WO2020101654A1 - System, method, and computer program product for conducting secure online payment transactions - Google Patents
System, method, and computer program product for conducting secure online payment transactions Download PDFInfo
- Publication number
- WO2020101654A1 WO2020101654A1 PCT/US2018/060734 US2018060734W WO2020101654A1 WO 2020101654 A1 WO2020101654 A1 WO 2020101654A1 US 2018060734 W US2018060734 W US 2018060734W WO 2020101654 A1 WO2020101654 A1 WO 2020101654A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- account
- user
- payment
- payment transaction
- data associated
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/08—Payment architectures
- G06Q20/10—Payment architectures specially adapted for electronic funds transfer [EFT] systems; specially adapted for home banking systems
- G06Q20/105—Payment architectures specially adapted for electronic funds transfer [EFT] systems; specially adapted for home banking systems involving programming of a portable memory device, e.g. IC cards, "electronic purses"
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/327—Short range or proximity payments by means of M-devices
- G06Q20/3278—RFID or NFC payments by means of M-devices
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/352—Contactless payments by cards
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/354—Card activation or deactivation
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3821—Electronic credentials
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3823—Payment protocols; Details thereof insuring higher security of transaction combining multiple encryption tools for a transaction
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/401—Transaction verification
Definitions
- This disclosure relates generally to systems, devices, products, apparatus, and methods that are used for conducting online payment transactions, in one particular embodiment, to a system, product, and method for conducting secure online payment transactions using an integrated circuit card (ICC).
- ICC integrated circuit card
- An integrated circuit card (ICC) (e.g., a smart card, a chip card, and/or the like), may include a pocket-sized card that has embedded integrated circuits.
- An ICC may include a pattern of metal contacts to electrically connect to an internal chip, and the metal contacts may be used to communicate information based on physical contact.
- an ICC may be contactless, such that the ICC may include a radio frequency identification (RFID) chip.
- RFID radio frequency identification
- An ICC may be used to communicate personal identification, authentication, data storage, and application processing.
- An ICC that is contactless may communicate with and is powered by a reader through RF induction technology.
- An ICC that is contactless may be required to be in proximity to a reader to communicate.
- an ICC does not have an internal power source.
- the ICC may use an inductor to capture an incident RF interrogation signal from a reader, rectify the incident RF interrogation signal, and use the incident RF interrogation signal to power the internal chip of the ICC.
- card information e.g., a primary account number (PAN) of an account
- PAN primary account number
- the merchant involved in the online payment transaction may receive the PAN from a user device associated with a user after the user inputs the PAN to a website of the merchant via the user device.
- the merchant may not secure the PAN via tokenization or other techniques, and the PAN may be intercepted by another party.
- the merchant may have a system that secures the PAN, however, rogue software and/or individuals may intercept the PAN before the merchant secures the PAN.
- a computer-implemented method for conducting a secure online payment transaction using an ICC comprises receiving, with at least one processor, an initiate signal for an online payment transaction from an ICC having a piezoelectric device and a transceiver via a near-field communication (NFC) connection, based on the piezoelectric device providing power to the transceiver; receiving, with at least one processor, a payment transaction message from the ICC via the NFC connection, the payment transaction message comprising payment account data associated with an account of a user that is encrypted by the ICC; determining, with at least one processor, whether the payment account data associated with the account of the user is encrypted; displaying, with at least one processor, an indication that the payment account data associated with the account of the user is encrypted; and communicating, with at least one processor, the payment transaction message based on determining that the payment account data associated with the account of the user is encrypted.
- NFC near-field communication
- a system for conducting a secure online payment transaction using an ICC comprises a computing device having at least one processor, wherein the at least one processor is programmed or configured to: receive an initiate signal for an online payment transaction from an ICC via a near-field communication (NFC) connection, based on a piezoelectric device of the ICC providing power to a transceiver of the ICC; receive a payment transaction message from the ICC via the NFC connection, the payment transaction message comprising payment account data associated with an account of a user that is encrypted by the ICC; determine whether the payment account data associated with the account of the user is encrypted; display an indication that the payment account data associated with the account of the user is encrypted; and communicate the payment transaction message based on determining that the payment account data associated with the account of the user is encrypted.
- NFC near-field communication
- a computer program product for conducting a secure online payment transaction using an ICC.
- the computer program product comprises at least one non-transitory computer- readable medium including one or more instructions that, when executed by at least one processor, cause the at least one processor to receive an initiate signal for an online payment transaction from an ICC via a near-field communication (NFC) connection, based on a piezoelectric device of the ICC providing power to a transceiver of the ICC; receive a payment transaction message from the ICC via the NFC connection, the payment transaction message comprising payment account data associated with an account of a user that is encrypted by the ICC; determine that the payment account data associated with the account of the user is encrypted; and communicate the payment transaction message based on determining that the payment account data associated with the account of the user is encrypted.
- NFC near-field communication
- a computer-implemented method for conducting a secure online payment transaction using an ICC comprising: receiving, with at least one processor, an initiate signal for an online payment transaction from an ICC having a piezoelectric device and a transceiver via a near-field communication (NFC) connection, based on the piezoelectric device providing power to the transceiver; receiving, with at least one processor, a payment transaction message from the ICC via the NFC connection, the payment transaction message comprising payment account data associated with an account of a user that is encrypted by the ICC; determining, with at least one processor, whether the payment account data associated with the account of the user is encrypted; displaying, with at least one processor, an indication that the payment account data associated with the account of the user is encrypted; and communicating, with at least one processor, the payment transaction message based on determining that the payment account data associated with the account of the user is encrypted.
- NFC near-field communication
- Clause 2 The computer-implemented method of clause 1 , wherein receiving the initiate signal from the ICC comprises: receiving the initiate signal from the ICC, wherein the initiate signal is a signal based on an ISO/IEC 14443 standard.
- Clause 3 The computer-implemented method of clauses 1 or 2, further comprising: verifying an identity of the user based on account identity data associated with an identity of the user included in the payment account data associated with the account of the user, wherein determining whether the payment account data associated with the account of the user is encrypted comprises: determining whether the payment account data associated with the account of the user is encrypted based on verifying the identity of the user.
- Clause 4 The computer-implemented method of any of clauses 1-3, further comprising: communicating transaction amount data associated with a transaction amount of the online payment transaction to the ICC, and wherein receiving the payment transaction message that comprises the payment account data associated with the account of the user comprises: receiving the payment transaction message after communicating the transaction amount data associated with the transaction amount of the online payment transaction, wherein the payment account data associated with the account of the user comprises: a payment account identifier of the account of the user that has been encrypted with an issuer encryption key; and a payment account identifier of the account of the user that has been encrypted with a transaction service provider encryption key.
- Clause 5 The computer-implemented method of any of clauses 1-4, wherein communicating the payment transaction message comprises: communicating the payment transaction message to a merchant system associated with the merchant involved in the online payment transaction.
- Clause 6 The computer-implemented method of any of clauses 1-5, further comprising: displaying a webpage associated with the merchant involved in the online payment transaction, wherein communicating the payment transaction message comprises: communicating the payment transaction message to a web server serving the webpage associated with the merchant involved in the online payment transaction.
- Clause 7 The computer-implemented method of any of clauses 1-6, wherein receiving the payment transaction message from the ICC comprises: receiving the payment transaction message based on a Europay, Mastercard, Visa (EMV) contactless communication protocol.
- EMV Europay, Mastercard, Visa
- a system for conducting a secure online payment transaction using an integrated circuit card comprising: a computing device having at least one processor, wherein the at least on processor is programmed or configured to: receive an initiate signal for an online payment transaction from an ICC via a nearfield communication (NFC) connection, based on a piezoelectric device of the ICC providing power to a transceiver of the ICC; receive a payment transaction message from the ICC via the NFC connection, the payment transaction message comprising payment account data associated with an account of a user that is encrypted by the ICC; determine whether the payment account data associated with the account of the user is encrypted; display an indication that the payment account data associated with the account of the user is encrypted; and communicate the payment transaction message based on determining that the payment account data associated with the account of the user is encrypted.
- NFC nearfield communication
- Clause 9 The system of clause 8, wherein, when receiving the initiate signal from the ICC, the at least one processor is programmed or configured to: receive the initiate signal from the ICC, wherein the initiate signal is a signal based on an ISO/IEC 14443 standard.
- Clause 10 The system of clauses 8 or 9, wherein the at least one processor is further programmed or configured to: verify an identity of the user based on account identity data associated with an identity of the user included in the payment account data associated with the account of the user; and wherein, when determining whether the payment account data associated with the account of the user is encrypted, the at least one processor is programmed or configured to: determine whether the payment account data associated with the account of the user is encrypted based on verifying the identity of the user.
- Clause 1 1 The system of any of clauses 8-10, wherein the at least one processor is further programmed or configured to: communicate transaction amount data associated with a transaction amount of the online payment transaction to the ICC; and wherein, when receiving the payment transaction message that comprises the payment account data associated with the account of the user, the at least one processor is programmed or configured to: receive the payment transaction message after communicating the transaction amount data associated with the transaction amount of the online payment transaction, wherein the payment account data associated with the account of the user comprises: a payment account identifier of the account of the user that has been encrypted with an issuer encryption key; and a payment account identifier of the account of the user that has been encrypted with a transaction service provider encryption key.
- Clause 12 The system of any of clauses 8-11 , wherein, when communicating the payment transaction message, the at least one processor is programmed or configured to: communicate the payment transaction message to a merchant system associated with the merchant involved in the online payment transaction.
- Clause 13 The system of any of clauses 8-12, wherein the at least one processor is further programmed or configured to: display a webpage associated with the merchant involved in the online payment transaction; and wherein, when communicating the payment transaction message, the at least one processor is programmed or configured to: communicate the payment transaction message to a web server serving the webpage associated with the merchant involved in the online payment transaction.
- Clause 14 The system of any of clauses 8-13, wherein, when receiving the payment transaction message from the ICC, the at least one processor is programmed or configured to: receive the payment transaction message based on a Europay, Mastercard, Visa (EMV) contactless communication protocol.
- EMV Europay, Mastercard, Visa
- NFC near-field communication
- Clause 16 The computer program product of clause 15, wherein the one or more instructions further cause the at least one processor to: verify an identity of the user based on account identity data associated with an identity of the user included in the payment account data associated with the account of the user; and wherein, when determining whether the payment account data associated with the account of the user is encrypted, the at least one processor is programmed or configured to: determine whether the payment account data associated with the account of the user is encrypted based on verifying the identity of the user.
- Clause 17 The computer program product of clauses 15 or 16, wherein the one or more instructions further cause the at least one processor to: communicate transaction amount data associated with a transaction amount of the online payment transaction to the ICC; and wherein, the one or more instructions that cause the at least one processor to receive the payment transaction message, cause the at least one processor to: receive the payment transaction message after communicating the transaction amount data associated with the transaction amount of the online payment transaction, wherein the payment account data associated with the account of the user comprises: a payment account identifier of the account of the user that has been encrypted with an issuer encryption key; and a payment account identifier of the account of the user that has been encrypted with a transaction service provider encryption key.
- Clause 18 The computer program product of any of clauses 15-17, wherein, the one or more instructions that cause the at least one processor to communicate the payment transaction message, cause the at least one processor to: communicate the payment transaction message to a merchant system associated with the merchant involved in the online payment transaction.
- Clause 19 The computer program product of any of clauses 15-18, wherein the one or more instructions further cause the at least one processor to: display a webpage associated with the merchant involved in the online payment transaction; and wherein, when communicating the payment transaction message, the at least one processor is programmed or configured to: communicate the payment transaction message to a web server serving the webpage associated with the merchant involved in the online payment transaction.
- Clause 20 The computer program product of any of clauses 15-19, wherein, the one or more instructions that cause the at least one processor to receive the payment transaction message from the ICC, cause the at least one processor to: receive the payment transaction message based on a Europay, Mastercard, Visa (EMV) contactless communication protocol.
- EMV Europay, Mastercard, Visa
- FIG. 1 is a diagram of a non-limiting embodiment of an environment in which systems, devices, products, apparatus, and/or methods, described herein, may be implemented according to the principles of the present disclosure
- FIG. 2 is a diagram of a non-limiting embodiment of components of one or more devices of FIG. 1 ;
- FIG. 3 is a flowchart of a non-limiting embodiment of a process for conducting a secure online payment transaction.
- FIGS. 4A-4D are diagrams of an implementation of a non-limiting embodiment of the process shown in FIG. 3.
- the terms“communication” and“communicate” may refer to the reception, receipt, transmission, transfer, provision, and/or the like of information (e.g., data, signals, messages, instructions, commands, and/or the like).
- one unit e.g., a device, a system, a component of a device or system, combinations thereof, and/or the like
- to be in communication with another unit means that the one unit is able to directly or indirectly receive information from and/or transmit information to the other unit. This may refer to a direct or indirect connection that is wired and/or wireless in nature.
- two units may be in communication with each other even though the information transmitted may be modified, processed, relayed, and/or routed between the first and second unit.
- a first unit may be in communication with a second unit even though the first unit passively receives information and does not actively transmit information to the second unit.
- a first unit may be in communication with a second unit if at least one intermediary unit (e.g., a third unit located between the first unit and the second unit) processes information received from the first unit and communicates the processed information to the second unit.
- a message may refer to a network packet (e.g., a data packet and/or the like) that includes data. It will be appreciated that numerous other arrangements are possible.
- issuer institution may refer to one or more entities that provide one or more accounts to a user (e.g., customer, consumer, and/or the like) for conducting transactions (e.g., payment transactions), such as initiating credit card payment transactions and/or debit card payment transactions.
- a user e.g., customer, consumer, and/or the like
- an issuer institution may provide an account identifier, such as a primary account number (PAN), to a user that uniquely identifies one or more accounts associated with that user.
- PAN primary account number
- the account identifier may be embodied on a payment device, such as a physical financial instrument (e.g., a payment card), and/or may be electronic and used for electronic payment transactions.
- an issuer institution may be associated with a bank identification number (BIN) that uniquely identifies the issuer institution.
- issuer system may refer to one or more computer systems operated by or on behalf of an issuer institution, such as a server computer executing one or more software applications.
- an issuer system may include one or more authorization servers for authorizing a payment transaction.
- the term“account identifier” may refer to one or more types of identifiers associated with a user account (e.g., an account identifier, a PAN, a card number, a payment card number, a token, and/or the like).
- an issuer institution may provide an account identifier (e.g., a PAN, a token, and/or the like) to a user that uniquely identifies one or more accounts associated with that user.
- the account identifier may be embodied on a physical financial instrument (e.g., a payment device, a payment card, a credit card, a debit card, and/or the like) and/or may be electronic information communicated to the user that the user may use for electronic payment transactions.
- the account identifier may be an original account identifier, where the original account identifier was provided to a user at the creation of the account associated with the account identifier.
- the account identifier may be an account identifier (e.g., a supplemental account identifier) that is provided to a user after the original account identifier was provided to the user.
- an account identifier may be directly or indirectly associated with an issuer institution such that an account identifier may be a token that maps to a PAN or other type of identifier.
- Account identifiers may be alphanumeric, any combination of characters and/or symbols, and/or the like.
