Authenticating transactions using risk scores derived from detailed device information
Abstract
One embodiment of the invention is directed to a method comprising, receiving an authentication request message for a transaction. The method further comprises determining that detailed device information is required to authenticate the transaction and generating a message including an identifier and a request for the detailed device information. The method further comprises retrieving the detailed device information from a remote server computer using the identifier and modifying the authentication request message to include the detailed device information. The method further comprises sending the modified authentication request message to an access control server computer. The method further comprises receiving an authentication response message from the access control server computer including a verification value for the transaction, where the verification value is generated based on a result of a risk analysis performed using the detailed device information.
Claims
exact text as granted — not AI-modified1 .- 20 . (canceled)
21 . A method comprising:
generating, by a server computer, a message including an identifier and a request for detailed device information; retrieving, by the server computer, the detailed device information from an external server computer using the identifier; receiving, by the server computer, an authentication request message in an authentication process for a transaction; and determining, by the server computer, that the detailed device information is required to authenticate the transaction, wherein an authentication result is determined using at least the detailed device information.
22 . The method of claim 21 , further comprising:
transmitting, by the server computer, an authentication response message indicating the authentication result.
23 . The method of claim 21 , further comprising:
receiving, by the external server computer, the detailed device information prior to generating the message including the identifier and the request for the detailed device information.
24 . The method of claim 23 , wherein the detailed device information comprises a device identifier of a portable device that is used in the authentication process.
25 . The method of claim 21 , wherein the authentication request message is received from a portable device operated by a user conducting the transaction with a merchant.
26 . The method of claim 25 , wherein the portable device is a mobile phone.
27 . The method of claim 21 , wherein the detailed device information is used to perform a risk analysis of the transaction.
28 . The method of claim 27 , wherein an access control server in communication with the server computer performs the risk analysis.
29 . The method of claim 21 , wherein the authentication request message is received from an authentication application portable device operated by a user conducting the transaction with a merchant.
30 . The method of claim 21 , wherein the identifier is a session identifier for the transaction.
31 . The method of claim 21 , wherein the server computer is a group of servers functioning as a unit.
32 . The method of claim 21 , wherein the server computer is a directory server computer.
33 . A server computer comprising:
a processor; and a computer readable medium comprising code, executable by the processor, for performing operations comprising: generating a message including an identifier and a request for detailed device information; retrieving the detailed device information from an external server computer using the identifier; receiving an authentication request message in an authentication process for a transaction; and determining that the detailed device information is required to authenticate the transaction, wherein an authentication result is determined using at least the detailed device information.
34 . The server computer of claim 33 , wherein the operations further comprise:
transmitting, by the server computer, an authentication response message indicating the authentication result.
35 . The server computer of claim 33 , wherein the operations further comprise:
receiving, by the external server computer, the detailed device information prior to generating the message including the identifier and the request for the detailed device information.
36 . A system comprising:
a server computer comprising a processor, and a computer readable medium comprising code, executable by the processor, for performing operations comprising generating a message including an identifier and a request for detailed device information, retrieving the detailed device information from an external server computer using the identifier, receiving an authentication request message in an authentication process for a transaction, and determining that the detailed device information is required to authenticate the transaction, wherein an authentication result is determined using at least the detailed device information; and the external server computer.
37 . The system of claim 36 , wherein the operations further comprise:
transmitting, by the server computer, an authentication response message indicating the authentication result.
38 . The system of claim 36 , wherein the authentication request message is received from an authentication application on a portable device operated by a user conducting the transaction with a merchant.
39 . The system of claim 38 , further comprising the portable device.
40 . The system of claim 39 , wherein the portable device is a phone.Join the waitlist — get patent alerts
Track US2022414672A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.