US2023410119A1PendingUtilityA1

System and methods for obtaining real-time cardholder authentication of a payment transaction

Assignee: MASTERCARD INTERNATIONAL INCPriority: Aug 23, 2018Filed: Sep 5, 2023Published: Dec 21, 2023
Est. expiryAug 23, 2038(~12.1 yrs left)· nominal 20-yr term from priority
G06Q 20/102G06Q 20/204G06Q 20/085G06Q 20/405G06Q 20/4093G06Q 20/3823G06Q 20/40145G06Q 20/4012G06Q 20/3224G06Q 20/425G06Q 20/00
71
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A secondary authentication system and computer-implemented method for obtaining real-time cardholder authentication of a payment transaction associated with a cardholder's payment card includes a memory device for storing data and a processor communicatively coupled to the memory device. The processor is programmed to receive a payment authorization request message including a primary account number corresponding to a payment account of the cardholder for funding the payment transaction. In addition, the processor is programmed to determine whether the payment account requires secondary authentication by the cardholder for the payment transaction, and if, based on the determination, the payment account requires secondary authentication of the payment transaction, place the payment transaction on hold. Furthermore, the processor is programed to identify a mobile device associated with the payment account of the cardholder, transmit an authentication request message to the identified mobile device, and receive, from the mobile device, an authentication response message.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for obtaining real-time cardholder authentication of a payment transaction based on geolocation, said method comprising:
 receiving, from a point-of-sale terminal, a payment authorization request message including a primary account number corresponding to a payment account of a cardholder and location data corresponding to a physical location of the point-of-sale terminal;   identifying the physical location of the point-of-sale terminal based on the location data included in the payment authorization request message;   identifying a location of a mobile device of the cardholder, the mobile device including a secondary authentication application configured to provide the location of the mobile device;   comparing the identified location of the mobile device to the identified physical location of the point-of-sale terminal;   determining whether the payment account requires secondary authentication of the payment transaction by the cardholder;   placing the payment transaction on hold if, based on the determination, the payment account requires secondary authentication of the payment transaction;   transmitting an authentication request message to the mobile device;   determining that a difference between the identified location of the mobile device and the identified physical location of point-of-sale terminal is below a predefined threshold distance;   monitoring the difference until it exceeds the predetermined threshold distance;   upon the difference exceeding the predetermined threshold distance, determining whether an authentication response message was received from the mobile device;   if the authentication response message was not received from the mobile device, populating a field of the payment authorization request message with a decline code; and   transmitting the payment authorization request message to an acquirer as a payment authorization response message.   
     
     
         2 . The method in accordance with  claim 1 , wherein identifying the location of the mobile device comprises obtaining location information by one or more of the following: a global positioning system service, ping data that includes geotemporal data, and from cell location register information held by a telecommunications provider to which the mobile device is connected. 
     
     
         3 . The method in accordance with  claim 1 , wherein receiving, from the point-of-sale terminal, the payment authorization request message comprises intercepting the payment authorization request message transmitted from the point-of-sale terminal. 
     
     
         4 . The method in accordance with  claim 3 , wherein the method is performed by a secondary authentication system that is a component of an interchange network. 
     
     
         5 . The method in accordance with  claim 4 , wherein intercepting the payment authorization request message comprises intercepting the payment authorization request message intended for the interchange network. 
     
     
         6 . The method in accordance with  claim 1 , further comprising:
 receiving, from the secondary authentication application executing on the mobile device associated with the cardholder:
 account registration information, the account registration information including the primary account number and mobile device identification data corresponding to the mobile device; 
 account credentials comprising a login identifier and a password; 
 a biometric profile of the cardholder, the biometric profile including a digital representation of a select physical feature of the cardholder; and 
 a secondary authentication restriction; 
   generating a new cardholder account, the new cardholder account including the account registration information, the account credentials, and the secondary authentication restriction; and   storing the new cardholder account and the biometric profile.   
     
     
         7 . The method in accordance with  claim 6 , wherein determining whether the payment account requires secondary authentication of the payment transaction comprises determining that the payment transaction requires secondary authentication based on the secondary authentication restriction. 
     
