WO2020005897A1 - System, method, and apparatus for aggregated authentication - Google Patents
System, method, and apparatus for aggregated authentication Download PDFInfo
- Publication number
- WO2020005897A1 WO2020005897A1 PCT/US2019/038918 US2019038918W WO2020005897A1 WO 2020005897 A1 WO2020005897 A1 WO 2020005897A1 US 2019038918 W US2019038918 W US 2019038918W WO 2020005897 A1 WO2020005897 A1 WO 2020005897A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- authentication
- merchant
- issuer
- transaction
- transactions
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/08—Payment architectures
- G06Q20/10—Payment architectures specially adapted for electronic funds transfer [EFT] systems; specially adapted for home banking systems
- G06Q20/102—Bill distribution or payments
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/36—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes
- G06Q20/367—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes involving electronic purses or money safes
- G06Q20/3674—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes involving electronic purses or money safes involving authentication
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3821—Electronic credentials
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/401—Transaction verification
- G06Q20/4018—Transaction verification using the card verification value [CVV] associated with the card
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/409—Device specific authentication in transaction processing
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0853—Network architectures or network communication protocols for network security for authentication of entities using an additional device, e.g. smartcard, SIM or a different communication terminal
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2463/00—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
- H04L2463/102—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying security measure for e-commerce
Definitions
- This disclosure relates generally to authentication and, in some non-limiting embodiments or aspects, to a system, method, and apparatus for aggregated authentication in an online, open loop payment network.
- 3DS 3-D Secure
- a computer-implemented method for aggregated authentication in an online, open loop payment network comprising an issuer authentication system, a merchant system, a client device, and a transaction service provider system, including: receiving, by the issuer authentication system from the merchant system, a single authentication request message to conduct a plurality of transactions with a plurality of merchants, the single authentication request message comprising an aggregation identifier, a plurality of merchant identifiers, and transaction data for each transaction of the plurality of transactions; detecting, by the issuer authentication system, the aggregation identifier in the single authentication request message; in response to detecting the aggregation identifier, generating, by the issuer authentication system, a single authentication response message comprising a plurality of authentication codes, each authentication code of the plurality of authentication codes corresponding to a merchant of the plurality of merchants; and communicating, by the issuer authentication system, the single authentication response message to the merchant system, the single authentication response message
- the single authentication response message comprises a plurality of fields, each field of the plurality of fields comprising an authentication code of the plurality of authentication codes.
- the merchant system comprises a merchant plug-in configured to communicate with the issuer authentication system.
- the merchant plug-in is configured to communicate with the issuer authentication system via at least one Application Programming Interface (API).
- API Application Programming Interface
- the merchant system is configured to communicate with the issuer authentication system through a payment gateway.
- the merchant system is controlled by an aggregator merchant, wherein the merchant system is in communication with a plurality of other merchant systems associated with the plurality of merchants.
- the method further includes prompting the user for a single authentication for the plurality of transactions. In some non-limiting embodiments or aspects, the method further includes separately processing, by the transaction service provider system, the plurality of transactions based on the single authentication received from the client device. In some non-limiting embodiments or aspects, the single authentication request message is received by the issuer authentication system from the transaction service provider system, wherein the single authentication request message is received by the transaction service provider system from the merchant system.
- a system for aggregated authentication in an online, open loop payment network including at least one processor programmed or configured to: receive, from a merchant system, a single authentication request message to conduct a plurality of transactions with a plurality of merchants, the single authentication request message comprising an aggregation identifier, a plurality of merchant identifiers, and transaction data for each transaction of the plurality of transactions; detect the aggregation identifier in the single authentication request message; in response to detecting the aggregation identifier, generate a single authentication response message comprising a plurality of authentication codes, each authentication code of the plurality of authentication codes corresponding to a merchant of the plurality of merchants; and communicate the single authentication response message to the merchant system, the single authentication response message configured to cause the merchant system to separately process each transaction of the plurality of transactions.
- the system further includes an issuer authentication system including the at least one processor.
- the single authentication response message includes a plurality of fields, each field of the plurality of fields comprising an authentication code of the plurality of authentication codes.
- the system further includes a merchant plug-in installed at the merchant system, the merchant plug-in configured to communicate with the at least one processor.
- the merchant plug-in is configured to communicate with the at least one processor via at least one API.
- the at least one processor communicates with the merchant system through a payment gateway.
- the system further includes the merchant system, wherein the merchant system is operated by an aggregator merchant, and wherein the merchant system is in communication with a plurality of other merchant systems associated with the plurality of merchants.
- the issuer authentication system prompts the user for a single authentication for the plurality of transactions.
- the system further includes a transaction service provider system in communication with the at least one processor, the transaction service provider system configured to process the plurality of transactions based on the single authentication received from the client device.
- a computer program product for aggregated authentication in an online, open loop payment network including at least one non-transitory computer-readable medium including program instructions that, when executed by at least one processor, cause the at least one processor to: receive, from a merchant system, a single authentication request message to conduct a plurality of transactions with a plurality of merchants, the single authentication request message comprising an aggregation identifier, a plurality of merchant identifiers, and transaction data for each transaction of the plurality of transactions; detect the aggregation identifier in the single authentication request message; in response to detecting the aggregation identifier, generate a single authentication response message comprising a plurality of authentication codes, each authentication code of the plurality of authentication codes corresponding to a merchant of the plurality of merchants; and communicate the single authentication response message to the merchant system, the single authentication response message configured to cause the merchant system to separately process each transaction of the plurality of transactions.
- a computer-implemented method for aggregated authentication in an online, open loop payment network comprising an issuer authentication system, a merchant system, a client device, and a transaction service provider system, including: receiving, by the merchant system from the client device, a transaction request to conduct a plurality of transactions with a plurality of merchants; generating, by the merchant system, a single authentication request message based on the transaction request, the single authentication request message comprising an aggregation identifier, a plurality of merchant identifiers corresponding to the plurality of merchants, and transaction data for each transaction of the plurality of transactions; communicating, by the merchant system to the issuer authentication system, the single authentication request message; receiving, by the merchant system from the issuer authentication system in response to the single authentication request message, a single authentication response message comprising a plurality of authentication codes, each authentication code of the plurality of authentication codes corresponding to a merchant of the plurality of merchants; prompting, by the merchant system,
- the merchant system includes a merchant plug-in configured to communicate with the issuer authentication system and generate the single authentication request message.
- the merchant plug-in is configured to communicate with the issuer authentication system via at least one API.