- the term“token” may refer to an identifier that is used as a substitute or replacement identifier for an account identifier, such as a PAN.
- a token may be used as a substitute or replacement identifier for an original account identifier, such as a PAN.
- Tokens may be associated with a PAN or other original account identifier in one or more data structures (e.g., one or more databases and/or the like) such that they may be used to conduct a transaction without directly using the original account identifier.
- an original account identifier such as a PAN, may be associated with a plurality of tokens for different individuals or purposes.
- tokens may be associated with a PAN or other account identifiers in one or more data structures such that they can be used to conduct a transaction without directly using the account identifier, such as a PAN.
- an account identifier such as a PAN, may be associated with a plurality of tokens for different uses or different purposes.
- the term“merchant” may refer to one or more entities (e.g., operators of retail businesses) that provide goods and/or services, and/or access to goods and/or services, to a user based on a transaction, such as a payment transaction.
- “merchant system” may refer to one or more computer systems operated by or on behalf of a merchant, such as a server executing one or more software applications.
- the term“product” may refer to one or more goods and/or services offered by a merchant.
- a“point-of-sale (POS) device” may refer to one or more devices, which may be used by a merchant to conduct a transaction (e.g., a payment transaction) and/or process a transaction.
- a POS device may include one or more computers, peripheral devices, card readers, near-field communication (NFC) receivers, radio frequency identification (RFID) receivers, and/or other contactless transceivers or receivers, contact-based receivers, payment terminals, computers, servers, input devices, and/or the like.
- NFC near-field communication
- RFID radio frequency identification
- a“POS system” may refer to one or more computers and/or peripheral devices used by a merchant to conduct a transaction.
- a POS system may include one or more POS devices, and/or other like devices that may be used to conduct a payment transaction.
- a POS system e.g., a merchant POS system
- transaction service provider may refer to an entity that receives transaction authorization requests from merchants or other entities and provides guarantees of payment, in some cases through an agreement between the transaction service provider and an issuer institution.
- a transaction service provider may include a payment network, such as Visa®, MasterCard®, American Express®, or any other entity that processes transactions.
- transaction service provider system may refer to one or more computer systems operated by or on behalf of a transaction service provider, such as a transaction service provider system executing one or more software applications.
- a transaction service provider system may include one or more processors and, in some non-limiting embodiments, may be operated by or on behalf of a transaction service provider.
- client and“client device” may refer to one or more computing devices, such as processors, storage devices, and/or similar computer components, that access a service made available by a server.
- a“client device” may refer to one or more devices that facilitate payment transactions, such as POS devices and/or POS systems used by a merchant.
- a client device may be any electronic device configured to communicate with one or more networks and/or initiate or facilitate transactions such as, but not limited to, one or more computers, portable computers (e.g., tablet computers), mobile devices (e.g., cellular phones, smartphones, wearable devices, such as watches, glasses, lenses, and/or clothing, PDAs, and/or the like), and/or other like devices.
- portable computers e.g., tablet computers
- mobile devices e.g., cellular phones, smartphones, wearable devices, such as watches, glasses, lenses, and/or clothing, PDAs, and/or the like
- a“client” may also refer to an entity, such as a merchant, that owns, utilizes, and/or operates a client device for initiating transactions with a transaction service provider.
- the term“server” may refer to one or more computing devices, such as processors, storage devices, and/or similar computer components, that communicate with client devices and/or other computing devices over a network, such as the Internet or private networks, and, in some examples, facilitate communication among other servers and/or client devices. It will be appreciated that various other arrangements are possible.
- the term“system” may refer to one or more computing devices or combinations of computing devices such as, but not limited to, processors, servers, client devices, software applications, and/or other like components.
- references to“a server” or“a processor,” as used herein, may refer to a previously-recited server and/or processor that is recited as performing a previous step or function, a different server and/or processor, and/or a combination of servers and/or processors.
- a first server and/or a first processor that is recited as performing a first step or function may refer to the same or different server and/or a processor recited as performing a second step or function.
- Non-limiting embodiments of the present disclosure are directed to systems, methods, and computer program products for conducting a secure online payment transaction using an integrated circuit card (ICC).
- ICC integrated circuit card
- a method may include receiving an initiate signal for an online payment transaction from an ICC having a piezoelectric device and a transceiver via a near-field communication (NFC) connection, based on the piezoelectric device providing power to the transceiver, receiving a payment transaction message from the ICC via the NFC connection, the payment transaction message comprising payment account data associated with an account of a user that is encrypted by the ICC, determining that the payment account data associated with the account of the user is encrypted, and communicating the payment transaction message based on determining that the payment account data associated with the account of the user is encrypted.
- NFC near-field communication
- embodiments of the present disclosure may allow payment account data associated with an account of a user to be secured by a merchant involved in the online payment transaction based on the ICC encrypting the payment account data associated with the account of the user before the merchant receives the payment account data.
- FIG. 1 is a diagram of an example environment 100 in which devices, systems, and/or methods, described herein, may be implemented.
- environment 100 includes user device 102, integrated circuit card (ICC) 104, issuer system 106, transaction service provider system 108, merchant system 1 10, and network 112.
- User device 102, integrated circuit card (ICC) 104, issuer system 106, transaction service provider system 108, and/or merchant system 110 may interconnect (e.g., establish a connection to communicate) via wired connections, wireless connections, or a combination of wired and wireless connections.
- ICC integrated circuit card
- User device 102 may include one or more devices capable of receiving information from and/or communicating information to issuer system 106, transaction service provider system 108, and/or merchant system 1 10 via network 1 12.
- user device 102 may include one or more computing devices, such as one or more computers, one or more portable computers (e.g., tablet computers), one or more mobile devices (e.g., cellular phones, smartphones, wearable devices, such as watches, glasses, lenses, and/or clothing, PDAs, and/or the like), and/or other like devices.
- computing devices such as one or more computers, one or more portable computers (e.g., tablet computers), one or more mobile devices (e.g., cellular phones, smartphones, wearable devices, such as watches, glasses, lenses, and/or clothing, PDAs, and/or the like), and/or other like devices.
- user device 102 may be capable of receiving information (e.g., from ICC 104) via a short-range wireless communication connection, such as an NFC communication connection, an RFID communication connection, a Bluetooth® communication connection, and/or the like, and/or communicating information (e.g., to ICC 104) via a short-range wireless communication connection.
- user device 102 may include an application associated with user device 102, such as an application stored on user device 102, a mobile application (e.g., a mobile device application, a native application for a mobile device, a mobile cloud application for a mobile device, and/or the like) stored on user device 102, and/or the like.
- the application associated with user device 102 may be operated by an entity that is the same as the entity associated with ICC 104.
- the application associated with user device 102 may be operated by a transaction service provider that controls a payment processing network on which ICC 104 may be used or the application associated with user device 102 may be operated by an issuer institution that issued ICC 104.
- ICC 104 may include one or more devices capable of receiving information from user device 102 and/or communicating information to user device 102 via a short- range wireless communication connection.
- ICC 104 may include an integrated chip card associated with an account of a user.
- ICC 104 may include a piezoelectric device (e.g., a piezoelectric chip, a solid state piezoelectric chip, and/or the like) to provide power to the circuitry of ICC 104, an NFC device (e.g., an NFC chip) to provide NFC capability, a transceiver, and/or a processing device (e.g., a processor, a computing chip, an integrated circuit, a microprocessor, a digital signal processor (DSP), and/or any processing component, such as a field-programmable gate array (FPGA) or an application-specific integrated circuit (ASIC) etc.), that can be programmed to perform a function, and/or the like) to provide computing and/or encryption capabilities.
- a piezoelectric device e.g., a piezoelectric chip, a solid state piezoelectric chip, and/or the like
- an NFC device e.g., an NFC chip
- a processing device e.g., a
- the processing device may be compliant with the Europay, Mastercard, Visa (EMV) standard or the processing device may not be compliant with the EMV standard.
- ICC 104 may include a payment device, embodiments of which are described in U.S. Patent Application Publication No. 2017/0124445, which is incorporated by reference herein in its entirety.
- Issuer system 106 may include one or more devices capable of receiving information from and/or communicating information to user device 102, transaction service provider system 108, and/or merchant system 1 10 via network 1 12.
- issuer system 106 may include a computing device, such as a server, a group of servers, and/or other like devices.
- issuer system 106 may be associated with an issuer institution as described herein.
- issuer system 106 may be associated with an issuer institution that issued a credit account, debit account, credit card, debit card, and/or the like to a user associated with user device 102 and/or ICC 104.
- Transaction service provider system 108 may include one or more devices capable of receiving information from and/or communicating information to user device 102, issuer system 106, and/or merchant system 1 10 via network 1 12.
- transaction service provider system 108 may include a computing device, such as a server (e.g., a transaction processing server), a group of servers, and/or other like devices.
- transaction service provider system 108 may be associated with a transaction service provider as described herein.
- transaction service provider system 108 may be in communication with a data storage device, which may be local or remote to the transaction service provider system 108.
- transaction service provider system 108 may be capable of receiving information from, storing information in, communicating information to, or searching information stored in a data storage device.
- Merchant system 110 may include one or more devices capable of receiving information from and/or communicating information to user device 102, issuer system 106, and/or transaction service provider system 108 via network 1 12.
- Merchant system 110 may also include a device capable of receiving information from user device 102 via network 1 12, a communication connection (e.g., an NFC communication connection, an RFID communication connection, a Bluetooth® communication connection, and/or the like) with user device 102, and/or the like, and/or communicating information to user device 102 via the network, the communication connection, and/or the like.
- merchant system 1 10 may include a computing device, such as a server, a group of servers, a client device, a group of client devices, and/or other like devices.
- merchant system 1 10 may be associated with a merchant as described herein.
- merchant system 1 10 may include one or more user devices 102.
- merchant system 1 10 may include user device 102 that allows a merchant to communicate information to transaction service provider system 108.
- merchant system 1 10 may include one or more devices, such as computers, computer systems, and/or peripheral devices capable of being used by a merchant to conduct a payment transaction with a user.
- merchant system 1 10 may include a POS device and/or a POS system.
- Network 1 12 may include one or more wired and/or wireless networks.
- network 1 12 may include a cellular network (e.g., a long-term evolution (LTE) network, a third generation (3G) network, a fourth generation (4G) network, a code division multiple access (CDMA) network, etc.), a public land mobile network (PLMN), a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a telephone network (e.g., the public switched telephone network (PSTN)), a private network, an ad hoc network, an intranet, the Internet, a fiber optic-based network, a cloud computing network, and/or the like, and/or a combination of these or other types of networks.
- LTE long-term evolution
- 3G third generation
- 4G fourth generation
- CDMA code division multiple access
- PLMN public land mobile network
- LAN local area network
- WAN wide area network
- MAN metropolitan area network
- PSTN public switched telephone network
- FIG. 1 The number and arrangement of devices and networks shown in FIG. 1 are provided as an example. There may be additional devices and/or networks, fewer devices and/or networks, different devices and/or networks, or differently arranged devices and/or networks than those shown in FIG. 1. Furthermore, two or more devices shown in FIG. 1 may be implemented within a single device, or a single device shown in FIG. 1 may be implemented as multiple, distributed devices. Additionally or alternatively, a set of devices (e.g., one or more devices) of environment 100 may perform one or more functions described as being performed by another set of devices of environment 100.
- a set of devices e.g., one or more devices
- FIG. 2 is a diagram of example components of a device 200.
- Device 200 may correspond to user device 102, and/or one or more devices of issuer system 106, transaction service provider system 108, and/or merchant system 1 10.
- user device 102, issuer system 106, transaction service provider system 108, and/or merchant system 110 may include at least one device 200 and/or at least one component of device 200.
- device 200 may include bus 202, processor 204, memory 206, storage component 208, input component 210, output component 212, and communication interface 214.
- Bus 202 may include a component that permits communication among the components of device 200.
- processor 204 may be implemented in hardware, firmware, or a combination of hardware and software.
- processor 204 may include a processor (e.g., a central processing unit (CPU), a graphics processing unit (GPU), an accelerated processing unit (APU), etc.), a microprocessor, a digital signal processor (DSP), and/or any processing component (e.g., a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), etc.) that can be programmed to perform a function.
- Memory 206 may include random access memory (RAM), read only memory (ROM), and/or another type of dynamic or static storage device (e.g., flash memory, magnetic memory, optical memory, etc.) that stores information and/or instructions for use by processor 204.
- RAM random access memory
- ROM read only memory
- static storage device e.g., flash memory, magnetic memory, optical memory, etc.
- Storage component 208 may store information and/or software related to the operation and use of device 200.
- storage component 208 may include a hard disk (e.g., a magnetic disk, an optical disk, a magneto-optic disk, a solid state disk, etc.), a compact disc (CD), a digital versatile disc (DVD), a floppy disk, a cartridge, a magnetic tape, and/or another type of computer-readable medium, along with a corresponding drive.
- Input component 210 may include a component that permits device 200 to receive information, such as via user input (e.g., a touch screen display, a keyboard, a keypad, a mouse, a button, a switch, a microphone, etc.). Additionally or alternatively, input component 210 may include a sensor for sensing information (e.g., a global positioning system (GPS) component, an accelerometer, a gyroscope, an actuator, etc.). Output component 212 may include a component that provides output information from device 200 (e.g., a display, a speaker, one or more light-emitting diodes (LEDs), etc.).
- GPS global positioning system
- LEDs light-emitting diodes
- Communication interface 214 may include a transceiver-like component (e.g., a transceiver, a separate receiver and transmitter, etc.) that enables device 200 to communicate with other devices, such as via a wired connection, a wireless connection, or a combination of wired and wireless connections.
- Communication interface 214 may permit device 200 to receive information from another device and/or provide information to another device.
- communication interface 214 may include an Ethernet interface, an optical interface, a coaxial interface, an infrared interface, a radio frequency (RF) interface, a universal serial bus (USB) interface, a Wi-Fi® interface, a cellular network interface, and/or the like.
- Device 200 may perform one or more processes described herein. Device 200 may perform these processes based on processor 204 executing software instructions stored by a computer-readable medium, such as memory 206 and/or storage component 208.
- a computer-readable medium e.g., a non-transitory computer-readable medium
- a memory device includes memory space located inside of a single physical storage device or memory space spread across multiple physical storage devices.
- Software instructions may be read into memory 206 and/or storage component 208 from another computer-readable medium or from another device via communication interface 214. When executed, software instructions stored in memory 206 and/or storage component 208 may cause processor 204 to perform one or more processes described herein. Additionally or alternatively, hardwired circuitry may be used in place of or in combination with software instructions to perform one or more processes described herein. Thus, embodiments described herein are not limited to any specific combination of hardware circuitry and software.
- device 200 may include additional components, fewer components, different components, or differently arranged components than those shown in FIG. 2. Additionally or alternatively, a set of components (e.g., one or more components) of device 200 may perform one or more functions described as being performed by another set of components of device 200.
- FIG. 3 is a flowchart of a non-limiting embodiment of a process 300 for conducting a secure online payment transaction.
- one or more of the steps of process 300 may be performed (e.g., completely, partially, etc.) by user device 102.
