IP Library › Granted Patent US 12,423,672
Granted Patent B2
US 12,423,672 · App. 17/149,008 · Granted Sep 23, 2025

Authentication systems and methods using location matching

Inventors: Jalpesh Chitalia (Castro Valley, CA); Ansar Ansari (San Ramon, CA)
Assignee: Visa International Service Association
G06Q20/3224G06Q20/3276G06Q20/385H04W12/63
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,423,672
App. No.
17/149,008
Granted
Sep 23, 2025
Kind
B2
Abstract

According to some embodiments of the invention, an authentication method is provided. Transaction data for a transaction is received at a communication device from an access device or a resource provider. The transaction data comprises a location of the access device. A location of the communication device is determined by the communication device. It is determined whether a distance between the location of the access device and the location of the communication device is within a predetermined threshold. The transaction is not authorized if the distance between the location of the access device and the location of the communication device is not within a predetermined threshold.

Claims (32)

1. A method of conducting a transaction between a user and a resource provider, the method comprising:

providing, by an access device of a resource provider system associated with the resource provider to a communication device of the user, a code comprising transaction data for the transaction, which provides the transaction data to an application provider computer, which provides a transaction identifier associated with the transaction data to a token server, wherein the transaction data comprises a location of the access device and a first time at which the location of the access device is determined, and wherein the communication device is programmed to determine a location of the communication device and a second time at which the location of the communication device is determined, calculate using a distance module on the communication device, a distance between the location of the access device and the communication device, calculate a time difference between the first time and the second time, and in response to determining that the distance is below a distance threshold and that the time difference is below a time threshold, transmit sensitive information to the application provider computer;

transmitting, by the access device to a resource provider computer in the resource provider system, the transaction data and the transaction identifier;

retrieving, by the resource provider computer from the token server, a token using the transaction identifier, the token associated with the sensitive information;

constructing, by the resource provider computer, an authorization request message comprising the transaction data and the token; and

transmitting, by the resource provider computer, the authorization request message comprising the transaction data and the token to a transaction processing computer, which retrieves the sensitive information associated with the token from the token server and obtains authorization for the transaction.

2. The method of claim 1 , further comprising:

receiving, by the resource provider computer, an authorization response message for the transaction from the transaction processing computer.

3. The method of claim 1 , wherein the application provider computer hosts a digital wallet application operating at the communication device.

4. The method of claim 1 , wherein the access device is a POS terminal.

5. The method of claim 1 , wherein the code is a QR code.

6. The method of claim 1 , wherein obtaining authorization for the transaction comprises transmitting the authorization request message comprising the sensitive information associated with the token to an authorizing entity computer for authorization.

7. The method of claim 6 , wherein the sensitive information comprises a PAN.

8. The method of claim 1 , wherein the communication device of the user also provides a location or address of the access device to the application provider computer.

9. The method of claim 1 , wherein the communication device is a mobile phone.

10. The method of claim 1 wherein the token is a payment token.

11. The method of claim 1 , wherein the authorization request message comprises an amount.

12. The method of claim 11 , wherein the transaction is a payment transaction.

13. A system comprising:

an access device comprising a first processor, and a first non-transitory computer readable medium, the first non-transitory computer readable medium comprising code, executable by the first processor to cause the access device to perform operations including,

providing, to a communication device of a user, a code comprising transaction data for a transaction, which provides the transaction data to an application provider computer, which provides a transaction identifier associated with the transaction data to a token server, wherein the transaction data comprises a location of the access device and a first time at which the location of the access device is determined, and wherein the communication device is programmed to determine a location of the communication device and a second time at which the location of the communication device is determined, calculate using a distance module on the communication device, a distance between the location of the access device and the communication device, calculate a time difference between the first time and the second time, and in response to determining that the distance is below a distance threshold and that the time difference is below a time threshold, transmit sensitive information to the application provider computer, and

transmitting, by the access device to a resource provider computer in the system, the transaction data and the transaction identifier; and

the resource provider computer, the resource provider computer comprising a second processor, and a second non-transitory computer readable medium, the second non-transitory computer readable medium comprising code executable by the second processor to cause the resource provider computer to perform operations including,

retrieving, by the resource provider computer from the token server, a token using the transaction identifier, the token associated with the sensitive information,

constructing, by the resource provider computer, an authorization request message comprising the transaction data and the token, and

transmitting, by the resource provider computer, the authorization request message comprising the transaction data and the token to a transaction processing computer, which retrieves the sensitive information associated with the token from the token server and obtains authorization for the transaction.