- the merchant system is configured to communicate with the issuer authentication system through a payment gateway.
- the merchant system is controlled by an aggregator merchant, and wherein the merchant system is in communication with a plurality of other merchant systems associated with the plurality of merchants.
- a computer-implemented method for aggregated authentication in an online, open loop payment network comprising an issuer authentication system, a merchant system, a client device, and a transaction service provider system.
- the method includes receiving, by the transaction service provider system from the merchant system, a request to conduct a plurality of transactions with a plurality of merchants, the request comprising account data for a user; identifying, by the transaction service provider system, the issuer authentication system from a plurality of issuer authentication systems based on the account data; in response to identifying the issuer authentication system, communicating, by the transaction service provider system to the issuer authentication system, an identifier of the issuer authentication system; receiving, by the transaction service provider system from the merchant system, a plurality of authorization requests, each authorization request of the plurality of authorization requests corresponding to a transaction of the plurality of transactions; and separately processing each authorization request of the plurality of authorization requests.
- the method further includes verifying, by the transaction service provider system, that an account identified in the account data is enrolled for secure authentication.
- the identifier of the issuer authentication system comprises a URL configured to redirect the client device from the merchant system to the issuer authentication system.
- Clause 1 A computer-implemented method for aggregated authentication in an online, open loop payment network comprising an issuer authentication system, a merchant system, a client device, and a transaction service provider system, comprising: receiving, by the issuer authentication system from the merchant system, a single authentication request message to conduct a plurality of transactions with a plurality of merchants, the single authentication request message comprising an aggregation identifier, a plurality of merchant identifiers, and transaction data for each transaction of the plurality of transactions; detecting, by the issuer authentication system, the aggregation identifier in the single authentication request message; in response to detecting the aggregation identifier, generating, by the issuer authentication system, a single authentication response message comprising a plurality of authentication codes, each authentication code of the plurality of authentication codes corresponding to a merchant of the plurality of merchants; and communicating, by the issuer authentication system,
- Clause 2 The computer-implemented method of clause 1 , wherein the single authentication response message comprises a plurality of fields, each field of the plurality of fields comprising an authentication code of the plurality of authentication codes.
- Clause 3 The method of clauses 1 or 2, wherein the merchant system comprises a merchant plug-in configured to communicate with the issuer authentication system.
- Clause 4 The method of any of clauses 1-3, wherein the merchant plug-in is configured to communicate with the issuer authentication system via at least one Application Programming Interface (API).
- API Application Programming Interface
- Clause 5 The method of any of clauses 1 -4, wherein the merchant system is configured to communicate with the issuer authentication system through a payment gateway.
- Clause 6 The method of any of clauses 1 -5, wherein the merchant system is controlled by an aggregator merchant, and wherein the merchant system is in communication with a plurality of other merchant systems associated with the plurality of merchants.
- Clause 7 The method of any of clauses 1 -6, further comprising prompting a user for a single authentication for the plurality of transactions.
- Clause 8 The method of any of clauses 1-7, wherein the single authentication request message is received by the issuer authentication system from the transaction service provider system, and wherein the single authentication request message is received by the transaction service provider system from the merchant system.
- a system for aggregated authentication in an online, open loop payment network comprising at least one processor programmed or configured to: receive, from a merchant system, a single authentication request message to conduct a plurality of transactions with a plurality of merchants, the single authentication request message comprising an aggregation identifier, a plurality of merchant identifiers, and transaction data for each transaction of the plurality of transactions; detect the aggregation identifier in the single authentication request message; in response to detecting the aggregation identifier, generate a single authentication response message comprising a plurality of authentication codes, each authentication code of the plurality of authentication codes corresponding to a merchant of the plurality of merchants; and communicate the single authentication response message to the merchant system, the single authentication response message configured to cause the merchant system to separately process each transaction of the plurality of transactions.
- Clause 10 The system of clause 9, further comprising an issuer authentication system, the issuer authentication system including the at least one processor.
- Clause 1 1 The system of clauses 9 or 10, wherein the single authentication response message comprises a plurality of fields, each field of the plurality of fields comprising an authentication code of the plurality of authentication codes.
- Clause 12 The system of any of clauses 9-1 1 , further comprising a merchant plug-in installed at the merchant system, the merchant plug-in configured to communicate with the at least one processor.
- Clause 13 The system of any of clauses 9-12, wherein the merchant plugin is configured to communicate with the at least one processor via at least one Application Programming Interface (API).
- API Application Programming Interface
- Clause 14 The system of any of clauses 9-13, wherein the at least one processor communicates with the merchant system through a payment gateway.
- Clause 15 The system of any of clauses 9-14, further comprising the merchant system, wherein the merchant system is operated by an aggregator merchant, and wherein the merchant system is in communication with a plurality of other merchant systems associated with the plurality of merchants.
- Clause 16 The system of any of clauses 9-15, wherein the at least one processor is further programmed or configured to prompt a user for a single authentication for the plurality of transactions.
- a computer program product for aggregated authentication in an online, open loop payment network comprising at least one non-transitory computer- readable medium including program instructions that, when executed by at least one processor, cause the at least one processor to: receive, from a merchant system, a single authentication request message to conduct a plurality of transactions with a plurality of merchants, the single authentication request message comprising an aggregation identifier, a plurality of merchant identifiers, and transaction data for each transaction of the plurality of transactions; detect the aggregation identifier in the single authentication request message; in response to detecting the aggregation identifier, generate a single authentication response message comprising a plurality of authentication codes, each authentication code of the plurality of authentication codes corresponding to a merchant of the plurality of merchants; and communicate the single authentication response message to the merchant system, the single authentication response message configured to cause the merchant system to separately process each transaction of the plurality of transactions.
- a computer-implemented method for aggregated authentication in an online, open loop payment network comprising an issuer authentication system, a merchant system, a client device, and a transaction service provider system, comprising: receiving, by the merchant system from the client device, a transaction request to conduct a plurality of transactions with a plurality of merchants; generating, by the merchant system, a single authentication request message based on the transaction request, the single authentication request message comprising an aggregation identifier, a plurality of merchant identifiers corresponding to the plurality of merchants, and transaction data for each transaction of the plurality of transactions; communicating, to the issuer authentication system, the single authentication request message; receiving, by the merchant system from the issuer authentication system in response to the single authentication request message, a single authentication response message comprising a plurality of authentication codes, each authentication code of the plurality of authentication codes corresponding to a merchant of the plurality of merchants; and in response to receiving a single authorization response from the client device, generating, by the merchant
- Clause 19 The computer-implemented method of clause 18, wherein the merchant system comprises a merchant plug-in configured to communicate with the issuer authentication system and generate the single authentication request message.
