Data value routing system and method

By splitting data packets into multiple data values ​​and processing them separately, the inefficiency and security risks of processing computers are solved, achieving more efficient and secure data packet processing.

CN111611594BActive Publication Date: 2026-02-27VISA INTERNATIONAL SERVICE ASSOCIATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202010112565.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-02-26
Filing Date
2020-02-24
Publication Date
2026-02-27
Estimated Expiration
2040-02-24

AI Technical Summary

Technical Problem

The processing of data packets by computers is inefficient and poses security risks, especially when processing biometric templates. Other data values ​​must wait for processing, causing bottlenecks, and malicious entities may be able to access all data values ​​in the data packet.

Method used

The data packet is split into multiple data values, and multiple authorization request messages are generated and transmitted to multiple processing computers for processing. Authorization or rejection of interaction is performed through the data distribution computer and the authorization computer.

Benefits of technology

It improves processing efficiency, reduces bottlenecks in packet processing, and enhances packet security by reducing security risks through distributed processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN111611594B_ABST
    Figure CN111611594B_ABST
Patent Text Reader

Abstract

A disclosed method includes a data distribution computer receiving a data packet including a plurality of data values in response to an interaction between a resource provider and a user. The data distribution computer can then determine a data item for each data value of the plurality of data values and associate each data value with a processing computer using the data item for each data value. The data distribution computer can generate a plurality of authorization request messages including at least one data value. The data distribution computer can then transmit the plurality of authorization request messages to a plurality of processing computers adapted to process the data value in the respective authorization request message, wherein the plurality of processing computers processes the data value in the respective authorization request message. The plurality of authorization request messages are then forwarded to an authorization computer. The authorization computer analyzes each authorization request message to authorize or deny the interaction.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] The processing computer that handles the data can become a bottleneck in the data flow of a processing system. The processing computer can process each data value received in a data packet. For example, the processing computer might receive a data packet that includes a biometric template as well as other data values. While the processing computer is evaluating the biometric template, the other data values ​​are simply held in memory until the processing computer evaluates the biometric template, thus leading to inefficiency.

[0002] Furthermore, there are security risks associated with sending data packets containing all data values ​​to the processing computer. Malicious entities that compromise the processing computer and / or communication channels could gain access to all data values ​​in the data packets. This could be problematic, for example, when the data values ​​are related to user authentication data such as biometric identification and passwords.

[0003] The embodiments of the present invention individually and collectively address this problem and other problems. Summary of the Invention

[0004] Embodiments of the present invention relate to a method and system for splitting data packets into multiple data values ​​and generating multiple authorization request messages including at least one data value.

[0005] One embodiment relates to a method comprising: in response to an interaction between a resource provider and a user, receiving a data packet comprising a plurality of data values ​​by a data distribution computer; determining a data item for each of the plurality of data values ​​by the data distribution computer; associating each data value with a processing computer using the data item for each data value by the data distribution computer; generating a plurality of authorization request messages comprising at least one data value by the data distribution computer; and transmitting the plurality of authorization request messages by the data distribution computer to a plurality of processing computers adapted to process the data value in a corresponding authorization request message, wherein the plurality of processing computers process the data value in the corresponding authorization request message, wherein the plurality of authorization request messages are subsequently forwarded to an authorization computer, wherein the authorization computer analyzes each authorization request message to authorize or deny the interaction.

[0006] Another embodiment relates to a data distribution computer, comprising: a processor; a memory device; and a computer-readable medium coupled to the processor, the computer-readable medium including code executable by the processor to implement a method comprising: receiving a data packet comprising a plurality of data values ​​in response to an interaction between a resource provider and a user; determining a data item for each of the plurality of data values; associating each data value with a processing computer using the data item for each data value; generating a plurality of authorization request messages comprising at least one data value; and transmitting the plurality of authorization request messages to a plurality of processing computers adapted to process the data value in a corresponding authorization request message, wherein the plurality of processing computers process the data value in the corresponding authorization request message, wherein the plurality of authorization request messages are subsequently forwarded to an authorization computer, wherein the authorization computer analyzes each authorization request message to authorize or deny the interaction.

[0007] Further details regarding embodiments of the present invention can be found in the detailed description and accompanying drawings. Attached Figure Description

[0008] Figure 1 A block diagram illustrating a data processing system according to an embodiment of the present invention is shown.

[0009] Figure 2 A block diagram illustrating a data distribution computer according to an embodiment of the present invention is shown.

[0010] Figure 3 A block diagram illustrating an authorized computer according to an embodiment of the present invention is shown.

[0011] Figure 4 A block diagram illustrating a method for distributing data values ​​according to an embodiment of the present invention is shown.

[0012] Figure 5 A block diagram illustrating a method for splitting data packets according to an embodiment of the present invention is shown.

[0013] Figure 6 A flowchart illustrating an authorization request message method according to an embodiment of the present invention is shown.

[0014] Figure 7 A flowchart illustrating an authorization response message method according to an embodiment of the present invention is shown.

[0015] Figure 8 A flowchart illustrating an authorization response message method according to an embodiment of the present invention is shown. Detailed Implementation

[0016] Before discussing the embodiments of the present invention, some terms may be described in further detail.

[0017] "User" can include an individual. In some embodiments, a user may be associated with one or more personal accounts and / or mobile devices. In some embodiments, a user may also be referred to as a cardholder, account holder, or consumer.

[0018] A “user device” can be a device operated by a user. Examples of user devices include mobile phones, smartphones, cards, personal digital assistants (PDAs), laptops, desktop computers, server computers, vehicles such as automobiles, simplified client devices, tablet PCs, etc. Additionally, a user device can be any type of wearable technology device, such as a watch, headphones, glasses, etc. A user device can include one or more processors capable of processing user input. A user device can also include one or more input sensors for receiving user input. As is known in the art, there are various input sensors capable of detecting user input, such as accelerometers, cameras, microphones, etc. User input obtained by the input sensors can come from various data input types, including but not limited to audio data, visual data, or biometric data. A user device can include any electronic device that can be operated by the user, and said electronic device can also provide remote communication capabilities with a network. Examples of remote communication capabilities include using mobile phone (wireless) networks, wireless data networks (e.g., 3G, 4G, or similar networks), Wi-Fi, Wi-Max, or any other communication medium that provides access to networks such as the Internet or private networks.

