Digital access code
A method is disclosed. One embodiment of the invention is directed to a method. The method comprises: prompting, by an access device, a user to enter an access code; receiving, by the access device, the access code from the user; transmitting, by the access device, the access code to a validation computer, which validates the access code; receiving, by the access device, an access identifier or access token from the validation computer in response to validating the access code; transmitting, by the access device, an authorization request message including the access identifier or the access token to an authorizing computer; and receiving, by the access device, an authorization response message from the authorizing computer.
1 . A method comprising:
prompting, by an access device, a user to enter an access code,
responsive to prompting the user to enter the access code, receiving, by the access device, the access code from the user;
transmitting, by the access device, the access code to a validation computer, wherein the access code is transmitted directly from the access device to the validation computer, wherein the access device and the validation computer communicate by invoking an application programming interface (API) that uses mutual secure socket layer authentication and channel encryption, and wherein the validation computer is programmed to identify a stored user-specified delivery channel, selected by the user from options including an email and an application push notification, use the user-specified delivery channel to provide the access code to a user device of the user,
validate the access code received from the access device based on an expiration time period for the access code, the expiration time period determined based on one or more policies including a number of access requests previously transmitted by the user device compared to a time period, and whether the access code was received from the user device;
receiving, by the access device, an account number or payment token from the validation computer in response to validating the access code;
prompting, by the access device, the user for a PIN;
generating, by the access device, an authorization request message including the PIN and the account number or the payment token;
transmitting, by the access device, the authorization request message and a transaction time and date to an authorizing computer;
receiving, by the access device, an authorization response message from the authorizing computer, wherein the authorization response message includes an authorization response generated based on the PIN and the account number or the payment token; and
based on the authorization response message, conducting, by the access device, a transaction with the user.
2 . The method of claim 1 , wherein the access device is an ATM.
3 . The method of claim 1 , further comprising:
generating a notification indicating a result of authorization by the authorizing computer; and
transmitting the notification to the user device which is associated with the user.
4 . The method of claim 3 , wherein the notification includes the access code and a geographic location of the access device associated with the authorization.
5 . The method of claim 1 , wherein the authorizing computer maintains information including the account number which is associated with the user, a type of transaction, a monetary amount of the transaction, and a personal identifier of the user.
6 . A system comprising an access device comprising:
a processor;
a wireless communication device coupled to the processor; and
a memory element including instructions that, when executed with the processor, cause the access device to at least:
prompt a user for an access code,
responsive to prompting the user to enter the access code, receive the access code from the user;
transmit the access code to a validation computer, wherein the access code is transmitted directly from the access device to the validation computer, and wherein the access device and the validation computer communicate by invoking an application programming interface (API) that uses mutual secure socket layer authentication and channel encryption, and wherein the validation computer is programmed to:
identify a stored user-specified delivery channel, selected by the user from options including an email and an application push notification,
use the user-specified delivery channel to provide the access code to a user device of the user, and
validate the access code based on an expiration time period for the access code, determined based on one or more policies including a number of access requests previously transmitted by the user device compared to a time period, and whether the access code was received from the user device;
receive an account number or payment token in response to validating the access code by the validation computer;
prompt the user for a PIN;
generate an authorization request message including the PIN and the account number or the payment token;
transmit the authorization request message and a transaction time and date to an authorizing computer;
receive, from the authorizing computer, an authorization response message, wherein the authorization response message includes an authorization response generated based on the PIN and the account number or the payment token; and
based on the authorization response message, conduct a transaction with the user.
7 . The access device of claim 6 , wherein the access device is an ATM.
8 . The access device of claim 6 , wherein the instructions when executed with the processor further cause the access device to at least:
generate a notification indicating a result of authorization by the authorizing computer; and
transmit the notification to the user device which is associated with the user.
9 . The access device of claim 8 , wherein the notification includes the access code and a geographic location of the access device associated with the authorization.
10 . The access device of claim 6 , wherein the authorizing computer maintains information including the account number which is associated with the user, a type of transaction, a monetary amount of the transaction, and a personal identifier of the user.
11 . The access device of claim 6 , wherein the one or more policies for the expiration time period are specified by the user.
12 . The access device of claim 6 , wherein the one or more policies for the expiration time period are specified by an issuer.
13 . The access device of claim 6 , wherein the authorization request message includes transaction information, the transaction information including a type of transaction associated with the prompt for the access code or an amount of the transaction associated with the prompt for the access code.
14 . The access device of claim 6 , wherein the authorizing computer stores previously generated authorization response messages.
15 . The method of claim 1 , wherein providing the access code to the user device of the user comprises causing display of a graphical user interface (GUI) on the user device, the GUI comprising the access code.
16 . The method of claim 15 , wherein the GUI further comprises a user-selectable option for identifying a nearby access device, and wherein upon user selection of the option, a map comprising the access device is displayed on the user device.
17 . The access device of claim 6 , wherein providing the access code to the user device of the user comprises causing display of a graphical user interface (GUI) on the user device, the GUI comprising the access code.
18 . The access device of claim 17 , wherein the GUI further comprises a user-selectable option for identifying a nearby access device, and wherein upon user selection of the option, a map comprising the access device is displayed on the user device.