Constraining transactional capabilities for contactless cards
Abstract
Systems, methods, articles of manufacture, and computer-readable media. A communications interface may receive an indication that a server preauthorized a transaction. The communications interface may receive, from a point of sale device, an indication to pay for the transaction. The contactless card may determine, based on rules stored in the memory, that the location of the mobile device is within one or more locations the contactless card is permitted for use. The contactless card may generate transaction data comprising: indications of an account number and an expiration date of the contactless card, and the indication of the preauthorization. The contactless card may transmit the transaction data to the POS device as payment for the transaction. The server may authorize payment for the transaction using at least a portion of the transaction data based at least in part on identifying the indication of the preauthorization in the transaction data.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A non-transitory computer-readable storage medium, the computer-readable storage medium including instructions that when executed by a processor, cause the processor to:
receive, from a mobile device, a request comprising encrypted data and location data, the location data associated with the mobile device; decrypt the encrypted data based on a key associated with a contactless card; determine, based on a rule associated with an account and the decryption of the encrypted data, that the location data received is within a threshold distance of a location the contactless card is permitted for use; preauthorize a transaction based on the decryption of the encrypted data and the determination that the location data is within the threshold distance of the location the contactless card is permitted for use; select a first level of preauthorization for the transaction from a plurality of levels of preauthorization; store an indication of the preauthorization for the transaction, the indication comprising: (i) the first level of preauthorization, (ii) a timestamp of the preauthorization, (iii) the location data, and (iv) a unique identifier; transmit, to the mobile device, the indication of the preauthorization for the transaction; receive, from a point of sale (POS) device, transaction data comprising: (i) an indication of payment information of the contactless card, and (ii) the indication of the preauthorization of the transaction, wherein the indication of the preauthorization of the transaction is received by the POS device from the contactless card; and approve the transaction based at least in part on a determination that the unique identifier of the indication of the preauthorization of the transaction in the transaction data matches the unique identifier of the stored indication of the preauthorization for the transaction.
2 . The computer-readable storage medium of claim 1 , wherein the indication of the preauthorization is one of a plurality of indications of preauthorization, wherein each indication of preauthorization is for a respective transaction of a plurality of transactions include the transaction, wherein each indication of preauthorization further comprises a respective unique identifier.
3 . The computer-readable storage medium of claim 1 , wherein the first level of preauthorization is selected based on the decryption of the encrypted data and the determination that the location data is within the threshold distance of the location the contactless card is permitted for use.
4 . The computer-readable storage medium of claim 1 , wherein the instructions further cause the processor to, prior to approving the transaction:
determine that the unique identifier of the indication of the preauthorization of the transaction in the transaction data matches the unique identifier of the stored indication of the preauthorization for the transaction.
5 . The computer-readable storage medium of claim 1 , wherein the payment information of the contactless card comprises an account number of the contactless card, an expiration date of the contactless card, and a card verification value (CVV) of the contactless card.
6 . The computer-readable storage medium of claim 5 , wherein the instructions further cause the processor to, prior to approving the transaction:
identify the indication of the preauthorization of the transaction, the account number, the expiration date, and the CVV in the transaction data.
7 . The computer-readable storage medium of claim 6 , wherein the transaction data comprises an EMV payload.
8 . A method, comprising:
receiving, by a server from a mobile device, a request comprising encrypted data and location data, the location data associated with the mobile device; decrypting, by the server, the encrypted data based on a key associated with a contactless card; determining, by the server based on a rule associated with an account and the decryption of the encrypted data, that the location data received is within a threshold distance of a location the contactless card is permitted for use; preauthorizing, by the server, a transaction based on the decryption of the encrypted data and the determination that the location data is within the threshold distance of the location the contactless card is permitted for use; selecting, by the server, a first level of preauthorization for the transaction from a plurality of levels of preauthorization; storing, by the server, an indication of the preauthorization for the transaction, the indication comprising: (i) the first level of preauthorization, (ii) a timestamp of the preauthorization, (iii) the location data, and (iv) a unique identifier; transmitting, by the server to the mobile device, the indication of the preauthorization for the transaction; receiving, by the server from a point of sale (POS) device, transaction data comprising: (i) an indication of payment information of the contactless card, and (ii) the indication of the preauthorization of the transaction, wherein the indication of the preauthorization of the transaction is received by the POS device from the contactless card; and approving the transaction by the server based at least in part on a determination that the unique identifier of the indication of the preauthorization of the transaction in the transaction data matches the unique identifier of the stored indication of the preauthorization for the transaction.