- Clause 20 The computer-implemented method of clauses 18 or 19, wherein the merchant plug-in is configured to communicate with the issuer authentication system via at least one Application Programming Interface (API).
- API Application Programming Interface
- Clause 21 The computer-implemented method of any of clauses 18-20, wherein the merchant system is configured to communicate with the issuer authentication system through a payment gateway.
- Clause 22 The computer-implemented method of any of clauses 18-21 , wherein the merchant system is controlled by an aggregator merchant, and wherein the merchant system is in communication with a plurality of other merchant systems associated with the plurality of merchants.
- Clause 23 The computer-implemented method of any of clauses 18-22, further comprising redirecting the client device from the merchant system to the issuer authentication system to prompt a user for the single authorization response.
- a computer-implemented method for aggregated authentication in an online, open loop payment network comprising an issuer authentication system, a merchant system, a client device, and a transaction service provider system, comprising: receiving, by the transaction service provider system from the merchant system, a request to conduct a plurality of transactions with a plurality of merchants, the request comprising account data for a user; identifying, by the transaction service provider system, the issuer authentication system from a plurality of issuer authentication systems based on the account data; in response to identifying the issuer authentication system, communicating, by the transaction service provider system to the issuer authentication system, an identifier of the issuer authentication system; receiving, by the transaction service provider system from the merchant system, a plurality of authorization requests, each authorization request of the plurality of authorization requests corresponding to a transaction of the plurality of transactions; and separately processing each authorization request of the plurality of authorization requests.
- Clause 25 The computer-implemented method of clause 24, further comprising verifying, by the transaction service provider system, that an account identified in the account data is enrolled for secure authentication.
- Clause 26 The computer-implemented method of clauses 24 or 25, wherein the identifier of the issuer authentication system comprises a Uniform Resource Locator (URL) configured to redirect the client device from the merchant system to the issuer authentication system.
- URL Uniform Resource Locator
- FIG. 1 is a schematic diagram of a system for aggregated authentication according to some non-limiting embodiments or aspects
- FIG. 2 is another schematic diagram of a system for aggregated authentication according to some non-limiting embodiments or aspects
- FIG. 3 is a step diagram of a method for aggregated authentication according to some non-limiting embodiments or aspects
- FIG. 4 is a step diagram of a method for aggregated authentication according to some non-limiting embodiments or aspects;
- FIG. 5 is a step diagram of a method for aggregated authentication according to some non-limiting embodiments or aspects;
- FIG. 6A is an authentication request message according to some nonlimiting embodiments or aspects.
- FIG. 6B is an authentication response message according to some nonlimiting embodiments or aspects.
- the terms“communication” and“communicate” may refer to the reception, receipt, transmission, transfer, provision, and/or the like, of information (e.g., data, signals, messages, instructions, commands, and/or the like).
- information e.g., data, signals, messages, instructions, commands, and/or the like.
- one unit e.g., a device, a system, a component of a device or system, combinations thereof, and/or the like
- This may refer to a direct or indirect connection (e.g., a direct communication connection, an indirect communication connection, and/or the like) that is wired and/or wireless in nature.
- two units may be in communication with each other even though the information transmitted may be modified, processed, relayed, and/or routed between the first and second unit.
- a first unit may be in communication with a second unit even though the first unit passively receives information and does not actively transmit information to the second unit.
- a first unit may be in communication with a second unit if at least one intermediary unit (e.g., a third unit located between the first unit and the second unit) processes information received from the first unit and communicates the processed information to the second unit.
- a message may refer to a network packet (e.g., a data packet and/or the like) that includes data. It will be appreciated that numerous other arrangements are possible.
- transaction service provider may refer to an entity that receives transaction authorization requests from merchants or other entities and provides guarantees of payment, in some cases through an agreement between the transaction service provider and an issuer institution.
- a transaction service provider may include a payment network such as Visa®, MasterCard®, American Express®, or any other entity that processes transactions.
- transaction processing system may refer to one or more computer systems operated by or on behalf of a transaction service provider, such as a transaction processing server executing one or more software applications.
- a transaction processing server may include one or more processors and, in some non-limiting embodiments or aspects, may be operated by or on behalf of a transaction service provider.
- the term“account identifier” may refer to one or more types of identifiers associated with an account (e.g., a unique identifier of an account, an account number, a primary account number (PAN), a card number, a payment card number, a token, and/or the like) of a user.
- an issuer may provide an account identifier to a user that uniquely identifies one or more accounts associated with that user.
- an account identifier may be embodied on a physical financial instrument (e.g., a portable financial device, a payment card, a credit card, a debit card, and/or the like) and/or may be electronic information communicated to the user that the user may use for electronic payment transactions.
- a physical financial instrument e.g., a portable financial device, a payment card, a credit card, a debit card, and/or the like
- an account identifier may be an original account identifier, where the original account identifier was provided to a user at the creation of the account associated with the account identifier.
- the account identifier may be an account identifier (e.g., a supplemental account identifier) that is provided to a user after the original account identifier was provided to the user.
- an account identifier may be directly or indirectly associated with an issuer such that an account identifier may be a token that maps to a PAN or other type of identifier.
- Account identifiers may be alphanumeric, any combination of characters and/or symbols, and/or the like.
- issuer institution may refer to one or more entities, such as a bank, that provide accounts to users for conducting transactions (e.g., payment transactions), such as initiating credit and/or debit payments.
- an issuer institution may provide an account identifier, such as a PAN, to a user that uniquely identifies one or more accounts associated with that user.
- the account identifier may be embodied on a portable financial device, such as a physical financial instrument, e.g., a payment card, and/or may be electronic and used for electronic payments.
- issuer system refers to one or more computer systems, computing devices, software applications, and/or the like operated by or on behalf of an issuer institution, such as a server computer executing one or more software applications.
- an issuer system may include one or more authorization servers for authorizing a transaction, one or more authentication servers for authenticating a transaction, and/or one or more databases of account data.
- An issuer system may include a separate or integrated issuer authentication system, such as an Access Control Server (ACS), for authenticating online transactions.
- ACS Access Control Server
- An issuer institution may be associated with a bank identification number (BIN) or other unique identifier that uniquely identifies it among other issuer institutions.
- BIN bank identification number
- the term“acquirer institution” may refer to an entity licensed and/or approved by the transaction service provider to originate transactions (e.g., payment transactions) using a portable financial device associated with the transaction service provider.
