Apparatus and method for a payment processing system for securing bankcard data
US-2016232520-A9 · Aug 11, 2016 · US
US11847645B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11847645-B2 |
| Application number | US-202016905815-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jun 18, 2020 |
| Priority date | Aug 12, 2010 |
| Publication date | Dec 19, 2023 |
| Grant date | Dec 19, 2023 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Systems, apparatuses, and methods for providing an account token to an external entity during the lifecycle of a payment transaction. In some embodiments, an external entity may be a merchant computer requesting authorization of a payment message. In other embodiments, the external entity may be a support computer providing a payment processing network or a merchant support functions.
Opening claim text (preview).
What is claimed is: 1. A method comprising: in connection with a first transaction: receiving, by a merchant computer from a user device, an account identifier; transmitting, by the merchant computer to a server computer, an authorization request message, the authorization request message including the account identifier and a merchant verification value associated with the merchant computer; receiving, by the merchant computer from the server computer, an authorization response message in response to the authorization request message, the authorization response message including a first account token representing the account identifier, a token derivation key index identifying a token derivation key associated with the merchant verification value, and an indicator indicating whether the first transaction is authorized or denied, wherein the first account token is obtained using the merchant verification value and the account identifier such that the first account token is different from a second account token associated with the account identifier generated for a different merchant computer; storing, by the merchant computer, the first account token without storing the account identifier; performing, by the merchant computer, customer analytics using the first account token in lieu of the account identifier; in connection with a second transaction: transmitting, by the merchant computer, a first message including the first account token, the merchant verification value and the token derivation key index to the server computer; receiving, by the merchant computer from the server computer in response to the first message, the account identifier associated with the first account token; transmitting, by the merchant computer, a second message including the account identifier and the merchant verification value to the server computer; and receiving, by the merchant computer from the server computer in response to the second message, a second account token having a same value as the first account token. 2. The method of claim 1 , further comprising: transmitting a registration request message to the server computer, the registration request message including one or more of a merchant name, a merchant category type, a merchant location, a contact information, and an account information; and responsive to transmitting the registration request message, receiving the merchant verification value. 3. The method of claim 1 , wherein the token derivation key index is a hidden index. 4. The method of claim 1 , wherein the account identifier is identified by the server computer using the first account token and a reverse tokenization key assigned to a merchant associated with the merchant computer, wherein the reverse tokenization key is retrieved by the server computer using the merchant verification value. 5. The method of claim 1 , further comprising: storing, by the merchant computer, the second account token without storing the account identifier. 6. The method of claim 1 , further comprising: transmitting, by the merchant computer, the first account token and the merchant verification value to a support server; and receiving, by the merchant computer from the support server, a risk score associated with the first account token. 7. A merchant computer comprising: a processor and a non-transitory computer-readable storage medium coupled to the processor, the non-transitory computer-readable storage medium comprising code that, when executed by the processor, causes the processor to perform a method comprising: in connection with a first transaction: receiving, from a user device, an account identifier; generating an authorization request message in connection with a first transaction; incorporating the account identifier and a merchant verification value associated with the merchant computer in the authorization request message; transmitting, to a server computer, the authorization request message including the account identifier and the merchant verification value associated with the merchant computer; receiving, from the server computer, an authorization response message in response to the authorization request message; determining that the authorization response message includes a first account token representing the account identifier, a token derivation key index identifying a token derivation key associated with the merchant verification value, and an indicator indicating whether the first transaction is authorized or denied, wherein the first account token is obtained based on the merchant verification value and the account identifier previously transmitted by the merchant computer; storing the first account token without storing the account identifier based on the determining; performing customer analytics using the first account token in lieu of the account identifier; in connection with a second transaction: transmitting a first message including the first account token, the merchant verification value and the token derivation key index to the server computer; receiving, from the server computer in response to the first message, the account identifier associated with the first account token; transmitting a second message including the account identifier and the merchant verification value to the server computer; and receiving, from the server computer in response to the second message, a second account token having a same value as the first account token. 8. The merchant computer of claim 7 , wherein the first account token is generated using the merchant verification value and the account identifier, and wherein the first account token is generated by applying the account identifier to an encryption or hash function using a token derivation key unique for a merchant associated with the merchant computer as a parameter. 9. The merchant computer of claim 7 , wherein the method further comprises: transmitting one or more of a merchant name, a merchant category type, a merchant location, a contact information, and an account information to the server computer. 10. The merchant computer of claim 7 , wherein the method further comprises: storing the second account token without storing the account identifier. 11. The merchant computer of claim 7 , wherein the authorization response message includes a bitmap field, and wherein a bit in the bitmap field is set by the server computer upon incorporating the first account token in the authorization response message. 12. The merchant computer of claim 7 , wherein the authorization response message includes a field tag that identifies a field in the authorization response message containing the first account token. 13. The merchant computer of claim 7 , wherein the method further comprises: transmitting, the first account token and the merchant verification value to a support server associated with a fraud scoring service that provides a fraud score for the first transaction; and receiving, from the support server, a fraud score associated with the first transaction. 14. The merchant computer of claim 13 , wherein the method further comprises: receiving, from the server computer, the merchant verification value assigned to the merchant computer prior to transmitting the account identifier and the merchant verification value to the server computer. 15. A non-transitory computer-readable medium storing instructions, that when executed by a merchant computer, cause the merchant computer to: in connection with a first transaction: receive, from a user device, an account identifier; generate an authorization request message
using an alias or single-use codes · CPC title
involving a neutral party, e.g. certification authority, notary or trusted third party [TTP] · CPC title
specially adapted for electronic shopping systems · CPC title
Aspects of commerce using mobile devices [M-devices] · CPC title
initialising or reloading thereof · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.