- one or more of the steps of process 300 may be performed (e.g., completely, partially, etc.) by another device or a group of devices separate from user device 102, such as ICC 104, issuer system 106 (e.g., one or more devices of issuer system 106), transaction service provider system 108 (e.g., one or more devices of transaction service provider system 108), or merchant system 1 10 (e.g., one or more devices of merchant system 1 10).
- issuer system 106 e.g., one or more devices of issuer system 106
- transaction service provider system 108 e.g., one or more devices of transaction service provider system 108
- merchant system 1 10 e.g., one or more devices of merchant system 1 10
- process 300 includes receiving an initiate signal for an online payment transaction from an integrated circuit card (ICC) via a near-field communication (NFC) connection.
- user device 102 may receive the initiate signal for the online payment transaction from ICC 104 via the NFC connection between user device 102 and ICC 104.
- ICC 104 may include a piezoelectric device and a transceiver and the initial signal is transmitted by ICC 104 and received by user device 102 based on the piezoelectric device providing power to the transceiver of ICC 104.
- user device 102 may receive the initiate signal from the ICC and the initiate signal is a signal based on an ISO/I EC 14443 standard.
- ICC 104 may establish the NFC connection between user device 102 and ICC 104.
- ICC 104 may establish the NFC connection between user device 102 and ICC 104 based on ICC 104 transmitting a signal after the piezoelectric device provides power to the transceiver of ICC 104.
- user device 102 and/or ICC 104 may be associated with a user.
- a user may have control and the user may operate both user device 102 and ICC 104.
- the user may have control and the user may operate one of user device 102 or ICC 104.
- user device 102 may be controlled and operated by a merchant (e.g., a merchant associated with merchant system 1 10).
- user device 102 may establish the NFC connection between user device 102 and ICC 104.
- user device 102 may establish the NFC connection between user device 102 and ICC 104 based on user device 102 transmitting a signal that is received by the transceiver of ICC 104.
- user device 102 makes a Hyper Text Transfer Protocol Secure (HTTPS) connection with transaction service provider system 108 via network 1 12 based on user device 102 receiving the initiate signal for the online payment transaction.
- HTTPS Hyper Text Transfer Protocol Secure
- user device 102 receives the initiate signal from ICC 104 and user device 102 makes an HTTPS connection with transaction service provider system 108 via network 1 12 based on receiving the initiate signal from ICC 104.
- user device 102 makes an HTTPS connection with transaction service provider system 108 via network 1 12 based on user device 102 providing an input to a website of a merchant.
- user device 102 may display the website of the merchant, and the website may include a graphical user interface (GUI) element (e.g., an icon, a button, and/or the like) associated with conducting on online payment transaction involving ICC 104.
- GUI graphical user interface
- User device 102 may make the HTTPS connection with transaction service provider system 108 via network 1 12 based on user device 102 providing an input to the website of the merchant via the GUI element.
- transaction service provider system 108 may communicate a payment code (e.g., a one-time payment code) associated with the online payment transaction to user device 102.
- transaction service provider system 108 may communicate the payment code associated with the online payment transaction to user device 102 based on user device 102 making an HTTPS connection with transaction service provider system 108 via network 1 12.
- the payment code may be a unique payment code for the online payment transaction.
- transaction service provider system 108 may communicate a unique payment code for each online payment transaction of a plurality of online payment transactions.
- user device 102 may communicate transaction amount data associated with a transaction amount of the online payment transaction to ICC 104.
- user device 102 may communicate the transaction amount data to ICC 104 based on receiving the initiate signal for the online payment transaction.
- process 300 includes receiving a payment transaction message from the ICC via the NFC connection.
- user device 102 may receive the payment transaction message (e.g., a data packet including information associated with the online payment transaction) from ICC 104 via the NFC connection.
- user device 102 may receive the payment transaction message from ICC 104 after user device 102 communicates a response signal to the initiate signal for the online payment transaction that is received from ICC 104.
- user device 102 may receive the payment transaction message from ICC 104 after communicating transaction amount data associated with the transaction amount of the online payment transaction to ICC 104. In some non-limiting embodiments, user device 102 may receive the payment transaction message from ICC 104 based on an EMV contactless communication protocol.
- ICC 104 may generate the payment transaction message. For example, ICC 104 may generate the payment transaction message based on determining that an NFC connection has been established with user device 102. In another example, ICC 104 may generate the payment transaction message based on receiving transaction amount data associated with a transaction amount of the online payment transaction from user device 102.
- the payment transaction message may include payment account data associated with an account of a user (e.g., the account of the user associated with ICC 104).
- the payment transaction message may include a payment account identifier of the account of the user that has been encrypted with an encryption key associated with an issuer (e.g., an issuer encryption key) and/or a payment account identifier of the account of the user that has been encrypted with the encryption key associated with a transaction service provider (e.g., a transaction service provider encryption key).
- the payment transaction message may include account identification data associated with an identity of the user associated with the account and/or an identification of the account of the user.
- the account identification data may include at least one identifier associated with a name of a user associated with the account, an account identifier of the account of the user, a code of the user associated with the account, and/or the like.
- the payment transaction message may include an identifier associated with a transaction service provider (e.g., a transaction service provider associated with transaction service provider system 108) to which the payment transaction message is to be communicated.
- ICC 104 may store an issuer encryption key and/or a transaction service provider encryption key. In some non-limiting embodiments, ICC 104 may encrypt a payment account identifier of the account of the user using the issuer encryption key and/ora payment account identifier of the account using the transaction service provider encryption key. In some non-limiting embodiments, ICC 104 may generate a payment transaction message based on encrypting a payment account identifier of the account of the user using the issuer encryption key and/or encrypting the payment account identifier of the account using the transaction service provider encryption key.
- user device 102 may verify an identity of the user associated with the account. For example, user device 102 may verify the identity of the user associated with the account based on account identification data associated with an identity of the user and/or an identification of the account of the user included in the payment account data. [0077] In some non-limiting embodiments, user device 102 may communicate transaction amount data associated with a transaction amount of the online payment transaction to ICC 104. For example, user device 102 may communicate transaction amount data associated with a transaction amount of the online payment transaction to ICC 104 via the NFC connection based on receiving the initiate signal for the online payment transaction. In some non-limiting embodiments, the payment transaction message may include transaction amount data associated with a transaction amount of the online payment transaction. In some non-limiting embodiments, user device 102 may communicate transaction amount data associated with a transaction amount of the online payment transaction to ICC 104 based on verifying an identity of the user associated with the account.
- ICC 104 may store an issuer encryption key and/or a transaction service provider encryption key in a memory of ICC 104.
- the issuer encryption key may include a public encryption key (e.g., an issuer public encryption key).
- the transaction service provider encryption key may include a public encryption key (e.g., a transaction service provider public encryption key).
- process 300 includes determining whether payment account data associated with an account of a user is encrypted.
- user device 102 may determine whether the payment account data associated with the account of the user included in the payment transaction message is encrypted.
- user device 102 may determine whether the payment account data associated with the account of the user is encrypted based on verifying the identity of the user.
- user device 102 may determine whether the payment account data is encrypted based on an indication that indicates the payment account data associated with the account of the user included in the payment transaction message is encrypted. For example, user device 102 may determine whether the payment account data is encrypted based on an indication included in the payment transaction message.
- user device 102 may determine that the payment account data is encrypted based on an indication of whether the payment account data associated with the account of the user included in the payment transaction message is encrypted. For example, user device 102 may determine that the indication indicates that the payment account data associated with the account of the user is encrypted and user device 102 may determine that the payment account data is encrypted based on the indication. In another example, user device 102 may determine that the indication indicates that the payment account data associated with the account of the user is not encrypted and user device 102 may determine that the payment account data is not encrypted based on the indication.
- user device 102 may determine that the payment account data is encrypted based on a data format (e.g., a data format that specifies data is to be provided a location) of the payment transaction message. For example, user device 102 may receive the payment transaction message and determine that the payment transaction message includes data in a specified location of the payment transaction message. User device 102 may determine that the payment account data is encrypted based on determining that the payment transaction message includes the data in the specified location of the payment transaction message.
- a data format e.g., a data format that specifies data is to be provided a location
- process 300 includes displaying an indication that the payment account data associated with the account of the user is not encrypted.
- user device 102 may display the indication that the payment account data associated with the account of the user included in the payment transaction message is not encrypted.
- user device 102 may display the indication that the payment account data is not encrypted based on user device 102 determining that the payment account data is not encrypted.
- user device 102 may display a graphical user interface element that indicates that the payment account data is not encrypted based on user device 102 determining that the payment account data is not encrypted.
- process 300 includes displaying an indication that the payment account data associated with the account of the user is encrypted.
- user device 102 may display the indication that the payment account data associated with the account of the user included in the payment transaction message is encrypted.
- user device 102 may display the indication that the payment account data is encrypted based on user device 102 determining that the payment account data is encrypted.
- user device 102 may display a graphical user interface element (e.g., an icon, a icon having an appearance associated with a lock, a standard icon, and/or the like) that indicates that the payment account data is encrypted based on user device 102 determining that the payment account data is encrypted.
- user device 102 may display a webpage that includes an indication that indicates that the payment account data is encrypted.
- user device 102 may display a webpage that includes an address (e.g., an address having a certain color font) displayed in an address bar of a browser that indicates that the payment account data is encrypted.
- user device 102 may include an operating system that causes an application of user device 102 to display an indication that indicates that the payment account data is encrypted.
- the operating system of user device 102 may cause the application of user device 102 to display the indication that indicates that the payment account data is encrypted based on a device specific standard format.
- process 300 includes communicating the payment transaction message.
- user device 102 may communicate the payment transaction message based on determining that the payment account data associated with the account of the user included in the payment transaction message is encrypted.
- user device 102 may communicate the payment transaction message to merchant system 110.
- user device 102 may display a webpage associated with the merchant involved in the online payment transaction and user device 102 may communicate the payment transaction message to a web server serving the webpage associated with the merchant (e.g., a web server of merchant system 1 10 associated with the merchant) involved in the online payment transaction.
- user device 102 may modify the payment transaction message and communicate the payment transaction message based on modifying the payment transaction message. For example, user device 102 may receive the payment transaction message from ICC 104 and user device 102 may modify the payment transaction message to include a payment code (e.g., a payment code received from transaction service provider system 108). User device 102 may communicate the payment transaction message after the payment transaction message has been modified. In some non-limiting embodiments, user device 102 may communicate the payment transaction message to merchant system 1 10 after the payment transaction message has been modified.
- a payment code e.g., a payment code received from transaction service provider system 108
- user device 102 may receive a payment transaction message from ICC 104 and user device 102 may calculate a hash value of the transaction amount of the online payment transaction using a hashing algorithm.
- User device 102 may modify the payment transaction message to include the hash value of the transaction amount of the online payment transaction, the hashing algorithm used to calculate the hash value, and/or a user identifier associated with an identity of the user associated with user device 102 and/or ICC 104.
- user device 102 may modify the payment transaction message to include an identifier associated with a transaction service provider (e.g., a transaction service provider associated with transaction service provider system 108) to which the payment transaction message is to be communicated.
- a transaction service provider e.g., a transaction service provider associated with transaction service provider system 108
- user device 102 may communicate the payment transaction message after the payment transaction message has been modified. In some non-limiting embodiments, user device 102 may communicate the payment transaction message to merchant system 110 or transaction service provider system 108 after the payment transaction message has been modified.
- merchant system 1 10 may modify the payment transaction message and communicate the payment transaction message based on modifying the payment transaction message. For example, merchant system 110 may receive the payment transaction message from user device 102, and merchant system 1 10 may calculate a hash value of the transaction amount of the online payment transaction using a hashing algorithm. Merchant system 1 10 may modify the payment transaction message to include the hash value of the transaction amount of the online payment transaction, the hashing algorithm used to calculate the hash value, and/or a merchant identifier associated with an identity of the merchant associated with merchant system 1 10. Merchant system 110 may communicate the payment transaction message after the payment transaction message has been modified. In some non-limiting embodiments, merchant system 1 10 may communicate the payment transaction message to transaction service provider system 108 after the payment transaction message has been modified.
- transaction service provider system 108 may validate the payment transaction message. For example, transaction service provider system 108 may validate the payment transaction message based on a payment code included in the payment transaction message and/or transaction amount data associated with a transaction amount of the online payment transaction, a hash value of a transaction amount of the online payment transaction, and a hashing algorithm used to calculate the hash value included in the payment transaction message. In some non-limiting embodiments, transaction service provider system 108 may validate the payment transaction message based on determining whether the payment transaction message includes a payment code communicated by transaction service provider system 108. For example, transaction service provider system 108 may determine whether the payment transaction message includes a payment code communicated by transaction service provider system 108 to user device 102.
- transaction service provider system 108 may validate the payment transaction message. If transaction service provider system 108 determines that the payment transaction message does not include the payment code, transaction service provider system 108 may determine not to validate the payment transaction message. In some non-limiting embodiments, transaction service provider system 108 may forego processing of the payment transaction message based on determining not to validate the payment transaction message.
- transaction service provider system 108 may validate the payment transaction message based on transaction amount data associated with a transaction amount of the online payment transaction, a hash value of the transaction amount of the online payment transaction, and a hashing algorithm used to calculate the hash value that are included in the payment transaction message. For example, transaction service provider system 108 may determine the transaction amount of the online payment transaction based on the transaction amount data associated with the transaction amount of the online payment transaction.
- Transaction service provider system 108 may calculate a hash value of the transaction amount of the online payment transaction using the hashing algorithm and transaction service provider system 108 may compare the hash value of the transaction amount of the online payment transaction calculated by transaction service provider system 108 using the hashing algorithm to the hash value of the transaction amount of the online payment transaction included in the payment transaction message. If transaction service provider system 108 determines that the hash value of the transaction amount of the online payment transaction calculated by transaction service provider system 108 using the hashing algorithm and the hash value of the transaction amount of the online payment transaction included in the payment transaction message match, transaction service provider system 108 may validate the payment transaction message.
- transaction service provider system 108 may determine not to validate the payment transaction message.
- transaction service provider system 108 may decrypt payment account data associated with the account of the user that is encrypted using a transaction service provider public encryption key. For example, transaction service provider system 108 may decrypt the payment account data associated with the account of the user using a transaction service provider private key that corresponds to the transaction service provider public key based on transaction service provider system 108 validating the payment transaction message. In some non-limiting embodiments, transaction service provider system 108 may decrypt the payment account data associated with the account of the user to determine a payment account identifier of the account of the user that is encrypted with the transaction service provider public encryption key.
- transaction service provider system 108 may determine an issuer identification number (IIN) of an issuer that issued the account of the user. For example, transaction service provider system 108 may determine the IIN of an issuer that issued the account of the user based on determining a payment account identifier of the account of the user by decrypting the payment account data associated with the account of the user. In some non-limiting embodiments, transaction service provider system 108 may determine an identity of an issuer associated with issuer system 106 based on the IIN of the issuer.
- IIN issuer identification number
- transaction service provider system 108 may communicate the payment transaction message to issuer system 106.
- transaction service provider system 108 may communicate the payment transaction message to issuer system 106 based on transaction service provider system 108 determining the identity of the issuer associated with issuer system 106.
- transaction service provider system 108 may communicate an authorization request message to issuer system 106 based on determining to process the online payment transaction.