- the transactions the acquirer institution may originate may include payment transactions (e.g., purchases, original credit transactions (OCTs), account funding transactions (AFTs), and/or the like).
- an acquirer institution may be a financial institution, such as a bank.
- the term “acquirer system” may refer to one or more computer systems, computing devices, software applications, and/or the like operated by or on behalf of an acquirer institution.
- the term“merchant” may refer to an individual or entity that provides goods and/or services, or access to goods and/or services, to users (e.g., users) based on a transaction (e.g., a payment transaction).
- the term“merchant system” may refer to one or more computer systems, computing devices, and/or software applications operated by or on behalf of a merchant, such as a server computer executing one or more software applications.
- a “point-of-sale (POS) system,” as used herein, may refer to one or more computers and/or peripheral devices used by a merchant to engage in payment transactions with users, including one or more card readers, near-field communication (NFC) receivers, RFID receivers, and/or other contactless transceivers or receivers, contact-based receivers, payment terminals, computers, servers, input devices, and/or other like devices that can be used to initiate a payment transaction.
- a POS system may be part of a merchant system.
- a merchant system may also include a merchant plug-in for facilitating online, Internet-based transactions through a merchant webpage or software application.
- a merchant plug-in may include software that runs on a merchant server or is hosted by a third-party for facilitating such online transactions.
- the term“computing device” may refer to one or more electronic devices that are configured to directly or indirectly communicate with or over one or more networks.
- the computing device may be a mobile device.
- a mobile device may include a cellular phone (e.g., a smartphone or standard cellular phone), a portable computer, a wearable device (e.g., watches, glasses, lenses, clothing, and/or the like), a personal digital assistant (PDA), and/or other like devices.
- PDA personal digital assistant
- the computing device may not be a mobile device, such as a desktop computer.
- the term“computer” may refer to any computing device that includes the necessary components to receive, process, and output data, and normally includes a display, a processor, a memory, an input device, and a network interface.
- An“application” or“application program interface” (API) refers to computer code or other data sorted on a computer-readable medium that may be executed by a processor to facilitate the interaction between software components, such as a client- side front-end and/or server-side back-end for receiving data from the client.
- An “interface” refers to a generated display, such as one or more graphical user interfaces (GUIs) with which a user may interact, either directly or indirectly (e.g., through a keyboard, mouse, etc.).
- GUIs graphical user interfaces
- client device refers to any electronic device that is configured to communicate with one or more remote devices or systems, such as a server.
- a client device may include a desktop computer, laptop computer, mobile computer (e.g., smartphone), a wearable computer (e.g., a watch, pair of glasses, lens, clothing, and/or the like), a cellular phone, a network-enabled appliance (e.g., a network-enabled television, refrigerator, thermostat, and/or the like), and/or any other device, system, and/or software application configured to communicate with a remote device or system.
- mobile computer e.g., smartphone
- wearable computer e.g., a watch, pair of glasses, lens, clothing, and/or the like
- a cellular phone e.g., a network-enabled appliance
- any other device, system, and/or software application configured to communicate with a remote device or system.
- an electronic wallet and “electronic wallet application” refer to one or more electronic devices and/or software applications configured to initiate and/or conduct payment transactions.
- an electronic wallet may include a mobile device executing an electronic wallet application and may further include server-side software and/or databases for maintaining and providing transaction data to the mobile device.
- An“electronic wallet provider” may include an entity that provides and/or maintains an electronic wallet for a user, such as Google WalletTM, Android Pay®, Apple Pay®, Samsung Pay®, and/or other like electronic payment systems.
- an issuer bank may be an electronic wallet provider.
- server or“processor” may refer to one or more devices that provide a functionality to one or more devices (e.g., one or more client devices) via a network (e.g., a public network, a private network, the Internet, and/or the like).
- a server may include one or more computing devices.
- system may refer to one or more devices, such as one or more processors, servers, client devices, computing devices that include software applications, and/or the like.
- reference to“a server” or“a processor,” as used herein, may refer to a previously-recited server and/or processor that is recited as performing a previous step or function, a different server and/or processor, and/or a combination of servers and/or processors.
- a first server and/or a first processor that is recited as performing a first step or function may refer to the same or different server and/or a processor recited as performing a second step or function.
- the term“mobile device” may refer to one or more portable electronic devices configured to communicate with one or more networks.
- a mobile device may include a cellular phone (e.g., a smartphone or standard cellular phone), a portable computer (e.g., a tablet computer, a laptop computer, etc.), a wearable device (e.g., a watch, pair of glasses, lens, clothing, and/or the like), a PDA, and/or other like devices.
- client device refers to any electronic device that is configured to communicate with one or more servers or remote devices and/or systems.
- a client device may include a mobile device, a network- enabled appliance (e.g., a network-enabled television, refrigerator, thermostat, and/or the like), a computer, a POS system, and/or any other device or system capable of communicating with a network.
- a network- enabled appliance e.g., a network-enabled television, refrigerator, thermostat, and/or the like
- a computer e.g., a POS system, and/or any other device or system capable of communicating with a network.
- the term“portable financial device” may refer to a payment device, an electronic payment device, a payment card (e.g., a credit or debit card), a gift card, a smartcard, smart media, a payroll card, a healthcare card, a wrist band, a machine-readable medium containing account information, a keychain device or fob, an RFID transponder, a retailer discount or loyalty card, a cellular phone, an electronic wallet mobile application, a personal digital assistant (PDA), a pager, a security card, a computer, an access card, a wireless terminal, a transponder, and/or the like.
- the portable financial device may include volatile or non-volatile memory to store information (e.g., an account identifier, a name of the account holder, and/or the like).
- the term“payment gateway” may refer to an entity and/or a payment processing system operated by or on behalf of such an entity (e.g., a merchant service provider, a payment service provider, a payment facilitator, a payment facilitator that contracts with an acquirer, a payment aggregator, and/or the like), which provides payment services (e.g., transaction service provider payment services, payment processing services, and/or the like) to one or more merchants.
- the payment services may be associated with the use of portable financial devices managed by a transaction service provider.
- the term “payment gateway system” may refer to one or more computer systems, computer devices, servers, groups of servers, and/or the like, operated by or on behalf of a payment gateway.
- authentication refers to a process of proving or verifying the identity of an individual.
- an account holder associated with a portable financial device corresponding to an account number may be asked to authenticate himself or herself, or a separate system or entity may be asked to authenticate the account holder, before a transaction is completed between the account holder’s payment account and another individual or entity, such as a merchant.
