IP Library › Granted Patent US 12,632,853
Granted Patent B2
US 12,632,853 · App. 18/615,853 · Granted May 19, 2026

Payment authentication system for electronic commerce transactions

Inventor: Rahul Mutha (Norwood, MA)
G06Q20/38215G06Q20/4014H04L9/3228H04L63/0421
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,632,853
App. No.
18/615,853
Granted
May 19, 2026
Kind
B2
Abstract

A payment managing system and method for enhancing the security of electronic user payment data can include employing a two factor authentication and keeping e-commerce host system outside the PCI scope. The two-factor authentication can include using a session ID and a one-time token (OTT). The session ID can identify a payment session that is initiated upon initiation of an e-commerce transaction. The payment managing system can provide a computing device initiating the transaction an iFrame to handle input user input data on an information resource. The OTT can be used to tokenize the user input data. The OTT can be included in payment authorization requests sent to the payment managing system. The payment managing system can obtain payment authorization without the user payment data being shared with e-commerce host systems.

Claims (66)

1 . A system for securing electronic payments, the system comprising:

one or more processors; and

a memory storing computer code instructions, the computer code instructions, when executed by the one or more processors, cause the system to:

provide a session identifier (ID) and a URL of an iFrame to an electronic commerce (e-commerce) host server for forwarding to a computing device responsive to the computing device initiating an e-commerce transaction on an information resource, the URL associated with the session ID;

provide, upon validating a first instance of the session ID, the iFrame to the computing device for display thereon, the iFrame for decoupling processing of user payment data from the information resource and restricting access to the user payment data to the iFrame via executable instructions which cause the computing device to identify, via a user interface of the iFrame, a first selected information comprising one of a billing information, a shipping information or a zip code;

receive, from the e-commerce host server, a second selected information comprising a second one of the billing information, the shipping information or the zip code;

store, in association with the session ID and the URL, the first selected information and the second selected information;

receive user payment data and a second instance of the session ID from the iFrame;

provide, upon validating the second instance of the session ID, a one-time token (OTT) to the computing device for use to initiate payment pre-authorization, the OTT associated with the session ID;

verify consistency of selected data associated with the session ID based on the first selected information and the second selected information;

validate, upon receiving a payment pre-authorization request from the e-commerce host server including an instance of the OTT and responsive to the verified consistency of the selected data, the instance of the OTT;

obtain, upon validating the instance of the OTT, payment pre-authorization from a payment provider system using the user payment data; and

provide an indication of the payment pre-authorization to the e-commerce host server for forwarding to the computing device, the payment pre-authorization allowing the computing device to finalize the e-commerce transaction.

2 . The system of claim 1 , wherein the computer code instructions, when executed by the one or more processors, further cause the system to: receive a request for the iFrame from the computing device, wherein the request includes an instance of the URL appended with the first instance of the session ID.

3 . The system of claim 1 , wherein the computer code instructions, when executed by the one or more processors, further cause the system to:

validate the first instance of the session ID by determining that the first instance of the session ID is equal to the session ID associated with the URL.

4 . The system of claim 1 , wherein the iFrame includes software instructions, which when executed by the computing device cause the computing device to:

display a user interface to prompt input of the user payment data;

encrypt the user input data when input via the user interface; and

send the encrypted user input data to the system.

5 . The system of claim 1 , wherein the computer code instructions, when executed by the one or more processors, cause the system to provide the session ID and the URL of the iFrame to the e-commerce host server via a secure communication link between the system and the e-commerce host server.

6 . The system of claim 1 , wherein the computer code instructions, when executed by the one or more processors, further cause the system to generate the OTT.

7 . The system of claim 1 , wherein the computer code instructions, when executed by the one or more processors, further cause the system to verify consistency of the selected data by comparing geographical data associated with the first selected information with geographical data associated with the second selected information.

