Mobile network operator authentication protocol

By providing virtual access credentials through the mobile network operator's computer system, the problem of resource access when users do not have credentials is solved, and secure and efficient transaction processing is achieved.

CN116527384BActive Publication Date: 2026-03-20VISA INTERNATIONAL SERVICE ASSOCIATION
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202310615621.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2018-05-14
Filing Date
2019-05-13
Publication Date
2026-03-20
Estimated Expiration
2039-05-13

AI Technical Summary

Technical Problem

A user may want to access resources without the appropriate credentials, such as entering a building or purchasing items.

Method used

By providing virtual access credentials through the mobile network operator's computer system, first and second level authentication is established, allowing users to initiate purchase transactions or access restricted areas using the mobile network operator's computer system associated with their communication devices.

Benefits of technology

This enables users to access resources without traditional credentials, improving transaction efficiency and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116527384B_ABST
    Figure CN116527384B_ABST
Patent Text Reader

Abstract

A method is disclosed and includes receiving, by a server computer, a virtual access credential request for an interaction between a resource provider computer and a communication device operated by a user and associated with a mobile network operator computer system. The method also includes transmitting, by the server computer, the virtual access credential request to an authorizing entity computer, receiving, by the server computer, a virtual access credential from the authorizing entity computer, and transmitting, by the server computer, the virtual access credential to the communication device or the resource provider computer.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a continuation of International Application No. PCT / US2019 / 031998, International Filing Date, May 13, 2019, entitled “Mobile Network Operator Authentication Protocol,” which entered the National Stage at U.S. Patent Application No. 201980032528.8, which claims the benefit of U.S. Provisional Application No. 62 / 671,325, filed May 14, 2018, which is incorporated by reference herein in its entirety for all purposes.

[0002] Related Applications

[0003] This application claims the benefit of U.S. Provisional Application No. 62 / 671,325, filed May 14, 2018, which is incorporated by reference herein in its entirety for all purposes. BACKGROUND

[0004] There are many situations where a user can not have the proper credentials but can wish to have access to a resource. In one example, a person can wish to enter a building but can not have the proper identification card or key card for the building’s access. In another example, a person can wish to purchase an item but can not have an electronic debit or credit card to purchase the item. It is desirable to provide a user with access to a resource when the user does not have access credentials.

[0005] Embodiments of the invention address the above problems and others, singly and collectively. SUMMARY

[0006] Embodiments of the present disclosure relate to methods and systems that provide authentication and authorization for access. In some examples, the methods and systems will establish first and second levels of authentication, where an authorized entity can establish the first authentication and a mobile network operator computer can establish the second authentication. In other examples, the system will allow a user to initiate a purchase transaction or access a restricted area using a mobile network operator computer system associated with the user’s communication device rather than a bank’s account.

[0007] One embodiment of the invention relates to a method or system comprising: receiving, by a server computer, a virtual access credential request for an interaction between a resource provider computer and a communication device operated by a user and associated with a mobile network operator computer system; transmitting, by the server computer, the virtual access credential request to an authorizing entity computer; receiving, by the server computer, a virtual access credential from the authorizing entity computer; transmitting, by the server computer, the virtual access credential to the communication device or the resource provider computer; receiving, by the server computer, an authorization request message comprising the virtual access credential, wherein the authorization request message requests authorization for the interaction; forwarding, by the server computer, the authorization request message to the authorizing entity computer; receiving, by the server computer, an authorization response message from the authorizing entity computer; and forwarding, by the server computer, the authorization response message to the resource provider computer, wherein the authorizing entity computer subsequently completes the interaction with the mobile network operator computer system.

[0008] Another embodiment of the invention relates to: receiving, by an authorizing entity computer, a virtual access credential request for an interaction between a resource provider computer and a communication device operated by a user and associated with a mobile network operator computer system; generating, by the authorizing entity computer, a virtual access credential associated with an approved amount; transmitting, by the authorizing entity computer, the virtual access credential to a processing network computer, wherein the virtual access credential is forwarded to the communication device or the resource provider computer; receiving, by the authorizing entity computer, an authorization request message comprising the virtual access credential, wherein the authorization request message requests authorization for the interaction; comparing a total amount of the authorization request to the approved amount of the virtual access credential; determining, by the authorizing entity computer, an approval or denial of the authorization request message based on the comparison; generating, by the authorizing entity computer, an authorization response message based on the approval or denial of the authorization request message; forwarding, by the server computer, the authorization response message to the processing network computer; and subsequently forwarding a completion message to the mobile network operator computer system based on the approval or denial of the authorization request message.

[0009] Other embodiments relate to server computers and systems adapted to perform the above and other methods.

[0010] These and other embodiments of the invention are described in further detail below. BRIEF DESCRIPTION OF DRAWINGS

[0011] Figure 1 A block diagram illustrating an authentication and authorization system according to an embodiment of the invention.

[0012] Figure 2 A block diagram of a processing network server computer is shown in accordance with an embodiment of the application.

[0013] Figure 3 A block diagram of a resource provider computer is shown in accordance with an embodiment of the application.

[0014] Figure 4 A block diagram of an authorized entity computer is shown in accordance with an embodiment of the application.

[0015] Figure 5 A block diagram of a mobile network operator computer system is shown in accordance with an embodiment of the application.

[0016] Figure 6 A block diagram of a communication device is shown in accordance with an embodiment of the application. DETAILED DESCRIPTION

[0017] Before discussing the embodiments of the application, further description of some terms can be helpful in understanding the embodiments of the application.

[0018] A "virtual access credential" can be a credential that has a limited lifetime of use or a limited number of uses. As described further below, a virtual access credential can have the form or attributes of a credential or payment credential, a token or a payment token. A virtual access credential can be used to obtain a resource such as a good, a service, a location, and secure data. A virtual access credential can also be in any suitable form, including letters or numbers (e.g., a 16-digit number).

[0019] A "credential" can be any suitable information that serves as reliable evidence of value, ownership, identity, or entitlement. A credential can be a string of numbers, letters, or any other suitable characters, as well as any object or document that can be used as confirmation. Examples of credentials include value credentials such as payment credentials, identification cards, authentication documents, access cards, passwords and other login information, and the like.

[0020] A "payment credential" can include any suitable information associated with an account (e.g., a payment account and / or a payment device associated with an account). Such information can be directly related to an account or can be derived from information related to an account. Examples of account information can include a PAN (primary account number or "account number"), a user name, an expiration date, and verification values such as CVV, dCVV, CVV2, dCVV2, and CVC3 values.

