Configurable payment tokens
Abstract
Methods and systems are disclosed for the generation and use of merchant-customizable token formats that define tokens that represent credit card and other payment numbers in online transactions. The tokens, which are used instead of the card numbers themselves for security, can be specified by the token format to have a certain number of characters, have certain fields reserved for major card identifiers, use encryption and/or randomization, be alphanumeric, and have other formatting. The customized tokens can be used with legacy equipment that uses longer or shorter card numbers than the standard sixteen-digit payment card number format and can be less likely to be recognized as related to card numbers by identify thieves.
Claims
exact text as granted — not AI-modified1 .- 20 . (canceled)
21 . A method comprising:
providing, by a user computer, via a graphical user interface operated by a user, a user-configured token format to a payment processor computer; providing, by a merchant computer, an authorization request message comprising a payment account number to the payment processor computer, which forwards the authorization request message to an issuer computer, which returns an authorization response message with an authorization to the payment processor computer, the payment processor computer determining that the authorization response message contains the authorization and generating a token associated with the payment account number, wherein the token conforms to the user-configured token format; receiving, by the merchant computer, the authorization response message comprising the authorization from the payment processor computer, the authorization response message comprising the token associated with the payment account number; and storing, by the merchant computer, the token.
22 . The method of claim 21 further comprising:
transmitting, by the merchant computer, the token to the payment processor computer in a second authorization request message, wherein the payment processor computer determines the payment account number associated with the token, forwards the second authorization request message to the issuer computer with the payment account number and without the token, and receives an authorization response message with the payment account number and without the token, and forwards an authorization response message with the token and without the payment account number to the merchant computer; and
receiving, by the merchant computer, the second authorization response message comprising the token.
23 . The method of claim 22 wherein the specified total number of characters for the token is different than a number of total characters of the payment account number.
24 . The method of claim 21 wherein the generating the token includes:
encrypting a portion of the payment account number; and
building the token using the encrypted portion of the payment account number.
25 . The method of claim 21 wherein the user-configured token format specifies one or more characters indicating a particular payment network.
26 . The method of claim 21 wherein the user-configured token format specifies that only letters are in the tokens to be generated.
27 . The method of claim 21 wherein the user-configured token format specifies that only numbers are in the tokens to be generated.
28 . The method of claim 21 wherein the payment account number identifies an account associated with a card selected from the group consisting of a credit card, debit card, and prepaid card.
29 . The method of claim 21 wherein the generated token is not mod 10 compliant.
30 . The method of claim 21 wherein the user-configured token format further specifies a position where a portion of the token is generated using a random number generator.
31 . A computer system comprising:
a processor; and a computer readable medium comprising code, executable by the processor, to implement a method comprising providing via a graphical user interface operated by a user, a user-configured token format to a payment processor computer; providing an authorization request message comprising a payment account number to the payment processor computer, which forwards the authorization request message to an issuer computer, which returns an authorization response message with an authorization to the payment processor computer, the payment processor computer determining that the authorization response message contains the authorization and generating a token associated with the payment account number, wherein the token conforms to the user-configured token format; receiving the authorization response message comprising the authorization from the payment processor computer, the authorization response message comprising the token associated with the payment account number; and storing the token.
32 . The computer system of claim 31 , wherein the method further comprises:
transmitting the token to the payment processor computer in a second authorization request message, wherein the payment processor computer determines the payment account number associated with the token, forwards the second authorization request message to the issuer computer with the payment account number and without the token, and receives an authorization response message with the payment account number and without the token, and forwards an authorization response message with the token and without the payment account number to the merchant computer; and receiving the second authorization response message comprising the token.
33 . The computer system of claim 32 wherein the specified total number of characters for the token is different than a number of total characters of the payment account number.
34 . The computer system of claim 31 wherein the generating the token includes:
encrypting a portion of the payment account number; and
building the token using the encrypted portion of the payment account number.
35 . The computer system of claim 31 wherein the user-configured token format specifies one or more characters indicating a particular payment network.
36 . The computer system of claim 31 wherein the user-configured token format specifies that only letters are in the tokens to be generated.
37 . The computer system of claim 31 wherein the user-configured token format specifies that only numbers are in the tokens to be generated.
38 . The computer system of claim 31 wherein the payment account number identifies an account associated with a card selected from the group consisting of a credit card, debit card, and prepaid card.
39 . The computer system of claim 31 wherein the generated token is not mod 10 compliant.
40 . The computer system of claim 31 wherein the user-configured token format further specifies a position where a portion of the token is generated using a random number generator.Join the waitlist — get patent alerts
Track US2017228724A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.