US2014279556A1PendingUtilityA1
Distributed authenticity verification for consumer payment transactions
Est. expiryMar 12, 2033(~6.6 yrs left)· nominal 20-yr term from priority
G06Q 20/38215G06Q 20/40G06Q 20/385G06Q 20/322G06Q 20/3829
64
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Payment tokens designed for display on a consumer's mobile device include dynamic trust data (e.g., transaction history and/or token generation date) along with financial account information, enabling merchants to make an informed decision about whether to accept payment without communication with the central processing system, and also protecting the consumer's account information from theft.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of processing a transaction among a consumer, a merchant point-of-sale system and a transaction-processing entity, the method comprising:
generating a token encrypted with data identifying a financial account of the consumer and trust data for the consumer; receiving and storing the token by a device of the consumer; reading and decrypting, by the merchant system, the token upon presentation thereof by the consumer's device in connection with the transaction; authorizing, by the merchant system, the transaction based on (i) successful decryption of the token and (ii) the trust level without communication with the transaction-processing entity; subsequent to authorization of the transaction by the merchant system, communicating, by the merchant to the transaction-processing entity, a record of the transaction and authorization thereof; and following the communication from the merchant system to the transaction-processing entity, completing the authorized transaction by causing funds to be transferred from the consumer's financial account to the merchant.
2 . The method of claim 1 , wherein the authorized transaction is completed upon approval by the transaction-processing entity of a basis for the authorization by the merchant system.
3 . The method of claim 1 , wherein approval by the merchant system is also based on a time of generation of the token and a time of the reading.
4 . The method of claim 1 , wherein the trust data contains at least one of (i) a token generation time, (ii) a transaction history of the consumer, (iii) a spending limit of the consumer or (iv) a home region of the consumer.
5 . The method of claim 1 , wherein the trust data is a single trust-factor value.
6 . The method of claim 1 , wherein the token is encrypted using public key cryptography.
7 . The method of claim 1 , wherein the token is displayed as a QR code on the consumer device.
8 . The method of claim 1 , wherein the token is a one-time-use token.
9 . The method of claim 1 , further comprising generating and storing, on the consumer device, a plurality of tokens.
10 . The method of claim 9 , wherein following presentation of a first token, the first token is marked for deletion and a second token is marked for display on a subsequent presentation.
11 . The method of claim 10 , wherein presentation of the first token comprises receiving confirmation from the merchant system that the token was received.
12 . The method of claim 10 , wherein the token is not marked for deletion until a deletion communication is received from the transaction-processing entity.
13 . The method of claim 9 , wherein following presentation of a first token, the first token is marked for deletion and a second token is marked for display after a predetermined time period.
14 . The method of claim 1 , further comprising marking a token for deletion and generating a token to replace the token marked for deletion.
15 . The method of claim 1 , wherein the tokens are stored in a stack for sequential access on a first in, first out basis.
16 . The method of claim 1 , wherein the tokens are stored in a stack for sequential access on a first in, last out basis.
17 . The method of claim 1 , further comprising identifying the consumer prior to generating the token.
18 . A system for processing a transaction among a consumer, a merchant and a transaction-processing entity, the system comprising:
a token server for (i) generating a token encrypted with data identifying a financial account of the consumer and trust data for the consumer, and (ii) communicating the token to a device of the consumer; a point-of-sale system for reading and decrypting the token upon presentation thereof by the consumer in connection with the transaction, the point-of-sale system being configured to authorize the transaction based on (i) successful decryption of the token and (ii) the trust level without communication with the transaction-processing entity; and a transaction-processing server configured to (i) receive, from the point-of-sale system subsequent to transaction authorization, a record of the transaction and authorization thereof, and (ii) cause completion of the authorized transaction by causing funds to be transferred from the consumer's financial account to the merchant.
19 . The system of claim 18 , wherein the point-of-sale system is configured to authorize the transaction based at least in part on a time of generation of the token and a time of the reading.
20 . The system of claim 18 , wherein the token server is configured to encrypt the token using private key cryptography.
21 . The system of claim 18 , wherein the token server is configured to embed an expiration time in the generated token.
22 . The system of claim 18 , wherein the token server is configured to embed a creation time in the generated token.
23 . The system of claim 18 , wherein the token server is configured to generate and communicate a series of tokens to the device.
24 . The system of claim 18 , wherein the token server is configured to verify the consumer's identity prior to token generation.
25 . A method of processing a transaction among a consumer, a merchant point-of-sale system and a transaction-processing entity, the method comprising:
generating a token with a digital signature, encrypted using a private key, with data identifying a financial account of the consumer and trust data for the consumer; receiving and storing the token and the signature by a device of the consumer; reading the token and decrypting the signature, by the merchant system, upon presentation of the token by the consumer's device in connection with the transaction; authorizing, by the merchant system, the transaction based on (i) successful verification of the signature and (ii) the trust level without communication with the transaction-processing entity; subsequent to authorization of the transaction by the merchant system, communicating, by the merchant to the transaction-processing entity, a record of the transaction and authorization thereof; and following the communication from the merchant system to the transaction-processing entity, completing the authorized transaction by causing funds to be transferred from the consumer's financial account to the merchant.
26 . A system for processing a transaction among a consumer, a merchant and a transaction-processing entity, the system comprising:
a token server for (i) generating a token with a digital signature, encrypted using a private key, with data identifying a financial account of the consumer and trust data for the consumer, and (ii) communicating the token to a device of the consumer; a point-of-sale system for reading and decrypting the signature upon presentation of the token by the consumer in connection with the transaction, the point-of-sale system being configured to authorize the transaction based on (i) successful verification of the signature and (ii) the trust level without communication with the transaction-processing entity; and a transaction-processing server configured to (i) receive, from the point-of-sale system subsequent to transaction authorization, a record of the transaction and authorization thereof, and (ii) cause completion of the authorized transaction by causing funds to be transferred from the consumer's financial account to the merchant.Join the waitlist — get patent alerts
Track US2014279556A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.