System and methods for obtaining real-time cardholder authentication of a payment transaction
Abstract
A secondary authentication system and computer-implemented method for obtaining real-time cardholder authentication of a payment transaction associated with a cardholder's payment card includes a memory device for storing data and a processor communicatively coupled to the memory device. The processor is programmed to receive a payment authorization request message including a primary account number corresponding to a payment account of the cardholder for funding the payment transaction. In addition, the processor is programmed to determine whether the payment account requires secondary authentication by the cardholder for the payment transaction, and if, based on the determination, the payment account requires secondary authentication of the payment transaction, place the payment transaction on hold. Furthermore, the processor is programed to identify a mobile device associated with the payment account of the cardholder, transmit an authentication request message to the identified mobile device, and receive, from the mobile device, an authentication response message.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for obtaining real-time cardholder authentication of a payment transaction based on geolocation, said method comprising:
receiving, from a point-of-sale terminal, a payment authorization request message including a primary account number corresponding to a payment account of a cardholder and location data corresponding to a physical location of the point-of-sale terminal; identifying the physical location of the point-of-sale terminal based on the location data included in the payment authorization request message; identifying a location of a mobile device of the cardholder, the mobile device including a secondary authentication application configured to provide the location of the mobile device; comparing the identified location of the mobile device to the identified physical location of the point-of-sale terminal; determining whether the payment account requires secondary authentication of the payment transaction by the cardholder; placing the payment transaction on hold if, based on the determination, the payment account requires secondary authentication of the payment transaction; transmitting an authentication request message to the mobile device; determining that a difference between the identified location of the mobile device and the identified physical location of point-of-sale terminal is below a predefined threshold distance; monitoring the difference until it exceeds the predetermined threshold distance; upon the difference exceeding the predetermined threshold distance, determining whether an authentication response message was received from the mobile device; if the authentication response message was not received from the mobile device, populating a field of the payment authorization request message with a decline code; and transmitting the payment authorization request message to an acquirer as a payment authorization response message.
2 . The method in accordance with claim 1 , wherein identifying the location of the mobile device comprises obtaining location information by one or more of the following: a global positioning system service, ping data that includes geotemporal data, and from cell location register information held by a telecommunications provider to which the mobile device is connected.
3 . The method in accordance with claim 1 , wherein receiving, from the point-of-sale terminal, the payment authorization request message comprises intercepting the payment authorization request message transmitted from the point-of-sale terminal.
4 . The method in accordance with claim 3 , wherein the method is performed by a secondary authentication system that is a component of an interchange network.
5 . The method in accordance with claim 4 , wherein intercepting the payment authorization request message comprises intercepting the payment authorization request message intended for the interchange network.
6 . The method in accordance with claim 1 , further comprising:
receiving, from the secondary authentication application executing on the mobile device associated with the cardholder:
account registration information, the account registration information including the primary account number and mobile device identification data corresponding to the mobile device;
account credentials comprising a login identifier and a password;
a biometric profile of the cardholder, the biometric profile including a digital representation of a select physical feature of the cardholder; and
a secondary authentication restriction;
generating a new cardholder account, the new cardholder account including the account registration information, the account credentials, and the secondary authentication restriction; and storing the new cardholder account and the biometric profile.
7 . The method in accordance with claim 6 , wherein determining whether the payment account requires secondary authentication of the payment transaction comprises determining that the payment transaction requires secondary authentication based on the secondary authentication restriction.
8 . The method in accordance with claim 6 , further comprising identifying the mobile device associated with the new cardholder account based on the mobile device identification data.
9 . The method in accordance with claim 1 , wherein placing the payment transaction on hold comprises:
interrupting a normal transaction process; and storing the payment authorization request message.
10 . The method in accordance with claim 1 , wherein transmitting the authentication request message to the mobile device comprises pushing the authentication request message to a secondary authentication application installed at least partially on the mobile device, the authentication request message causing the mobile device to display a notification indicating that the authentication request message is received.
11 . A method for obtaining real-time cardholder authentication of a payment transaction based on geolocation, said method comprising:
receiving, from a point-of-sale terminal, a payment authorization request message including a primary account number corresponding to a payment account of a cardholder and location data corresponding to a physical location of the point-of-sale terminal; identifying the physical location of the point-of-sale terminal based on the location data included in the payment authorization request message; identifying a location of a mobile device of the cardholder, the mobile device including a secondary authentication application configured to provide the location of the mobile device; comparing the identified location of the mobile device to the identified physical location of the point-of-sale terminal; determining that the payment account requires secondary authentication of the payment transaction by the cardholder; based on the determination that the payment account requires secondary authentication, placing the payment transaction on hold; transmitting an authentication request message to the mobile device; determining that a difference between the identified location of the mobile device and the identified physical location of point-of-sale terminal exceeds a predefined threshold distance; based on the difference exceeding the predetermined threshold distance, determining that an authentication response message was received from the mobile device; based on the determination that the authentication response message was received, releasing the hold on the payment authorization request message; and forwarding the payment authorization request message to an issuer associated with the primary account number.
12 . The method in accordance with claim 11 , wherein identifying the location of the mobile device comprises obtaining location information by one or more of the following: a global positioning system service, ping data that includes geotemporal data, and from cell location register information held by a telecommunications provider to which the mobile device is connected.
13 . The method in accordance with claim 11 , wherein receiving, from the point-of-sale terminal, the payment authorization request message comprises intercepting the payment authorization request message transmitted from the point-of-sale terminal.
14 . The method in accordance with claim 13 , wherein the method is performed by a secondary authentication system that is a component of an interchange network.
15 . The method in accordance with claim 14 , wherein intercepting the payment authorization request message comprises intercepting the payment authorization request message intended for the interchange network.
16 . The method in accordance with claim 14 , wherein forwarding the payment authorization request message to the issuer comprises forwarding the payment authorization request message to the interchange network such that the interchange network forwards the payment authorization request message to the issuer.
17 . The method in accordance with claim 11 , further comprising:
receiving, from the secondary authentication application executing on the mobile device associated with the cardholder:
account registration information, the account registration information including the primary account number and mobile device identification data corresponding to the mobile device;
account credentials comprising a login identifier and a password;
a biometric profile of the cardholder, the biometric profile including a digital representation of a select physical feature of the cardholder; and
a secondary authentication restriction;
generating a new cardholder account, the new cardholder account including the account registration information, the account credentials, and the secondary authentication restriction; and storing the new cardholder account and the biometric profile.
18 . The method in accordance with claim 17 , wherein determining whether the payment account requires secondary authentication of the payment transaction comprises determining that the payment transaction requires secondary authentication based on the secondary authentication restriction.
19 . The method in accordance with claim 17 , further comprising identifying the mobile device associated with the new cardholder account based on the mobile device identification data.
20 . The method in accordance with claim 11 , wherein transmitting the authentication request message to the mobile device comprises pushing the authentication request message to a secondary authentication application installed at least partially on the mobile device, the authentication request message causing the mobile device to display a notification indicating that the authentication request message is received.Join the waitlist — get patent alerts
Track US2023410119A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.