[0019] A “credential” can include any evidence of power, rights, or privileges. For example, an access credential can include permission to access certain tangible or intangible assets, such as a building or documents. In another instance, a payment credential can include any suitable information associated with and / or identifying an account (e.g., a payment account and / or a payment device associated with said account). Such information may be directly related to the account or may be derived from account-related information. Examples of account information can include an “account identifier”, such as a primary account number or “account number” (PAN), a token, a sub-token, a gift card number or code, a prepaid card number or code, a username, an expiry date, a card verification value (CVV), a dynamic card verification value (dCVV), a card verification value 2 (CVV2), a card verification value 3 (CVC3), etc. An example of a PAN is a 16-digit number, such as “4147 0900 0000 1234”. In some embodiments, the credential may be considered sensitive information.

[0020] "Interaction" can include reciprocal effects or influences. "Interaction" can include communication, contact, or exchange between parties, devices, and / or entities. Instances of interaction include transactions between two parties and data exchange between two devices.

[0021] An "access device" can be any suitable device that provides access to a remote system. An access device can also be used to communicate with a coordinating computer, communications network, or any other suitable system. Access devices can typically be located anywhere suitable, such as at the merchant's location. Access devices can take any suitable form. Some examples of access devices include POS or point-of-sale devices (e.g., POS terminals), cellular phones, personal digital assistants (PDAs), personal computers (PCs), tablet PCs, handheld dedicated readers, set-top boxes, electronic cash registers (ECRs), automated teller machines (ATMs), virtual cash registers (VCRs), kiosks, security systems, access systems, and so on. In some embodiments, an access device can be a device that acts as a payment terminal at a resource provider's location. For example, in some embodiments where the access device may include a POS terminal, any suitable POS terminal can be used, and it may include a reader, a processor, and a computer-readable medium.

[0022] Access devices can use any suitable contact or contactless operating mode to send or receive data from or associated with mobile communication devices or payment devices. For example, an access device may have a card reader, which may include electrical contacts, radio frequency (RF) antennas, optical scanners, barcode readers, or magnetic stripe readers to interact with user devices.

[0023] A “data packet” may include one or more data units formed into a packet. A data packet may include one or more data values. For example, a user device may receive data values ​​from a user and then generate a data packet including the data values. The user device may then transmit the data packet to an access device. In some embodiments, the data packet may further include a data header.

[0024] A “data value” can include data units. A data value can be associated with a data item. A data value can include data associated with an interaction between a user and a resource provider’s computer. For example, a data value could be “415-123-4567,” which could correspond to the data item “Phone Number.” A data value can be associated with any data item described herein. As another example, a data value could be “Jane Doe,” which could correspond to the data item “Name.” In some embodiments, the data value can be encrypted.

[0025] A "data item" can include data values ​​of a specific type. A data item can be defined by the values ​​that the data value can take, the programming language used, or the operations that can be performed on the data item. For example, a data item can be a biometric template, name, user credentials (e.g., username, password, etc.), security code, location access code, phone number, product data, physical address, location, IP address, email address, user identifier, device identifier, etc. In some embodiments, product data can be Stock Keeping Unit (SKU) data, including transaction amount, date, tax amount, customer code, merchant postal code, tax identification code, merchant minority code, merchant status code, ship from postal code, destination postal code, invoice number, order number, product code, commodity code, commodity description, commodity quality, commodity unit of measurement, commodity expansion amount, shipping cost, customs duty amount, etc.

[0026] For example, a data packet may include four data values. These four data values ​​may correspond to four data items: "biometric template," "phone number," "username," and "password." The four data values ​​could be: biometric template "LW92J349VNM186FD...", phone number "415-123-4567," username "JohnDoe123," and password "123456789."

[0027] As another example, a data packet may include three data values. These three data values ​​may correspond to three data items: "Grocery SKU," "Orange SKU," and "Electronic Device SKU," with two data values ​​corresponding to the same data item. The three data values ​​could be "APPL04," "ORNG01," and "TV02," representing products such as apples, oranges, and televisions, respectively. Product data may include subfields and / or associated data such as transaction amounts. For example, the three data values ​​"APPL04," "ORNG01," and "TV02" could be associated with transaction amounts of "$1.23," "$0.86," and "$799," respectively.

[0028] The "header" may include supplementary data (e.g., authorization response messages, authorization request messages, etc.) placed within a data packet or message. In some embodiments, the header may include supplementary data related to the interaction between the user and the resource provider. The header may include any suitable information, such as, but not limited to, sender and / or receiver addresses (e.g., IP addresses), amounts, protocols governing message formats, cryptographic information (e.g., digital signatures, etc.), and so on.

[0029] "Access data" can include any suitable data that can be used to access a resource or create data that allows access to a resource. In some embodiments, access data can be account information for a payment account. Account information can include a PAN, payment token, expiration date, card verification value (e.g., CVV, CVV2), dynamic card verification value (dCVV, dCVV2), etc. In other embodiments, access data can include data that can be used to access a location or access secure data. Such information can be event ticket information, data for accessing a building, transit ticket information, passwords, biometric identification, or other credentials for accessing secure data.

[0030] In some embodiments, data values ​​may include product data. "Product data" may include data associated with one or more resources involved in the interaction. Product data may include, but is not limited to, transaction amount, date, tax amount, customer code, merchant postal code, tax identification code, merchant minority code, merchant status code, shipping postal code, destination postal code, invoice number, order number, product code, commodity code, product description, commodity quality, commodity unit of measurement, commodity extended amount, shipping cost, customs duty amount, etc. Product data may include any suitable product data. For example, data items may be "grocery product data," "electronic device data," "fitness product data," "home decor product data," and any other suitable product data.

[0031] A "resource provider" can be an entity that can provide resources such as goods, services, information, and / or access. Examples of resource providers include merchants, data providers, transportation departments, government entities, venue and residential operators, etc. A "merchant" can typically be an entity that participates in a transaction and can sell goods or services or provide access to goods or services.

[0032] The term "verification" and its derivatives can refer to the process of using information to determine whether an underlying subject is valid under a given set of conditions. Verification can include any comparison of information to ensure that certain data or information is correct, valid, accurate, legitimate, and / or credible.

