Multiple tokenization for authentication
US-9280765-B2 · Mar 8, 2016 · US
US11470164B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11470164-B2 |
| Application number | US-201715593243-A |
| Country | US |
| Kind code | B2 |
| Filing date | May 11, 2017 |
| Priority date | May 1, 2014 |
| Publication date | Oct 11, 2022 |
| Grant date | Oct 11, 2022 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
An embodiment of the invention is directed to a method comprising receiving, at a server computer, information for a portable device that includes a mobile device identifier and storing, by the server computer, the information for the portable device that includes the mobile device identifier in a database associated with the server computer. The method further comprising receiving, by the server computer, transaction data from an access device for a transaction conducted at the access device, determining, by the server computer, from the transaction data that the transaction is associated with the portable device, determining, by the server computer, a location of the access device, determining, by the server computer, a location of a mobile device associated with the mobile device identifier, determining, by the server computer, that the location of the mobile device matches the location of the access device, and marking, by the server computer, the stored information for the portable device as authentication verified.
Opening claim text (preview).
What is claimed is: 1. A method comprising: receiving, at a server computer, information for a portable device that includes a mobile device identifier; storing, by the server computer, the information for the portable device that includes the mobile device identifier in a database associated with the server computer; receiving, by the server computer, first transaction data from an access device for a first transaction conducted at the access device; determining, by the server computer, from the first transaction data that the first transaction is associated with the portable device; determining, by the server computer, a location of the access device; determining, by the server computer, a location of a mobile device associated with the mobile device identifier; determining, by the server computer, that the location of the mobile device matches the location of the access device; marking, by the server computer, the information for the portable device as authentication verified in response to determining that the location of the mobile device matches the location of the access device, wherein the information for the portable device is provided by a user during an initial transaction before the first transaction, and wherein marking the information for the portable device as authentication verified indicates that an association between the mobile device and portable device is verified, and that the portable device is eligible for use in remote transactions without having to check or compare a physical location; receiving, at the server computer, second transaction data for a second transaction conducted via a transactor server computer using the portable device; determining, by the server computer, from the second transaction data that the second transaction is associated with the portable device; determining, by the server computer, that information for the portable device is marked as authentication verified; and sending, by the server computer, a message to the transactor server computer or to an issuer computer indicating a status of the portable device as authentication verified. 2. The method of claim 1 further comprising: generating, by the server computer, a digital certificate indicating that a status of the portable device is authentication verified; and storing, by the server computer, the digital certificate in the database associated with the server computer. 3. The method of claim 1 wherein determining the location of the access device includes determining the location of the access device from location information included in the first transaction data. 4. The method of claim 1 wherein determining the location of the mobile device includes sending a message to the mobile device requesting information to confirm the location of the mobile device. 5. The method of claim 4 wherein requesting information includes a request for confirmation for a recent transaction or a challenge question. 6. The method of claim 1 wherein determining the location of the mobile device includes utilizing location technology to determine the location of the mobile device. 7. The method of claim 1 wherein storing the information for the portable device that includes the mobile device identifier further comprises indicating that the stored information for the portable device is not yet authentication verified. 8. The method of claim 1 , wherein the second transaction is a remote transaction, and the transactor server computer is a merchant computer. 9. The method of claim 1 , wherein sending the message to the transactor server computer or the issuer computer indicating the status of the portable device as authentication verified includes sending a digital certificate to the transactor server computer or the issuer computer. 10. A server computer comprising: a processor, and a non-transitory computer readable medium coupled with the processor, the non-transitory computer readable medium comprising instructions executable by the processor, to implement a method comprising: receiving information for a portable device that includes a mobile device identifier; storing the information for the portable device that includes the mobile device identifier in a database associated with the server computer; receiving first transaction data from an access device for a first transaction conducted at the access device; determining from the first transaction data that the first transaction is associated with the portable device; determining a location of the access device; determining a location of a mobile device associated with the mobile device identifier; determining that the location of the mobile device matches the location of the access device; and marking the information for the portable device as authentication verified in response to determining that the location of the mobile device matches the location of the access device, wherein the information for the portable device is provided by a user during an initial transaction before the first transaction, and wherein marking the information for the portable device as authentication verified indicates that an association between the mobile device and portable device is verified, and that the portable device is eligible for use in remote transactions without having to check or compare a physical location; receiving second transaction data for a second transaction conducted via a transactor server computer using the portable device; determining from the second transaction data that the second transaction is associated with the portable device; determining that information for the portable device is marked as authentication verified; and sending a message to the transactor server computer or to an issuer computer indicating a status of the portable device as authentication verified. 11. The server computer of claim 10 , the method further comprising: generating a digital certificate indicating that a status of the portable device is authentication verified; and storing the digital certificate in the database associated with the server computer. 12. The server computer of claim 10 wherein determining the location of the access device includes determining the location of the access device from location information included in the first transaction data. 13. The server computer of claim 10 wherein determining the location of the mobile device includes sending a message to the mobile device requesting information to confirm the location of the mobile device. 14. The server computer of claim 10 wherein requesting information includes a request for confirmation for a recent transaction or a challenge question. 15. The server computer of claim 10 wherein determining the location of the mobile device includes utilizing location technology to determine the location of the mobile device. 16. The server computer of claim 10 wherein storing the information for the portable device that includes the mobile device identifier further comprises indicating that the stored information for the portable device is not yet authentication verified. 17. The server computer of claim 10 wherein the access device is an electronic cash register. 18. The server computer of claim 10 , wherein the second transaction is a remote transaction, and the transactor server computer is a merchant computer. 19. The server computer of claim 10 , wherein sending the message to the transactor server computer or the issuer computer indicating the status of the portable device as authentication verified inclu
Multiple levels of security · CPC title
using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title
Transactions dependent on location of M-devices · CPC title
Integrity · CPC title
specially adapted for the location of the user terminal · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.