9 . The method of claim 8 , wherein the indication of the preauthorization is one of a plurality of indications of preauthorization, wherein each indication of
preauthorization is for a respective transaction of a plurality of transactions including the transaction, wherein each indication of preauthorization further comprises a respective unique identifier.
10 . The method of claim 8 , wherein the first level of preauthorization is selected based on the decryption of the encrypted data and the determination that the location data is within the threshold distance of the location the contactless card is permitted for use.
11 . The method of claim 8 , further comprising, prior to approving the transaction:
determining, by the server, that the unique identifier of the indication of the preauthorization of the transaction in the transaction data matches the unique identifier of the stored indication of the preauthorization for the transaction.
12 . The method of claim 8 , wherein the payment information of the contactless card comprises an account number of the contactless card, an expiration date of the contactless card, and a card verification value (CVV) of the contactless card.
13 . The method of claim 12 , further comprising, prior to approving the transaction:
identifying, by the server, the indication of the preauthorization of the transaction, the account number, the expiration date, and the CVV in the transaction data.
14 . The method of claim 13 , wherein the transaction data comprises an EMV payload.
15 . A computing apparatus comprising:
a processor; and a memory storing instructions that, when executed by the processor, cause the processor to:
receive, from a mobile device, a request comprising encrypted data and location data, the location data associated with the mobile device;
decrypt the encrypted data based on a key associated with a contactless card;
determine, based on a rule associated with an account and the decryption of the encrypted data, that the location data received is within a threshold distance of a location the contactless card is permitted for use;
preauthorize a transaction based on the decryption of the encrypted data and the determination that the location data is within the threshold distance of the location the contactless card is permitted for use;
select a first level of preauthorization for the transaction from a plurality of levels of preauthorization;
store an indication of the preauthorization for the transaction, the indication comprising: (i) the first level of preauthorization, (ii) a timestamp of the preauthorization, (iii) the location data, and (iv) a unique identifier;
transmit, to the mobile device, the indication of the preauthorization for the transaction;
receive, from a point of sale (POS) device, transaction data comprising: (i) an indication of payment information of the contactless card, and (ii) the indication of the preauthorization of the transaction, wherein the indication of the preauthorization of the transaction is received by the POS device from the contactless card; and
approve the transaction based at least in part on a determination that the unique identifier of the indication of the preauthorization of the transaction in the transaction data matches the unique identifier of the stored indication of the preauthorization for the transaction.
16 . The computing apparatus of claim 15 , wherein the indication of the preauthorization is one of a plurality of indications of preauthorization, wherein each indication of preauthorization is for a respective transaction of a plurality of transactions include the transaction, wherein each indication of preauthorization further comprises a respective unique identifier.
17 . The computing apparatus of claim 15 , wherein the first level of preauthorization is selected based on the decryption of the encrypted data and the determination that the location data is within the threshold distance of the location the contactless card is permitted for use.
18 . The computing apparatus of claim 15 , wherein the instructions further cause the processor to, prior to approving the transaction:
determine that the unique identifier of the indication of the preauthorization of the transaction in the transaction data matches the unique identifier of the stored indication of the preauthorization for the transaction.
19 . The computing apparatus of claim 15 , wherein the payment information of the contactless card comprises an account number of the contactless card, an expiration date of the contactless card, and a card verification value (CVV) of the contactless card.
20 . The computing apparatus of claim 19 , wherein the instructions further configure the apparatus to, prior to approving the transaction:
identify the indication of the preauthorization of the transaction, the account number, the expiration date, and the CVV in the transaction data.Join the waitlist — get patent alerts
Track US2023274257A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.