[0033] An "authorization request message" can be an electronic message requesting authorization for an interaction. In some embodiments, the message is sent to the transaction processing computer and / or the issuer of the payment card to request authorization for the transaction. According to some embodiments, the authorization request message may comply with International Organization for Standardization (ISO) 8583, a standard for systems that exchange information about electronic transactions associated with payments made by a user using a payment device or payment account. The authorization request message may include an issuer account identifier that may be associated with the payment device or payment account. The authorization request message may also include additional data elements corresponding to "identification information," including (by way of example only): service code, card verification value (CVV), dynamic card verification value (dCVV), primary account number or "account number" (PAN), payment token, username, expiration date, etc. The authorization request message may also include "transaction information," such as any information associated with the current transaction, such as transaction value, merchant identifier, merchant location, buyer's bank identification number (BIN), card acceptor ID, information identifying the item being purchased, etc., and any other information that may be used to determine whether to identify and / or authorize the transaction.

[0034] An "authorization response message" can be a message responding to an authorization request. In some cases, an authorization response message can be an electronic message response to an authorization request message generated by the issuing financial institution or transaction processing computer. An authorization response message may include (by way of example only) one or more of the following status indicators: Approved – the transaction is approved; Rejected – the transaction is not approved; or Call Center – further information is pending, and the merchant must call the toll-free authorization number. An authorization response message may also include an authorization code, which can be a code indicating approval of the transaction returned by the credit card issuing bank to the merchant's access device (e.g., a POS device) in response to the authorization request message in the electronic message (directly or via the transaction processing computer). This code can serve as evidence of authorization.

[0035] "Authorizing entity" can be the entity requesting authorization. Instances of authorizing entities can be issuers, government agencies, document repositories, access administrators, etc. Authorizing entities can operate authorized computers. "Issuer" can refer to a commercial entity (e.g., a bank) that issues and optionally maintains user accounts. Issuers can also issue payment credentials stored on user devices, such as cellular phones, smart cards, tablets, or laptops, to consumers, or in some embodiments to portable devices.

[0036] An “acquiring party” can typically be a business entity (e.g., a commercial bank) that has a business relationship with a particular merchant or other entity. Some entities can perform both issuing and acquiring functions. Some embodiments may cover such a single entity as an issuing-acquiring party. The acquiring party can operate an acquiring party computer, which may also be generally referred to as a “transfer computer.”

[0037] A "processing computer" may include a computer or computer network capable of processing data. The processing computer may receive data packets containing several data values ​​and may process these data values. The processing computer may forward the data packets to an authorized computer. In some embodiments, the processing computer may output a processing result and include the result along with the data packet destined for the authorized computer in a message.

[0038] A “networked computer” can include a computer or computer network capable of handling interaction. In some embodiments, a networked computer may be in an electronic system for accepting, transmitting, or processing transactions made by a user device for access to resources, goods, services, or locations or data. A networked computer can transfer information and / or funds between issuers, acquirers, transacting parties, and / or users. Examples of networked computers may include processing server computers, such as those provided by… VisaNet operation TM .

[0039] "Biometrics" can be any human characteristic unique to an individual. For example, biometrics can be a person's fingerprints, voice samples, face, DNA, retina, and so on.

[0040] A "biometric reader" can include a device for capturing data from a personal biometric sample. Examples of biometric readers can include fingerprint readers, front-facing cameras, microphones, and iris scanners.

[0041] "Biometric samples" can include data obtained by a biometric reader. This data can be an analog or digital representation of a user's biometrics, generated before determining the different features required for a match. For example, a biometric sample of a user's face could be image data. In another instance, a biometric sample of a user's voice could be audio data.

[0042] A "biometric template" or "biometric sample template" may include a file containing different features extracted from a biometric sample, which can be used in the biometric authentication process. For example, a biometric template may be a binary mathematical file that represents the unique characteristics of an individual's fingerprint, eyes, hands, or voice required to perform accurate authentication of the individual.

[0043] A “processor” can include means for performing a task. In some embodiments, a processor can include any suitable one or more data computing means. A processor can include one or more microprocessors that work together to perform a desired function. A processor can include a CPU that includes at least one high-speed data processor sufficient to execute program components for performing user and / or system-generated requests. A CPU can be a microprocessor such as AMD’s Athlon, Duron, and / or Opteron; IBM and / or Motorola’s PowerPC; IBM and Sony’s Cell processors; Intel’s Celeron, Itanium, Pentium, Xeon, and / or XScale; and / or similar one or more processors.

[0044] "Memory" can be any suitable one or more devices capable of storing electronic data. Suitable memory can include non-transient computer-readable media whose storage contains instructions executable by a processor to implement a desired method. Instances of memory can include one or more memory chips, disk drives, etc. Such memory can be operated using any suitable electrical, optical, and / or magnetic modes of operation.

[0045] A "server computer" can include a powerful computer or a cluster of computers. For example, a server computer can be a mainframe, a small cluster of computers, or a group of servers that operate like cells. In one instance, a server computer can be a database server coupled to a web server. A server computer can include one or more computing devices and can use any of a variety of computing architectures, arrangements, and compilations to serve requests from one or more client computers.

[0046] Embodiments of the present invention allow a data distribution computer to receive data packets comprising multiple data values ​​during an interaction between a user and a resource provider. The data distribution computer can determine the data item associated with each data value and then, depending on the capacity of the processing computer, determine which data value to send to the processing computer. Upon receiving data values, each processing computer can process the data values ​​in parallel with each other and then transmit the data values ​​to an authorization computer. The authorization computer can then determine whether to authorize the interaction between the user and the resource provider.

[0047] Figure 1 A block diagram of a system 100 comprising several components is shown according to some embodiments of the present invention. The system 100 includes a user device 102, an access device 104, a data distribution computer 106, a plurality of processing computers 108, and an authorization computer 110, wherein the processing computers include a first processing computer 108A, a second processing computer 108B, and an nth processing computer 108C.

[0048] User device 102 can operationally communicate with access device 104. Access device 104 can operationally communicate with data distribution computer 106, which can operationally communicate with a plurality of processing computers 108, including a first processing computer 108A, a second processing computer 108B, and an nth processing computer 108C. Data distribution computer 106 can operationally communicate with any suitable number of processing computers. Each of the plurality of processing computers 108 can operationally communicate with authorization computer 110.

