authorization and Privacy-Enhanced Routing for Information-Centric Networks. ACSAC '15: Proceedings of the 31st Annual Computer Security Applications Conference. https://doi.org/10.… [cited by examiner]
Dodanduwa, Kavindu; Kaluthanthri, Ishara. Trust-based identity sharing for token grants. ICCSP '19: Proceedings of the 3rd International Conference on Cryptography, Security and Privacy. https://doi.org/10.1145/3309074.… [cited by examiner]
Helland, Randy et al. Authentication and Authorization Considerations for a Multi-tenant Service. Scream '15: Proceedings of the 1st Workshop on The Science of Cyberinfrastructure: Research, Experience, Applications and… [cited by examiner]
PCT/US2020/054929, “International Search Report and Written Opinion”, Jun. 21, 2021, 11 pages. [cited by applicant]
EP20956894.8 , “Extended European Serach Report”, Oct. 5, 2023, 6 pages. [cited by applicant]