- issuer system 106 receives the payment transaction message and determines to process the online payment transaction based on payment account data associated with the account of the user that is encrypted and included in the payment transaction message. For example, issuer system 106 may receive the payment transaction message and extract payment account data associated with the account of the user that was encrypted using an issuer public encryption key. Issuer system 106 may decrypt the payment account data associated with the account of the user using an issuer private encryption key that corresponds to the issuer public encryption key. Issuer system 106 may determine to process the online payment transaction based on the payment account data associated with the account of the user that was decrypted using the private encryption key. In some nonlimiting embodiments, issuer system 106 may decrypt the payment account data associated with the account of the user to determine a payment account identifier of the account of the user that is encrypted with the transaction service provider public encryption key.
- issuer system 106 may receive transaction data associated with the online payment transaction based on receiving the payment transaction message. For example, issuer system 106 may receive identification data associated with an identification of the merchant involved in the online payment transaction, transaction amount data associated with a transaction amount of the online payment transaction, and/or product data associated with a product involved in the online payment transaction that is included in the payment transaction message.
- issuer system 106 may determine a payment account identifier of the account of the user involved in the online payment transaction, an identification of the merchant involved in the online payment transaction, a transaction amount of the online payment transaction, and/or a product involved in the online payment transaction based on transaction data associated with the online payment transaction included in the payment transaction message. In some non-limiting embodiments, issuer system 106 may process the online payment transaction based on the transaction data associated with the online payment transaction included in the payment transaction message.
- issuer system 106 may process the online payment transaction based on a payment account identifier of the account of the user, the identification of the merchant involved in the online payment transaction, the transaction amount of the online payment transaction, and/or the product involved in the online payment transaction.
- issuer system 106 may communicate an authorization response message associated with the online payment transaction to merchant system 110 based on processing the online payment transaction.
- FIGS. 4A-4D are diagrams of an overview of a non-limiting embodiment of an implementation 400 relating to process 300 shown in FIG. 3.
- implementation 400 may include user device 402, ICC 404, issuer system 406, transaction service provider system 408, and merchant system 410.
- user device 402 may be the same or similar to user device 102
- ICC 404 may be the same or similar to ICC 104
- issuer system 406 may be the same or similar to issuer system 106
- transaction service provider system 408 may be the same or similar to transaction service provider system 108
- merchant system 410 may be the same or similar to merchant system 1 10.
- user device 402 may receive an initiate signal for an online payment transaction from ICC 404 via an NFC connection, based on a piezoelectric device of ICC 404 providing power to a transceiver of ICC 404.
- user device 402 may receive a payment transaction message from ICC 404 via the NFC connection.
- the payment transaction message may include transaction data associated with an online payment transaction to be processed and payment account data associated with an account of a user associated with ICC 404.
- the payment account data associated with the account of the user may be encrypted by ICC 404 using a transaction service provider public encryption key.
- user device 402 may determine that the payment account data associated with the account of the user included in the payment transaction message is encrypted.
- user device 402 may display an indication that the payment account data associated with the account of the user is encrypted. As further shown by reference number 435 in FIG. 4B, user device 402 may communicate the payment transaction message to merchant system 410 based on determining that the payment account data associated with the account of the user is encrypted. As further shown by reference number 440 in FIG. 4B, merchant system 410 may receive the payment transaction message and modify the payment transaction message. For example, merchant system 410 may receive the payment transaction message and determine a transaction amount of the online payment transaction based on transaction data associated with the online payment transaction included in the payment transaction message. Merchant system 410 may calculate a hash value of the transaction amount of the online payment transaction using a hashing algorithm.
- Merchant system 410 may modify the payment transaction message to include the hash value of the transaction amount of the online payment transaction, the hashing algorithm used to calculate the hash value, and/or a merchant identifier associated with an identity of the merchant associated with merchant system 410. As further shown by reference number 445 in FIG. 4B, merchant system 410 may communicate the payment transaction message to transaction service provider system 408 based on modifying the payment transaction message.
- transaction service provider system 408 may receive the payment transaction message and may validate the payment transaction message. For example, transaction service provider system 408 may receive the payment transaction message and validate the payment transaction message based on a payment code included in the payment transaction message and/or transaction amount data associated with a transaction amount of the online payment transaction, a hash value of the transaction amount of the online payment transaction, and a hashing algorithm used to calculate the hash value included in the payment transaction message. As further shown by reference number 455 in FIG. 4C, transaction service provider system 408 may decrypt the payment account data associated with the account of the user included in the payment transaction message, where the payment account data is encrypted using a transaction service provider public encryption key. For example, transaction service provider system 408 may decrypt the payment account data associated with the account of the user using a transaction service provider private key that corresponds to the transaction service provider public key based on transaction service provider system 408 validating the payment transaction message.
- transaction service provider system 408 may determine an issuer identification number of an issuer that issued the account of the user. For example, transaction service provider system 408 may determine an IIN of an issuer that issued the account of the user based on determining a payment account identifier of the account of the user by decrypting the payment account data associated with the account of the user. In some non-limiting embodiments, transaction service provider system 408 may determine an identity of an issuer associated with issuer system 406 based on the I IN of the issuer.
- transaction service provider system 408 may communicate the payment transaction message to issuer system 406 based on determining an identity of the issuer associated with issuer system 406.
- issuer system 406 may receive the payment transaction message and determine to process the online payment transaction based on payment account data associated with the account of the user that is encrypted and included in the payment transaction message. For example, issuer system 406 may receive the payment transaction message and extract payment account data associated with the account of the user that was encrypted using an issuer public encryption key. Issuer system 406 may decrypt the payment account data associated with the account of the user using an issuer private encryption key that corresponds to the issuer public encryption key.
- Issuer system 406 may determine to process the online payment transaction based on the payment account data associated with the account of the user that was decrypted using the private encryption key. In some non-limiting embodiments, issuer system 406 may decrypt the payment account data associated with the account of the user to determine a payment account identifier of the account of the user that is encrypted with the transaction service provider public encryption key.
- issuer system 406 may process the online payment transaction based on the transaction data associated with the online payment transaction included in the payment transaction message. For example, issuer system 106 may process the online payment transaction based on a payment account identifier of the account of the user, an identification of the merchant involved in the online payment transaction, a transaction amount of the online payment transaction, and/or a product involved in the online payment transaction. As further shown by reference number 475 in FIG. 4D, issuer system 406 may communicate an authorization response message for the online payment transaction to merchant system 410 based on processing the online payment transaction.
Landscapes
- Business, Economics & Management (AREA)
- Engineering & Computer Science (AREA)
- Accounting & Taxation (AREA)
- Physics & Mathematics (AREA)
- Strategic Management (AREA)
- General Business, Economics & Management (AREA)
- General Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Finance (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Microelectronics & Electronic Packaging (AREA)
- Development Economics (AREA)
- Economics (AREA)
- Cash Registers Or Receiving Machines (AREA)
Abstract
Provided is a computer-implemented method for conducting a secure online payment transaction using an integrated circuit card (ICC) that includes receiving an initiate signal for an online payment transaction from an ICC having a piezoelectric device and a transceiver via a near-field communication (NFC) connection, based on the piezoelectric device providing power to the transceiver, receiving a payment transaction message from the ICC via the NFC connection, the payment transaction message including payment account data associated with an account of a user, determining whether the payment account data associated with the account of the user is encrypted, displaying an indication that the payment account data associated with the account of the user is encrypted, and communicating the payment transaction message based on determining that the payment account data associated with the account of the user is encrypted. A system and computer program product are also disclosed.
Description
SYSTEM, METHOD, AND COMPUTER PROGRAM PRODUCT FOR
CONDUCTING SECURE ONLINE PAYMENT TRANSACTIONS
BACKGROUND
1. Field of the Disclosure
[0001] This disclosure relates generally to systems, devices, products, apparatus, and methods that are used for conducting online payment transactions, in one particular embodiment, to a system, product, and method for conducting secure online payment transactions using an integrated circuit card (ICC).
2. Technical Considerations
[0002] An integrated circuit card (ICC) (e.g., a smart card, a chip card, and/or the like), may include a pocket-sized card that has embedded integrated circuits. An ICC may include a pattern of metal contacts to electrically connect to an internal chip, and the metal contacts may be used to communicate information based on physical contact. In some instances, an ICC may be contactless, such that the ICC may include a radio frequency identification (RFID) chip. An ICC may be used to communicate personal identification, authentication, data storage, and application processing. An ICC that is contactless may communicate with and is powered by a reader through RF induction technology. An ICC that is contactless may be required to be in proximity to a reader to communicate. In some instances, an ICC does not have an internal power source. In such an instance, the ICC may use an inductor to capture an incident RF interrogation signal from a reader, rectify the incident RF interrogation signal, and use the incident RF interrogation signal to power the internal chip of the ICC.
[0003] However, during an online payment transaction (e.g., an online commerce transaction, an Internet payment transaction, and/or the like), card information (e.g., a primary account number (PAN) of an account) associated with an ICC may not be secured by a merchant involved in the online payment transaction. For example, the merchant involved in the online payment transaction may receive the PAN from a user device associated with a user after the user inputs the PAN to a website of the merchant via the user device. The merchant may not secure the PAN via tokenization or other techniques, and the PAN may be intercepted by another party. In some instances, the merchant may have a system that secures the PAN, however, rogue
software and/or individuals may intercept the PAN before the merchant secures the PAN.
SUMMARY
[0004] Accordingly, systems, devices, products, apparatus, and/or methods for conducting a secure online payment transaction using an ICC are disclosed that overcome some or all of the deficiencies of the prior art.
[0005] According to a non-limiting embodiment, provided is a computer- implemented method for conducting a secure online payment transaction using an ICC. The computer-implemented method comprises receiving, with at least one processor, an initiate signal for an online payment transaction from an ICC having a piezoelectric device and a transceiver via a near-field communication (NFC) connection, based on the piezoelectric device providing power to the transceiver; receiving, with at least one processor, a payment transaction message from the ICC via the NFC connection, the payment transaction message comprising payment account data associated with an account of a user that is encrypted by the ICC; determining, with at least one processor, whether the payment account data associated with the account of the user is encrypted; displaying, with at least one processor, an indication that the payment account data associated with the account of the user is encrypted; and communicating, with at least one processor, the payment transaction message based on determining that the payment account data associated with the account of the user is encrypted.
[0006] According to another non-limiting embodiment, provided is a system for conducting a secure online payment transaction using an ICC. The system comprises a computing device having at least one processor, wherein the at least one processor is programmed or configured to: receive an initiate signal for an online payment transaction from an ICC via a near-field communication (NFC) connection, based on a piezoelectric device of the ICC providing power to a transceiver of the ICC; receive a payment transaction message from the ICC via the NFC connection, the payment transaction message comprising payment account data associated with an account of a user that is encrypted by the ICC; determine whether the payment account data associated with the account of the user is encrypted; display an indication that the payment account data associated with the account of the user is encrypted; and
communicate the payment transaction message based on determining that the payment account data associated with the account of the user is encrypted.
[0007] According to a further non-limiting embodiment, provided is a computer program product for conducting a secure online payment transaction using an ICC. The computer program product comprises at least one non-transitory computer- readable medium including one or more instructions that, when executed by at least one processor, cause the at least one processor to receive an initiate signal for an online payment transaction from an ICC via a near-field communication (NFC) connection, based on a piezoelectric device of the ICC providing power to a transceiver of the ICC; receive a payment transaction message from the ICC via the NFC connection, the payment transaction message comprising payment account data associated with an account of a user that is encrypted by the ICC; determine that the payment account data associated with the account of the user is encrypted; and communicate the payment transaction message based on determining that the payment account data associated with the account of the user is encrypted.
[0008] Further embodiments or aspects are set forth in the following numbered clauses:
[0009] Clause 1 : A computer-implemented method for conducting a secure online payment transaction using an ICC, comprising: receiving, with at least one processor, an initiate signal for an online payment transaction from an ICC having a piezoelectric device and a transceiver via a near-field communication (NFC) connection, based on the piezoelectric device providing power to the transceiver; receiving, with at least one processor, a payment transaction message from the ICC via the NFC connection, the payment transaction message comprising payment account data associated with an account of a user that is encrypted by the ICC; determining, with at least one processor, whether the payment account data associated with the account of the user is encrypted; displaying, with at least one processor, an indication that the payment account data associated with the account of the user is encrypted; and communicating, with at least one processor, the payment transaction message based on determining that the payment account data associated with the account of the user is encrypted.
[0010] Clause 2: The computer-implemented method of clause 1 , wherein receiving the initiate signal from the ICC comprises: receiving the initiate signal from the ICC, wherein the initiate signal is a signal based on an ISO/IEC 14443 standard.
[0011] Clause 3: The computer-implemented method of clauses 1 or 2, further comprising: verifying an identity of the user based on account identity data associated with an identity of the user included in the payment account data associated with the account of the user, wherein determining whether the payment account data associated with the account of the user is encrypted comprises: determining whether the payment account data associated with the account of the user is encrypted based on verifying the identity of the user.
[0012] Clause 4: The computer-implemented method of any of clauses 1-3, further comprising: communicating transaction amount data associated with a transaction amount of the online payment transaction to the ICC, and wherein receiving the payment transaction message that comprises the payment account data associated with the account of the user comprises: receiving the payment transaction message after communicating the transaction amount data associated with the transaction amount of the online payment transaction, wherein the payment account data associated with the account of the user comprises: a payment account identifier of the account of the user that has been encrypted with an issuer encryption key; and a payment account identifier of the account of the user that has been encrypted with a transaction service provider encryption key.
[0013] Clause 5: The computer-implemented method of any of clauses 1-4, wherein communicating the payment transaction message comprises: communicating the payment transaction message to a merchant system associated with the merchant involved in the online payment transaction.
[0014] Clause 6: The computer-implemented method of any of clauses 1-5, further comprising: displaying a webpage associated with the merchant involved in the online payment transaction, wherein communicating the payment transaction message comprises: communicating the payment transaction message to a web server serving the webpage associated with the merchant involved in the online payment transaction.
[0015] Clause 7: The computer-implemented method of any of clauses 1-6, wherein receiving the payment transaction message from the ICC comprises: receiving the payment transaction message based on a Europay, Mastercard, Visa (EMV) contactless communication protocol.
[0016] Clause 8: A system for conducting a secure online payment transaction using an integrated circuit card (ICC), comprising: a computing device having at least one processor, wherein the at least on processor is programmed or configured to:
receive an initiate signal for an online payment transaction from an ICC via a nearfield communication (NFC) connection, based on a piezoelectric device of the ICC providing power to a transceiver of the ICC; receive a payment transaction message from the ICC via the NFC connection, the payment transaction message comprising payment account data associated with an account of a user that is encrypted by the ICC; determine whether the payment account data associated with the account of the user is encrypted; display an indication that the payment account data associated with the account of the user is encrypted; and communicate the payment transaction message based on determining that the payment account data associated with the account of the user is encrypted.
[0017] Clause 9: The system of clause 8, wherein, when receiving the initiate signal from the ICC, the at least one processor is programmed or configured to: receive the initiate signal from the ICC, wherein the initiate signal is a signal based on an ISO/IEC 14443 standard.