[0021] A "digital wallet" can include an electronic device that allows an individual to conduct e-commerce transactions. The digital wallet can store user profile information, payment credentials, bank account information, one or more digital wallet identifiers, and the like, and can be used in various transactions, such as but not limited to e-commerce, social networking, peer-to-peer payments, mobile commerce, proximity payments, gaming, and the like, for retail purchases, digital good purchases, utility payments, purchases of games or game credits from a gaming website, transfers of funds between users, and the like. A digital wallet can be designed to simplify the purchase and payment process. A digital wallet can allow a user to load one or more payment cards onto the digital wallet so that payments can be made without the need to enter an account number or present a physical card.

[0022] A "token" can be a substitute value for a credential. A token can be a string of numbers, letters, or any other suitable characters. Examples of tokens include payment tokens, access tokens, personal identification tokens, and the like.

[0023] A "payment token" can include an identifier for a payment account that is a substitute for an account identifier, such as a primary account number (PAN). For example, a payment token can include a series of alphanumeric characters that can be used as a substitute for an original account identifier. For example, the token "4900 0000 0000 0001" can be used in place of a PAN "41470900 0000 1234." In some embodiments, a payment token can be "reserved format" and can have a numeric format consistent with account identifiers used in existing transaction processing networks (e.g., the ISO 8583 financial transaction message format). In some embodiments, a payment token can be used in place of a PAN to initiate, authorize, settle, or resolve a payment transaction, or to represent an original credential in other systems that would normally provide the original credential. In some embodiments, a payment token can be generated such that a recovery of the original PAN or other account identifier from the token value is not computationally possible. Further, in some embodiments, the token format can be configured to allow an entity receiving the token to identify it as a token and to recognize the entity that issued the token.

[0024] "Tokenization" is the process of replacing data with substitute data. For example, a payment account identifier (e.g., a primary account number (PAN)) can be tokenized by replacing the primary account identifier with a substitute number (e.g., a token) that can be associated with the payment account identifier. Further, tokenization can apply to any other information that can be replaced with a substitute value (i.e., a token). Tokenization improves transaction efficiency and security.

[0025] A "virtual access credential request message" can be an electronic message that requests a virtual access credential. The virtual access credential request message can include information that can be used to identify a payment account or digital wallet, and / or information used to generate a virtual access credential. For example, the virtual access credential request message can include a payment credential, mobile device identification information (e.g., a phone number or MSISDN), a digital wallet identifier, information identifying a tokenization service provider, a merchant identifier, a cryptogram, and / or any other suitable information. Information included in the virtual access credential request message can be encrypted (e.g., using an issuer-specific key). In some examples, the virtual access credential request message can include an approved amount (e.g., a debit amount, etc.) provided to the user on behalf of the authorizing entity computer, and the approved amount is stored in a user profile at the authorizing entity computer for comparison to a total amount included in an authorization request message at a later time.

[0026] A "virtual access credential response message" can be a message that responds to a virtual access credential request. The virtual access credential response message can include an indication that the virtual access credential request was approved or declined. The virtual access credential response message can also include a virtual access credential, mobile device identification information (e.g., a phone number or MSISDN), a digital wallet identifier, information identifying a tokenization service provider, a resource provider identifier, a cryptogram, and / or any other suitable information. Information included in the virtual access credential response message can be encrypted (e.g., using an issuer-specific key).

[0027] A "user" can include an individual. In some embodiments, a user can be associated with one or more personal accounts and / or mobile devices. In some embodiments, a user can also be referred to as a cardholder, account holder, or consumer.

[0028] An "authorization request message" can be an electronic message that requests authorization for a transaction. In some embodiments, an authorization request message is sent to a transaction processing computer and / or an issuer of a payment card to request authorization for a transaction. An authorization request message according to some embodiments can comply with ISO 8583, which is a standard for systems that exchange electronic transaction information associated with payments made by users using payment devices or payment accounts. An authorization request message can include an issuer account identifier that can be associated with a payment device or payment account. An authorization request message can also include additional data elements corresponding to "identification information," including (by way of example only): a service code, a CVV (card verification value), a dCVV (dynamic card verification value), a PAN (primary account number or "account number"), a payment token, a user name, an expiration date, and the like. An authorization request message can also include "transaction information," such as any information associated with a current transaction, such as a total transaction amount, a merchant identifier, a merchant location, an acquirer bank identification number (BIN), a card acceptor ID, information identifying items being purchased, and the like, as well as any other information that can be used to determine whether to identify and / or authorize a transaction.

[0029] An "authorization response message" can be a message in response to an authorization request. In some cases, an authorization response message can be an electronic message reply to an authorization request message generated by an issuing financial institution or a transaction processing computer. By way of example only, an authorization response message can include one or more of the following status indicators: approved - the transaction was approved; declined - the transaction was not approved; or call center - more information is pending a response, the merchant must call a toll-free authorization phone number. An authorization response message can also include an authorization code, which can be a code returned by a credit card issuing bank to a merchant's access device (e.g., a POS device) in response to an authorization request message in an electronic message (directly or through a transaction processing computer) indicating that a transaction was approved. The code can serve as proof of authorization.

[0030] A "server computer" can include a powerful computer or cluster of computers. For example, the server computer can be a large mainframe, a minicomputer cluster, or a group of servers acting in concert. In one example, the server computer can be a database server coupled to a Web server. The server computer can include one or more computational apparatuses and can use any of a number of computer architectures, arrangements, and compilations to serve requests from one or more client computers.

[0031] Embodiments of this disclosure include methods and systems for authenticating and authorizing access. In some examples, the system establishes first and second levels of authentication, where an authorizing entity can establish the first authentication and a mobile network operator's computer can establish the second authentication. In other examples, the system allows a user to initiate a purchase transaction or access a restricted area using a mobile network operator's computer system associated with the user's communication device, rather than a bank account.

[0032] Figure 1 A block diagram of an authentication and authorization system according to an embodiment of the present invention is shown. As shown, the system may include a communication device 102, a resource provider computer 110, a transmission computer 115, a processing network server computer 120, an authorization entity computer 130, and a mobile network operator computer system 140.