[0049] To simplify the explanation, Figure 1 A certain number of components are shown. However, it should be understood that embodiments may include more than one of each component. Furthermore, some embodiments of the invention may include more than one of each component. Figure 1 All components shown are fewer or more components. For example, system 100 may include 2, 5, 9, 15, 25, etc., processing computers. As another example, any suitable number of licensed computers may exist (e.g., 1, 2, 4, 10, 20, etc.).

[0050] Figure 1 Messages between the entities, providers, networks, and devices shown may be transmitted using secure communication protocols, such as, but not limited to, File Transfer Protocol (FTP); Hypertext Transfer Protocol (HTTP); Secure Hypertext Transfer Protocol (HTTPS), Secure Sockets Layer (SSL), ISO (e.g., ISO 8583), etc. The communication network may include any suitable communication medium. The communication network may be one or a combination of the following: direct interconnection; the Internet; a local area network (LAN); a metropolitan area network (MAN); operating a task as a node on the Internet (OMNI); a secure custom connection; a wide area network (WAN); a wireless network (e.g., employing protocols such as, but not limited to, Wireless Application Protocol (WAP), I-mode, etc.), etc.

[0051] User device 102 may include any suitable device, such as a mobile phone, smartphone, card, PDA, laptop, desktop computer, etc. User device 102 may be configured to receive data values ​​from a user. For example, user device 102 may capture data from the user via a touchscreen, biometric scanner, keyboard, and / or any other suitable input element. User device 102 may also be configured to store the received data values ​​that can be used during subsequent interactions.

[0052] In some embodiments, a user can use user device 102 to interact at a resource provider location (e.g., a merchant location). The interaction can be an authentication interaction, a payment transaction (e.g., for purchasing goods or services), an access interaction (e.g., for accessing a relay system), and / or any other suitable interaction. User device 102 can interact with access device 104 at the resource provider location. For example, a user can tap user device 102 against a near-field communication (NFC) reader in access device 104. Alternatively, a user can electronically direct data packets to a resource provider computer (not shown) associated with access device 104, for example, in an online interaction. In some cases, user device 102 can transmit account identifiers, such as payment tokens, to access device 104.

[0053] As described herein, access device 104 may receive data packets from user device 102 via an NFC reader or other suitable input element. Access device 104 may then transmit the data packets to data distribution computer 106. In some embodiments, access device 104 may transmit the data packets to resource provider computer, which may then forward the data packets to data distribution computer 106. Data packets may include any suitable data values ​​associated with the interaction. For example, data values ​​may include biometric templates, user credentials (e.g., username, password, etc.), telephone numbers, product data, physical addresses, etc. In some embodiments, product data may include SKU data, such as transaction amount, date, tax amount, customer code, merchant postal code, tax identification code, merchant minority code, merchant status code, shipping postal code, destination postal code, invoice number, order number, product code, commodity code, commodity description, commodity quality, commodity unit of measurement, commodity expansion amount, shipping cost, customs duty amount, etc.

[0054] In some embodiments, the resource provider may operate a hosting site. The hosting site may be a website and can be accessed via a browser on user device 102. The hosting site may be a location connected to the Internet that maintains one or more pages on the World Wide Web. In other embodiments, the resource provider's computer may receive data packets from access device 104.

[0055] To authorize the interaction, access device 104 or the resource provider computer can transmit data packets to data distribution computer 106. In some embodiments, access device 104 or the resource provider computer can generate an authorization request message and then transmit the authorization request message to data distribution computer 106. The authorization request message may include data packets.

[0056] Data distribution computer 106 can be configured to distribute data among a plurality of processing computers 108. After receiving a data packet, data distribution computer 106 can be configured to determine a data item for each data value included in the data packet. Data distribution computer 106 can also be configured to associate each data value with a processing computer among the plurality of processing computers 108 using the data item for each data value. For example, the data distribution computer can store a table indicating which data items a particular processing computer is suitable to receive.

[0057] The data distribution computer 106 may also generate multiple authorization request messages that include at least one data value. In some embodiments, each authorization request message may further include a data header. For example, the data header may include an IP address, or other means of identifying the data distribution computer 106 (e.g., a device identifier, etc.), and a sum (i.e., an amount) associated with the data value.

[0058] The data distribution computer 106 can then transmit multiple authorization request messages to multiple processing computers 108. For example, the data distribution computer 106 can transmit a first authorization request message to a first processing computer 108A, a second authorization request message to a second processing computer 108B, and an Nth authorization request message to an Nth processing computer 108C.

[0059] In some embodiments, the data distribution computer 106 may be a delivery computer. The delivery computer may be located (operationally) between the resource provider computer and multiple processing computers 108. The delivery computer may be operated by, for example, an acquiring entity. The acquiring party may maintain accounts for any merchant (e.g., an airline) with which a user may wish to interact.

[0060] Multiple processing computers 108 (e.g., first processing computer 108A, second processing computer 108B, Nth processing computer 108C, etc.) can route or exchange messages between several data distribution computers, including data distribution computer 106, and several authorization computers, including authorization computer 110. In some embodiments, a processing computer may be a network computer. A network computer may be configured to provide authorization services and clearing and settlement services for payment interactions. A network computer may include a data processing subsystem, network, and operations for supporting and delivering authorization services, exception document services, and clearing and settlement services. An exemplary network computer may include VisaNet. TM For example, VisaNet TM Networked computers are capable of handling credit card transactions, debit card transactions, and other types of business transactions. VisaNet TMSpecifically, this includes a Visa Integrated Payment (VIP) system for processing authorization requests and a BaseII system for performing clearing and settlement services. Furthermore, the processing computer may include a server computer and may use any suitable wired or wireless telecommunications network, including the Internet. In some embodiments, the network computer may forward authorization requests received from data distribution computer 106 to authorization computer 110 via a communication channel. The network computer may further forward authorization response messages received from authorization computer 110 to data distribution computer 106. In some embodiments, the network computer may include an authentication processing computer.

[0061] Each of the plurality of processing computers 108 may then forward the authorization request message to a corresponding authorization computer 110 associated with an authorization entity, which is associated with a user account.