14. The system of claim 13 , wherein the access device is a POS terminal.

15. The system of claim 13 , wherein the sensitive information comprises a PAN.

16. The system of claim 13 , wherein the token is in a same format as the sensitive information.

17. The system of claim 13 , wherein the code is a QR code.

18. The system of claim 17 , wherein a location of the access device is embedded in the QR code.

19. The system of claim 17 , further comprising the communication device.

Continuity (3)
Continuation 15431235 · Feb 13, 2017
Provisional Application 62294471 · Feb 12, 2016
Related Publication 20210142312A1 · May 13, 2021
References Cited (74)
US 9928518B1 · Vippagunta · 2018 [cited by examiner]
US 10922672B2 · Chitalia et al. · 2021 [cited by applicant]
US 20090187492A1 · Hammad et al. · 2009 [cited by applicant]
US 20110124317A1 · Joo · 2011 [cited by applicant]
US 20110238514A1 · Ramalingam et al. · 2011 [cited by applicant]
US 20110307710A1 · McGuire et al. · 2011 [cited by applicant]
US 20120022965A1 · Seergy · 2012 [cited by applicant]
US 20120290468A1 · Benco et al. · 2012 [cited by applicant]
US 20130214902A1 · Pineau et al. · 2013 [cited by applicant]
US 20130238455A1 · Laracey · 2013 [cited by examiner]
US 20130268378A1 · Yovin · 2013 [cited by applicant]
US 20140012757A1 · Henderson et al. · 2014 [cited by applicant]
US 20140081783A1 · Paranjape et al. · 2014 [cited by applicant]
US 20140108263A1 · Ortiz et al. · 2014 [cited by applicant]
US 20140222594A1 · Rose et al. · 2014 [cited by applicant]
US 20140337138A1 · Chitalia et al. · 2014 [cited by applicant]
US 20140372308A1 · Sheets · 2014 [cited by applicant]
US 20140380424A1 · Thompson · 2014 [cited by applicant]
US 20150032625A1 · Dill et al. · 2015 [cited by applicant]
US 20150032627A1 · Dill et al. · 2015 [cited by applicant]
US 20150088674A1 · Flurscheim et al. · 2015 [cited by applicant]
US 20150142673A1 · Nelsen et al. · 2015 [cited by applicant]
US 20150199689A1 · Kumnick et al. · 2015 [cited by applicant]
US 20150235195A1 · Lee · 2015 [cited by applicant]
US 20150248664A1 · Makhdumi · 2015 [cited by examiner]
US 20150312038A1 · Palanisamy · 2015 [cited by examiner]
US 20150356560A1 · Shastry et al. · 2015 [cited by applicant]
US 20160042263A1 · Gaddam et al. · 2016 [cited by applicant]
US 20170221054A1 · Flurscheim · 2017 [cited by examiner]
US 20170236113A1 · Chitalia et al. · 2017 [cited by applicant]
US 20180144339A1 · Beidas · 2018 [cited by applicant]
US 20210264434A1 · Sheets · 2021 [cited by examiner]
CN 102272767A · 2011 [cited by applicant]
CN 104838399A · 2015 [cited by applicant]
CN 104883686A · 2015 [cited by applicant]
EP 2634739 · 2013 [cited by applicant]
JP 2013513158A · 2013 [cited by applicant]
JP 2016524249A · 2016 [cited by applicant]
WO 2013113004A1 · 2013 [cited by applicant]
WO 2014202951A1 · 2014 [cited by applicant]
WO 2015179922A1 · 2015 [cited by applicant]
WO 2017139772 · 2017 [cited by applicant]