8 . The system of claim 1 , wherein in validating the instance of the OTT the computer code instructions, when executed by the one or more processors, cause the system to:

check that the instance of the OTT matches the OTT in a data structure that associates the OTT with the session ID, and that the OTT in the data structure did not expire;

check that the session ID in the data structure is valid; and

determine validity of the OTT upon determining that the OTT in the data structure did not expire and that the session ID in the data structure is valid.

9 . The system of claim 1 , wherein at least one of the billing information, the shipping information, or the zip code corresponds to a geographic location associated with the user.

10 . The system of claim 1 , wherein the computer code instructions when executed by the one or more processors further cause the system to identify a geographic location associated with the user based on at least one of the billing information, the shipping information, or the zip code.

11 . The system of claim 10 , wherein the computer code instructions when executed by the one or more processors further cause the system to verify the consistency of the selected data according to the identified geographic location.

12 . The system of claim 1 , wherein the computer code instructions when executed by the one or more processors further cause the system to identify, based on at least one of the billing information, the shipping information or the zip code, a geographic location from which the user is accessing the system.

13 . A method comprising:

providing, by a digital payment processing system, a session identifier (ID) and a URL of an iFrame to an e-commerce host server over a secure communication link for forwarding to a computing device responsive to the computing device initiating an e-commerce transaction on an information resource, the URL associated with the session ID;

providing, by the digital payment processing system, upon validating a first instance of the session ID, the iFrame to the computing device for display thereon, the iFrame for decoupling processing of user payment data from the information resource and restricting access to the user payment data to the iFrame via executable instructions which cause the computing device to identify, via a user interface of the iFrame, a first selected information comprising one of a billing information, a shipping information or a zip code;

receiving, by the digital processing system, from the e-commerce host server, a second selected information comprising a second one of the billing information, the shipping information or the zip code;

storing, by the digital processing system, in association with the session ID and the URL, the first selected information and the second selected information;

receiving, by the digital payment processing system, user payment data and a second instance of the session ID from the iFrame;

providing, by the digital payment processing system, upon validating the second instance of the session ID, a one-time token (OTT) to the computing device for use to initiate payment pre-authorization, the OTT associated with the session ID;

verifying, by the digital processing system, consistency of selected data associated with the session ID based on the first selected information and the second selected information;

validating, by the digital payment processing system, upon receiving a payment pre-authorization request from the e-commerce host server including an instance of the OTT and responsive to the verified consistency of the selected data, the instance of the OTT;

obtaining, by the digital payment processing system, upon validating the instance of the OTT, payment pre-authorization from a payment provider system using the user payment data; and

providing, by the digital payment processing system, an indication of the payment pre-authorization to the e-commerce host server for forwarding to the computing device, the payment pre-authorization allowing the computing device to finalize the e-commerce transaction.

14 . The method of claim 13 , wherein the URL is valid for a single payment session identified by the session ID.

15 . The method of claim 13 , wherein the iFrame includes software instructions, which when executed by the computing device cause the computing device to:

display a user interface to prompt input of the user payment data;

encrypt the user input data when input via the user interface; and

send the encrypted user input data to the system.

16 . The method of claim 13 , wherein the OTT expires after a predefined time period.

17 . The method of claim 13 , further comprising:

verifying, by the digital payment processing system, consistency of the selected data by comparing geographical data associated with the first selected information with geographical data associated with the second selected information.

18 . The method of claim 13 , further comprising maintaining a data structure associating the OTT with the session ID.

19 . The method of claim 18 , wherein validating the instance of the OTT the computer code instructions includes:

checking that the instance of the OTT matches the OTT in the data structure and that the OTT in the data structure did not expire;

checking that the session ID in the data structure is valid; and

determining validity of the OTT upon determining that the OTT in the data structure did not expire and that the session ID in the data structure is valid.