[0062] Authorization computer 110 can be configured to authorize any suitable request, including access to data, access to location, or approval of payment. In some embodiments, authorization computer 110 may be operated by an account issuer. Typically, an issuer is an entity that issues and maintains user accounts (e.g., a bank). Accounts can be credit, debit, prepaid, or any other type of account.

[0063] After receiving multiple authorization request messages, the authorization computer 110 can transmit multiple authorization response messages back to the corresponding processing computer among the multiple processing computers 108 to indicate whether the current interaction is authorized (or unauthorized). Each processing computer can forward the multiple authorization response messages to the data distribution computer 106. In some embodiments, even if the authorization computer 110 has authorized the interaction, each processing computer can refuse the interaction, for example, based on the value of a fraud risk score. In other embodiments, the authorization computer 110 can transmit the multiple authorization response messages directly to the data distribution computer 106. After receiving the multiple authorization response messages, the data distribution computer 106 can then transmit the multiple authorization response messages to the access device 104. In some embodiments, the data distribution computer 106 can transmit the authorization response messages to the resource provider computer.

[0064] After the resource provider's computer receives multiple authorization response messages, it can then provide an indication of whether interaction with user device 102 and / or access device 104 is authorized. This indication can be displayed by access device 104 or printed on a physical receipt. Alternatively, if the interaction is online, the resource provider can provide the user with a webpage or other indication of the authorization response messages as a virtual receipt.

[0065] In some embodiments, at the end of the day (or other suitable length of time), the clearing and settlement process may be performed by multiple processing computers. The clearing process is the exchange of financial details between the acquiring party and the authorizing entity to facilitate posting to the customer's account and verifying the user's settlement position.

[0066] Figure 2 A block diagram of a data distribution computer 200 according to some embodiments of the present invention is shown. An exemplary data distribution computer 200 may include a processor 204. The processor 204 may be coupled to a memory 202, a network interface 206, and a computer-readable medium 208 including a data value extraction module 208A, a data item determination module 208B, a distribution rule module 208C, and a routing module 208D.

[0067] Memory 202 can be any suitable memory capable of storing data, information, and / or code. Memory 202 can securely store keys, key identifiers, routing tables, and any other related data. Memory 202 can take the form of a secure element, a hardware security module, or any other suitable data storage format.

[0068] Network interface 206 may include an interface that allows data distribution computer 200 to communicate with external computers. Network interface 206 enables data distribution computer 200 to transmit data to and from another device (e.g., a resource provider computer, an authorizing computer, etc.). Some examples of network interface 206 may include a modem, a physical network interface (e.g., an Ethernet card or other network interface card (NIC)), a virtual network interface, a communication port, a PCMCIA slot and card, etc. Wireless protocols enabled by network interface 206 may include Wi-Fi. TM Data transmitted via network interface 206 may be in the form of signals, which may be electrical, electromagnetic, optical, or any other signal that can be received by an external communication interface (collectively, "electronic signals" or "electronic messages"). These electronic messages, which may include data or instructions, may be provided between network interface 206 and other devices via a communication path or channel. As described above, any suitable communication path or channel may be used, such as wires or cables, fiber optic cables, telephone lines, cellular links, radio frequency (RF) links, WAN or LAN networks, the Internet, or any other suitable medium.

[0069] Computer-readable medium 208 may include code executable by processor 204 to implement a method comprising: receiving a data packet comprising a plurality of data values ​​in response to an interaction between a resource provider and a user; determining a data item for each of the plurality of data values; associating each data value with a processing computer using the data item for each data value; generating a plurality of authorization request messages comprising at least one data value; and transmitting the plurality of authorization request messages to a plurality of processing computers adapted to process the data values ​​in the respective authorization request messages, wherein the plurality of processing computers process the data values ​​in the respective authorization request messages, wherein the plurality of authorization request messages are subsequently forwarded to an authorization computer, wherein the authorization computer analyzes each authorization request message to authorize or deny the interaction.

[0070] The data value extraction module 208A, together with the processor 204, can extract multiple data values ​​from a data packet. The data value extraction module 208A can extract any suitable number of data values ​​from the data packet (e.g., 2, 5, 20, 50, etc.). In some embodiments, the data value extraction module 208A can extract data values ​​by parsing the data packet into delimiter-based segments. Any suitable method known to those skilled in the art can be used to extract the data values.

[0071] The data item determination module 208B, together with the processor 204, can determine the data item of a data value. For example, the data item determination module 208B can determine a data item whose data value has a fingerprint biometric identification template. The data item determination module 208B can determine the data item by evaluating the characteristics of the data value. For example, the data item determination module 208B can evaluate the length and / or size of the data value (e.g., 8 characters, 15MB, etc.), the primitive type of the data value (e.g., Boolean, integer, character, double, etc.), and / or the value and / or content of the data value.

[0072] In some embodiments, the data item determination module 208B can also be configured to determine the data item based on which access device the data packet was received from, since some access devices may include certain data items at certain frequencies. For example, the data distribution computer 200 may receive email address data items in 87% of the data packets received from a particular access device. Additionally, the data item determination module 208B can determine the type of data value based on other data values ​​included in the data packet. For example, a data packet including a username data item typically also includes a password data item.

[0073] In some embodiments, multiple data values ​​in a data packet can be labeled with a data item for each data value. The data item determination module 208B can determine the data item based on the label. For example, before transmitting the data packet to the data distribution computer 200, an access device or user device can label the data values ​​in the data packet. In some embodiments, the label of the data item can be included in the data header of the data packet.

[0074] In some embodiments, the data item determination module 208B, together with the processor 204, can use a lookup table to determine the data item of the data value. The data distribution computer 200 can store a lookup table that includes data values ​​and associated data items. For example, the lookup table may include data values ​​such as “APPL04”, “ORNG01”, and “TV02”, which can be associated with data items “grocery SKU”, “grocery SKU”, and “electronic device SKU”, respectively.

[0075] The distribution rule module 208C, together with the processor 204, can determine which of the plurality of processing computers will transmit the authorization request message to it. The distribution rule module 208C can associate each data value with a processing computer among the plurality of processing computers, determined by the data item determination module 208B, using data items for each data value. For example, in some embodiments, the data distribution computer 200 can store a table indicating data items suitable for a particular processing computer to receive. The table may include a list of processing computers, including the IP address of each processing computer. Each processing computer in the list can be associated with one or more data items that the processing computer is suitable to process.