- Various authentication methods and protocols may be used to authenticate a user, such as but not limited to the 3-D Secure protocol.
- the 3-D Secure protocol is a three-domain model used for Internet-based transactions that consider an acquirer domain (e.g., an acquirer institution), an issuer domain (e.g., an issuer institution), and an interoperability domain (e.g., the payment network infrastructure).
- An“authentication request message,” as used herein, refers to a message configured to request authentication from a user or system.
- An “authentication response message,” as used herein, refers to a message configured to provide one or more authentication codes that may be used to authenticate an account holder.
- the term“authorization” refers to a process of providing, receiving, and/or obtaining permission.
- an issuer institution that issued a portable financial device to a user may authorize a transaction being requested by the account holder by, for example, determining that the account is valid and that a sufficient amount of funds or credit is available for the transaction.
- An“authorization request message,” as used herein, refers to a message configured to request authorization from an issuer institution, transaction service provider, or other entity.
- An“authorization response message,” as used herein, refers to a message that conveys an authorization response (e.g., authorized or not authorized).
- Non-limiting embodiments of the present disclosure are directed to a system, method, and apparatus for processing a plurality of separate transactions based on a single authentication in an online, open loop payment network.
- Nonlimiting embodiments allow for a merchant system to facilitate payments made from a user or other entity to multiple, separate recipients without requiring multiple authentications.
- Non-limiting embodiments utilize a unique single authentication request message having an aggregation identifier and a specific flow of messages and responses among the nodes of a payment network. This arrangement provides for improved efficiencies of computing resources, such as network bandwidth, memory, and computational power, by reducing the number of authentication messages, by avoiding the need for every node to separately process each transaction, and by only requiring a single authentication from the individual or entity that is providing the payment to the recipients. It will be appreciated that various other efficiencies and benefits are provided with non-limiting embodiments of the disclosure.
- the system 1000 shown in FIG. 1 includes components of an open loop payment network in which a transaction service provider facilitates processing and settlement of transactions between issuer institutions and acquirer institutions.
- a merchant system 106 is in communication with a client device 1 1 1 via a network environment 1 10, such as the Internet.
- the merchant system 106 may be operated by a merchant that acts as an aggregator or marketplace merchant.
- the merchant operating the merchant system 106 may be an online mall or marketplace through which multiple other merchants provide goods and/or services.
- a user operating the client device 1 1 1 may visit a webpage or other graphical user interface (GUI) 1 12 of the merchant system 106 through a web browser or other software application.
- GUI graphical user interface
- the user may select goods and/or services from a plurality of different merchants, add the goods and/or services to an online shopping cart, and check out through the GUI 1 12 or an additional GUI presented by the merchant system 106.
- the merchant system 106 when the user chooses to check out and complete the transactions for the goods and/or services selected through the GUI 1 12 of the merchant system 106, the merchant system 106 generates a single authentication request message and communicates it to the issuer system 104.
- the single authentication request message may be communicated directly to the issuer system 104 or, in other examples, may be communicated to the issuer system 104 indirectly through the transaction service provider system 102, a payment gateway (not shown in FIG. 1 ), or any other system.
- the issuer system 104 may include an issuer authentication system that receives and processes the single authentication request message.
- the authentication request message may be structured in various ways.
- the authentication request messages and authentication response messages may be structured in extensible Markup Language (XML) or any other format or data structure, such as JavaScript Object Notation (JSON), one or more arrays, and/or the like.
- XML extensible Markup Language
- JSON JavaScript Object Notation
- the single authentication request message includes an aggregation identifier that identifies the single authentication request message as an aggregated authentication request message.
- the aggregation identifier may include, for example, one or more flags or other variables inserted into one or more fields of the authentication request message.
- the aggregation identifier may in some non-limiting embodiments be a binary value in which a value of “1” or TRUE identifies the authentication request message as an aggregated authentication request message.
- an aggregation identifier may be a signature, size, or structure of the authentication request message, such as an authentication request message that includes multiple additional fields. It will be appreciated that numerous other arrangements are possible.
- the issuer authentication system 104 processes the message and determines if the message is an aggregated authentication request message based on whether an aggregation identifier is included in the message. In response to determining that the message is an aggregated authentication request message, the issuer system 104 authenticates the user.
- the issuer system 104 may authenticate the user by, for example, prompting the user to input credentials, such as but not limited to a user name, password, biometric input, key, and/or the like.
- the credential may be a one-time key that is communicated to the client device 1 1 1 via a text message.
- the user may be redirected from a merchant website to a website of the issuer system 104, such as a website provided by an issuer ACS.
- a user may be prompted to authenticate himself or herself through an application on the client device 1 1 1 or another client device, such as a mobile phone, based on the issuer system 104 communicating a signal or taking control over some functionality of the client device 1 1 1.
- a user may authenticate himself or herself on the merchant website through an embedded authentication tool, such as input boxes and selectable options provided by the issuer authentication system 105.
- the issuer system 104, transaction service provider system 102, a payment gateway (not shown in FIG. 1 ), an e-wallet application (not shown in FIG. 1 ), and/or any other system may prompt the user for authentication. In this manner, the user only authenticates himself or herself only once for the single aggregated transaction.
- the issuer system 104 determines an authentication code for each merchant of the multiple merchants identified in the single authentication request message. In some non-limiting embodiments or aspects, a separate authentication code will correspond to each separate merchant. The issuer system 104 determines an authentication code by generating it or identifying it from a database. The issuer authentication system 104 then generates a single authentication response message and communicates it to the merchant system 106.
- the authentication codes may include, for example, Universal Cardholder Authentication Field (UCAF) identifiers for each intended recipient that are included in one or more fields of the authentication response message.
- the UCAF identifier may depend upon the payment network and may include, for example, a Cardholder Authentication Verification Value (CAW).
- CAW Cardholder Authentication Verification Value
- the authentication response message may also include Electronic Commerce Indicator (ECI) identifiers for each intended recipient in one or more fields. It will be appreciated that various identifiers and data may be used instead of or in addition to UCAF and ECI identifiers.
- the authentication codes are eventually communicated to an acquirer system for settling transactions.
- the merchant system 106 in response to receiving the single authentication response message with multiple authentication codes, processes the single authentication response message to identify each individual authentication code.
- the merchant system 106 then generates multiple separate authorization request messages, which differ from authentication request messages in structure, content, and/or function, for each individual transaction of the multiple transactions with multiple merchants. In this manner, each authentication code is used to generate each individual authorization request message.