[0033] Figure 1 The system may include a network server computer 120. Figure 1 Example processing network server computer 120, such as Figure 2 As shown. The processing network server computer 120 may include one or more server computers, as well as a data processing subsystem, a network, and operations for supporting and delivering authorization services, exception file services, and clearing and settlement services. An exemplary processing network may include VisaNet. TM For example, VisaNet TM The processing network can handle credit card transactions, debit card transactions, and other types of commercial transactions. VisaNet TM Specifically, this includes the VIP system (Visa Integrated Payment System) for processing authorization requests and the Base II system for performing clearing and settlement services. The processing network can use any suitable wired or wireless network, including the Internet.

[0034] The computer that processes the network server may include, for example Figure 2 The diagram shows subsystems or components interconnected via system bus 210. This interconnection via system bus 210 allows processor 212 to communicate with each subsystem and control the execution of instructions from system memory 214. System memory 214 may embody a computer-readable medium. Communication interface 216 may be used to connect the server computer to a wide area network, such as the Internet, or other I / O devices associated with the computer system. System bus 210 may also connect one or more modules or engines embodying in memory, including communication module 230, virtual access credential module 232, and / or interaction engine 234.

[0035] The communication module 230 can be configured to... Figure 1The entire system shown receives and transmits electronic messages from other computers and devices. For example, communication module 230 can be configured to receive virtual access credential requests from communication device 102, transmit virtual access credential requests to authorized entity computer 130, receive and transmit virtual access credentials, receive and transmit authorization request messages, and receive and transmit authorization response messages.

[0036] The virtual access credential module 232 can be configured to parse a virtual access credential request to determine a user identifier associated with the communication device 102 operated by the user. The user identifier may correspond to the mobile network operator's computer system 140 to receive additional information associated with the user identifier. This additional information may include order history, location history, or user profile information of the communication device registered in the mobile network operator's computer system 140. The virtual access credential module 232 can determine whether to generate a virtual access credential based on the additional information.

[0037] Interaction engine 234 can be configured to identify authorized entity computer 130 based on virtual access credentials and route authorization request messages to the appropriate authorized entity computer 130. For example, the authorization request message may include credentials, including a Bank Identifier Number (BIN) uniquely identifying one of a plurality of authorized entity computers. Interaction engine 234 can associate the received BIN with appropriate routing information to the authorized entity computer and enable the transmission of the authorization request message to the appropriate authorized entity computer.

[0038] Figure 1 The system may also include resource provider computer 110. Figure 1 Example resource provider computer 110, such as Figure 3 As shown. A resource provider computer can be an entity that can provide resources such as goods, services, information, and / or access. Examples of resource providers include merchants, data providers, transportation agents, government entities, site and residential operators, etc. Merchants can typically be entities that participate in transactions and are able to sell goods or services or provide access to goods or services.

[0039] Resource provider computers may include, for example Figure 3The diagram shows subsystems or components interconnected via system bus 310. This interconnection via system bus 310 allows processor 312 to communicate with each subsystem and control the execution of instructions from system memory 314. System memory 314 may embody a computer-readable medium. Communication interface 316 may be used to connect the resource provider computer to a wide area network, such as the Internet, or other I / O devices associated with the resource provider computer. System bus 310 may also connect one or more modules or engines embodying in memory, including communication module 330, request engine 332, and / or interaction engine 334. One or more databases may store information received, maintained, and transmitted by the resource provider computer, including item database 350.

[0040] The communication module 330 can be configured to... Figure 1 The entire system shown receives and transmits electronic messages from other computers and devices. For example, the communication module can be configured to receive requests for items or services at the ordering interaction site 112, receive instructions for interactions at the interaction site 112 (e.g., selecting the "Bill me" button, etc.), transmit virtual access credential requests to the processing web server computer 120, and transmit authorization request messages to the delivery computer 115.

[0041] Request engine 332 can be configured to generate and communicate with communication device 102 and interactive site 112. Figure 3 A virtual access credential request associated with an interaction between (not shown in the image) and a communication device operated by the user. The virtual access credential request may include information associated with the communication device 102. In some embodiments, the virtual access credential may correspond to an approved amount associated with a request for access to a resource requested by the communication device 102. The amount may be approved by the authorizing entity computer 130.

[0042] The request engine 332 can also be configured to generate an authorization request message, which includes a virtual access credential received from the authorizing entity computer 130 and a total amount associated with the resource requested by the communication device 102. The request engine 332 can associate the authorization request message with one or more resources (e.g., items or services) provided by the resource provider computer 110. Resources may correspond to item descriptions, value amounts, and other relevant information stored in the item database 350.

[0043] The interaction engine 334 can be configured to allow access to resources after authentication of virtual access credentials and authorization associated with an authorization response message including approval confirmation from the authorized entity computer 130.

[0044] The resource provider computer 110 can also be associated with an access device. The access device can be operated by the resource provider and can include any suitable device that provides access to a remote system. The access device can also be used to communicate with the resource provider computer 110, a transaction processing computer, an authentication computer, or any other suitable system. The access device can generally be located in any suitable location, such as at a location of the resource provider. The access device can take any suitable form. Some examples of access devices include POS or point of sale devices (e.g., POS terminals), cellular phones, PDAs, personal computers (PCs), tablet PCs, hand-held specialized readers, set-top boxes, electronic cash registers (ECRs), automated teller machines (ATMs), virtual cash registers (VCRs), kiosks, security systems, access systems, and the like. The access device can use any suitable contact or contactless mode of operation to send or receive data from or associated with a mobile communication device or a payment device. In some embodiments in which the access device can include a POS terminal, any suitable POS terminal can be used and can include a reader, a processor, and a computer- readable medium. The reader can include any suitable contact or contactless mode of operation. For example, an exemplary card reader can include a radio frequency (RF) antenna, an optical scanner, a bar code reader, or a magnetic stripe reader to interact with a payment device and / or mobile device. In some embodiments, a cellular phone, tablet, or other specialized wireless device used as a POS terminal can be referred to as a mobile point of sale or "mPOS" terminal.

[0045] Figure 1 The system of FIG. 1 can also include a transport computer 115. The transport computer 115 can be operated by an acquirer or a business entity (e.g., a commercial bank) that has a business relationship with a particular merchant or other entity. Some entities can perform both issuer and acquirer functions. Some embodiments can encompass such single entity issuer-acquirers.

[0046] Figure 1 The system of FIG. 1 can also include an authorization entity computer 130. An example authorization entity computer 130 is shown in FIG. 1. Figure 4 The authorization entity can be the entity that authorizes the request. Examples of authorization entities can be an issuer, a government agency, a file repository, an access administrator, a bank, etc. The authorization entity computer 130 can generally refer to a business entity (e.g., a bank or issuer computer) that maintains an account of a user.

