IP Library Granted Patent US 12,373,843
Granted Patent B2
US 12,373,843 · App. 17/571,863 · Granted Jul 29, 2025

Generating a random verification code for a transaction

Inventors: Joshua Edwards (Philadelphia, PA); Abdelkadar M'hamed Benkreira (Washington, DC); Michael Mossoba (Arlington, VA)
Assignee: Capital One Services, LLC
G06Q20/4018G06F7/582G06Q20/326G06Q20/382
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,373,843
App. No.
17/571,863
Filed
Jan 10, 2022
Granted
Jul 29, 2025
Kind
B2
Art Unit
3694
USPC
705/40
Abstract

A device receives, from a user device, a request to generate a verification code for a transaction associated with a user of the user device, and receives user profile information associated with a transaction card to be used for the transaction. The device generates a random verification code for the transaction based on the request and the user profile information, and authenticates the random verification code, based on the user profile information, to generate an authenticated random verification code. The device provides the authenticated random verification code to the user device, and receives transaction information, including the authenticated random verification code, from a merchant device associated with the transaction. The device validates the transaction based on the transaction information, and provides, to the merchant device associated with the transaction, information indicating that the transaction is validated.

Claims (82)

1. A method, comprising:

receiving, by a user device and based on receiving a request to provide a verification code for a transaction associated with a transaction card, user input initiating the transaction;

establishing a communication session between the user device and a transaction device based on receiving the user input initiating the transaction;

selecting, by the user device, an encryption technique from a plurality of encryption techniques;

encrypting, by the user device, using the encryption technique, and based on receiving the user input initiating the transaction, a request to generate the verification code for the transaction, wherein the encryption technique comprises:

encrypting data using a public encryption key, and

decrypting the data using a private decryption key;

automatically providing, by the user device, based on encrypting the request to generate the verification code for the transaction, the request to generate the verification code for the transaction;

receiving, by the user device and based on automatically providing the request to generate the verification code for the transaction, the verification code; and

providing, by the user device, using the encryption technique, and based on receiving the verification code, transaction information associated with the transaction.

2. The method of claim 1 , wherein the verification code is not on the transaction card.

3. The method of claim 1 , wherein the request to generate the verification code includes at least one of:

card number information associated with the transaction card,

first credential information associated with a user of the user device,

second credential information associated with the user device,

identifying information associated with a merchant associated with the transaction, or

biometric information associated with the user.

4. The method of claim 1 , wherein the request to generate the verification code includes verification code generation instructions associated with a user profile, and

wherein the verification code generation instructions indicate whether the verification code is valid for at least one of:

a single transaction,

a particular merchant, or

a particular time period.

5. The method of claim 1 , wherein the transaction information is provided based on receiving additional transaction user input associated with the transaction.

6. The method of claim 1 , wherein the transaction information is provided automatically without additional user input.

7. The method of claim 1 , further comprising:

receiving, based on providing the transaction information, order confirmation information associated with the transaction.

8. The method of claim 1 , further comprising:

automatically populating, based on receiving the verification code, transaction form information including the verification code.

9. A user device, comprising:

one or more memories; and

one or more processors, coupled to the one or more memories, configured to:

receive, based on receiving a request to provide a verification code for a transaction card, user input initiating a transaction;

establish a communication session between the user device and a transaction device based on receiving the user input initiating the transaction;

select an encryption technique from a plurality of encryption techniques;

encrypt, using the encryption technique and based on receiving the user input initiating the transaction, a request to generate the verification code for the transaction, wherein the encryption technique:

encrypts data using a public encryption key, and

decrypts the data using a private decryption key;

automatically provide, to a transaction device and based on encrypting the request to generate the verification code for the transaction, the request to generate the verification code for the transaction;

receive, from the transaction device and based on automatically providing the request to generate the verification code for the transaction, the verification code; and

provide, to a merchant device associated with the transaction, using the encryption technique, and based on receiving the verification code, transaction information associated with the transaction.

10. The user device of claim 9 , wherein the request to generate the verification code includes at least one of:

card number information associated with the transaction card,

first credential information associated with a user of the user device,

second credential information associated with the user device,

identifying information associated with a merchant associated with the transaction, or

biometric information associated with the user.

11. The user device of claim 9 , wherein the request to generate the verification code includes verification code generation instructions associated with a user profile.

12. The user device of claim 11 , wherein the verification code generation instructions indicate whether the verification code is valid for at least one of:

a single transaction,

a particular merchant, or

a particular time period.

13. The user device of claim 9 , wherein the one or more processors are further configured to:

receive, based on providing the transaction information, order confirmation information associated with the transaction.

14. The user device of claim 9 , wherein the one or more processors are further configured to:

automatically populate, based on receiving the verification code, transaction form information including the verification code.

15. A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a user device, cause the user device to:

receive, based on receiving a request to provide a verification code for a transaction associated with a transaction card, user input initiating the transaction;

establish a communication session between the user device and a transaction device based on receiving the user input initiating the transaction;

select an encryption technique from a plurality of encryption techniques;

encrypt, using the encryption technique and based on receiving the user input initiating the transaction, a request to generate the verification code for the transaction, wherein the encryption technique comprises:

encrypting data using a public encryption key; and

decrypting the data using a private decryption key;

automatically provide, based on encrypting the request to generate the verification code for the transaction, the request to generate the verification code for the transaction;

receive, based on automatically providing the request to generate the verification code for the transaction, the verification code; and

automatically provide, using the encryption technique and based on receiving the verification code and without receiving additional user input, transaction information associated with the transaction.

