Tokenization capable authentication framework

US10552834B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10552834-B2
Application numberUS-201514701437-A
CountryUS
Kind codeB2
Filing dateApr 30, 2015
Priority dateApr 30, 2015
Publication dateFeb 4, 2020
Grant dateFeb 4, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Embodiments are directed to systems and methods for performing consumer authentication in a tokenized transaction. The token in the authentication request may be resolved to corresponding credentials before the consumer authentication process is initiated. As part of an authentication system, the merchant computer may include a merchant plug-in module as a proxy between the merchant computer and an issuer access control server. The merchant plug-in module may communicate with the issuer access control server by sending verification and authentication messages to the issuer access control server via a directory server. The token may be resolved to corresponding credentials before the authentication request reaches the issuer access computer for authentication. The merchant plug-in module, the directory server or a token router coupled to the issuer access control server may each be in communication with one or more token service providers to de-tokenize the token provided by the consumer's user device.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: receiving, by a first server computer, transaction data associated with a tokenized transaction initiated by a user; determining, by the first server computer, that the transaction data includes a token, wherein the token comprises tokenized credentials; initiating, by the first server computer, a user authentication process in connection with the tokenized transaction prior to a transaction authorization process in connection with the tokenized transaction, wherein the user authentication process includes: identifying, by the first server computer, a token service provider among a plurality of token service providers; sending, by the first server computer, the token to the token service provider to detokenize the token comprising the tokenized credentials to form detokenized credentials; receiving, by the first server computer, from the token service provider, the detokenized credentials; forwarding, by the first server computer, the detokenized credentials to a second server computer for authentication; and receiving, by the first server computer, the detokenized credentials and an authentication value from the second server computer upon the second server computer authenticating the detokenized credentials before the transaction authorization process starts, wherein the authentication value and the token are incorporated into a transaction authorization request message after the transaction authorization process in connection with the tokenized transaction starts, and wherein the transaction authorization request message associated with the tokenized transaction includes at least the token and the authentication value. 2. The method of claim 1 , further comprising: sending, by the first server computer, the detokenized credentials to the token service provider after receiving the detokenized credentials and the authentication value to re-tokenize the detokenized credentials; and receiving, by the first server computer, the token associated with re-tokenized credentials from the token service provider. 3. The method of claim 2 , the method further comprising: sending, by the first server computer, the token and the authentication value to a third server computer for initiating the transaction authorization process using the token and the authentication value, wherein the first server computer is a directory server computer or a token router computer, wherein the third server computer is a merchant computer, and wherein the tokenized transaction is between the user and a merchant associated with the merchant computer. 4. The method of claim 1 , wherein the token in the transaction authorization request message is de-tokenized using the token service provider and sent to an authorization computer as part of the transaction authorization process. 5. The method of claim 1 , wherein the detokenized credentials include a unique primary account number. 6. The method of claim 1 , wherein the token service provider is identified among the plurality of token service providers based on a format of the token or based on one or more predetermined rules. 7. A server computer comprising: a processor and a computer readable medium coupled to the processor, the computer readable medium comprising instructions that, when executed by the processor, cause the processor to: receive transaction data associated with a tokenized transaction initiated by a user; determine that the transaction data includes a token, wherein the token comprises tokenized credentials; initiate a user authentication process in connection with the tokenized transaction prior to a transaction authorization process in connection with the tokenized transaction, wherein the user authentication process includes: identifying a token service provider among a plurality of token service providers; sending the token to the token service provider to detokenize the token comprising the tokenized credentials to form detokenized credentials; receiving from the token service provider the detokenized credentials; forwarding the detokenized credentials to a second server computer for authentication; and receiving the detokenized credentials and an authentication value from the second server computer upon the second server computer authenticating the detokenized credentials before the transaction authorization process starts, wherein the authentication value and the token are incorporated into a transaction authorization request message after the transaction authorization process in connection with the tokenized transaction starts, and wherein the transaction authorization request message associated with the tokenized transaction includes at least the token and the authentication value. 8. The server computer of claim 7 , wherein the computer readable medium further comprises instructions that, when executed by the processor, cause the processor to: send the detokenized credentials to the token service provider after receiving the detokenized credentials and the authentication value to re-tokenize the detokenized credentials; and receive the token associated with re-tokenized credentials from the token service provider. 9. The server computer of claim 8 , wherein the computer readable medium further comprises instructions that, when executed by the processor, cause the processor to: send the token and the authentication value to a third server computer for initiating the transaction authorization process using the token and the authentication value, wherein the server computer is a directory server computer or a token router computer, wherein the third server computer is a merchant computer, wherein the tokenized transaction is between the user and a merchant associated with the merchant computer. 10. The server computer of claim 7 , wherein the detokenized credentials include a unique primary account number. 11. The server computer of claim 7 , wherein the token service provider is identified among the plurality of token service providers based on a format of the token or based on one or more predetermined rules. 12. A system comprising: a first server computer including a first processor and a first computer readable medium coupled to the first processor, the first computer readable medium comprising instructions that, when executed by the first processor, cause the first processor to: receive transaction data associated with a tokenized transaction initiated by a user; determine that the transaction data includes a token, wherein the token comprises tokenized credentials; initiate a user authentication process in connection with the tokenized transaction prior to a transaction authorization process in connection with the tokenized transaction, wherein the user authentication process includes: identifying a token service provider among a plurality of token service providers; sending the token to the token service provider to detokenize the token comprising the tokenized credentials to form detokenized credentials; and receiving from the token service provider the detokenized credentials; and a second server computer including a second processor and a second computer readable medium coupled to the second processor, the second computer readable medium comprising instructions that, when executed by the second processor, cause the second processor to: receive the detokenized credentials directly or indirectly from the first server computer for authentication; authenticate the detokenized credentials; generate an authentication value upon authenticating the detokenized credentials; and send the detokenized credentials and the authentication value

Assignees

Inventors

Classifications

  • Use of certificates or encrypted proofs of transaction rights · CPC title

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

  • Business processing using cryptography · CPC title

  • applying security measure for e-commerce · CPC title

  • G06Q20/401Primary

    Transaction verification · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10552834B2 cover?
Embodiments are directed to systems and methods for performing consumer authentication in a tokenized transaction. The token in the authentication request may be resolved to corresponding credentials before the consumer authentication process is initiated. As part of an authentication system, the merchant computer may include a merchant plug-in module as a proxy between the merchant computer an…
Who is the assignee on this patent?
Visa Int Service Ass
What technology area does this patent fall under?
Primary CPC classification G06Q20/401. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Feb 04 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 11 related publications on this page (citations in our corpus or others sharing the same primary CPC).