[0018] Clause 10: The system of clauses 8 or 9, wherein the at least one processor is further programmed or configured to: verify an identity of the user based on account identity data associated with an identity of the user included in the payment account data associated with the account of the user; and wherein, when determining whether the payment account data associated with the account of the user is encrypted, the at least one processor is programmed or configured to: determine whether the payment account data associated with the account of the user is encrypted based on verifying the identity of the user.
[0019] Clause 1 1 : The system of any of clauses 8-10, wherein the at least one processor is further programmed or configured to: communicate transaction amount data associated with a transaction amount of the online payment transaction to the ICC; and wherein, when receiving the payment transaction message that comprises the payment account data associated with the account of the user, the at least one processor is programmed or configured to: receive the payment transaction message after communicating the transaction amount data associated with the transaction amount of the online payment transaction, wherein the payment account data associated with the account of the user comprises: a payment account identifier of the account of the user that has been encrypted with an issuer encryption key; and a payment account identifier of the account of the user that has been encrypted with a transaction service provider encryption key.
[0020] Clause 12: The system of any of clauses 8-11 , wherein, when communicating the payment transaction message, the at least one processor is programmed or configured to: communicate the payment transaction message to a merchant system associated with the merchant involved in the online payment transaction.
[0021] Clause 13: The system of any of clauses 8-12, wherein the at least one processor is further programmed or configured to: display a webpage associated with the merchant involved in the online payment transaction; and wherein, when communicating the payment transaction message, the at least one processor is programmed or configured to: communicate the payment transaction message to a web server serving the webpage associated with the merchant involved in the online payment transaction.
[0022] Clause 14: The system of any of clauses 8-13, wherein, when receiving the payment transaction message from the ICC, the at least one processor is programmed or configured to: receive the payment transaction message based on a Europay, Mastercard, Visa (EMV) contactless communication protocol.
[0023] Clause 15: A computer program product for conducting a secure online payment transaction using an integrated circuit card (ICC), the computer program product comprising at least one non-transitory computer-readable medium including one or more instructions that, when executed by at least one processor, cause the at least one processor to: receive an initiate signal for an online payment transaction from an ICC via a near-field communication (NFC) connection, based on a piezoelectric device of the ICC providing power to a transceiver of the ICC; receive a payment transaction message from the ICC via the NFC connection, the payment transaction message comprising payment account data associated with an account of a user that is encrypted by the ICC; determine that the payment account data associated with the account of the user is encrypted; and communicate the payment transaction message based on determining that the payment account data associated with the account of the user is encrypted.
[0024] Clause 16: The computer program product of clause 15, wherein the one or more instructions further cause the at least one processor to: verify an identity of the user based on account identity data associated with an identity of the user included in the payment account data associated with the account of the user; and wherein, when determining whether the payment account data associated with the account of the
user is encrypted, the at least one processor is programmed or configured to: determine whether the payment account data associated with the account of the user is encrypted based on verifying the identity of the user.
[0025] Clause 17: The computer program product of clauses 15 or 16, wherein the one or more instructions further cause the at least one processor to: communicate transaction amount data associated with a transaction amount of the online payment transaction to the ICC; and wherein, the one or more instructions that cause the at least one processor to receive the payment transaction message, cause the at least one processor to: receive the payment transaction message after communicating the transaction amount data associated with the transaction amount of the online payment transaction, wherein the payment account data associated with the account of the user comprises: a payment account identifier of the account of the user that has been encrypted with an issuer encryption key; and a payment account identifier of the account of the user that has been encrypted with a transaction service provider encryption key.
[0026] Clause 18: The computer program product of any of clauses 15-17, wherein, the one or more instructions that cause the at least one processor to communicate the payment transaction message, cause the at least one processor to: communicate the payment transaction message to a merchant system associated with the merchant involved in the online payment transaction.
[0027] Clause 19: The computer program product of any of clauses 15-18, wherein the one or more instructions further cause the at least one processor to: display a webpage associated with the merchant involved in the online payment transaction; and wherein, when communicating the payment transaction message, the at least one processor is programmed or configured to: communicate the payment transaction message to a web server serving the webpage associated with the merchant involved in the online payment transaction.
[0028] Clause 20: The computer program product of any of clauses 15-19, wherein, the one or more instructions that cause the at least one processor to receive the payment transaction message from the ICC, cause the at least one processor to: receive the payment transaction message based on a Europay, Mastercard, Visa (EMV) contactless communication protocol.
[0029] These and other features and characteristics of the present disclosure, as well as the methods of operation and functions of the related elements of structures
and the combination of parts and economies of manufacture, will become more apparent upon consideration of the following description and the appended claims with reference to the accompanying drawings, all of which form a part of this specification, wherein like reference numerals designate corresponding parts in the various figures. It is to be expressly understood, however, that the drawings are for the purpose of illustration and description only and are not intended as a definition of the limits of the disclosure. As used in the specification and the claims, the singular form of“a,”“an,” and“the” include plural referents unless the context clearly dictates otherwise.
BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Additional advantages and details of the disclosure are explained in greater detail below with reference to the exemplary embodiments that are illustrated in the accompanying schematic figures, in which:
[0031] FIG. 1 is a diagram of a non-limiting embodiment of an environment in which systems, devices, products, apparatus, and/or methods, described herein, may be implemented according to the principles of the present disclosure;
[0032] FIG. 2 is a diagram of a non-limiting embodiment of components of one or more devices of FIG. 1 ;
[0033] FIG. 3 is a flowchart of a non-limiting embodiment of a process for conducting a secure online payment transaction; and
[0034] FIGS. 4A-4D are diagrams of an implementation of a non-limiting embodiment of the process shown in FIG. 3.
DETAILED DESCRIPTION
[0035] For purposes of the description hereinafter, the terms “end,” “upper,” “lower,”“right,”“left,”“vertical,”“horizontal,”“top,”“bottom,”“lateral,” longitudinal,” and derivatives thereof shall relate to the disclosure as it is oriented in the drawing figures. However, it is to be understood that the disclosure may assume various alternative variations and step sequences, except where expressly specified to the contrary. It is also to be understood that the specific devices and processes illustrated in the attached drawings, and described in the following specification, are simply exemplary embodiments or aspects of the disclosure. Hence, specific dimensions and other physical characteristics related to the embodiments or aspects of the embodiments disclosed herein are not to be considered as limiting unless otherwise indicated.
[0036] No aspect, component, element, structure, act, step, function, instruction, and/or the like used herein should be construed as critical or essential unless explicitly described as such. Also, as used herein, the articles“a” and“an” are intended to include one or more items and may be used interchangeably with“one or more” and “at least one.” Furthermore, as used herein, the term“set” is intended to include one or more items (e.g., related items, unrelated items, a combination of related and unrelated items, etc.) and may be used interchangeably with“one or more” or“at least one.” Where only one item is intended, the term“one” or similar language is used. Also, as used herein, the terms“has,”“have,”“having,” or the like are intended to be open-ended terms. Further, the phrase“based on” is intended to mean“based at least partially on” unless explicitly stated otherwise.
[0037] As used herein, the terms“communication” and“communicate” may refer to the reception, receipt, transmission, transfer, provision, and/or the like of information (e.g., data, signals, messages, instructions, commands, and/or the like). For one unit (e.g., a device, a system, a component of a device or system, combinations thereof, and/or the like), to be in communication with another unit, means that the one unit is able to directly or indirectly receive information from and/or transmit information to the other unit. This may refer to a direct or indirect connection that is wired and/or wireless in nature. Additionally, two units may be in communication with each other even though the information transmitted may be modified, processed, relayed, and/or routed between the first and second unit. For example, a first unit may be in communication with a second unit even though the first unit passively receives information and does not actively transmit information to the second unit. As another example, a first unit may be in communication with a second unit if at least one intermediary unit (e.g., a third unit located between the first unit and the second unit) processes information received from the first unit and communicates the processed information to the second unit. In some non-limiting embodiments, a message may refer to a network packet (e.g., a data packet and/or the like) that includes data. It will be appreciated that numerous other arrangements are possible.
[0038] As used herein, the terms “issuer institution,” “payment device issuer,” “issuer,” or“issuer bank” may refer to one or more entities that provide one or more accounts to a user (e.g., customer, consumer, and/or the like) for conducting transactions (e.g., payment transactions), such as initiating credit card payment transactions and/or debit card payment transactions. For example, an issuer
institution may provide an account identifier, such as a primary account number (PAN), to a user that uniquely identifies one or more accounts associated with that user. The account identifier may be embodied on a payment device, such as a physical financial instrument (e.g., a payment card), and/or may be electronic and used for electronic payment transactions. In some non-limiting embodiments, an issuer institution may be associated with a bank identification number (BIN) that uniquely identifies the issuer institution. As used herein“issuer system” may refer to one or more computer systems operated by or on behalf of an issuer institution, such as a server computer executing one or more software applications. For example, an issuer system may include one or more authorization servers for authorizing a payment transaction.
[0039] As used herein, the term“account identifier” may refer to one or more types of identifiers associated with a user account (e.g., an account identifier, a PAN, a card number, a payment card number, a token, and/or the like). In some non-limiting embodiments, an issuer institution may provide an account identifier (e.g., a PAN, a token, and/or the like) to a user that uniquely identifies one or more accounts associated with that user. The account identifier may be embodied on a physical financial instrument (e.g., a payment device, a payment card, a credit card, a debit card, and/or the like) and/or may be electronic information communicated to the user that the user may use for electronic payment transactions. In some non-limiting embodiments, the account identifier may be an original account identifier, where the original account identifier was provided to a user at the creation of the account associated with the account identifier. In some non-limiting embodiments, the account identifier may be an account identifier (e.g., a supplemental account identifier) that is provided to a user after the original account identifier was provided to the user. For example, if the original account identifier is forgotten, stolen, and/or the like, a supplemental account identifier may be provided to the user. In some non-limiting embodiments, an account identifier may be directly or indirectly associated with an issuer institution such that an account identifier may be a token that maps to a PAN or other type of identifier. Account identifiers may be alphanumeric, any combination of characters and/or symbols, and/or the like.
[0040] As used herein, the term“token” may refer to an identifier that is used as a substitute or replacement identifier for an account identifier, such as a PAN. A token may be used as a substitute or replacement identifier for an original account identifier, such as a PAN. Tokens may be associated with a PAN or other original account
identifier in one or more data structures (e.g., one or more databases and/or the like) such that they may be used to conduct a transaction without directly using the original account identifier. In some non-limiting embodiments, an original account identifier, such as a PAN, may be associated with a plurality of tokens for different individuals or purposes. In some non-limiting embodiments, tokens may be associated with a PAN or other account identifiers in one or more data structures such that they can be used to conduct a transaction without directly using the account identifier, such as a PAN. In some examples, an account identifier, such as a PAN, may be associated with a plurality of tokens for different uses or different purposes.
[0041] As used herein, the term“merchant” may refer to one or more entities (e.g., operators of retail businesses) that provide goods and/or services, and/or access to goods and/or services, to a user based on a transaction, such as a payment transaction. As used herein“merchant system” may refer to one or more computer systems operated by or on behalf of a merchant, such as a server executing one or more software applications. As used herein, the term“product” may refer to one or more goods and/or services offered by a merchant.
[0042] As used herein, a“point-of-sale (POS) device” may refer to one or more devices, which may be used by a merchant to conduct a transaction (e.g., a payment transaction) and/or process a transaction. For example, a POS device may include one or more computers, peripheral devices, card readers, near-field communication (NFC) receivers, radio frequency identification (RFID) receivers, and/or other contactless transceivers or receivers, contact-based receivers, payment terminals, computers, servers, input devices, and/or the like.
[0043] As used herein, a“POS system” may refer to one or more computers and/or peripheral devices used by a merchant to conduct a transaction. For example, a POS system may include one or more POS devices, and/or other like devices that may be used to conduct a payment transaction. A POS system (e.g., a merchant POS system) may also include one or more server computers programmed or configured to process online payment transactions through webpages, mobile applications, and/or the like.
[0044] As used herein, the term“transaction service provider” may refer to an entity that receives transaction authorization requests from merchants or other entities and provides guarantees of payment, in some cases through an agreement between the transaction service provider and an issuer institution. For example, a transaction service provider may include a payment network, such as Visa®, MasterCard®,
American Express®, or any other entity that processes transactions. As used herein “transaction service provider system” may refer to one or more computer systems operated by or on behalf of a transaction service provider, such as a transaction service provider system executing one or more software applications. A transaction service provider system may include one or more processors and, in some non-limiting embodiments, may be operated by or on behalf of a transaction service provider.
[0045] As used herein, the terms“client” and“client device” may refer to one or more computing devices, such as processors, storage devices, and/or similar computer components, that access a service made available by a server. In some non-limiting embodiments, a“client device” may refer to one or more devices that facilitate payment transactions, such as POS devices and/or POS systems used by a merchant. In some non-limiting embodiments, a client device may be any electronic device configured to communicate with one or more networks and/or initiate or facilitate transactions such as, but not limited to, one or more computers, portable computers (e.g., tablet computers), mobile devices (e.g., cellular phones, smartphones, wearable devices, such as watches, glasses, lenses, and/or clothing, PDAs, and/or the like), and/or other like devices. Moreover, a“client” may also refer to an entity, such as a merchant, that owns, utilizes, and/or operates a client device for initiating transactions with a transaction service provider.
[0046] As used herein, the term“server” may refer to one or more computing devices, such as processors, storage devices, and/or similar computer components, that communicate with client devices and/or other computing devices over a network, such as the Internet or private networks, and, in some examples, facilitate communication among other servers and/or client devices. It will be appreciated that various other arrangements are possible. As used herein, the term“system” may refer to one or more computing devices or combinations of computing devices such as, but not limited to, processors, servers, client devices, software applications, and/or other like components. In addition, reference to“a server” or“a processor,” as used herein, may refer to a previously-recited server and/or processor that is recited as performing a previous step or function, a different server and/or processor, and/or a combination of servers and/or processors. For example, as used in the specification and the claims, a first server and/or a first processor that is recited as performing a first step or function may refer to the same or different server and/or a processor recited as performing a second step or function.
[0047] Non-limiting embodiments of the present disclosure are directed to systems, methods, and computer program products for conducting a secure online payment transaction using an integrated circuit card (ICC). In some non-limiting embodiments, a method may include receiving an initiate signal for an online payment transaction from an ICC having a piezoelectric device and a transceiver via a near-field communication (NFC) connection, based on the piezoelectric device providing power to the transceiver, receiving a payment transaction message from the ICC via the NFC connection, the payment transaction message comprising payment account data associated with an account of a user that is encrypted by the ICC, determining that the payment account data associated with the account of the user is encrypted, and communicating the payment transaction message based on determining that the payment account data associated with the account of the user is encrypted.
[0048] In this way, embodiments of the present disclosure may allow payment account data associated with an account of a user to be secured by a merchant involved in the online payment transaction based on the ICC encrypting the payment account data associated with the account of the user before the merchant receives the payment account data.
[0049] Referring now to FIG. 1 , FIG. 1 is a diagram of an example environment 100 in which devices, systems, and/or methods, described herein, may be implemented. As shown in FIG. 1 , environment 100 includes user device 102, integrated circuit card (ICC) 104, issuer system 106, transaction service provider system 108, merchant system 1 10, and network 112. User device 102, integrated circuit card (ICC) 104, issuer system 106, transaction service provider system 108, and/or merchant system 110 may interconnect (e.g., establish a connection to communicate) via wired connections, wireless connections, or a combination of wired and wireless connections.
