IP Library Granted Patent US 9,256,871
Granted Patent B2
US 9,256,871 · App. 13/558,979 · Granted Feb 9, 2016

Configurable payment tokens

Inventors: Lisa Anderson (San Francisco, CA); Seamus Cushley (Derry, GB); Fergal Downey (Newry, GB)
Assignee: Visa U.S.A. Inc.
G06Q20/385G06Q20/12G06Q20/227
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,256,871
App. No.
13/558,979
Granted
Feb 9, 2016
Kind
B2
Abstract

Methods and systems are disclosed for the generation and use of merchant-customizable token formats that define tokens that represent credit card and other payment numbers in online transactions. The tokens, which are used instead of the card numbers themselves for security, can be specified by the token format to have a certain number of characters, have certain fields reserved for major card identifiers, use encryption and/or randomization, be alphanumeric, and have other formatting. The customized tokens can be used with legacy equipment that uses longer or shorter card numbers than the standard sixteen-digit payment card number format and can be less likely to be recognized as related to card numbers by identify thieves.

Claims (49)

1. A method comprising:

receiving, by a payment processor computer, via a graphical user interface on a merchant computer operated by a merchant, a merchant-configured token format from the merchant, wherein the graphical user interface is configured to allow the merchant to specify a length of characters or character set in the merchant-configured token format, wherein the merchant-configured token format specifies at least one of the length and characters of tokens to be generated;

after receiving the merchant-configured token format, storing, by the payment processor computer, the merchant-configured token format received from the merchant computer in a database;

after the merchant-configured token format is stored, receiving, by the payment processor computer, from the merchant, a payment account number from a customer during a first transaction with the merchant;

generating or receiving, by the payment processor computer, an authorization request message comprising the payment account number;

sending, by the payment processor computer, the authorization request message comprising the payment account number to an issuer computer associated with the payment account number;

receiving, by the payment processor computer, an authorization response message comprising the payment account number from the issuer computer;

after receiving the authorization response message from the issuer computer, retrieving, by the payment processor computer, the merchant-configured token format from the database;

generating, by the payment processor computer, a token associated with the payment account number using the retrieved merchant-configured token format, the token including a set of characters, wherein the token conforms to the merchant-configured token format; and

sending, by the payment processor computer, to the merchant the token associated with the payment account number, wherein the token is stored at the merchant.

2. The method of claim 1 wherein the merchant-configured token format specifies a total number of characters for the tokens to be generated.

3. The method of claim 2 wherein the specified total number of characters for the token is different than a number of total characters of the payment account number.

4. The method of claim 1 wherein the generating the token includes:

encrypting a portion of the payment account number; and

building the token using the encrypted portion of the payment account number.

5. The method of claim 1 wherein the merchant-configured token format specifies one or more characters indicating a particular payment network.

6. The method of claim 1 wherein the merchant-configured token format specifies that only letters are in the tokens to be generated.

7. The method of claim 1 wherein the merchant-configured token format specifies that only numbers are in the tokens to be generated.

8. The method of claim 1 wherein the payment account number identifies an account associated with a card selected from the group consisting of a credit card, debit card, and prepaid card.

9. The method of claim 1 wherein the characters include only those specified by the American Standard Code for Information Exchange (ASCII).

10. The method of claim 1 wherein the generated token is not mod 10 compliant.

11. The method of claim 1 wherein the merchant-configured token format further specifies a position where a portion of the token is generated using a random number generator.

12. The method of claim 1 further comprising:

receiving a selection of the token at the merchant;

receiving the token at the payment processor computer;

determining, by the payment processor computer, the payment account number associated with the token;

generating or receiving, by the payment processor computer, a second authorization request message comprising the payment account number;

sending, by the payment processor computer, the second authorization request message comprising the payment account number to the issuer computer;

receiving, by the payment processor computer, a second authorization response message comprising the payment account number from the issuer computer; and

sending, by the payment processor computer, a payment authorization message to the merchant.

13. The method of claim 1 wherein before the merchant-configured token format is received, a user affiliated with the merchant selects parameters for creating the merchant-configured token format and the graphical user interface displays a preview of an example token that has the merchant-configured token format.

14. The method of claim 1 wherein generating, by the payment processor computer, the token associated with the payment account number also comprises using a random number generator to generate a portion of the token.

15. A payment processing computer comprising:

a processor; and

a non-transitory computer readable medium storing instructions, which when executed causes the processor to perform a method comprising

receiving via a graphical user interface on a merchant computer operated by a merchant, a merchant-configured token format from the merchant, wherein the graphical user interface is configured to allow the merchant to specify a length of characters or character set in the token format, wherein the merchant-configured token format specifies at least one of the length and characters of the tokens to be generated,

after receiving the merchant-configured token format, storing the merchant-configured token format received from the merchant in a database,

after the merchant-configured token format is stored, receiving from the merchant, a payment account number from a customer during a first transaction with the merchant,

generating or receiving an authorization request message comprising the payment account number,

sending the authorization request message comprising the payment account number to an issuer computer associated with the payment account number;

receiving an authorization response message comprising the payment account number from the issuer computer,

after receiving the authorization response message from the issuer computer, retrieving the merchant-configured token format from the database,

generating a token associated with the payment account number using the retrieved merchant-configured token format, the token including a set of characters, wherein the token conforms to the merchant-configured token format, and

sending to the merchant the token associated with the payment account number, wherein the token is stored at the merchant.

16. The method of claim 14 wherein the portion of the token generated using the random number generator has no mathematical relation to the payment account number.

17. The method of claim 1 wherein the graphical user interface is configured to allow the merchant to specify the length of characters and character set used to generate tokens using the token format, wherein the merchant-configured token format specifies the length and characters of the tokens to be generated.

18. The method of claim 17 wherein the graphical user interface is further configured to allow the merchant to specify whether the tokens to be generated are generated by using only numbers, only letters, or only numbers and letters.

19. The method of claim 18 wherein the graphical user interface is further configured to allow the merchant to keep the last four digits of the payment account number in subsequently generated tokens or not keep the last four digits of the payment account number in subsequently generated tokens.

20. The payment processing computer of claim 15 wherein the graphical user interface is configured to allow the merchant to specify the length of characters and character set used to generate tokens using the token format, wherein the merchant-configured token format specifies the length and characters of the tokens to be generated.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2012
From: ANDERSON, LISA; CUSHLEY, SEAMUS; DOWNEY, FERGAL
To: VISA U.S.A. INC.
Reel/Frame 028651/0014 →
Continuity (1)
Related Publication 20140032419A1 · Jan 30, 2014