- the individual authorization request messages may include one or more authentication flags or other authentication data to indicate that the transaction was authenticated.
- each authorization request message is processed by the issuer system 104 and, once the issuer system 104 authorizes the transaction, the issuer system 104 returns an authorization response message. If the authorization response message indicates that the transaction is authorized, the transaction service provider system 102 facilitates the payment to be made from the issuer institution corresponding to the issuer system 104 to an acquiring institution corresponding to the individual merchant for that transaction. In this manner, the account holder’s account statement may list each individual transaction individually, even though the account holder only authenticated a single time, making it more efficient to keep records and simpler to dispute erroneous or fraudulent charges with individual merchants.
- the system 1001 includes a merchant system 108, merchant plug-in (MPI) 109, transaction service provider authentication system 103, transaction service provider authentication history system 107, issuer authentication system 105, and payment gateway 1 14.
- the components of the system 1001 may be in communication via one or more network connections.
- the MPI 109 may include software executing on the merchant system 108, such as a web server used by the merchant.
- the transaction service provider authentication system 103 may include one or more processors and/or software applications and may be part of or separate from a transaction service provider system 102 (not shown in FIG. 2).
- the transaction service provider authentication system 103 may include a 3-D Secure service provided by a transaction service provider of a payment network.
- the issuer authentication system 105 may include one or more processors and/or software applications and may be part of or separate from the issuer system 104 (not shown in FIG. 2).
- the transaction service provider authentication system 103 may include an ACS server.
- a user may operate a client device 124 to access a GUI 122, such as a merchant website, and conduct an aggregate transaction with the merchant system 108.
- the client device 124 communicates a request to conduct an aggregated transaction.
- the merchant system 108 communicates transaction data and/or account data to the MPI 109 and, at step (3), the data is communicated to the transaction service provider authentication system 103.
- the 108 may communicate with the transaction service provider authentication system 103 without the use of the MPI 109, utilizing an Application Programming Interface (API) or other technique.
- API Application Programming Interface
- a Representational State Transfer (REST) API (e.g., RESTful API) may be utilized.
- the transaction service provider authentication system 103 in response to receiving at least account data from the merchant system 108, determines if the account holder is enrolled in a service that permits usage of the transaction service provider authentication system 103. Once the transaction service provider authentication system 103 verifies that the account holder is enrolled, the transaction service provider authentication system 103 communicates a verification message to the MPI 109 at step (4).
- the verification message may include, for example, a Uniform Resource Locator (“URL”) pointing to the issuer authentication system 105.
- the MPI 109 passes the verification message to the merchant system 108.
- the merchant system 108 or MPI 109 generates a single authentication request message in response to receiving the verification message.
- the merchant system 108 communicates the single authentication request message to the issuer authentication system 105.
- the single authentication request message may be communicated to the issuer authentication system 105 via the payment gateway 1 14.
- the issuer authentication system 105 processes the authentication request message to determine whether the transaction is an aggregated transaction by, for example, identifying an aggregation identifier.
- the issuer authentication system 105 authenticates the user.
- the issuer authentication system 105 may authenticate the user by, for example, prompting the user to input credentials, such as but not limited to a user name, password, biometric input, key, and/or the like.
- the user may be redirected from a merchant website to a website of the issuer authentication system 105, such as a website provided by an issuer ACS server, based on the URL returned from the transaction service provider authentication system 103 at step (4).
- a user may be prompted to authenticate himself or herself through an application on the client device 124 or another client device, such as a mobile phone.
- a user may authenticate himself or herself on the merchant website through an embedded authentication tool, such as input boxes and selectable options provided by the issuer authentication system 105.
- an embedded authentication tool such as input boxes and selectable options provided by the issuer authentication system 105.
- the issuer authentication system 105, transaction service provider authentication system 103, payment gateway 1 14, an e-wallet application (not shown in FIG. 2), and/or any other system may prompt the user for authentication. In this manner, the user only authenticates himself or herself only once for the single aggregated transaction. It will be appreciated that authentication may be provided in various other ways.
- the issuer authentication system 105 in response to authenticating the user, identifies each merchant of multiple merchants identified in the message and, for each merchant or individual transaction, determines an authentication code.
- the issuer authentication system 105 generates an authentication response message based on the identified merchants and the authentication codes and, at step (7), communicates the authentication response message to the merchant system 108.
- the merchant system 108 communicates the authentication response message to the MPI 109 at step (8).
- the MPI 109 in response to receiving the authentication response message, determines whether the transaction is authenticated. This may include, for example, processing each of the authentication codes in the authentication response message and/or prompting a user for input through the client device 124.
- the MPI 109 at step (9), communicates the authentication result and any associated authentication data to the merchant system.
- the transaction data for each individual transaction is sent to a payment gateway 1 14, acquirer system (not shown in FIG. 2), or any other entity for processing the individual transactions.
- the merchant system 108 may generate multiple authorization request messages and communicate the messages to the payment gateway 1 14.
- FIG. 3 a step diagram for a method for aggregated authentication is shown according to some non-limiting embodiments or aspects.
- the step diagram in FIG. 3 is shown from the perspective of an issuer authentication system, although it will be appreciated that one or more other systems may perform one or more steps in one or more orders.
- the issuer authentication system receives a single authentication request message from a merchant system.
- the issuer authentication system may receive the authentication request message as it would receive any authentication request message from a merchant system.
- the issuer authentication system determines if the authentication request message is an aggregated authentication request message.
- the issuer authentication system may make this determination based on an aggregation identifier in the message, as an example. If the authentication request message is an aggregated authentication request message, the method proceeds to step 304 in which the issuer authentication system prompts the user for authentication. The user may be prompted for authentication through a client device. In some non-limiting embodiments or aspects, the issuer authentication system may prompt the user for authentication after the client device operated by the user is pointed to the issuer authentication system from the merchant system through, for example, a redirection URL or other mechanism.
- the issuer authentication system determines if the user is authenticated. As an example, the issuer authentication system may compare user credentials (e.g., user name, password, key, user identifier, device identifier, etc.) with stored user credentials. If the user is not authenticated, the method ends and returns to step 300 to receive a next authentication request message. If the user is authenticated, the method proceeds to step 308 and the issuer authentication system determines authentication codes for each individual transaction and/or merchant identified in the aggregated message. If the authentication request message is not an aggregated authentication request message, then the issuer authentication system determines a single authentication code for the single requested transaction. The authentication codes may be generated or identified from a database, as examples. The issuer authentication system, at step 310, generates a single authentication response message including each authentication code determined at step 308. The single authentication response message is communicated to the merchant system at step 312.
