Consumer device payment token management
Abstract
Embodiments are provided that improve secure validation of device identity and/or user identity. Some example embodiments receive, from a provider computing device via provider device second communication capabilities, a short-range token indication associated with a client computing device, the short-range token indication including an identifying token provided utilizing client device first communication capabilities, where the identifying token is received in response to the provider computing device detecting that the client computing device is within a provider environment associated with a first provider device communication range corresponding to provider device first communication capabilities, where the first provider device communication range is shorter. Some example embodiments validate the short-term token indication by determining a token set associated with the client computing device includes the identifying token and in response, transmits a confirmation to the provider computing device via the provider device second communication capabilities.
Claims
exact text as granted — not AI-modified1 - 39 . (canceled)
40 . An apparatus comprising at least one processor and at least one non-transitory memory comprising program code, wherein the at least one non-transitory memory and the program code are configured to, with the at least one processor, cause the apparatus to:
receive, from a provider computing device via provider device second communication capabilities, a short-range token indication associated with a client computing device, wherein the short-range token indication comprises at least an identifying token provided via the client computing device utilizing client device first communication capabilities, wherein the identifying token is received from the provider computing device in response to the provider computing device detecting that the client computing device is within a provider environment associated with a first provider device communication range corresponding to provider device first communication capabilities, wherein the first provider device communication range is shorter than the second provider device communication range; validate the short-term token indication by at least determining a token set associated with the client computing device comprises the identifying token; and in response to validating the short-term token indication, transmit a confirmation to the provider computing device via the provider device second communication capabilities.
41 . The apparatus according to claim 40 , the apparatus further caused to:
generate the token set corresponding to the client computing device, wherein each identifying token of the token set is associated with a private key and client identifying data, and wherein each identifying token of the token set comprises non-sensitive data; and transmit the token set to the client computing device.
42 . The apparatus according to claim 40 , the apparatus further caused to:
initiate a redemption period in response to receiving the identifying token indicating that the client computing device is within the provider environment; and validate a transaction initiated during the redemption period associated with the first provider device.
43 . The apparatus according to claim 40 , wherein to transmit the confirmation to the provider computing device the apparatus is caused to:
retrieve client identifying data associated with the client computing device; and transmit the client identifying data to the provider computing device via the provider device second communication capabilities.
44 . The apparatus according to claim 40 , wherein to validate the short-term token indication the apparatus is further caused to:
identify at least one private key associated with the identifying token associated with the client computing device; and authenticating the identifying token utilizing the at least one private key.
45 . The apparatus according to claim 40 , wherein at a first time the apparatus is communicable with the client computing device via client device second communication capabilities, wherein the client device first communication capabilities are associated with a client device first communication range and the client device second communication capabilities are associated with a client device second communication range, wherein the client device first communication range is shorter than the client device second communication range, and wherein the short-range token indication is received at a second time where the apparatus is not communicable with the client computing device.
46 . The apparatus according to claim 40 , the apparatus further caused to:
receive a second identifying token of the token set; initiate a redemption period associated with the second identifying token of the token set; track a timestamp interval during the redemption period; determine the redemption period has expired; and invalidate the second identifying token.
47 . A computer-implemented method comprising:
receiving, from a provider computing device via provider device second communication capabilities, a short-range token indication associated with a client computing device, wherein the short-range token indication comprises at least an identifying token provided via the client computing device utilizing client device first communication capabilities, wherein the identifying token is received from the provider computing device in response to the provider computing device detecting that the client computing device is within a provider environment associated with a first provider device communication range corresponding to provider device first communication capabilities, wherein the first provider device communication range is shorter than the second provider device communication range; validating the short-term token indication by at least determining a token set associated with the client computing device comprises the identifying token; and in response to validating the short-term token indication, transmitting a confirmation to the provider computing device via the provider device second communication capabilities.
48 . The computer-implemented method according to claim 47 , the computer-implemented method further comprising:
generating the token set corresponding to the client computing device, wherein each identifying token of the token set is associated with a private key and client identifying data, and wherein each identifying token of the token set comprises non-sensitive data; and transmitting the token set to the client computing device.
49 . The computer-implemented method according to claim 47 , the computer-implemented method further comprising:
initiating a redemption period in response to receiving the identifying token indicating that the client computing device is within the provider environment; and validating a transaction initiated during the redemption period associated with the first provider device.
50 . The computer-implemented method according to claim 47 , wherein transmitting the confirmation to the provider computing device comprises:
retrieving client identifying data associated with the client computing device; and transmitting the client identifying data to the provider computing device via the provider device second communication capabilities.
51 . The computer-implemented method according to claim 47 , wherein validating the short-term token indication comprises:
identifying at least one private key associated with the identifying token associated with the client computing device; and authenticating the identifying token utilizing the at least one private key.
52 . The computer-implemented method according to claim 47 performed by a central system, wherein at a first time the central system is communicable with the client computing device via client device second communication capabilities, wherein the client device first communication capabilities are associated with a client device first communication range and the client device second communication capabilities are associated with a client device second communication range, wherein the client device first communication range is shorter than the client device second communication range, and wherein the short-range token indication is received at a second time where the central system is not communicable with the client computing device.
53 . The computer-implemented method according to claim 47 , the computer-implemented method further comprising:
receiving a second identifying token of the token set; initiating a redemption period associated with the second identifying token of the token set; tracking a timestamp interval during the redemption period; determining the redemption period has expired; and invalidating the second identifying token.
54 . A computer program product comprising a non-transitory computer readable storage medium and computer program instructions stored therein, the computer program instructions comprising program instructions that in execution with at least one processor are configured to:
receive, from a provider computing device via provider device second communication capabilities, a short-range token indication associated with a client computing device, wherein the short-range token indication comprises at least an identifying token provided via the client computing device utilizing client device first communication capabilities, wherein the identifying token is received from the provider computing device in response to the provider computing device detecting that the client computing device is within a provider environment associated with a first provider device communication range corresponding to provider device first communication capabilities, wherein the first provider device communication range is shorter than the second provider device communication range; validate the short-term token indication by at least determining a token set associated with the client computing device comprises the identifying token; and in response to validating the short-term token indication, transmit a confirmation to the provider computing device via the provider device second communication capabilities.
55 . The computer program product according to 54 , the computer program product further configured to:
generate the token set corresponding to the client computing device, wherein each identifying token of the token set is associated with a private key and client identifying data, and wherein each identifying token of the token set comprises non-sensitive data; and transmit the token set to the client computing device.
56 . The computer program product according to claim 54 , wherein to transmit the confirmation to the provider computing device the computer program product is configured to:
retrieve client identifying data associated with the client computing device; and transmit the client identifying data to the provider computing device via the provider device second communication capabilities.
57 . The computer program product according to claim 54 , wherein to validate the short-term token indication the computer program product is configured to:
identify at least one private key associated with the identifying token associated with the client computing device; and authenticate the identifying token utilizing the at least one private key.
58 . The computer program product according to claim 54 , wherein at a first time the computer program product is communicable with the client computing device via client device second communication capabilities, wherein the client device first communication capabilities are associated with a client device first communication range and the client device second communication capabilities are associated with a client device second communication range, wherein the client device first communication range is shorter than the client device second communication range, and wherein the short-range token indication is received at a second time where the computer program product is not communicable with the client computing device.
59 . The computer program product according to claim 54 , the computer program product further caused to:
receive a second identifying token of the token set; initiate a redemption period associated with the second identifying token of the token set; track a timestamp interval during the redemption period; determine the redemption period has expired; and invalidate the second identifying token.Join the waitlist — get patent alerts
Track US2022253831A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.