IP Library Granted Patent US 12,627,652
Granted Patent B2
US 12,627,652 · App. 18/759,433 · Granted May 12, 2026

On demand tokenization processing

Inventor: Yuexi Chen (Foster City, CA)
Assignee: Visa International Service Association
H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,627,652
App. No.
18/759,433
Granted
May 12, 2026
Kind
B2
Abstract

One embodiment is related to a method. The method includes receiving from a storage application server computer, a token request message comprising a user identifier associated with a storage application on a user device, and determining a token. The token is a limited use token. The method includes mapping the token to the user identifier, transmitting, a token response message comprising the token to the storage application server computer. The method includes receiving from a processing network computer, a de-tokenization request message comprising the token, after the processing network computer receives an authorization request message comprising the token from a resource provider computer via a transport computer. The method also includes determining the user identifier using the token, and transmitting the user identifier to the processing network computer.

Claims (49)

1 . A method comprising:

receiving, by a token service computer from a storage application server computer, a token request message comprising a user identifier associated with a storage application on a user device operated by user;

determining, by the token service computer, a token, wherein the token is a limited use token;

mapping, by the token service computer, the token to the user identifier;

transmitting, by the token service computer, a token response message comprising the token to the storage application server computer, which provides the token to the storage application on the user device;

receiving, by the token service computer from a processing network computer, a de-tokenization request message comprising the token, after the processing network computer receives an authorization request message comprising the token from a resource provider computer;

determining, by the token service computer, the user identifier using the token; and

transmitting, by the token service computer, the user identifier to the processing network computer, wherein the processing network computer transforms the authorization request message and sends the transformed authorization request message to the storage application server computer for authorization.

2 . The method of claim 1 , further comprising:

receiving, by the token service computer from the processing network computer, a re-tokenization request message, after the processing network computer receives an authorization response message comprising the user identifier from the storage application server computer;

determining, by the token service computer, the token using the user identifier; and

transmitting, by the token service computer, the token to the processing network computer, which transforms the authorization response message to include the token and sends the transformed authorization response message to the resource provider computer.

3 . The method of claim 2 , wherein the user device provides the token to the resource provider computer to request access to a resource offered by a resource provider, and wherein the resource provider determines whether or not to grant access based on the transformed authorization response message.

4 . The method of claim 1 , wherein the authorization request message is in a first format and the transformed authorization request message is in a second format.

5 . The method of claim 4 , wherein the first format is a JSON data format and the second format is an ISO 8583 message format.

6 . The method of claim 1 , wherein the authorization request message further comprises a value for an interaction.

7 . The method of claim 6 , wherein the user device is a mobile phone.

8 . The method of claim 6 , wherein the token is valid for a certain volume of interactions.

9 . The method of claim 8 , wherein the storage application stores data.

10 . The method of claim 1 , wherein the user identifier has a different format than the token.

11 . A server computer comprising:

a processor; and

a computer readable medium comprising code, executable by the processor for implementing a method comprising:

receiving from a storage application server computer, a token request message comprising a user identifier associated with a storage application on a user device;

determining a token, wherein the token is a limited use token;

mapping the token to the user identifier;

transmitting a token response message comprising the token to the storage application server computer, which provides the token to the storage application on the user device;

receiving from a processing network computer, a de-tokenization request message comprising the token, after the processing network computer receives an authorization request message comprising the token from a resource provider computer;

determining the user identifier using the token; and

transmitting the user identifier to the processing network computer, wherein the processing network computer transforms the authorization request message and sends the transformed authorization request message to the storage application server computer for authorization.

12 . The server computer of claim 11 , the method further comprising:

receiving from the processing network computer, a re-tokenization request message, after the processing network computer receives an authorization response message comprising the user identifier from the storage application server computer;

determining the token using the user identifier; and

transmitting, the token to the processing network computer, which transforms the authorization response message to include the token and sends the transformed authorization response message to the resource provider computer.

13 . The server computer of claim 12 , wherein the user device provides the token to the resource provider computer to request access to a resource offered by a resource provider operating the resource provieder computer, and wherein the authorizing entity computer determines whether or not to grant access based on the transformed authorization response message.