AU2017218013 , “Fourth Examination Report”, Mar. 22, 2022, 5 pages. [cited by applicant]
CN201780009300.8 , “Notice of Decision to Grant”, Jan. 11, 2022, 4 pages. [cited by applicant]
AU2022202599 , “Second Examination Report”, Aug. 30, 2023, 4 pages. [cited by applicant]
CA3,009,364 , “Office Action”, Aug. 24, 2023, 5 pages. [cited by applicant]
JP2022-152306 , “Office Action”, Aug. 15, 2023, 4 pages. [cited by applicant]
AU2017218013 , “First Examination Report”, Apr. 20, 2021, 3 pages. [cited by applicant]
CN201780009300.8 , “Office Action”, Jun. 23, 2021, 14 pages. [cited by applicant]
EP17750971.8 , “Notice of Decision to Grant”, Jun. 24, 2021, 2 pages. [cited by applicant]
AU2022202599 , “Third Examination Report”, Feb. 6, 2024, 5 pages. [cited by applicant]
CN201780009300.8 , “Office Action”, Jan. 12, 2021, 19 pages. [cited by applicant]
JP2018-541140 , “Office Action”, Mar. 5, 2021, 5 pages. [cited by applicant]
Application No. EP21186580.3 , Extended European Search Report, Mailed on Oct. 20, 2021, 9 pages. [cited by applicant]
AU2022202599 , “First Examination Report”, Apr. 20, 2023, 6 pages. [cited by applicant]
EP 21186583.3, “Examination Report”, May 5, 2023, 4 pages. [cited by applicant]
AU2017218013 , “Second Examination Report”, Aug. 30, 2021, 4 pages. [cited by applicant]
IN201847033161 , “First Examination Report”, Jul. 30, 2021, 6 pages. [cited by applicant]
AU2017218013 , “Third Examination Report”, Oct. 28, 2021, 6 pages. [cited by applicant]
JP2018-541140 , “Office Action”, Nov. 24, 2021, 3 pages. [cited by applicant]
U.S. Appl. No. 15/431,235 , “Final Office Action”, Jun. 13, 2019, 35 pages. [cited by applicant]
U.S. Appl. No. 15/431,235 , “Final Office Action”, Aug. 4, 2020, 6 pages. [cited by applicant]
U.S. Appl. No. 15/431,235 , “Non-Final Office Action”, Mar. 16, 2020, 13 pages. [cited by applicant]
U.S. Appl. No. 15/431,235 , “Non-Final Office Action”, Nov. 29, 2018, 33 pages. [cited by applicant]
U.S. Appl. No. 15/431,235 , “Notice of Allowance”, Oct. 14, 2020, 10 pages. [cited by applicant]
EP17750971.8 , “Extended European Search Report”, Oct. 8, 2018, 12 pages. [cited by applicant]
EP17750971.8 , “Office Action”, Apr. 9, 2020, 4 pages. [cited by applicant]
PCT/US2017/017682 , “International Preliminary Report on Patentability”, Aug. 23, 2018, 7 pages. [cited by applicant]
PCT/US2017/017682 , “International Search Report and Written Opinion”, Feb. 10, 2017, 10 pages. [cited by applicant]
Zhang et al., “Location-Based Authentication and Authorization Using Smart Phones”, 2012 IEEE 11th International Conference on Trust, Security and Privacy in Computing and Communications, 2012, pp. 1285-1292. [cited by applicant]
JP2018-541140 , “Office Action”, Jun. 7, 2022, 5 pages. [cited by applicant]
AU2022202599 , “Fourth Examination Report”, Apr. 18, 2024, 3 pages. [cited by applicant]
CN202210312351.0 , “Office Action”, Mar. 19, 2025, 13 pages. [cited by applicant]
CA3,009,364 , “Office Action”, Nov. 22, 2022, 5 pages. [cited by applicant]