[0050] User device 102 may include one or more devices capable of receiving information from and/or communicating information to issuer system 106, transaction service provider system 108, and/or merchant system 1 10 via network 1 12. For example, user device 102 may include one or more computing devices, such as one or more computers, one or more portable computers (e.g., tablet computers), one or more mobile devices (e.g., cellular phones, smartphones, wearable devices, such as watches, glasses, lenses, and/or clothing, PDAs, and/or the like), and/or other like devices. In some non-limiting embodiments, user device 102 may be capable of
receiving information (e.g., from ICC 104) via a short-range wireless communication connection, such as an NFC communication connection, an RFID communication connection, a Bluetooth® communication connection, and/or the like, and/or communicating information (e.g., to ICC 104) via a short-range wireless communication connection. In some non-limiting embodiments, user device 102 may include an application associated with user device 102, such as an application stored on user device 102, a mobile application (e.g., a mobile device application, a native application for a mobile device, a mobile cloud application for a mobile device, and/or the like) stored on user device 102, and/or the like. In some non-limiting embodiments, the application associated with user device 102 may be operated by an entity that is the same as the entity associated with ICC 104. For example, the application associated with user device 102 may be operated by a transaction service provider that controls a payment processing network on which ICC 104 may be used or the application associated with user device 102 may be operated by an issuer institution that issued ICC 104.
[0051] ICC 104 may include one or more devices capable of receiving information from user device 102 and/or communicating information to user device 102 via a short- range wireless communication connection. For example, ICC 104 may include an integrated chip card associated with an account of a user. In some non-limiting embodiments, ICC 104 may include a piezoelectric device (e.g., a piezoelectric chip, a solid state piezoelectric chip, and/or the like) to provide power to the circuitry of ICC 104, an NFC device (e.g., an NFC chip) to provide NFC capability, a transceiver, and/or a processing device (e.g., a processor, a computing chip, an integrated circuit, a microprocessor, a digital signal processor (DSP), and/or any processing component, such as a field-programmable gate array (FPGA) or an application-specific integrated circuit (ASIC) etc.), that can be programmed to perform a function, and/or the like) to provide computing and/or encryption capabilities. In some non-limiting embodiments, the processing device may be compliant with the Europay, Mastercard, Visa (EMV) standard or the processing device may not be compliant with the EMV standard. In some non-limiting embodiments, ICC 104 may include a payment device, embodiments of which are described in U.S. Patent Application Publication No. 2017/0124445, which is incorporated by reference herein in its entirety.
[0052] Issuer system 106 may include one or more devices capable of receiving information from and/or communicating information to user device 102, transaction
service provider system 108, and/or merchant system 1 10 via network 1 12. For example, issuer system 106 may include a computing device, such as a server, a group of servers, and/or other like devices. In some non-limiting embodiments, issuer system 106 may be associated with an issuer institution as described herein. For example, issuer system 106 may be associated with an issuer institution that issued a credit account, debit account, credit card, debit card, and/or the like to a user associated with user device 102 and/or ICC 104.
[0053] Transaction service provider system 108 may include one or more devices capable of receiving information from and/or communicating information to user device 102, issuer system 106, and/or merchant system 1 10 via network 1 12. For example, transaction service provider system 108 may include a computing device, such as a server (e.g., a transaction processing server), a group of servers, and/or other like devices. In some non-limiting embodiments, transaction service provider system 108 may be associated with a transaction service provider as described herein. In some non-limiting embodiments, transaction service provider system 108 may be in communication with a data storage device, which may be local or remote to the transaction service provider system 108. In some non-limiting embodiments, transaction service provider system 108 may be capable of receiving information from, storing information in, communicating information to, or searching information stored in a data storage device.
[0054] Merchant system 110 may include one or more devices capable of receiving information from and/or communicating information to user device 102, issuer system 106, and/or transaction service provider system 108 via network 1 12. Merchant system 110 may also include a device capable of receiving information from user device 102 via network 1 12, a communication connection (e.g., an NFC communication connection, an RFID communication connection, a Bluetooth® communication connection, and/or the like) with user device 102, and/or the like, and/or communicating information to user device 102 via the network, the communication connection, and/or the like. For example, merchant system 1 10 may include a computing device, such as a server, a group of servers, a client device, a group of client devices, and/or other like devices. In some non-limiting embodiments, merchant system 1 10 may be associated with a merchant as described herein. In some non-limiting embodiments, merchant system 1 10 may include one or more user devices 102. For example, merchant system 1 10 may include user device 102 that
allows a merchant to communicate information to transaction service provider system 108. In some non-limiting embodiments, merchant system 1 10 may include one or more devices, such as computers, computer systems, and/or peripheral devices capable of being used by a merchant to conduct a payment transaction with a user. For example, merchant system 1 10 may include a POS device and/or a POS system.
[0055] Network 1 12 may include one or more wired and/or wireless networks. For example, network 1 12 may include a cellular network (e.g., a long-term evolution (LTE) network, a third generation (3G) network, a fourth generation (4G) network, a code division multiple access (CDMA) network, etc.), a public land mobile network (PLMN), a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a telephone network (e.g., the public switched telephone network (PSTN)), a private network, an ad hoc network, an intranet, the Internet, a fiber optic-based network, a cloud computing network, and/or the like, and/or a combination of these or other types of networks.
[0056] The number and arrangement of devices and networks shown in FIG. 1 are provided as an example. There may be additional devices and/or networks, fewer devices and/or networks, different devices and/or networks, or differently arranged devices and/or networks than those shown in FIG. 1. Furthermore, two or more devices shown in FIG. 1 may be implemented within a single device, or a single device shown in FIG. 1 may be implemented as multiple, distributed devices. Additionally or alternatively, a set of devices (e.g., one or more devices) of environment 100 may perform one or more functions described as being performed by another set of devices of environment 100.
[0057] Referring now to FIG. 2, FIG. 2 is a diagram of example components of a device 200. Device 200 may correspond to user device 102, and/or one or more devices of issuer system 106, transaction service provider system 108, and/or merchant system 1 10. In some non-limiting embodiments, user device 102, issuer system 106, transaction service provider system 108, and/or merchant system 110 may include at least one device 200 and/or at least one component of device 200. As shown in FIG. 2, device 200 may include bus 202, processor 204, memory 206, storage component 208, input component 210, output component 212, and communication interface 214.
[0058] Bus 202 may include a component that permits communication among the components of device 200. In some non-limiting embodiments, processor 204 may
be implemented in hardware, firmware, or a combination of hardware and software. For example, processor 204 may include a processor (e.g., a central processing unit (CPU), a graphics processing unit (GPU), an accelerated processing unit (APU), etc.), a microprocessor, a digital signal processor (DSP), and/or any processing component (e.g., a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), etc.) that can be programmed to perform a function. Memory 206 may include random access memory (RAM), read only memory (ROM), and/or another type of dynamic or static storage device (e.g., flash memory, magnetic memory, optical memory, etc.) that stores information and/or instructions for use by processor 204.
[0059] Storage component 208 may store information and/or software related to the operation and use of device 200. For example, storage component 208 may include a hard disk (e.g., a magnetic disk, an optical disk, a magneto-optic disk, a solid state disk, etc.), a compact disc (CD), a digital versatile disc (DVD), a floppy disk, a cartridge, a magnetic tape, and/or another type of computer-readable medium, along with a corresponding drive.
[0060] Input component 210 may include a component that permits device 200 to receive information, such as via user input (e.g., a touch screen display, a keyboard, a keypad, a mouse, a button, a switch, a microphone, etc.). Additionally or alternatively, input component 210 may include a sensor for sensing information (e.g., a global positioning system (GPS) component, an accelerometer, a gyroscope, an actuator, etc.). Output component 212 may include a component that provides output information from device 200 (e.g., a display, a speaker, one or more light-emitting diodes (LEDs), etc.).
[0061] Communication interface 214 may include a transceiver-like component (e.g., a transceiver, a separate receiver and transmitter, etc.) that enables device 200 to communicate with other devices, such as via a wired connection, a wireless connection, or a combination of wired and wireless connections. Communication interface 214 may permit device 200 to receive information from another device and/or provide information to another device. For example, communication interface 214 may include an Ethernet interface, an optical interface, a coaxial interface, an infrared interface, a radio frequency (RF) interface, a universal serial bus (USB) interface, a Wi-Fi® interface, a cellular network interface, and/or the like.
[0062] Device 200 may perform one or more processes described herein. Device 200 may perform these processes based on processor 204 executing software
instructions stored by a computer-readable medium, such as memory 206 and/or storage component 208. A computer-readable medium (e.g., a non-transitory computer-readable medium) is defined herein as a non-transitory memory device. A memory device includes memory space located inside of a single physical storage device or memory space spread across multiple physical storage devices.
[0063] Software instructions may be read into memory 206 and/or storage component 208 from another computer-readable medium or from another device via communication interface 214. When executed, software instructions stored in memory 206 and/or storage component 208 may cause processor 204 to perform one or more processes described herein. Additionally or alternatively, hardwired circuitry may be used in place of or in combination with software instructions to perform one or more processes described herein. Thus, embodiments described herein are not limited to any specific combination of hardware circuitry and software.
[0064] The number and arrangement of components shown in FIG. 2 are provided as an example. In some non-limiting embodiments, device 200 may include additional components, fewer components, different components, or differently arranged components than those shown in FIG. 2. Additionally or alternatively, a set of components (e.g., one or more components) of device 200 may perform one or more functions described as being performed by another set of components of device 200.
[0065] Referring now to FIG. 3, FIG. 3 is a flowchart of a non-limiting embodiment of a process 300 for conducting a secure online payment transaction. In some nonlimiting embodiments, one or more of the steps of process 300 may be performed (e.g., completely, partially, etc.) by user device 102. In some non-limiting embodiments, one or more of the steps of process 300 may be performed (e.g., completely, partially, etc.) by another device or a group of devices separate from user device 102, such as ICC 104, issuer system 106 (e.g., one or more devices of issuer system 106), transaction service provider system 108 (e.g., one or more devices of transaction service provider system 108), or merchant system 1 10 (e.g., one or more devices of merchant system 1 10).
[0066] As shown in FIG. 3, at step 302, process 300 includes receiving an initiate signal for an online payment transaction from an integrated circuit card (ICC) via a near-field communication (NFC) connection. For example, user device 102 may receive the initiate signal for the online payment transaction from ICC 104 via the NFC connection between user device 102 and ICC 104. ICC 104 may include a
piezoelectric device and a transceiver and the initial signal is transmitted by ICC 104 and received by user device 102 based on the piezoelectric device providing power to the transceiver of ICC 104. In some non-limiting embodiments, user device 102 may receive the initiate signal from the ICC and the initiate signal is a signal based on an ISO/I EC 14443 standard.
[0067] In some non-limiting embodiments, ICC 104 may establish the NFC connection between user device 102 and ICC 104. For example, ICC 104 may establish the NFC connection between user device 102 and ICC 104 based on ICC 104 transmitting a signal after the piezoelectric device provides power to the transceiver of ICC 104. In some non-limiting embodiments, user device 102 and/or ICC 104 may be associated with a user. For example, a user may have control and the user may operate both user device 102 and ICC 104. In another example, the user may have control and the user may operate one of user device 102 or ICC 104. In such an example, user device 102 may be controlled and operated by a merchant (e.g., a merchant associated with merchant system 1 10). In some non-limiting embodiments, user device 102 may establish the NFC connection between user device 102 and ICC 104. For example, user device 102 may establish the NFC connection between user device 102 and ICC 104 based on user device 102 transmitting a signal that is received by the transceiver of ICC 104.
[0068] In some non-limiting embodiments, user device 102 makes a Hyper Text Transfer Protocol Secure (HTTPS) connection with transaction service provider system 108 via network 1 12 based on user device 102 receiving the initiate signal for the online payment transaction. For example, user device 102 receives the initiate signal from ICC 104 and user device 102 makes an HTTPS connection with transaction service provider system 108 via network 1 12 based on receiving the initiate signal from ICC 104. In some non-limiting embodiments, user device 102 makes an HTTPS connection with transaction service provider system 108 via network 1 12 based on user device 102 providing an input to a website of a merchant. For example, user device 102 may display the website of the merchant, and the website may include a graphical user interface (GUI) element (e.g., an icon, a button, and/or the like) associated with conducting on online payment transaction involving ICC 104. User device 102 may make the HTTPS connection with transaction service provider system 108 via network 1 12 based on user device 102 providing an input to the website of the merchant via the GUI element.
[0069] In some non-limiting embodiments, transaction service provider system 108 may communicate a payment code (e.g., a one-time payment code) associated with the online payment transaction to user device 102. For example, transaction service provider system 108 may communicate the payment code associated with the online payment transaction to user device 102 based on user device 102 making an HTTPS connection with transaction service provider system 108 via network 1 12. The payment code may be a unique payment code for the online payment transaction. In some non-limiting embodiments, transaction service provider system 108 may communicate a unique payment code for each online payment transaction of a plurality of online payment transactions.
[0070] In some non-limiting embodiments, user device 102 may communicate transaction amount data associated with a transaction amount of the online payment transaction to ICC 104. For example, user device 102 may communicate the transaction amount data to ICC 104 based on receiving the initiate signal for the online payment transaction.
[0071] As further shown in FIG. 3, at step 304, process 300 includes receiving a payment transaction message from the ICC via the NFC connection. For example, user device 102 may receive the payment transaction message (e.g., a data packet including information associated with the online payment transaction) from ICC 104 via the NFC connection. In some non-limiting embodiments, user device 102 may receive the payment transaction message from ICC 104 after user device 102 communicates a response signal to the initiate signal for the online payment transaction that is received from ICC 104.
[0072] In some non-limiting embodiments, user device 102 may receive the payment transaction message from ICC 104 after communicating transaction amount data associated with the transaction amount of the online payment transaction to ICC 104. In some non-limiting embodiments, user device 102 may receive the payment transaction message from ICC 104 based on an EMV contactless communication protocol.
[0073] In some non-limiting embodiments, ICC 104 may generate the payment transaction message. For example, ICC 104 may generate the payment transaction message based on determining that an NFC connection has been established with user device 102. In another example, ICC 104 may generate the payment transaction
message based on receiving transaction amount data associated with a transaction amount of the online payment transaction from user device 102.
[0074] In some non-limiting embodiments, the payment transaction message may include payment account data associated with an account of a user (e.g., the account of the user associated with ICC 104). For example, the payment transaction message may include a payment account identifier of the account of the user that has been encrypted with an encryption key associated with an issuer (e.g., an issuer encryption key) and/or a payment account identifier of the account of the user that has been encrypted with the encryption key associated with a transaction service provider (e.g., a transaction service provider encryption key). Additionally or alternatively, the payment transaction message may include account identification data associated with an identity of the user associated with the account and/or an identification of the account of the user. In some non-limiting embodiments, the account identification data may include at least one identifier associated with a name of a user associated with the account, an account identifier of the account of the user, a code of the user associated with the account, and/or the like. In some non-limiting embodiments, the payment transaction message may include an identifier associated with a transaction service provider (e.g., a transaction service provider associated with transaction service provider system 108) to which the payment transaction message is to be communicated.