[0047] The authorization entity computer can include a processor 132, a memory 134, and a communication interface 136, as shown in FIG. 1. Figure 4The illustrated subsystems or components are interconnected via system bus 410. Interconnection via the system bus 410 allows the processor 412 to communicate with each subsystem and to control the execution of instructions from system memory 414. The system memory 414 can embody a computer-readable medium. The communication interface 416 can be used to connect the authorizing entity computer to a wide area network, such as the Internet, or other I / O devices associated with the authorizing entity computer. The system bus 410 can also connect one or more modules or engines embodied in memory, including a communication module 430, a virtual access credential module 432, and / or an authorization module 434. One or more databases can store information received, maintained, and transmitted by the authorizing entity computer, including a credential database 450.

[0048] The communication module 430 can be configured to receive and transmit electronic messages from other computers and devices throughout the system illustrated in Figure 1 FIG. 1. For example, the communication module 430 can be configured to receive virtual access credential requests from the processing network server computer 120, transmit virtual access credentials to the processing network server computer 120, receive authorization request messages, generate and transmit authorization response messages, and transmit electronic messages associated with clearing and settlement after an interaction has occurred between the communication device 102 and the resource provider computer 110.

[0049] The virtual access credential module 432 can be configured to generate virtual access credentials and issue virtual access credentials to a communication device 102, such as a cellular phone, smart card, tablet, or laptop computer. The virtual access credential can include a user identifier associated with the communication device operated by a user. The user identifier can correspond to a user account registered with the mobile network operator computer system 140. The virtual access credential can also correspond to an approved amount to subscribe to resources provided by the resource provider computer 110.

[0050] The authorization module 434 can be configured to determine whether to allow or deny access to resources provided by the resource provider computer 110 based at least in part on comparing a first virtual access credential provided in response to a virtual access credential request to a second virtual access credential received with an authorization request message. The virtual access credential can be stored in the credential database 450 and associated with the communication device 102 or the user.

[0051] The authorization module 434 can also be configured to determine whether to allow or deny access to resources provided by the resource provider computer 110 based at least in part on comparing a total amount included in the authorization request message to an approved amount provided to the user on behalf of the authorizing entity computer. The approved amount can be stored in a user profile and virtual access credential at the authorizing entity computer 130.

[0052] Figure 1 The system of FIG. 1 can also include a mobile network operator computer system 140. An example mobile network operator computer system 140 is shown in FIG. 2. The mobile network operator computer system 140 can include an entity that provides mobile network services for mobile devices, including the communication device 102. The mobile network operator computer system 140 can perform radio spectrum allocation, wireless network infrastructure, and the like. The mobile network operator computer system 140 can identify mobile devices by user accounts associated with one or more corresponding users of the mobile devices. The mobile network operator computer system 140 can also provide invoices or bills to users in exchange for providing the mobile network services. Figure 5

[0053] The mobile network operator computer system can include subsystems or components interconnected via a system bus 510 as shown in FIG. 2. The interconnection via the system bus 410 allows the processor 512 to communicate with each subsystem and control the execution of instructions from the system memory 514. The system memory 514 can embody a computer-readable medium. The communication interface 516 can be used to connect the resource provider computer to a wide area network, such as the Internet, or other I / O devices associated with the resource provider computer. The system bus 510 can also connect one or more modules or engines embodied in memory, including a communication module 530, an interaction engine 532, and / or a network operations engine 534. One or more databases can store information received, maintained, and transmitted by the mobile network operator computer system, including a user database 550. Figure 5 The communication module 530 can be configured to receive and transmit electronic messages from other computers and devices throughout the system shown in FIG. 2. For example, the communication module 530 can be configured to provide mobile network services to the communication device 102, receive communications from the communication device 102 including payment of invoices for the mobile network services, and receive and transmit communications with the authorization entity computer 130, including messages associated with the settlement and clearing process.

[0054] Figure 1

[0055] ​​​The interaction engine 532 can be configured to determine order history, location history, or user profile information associated with the communication device 102 through the process of providing mobile network communication services. For example, a user may periodically subscribe to mobile network communication services from a mobile network operator's computer system 140. The history of service subscriptions can be received and processed by the profile engine 142 and stored in the user database 550. In some examples, the communication device 102 may transmit location messages, which are received by the mobile network operator's computer system 140 and stored in the user database 550, to generate a history of location information associated with the communication device 102.

[0056] The network operation engine 534 can be configured to perform radio spectrum allocation, wireless network infrastructure, etc. The network operation engine 534 can identify the communication device 102 through user accounts associated with one or more corresponding users of the device.

[0057] Figure 1 The system may include a communication device 120. Figure 1 Example communication device 102 Figure 6 As shown. A communication device can include any suitable electronic device operable by a user, which may also provide remote communication capabilities with a network. A mobile communication device can be an example of a communication device that can be easily transmitted. Examples of remote communication capabilities include the use of mobile phone (wireless) networks, wireless data networks (e.g., 3G, 4G, or similar networks), Wi-Fi, Wi-Max, or any other communication medium that provides access to networks such as the Internet or a private network. Examples of mobile communication devices include mobile phones (e.g., cellular phones), PDAs, tablets, netbooks, laptops, personal music players, handheld dedicated readers, etc. Other examples of mobile communication devices include wearable devices such as smartwatches, fitness trackers, anklets, rings, earrings, etc., and automobiles with remote communication capabilities. In some embodiments, a mobile communication device can act as a payment device (e.g., the mobile communication device can store and be able to transmit payment credentials for transactions).

[0058] The payment device may be incorporated into communication device 102 and include any suitable device that can be used to conduct financial transactions to provide payment credentials to merchants. The payment device may be a software object (e.g., a payment application associated with a credit, debit, or prepaid account), a hardware object, or a physical object. The payment device may be associated with, for example, monetary value, a discount, or a store credit value, and may be associated with an entity such as a bank, merchant, payment processing network, or individual.

[0059] Figure 6The communication device 600 can include a processor 602 and a body 614. It can also include a computer readable medium 604. The computer readable medium 604 can be in the form of (or can include) a memory that stores transaction data, and can be in any suitable form including a magnetic strip, a memory chip, etc. The memory can store information such as financial information, including bank account information, account balance information, expiration dates, or consumer information such as the name of the account holder, date of birth, etc. Any of this information can be transmitted by the communication device 600 via an antenna 618.

