Securing sensitive user data associated with electronic transactions
Abstract
A payment processor for providing a payment service includes a transaction processor to process a transaction request. An application programming interface links a merchant to the transaction processor based on an identifier. A merchant center, located between a gateway and a point of sale device of the merchant, queries a database for information associated with a buyer and the merchant based on information received from the point of sale device, to generate the transaction request based from merchant transaction data received from the point of sale device and the information associated with the buyer and the merchant received from the database, and to communicate the transaction request to the transaction processor. The transaction processor also communicates information associated with the transaction request with the merchant based on the identifier.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A computing system, comprising:
communication circuitry; and one or more processing elements configured to:
receive, from a first entity via the communication circuitry, a transaction request that includes first information identifying a user, wherein the first information is entered via a virtual point-of-sale device that is integrated into a website of the first entity;
retrieve, from an electronic database, second information that identifies an account of the user that is to be used for the transaction, wherein the transaction request does not include the second information and wherein the electronic database is not accessible to the first entity;
transmit a request, via a gateway component, wherein the request includes both the first and second information, wherein the gateway component is configured to route transactions to a processor network based on the second information;
receive an authorization response via the gateway component; and
transmit the authorization response to the first entity.
22 . The computing system of claim 21 , wherein the one or more processing elements are further configured to register the user and store the second information in the electronic database prior to receiving the transaction request.
23 . The computing system of claim 21 , wherein the one or more processing elements are further configured to retrieve third information for the first entity from the electronic database and include the third information in the request.
24 . The computing system of claim 23 , wherein the third information is not accessible to the user.
25 . The computing system of claim 21 , wherein the one or more processing elements execute instructions of an application programming interface (API) to include the second information in the request.
26 . The computing system of claim 21 , wherein the one or more processing elements are further configured to transmit, to the first entity, digital information that encodes the virtual point-of-sale device.
27 . The computing system of claim 21 , wherein the one or more processing elements are configured to transmit an identifier for the request to both the first entity and the processor network.
28 . A method, comprising:
receiving, by a merchant center system from a first entity, a transaction request that includes first information identifying a user, wherein the first information is entered via a virtual point-of-sale device that is integrated into a website of the first entity; retrieving, by the merchant center system from an electronic database, second information that identifies an account of the user that is to be used for the transaction, wherein the transaction request does not include the second information and wherein the electronic database is not accessible to the first entity; transmitting a request from the merchant center system via a gateway component, wherein the request includes both the first and second information, wherein the gateway component is configured to route transactions to an processor network based on the second information; receiving, by the merchant center system, an authorization response via the gateway component; and transmitting, by the merchant center system, the authorization response to the first entity.
29 . The method of claim 28 , wherein the transaction request is routed to the merchant center system based on registration of the first entity with the merchant center system.
30 . The method of claim 28 , further comprising:
prior to receiving the transaction request:
registering the user;
receiving the second information from the user; and
storing the second information in the electronic database.
31 . The method of claim 28 , further comprising:
retrieving third information for the first entity from the electronic database and including the third information in the request.
32 . The method of claim 31 , wherein the third information is not accessible to the user.
33 . The method of claim 28 , wherein the second information is included in the request according to an application programming interface (API).
34 . The method of claim 28 , further comprising:
transmitting digital information that encodes the virtual point-of-sale device to the first entity for integration with the website of the first entity.
35 . The method of claim 28 , further comprising:
including an identifier in the request and transmitting the identifier to the first entity.
36 . A non-transitory computer-readable medium having instructions stored thereon that are executable by a computing device to perform operations comprising:
receiving, from a first entity, a transaction request that includes first information identifying a user, wherein the first information is entered via a virtual point-of-sale device that is integrated into a website of the first entity; retrieving, from a database, second information that identifies an account of the user that is to be used for the transaction, wherein the transaction request does not include the second information and wherein the database is not accessible to the first entity; transmitting a request via a gateway component, wherein the request includes both the first and second information, wherein the gateway component is configured to route transactions to an processor network based on the second information; receiving an authorization response via the gateway component; and transmitting the authorization response to the first entity.
37 . The non-transitory computer-readable medium of claim 36 , wherein the operations further comprise registering the user and storing the second information in the database.
38 . The non-transitory computer-readable medium of claim 36 , wherein the operations further comprise retrieving third information for the first entity from the database and including the third information in the request.
39 . The non-transitory computer-readable medium of claim 36 , wherein the operations further comprise transmitting digital information that encodes the virtual point-of-sale device to the first entity for integration with the website of the first entity.
40 . The non-transitory computer-readable medium of claim 36 , wherein the operations further comprise including an identifier in the request and transmitting the identifier to the first entity.Join the waitlist — get patent alerts
Track US2016379191A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.