[0076] For example, the first processing computer may have an IP address (e.g., 172.16.254.1 in Internet Protocol version 4 (IPv4) or 2001:db8:0:1234:0:567:8:1 in Internet Protocol version 6 (IPv6)) and may be adapted to process the data values ​​of the data item "Biometric Template". Additionally, the second processing computer may have an IP address (e.g., 123.45.678.9 in IPv4) and may be adapted to process the data values ​​of the data items "Name", "Email Address", "Physical Address", and "Birth Data".

[0077] The distribution rule module 208C can determine that the data value of the data item "Biometric Identification Template" can be transmitted to the first processing computer, while the data values ​​of the data items "Name" and "Email Address" can be transmitted to the second processing computer.

[0078] As another example, the first processing computer may be adapted to process the data value of the data item "grocery SKU", while the second processing computer may be adapted to process the data value of the data item "electronic device SKU". The distribution rule module 208C may determine that the data value of the data item "grocery SKU" can be transmitted to the first processing computer, while the data value of the data item "electronic device SKU" can be transmitted to the second processing computer.

[0079] The routing module 208D, together with the processor 204, can generate multiple authorization request messages, each including at least one data value, and transmit the multiple authorization request messages to multiple processing computers. The routing module 208D can transmit the multiple authorization request messages through any suitable communication channel described herein.

[0080] Figure 3 A block diagram of an authorization computer 300 according to an embodiment of the present invention is shown. An exemplary authorization computer 300 may include a processor 304. The processor 304 may be coupled to a memory 302, a network interface 306, and a computer-readable medium 308 including a result analysis module 308A, an authorization module 308B, and a response module 308C.

[0081] Memory 302 may be similar to memory 202, and will not be repeated here. Network interface 306 may be similar to network interface 206, and will not be repeated here. Computer-readable medium 308 may include code executable by processor 304 to perform the functionalities described herein.

[0082] In some specific instances, the authorization computer 300 may include a result analysis module 308A. The result analysis module 308A, together with the processor 304, can analyze one or more results received from one or more processing computers. The result analysis module 308A, for example, together with the processor 304, can compare information received via multiple authorization request messages with information stored at the authorization computer 300 and / or a suitable database (e.g., including verification values).

[0083] The authorization module 308B, together with the processor 304, can perform some or all of the functionality associated with authorizing an interaction, which is associated with multiple authorization request messages. These authorization request messages can be associated with interactions between a user and a resource provider. The multiple authorization request messages can include any suitable information that can be used to authorize or identify the interaction.

[0084] In some embodiments, the authorization module 308B may determine whether to authorize the interaction based on the analysis of the results. For example, the results may indicate that the biometric template received from the user does not match a previously stored biometric template. Because the biometric templates do not match, the authorization module 308B may determine not to authorize the interaction.

[0085] As another example, the result could indicate that the data item "Electronic Device SKU" has triggered a fraud warning. For instance, the data value associated with the "Electronic Device SKU" data item could indicate a total amount of $15,000, which could indicate a high probability of fraud. Due to the high probability of fraud, the authorization module 308B, together with the processor 304, can determine not to authorize the interaction. In other embodiments, if a low probability of fraud exists, the authorization module 308B can determine to authorize the interaction.

[0086] The response module 308C, together with the processor 304, can generate authorization response messages. In some embodiments, the response module 308C can generate multiple authorization response messages corresponding to multiple received authorization request messages. The authorization response messages may include an indication of whether to authorize the interaction between the user and the resource provider. In some embodiments, the authorization response messages may further include data values ​​and / or data headers. The authorization computer 300 may be configured to transmit multiple authorization response messages to multiple processing computers or data distribution computers via any suitable communication channel described herein.

[0087] Figure 4 A block diagram illustrating a method for distributing data values ​​according to an embodiment of the present invention is shown. System 400 includes a data distribution computer 402, a first processing computer 404, a second processing computer 406, a third processing computer 408, and an authorization computer 410. For simplicity of description, Figure 4 A certain number of components are shown. However, it should be understood that embodiments may include more than one of each component. Furthermore, some embodiments of the invention may include more than one of each component. Figure 4 All components shown are either fewer or more components.

[0088] Data distribution computer 402 can be used from any suitable computer (e.g., Figure 1 The access device 104 described herein receives data packets. A data packet may include multiple data values. For example, a data packet may include four data values, including di1, di2, di3, and di4. However, it should be understood that a data packet may include any suitable number of data values. In some embodiments, the data distribution computer 402 may receive data packets in response to interactions between a resource provider associated with the access device and a user of a user device.

[0089] The data distribution computer 402 can determine the data item for each of a plurality of data values. For example, the data distribution computer 402 can determine that di1 has a fingerprint biometric identification template as a data item. The data distribution computer 402 can also determine that di2 has a telephone number as a data item, di3 has a username as a data item, and di4 has a password as a data item.

[0090] For example, by evaluating the characteristics of data values ​​such as the size of di1 (e.g., 9 to 6 kb, etc.), data distribution computer 402 can determine that di1 has a fingerprint biometric identification template. Additionally, data distribution computer 402 can determine that di1 has a Common Biometric Exchange File Format (CBEFF) format. Data distribution computer 402 can determine that di2 has a telephone number data item because it is in the format "xxx-xxx-xxxx". By determining that the access device used to receive the data packets also transmits the username and password at a frequency of 95% when transmitting the fingerprint biometric identification template, data distribution computer 402 can further determine that di3 and di4 each have a username and password data item. Data distribution computer 402 can further confirm the data items of di3 and di4 by evaluating their sizes (e.g., between 7 and 99 characters, etc.).

[0091] After determining the data item for each data value, the data distribution computer 402 can use the data item to associate each data value with a processing computer. For example, the data distribution computer 402 can determine that di1 (fingerprint biometric template) can be transmitted to a first processing computer 404 (e.g., a biometric analysis computer operatively coupled to a biometric template database). The data distribution computer 402 can also determine that di2 (telephone number) can be transmitted to a second processing computer 406 (e.g., a user telephone authentication computer), and di3 (username) and di4 (password) can be transmitted to a third processing computer 408 (e.g., a user account hosting server computer). The data distribution computer 402 can determine the processing computer using any suitable method described herein, such as by using a table to associate the data item for each data value with a processing computer.

