US2023274257A1PendingUtilityA1

Constraining transactional capabilities for contactless cards

Assignee: CAPITAL ONE SERVICES LLCPriority: Jul 3, 2019Filed: May 10, 2023Published: Aug 31, 2023
Est. expiryJul 3, 2039(~12.9 yrs left)· nominal 20-yr term from priority
G06Q 20/352G06K 19/0723G06Q 20/202G06Q 20/3224G06Q 20/3829G06Q 20/4018G06Q 20/409H04L 9/088G06Q 2220/00G06Q 20/065G06Q 20/10G06Q 20/347G06Q 20/4012G06Q 20/3825G06Q 20/204G06Q 20/405G06Q 20/4015G06Q 20/16G06K 7/10297
70
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems, methods, articles of manufacture, and computer-readable media. A communications interface may receive an indication that a server preauthorized a transaction. The communications interface may receive, from a point of sale device, an indication to pay for the transaction. The contactless card may determine, based on rules stored in the memory, that the location of the mobile device is within one or more locations the contactless card is permitted for use. The contactless card may generate transaction data comprising: indications of an account number and an expiration date of the contactless card, and the indication of the preauthorization. The contactless card may transmit the transaction data to the POS device as payment for the transaction. The server may authorize payment for the transaction using at least a portion of the transaction data based at least in part on identifying the indication of the preauthorization in the transaction data.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A non-transitory computer-readable storage medium, the computer-readable storage medium including instructions that when executed by a processor, cause the processor to:
 receive, from a mobile device, a request comprising encrypted data and location data, the location data associated with the mobile device;   decrypt the encrypted data based on a key associated with a contactless card;   determine, based on a rule associated with an account and the decryption of the encrypted data, that the location data received is within a threshold distance of a location the contactless card is permitted for use;   preauthorize a transaction based on the decryption of the encrypted data and the determination that the location data is within the threshold distance of the location the contactless card is permitted for use;   select a first level of preauthorization for the transaction from a plurality of levels of preauthorization;   store an indication of the preauthorization for the transaction, the indication comprising: (i) the first level of preauthorization, (ii) a timestamp of the preauthorization, (iii) the location data, and (iv) a unique identifier;   transmit, to the mobile device, the indication of the preauthorization for the transaction;   receive, from a point of sale (POS) device, transaction data comprising: (i) an indication of payment information of the contactless card, and (ii) the indication of the preauthorization of the transaction, wherein the indication of the preauthorization of the transaction is received by the POS device from the contactless card; and   approve the transaction based at least in part on a determination that the unique identifier of the indication of the preauthorization of the transaction in the transaction data matches the unique identifier of the stored indication of the preauthorization for the transaction.   
     
     
         2 . The computer-readable storage medium of  claim 1 , wherein the indication of the preauthorization is one of a plurality of indications of preauthorization, wherein each indication of preauthorization is for a respective transaction of a plurality of transactions include the transaction, wherein each indication of preauthorization further comprises a respective unique identifier. 
     
     
         3 . The computer-readable storage medium of  claim 1 , wherein the first level of preauthorization is selected based on the decryption of the encrypted data and the determination that the location data is within the threshold distance of the location the contactless card is permitted for use. 
     
     
         4 . The computer-readable storage medium of  claim 1 , wherein the instructions further cause the processor to, prior to approving the transaction:
 determine that the unique identifier of the indication of the preauthorization of the transaction in the transaction data matches the unique identifier of the stored indication of the preauthorization for the transaction.   
     
     
         5 . The computer-readable storage medium of  claim 1 , wherein the payment information of the contactless card comprises an account number of the contactless card, an expiration date of the contactless card, and a card verification value (CVV) of the contactless card. 
     
     
         6 . The computer-readable storage medium of  claim 5 , wherein the instructions further cause the processor to, prior to approving the transaction:
 identify the indication of the preauthorization of the transaction, the account number, the expiration date, and the CVV in the transaction data.   
     
     
         7 . The computer-readable storage medium of  claim 6 , wherein the transaction data comprises an EMV payload. 
     