[0060] The communication device 600 can further include a contactless element 612, which can be implemented in the form of a semiconductor chip or other data storage element having an associated wireless transfer (e.g., data transmission) element such as the antenna 618. The contactless element 612 can be associated with or embedded within the communication device 600. Data or control instructions can be transmitted via the cellular network and can be applied to the contactless element 612 by means of a contactless element interface (not shown). The contactless element interface can be used to allow data and / or control instructions to be exchanged between the device circuitry (and thus the cellular network) and the optional contactless element.

[0061] The contactless element 612 can be capable of transferring and receiving data using near field communication (NFC) according to a standardized protocol or data transfer mechanism (e.g., ISO 14443 / NFC). The near field communication functionality can include short-range communication functionality, including RFID, Bluetooth, infrared, or other data transfer functionality that can be used to exchange data between the communication device and an interrogating device. Thus, the communication device can be capable of transmitting and transferring data and / or control instructions over the cellular network through near field communication.

[0062] The communication device can also include a processor 602 for processing the functions of the communication device. The communication device can also include a display 606 that allows the user to see information and messages via a user interface. The communication device can further include an input element 608 that allows the user to provide information to the communication device, a speaker 610 that allows the user to make secure voice communications, music, etc. The communication device can also include a microphone 616 that allows the user to transmit their voice or other sound files through the communication device. The communication device can also include an antenna 618 for wireless data transfer and transmission.

[0063] Returning to Figure 1Step 1, the user-operated communication device 102 can interact with the resource provider computer 110. The resource provider computer 110 can provide an interaction site 112 to receive one or more interactions from the communication device 102. In some examples, the resource provider computer 110 can provide an application that can be stored in the communication device 102 and executed by the communication device 102. The communication device 102 can present the application at a display of the communication device 102 to receive interactions from a user at the communication device 102.

[0064] The interaction site 112 (or the application) can provide one or more items or services for purchase. The communication device 102 can interact with the one or more items or services, adding the items to an electronic cart accompanying the interaction site 112 of the resource provider computer 110. The interaction site 112 (or the application) can also provide a "bill me" button. The "bill me" button, when selected, can initiate a transaction with the processing network server computer 120 for the items included in the electronic cart.

[0065] The resource provider computer 110 can receive the interaction from the communication device 102 through the "bill me" button provided at the interaction site 112. For example, after a user selects an item to add to an electronic cart on the resource provider computer 110, the user can select the button to initiate a purchase of the item. The interaction can be associated with a total value of the items added to the electronic cart.

[0066] In some examples, the user can not have a pre-existing credit or debit account, or can not be able to use the pre-existing credit or debit account for this particular purchase. In these examples, the user associated with the communication device 102 can not have a user account with the authorization entity computer. Thus, when the "bill me" button is provided at the interaction site 112 and the button is selected, the user can not correspond to a credit or debit account to complete the purchase of the item or service.

[0067] At Step 2, once the "bill me" button is selected via the communication device 102, a virtual access credential request is sent from the resource provider computer 110 (via the interaction site 112 or the application stored at the communication device 102) to the processing network server computer 120. In some examples, the virtual access credential request can identify the user corresponding to the communication device 102 to support a request for authorization of the interaction (e.g., to complete a transaction for the item or service in the electronic cart when the "bill me" button is activated, etc.). In some examples, the total value of the items added to the electronic cart can be included in the virtual access credential request.

[0068] Upon receiving the request, the processing network server computer 120 can initiate generation of a virtual access credential. The virtual access credential can not be tied to a pre-existing account of the user prior to the transaction. In some cases, the user can be considered "unbanked" and can not have any type of bank account with any bank, but can have an account with the mobile network operator computer system 140.

[0069] At step 3, the processing network server computer 120 can communicate with the authorizing entity computer 130, which can then generate the virtual access credential. The virtual access credential can be associated with the mobile network operator computer system 140 associated with the user operating the communication device 102, but not the user themselves. For example, the authorizing entity computer 130 can extend the business credit to the mobile network operator computer system 140, but not the user. The mobile network operator computer system 140 can be the party that conducts the transaction on behalf of the user.

[0070] Prior to generating the virtual access credential, the authorizing entity computer 130 can execute a set of rules associated with the user to determine whether the virtual access credential can be issued to the mobile network operator computer system 140. For example, the authorizing entity computer 130 can determine whether the mobile network operator computer system 140 provided an "opt-in" communication to offer credit to its users. In some examples, an "opt-out" communication can identify that the mobile network operator computer system 140 will not support issuance of virtual access credentials to its users.

[0071] The mobile network operator computer system 140 can also execute a set of rules associated with the user to determine whether the virtual access credential can be issued to the user operating the communication device associated with the mobile network operator computer system 140. The mobile network operator computer system 140 can identify suitable information, such as device information of the communication device 102, any data the mobile network operator computer system 140 or the resource provider computer 110 can have about the user, historical orders or payment information, etc.

[0072] In some examples, the mobile network operator computer system 140 can execute a set of rules associated with the user to determine whether the virtual access credential can be issued. The authorizing entity computer 130 can correspond with the mobile network operator computer system 140 to receive a determination by the mobile network operator computer system 140 as to whether to issue the virtual access credential to the user based on executing the set of rules associated with the user. Based on the determination by the mobile network operator computer system 140, the authorizing entity computer 130 can generate the virtual access credential.

[0073] The virtual access credential can include a reusable or one-time use account identifier. When the virtual access credential is reusable, the credential can be stored in and associated with a user profile at the mobile network operator computer system 140 and used for more than one transaction. When the virtual access credential is a one-time use account identifier, a virtual access credential request can be transmitted between the resource provider computer 110 and the processing network server computer 120 for each potential transaction. In either example, the virtual access credential can be stored in the credential database 450 of the authorizing entity computer 130 for retrieval and use during the authorization process. In some examples, the virtual access credential can be stored with a user account at the authorizing entity computer 130. The user account can include a total value requested through the virtual access credential.

[0074] At step 4, the authorizing entity computer 130 can provide the virtual access credential to the processing network server computer 120. The processing network server computer 120 can obtain the virtual access credential from the authorizing entity computer 130.

[0075] At step 5, the processing network server computer 120 can transmit the virtual access credential from the authorizing entity computer 130 to the resource provider computer 110 or the communication device 102 for processing. Via its mobile application or interactive site 112, the resource provider computer 110 can process a transaction using the virtual access credential. For example, the resource provider computer 110 can generate an authorization request message that includes the virtual access credential. The resource provider computer 110 can include the virtual access credential in the authorization request message to initiate a transaction for items and services associated with the "bill me" button and located in an electronic cart.

