US2022122061A1PendingUtilityA1

Systems and methods for use in facilitating network transactions

Assignee: MASTERCARD INTERNATIONAL INCPriority: Jun 1, 2016Filed: Dec 28, 2021Published: Apr 21, 2022
Est. expiryJun 1, 2036(~9.8 yrs left)· nominal 20-yr term from priority
G06Q 20/401G06Q 20/12G06Q 20/40G06Q 20/382G06Q 20/367G06Q 20/4016
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are provided for managing tokens from token providers and facilitating network transactions involving the tokens. One example computer-implemented method includes receiving, by a payment network, an external token for a payment account from an external token provider and storing the external token in a vault data structure. The external token provider is separate from the payment network. The method then includes intercepting, by the payment network, an authorization request message for a transaction involving the payment account. And, when the authorization request message includes the external token, the method includes identifying a primary account number (PAN) for the payment account based on a mapping of the external token with the PAN in the vault data structure and initiating at least one PAN-dependent service associated with the payment account, despite the external token being generated by the token provider that is separate from the payment network.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system for processing transactions to payment accounts based on use of tokens in the transactions, the system comprising:
 a payment network including at least one computing device, the at least one computing device comprising:
 a memory including a vault data structure; and 
 at least one processor coupled to the memory and configured to:
 in response to a request to provision a token for a first payment account:
 generate an internal token specific to the first payment account, the first payment account associated with a first primary account number (PAN); and 
 store the internal token linked to the first PAN in the vault data structure; 
 
 receive a file from an external token provider, the file including an external token and a second PAN, each of the external token and the second PAN being specific to a second payment account, the external token generated by the external token provider, the external token provider being external to and separate from the payment network; 
 store the external token linked to the second PAN in the vault data structure; 
 intercept an authorization request message for a transaction; and 
 in response to the authorization request message including a request token:
 identify the first PAN associated with the internal token, from the vault data structure, when the request token is the internal token; 
 identify the second PAN associated with the external token, from the vault data structure, when the request token is the external token; and 
 when one of the first PAN and the second PAN is identified, initiate at least one PAN-dependent service, based on the identified one of the first PAN and the second PAN, such that the at least one PAN-dependent service is imposed on the transaction. 
 
 
   
     
     
         2 . The system of  claim 1 , wherein the at least one PAN-dependent service includes a value-added service, the value added service including one or more of: a risk monitoring service, a fraud service, validation of an incoming cryptogram, and/or an authentication service. 
     
     
         3 . The system of  claim 1 , wherein the payment network includes an internal token provider; and
 wherein the at least one processor is configured, in connection with generating the internal token, to generate the token via the internal token provider.   
     
     
         4 . The system of  claim 1 , wherein the request to provision the token includes a request to provision the token to a smartphone associated with a user, and wherein the first payment account is specific to the user. 
     
     
         5 . The system of  claim 1 , wherein the at least one processor is configured, in response to the authorization request message including the external token, to transmit the authorization request message to an issuer of the second payment account without appending the second PAN to the authorization request message. 
     
     
         6 . The system of  claim 5 , wherein, when the second PAN is included in an authorization response message from the issuer of the second payment account, in response to the authorization request message, the at least one processor is configured to:
 append the external token to the authorization response message from the issuer;   remove at least part of the second PAN from the authorization response message; and then   transmit the authorization response message to an acquirer associated with the transaction.   
     
     
         7 . The system of  claim 5 , wherein the external token provider is configured to generate the external token specific to the second payment account and to transmit the file, including the external token, to the payment network. 
     
     
         8 . The system of  claim 7 , wherein the external token provider is further configured to transmit at least one cryptographic key to the payment network; and
 wherein the payment network is configured to validate a cryptogram included in the authorization request message based on the at least one cryptographic key, prior to transmitting the authentication request message to the issuer of the second payment account.   
     
     
         9 . The system of  claim 1 , wherein the at least one processor is further configured, in response to the authorization request message including the request token and when the request token is the internal token, to:
 append the identified first PAN to the authorization request message; and   transmit the authorization request message, with the first PAN, to an issuer of the first payment account.   
     
     
         10 . The system of  claim 1 , wherein the at least one processor is further configured to:
 receive a request to delete the external token;   retain the external token for a period of time; and   delete the external token after the period of time.   
     
     
         11 . A computer-implemented method for processing transactions to payment accounts based on use of tokens in the transactions, the method comprising:
 receiving, by a payment network, an external token from an external token provider, the external token associated with a payment account, and the external token provider being separate and apart from the payment network;   storing, by the payment network, the external token in a vault data structure of the payment network, along with a primary account number (PAN) and a mapping between the external token and the PAN, each of the external token and the PAN specific to a same payment account; and then   intercepting, by the payment network, an authorization request message for a transaction involving the payment account;   when the authorization request message includes the external token:
 identifying, by the payment network, the PAN for the payment account based on the mapping of the external token with the PAN in the vault data structure; and 
 initiating, by the payment network, at least one PAN-dependent service associated with the payment account, such that the at least one PAN-dependent service is imposed on the transaction based on inclusion of the external token in the vault data structure, despite the external token being generated by the token provider separate and apart from the payment network. 
   
     
     
         12 . The computer-implemented method of  claim 11 , further comprising:
 transmitting, by the payment network, the authorization request message to an issuer of the payment account without appending the PAN for the payment account to the authorization request message.   
     
     
         13 . The computer-implemented method of  claim 11 , further comprising:
 appending, by the payment network, the external token to an authorization response from the issuer; and   transmitting, by the payment network, the authorization response, with the external token, to an acquirer associated with the transaction.   
     
     
         14 . The computer-implemented method of  claim 13 , further comprising removing, by the payment network, at least part of the PAN from the authorization response, prior to transmitting the authorization response to the acquirer. 
     
     
         15 . The computing-implemented method of  claim 11 , wherein the external token provider is part of an issuer of the payment account. 
     
     
         16 . The computer-implemented method of  claim 15 , further comprising:
 receiving, by the payment network, at least one cryptographic key from the external token provider and/or the issuer of the payment account;   validating a cryptogram included in the intercepted authorization request message based on the at least one cryptographic key; and then   transmitting the authentication request message to the issuer of the payment account.   
     
     
         17 . The computer-implemented method of  claim 11 , wherein the at least one PAN-dependent service includes one or more of: a risk monitoring service, a fraud service, and/or an authentication service.

Join the waitlist — get patent alerts

Track US2022122061A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.