16. The non-transitory computer-readable medium of claim 15 , wherein the request is received from a merchant device associated with the transaction.

17. The non-transitory computer-readable medium of claim 15 , wherein the request to generate the verification code includes at least one of:

card number information associated with the transaction card,

first credential information associated with a user of the user device,

second credential information associated with the user device,

identifying information associated with a merchant associated with the transaction, or

biometric information associated with the user.

18. The non-transitory computer-readable medium of claim 15 , wherein the request to generate the verification code includes verification code generation instructions associated with a user profile.

19. The non-transitory computer-readable medium of claim 15 , wherein the one or more instructions further cause the user device to perform at least one of:

receive, based on providing the transaction information, order confirmation information associated with the transaction, or

automatically populate, based on receiving the verification code, transaction form information including the verification code.

20. The method of claim 1 , further comprising:

generating, based on the encrypted request, the verification code for the transaction, wherein generating the verification code for the transaction comprises:

converting at least a portion of a physical phenomenon to an electrical signal;

increasing an amplitude of fluctuations to a measurable level via electronic circuitry; and

generating a series of random numbers by repeatedly sampling a randomly varying signal.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2022
From: MOSSOBA, MICHAEL; BENKREIRA, ABDELKADAR M'HAMED; EDWARDS, JOSHUA
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 058604/0812 →
Continuity (3)
Continuation 16699939 · Dec 2, 2019
Division 15980175 · May 15, 2018
Related Publication 20220129902A1 · Apr 28, 2022
References Cited (32)
US 7988045B2 · Connell · 2011 [cited by examiner]
US 8355987B2 · Hirson · 2013 [cited by examiner]
US 8538863B1 · Saunders · 2013 [cited by examiner]
US 8676709B2 · Kunz · 2014 [cited by examiner]
US 8806603B2 · Svigals · 2014 [cited by examiner]
US 9424570B2 · Fefferman · 2016 [cited by examiner]
US 10346828B2 · Barrese · 2019 [cited by examiner]
US 10496998B1 · Edwards · 2019 [cited by applicant]
US 11080701B2 · Scott · 2021 [cited by examiner]
US 11222340B2 · Edwards et al. · 2022 [cited by applicant]
US 11354651B2 · Ortiz · 2022 [cited by examiner]
US 20040073688A1 · Sampson · 2004 [cited by examiner]
US 20070219928A1 · Madhogarhia · 2007 [cited by applicant]
US 20080029593A1 · Hammad et al. · 2008 [cited by applicant]
US 20090173782A1 · Muscato · 2009 [cited by applicant]
US 20090187507A1 · Brown et al. · 2009 [cited by applicant]
US 20100179907A1 · Atkinson · 2010 [cited by examiner]
US 20100299220A1 · Baskerville · 2010 [cited by examiner]
US 20120150742A1 · Poon et al. · 2012 [cited by applicant]
US 20120290482A1 · Atef · 2012 [cited by examiner]
US 20140249968A1 · MacKinnon Keith · 2014 [cited by examiner]
US 20150206147A1 · Stanfield et al. · 2015 [cited by applicant]
US 20170140379A1 · Deck et al. · 2017 [cited by applicant]
A New Framework for Credit Card Transactions Involving Mutual Authentication between Cardholder and Merchant; 2011 International Conference on Communication Systems and Network Technologies (pp. 22-26); Gupta, S. Johari… [cited by examiner]
Improvement of the SET Payment System by Using RBAC; 2008 4th International Conference on Wireless Communications, Networking and Mobile Computing (pp. 1-6); Hongxin Li, Yugang Wang, 12-Oct. 2008. (Year: 2008). [cited by examiner]
E-Payment System Using SMS Gateway and Line Application; 2018 International Conference on Information and Communication Technology for the Muslim World (ICT4M) (pp. 173-178); Emir Husni, Muhammad Ayat Hidayat;Jul. 1, 20… [cited by examiner]
A secure SMS protocol for implementing digital cash system; 2015 International Conference on Advances in Computing, Communications and Informatics (ICACCI) (pp. 1883-1892); N. Raghu Kisore, Supriya Sagi; Aug. 10, 2015. … [cited by examiner]
Extended European Search Report for Application No. EP19173204.9, mailed on Jul. 23, 2019, 9 pages. [cited by applicant]
Gaborit P., et al., “Lightweight Code-based Identification and Signature,” 2007 IEEE International Symposium on Information Theory, pp. 191-195. [cited by applicant]
Merhi M., et al., “Studying the Pseudo Random No. Generator of a Low-cost RFID Tag,” 2011 IEEE International Conference on RFID-Technologies and Applications, pp. 381-385. [cited by applicant]
Sung, et al., “User Authentication Using Mobile Phones for Mobile Payment”, International Conference on Information Networking (ICOIN), Cambodia, Jan. 2015, pp. 51-56. [cited by applicant]
Woo, et al., “Verification of Receipts from M-commerce Transactions on NFC Cellular Phones,” 10th IEEE Conference on E-Commerce Technology and the Fifth IEEE Conference on Enterprise Computing, E-Commerce and E-Services… [cited by applicant]