14 . The server computer of claim 11 , wherein the authorization request message is in a first format and the transformed authorization request message is in a second format.

15 . The server computer of claim 14 , wherein the first format is a JSON data format and the second format is an ISO 8583 message format.

16 . A method comprising:

receiving, by a token service computer from a service provider computer, a temporary user identifier request message comprising a token or a credential associated with a service provider application on a user device;

determining, by the token service computer, a temporary user identifier, wherein the temporary user identifier is formatted for processing by the service provider computer, the service provider computer associated with the service provider application;

mapping, by the token service computer, the token to the temporary user identifier;

transmitting, by the token service computer, a temporary user identifier response message comprising the temporary user identifier to (i) the service provider computer, which provides the temporary user identifier to the service provider application on the user device or (ii) a storage application server computer;

receiving, by the token service computer from a processing network computer, a temporary user identifier resolve request message comprising the temporary user identifier, after the processing network computer receives an authorization request message comprising the temporary user identifier from the user device via the storage application server computer;

determining, by the token service computer, the token or credential using the temporary user identifier; and

transmitting, by the token service computer, the token or the credential to the processing network computer, wherein the processing network computer transforms the authorization request message and sends the transformed authorization request message to an authorizing entity computer for authorization.

17 . The method of claim 16 , wherein the authorization request message further comprises a value for an interaction and the transformed authorization request message comprises the token or credential and the value for the interaction.

18 . The method of claim 17 , wherein the user device is a mobile phone.

19 . The method of claim 16 , wherein the temporary user identifier response message comprising the temporary user identifier is transmitted to the storage application server computer.

20 . The method of claim 16 , wherein the temporary user identifier response message comprising the temporary user identifier is transmitted to the service provider computer.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE'S ADDRESS BY REMOVING THE SUITE NUMBER THAT WAS ENTERED IN ERROR PREVIOUSLY RECORDED ON REEL 68317 FRAME 677. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Aug 27, 2024
From: CHEN, YUEXI
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 068789/0169 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2024
From: CHEN, YUEXI
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 068317/0677 →
Continuity (1)
Related Publication 20260006023A1 · Jan 1, 2026
References Cited (25)
US 6163771A · Walker · 2000 [cited by examiner]
US 6327578B1 · Linehan · 2001 [cited by examiner]
US 7249097B2 · Hutchison · 2007 [cited by examiner]
US 8543829B2 · von Krogh · 2013 [cited by examiner]
US 8965811B2 · Wankmueller · 2015 [cited by examiner]
US 9996835B2 · Dill et al. · 2018 [cited by applicant]
US 10558969B2 · Prakash · 2020 [cited by examiner]
US 11469895B2 · Shankar · 2022 [cited by examiner]
US 12003640B2 · Tomar · 2024 [cited by examiner]
US 12413580B2 · Thampi · 2025 [cited by examiner]
US 20010045451A1 · Tan · 2001 [cited by examiner]
US 20100088237A1 · Wankmueller · 2010 [cited by examiner]
US 20120030047A1 · Fuentes et al. · 2012 [cited by applicant]
US 20140164243A1 · Aabye · 2014 [cited by examiner]
US 20150195268A1 · Fang · 2015 [cited by examiner]
US 20150350186A1 · Chan · 2015 [cited by examiner]
US 20150371229A1 · Prakash · 2015 [cited by examiner]
US 20170286958A1 · Herman · 2017 [cited by examiner]
US 20170352034A1 · Yu · 2017 [cited by examiner]
US 20180316668A1 · Yasarapu · 2018 [cited by examiner]
US 20190356489A1 · Palanisamy · 2019 [cited by applicant]
US 20200052897A1 · Girish · 2020 [cited by examiner]
US 20210067316A1 · Bellenger · 2021 [cited by examiner]
US 20250337736A1 · Drechsler · 2025 [cited by examiner]
Application No. EP25185749.6, Extended European Search Report, Mailed on Oct. 30, 2025, 12 pages. [cited by applicant]