[0092] The data distribution computer 402 can then generate multiple authorization request messages, each including at least one data value. For example, the data distribution computer 402 can generate three authorization request messages: a first authorization request message including di1, a second authorization request message including di2, and a third authorization request message including di3 and di4. After generating the multiple authorization request messages, the data distribution computer 402 can transmit the multiple authorization request messages to multiple processing computers suitable for processing the data values ​​in the respective authorization request messages. For example, the data distribution computer 402 can transmit the first authorization request message to a first processing computer 404, the second authorization request message to a second processing computer 406, and the third authorization request message to a third processing computer 408.

[0093] Upon receiving multiple authorization request messages, each processing computer can process the data values ​​in the corresponding authorization request message. For example, the first processing computer 404 can compare the fingerprint biometric template with multiple stored biometric templates stored in a biometric template database.

[0094] The first processing computer 404 can process any suitable type of biometric template (e.g., fingerprint, iris, face, etc.). The first processing computer 404 can process the biometric template in any suitable manner, such as as described in U.S. Patent Application No. 9,847,997, filed November 11, 2015, entitled "Server Based Biometric Authentication," which is incorporated herein by reference. The first processing computer 404 can determine a result r1 that can indicate whether the biometric template matches. In some embodiments, r1 may include a match score.

[0095] Furthermore, the second processing computer 406 can, for example, generate code and transmit the code to a telephone associated with the received telephone number. In some embodiments, the telephone can be a user device. After receiving the code, the user can enter the code into a webpage associated with the second processing computer 406. The second processing computer 406 can then determine whether the received code matches the transmitted code. If they match, the second processing computer 406 can output a result r2, such as "match".

[0096] The third processing computer 408 can compare user credentials, including a username and password, with user credentials stored in a user database. The third processing computer 408 can determine whether a received credential matches a stored credential. The stored credential can be stored in any suitable manner. For example, the stored credential can be encrypted before storage (e.g., via MD5, MD6, SHA-256, etc.). In some embodiments, the third processing computer 408 can compare the encrypted received user credential with the encrypted stored credential. In other embodiments, the stored credential can be salted before hashing with a hash function. For example, a salt, which may be a random value, can be concatenated with the user credential before it is fed into the hash function. The salt can be a static salt or a dynamic salt generated by a random string generator, as known to those skilled in the art. The salt value can be used to prevent replay attacks.

[0097] The third processing computer 408 can output a result (e.g., r3). ​​The result determined by the third processing computer 408 can be an indication of whether the received username and password match previously stored usernames and passwords. For example, r3 could be "match" or "not match".

[0098] After each processing computer processes the data value, each processing computer may forward multiple authorization request messages to authorization computer 410. In some embodiments, each of the processing computers may insert a result (determined by the respective processing computer) into the authorization request message. In other embodiments, the multiple authorization request messages may not be modified by the multiple processing computers. For example, first processing computer 404 may forward a first authorization request message to authorization computer 410. Second processing computer 406 and third processing computer 408 may forward a second authorization request message and a third authorization request message to authorization computer 410, respectively.

[0099] The authorizing computer 410 can receive multiple authorization request messages from multiple processing computers. For example, the authorizing computer 410 can receive a first authorization request message including at least di1 from the first processing computer 404.

[0100] In some embodiments, the authorizing computer 410 may receive each of the authorization request messages at different times based on the processing time of the processing computer. For example, when the third processing computer 408 can process di3 and di4 and before the first processing computer 404 processes di1, the authorizing computer 410 may receive the third authorization request message before the first authorization request message.

[0101] The authorization computer 410 can then analyze each authorization request message to authorize or deny the interaction between the resource provider and the user. For example, the authorization computer 410 may include multiple authorization rules that can be used to determine whether an authorization request is valid. The authorization rules may include multiple conditions that can be compared with the parameters of the authorization request. If the parameters of the authorization request satisfy one or more conditions of one or more authorization rules, then the authorization computer 410 may determine that the authorization request should be denied (e.g., denying the user access to the resource). The authorization computer 410 may generate an authorization response message for each authorization request message. The authorization response message may include a result indication indicating whether the authorization request was denied or accepted.

[0102] Figure 5 A block diagram illustrating the splitting of data packets according to an embodiment of the present invention is shown. Figure 5 This includes data packet 520, first authorization request message 540, and second authorization request message 560.

[0103] Data packet 520 may include multiple data values ​​524. These multiple data values ​​may include data value 1, data value 2, and data value 3. Data packet 520 may further include a data header 522.

[0104] The data distribution computer can receive data packets 520 from the access device or other suitable computer. The data distribution computer can store tables that associate data items with processing computers. For example, the data distribution computer can store the following table:

[0105] Processing computers First Processing Computer First Processing Computer Second processing computer Third processing computer Data Items Data item 1 Data item 2 Data item 3 Data item 4

[0106] The data distribution computer can determine that data value 1 corresponds to data item 1, data value 2 corresponds to data item 2, and data value 3 corresponds to data item 3. The data distribution computer can then associate data value 1 and data value 2 with a first processing computer, and can then associate data value 3 with a second processing computer.

[0107] After determining the data item for each data value and associating each data value with a processing computer, as described herein, the data distribution computer can generate multiple authorization request messages, each including at least one data value. For example, the data distribution computer can generate a first authorization request message 540 and a second authorization request message 560.

[0108] The first authorization request message 540 may include data value 1 and data value 2. In some embodiments, the first authorization request message may further include a data header 542. Header 542 may include supplementary data (e.g., data about the interaction, device identifiers for routing, etc.). The second authorization request message 560 may include data value 3. In some embodiments, the second authorization request message 560 may further include a data header 562, which may be similar to data header 542.

[0109] After the data distribution computer generates multiple authorization request messages, it can transmit these messages to a previously determined processing computer among multiple processing computers.

[0110] Figure 6 A flowchart of an interaction method according to an embodiment of the present invention is shown. It will be described in the context of user interaction with a resource provider. Figure 6The method described herein allows users to submit data packets containing multiple data values ​​associated with authentication data. For example, a user may be authenticated before accessing a secure location. However, it should be understood that the invention can be applied to other types of interactions (i.e., data interactions, payment interactions, secure webpage interactions, etc.). Although the steps are shown in a specific order, it should be understood that embodiments of the invention may include methods with steps performed in a different order. Furthermore, steps may be omitted or added, and these steps may still be within the scope of embodiments of the invention.