- user credentials e.g., user name, password, key, user identifier, device identifier, etc.
- a step diagram for a method for aggregated authentication is shown according to some non-limiting embodiments or aspects.
- the step diagram in FIG. 4 is shown from the perspective of a merchant system, which may include an MPI, although it will be appreciated that one or more other systems may perform one or more steps in one or more orders.
- the merchant system receives a transaction request from a user to conduct a plurality of transactions with a plurality of merchants.
- the transaction request may be received through a merchant website or software application accessed by a client device.
- the merchant system generates a single authentication request message including an aggregation identifier, merchant identifiers for each individual merchant, and other transaction data.
- the merchant system communicates the single authentication request message to an applicable issuer authentication system.
- the merchant system redirects the client device to the issuer authentication system for the user to be authenticated.
- the issuer authentication system and/or redirection URL may be identified by communicating transaction data and/or account data to the transaction service provider authentication system and receiving such information in response.
- the merchant system receives a single authentication response message, including a plurality of authentication codes, from the issuer authentication system.
- the merchant system generates a separate, individual authorization request message for each individual transaction corresponding to an individual authentication code. These authorization request messages are then processed in any manner, such as by communicating them to a payment gateway, acquirer system, or transaction service provider system for further processing and handling.
- step 500 transaction data and/or account data is received from a merchant system.
- the transaction service provider authentication system determines if the user is enrolled for secure authentication.
- the transaction service provider authentication system may determine if a user is enrolled by querying an enrollment database based on a user identifier, account identifier, BIN, and/or the like. If the user is enrolled at step 502, the method proceeds to step 504 in which the transaction service provider authentication system identifies the issuer authentication system that corresponds to the account data by identifying an issuer institution that issued the account being used for the transaction.
- the transaction service provider authentication system generates a verification message at step 506 including a URL pointing to the issuer authentication system identified at step 504.
- the verification message is communicated to the merchant system such that the merchant system can redirect the client device operated by the user to the issuer authentication system through the URL or other mechanism.
- the transaction service provider receives and processes a plurality of authorization requests for individual transactions at step 510. The individual transactions correspond to the single request received at step 500 and the single verification message generated at step 506.
- an authentication request message 600 is shown according to some non-limiting embodiments or aspects.
- the authentication request message 600 is formatted in an XML format with tags identifying parameters.
- the tag ⁇ transactions> includes multiple individual transactions identified by the tag ⁇ transaction> and, for each ⁇ transaction>, an identifier having an ⁇ id> tag.
- Each ⁇ transaction> tag also includes other transaction data for that transaction, such as a ⁇ merchantlD> tag (merchant identifier), an ⁇ acquiringBin> tag (acquirer institution identifier or BIN), an ⁇ amount> tag (purchase amount), and a ⁇ currency> tag (currency type).
- the ⁇ transactionGrouplD> tag may serve as an aggregation identifier that identifies the authentication request message 600 as an aggregated authentication request message. It will be appreciated that various other parameters and formats may be used for structuring the authentication request message 600.
- an authentication response message 602 is shown according to some non-limiting embodiments or aspects.
- the authentication response message 602 is formatted in an XML format with tags identifying parameters.
- the tag ⁇ transactions> includes multiple individual transactions identified by the tag ⁇ transaction> and, for each ⁇ transaction>, an identifier having an ⁇ id> tag.
- the authentication response message 602 includes authentication codes for each transaction identified by the ⁇ cavv> and ⁇ eci> tags. It will be appreciated that various other parameters and formats may be used for structuring the authentication response message 602.
- an aggregator merchant may operate an online marketplace.
- an aggregator merchant may facilitate a user to pay bills for multiple different utility companies, such as electricity, phone, and water, by using a single authentication to effectuate all of the payments.
- An aggregator merchant may also include an online shopping mall or marketplace in which multiple merchants provide goods and/or services. In this manner, a user only needs to check out a single time through a website or application provided by the aggregator merchant.
- the aggregator merchant authorizes the multiple payments separately on the back-end for settling with different acquirer institutions (e.g., different acquirer institutions associated with different merchants) such that the separate authorizations and entries appear on the user’s credit card or bank statements.
Landscapes
- Business, Economics & Management (AREA)
- Engineering & Computer Science (AREA)
- Accounting & Taxation (AREA)
- Finance (AREA)
- Computer Security & Cryptography (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- General Business, Economics & Management (AREA)
- Strategic Management (AREA)
- Theoretical Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Signal Processing (AREA)
- Development Economics (AREA)
- Economics (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
Abstract
Description
Claims
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201980039942.1A CN112437937B (en) | 2018-06-26 | 2019-06-25 | System, method and device for aggregated authentication |
| SG11202012220XA SG11202012220XA (en) | 2018-06-26 | 2019-06-25 | System, method, and apparatus for aggregated authentication |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US16/018,363 | 2018-06-26 | ||
| US16/018,363 US11483308B2 (en) | 2018-06-26 | 2018-06-26 | System, method, and apparatus for aggregated authentication |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2020005897A1 true WO2020005897A1 (en) | 2020-01-02 |
Family
ID=68982234
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/US2019/038918 Ceased WO2020005897A1 (en) | 2018-06-26 | 2019-06-25 | System, method, and apparatus for aggregated authentication |
Country Status (4)
| Country | Link |
|---|---|
| US (2) | US11483308B2 (en) |
| CN (1) | CN112437937B (en) |
| SG (1) | SG11202012220XA (en) |
| WO (1) | WO2020005897A1 (en) |
