Open, on-device cardholder verification method for mobile devices

US2016162893A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016162893-A1
Application numberUS-201414561575-A
CountryUS
Kind codeA1
Filing dateDec 5, 2014
Priority dateDec 5, 2014
Publication dateJun 9, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

An open, on-device Cardholder Verification Method (“CVM”) controller may receive CVM policies from issuers and store the policies in a database. The open, on-device CVM controller may then receive a request from a remote mobile device, and automatically determine at least one issuer associated with the request. Appropriate CVM policies may be retrieved and transmitted to the remote mobile device. An open, on-device CVM application executing on the mobile device may then receive a CVM authentication request, associated with a payment token, from a payment application. Responsive to the authentication request, a CVM policy may be accessed based on the payment token. It may then be arranged for an authenticator of the mobile device to authenticate a user in accordance with the CVM policy. When the user is authenticated, an authentication success indication may be sent from the open, on-device CVM application to the payment application.

First claim

Opening claim text (preview).

What is claimed is: 1 . A computer-implemented method, comprising: receiving, at an open, on-device Cardholder Verification Method (“CVM”) controller, CVM policies from issuer platforms; storing the CVM policies in a CVM policy database at the open, on-device CVM controller; receiving, at the open, on-device CVM controller, a request from a remote mobile device; automatically determining, by a processor of the open, on-device CVM controller, at least one issuer associated with the request; retrieving at least one CVM policy from the CVM policy database based on the determined at least one issuer; and transmitting the retrieved CVM policy to the remote mobile device. 2 . The method of claim 1 , wherein the request comprises a registration request associated with a payment token for a payment application. 3 . The method of claim 2 , wherein the payment token is associated with at least one of: (i) a credit card, (ii) a debit card, or (iii) a pre-paid stored value card. 4 . The method of claim 1 , wherein at least one CVM policy is associated with at least one of: (i) a mobile device type, (ii) a mobile device authenticator type, (iii) a personal identification number, and (iv) a transaction amount. 5 . The method of claim 1 , further comprising: transmitting a CVM policy update to the remote mobile device. 6 . An open, on-device Cardholder Verification Method (“CVM”) controller, comprising: a first communication port to receive CVM policies from issuer platforms; a CVM policy database storing the CVM policies; a second communication port to receive a request from a remote mobile device; and a controller engine to: (i) determine at least one issuer associated with the request, (ii) retrieve at least one CVM policy from the CVM policy database based on the determined at least one issuer, and (iii) transmit the retrieved CVM policy to the remote mobile device. 7 . The system of claim 6 , wherein the request comprises a registration request associated with a payment token for a payment application, and the payment token is associated with at least one of: (i) a credit card, (ii) a debit card, or (iii) a pre-paid stored value card. 8 . The system of claim 6 , wherein at least one CVM policy is associated with at least one of: (i) a mobile device type, (ii) a mobile device authenticator type, (iii) a personal identification number, and (iv) a transaction amount. 9 . A computer-implemented method, comprising: receiving, at an open, on-device Cardholder Verification Method (“CVM”) application executing in a secure execution environment of a mobile device, a CVM authentication request from a payment application executing in an application execution environment of the mobile device, the CVM authentication request being associated with a payment token; responsive to the authentication request, accessing a CVM policy based on the payment token; arranging for an authenticator of the mobile device to authenticate a user of the mobile device in accordance with the CVM policy; and when the user is authenticated, sending an authentication success indication from the open, on-device CVM application to the payment application. 10 . The method of claim 9 , wherein the mobile device comprises at least one of: (i) a smartphone, (ii) a tablet computer, (iii) a watch, (iv) an automobile, (v) a laptop computer, (vi) a pair of eyeglasses, and (vii) any other mobile device. 11 . The method of claim 9 , wherein the payment token is associated with at least one of: (i) a credit card, (ii) a debit card, or (iii) a pre-paid stored value card. 12 . The method of claim 9 , wherein at least one CVM policy is associated with at least one of: (i) a mobile device type, (ii) a mobile device authenticator type, (iii) a personal identification number, and (iv) a transaction amount. 13 . The method of claim 9 , further comprising: determining, by the payment application, that a new payment token is to be added; and sending a registration request from the payment application to the open, on-device CVM application. 14 . The method of claim 9 , further comprising: receiving the CVM policy from a remote open, on-device CVM controller via a communication network, wherein the CVM policy is associated with a plurality of potential authenticators. 15 . The method of claim 9 , wherein the open, on-device CVM application includes: (i) client application programming interfaces, (ii) business logic, (iii) a policy rules processing and storage component, and (iv) on-device authenticator application programming interfaces. 16 . A mobile device, comprising: an application execution environment executing a payment application that generates a Cardholder Verification Method (“CVM”) authentication request associated with a payment token; a plurality of authenticators; and a secure execution environment executing a CVM application to: (i) receive the authentication request, (ii) access a CVM policy based on the payment token, (iii) arranging for at least one of authenticators to authenticate a user of the mobile device in accordance with the CVM policy, and (iv) when the user is authenticate, send an authentication success indication from the open, on-device CVM application to the payment application. 17 . The mobile device of claim 16 , wherein the mobile device comprises at least one of: (i) a smartphone, (ii) a tablet computer, (iii) a watch, (iv) an automobile, (v) a laptop computer, (vi) a pair of eyeglasses, and (vii) any other mobile device. 18 . The mobile device of claim 16 , wherein the payment token is associated with at least one of: (i) a credit card, (ii) a debit card, or (iii) a pre-paid stored value card. 19 . The mobile device of claim 16 , wherein at least one CVM policy is associated with at least one of: (i) a mobile device type, (ii) a mobile device authenticator type, (iii) a personal identification number, and (iv) a transaction amount. 20 . The mobile device of claim 16 , further comprising: determining, by the payment application, that a new payment token is to be added; and sending a registration request from the payment application to the open, on-device CVM application. 21 . The mobile device of claim 16 , further comprising: receiving the CVM policy from a remote open, on-device CVM controller via a communication network, wherein the CVM policy is associated with a plurality of potential authenticators. 22 . The mobile device of claim 16 , wherein the open, on-device CVM application includes: (i) client application programming interfaces, (ii) business logic, (iii) a policy rules processing and storage component, and (iv) on-device authenticator application programming interfaces.

Assignees

Inventors

Classifications

  • Use of secure elements separate from M-devices · CPC title

  • using cards, e.g. integrated circuit [IC] cards or magnetic cards · CPC title

  • G06Q20/405Primary

    Establishing or using transaction specific rules · CPC title

  • Payment applications installed on the mobile devices · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016162893A1 cover?
An open, on-device Cardholder Verification Method (“CVM”) controller may receive CVM policies from issuers and store the policies in a database. The open, on-device CVM controller may then receive a request from a remote mobile device, and automatically determine at least one issuer associated with the request. Appropriate CVM policies may be retrieved and transmitted to the remote mobile devic…
Who is the assignee on this patent?
Mastercard International Inc
What technology area does this patent fall under?
Primary CPC classification G06Q20/405. Mapped technology areas include Physics.
When was this patent published?
Publication date Thu Jun 09 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).