×

Authentication system and method

DC
  • US 10,148,659 B2
  • Filed: 02/28/2017
  • Issued: 12/04/2018
  • Est. Priority Date: 10/23/2011
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method for a credit or debit card account holder to authorize a resource provider to use a credit or debit card account number to pay a specific merchant for a specific transaction without transmitting or otherwise providing the credit or debit card account number to the merchant, the computer-implemented method comprising the steps of:

  • providing at least one interface adapted to receive and transmit data in communication with a credit or debit card account holder'"'"'s mobile device, a merchant'"'"'s payment application, or both;

    receiving registration information received from the credit or debit card account holder through the at least one interface, the registration information comprising a credit or debit card account holder identifier and at least one credit or debit card account number having an associated unique account identifier wherein the credit or debit card account number and unique account identifier are not the same;

    receiving an authorization request message to pay the specific merchant for the specific transaction from a given debit or credit card account, the authorization request message having been received through the at least one interface and originating from the credit or debit card account holder'"'"'s mobile device and comprising;

    a first merchant identifier;

    a first transaction specific information selected from the group consisting of a first transaction amount and first client reference identifier;

    the credit or debit card account holder identifier; and

    a designated unique account identifier selected from the at least one unique account identifiers; and

    generating a first transaction specific authentication credential associated with the authorization request, whereby the first transaction specific authentication credential comprises a key string wherein the key string is not a temporary credit or debit card account number and does not include or reveal the credit or debit card account number associated with the designated unique account identifier;

    receiving a payment request message from the merchant'"'"'s payment application through the at least one interface, the payment request message comprising;

    a second merchant identifier;

    a second transaction specific information selected from the group consisting of a second transaction amount and second client reference identifier; and

    a second transaction specific authentication credential whereby the second authentication credential was received by the merchant application from the credit or debit card account holder'"'"'s mobile device; and

    validating the credit or debit card account holder'"'"'s request to use the credit or debit card account number associated with the designated unique account identifier for payment to the specific merchant for the specific transaction and authorizing the resource provider to use the credit or debit card account number associated with the designated unique account identifier to pay a specific merchant for a specific transaction without transmitting or otherwise providing the credit or bank account number to the specific merchant by determining that;

    the first merchant identifier matches the second merchant identifier;

    the first transaction specific information matches the second transaction specific information; and

    the first transaction specific authentication credential matches the second transaction specific authentication credential.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×