[0076] In some examples, the "bill me" button is located at an application stored at the communication device 102. The virtual access credential can be provided to the application of the communication device 102 and the application can generate an authorization request message that includes the virtual access credential originating from the application at the communication device 102. The authorization request message can be transmitted from the communication device 102 to the resource provider computer 110.

[0077] At step 6, the resource provider computer 110 can transmit the authorization request message that includes the virtual access credential to the transport computer 115. The transport computer 115 can transmit the authorization request message to the processing network server computer 120. The processing network server computer 120 can receive the authorization request message that includes the virtual access credential, where the authorization request message requests authorization for an interaction.

[0078] In some examples, the processing network server computer 120 can identify the authorizing entity computer 130 based on resolving the virtual access credential. For example, the virtual access credential can include a substring that uniquely identifies the authorizing entity of the processing network server computer 120. The substring can be similar to a bank identification number (BIN) stored in the processing network server computer 120. When the substring of the virtual access credential matches the stored information, the processing network server computer 120 can identify the location of the appropriate authorizing entity to transmit the authorization request message.

[0079] At step 7, the processing network server computer 120 can forward the authorization request message to the authorizing entity computer 130. The authorizing entity computer 130 can determine whether to approve or decline the transaction. For example, during the approval or decline process, the authorizing entity computer 130 can compare the transaction value included in the authorization request message to the total value included in the virtual access credential and stored for the user account. When the transaction value is within a threshold range of the total value, the transaction can be approved. Otherwise, the transaction can be declined because the transaction value included in the authorization request message for the transaction does not match the total value included in the virtual access credential request.

[0080] At step 8, the authorizing entity computer 130 can generate an authorization response message to the processing network server computer 120 including an approval or decline of the transaction. The processing network server computer 120 can receive the authorization response message from the authorizing entity computer 130.

[0081] At step 9, the processing network server computer 120 can forward the authorization response message to the transport computer 115 and then to the resource provider computer 110. The processing network server computer 120 can also transmit the message to the mobile network operator computer system 140 notifying the mobile network operator computer system 140 of the just-conducted transaction.

[0082] In some examples, the authorizing entity computer 130 can subsequently complete the interaction with the mobile network operator computer system 140. This can include transferring funds between the mobile network operator computer system 140 and the authorizing entity computer 130 at the time of clearing and settlement procedures.

[0083] At step 10, a clearing and settlement process can be performed. At the end of the day or at any other suitable period of time, settlement can be performed between the transport computer 115 and the authorizing entity computer 130, or settlement can be performed directly with the mobile network operator computer system 140. If the authorizing entity computer 130 settles with the transport computer 115, the authorizing entity computer 130 can request reimbursement (for any fee adjustments) from the mobile network operator computer system 140. The mobile network operator computer system 140 can then invoice the user with the user's monthly phone bill invoice provided by the mobile network operator computer system 140.

[0084] The mobile network operator computer system 140 can generate an invoice for the user of the communication device 102. The invoice can include any transactions performed between the communication device 102 and the mobile network operator computer system 140, as well as any transactions performed between the communication device 102 and any resource provider computer. The transactions listed in the invoice can be aggregated for the resource provider computer 110, or provided separately according to the transaction and the time the transaction was performed. The user can provide the mobile network operator computer system 140 with a fee reimbursement.

[0085] Fees can also be exchanged. For example, the authorizing entity computer 130 can pay a fee to the processing network server computer 120. The resource provider computer 110 can pay a fee to the authorizing entity computer 130 based at least in part on the establishment and funding of the user's account corresponding to the approved amount tied to the virtual access credential. The authorizing entity computer 130 can request reimbursement from the mobile network operator computer system 140. The mobile network operator computer system 140 can charge the user of the communication device 102 using the phone bill.

[0086] Fees can also be exchanged. For example, the authorizing entity computer 130 can pay a fee to the processing network server computer 120. The resource provider computer 110 can pay a fee to the authorizing entity computer 130 based at least in part on the establishment and funding of the user's account corresponding to the approved amount tied to the virtual access credential. The authorizing entity computer 130 can request reimbursement from the mobile network operator computer system 140. The mobile network operator computer system 140 can charge the user of the communication device 102 using the phone bill. Figure 1 Additional embodiments are described. For example, in Figure 1 At step 1 of the additional embodiments, the communication device 102 can interact with the resource provider computer 110 to access a resource managed by the resource provider computer. The communication device 102 can interact with the resource provider computer 110 via the interaction site 112 or an application on a display screen of the communication device 102.

[0087] At step 2, the resource provider computer 110 can generate and transmit a virtual access credential request to the processing network server computer 120. The virtual access credential request can identify the user corresponding to the communication device 102. This information can support a request for authorization to interact (e.g., to gain access to a restricted area or resource, etc.).

[0088] At step 3, the processing network server computer 120 can communicate with the authorizing entity computer 130 to request access. The authorizing entity computer 130 can generate a virtual access credential.

[0089] In some examples, the authorizing entity computer 130 can act as an initial gateway to determine whether access should be authorized (e.g., access to restricted information of the resource provider computer 110). The authorizing entity computer 130 can correspond directly with the communication device 102 (or via the processing network server computer 120 to the communication device 102) to request an initial authentication response from the communication device 102, including a password or other unique identifier of the user. The communication device 102 can respond to the authorizing entity computer 130 with the password or other unique identifier, at which point the authorizing entity computer 130 can generate a virtual access credential.

[0090] In some examples, the authorizing entity computer 130 can correspond with the mobile network operator computer system 140 to access additional information about the communication device 102, including order history, location history, or user profile information associated with the communication device 102. For example, the mobile network operator computer system 140 can provide mobile network service to the communication device 102 and use global positioning system (GPS) storage location information associated with location tracking of the communication device 102 to access a history of location information. In some cases, the mobile network operator computer system 140 can provide this information to the authorizing entity computer 130 to initiate a first authentication process with the communication device 102.

[0091] At step 4, the authorizing entity computer 130 can provide the virtual access credential to the processing network server computer 120 (e.g., upon receiving a password or other unique identifier from the user, etc.).