     
         8 . The method in accordance with  claim 6 , further comprising identifying the mobile device associated with the new cardholder account based on the mobile device identification data. 
     
     
         9 . The method in accordance with  claim 1 , wherein placing the payment transaction on hold comprises:
 interrupting a normal transaction process; and   storing the payment authorization request message.   
     
     
         10 . The method in accordance with  claim 1 , wherein transmitting the authentication request message to the mobile device comprises pushing the authentication request message to a secondary authentication application installed at least partially on the mobile device, the authentication request message causing the mobile device to display a notification indicating that the authentication request message is received. 
     
     
         11 . A method for obtaining real-time cardholder authentication of a payment transaction based on geolocation, said method comprising:
 receiving, from a point-of-sale terminal, a payment authorization request message including a primary account number corresponding to a payment account of a cardholder and location data corresponding to a physical location of the point-of-sale terminal;   identifying the physical location of the point-of-sale terminal based on the location data included in the payment authorization request message;   identifying a location of a mobile device of the cardholder, the mobile device including a secondary authentication application configured to provide the location of the mobile device;   comparing the identified location of the mobile device to the identified physical location of the point-of-sale terminal;   determining that the payment account requires secondary authentication of the payment transaction by the cardholder;   based on the determination that the payment account requires secondary authentication, placing the payment transaction on hold;   transmitting an authentication request message to the mobile device;   determining that a difference between the identified location of the mobile device and the identified physical location of point-of-sale terminal exceeds a predefined threshold distance;   based on the difference exceeding the predetermined threshold distance, determining that an authentication response message was received from the mobile device;   based on the determination that the authentication response message was received, releasing the hold on the payment authorization request message; and   forwarding the payment authorization request message to an issuer associated with the primary account number.   
     
     
         12 . The method in accordance with  claim 11 , wherein identifying the location of the mobile device comprises obtaining location information by one or more of the following: a global positioning system service, ping data that includes geotemporal data, and from cell location register information held by a telecommunications provider to which the mobile device is connected. 
     
     
         13 . The method in accordance with  claim 11 , wherein receiving, from the point-of-sale terminal, the payment authorization request message comprises intercepting the payment authorization request message transmitted from the point-of-sale terminal. 
     
     
         14 . The method in accordance with  claim 13 , wherein the method is performed by a secondary authentication system that is a component of an interchange network. 
     
     
         15 . The method in accordance with  claim 14 , wherein intercepting the payment authorization request message comprises intercepting the payment authorization request message intended for the interchange network. 
     
     
         16 . The method in accordance with  claim 14 , wherein forwarding the payment authorization request message to the issuer comprises forwarding the payment authorization request message to the interchange network such that the interchange network forwards the payment authorization request message to the issuer. 
     
     
         17 . The method in accordance with  claim 11 , further comprising:
 receiving, from the secondary authentication application executing on the mobile device associated with the cardholder:
 account registration information, the account registration information including the primary account number and mobile device identification data corresponding to the mobile device; 
 account credentials comprising a login identifier and a password; 
 a biometric profile of the cardholder, the biometric profile including a digital representation of a select physical feature of the cardholder; and 
 a secondary authentication restriction; 
   generating a new cardholder account, the new cardholder account including the account registration information, the account credentials, and the secondary authentication restriction; and   storing the new cardholder account and the biometric profile.   
     
     
         18 . The method in accordance with  claim 17 , wherein determining whether the payment account requires secondary authentication of the payment transaction comprises determining that the payment transaction requires secondary authentication based on the secondary authentication restriction. 
     
     
         19 . The method in accordance with  claim 17 , further comprising identifying the mobile device associated with the new cardholder account based on the mobile device identification data. 
     
     
         20 . The method in accordance with  claim 11 , wherein transmitting the authentication request message to the mobile device comprises pushing the authentication request message to a secondary authentication application installed at least partially on the mobile device, the authentication request message causing the mobile device to display a notification indicating that the authentication request message is received.

Join the waitlist — get patent alerts

Track US2023410119A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.