20 . A non-transitory computer-readable medium including computer code instructions stored thereon, the computer code instructions when execute by one or more processors cause the one or more processors to:

provide a session identifier (ID) and a URL of an iFrame to a e-commerce host server for forwarding to a computing device responsive to the computing device initiating a e-commerce transaction on an information resource, the URL associated with the session ID;

provide, upon validating a first instance of the session ID, the iFrame to a client device for display thereon, the iFrame for decoupling processing of user payment data from the information resource and restricting access to the user payment data to the iFrame via executable instructions which cause the computing device to identify, via a user interface of the iFrame, a first selected information comprising one of a billing information, a shipping information or a zip code;

receive, from the e-commerce host server, a second selected information comprising a second one of the billing information, the shipping information or the zip code;

store, in association with the session ID and the URL, the first selected information and the second selected information;

receive user payment data and a second instance of the session ID from the iFrame;

provide, upon validating the second instance of the session ID, a one-time token (OTT) to the computing device for use to initiate payment pre-authorization, the OTT associated with the session ID;

verify consistency of selected data associated with the session ID based on the first selected information and the second selected information;

validate, upon receiving a payment pre-authorization request from the e-commerce host server including an instance of the OTT and responsive to the verified consistency of the selected data, the instance of the OTT;

obtain, upon validating the instance of the OTT, payment pre-authorization from a payment processor using the user payment data; and

provide an indication of the payment pre-authorization to the e-commerce host server for forwarding to the computing device, the payment pre-authorization allowing the computing device to finalize the e-commerce transaction.

Continuity (2)
Continuation 16510593 · Jul 12, 2019
Related Publication 20240232868A1 · Jul 11, 2024
References Cited (21)
US 11983788B2 · Dharmar · 2024 [cited by examiner]
US 20130060657A1 · Kudva et al. · 2013 [cited by applicant]
US 20130117185A1 · Collison · 2013 [cited by examiner]
US 20180349891A1 · Putre et al. · 2018 [cited by applicant]
US 20190043022A1 · Fosmark et al. · 2019 [cited by applicant]
US 20200097956A1 · Sharma · 2020 [cited by examiner]
WO WO2018002620A1 · 2018 [cited by examiner]
Solat, S., “Security of Electronic Payment Systems: A Comprehensive Survey”, ARXIV ID: 1701.04556, Publication Date: Jan. 17, 2017. (Year: 2017). [cited by examiner]
Final Office Action on U.S. Appl. No. 16/510,593 Dated Nov. 4, 2022. [cited by applicant]
Final Office Action on U.S. Appl. No. 16/510,593 Dated Dec. 7, 2021. [cited by applicant]
Final Office Action on U.S. Appl. No. 16/933,353 Dated Mar. 19, 2021. [cited by applicant]
Final Office Action on U.S. Appl. No. 16/933,353 Dated Mar. 23, 2022. [cited by applicant]
Final Office Action on U.S. Appl. No. 16/933,353 Dated Mar. 27, 2023. [cited by applicant]
Non-Final Office Action on U.S. Appl. No. 16/510,593 Dated May 14, 2021. [cited by applicant]
Non-Final Office Action on U.S. Appl. No. 16/510,593 Dated May 25, 2023. [cited by applicant]
Non-Final Office Action on U.S. Appl. No. 16/510,593 Dated Jun. 23, 2022. [cited by applicant]
Non-Final Office Action on U.S. Appl. No. 16/933,353 Dated Oct. 24, 2022. [cited by applicant]
Non-Final Office Action on U.S. Appl. No. 16/933,353 Dated Nov. 9, 2020. [cited by applicant]
Notice of Allowance on U.S. Appl. No. 16/510,593 Dated Nov. 21, 2023. [cited by applicant]
Notice of Allowance on U.S. Appl. No. 16/933,353 Dated Aug. 21, 2023. [cited by applicant]
US Office Action on U.S. Appl. No. 16/933,353 Dated Nov. 15, 2021. [cited by applicant]