[0092] At step 5, the processing network server computer 120 can transmit the virtual access credential from the authorizing entity computer 130 to the resource provider computer 110 or the communication device 102 for processing. The resource provider computer 110 can initiate a process to allow access to a resource based at least in part on receiving the virtual access credential. For example, the resource provider computer 110 can generate an authorization request message that includes the virtual access credential.

[0093] At step 6, the resource provider computer 110 can transmit the authorization request message that includes the virtual access credential to the transport computer 115. The transport computer 115 can transmit the authorization request message to the processing network server computer 120. The processing network server computer 120 can receive the authorization request message that includes the virtual access credential, where the authorization request message requests authorization for an interaction.

[0094] At step 7, the processing network server computer 120 can forward the authorization request message to the authorization entity computer 130. The authorization entity computer 130 can determine whether to allow or deny access based at least in part on comparing the virtual access credential from the initial authentication process to the user information included in the authorization request message. This comparison and matching can correspond to a second level of authentication.

[0095] At step 8, the authorization entity computer 130 can generate an authorization response message including an approval or denial of access to the processing network server computer 120. The processing network server computer 120 can receive the authorization response message from the authorization entity computer 130.

[0096] At step 9, the processing network server computer 120 can forward the authorization response message to the transport computer 115, and then to the resource provider computer 110.

[0097] At step 10, additional interactions can occur between the authorization entity computer 130, the transport computer 115, and the mobile network operator computer system 140, including allowing access to resources provided by the resource provider 110.

[0098] It should be noted that while the above example relates to payments, it should be understood that embodiments are not so limited. Other embodiments can relate to systems and methods that can generate virtual access credentials to access secure locations or secure data from a remote server computer.

[0099] Technical improvements are described throughout the application. Conventional systems can provide a single authentication or authorization for an interaction. Embodiments of the present disclosure can include a two-tiered authentication or authorization protocol, including a first process performed by an authorization entity computer and a second process performed by a mobile network operator computer system. This two-tiered authentication or authorization protocol can provide an improved technical confirmation prior to an interaction between a user and a resource, providing greater security.

[0100] Furthermore, embodiments also allow users without credentials to obtain temporary credentials so that they can access desired resources, such as data, locations, goods, or services. Embodiments can perform this operation without significant changes to the access infrastructure.

[0101] The computer system described herein can be embodied in hardware and includes one or more elements of the diagram that can be adapted to implement such functionality. Examples of such systems or components that can be incorporated with the computing system can be interconnected via a system bus. Additional subsystems such as a printer, keyboard, fixed disk, or other memory, monitors, or other components can also be provided. A monitor can be coupled to the system bus via a video adapter. Peripheral devices and other input / output (I / O) devices can be coupled to the computer system either directly or through an I / O controller, and can be connected to the computer system through any number of means, such as a serial port. For example, a serial port or other interface can be used to connect the computer system to a wide area network such as the Internet, a mouse input device, or a scanner. The interconnection via the system bus allows the central processor to communicate with each subsystem and to control the execution of instructions from the memory or the fixed disk, as well as the exchange of information between subsystems. The memory and / or the fixed disk embody a computer readable medium that can hold the instructions executable by the processor.

[0102] Moreover, although the present disclosure has been described in some detail with the intent of providing an overview of certain embodiments of the application, it will be appreciated that other embodiments can be modified or otherwise derived therefrom using any combination of the principles and features described herein. Accordingly, it is expressly intended that the description should not limit the application, which is defined solely by the claims.

[0103] Any of the software components or functions described in this application can be implemented as software code to be executed by a processor using, for example, conventional or object-oriented techniques. The software code can be stored as a series of instructions or commands or as a series of codes or commands on a computer readable medium such as a random access memory (RAM), a read-only memory (ROM), a magnetic medium such as a hard disk or floppy disk, or an optical medium such as a CD-ROM. Any such computer readable medium can reside on or within a single computational apparatus, and can be present on or within different computational apparatuses within a system or network.

[0104] The above description is illustrative and not restrictive. Many variations of the application will become apparent to those of skill in the art upon review of this disclosure. The scope of the application should, therefore, be determined not with reference to the above description, but instead with reference to the appended claims, along with their full scope of equivalents.

[0105] One or more features of any embodiment can be combined with one or more features of any other embodiment, without departing from the scope of the application.

[0106] The articles 'a', 'an', and 'the' are intended to mean one or more unless otherwise indicated.

[0107] All patents, patent applications, publications, and descriptions mentioned above are herein incorporated by reference in their entirety for all purposes. None is admitted to be prior art.

Claims

1. A method for authentication and authorization, the method comprising: A virtual access credential request is transmitted from a resource provider computer to an authorized entity computer, wherein the virtual access credential request includes an amount requested for an interaction between the resource provider computer and a communication device operated by a user associated with a mobile network operator's computer system, wherein the authorized entity computer then generates a virtual access credential for the interaction, the virtual access credential being associated with the mobile network operator's computer system but not with the user; The resource provider's computer receives the virtual access credential from the authorizing entity's computer, wherein the virtual access credential is generated by the authorizing entity's computer to be further associated with an approved amount corresponding to the amount requested in the virtual access credential request for the interaction; The resource provider's computer transmits an authorization request message, including the virtual access credential and the total interaction amount, to the authorized entity's computer, wherein the authorization request message requests authorization for the interaction; as well as The resource provider computer receives an authorization response message from the authorization entity computer, wherein the authorization entity computer generates the authorization response message based at least in part on a comparison of the total interaction amount with the approved amount, and wherein the authorization entity computer subsequently completes the interaction with the mobile network operator's computer system.

2. The method of claim 1, wherein the virtual access credential includes data that can be used to access a secure location or secure data.

3. The method of claim 1, wherein the communication device is a mobile phone.

4. The method of claim 1, wherein the mobile network operator's computer system executes a set of rules associated with the user before the virtual access credential is generated by the authorized entity computer.

5. The method of claim 1, further comprising: Generate a user profile associated with the virtual access credentials; as well as The authorized entity computer stores the approved amount together with the user profile.