[0075] In some non-limiting embodiments, ICC 104 may store an issuer encryption key and/or a transaction service provider encryption key. In some non-limiting embodiments, ICC 104 may encrypt a payment account identifier of the account of the user using the issuer encryption key and/ora payment account identifier of the account using the transaction service provider encryption key. In some non-limiting embodiments, ICC 104 may generate a payment transaction message based on encrypting a payment account identifier of the account of the user using the issuer encryption key and/or encrypting the payment account identifier of the account using the transaction service provider encryption key.
[0076] In some non-limiting embodiments, user device 102 may verify an identity of the user associated with the account. For example, user device 102 may verify the identity of the user associated with the account based on account identification data associated with an identity of the user and/or an identification of the account of the user included in the payment account data.
[0077] In some non-limiting embodiments, user device 102 may communicate transaction amount data associated with a transaction amount of the online payment transaction to ICC 104. For example, user device 102 may communicate transaction amount data associated with a transaction amount of the online payment transaction to ICC 104 via the NFC connection based on receiving the initiate signal for the online payment transaction. In some non-limiting embodiments, the payment transaction message may include transaction amount data associated with a transaction amount of the online payment transaction. In some non-limiting embodiments, user device 102 may communicate transaction amount data associated with a transaction amount of the online payment transaction to ICC 104 based on verifying an identity of the user associated with the account.
[0078] In some non-limiting embodiments, ICC 104 may store an issuer encryption key and/or a transaction service provider encryption key in a memory of ICC 104. In some non-limiting embodiments, the issuer encryption key may include a public encryption key (e.g., an issuer public encryption key). Additionally or alternatively, the transaction service provider encryption key may include a public encryption key (e.g., a transaction service provider public encryption key).
[0079] As further shown in FIG. 3, at step 306, process 300 includes determining whether payment account data associated with an account of a user is encrypted. For example, user device 102 may determine whether the payment account data associated with the account of the user included in the payment transaction message is encrypted. In some non-limiting embodiments, user device 102 may determine whether the payment account data associated with the account of the user is encrypted based on verifying the identity of the user.
[0080] In some non-limiting embodiments, user device 102 may determine whether the payment account data is encrypted based on an indication that indicates the payment account data associated with the account of the user included in the payment transaction message is encrypted. For example, user device 102 may determine whether the payment account data is encrypted based on an indication included in the payment transaction message.
[0081] In some non-limiting embodiments, user device 102 may determine that the payment account data is encrypted based on an indication of whether the payment account data associated with the account of the user included in the payment transaction message is encrypted. For example, user device 102 may determine that
the indication indicates that the payment account data associated with the account of the user is encrypted and user device 102 may determine that the payment account data is encrypted based on the indication. In another example, user device 102 may determine that the indication indicates that the payment account data associated with the account of the user is not encrypted and user device 102 may determine that the payment account data is not encrypted based on the indication.
[0082] In some non-limiting embodiments, user device 102 may determine that the payment account data is encrypted based on a data format (e.g., a data format that specifies data is to be provided a location) of the payment transaction message. For example, user device 102 may receive the payment transaction message and determine that the payment transaction message includes data in a specified location of the payment transaction message. User device 102 may determine that the payment account data is encrypted based on determining that the payment transaction message includes the data in the specified location of the payment transaction message.
[0083] As further shown in FIG. 3, at step 308 (“No”), process 300 includes displaying an indication that the payment account data associated with the account of the user is not encrypted. For example, user device 102 may display the indication that the payment account data associated with the account of the user included in the payment transaction message is not encrypted. In some non-limiting embodiments, user device 102 may display the indication that the payment account data is not encrypted based on user device 102 determining that the payment account data is not encrypted. For example, user device 102 may display a graphical user interface element that indicates that the payment account data is not encrypted based on user device 102 determining that the payment account data is not encrypted.
[0084] As further shown in FIG. 3, at step 310 (“Yes”), process 300 includes displaying an indication that the payment account data associated with the account of the user is encrypted. For example, user device 102 may display the indication that the payment account data associated with the account of the user included in the payment transaction message is encrypted. In some non-limiting embodiments, user device 102 may display the indication that the payment account data is encrypted based on user device 102 determining that the payment account data is encrypted. For example, user device 102 may display a graphical user interface element (e.g., an icon, a icon having an appearance associated with a lock, a standard icon, and/or the
like) that indicates that the payment account data is encrypted based on user device 102 determining that the payment account data is encrypted. In some non-limiting embodiments, user device 102 may display a webpage that includes an indication that indicates that the payment account data is encrypted. For example, user device 102 may display a webpage that includes an address (e.g., an address having a certain color font) displayed in an address bar of a browser that indicates that the payment account data is encrypted. In some non-limiting embodiments, user device 102 may include an operating system that causes an application of user device 102 to display an indication that indicates that the payment account data is encrypted. For example, the operating system of user device 102 may cause the application of user device 102 to display the indication that indicates that the payment account data is encrypted based on a device specific standard format.
[0085] As further shown in FIG. 3, at step 312, process 300 includes communicating the payment transaction message. For example, user device 102 may communicate the payment transaction message based on determining that the payment account data associated with the account of the user included in the payment transaction message is encrypted. In some non-limiting embodiments, user device 102 may communicate the payment transaction message to merchant system 110. In some non-limiting embodiments, user device 102 may display a webpage associated with the merchant involved in the online payment transaction and user device 102 may communicate the payment transaction message to a web server serving the webpage associated with the merchant (e.g., a web server of merchant system 1 10 associated with the merchant) involved in the online payment transaction.
[0086] In some non-limiting embodiments, user device 102 may modify the payment transaction message and communicate the payment transaction message based on modifying the payment transaction message. For example, user device 102 may receive the payment transaction message from ICC 104 and user device 102 may modify the payment transaction message to include a payment code (e.g., a payment code received from transaction service provider system 108). User device 102 may communicate the payment transaction message after the payment transaction message has been modified. In some non-limiting embodiments, user device 102 may communicate the payment transaction message to merchant system 1 10 after the payment transaction message has been modified.
[0087] In some non-limiting embodiments, user device 102 may receive a payment transaction message from ICC 104 and user device 102 may calculate a hash value of the transaction amount of the online payment transaction using a hashing algorithm. User device 102 may modify the payment transaction message to include the hash value of the transaction amount of the online payment transaction, the hashing algorithm used to calculate the hash value, and/or a user identifier associated with an identity of the user associated with user device 102 and/or ICC 104. Additionally or alternatively, user device 102 may modify the payment transaction message to include an identifier associated with a transaction service provider (e.g., a transaction service provider associated with transaction service provider system 108) to which the payment transaction message is to be communicated. In some non-limiting embodiments, user device 102 may communicate the payment transaction message after the payment transaction message has been modified. In some non-limiting embodiments, user device 102 may communicate the payment transaction message to merchant system 110 or transaction service provider system 108 after the payment transaction message has been modified.
[0088] In some non-limiting embodiments, merchant system 1 10 may modify the payment transaction message and communicate the payment transaction message based on modifying the payment transaction message. For example, merchant system 110 may receive the payment transaction message from user device 102, and merchant system 1 10 may calculate a hash value of the transaction amount of the online payment transaction using a hashing algorithm. Merchant system 1 10 may modify the payment transaction message to include the hash value of the transaction amount of the online payment transaction, the hashing algorithm used to calculate the hash value, and/or a merchant identifier associated with an identity of the merchant associated with merchant system 1 10. Merchant system 110 may communicate the payment transaction message after the payment transaction message has been modified. In some non-limiting embodiments, merchant system 1 10 may communicate the payment transaction message to transaction service provider system 108 after the payment transaction message has been modified.
[0089] In some non-limiting embodiments, transaction service provider system 108 may validate the payment transaction message. For example, transaction service provider system 108 may validate the payment transaction message based on a payment code included in the payment transaction message and/or transaction
amount data associated with a transaction amount of the online payment transaction, a hash value of a transaction amount of the online payment transaction, and a hashing algorithm used to calculate the hash value included in the payment transaction message. In some non-limiting embodiments, transaction service provider system 108 may validate the payment transaction message based on determining whether the payment transaction message includes a payment code communicated by transaction service provider system 108. For example, transaction service provider system 108 may determine whether the payment transaction message includes a payment code communicated by transaction service provider system 108 to user device 102. If transaction service provider system 108 determines that the payment transaction message includes the payment code, transaction service provider system 108 may validate the payment transaction message. If transaction service provider system 108 determines that the payment transaction message does not include the payment code, transaction service provider system 108 may determine not to validate the payment transaction message. In some non-limiting embodiments, transaction service provider system 108 may forego processing of the payment transaction message based on determining not to validate the payment transaction message.
[0090] In some non-limiting embodiments, transaction service provider system 108 may validate the payment transaction message based on transaction amount data associated with a transaction amount of the online payment transaction, a hash value of the transaction amount of the online payment transaction, and a hashing algorithm used to calculate the hash value that are included in the payment transaction message. For example, transaction service provider system 108 may determine the transaction amount of the online payment transaction based on the transaction amount data associated with the transaction amount of the online payment transaction. Transaction service provider system 108 may calculate a hash value of the transaction amount of the online payment transaction using the hashing algorithm and transaction service provider system 108 may compare the hash value of the transaction amount of the online payment transaction calculated by transaction service provider system 108 using the hashing algorithm to the hash value of the transaction amount of the online payment transaction included in the payment transaction message. If transaction service provider system 108 determines that the hash value of the transaction amount of the online payment transaction calculated by transaction service provider system 108 using the hashing algorithm and the hash value of the transaction
amount of the online payment transaction included in the payment transaction message match, transaction service provider system 108 may validate the payment transaction message. If transaction service provider system 108 determines that the hash value of the transaction amount of the online payment transaction calculated by transaction service provider system 108 using the hashing algorithm and the hash value of the transaction amount of the online payment transaction included in the payment transaction message do not match, transaction service provider system 108 may determine not to validate the payment transaction message.
[0091] In some non-limiting embodiments, transaction service provider system 108 may decrypt payment account data associated with the account of the user that is encrypted using a transaction service provider public encryption key. For example, transaction service provider system 108 may decrypt the payment account data associated with the account of the user using a transaction service provider private key that corresponds to the transaction service provider public key based on transaction service provider system 108 validating the payment transaction message. In some non-limiting embodiments, transaction service provider system 108 may decrypt the payment account data associated with the account of the user to determine a payment account identifier of the account of the user that is encrypted with the transaction service provider public encryption key.
[0092] In some non-limiting embodiments, transaction service provider system 108 may determine an issuer identification number (IIN) of an issuer that issued the account of the user. For example, transaction service provider system 108 may determine the IIN of an issuer that issued the account of the user based on determining a payment account identifier of the account of the user by decrypting the payment account data associated with the account of the user. In some non-limiting embodiments, transaction service provider system 108 may determine an identity of an issuer associated with issuer system 106 based on the IIN of the issuer.
[0093] In some non-limiting embodiments, transaction service provider system 108 may communicate the payment transaction message to issuer system 106. For example, transaction service provider system 108 may communicate the payment transaction message to issuer system 106 based on transaction service provider system 108 determining the identity of the issuer associated with issuer system 106. In some non-limiting embodiments, transaction service provider system 108 may
communicate an authorization request message to issuer system 106 based on determining to process the online payment transaction.
[0094] In some non-limiting embodiments, issuer system 106 receives the payment transaction message and determines to process the online payment transaction based on payment account data associated with the account of the user that is encrypted and included in the payment transaction message. For example, issuer system 106 may receive the payment transaction message and extract payment account data associated with the account of the user that was encrypted using an issuer public encryption key. Issuer system 106 may decrypt the payment account data associated with the account of the user using an issuer private encryption key that corresponds to the issuer public encryption key. Issuer system 106 may determine to process the online payment transaction based on the payment account data associated with the account of the user that was decrypted using the private encryption key. In some nonlimiting embodiments, issuer system 106 may decrypt the payment account data associated with the account of the user to determine a payment account identifier of the account of the user that is encrypted with the transaction service provider public encryption key.
[0095] In some non-limiting embodiments, issuer system 106 may receive transaction data associated with the online payment transaction based on receiving the payment transaction message. For example, issuer system 106 may receive identification data associated with an identification of the merchant involved in the online payment transaction, transaction amount data associated with a transaction amount of the online payment transaction, and/or product data associated with a product involved in the online payment transaction that is included in the payment transaction message.
[0096] In some non-limiting embodiments, issuer system 106 may determine a payment account identifier of the account of the user involved in the online payment transaction, an identification of the merchant involved in the online payment transaction, a transaction amount of the online payment transaction, and/or a product involved in the online payment transaction based on transaction data associated with the online payment transaction included in the payment transaction message. In some non-limiting embodiments, issuer system 106 may process the online payment transaction based on the transaction data associated with the online payment transaction included in the payment transaction message. For example, issuer system
106 may process the online payment transaction based on a payment account identifier of the account of the user, the identification of the merchant involved in the online payment transaction, the transaction amount of the online payment transaction, and/or the product involved in the online payment transaction. In some non-limiting embodiments, issuer system 106 may communicate an authorization response message associated with the online payment transaction to merchant system 110 based on processing the online payment transaction.
[0097] FIGS. 4A-4D are diagrams of an overview of a non-limiting embodiment of an implementation 400 relating to process 300 shown in FIG. 3. As shown in FIGS. 4A-4D, implementation 400 may include user device 402, ICC 404, issuer system 406, transaction service provider system 408, and merchant system 410. In some nonlimiting embodiments, user device 402 may be the same or similar to user device 102, ICC 404 may be the same or similar to ICC 104, issuer system 406 may be the same or similar to issuer system 106, transaction service provider system 408 may be the same or similar to transaction service provider system 108, and/or merchant system 410 may be the same or similar to merchant system 1 10.
[0098] As shown by reference number 415 in FIG. 4A, user device 402 may receive an initiate signal for an online payment transaction from ICC 404 via an NFC connection, based on a piezoelectric device of ICC 404 providing power to a transceiver of ICC 404. As further shown by reference number 420 in FIG. 4A, user device 402 may receive a payment transaction message from ICC 404 via the NFC connection. The payment transaction message may include transaction data associated with an online payment transaction to be processed and payment account data associated with an account of a user associated with ICC 404. In some nonlimiting embodiments, the payment account data associated with the account of the user may be encrypted by ICC 404 using a transaction service provider public encryption key. As further shown by reference number 425 in FIG. 4A, user device 402 may determine that the payment account data associated with the account of the user included in the payment transaction message is encrypted.
[0099] As shown by reference number 430 in FIG. 4B, user device 402 may display an indication that the payment account data associated with the account of the user is encrypted. As further shown by reference number 435 in FIG. 4B, user device 402 may communicate the payment transaction message to merchant system 410 based on determining that the payment account data associated with the account of the user
is encrypted. As further shown by reference number 440 in FIG. 4B, merchant system 410 may receive the payment transaction message and modify the payment transaction message. For example, merchant system 410 may receive the payment transaction message and determine a transaction amount of the online payment transaction based on transaction data associated with the online payment transaction included in the payment transaction message. Merchant system 410 may calculate a hash value of the transaction amount of the online payment transaction using a hashing algorithm. Merchant system 410 may modify the payment transaction message to include the hash value of the transaction amount of the online payment transaction, the hashing algorithm used to calculate the hash value, and/or a merchant identifier associated with an identity of the merchant associated with merchant system 410. As further shown by reference number 445 in FIG. 4B, merchant system 410 may communicate the payment transaction message to transaction service provider system 408 based on modifying the payment transaction message.