Families Citing this family (13)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11139964B1 (en) | 2018-09-07 | 2021-10-05 | Wells Fargo Bank, N.A. | Biometric authenticated biometric enrollment |
| US20210097527A1 (en) * | 2019-10-01 | 2021-04-01 | Shopify Inc. | Methods and systems for account creation |
| JP6910748B1 (en) * | 2020-03-16 | 2021-07-28 | 木戸 啓介 | Password authentication system |
| US11184306B1 (en) * | 2020-12-29 | 2021-11-23 | Square, Inc. | Contextual communication routing methods and systems |
| WO2022192659A1 (en) * | 2021-03-12 | 2022-09-15 | Visa International Service Association | System, method, and computer program product for secure client device and consumer authentication |
| JP2024520523A (en) * | 2021-05-26 | 2024-05-24 | ビザ インターナショナル サービス アソシエーション | SYSTEM, METHOD, AND COMPUTER PROGRAM PRODUCT FOR INTERACCOUNT TRADING NETWORK - Patent application |
| US11924351B1 (en) * | 2023-02-09 | 2024-03-05 | Hong Kong Applied Science and Technology Research Institute Company Limited | Optimizing data transactions and verification on a blockchain network |
| CN117010897B (en) * | 2023-08-02 | 2024-08-09 | 深圳市微云信众技术有限公司 | Mobile payment security detection method and system thereof |
| US12526264B1 (en) | 2023-08-18 | 2026-01-13 | Forward Lending, Inc. | Machine learning based authentication platform |
| US12242599B1 (en) | 2024-09-27 | 2025-03-04 | strongDM, Inc. | Fine-grained security policy enforcement for applications |
| US12348519B1 (en) * | 2025-02-07 | 2025-07-01 | strongDM, Inc. | Evaluating security policies in aggregate |
| US12432242B1 (en) | 2025-03-28 | 2025-09-30 | strongDM, Inc. | Anomaly detection in managed networks |
| US12603921B1 (en) | 2025-11-19 | 2026-04-14 | strongDM, Inc. | Indexing entities and attributes for policy enforcement |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20100243728A1 (en) * | 2009-03-27 | 2010-09-30 | Mark Wiesman | Methods and systems for performing a financial transaction |
| US20120041881A1 (en) * | 2010-08-12 | 2012-02-16 | Gourab Basu | Securing external systems with account token substitution |
| US20130073464A1 (en) * | 2011-09-21 | 2013-03-21 | Visa International Service Association | Systems and methods to communication via a merchant aggregator |
| WO2016081397A1 (en) * | 2014-11-19 | 2016-05-26 | Mastercard International Incorporated | E-commerce based payment system with authentication of electronic invoices |
Family Cites Families (10)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP1271434A1 (en) * | 2001-06-11 | 2003-01-02 | CMG Finance B.V. | Method and system for payment |
| US20040024698A1 (en) | 2002-08-02 | 2004-02-05 | William Hines | Method of facilitating charitable contributions using a credit card |
| US20100063926A1 (en) | 2008-09-09 | 2010-03-11 | Damon Charles Hougland | Payment application framework |
| AU2016202045A1 (en) * | 2011-09-25 | 2016-04-28 | Theranos Ip Company, Llc | Systems and methods for multi-analysis |
| US20140279474A1 (en) * | 2013-03-12 | 2014-09-18 | Visa International Service Association | Multi-purse one card transaction apparatuses, methods and systems |
| US20160155117A1 (en) * | 2013-07-31 | 2016-06-02 | Visa International Service Association | Enabling payments to be processed by only one merchant |
| US10346816B2 (en) * | 2014-07-11 | 2019-07-09 | Mastercard International Incorporated | Systems and methods for aggregating consumer-specific transactions associated with a social venture |
| CN107111810A (en) * | 2014-10-13 | 2017-08-29 | 万事达卡国际股份有限公司 | Method and system for direct operator's charging |
| US11107068B2 (en) * | 2017-08-31 | 2021-08-31 | Bank Of America Corporation | Inline authorization structuring for activity data transmission |
| US11080697B2 (en) * | 2017-10-05 | 2021-08-03 | Mastercard International Incorporated | Systems and methods for use in authenticating users in connection with network transactions |
-
2018
- 2018-06-26 US US16/018,363 patent/US11483308B2/en active Active
-
2019
- 2019-06-25 WO PCT/US2019/038918 patent/WO2020005897A1/en not_active Ceased
- 2019-06-25 CN CN201980039942.1A patent/CN112437937B/en active Active
- 2019-06-25 SG SG11202012220XA patent/SG11202012220XA/en unknown
-
2022
- 2022-09-19 US US17/947,555 patent/US12095760B2/en active Active
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20100243728A1 (en) * | 2009-03-27 | 2010-09-30 | Mark Wiesman | Methods and systems for performing a financial transaction |
| US20120041881A1 (en) * | 2010-08-12 | 2012-02-16 | Gourab Basu | Securing external systems with account token substitution |
| US20130073464A1 (en) * | 2011-09-21 | 2013-03-21 | Visa International Service Association | Systems and methods to communication via a merchant aggregator |
| WO2016081397A1 (en) * | 2014-11-19 | 2016-05-26 | Mastercard International Incorporated | E-commerce based payment system with authentication of electronic invoices |
Also Published As
| Publication number | Publication date |
|---|---|
| US20190394192A1 (en) | 2019-12-26 |
| CN112437937B (en) | 2024-06-11 |
| US12095760B2 (en) | 2024-09-17 |
| CN112437937A (en) | 2021-03-02 |
| SG11202012220XA (en) | 2021-01-28 |
| US11483308B2 (en) | 2022-10-25 |
| US20230012289A1 (en) | 2023-01-12 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12095760B2 (en) | System, method, and apparatus for aggregated authentication | |
| US12475456B2 (en) | Secure authentication system with token service | |
| US12120117B2 (en) | Method and system for token provisioning and processing | |
| US12137088B2 (en) | Browser integration with cryptogram | |
| US10909539B2 (en) | Enhancements to transaction processing in a secure environment using a merchant computer | |
| US10878420B2 (en) | System, method, and computer program product for authorizing a transaction | |
| US20180158052A1 (en) | Asynchronous cryptogram-based authentication processes | |
| US20220156742A1 (en) | System and method for authorizing a transaction | |
| EP3857486B1 (en) | System, method, and computer program product for secure, remote transaction authentication and settlement | |
| US12602685B2 (en) | Systems and methods for token-based device binding during merchant checkout | |
| US11343238B2 (en) | System, method, and apparatus for verifying a user identity | |
| US11790356B2 (en) | System, method, and computer program product for dynamic passcode communication | |
| US12314918B2 (en) | System, method, and computer program product for processing a transaction as a push payment transaction | |
| US20250182104A1 (en) | System, Method, and Computer Program Product for Secure Data Distribution | |
| US20240144258A1 (en) | System, Method, and Computer Program Product for Secure Client Device and Consumer Authentication | |
| Witkowski et al. | Method, System, and Computer program product for transaction authentication |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 19826535 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 19826535 Country of ref document: EP Kind code of ref document: A1 |
|
| WWG | Wipo information: grant in national office |
Ref document number: 202147000633 Country of ref document: IN |
|
| WWG | Wipo information: grant in national office |
Ref document number: 11202012220X Country of ref document: SG |
|
| WWP | Wipo information: published in national office |
Ref document number: 11202012220X Country of ref document: SG |