     
         8 . A method, comprising:
 receiving, by a server from a mobile device, a request comprising encrypted data and location data, the location data associated with the mobile device;   decrypting, by the server, the encrypted data based on a key associated with a contactless card;   determining, by the server based on a rule associated with an account and the decryption of the encrypted data, that the location data received is within a threshold distance of a location the contactless card is permitted for use;   preauthorizing, by the server, a transaction based on the decryption of the encrypted data and the determination that the location data is within the threshold distance of the location the contactless card is permitted for use;   selecting, by the server, a first level of preauthorization for the transaction from a plurality of levels of preauthorization;   storing, by the server, an indication of the preauthorization for the transaction, the indication comprising: (i) the first level of preauthorization, (ii) a timestamp of the preauthorization, (iii) the location data, and (iv) a unique identifier;   transmitting, by the server to the mobile device, the indication of the preauthorization for the transaction;   receiving, by the server from a point of sale (POS) device, transaction data comprising: (i) an indication of payment information of the contactless card, and (ii) the indication of the preauthorization of the transaction, wherein the indication of the preauthorization of the transaction is received by the POS device from the contactless card; and   approving the transaction by the server based at least in part on a determination that the unique identifier of the indication of the preauthorization of the transaction in the transaction data matches the unique identifier of the stored indication of the preauthorization for the transaction.   
     
     
         9 . The method of  claim 8 , wherein the indication of the preauthorization is one of a plurality of indications of preauthorization, wherein each indication of 
 preauthorization is for a respective transaction of a plurality of transactions including the transaction, wherein each indication of preauthorization further comprises a respective unique identifier.   
     
     
         10 . The method of  claim 8 , wherein the first level of preauthorization is selected based on the decryption of the encrypted data and the determination that the location data is within the threshold distance of the location the contactless card is permitted for use. 
     
     
         11 . The method of  claim 8 , further comprising, prior to approving the transaction:
 determining, by the server, that the unique identifier of the indication of the preauthorization of the transaction in the transaction data matches the unique identifier of the stored indication of the preauthorization for the transaction.   
     
     
         12 . The method of  claim 8 , wherein the payment information of the contactless card comprises an account number of the contactless card, an expiration date of the contactless card, and a card verification value (CVV) of the contactless card. 
     
     
         13 . The method of  claim 12 , further comprising, prior to approving the transaction:
 identifying, by the server, the indication of the preauthorization of the transaction, the account number, the expiration date, and the CVV in the transaction data.   
     
     
         14 . The method of  claim 13 , wherein the transaction data comprises an EMV payload. 
     
     
         15 . A computing apparatus comprising:
 a processor; and   a memory storing instructions that, when executed by the processor, cause the processor to:
 receive, from a mobile device, a request comprising encrypted data and location data, the location data associated with the mobile device; 
 decrypt the encrypted data based on a key associated with a contactless card; 
 determine, based on a rule associated with an account and the decryption of the encrypted data, that the location data received is within a threshold distance of a location the contactless card is permitted for use; 
 preauthorize a transaction based on the decryption of the encrypted data and the determination that the location data is within the threshold distance of the location the contactless card is permitted for use; 
 select a first level of preauthorization for the transaction from a plurality of levels of preauthorization; 
 store an indication of the preauthorization for the transaction, the indication comprising: (i) the first level of preauthorization, (ii) a timestamp of the preauthorization, (iii) the location data, and (iv) a unique identifier; 
 transmit, to the mobile device, the indication of the preauthorization for the transaction; 
 receive, from a point of sale (POS) device, transaction data comprising: (i) an indication of payment information of the contactless card, and (ii) the indication of the preauthorization of the transaction, wherein the indication of the preauthorization of the transaction is received by the POS device from the contactless card; and 
 approve the transaction based at least in part on a determination that the unique identifier of the indication of the preauthorization of the transaction in the transaction data matches the unique identifier of the stored indication of the preauthorization for the transaction. 
   
     
     
         16 . The computing apparatus of  claim 15 , wherein the indication of the preauthorization is one of a plurality of indications of preauthorization, wherein each indication of preauthorization is for a respective transaction of a plurality of transactions include the transaction, wherein each indication of preauthorization further comprises a respective unique identifier. 
     
     
         17 . The computing apparatus of  claim 15 , wherein the first level of preauthorization is selected based on the decryption of the encrypted data and the determination that the location data is within the threshold distance of the location the contactless card is permitted for use. 
     
     
         18 . The computing apparatus of  claim 15 , wherein the instructions further cause the processor to, prior to approving the transaction:
 determine that the unique identifier of the indication of the preauthorization of the transaction in the transaction data matches the unique identifier of the stored indication of the preauthorization for the transaction.   
     
     
         19 . The computing apparatus of  claim 15 , wherein the payment information of the contactless card comprises an account number of the contactless card, an expiration date of the contactless card, and a card verification value (CVV) of the contactless card. 
     
     
         20 . The computing apparatus of  claim 19 , wherein the instructions further configure the apparatus to, prior to approving the transaction:
 identify the indication of the preauthorization of the transaction, the account number, the expiration date, and the CVV in the transaction data.

Join the waitlist — get patent alerts

Track US2023274257A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.