[0100] As shown by reference number 450 in FIG. 4C, transaction service provider system 408 may receive the payment transaction message and may validate the payment transaction message. For example, transaction service provider system 408 may receive the payment transaction message and validate the payment transaction message based on a payment code included in the payment transaction message and/or transaction amount data associated with a transaction amount of the online payment transaction, a hash value of the transaction amount of the online payment transaction, and a hashing algorithm used to calculate the hash value included in the payment transaction message. As further shown by reference number 455 in FIG. 4C, transaction service provider system 408 may decrypt the payment account data associated with the account of the user included in the payment transaction message, where the payment account data is encrypted using a transaction service provider public encryption key. For example, transaction service provider system 408 may decrypt the payment account data associated with the account of the user using a transaction service provider private key that corresponds to the transaction service provider public key based on transaction service provider system 408 validating the payment transaction message.
[0101] In some non-limiting embodiments, transaction service provider system 408 may determine an issuer identification number of an issuer that issued the account of the user. For example, transaction service provider system 408 may determine an IIN
of an issuer that issued the account of the user based on determining a payment account identifier of the account of the user by decrypting the payment account data associated with the account of the user. In some non-limiting embodiments, transaction service provider system 408 may determine an identity of an issuer associated with issuer system 406 based on the I IN of the issuer.
[0102] As further shown by reference number 460 in FIG. 4C, transaction service provider system 408 may communicate the payment transaction message to issuer system 406 based on determining an identity of the issuer associated with issuer system 406. As further shown by reference number 465 in FIG. 4C, issuer system 406 may receive the payment transaction message and determine to process the online payment transaction based on payment account data associated with the account of the user that is encrypted and included in the payment transaction message. For example, issuer system 406 may receive the payment transaction message and extract payment account data associated with the account of the user that was encrypted using an issuer public encryption key. Issuer system 406 may decrypt the payment account data associated with the account of the user using an issuer private encryption key that corresponds to the issuer public encryption key. Issuer system 406 may determine to process the online payment transaction based on the payment account data associated with the account of the user that was decrypted using the private encryption key. In some non-limiting embodiments, issuer system 406 may decrypt the payment account data associated with the account of the user to determine a payment account identifier of the account of the user that is encrypted with the transaction service provider public encryption key.
[0103] As shown by reference number 470 in FIG. 4D, issuer system 406 may process the online payment transaction based on the transaction data associated with the online payment transaction included in the payment transaction message. For example, issuer system 106 may process the online payment transaction based on a payment account identifier of the account of the user, an identification of the merchant involved in the online payment transaction, a transaction amount of the online payment transaction, and/or a product involved in the online payment transaction. As further shown by reference number 475 in FIG. 4D, issuer system 406 may communicate an authorization response message for the online payment transaction to merchant system 410 based on processing the online payment transaction.
[0104] Although the disclosure has been described in detail for the purpose of illustration based on what is currently considered to be the most practical and preferred embodiments, it is to be understood that such detail is solely for that purpose and that the disclosure is not limited to the disclosed embodiments, but, on the contrary, is intended to cover modifications and equivalent arrangements that are within the spirit and scope of the appended claims. For example, it is to be understood that the present disclosure contemplates that, to the extent possible, one or more features of any embodiment can be combined with one or more features of any other embodiment.
Claims
1. A computer-implemented method for conducting a secure online payment transaction using an integrated circuit card (ICC), comprising:
receiving, with at least one processor, an initiate signal for an online payment transaction from an ICC having a piezoelectric device and a transceiver via a near-field communication (NFC) connection, based on the piezoelectric device providing power to the transceiver;
receiving, with at least one processor, a payment transaction message from the ICC via the NFC connection, the payment transaction message comprising payment account data associated with an account of a user that is encrypted by the ICC;
determining, with at least one processor, whether the payment account data associated with the account of the user is encrypted;
displaying, with at least one processor, an indication that the payment account data associated with the account of the user is encrypted; and
communicating, with at least one processor, the payment transaction message based on determining that the payment account data associated with the account of the user is encrypted.
2. The computer-implemented method of claim 1 , wherein receiving the initiate signal from the ICC comprises:
receiving the initiate signal from the ICC, wherein the initiate signal is a signal based on an ISO/IEC 14443 standard.
3. The computer-implemented method of claim 1 , further comprising:
verifying an identity of the user based on account identity data associated with an identity of the user included in the payment account data associated with the account of the user,
wherein determining whether the payment account data associated with the account of the user is encrypted comprises:
determining whether the payment account data associated with the account of the user is encrypted based on verifying the identity of the user.
4. The computer-implemented method of claim 1 , further comprising:
communicating transaction amount data associated with a transaction amount of the online payment transaction to the ICC,
wherein receiving the payment transaction message that comprises the payment account data associated with the account of the user comprises:
receiving the payment transaction message after communicating the transaction amount data associated with the transaction amount of the online payment transaction, wherein the payment account data associated with the account of the user comprises:
a payment account identifier of the account of the user that has been encrypted with an issuer encryption key; and
a payment account identifier of the account of the user that has been encrypted with a transaction service provider encryption key.
5. The computer-implemented method of claim 1 , wherein communicating the payment transaction message comprises:
communicating the payment transaction message to a merchant system associated with the merchant involved in the online payment transaction.
6. The computer-implemented method of claim 1 ,
displaying a webpage associated with the merchant involved in the online payment transaction,
wherein communicating the payment transaction message comprises: communicating the payment transaction message to a web server serving the webpage associated with the merchant involved in the online payment transaction.
7. The computer-implemented method of claim 1 , wherein receiving the payment transaction message from the ICC comprises:
receiving the payment transaction message based on a Europay, Mastercard, Visa (EMV) contactless communication protocol.
8. A system for conducting a secure online payment transaction using an integrated circuit card (ICC), comprising:
a computing device having at least one processor, wherein the at least on processor is programmed or configured to:
receive an initiate signal for an online payment transaction from an ICC via a near-field communication (NFC) connection, based on a piezoelectric device of the ICC providing power to a transceiver of the ICC;
receive a payment transaction message from the ICC via the NFC connection, the payment transaction message comprising payment account data associated with an account of a user that is encrypted by the ICC;
determine whether the payment account data associated with the account of the user is encrypted;
display an indication that the payment account data associated with the account of the user is encrypted; and
communicate the payment transaction message based on determining that the payment account data associated with the account of the user is encrypted.
9. The system of claim 8, wherein, when receiving the initiate signal from the ICC, the at least one processor is programmed or configured to:
receive the initiate signal from the ICC, wherein the initiate signal is a signal based on an ISO/IEC 14443 standard.
10. The system of claim 8, wherein the at least one processor is further programmed or configured to:
verify an identity of the user based on account identity data associated with an identity of the user included in the payment account data associated with the account of the user; and
wherein, when determining whether the payment account data associated with the account of the user is encrypted, the at least one processor is programmed or configured to:
determine whether the payment account data associated with the account of the user is encrypted based on verifying the identity of the user.
1 1. The system of claim 8, wherein the at least one processor is further programmed or configured to:
communicate transaction amount data associated with a transaction amount of the online payment transaction to the ICC; and
wherein, when receiving the payment transaction message that comprises the payment account data associated with the account of the user, the at least one processor is programmed or configured to:
receive the payment transaction message after communicating the transaction amount data associated with the transaction amount of the online payment transaction, wherein the payment account data associated with the account of the user comprises:
a payment account identifier of the account of the user that has been encrypted with an issuer encryption key; and
a payment account identifier of the account of the user that has been encrypted with a transaction service provider encryption key.
12. The system of claim 8, wherein, when communicating the payment transaction message, the at least one processor is programmed or configured to:
communicate the payment transaction message to a merchant system associated with the merchant involved in the online payment transaction.
13. The system of claim 8, wherein the at least one processor is further programmed or configured to:
display a webpage associated with the merchant involved in the online payment transaction; and
wherein, when communicating the payment transaction message, the at least one processor is programmed or configured to:
communicate the payment transaction message to a web server serving the webpage associated with the merchant involved in the online payment transaction.
14. The system of claim 8, wherein, when receiving the payment transaction message from the ICC, the at least one processor is programmed or configured to:
receive the payment transaction message based on a Europay, Mastercard, Visa (EMV) contactless communication protocol.
15. A computer program product for conducting a secure online payment transaction using an integrated circuit card (ICC), the computer program product comprising at least one non-transitory computer-readable medium including one or more instructions that, when executed by at least one processor, cause the at least one processor to:
receive an initiate signal for an online payment transaction from an ICC via a near-field communication (NFC) connection, based on a piezoelectric device of the ICC providing power to a transceiver of the ICC;
receive a payment transaction message from the ICC via the NFC connection, the payment transaction message comprising payment account data associated with an account of a user that is encrypted by the ICC;
determine that the payment account data associated with the account of the user is encrypted; and
communicate the payment transaction message based on determining that the payment account data associated with the account of the user is encrypted.
16. The computer program product of claim 15, wherein the one or more instructions further cause the at least one processor to:
verify an identity of the user based on account identity data associated with an identity of the user included in the payment account data associated with the account of the user; and
wherein, when determining whether the payment account data associated with the account of the user is encrypted, the at least one processor is programmed or configured to:
determine whether the payment account data associated with the account of the user is encrypted based on verifying the identity of the user.
17. The computer program product of claim 15, wherein the one or more instructions further cause the at least one processor to:
communicate transaction amount data associated with a transaction amount of the online payment transaction to the ICC; and
wherein, the one or more instructions that cause the at least one processor to receive the payment transaction message, cause the at least one processor to:
receive the payment transaction message after communicating the transaction amount data associated with the transaction amount of the online payment transaction, wherein the payment account data associated with the account of the user comprises:
a payment account identifier of the account of the user that has been encrypted with an issuer encryption key; and
a payment account identifier of the account of the user that has been encrypted with a transaction service provider encryption key.
18. The computer program product of claim 15, wherein, the one or more instructions that cause the at least one processor to communicate the payment transaction message, cause the at least one processor to:
communicate the payment transaction message to a merchant system associated with the merchant involved in the online payment transaction.
19. The computer program product of claim 15, wherein the one or more instructions further cause the at least one processor to:
display a webpage associated with the merchant involved in the online payment transaction; and
wherein, when communicating the payment transaction message, the at least one processor is programmed or configured to:
communicate the payment transaction message to a web server serving the webpage associated with the merchant involved in the online payment transaction.
20. The computer program product of claim 15, wherein, the one or more instructions that cause the at least one processor to receive the payment transaction message from the ICC, cause the at least one processor to:
receive the payment transaction message based on a Europay, Mastercard, Visa (EMV) contactless communication protocol.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/US2018/060734 WO2020101654A1 (en) | 2018-11-13 | 2018-11-13 | System, method, and computer program product for conducting secure online payment transactions |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/US2018/060734 WO2020101654A1 (en) | 2018-11-13 | 2018-11-13 | System, method, and computer program product for conducting secure online payment transactions |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2020101654A1 true WO2020101654A1 (en) | 2020-05-22 |
Family
ID=70730540
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/US2018/060734 Ceased WO2020101654A1 (en) | 2018-11-13 | 2018-11-13 | System, method, and computer program product for conducting secure online payment transactions |
Country Status (1)
| Country | Link |
|---|---|
| WO (1) | WO2020101654A1 (en) |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20070136211A1 (en) * | 2004-03-15 | 2007-06-14 | Brown Kerry D | Financial transactions with dynamic card verification values |
| US20070208671A1 (en) * | 2004-03-15 | 2007-09-06 | Brown Kerry D | Financial transactions with dynamic personal account numbers |
| US20100327054A1 (en) * | 2009-05-15 | 2010-12-30 | Ayman Hammad | Secure communication of payment information to merchants using a verification token |
| US20160307089A1 (en) * | 2011-10-17 | 2016-10-20 | Capital One Services, LLC. | System, method, and apparatus for a dynamic transaction card |
-
2018
- 2018-11-13 WO PCT/US2018/060734 patent/WO2020101654A1/en not_active Ceased
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20070136211A1 (en) * | 2004-03-15 | 2007-06-14 | Brown Kerry D | Financial transactions with dynamic card verification values |
| US20070208671A1 (en) * | 2004-03-15 | 2007-09-06 | Brown Kerry D | Financial transactions with dynamic personal account numbers |
| US20100327054A1 (en) * | 2009-05-15 | 2010-12-30 | Ayman Hammad | Secure communication of payment information to merchants using a verification token |
| US20160307089A1 (en) * | 2011-10-17 | 2016-10-20 | Capital One Services, LLC. | System, method, and apparatus for a dynamic transaction card |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12293365B2 (en) | Authentication based on biometric identification parameter of an individual for payment transaction | |
| US12003508B2 (en) | Systems, methods, and computer program products for authenticating devices | |
| US10861004B2 (en) | One use wearable | |
| EP4081964B1 (en) | Card issuing with restricted virtual numbers | |
| EP3980957B1 (en) | System, method, and computer program product for exchanging transaction data | |
| US12608693B2 (en) | System, method, and computer program product for a contactless ATM experience | |
| US11875348B2 (en) | System, method, and computer program product to ensure data integrity for conducting a payment transaction | |
| US11010482B2 (en) | System and method for secure device connection | |
| CN118103860B (en) | Systems, methods, and computer program products for dynamic cryptographic communication | |
| CN114341909B (en) | System, method and computer program product for authenticating a user who is transacting | |
| US20200160341A1 (en) | System, Computer Program Product, and Method for Authorization Rate Prediction | |
| US20250209457A1 (en) | Apparatus, System, and Method for Enabling Secure Transactions with Haptic Authorization | |
| US20240144258A1 (en) | System, Method, and Computer Program Product for Secure Client Device and Consumer Authentication | |
| US12211045B2 (en) | System, method, and computer program product for virtual accounts based on biometric measurements | |
| WO2025122143A1 (en) | Method, system, and computer program product for securely sharing sensitive information between devices | |
| Wang et al. | METHOD, SYSTEM, AND COMPUTER PROGRAM PRODUCT FOR CAPTURING TEMPORAL DYNAMICS | |
| WO2025095967A1 (en) | System, method, and computer program product for a secure element-based communication interface between a kernel application and a contactless payment application | |
| Witkowski et al. | Method, System, and Computer program product for transaction authentication | |
| WO2025015134A1 (en) | Method, system, and computer program product for processing e-commerce transactions using a computer-generated code | |
| WO2025155282A1 (en) | System and method for multifactor payment | |
| WO2025207339A1 (en) | System, method, and computer program product for initiating pull payments | |
| WO2019172866A1 (en) | System, method, and computer program product for communicating audio data based on an image |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 18939986 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 18939986 Country of ref document: EP Kind code of ref document: A1 |