6. A resource provider computer, the resource provider computer comprising: processor; as well as A computer-readable medium coupled to the processor, the computer-readable medium including code executable by the processor to perform a method comprising: A virtual access credential request is transmitted to an authorized entity computer, wherein the virtual access credential request includes an amount requested for an interaction between the resource provider computer and a communication device operated by a user associated with a mobile network operator's computer system, wherein the virtual access credential is generated by the authorized entity computer and is associated with the mobile network operator's computer system but not with the user; The virtual access credential is received from the authorized entity computer, wherein the virtual access credential is generated by the authorized entity computer to be further associated with an approved amount corresponding to the amount requested in the virtual access credential request for the interaction; Transmit an authorization request message, including the virtual access credential and the total interaction amount, to the authorized entity computer, wherein the authorization request message requests authorization for the interaction; and The authorized entity computer receives an authorization response message, wherein the authorized entity computer generates the authorization response message based at least in part on a comparison of the total interaction amount with the approved amount, wherein the authorized entity computer then completes the interaction with the mobile network operator's computer system.

7. The resource provider computer of claim 6, wherein the virtual access credential is 16 bits long.

8. The resource provider computer of claim 6, wherein the mobile network operator computer system routes messages to a plurality of wireless mobile devices including the communication device, and routes messages from the plurality of wireless mobile devices.

9. The resource provider computer of claim 6, wherein the mobile network operator computer system executes a set of rules associated with the user before determining the virtual access credential.

10. The resource provider computer of claim 6, wherein the method further comprises: Generate a user profile associated with the virtual access credentials; as well as The authorized entity computer stores the approved amount together with the user profile.

11. A method for authentication and authorization, the method comprising: A virtual access credential is generated by an authorized entity computer, wherein the virtual access credential is associated with an approved amount corresponding to an amount requested for an interaction between a resource provider's computer and a communication device operated by a user associated with a mobile network operator's computer system, and the virtual access credential is associated with the mobile network operator's computer system but not with the user, and wherein the amount requested for the interaction is received in a virtual access credential request. The virtual access credential is transmitted from the authorized entity computer to the communication device or the resource provider computer. The authorized entity computer receives an authorization request message including the virtual access credential, wherein the authorization request message requests authorization for the interaction and includes the total interaction amount; The authorized entity computer compares the total interaction amount included in the authorization request message with the approved amount; as well as The authorizing entity computer generates an authorization response message based on a comparison, wherein the authorization response message indicates approval or rejection of the authorization request message, wherein the authorization response message is forwarded to the resource provider computer, and wherein the authorizing entity computer subsequently completes interaction with the mobile network operator's computer system.

12. The method of claim 11, wherein the virtual access credential allows access to secure data.

13. The method of claim 11, wherein the communication device is a mobile phone.

14. The method of claim 11, further comprising: Generate a user profile associated with the virtual access credentials; as well as The approval or rejection of the authorization request message is stored together with the user profile.

15. An authorized entity computer, the authorized entity computer comprising: processor; as well as A computer-readable medium coupled to the processor, the computer-readable medium including code executable by the processor to perform a method comprising: A virtual access credential is generated, wherein the virtual access credential is associated with an approved amount corresponding to an amount requested for an interaction between a resource provider's computer and a communication device operated by a user associated with a mobile network operator's computer system, and the virtual access credential is associated with the mobile network operator's computer system but not with the user, and wherein the amount requested for the interaction is received in a virtual access credential request. Transmit the virtual access credential to the communication device or the resource provider's computer; Receive an authorization request message including the virtual access credential, wherein the authorization request message requests authorization for the interaction and includes the total interaction amount; Compare the total interaction amount included in the authorization request message with the approved amount; and An authorization response message is generated based on a comparison, wherein the authorization response message indicates approval or rejection of the authorization request message, wherein the authorization response message is forwarded to the resource provider computer, and wherein the authorization entity computer subsequently completes interaction with the mobile network operator's computer system.

16. The authorized entity computer of claim 15, wherein the virtual access credential allows access to a location.

17. The authorized entity computer of claim 15, wherein the communication device is a laptop computer.

18. The authorized entity computer of claim 15, wherein the method further comprises: Generate a user profile associated with the virtual access credentials; as well as The approval or rejection of the authorization request message is stored together with the user profile.

19. A method for authentication and authorization, the method comprising: A server computer transmits a virtual access credential request to an authorized entity computer, wherein the virtual access credential request includes an amount requested for an interaction between a resource provider computer and a communication device operated by a user associated with a mobile network operator's computer system, wherein the authorized entity computer then generates a virtual access credential for the interaction, the virtual access credential being associated with the mobile network operator's computer system but not with the user. The server computer receives the virtual access credential from the authorized entity computer, wherein the virtual access credential is generated by the authorized entity computer to be further associated with an approved amount corresponding to the amount requested in the virtual access credential request for the interaction; The virtual access credential is transmitted from the server computer to the communication device or the resource provider computer. The server computer receives an authorization request message including the virtual access credential and the total interaction amount, wherein the authorization request message requests authorization for the interaction; The server computer forwards the authorization request message to the authorization entity computer; as well as The server computer transmits an authorization response message from the authorization entity computer to the resource provider computer, wherein the authorization entity computer generates the authorization response message based at least in part on a comparison of the total interaction amount with the approved amount, wherein the authorization response message contains an indication of approval or rejection of the authorization request message, and wherein the authorization entity computer subsequently completes an interaction with the mobile network operator's computer system.

20. A server computer, the server computer comprising: processor; as well as A computer-readable medium coupled to the processor, the computer-readable medium including code executable by the processor to perform a method comprising: A virtual access credential request is transmitted to an authorized entity computer, wherein the virtual access credential request includes an amount requested for an interaction between a resource provider computer and a communication device operated by a user associated with a mobile network operator's computer system, wherein the virtual access credential is generated by the authorized entity computer and is associated with the mobile network operator's computer system but not with the user; The virtual access credential is received from the authorized entity computer, wherein the virtual access credential is generated by the authorized entity computer to be further associated with an approved amount corresponding to the amount requested in the virtual access credential request for the interaction; Transmit the virtual access credential to the communication device or the resource provider's computer; Receive an authorization request message including the virtual access credential and the total interaction amount, wherein the authorization request message requests authorization for the interaction; Forward the authorization request message to the authorized entity computer; and An authorization response message from the authorizing entity computer is transmitted to the resource provider computer, wherein the authorizing entity computer generates the authorization response message based at least in part on a comparison of the total interaction amount with the approved amount, wherein the authorization response message contains an indication of approval or rejection of the authorization response message, and wherein the authorizing entity computer subsequently completes an interaction with the mobile network operator's computer system.

Citation Information

Patent Citations

  • Systems and methods for interoperable network token processing

    CN105580038A

  • Information management system

    US20110289552A1

  • System and method for local data conversion

    US20170330185A1

  • Systems and methods for enhanced authorization response

    US20180053189A1