[0111] Prior to step 615, user device 602 may capture data from the user, and as described herein, user device 602 may convert the data into data values. For example, user device 602 may capture biometric samples from the user and convert the biometric samples into biometric templates (i.e., data values). Step 615 may be performed when the user initiates an interaction with a resource provider. For example, in some embodiments, the user may use user device 602 to communicate with access device 604. In some embodiments, access device 604 may request specific data values ​​from user device 602.

[0112] At step 615, user device 602 can transmit data packets to access device 604. In some embodiments, the user can interact with access device 604 using, for example, a credit card. For instance, the user can bring their credit card and insert it into a slot in access device 604, or slide it into a slot in access device 604. A device reader of access device 604 can read data packets from user device 602. In other embodiments, the user can input data packets into access device 604 using a keyboard or touchscreen. Data packets can include multiple data values. For example, data packets can include data values ​​containing a fingerprint biometric template, a phone number, a username, and a password.

[0113] At step 620, after receiving the data packet, the access device 604 may transmit the data packet to the data distribution computer 606. In some embodiments, the access device 604 may generate an authorization request message including the data packet, and may then transmit the authorization request message to the data distribution computer 606.

[0114] At step 625, after receiving the data packet, the data distribution computer 606 can determine the data item for each of a plurality of data values. The data distribution computer 606 can analyze the characteristics of the data values ​​to determine the data item. For example, the data distribution computer 606 can determine that the data value has the data item "telephone number" based on, for example, the length of the data value (e.g., 10 bits), the frequency with which telephone numbers are received from a particular access device 604 (e.g., 60%, 85%, etc.), and / or any other suitable characteristics as described herein.

[0115] At step 630, the data distribution computer 606 may then associate each data value with a processing computer using the data item for each data value. The data distribution computer 606 may determine the processing computer associated with a specific data item in a lookup table or database as described herein. For example, the data distribution computer 606 may determine that the data value of a fingerprint biometric template is associated with a first processing computer, the data value of a telephone number is associated with a second processing computer, and the data values ​​of both the username and password are associated with a third processing computer.

[0116] At step 635, after associating each data value with a processing computer, the data distribution computer 606 may generate multiple authorization request messages, each including at least one data value, as described herein. At steps 640, 645, and 650, the data distribution computer 606 may transmit the multiple authorization request messages to multiple processing computers 608. For example, the data distribution computer 606 may transmit a single authorization request message to each of the processing computers associated with the data value.

[0117] At steps 655, 660, and 665, after receiving multiple authorization request messages, each of the multiple processing computers 608 can process the authorization request messages. For example, a first processing computer among the multiple processing computers 608 can receive an authorization request message that includes data values ​​of a user's fingerprint biometric template. Each of the multiple processing computers can determine a result after processing the data values ​​in the corresponding authorization request message.

[0118] The first processing computer can determine whether a biometric template matches a previously stored biometric template associated with a user. The first processing computer can determine, for example, a match score indicating the similarity between two biometric templates. The first processing computer can output the result. In this case, the match score can be the result of the first processing computer.

[0119] A second processing computer among multiple processing computers 608 can receive an authorization request message including a data value of a user's phone number. The second processing computer can perform any suitable authentication process using the user's phone number. For example, the second processing computer can transmit a code and a link to a website to a telephone associated with the received phone number. For example, the code and link can be transmitted via SMS or any other suitable communication channel. In some embodiments, the telephone can be a user device 602. After receiving the code and the link to the website, the user can activate the link (e.g., click the link), which can direct a web browser on the telephone to a specific website run by the second processing computer. The user can enter a code into a data field on the webpage to verify that the user possesses a phone number. The second processing computer can then determine whether the received code matches the transmitted code. The second processing computer can output an indication as a result of whether the user has been authenticated via phone number.

[0120] A third processing computer among the multiple processing computers 608 can receive an authorization request message including a user's username and a user's password. The third processing computer can determine whether the username and password match previously stored usernames and passwords. The third processing computer can output an indication of whether the username and password are correct (i.e., "yes" or "no") as a result.

[0121] At steps 670, 675, and 680, each of the plurality of processing computers 608 may forward multiple authorization request messages to the authorization computer 610. In some embodiments, each processing computer may process multiple authorization request messages at different time intervals. Each processing computer may forward authorization request messages to the authorization computer 610 at different times.

[0122] In some embodiments, the processing computer may insert the result into the authorization request message. For example, if the first processing computer determines that the biometric template does not match a stored biometric template, the result could be a match score of 0. The first processing computer may insert the result into the authorization request message so that the authorization computer 610 can utilize the information that the biometric template does not match.

[0123] In other embodiments, the processing computer may not insert the result into the authorization request message unless there is a predetermined problem with the result, such as a match score indicating a mismatch between the biometric template and the actual biometric template. For example, the first processing computer may determine that the biometric template does indeed match a stored biometric template. The first processing computer may then determine not to insert the result into the authorization request message because the first processing computer may not need to notify the authorization computer 610 of the match.

[0124] At step 685, after receiving multiple authorization request messages, the authorization computer 610 can determine whether the interaction can be authorized. The authorization computer 610 can determine whether authorization can be granted for each of the authorization request messages. In some embodiments, the authorization computer 610 can perform any appropriate fraud checks on the interaction and can assess whether the user's account has sufficient funds and / or credit. If the user has sufficient funds and / or credit, then the interaction can be approved. In some embodiments, the authorization computer 610 can include multiple authorization rules available to determine whether an authorization request is valid.

[0125] In some embodiments, the authorization computer 610 may include dynamic rules that can determine which user account is associated with an authorization request message based on data items in the authorization request message. For example, dynamic rules may include rules that allow data items of a biometric template type to be associated with a user's authenticated account. As another example, a dynamic rule could be to apply data items representing a request to access a user's employer's location to a user account that may have been set up by the employer. The authorization computer 610 may determine the user account associated with each authorization request message based on at least one data item included in the authorization request message.

[0126] As another example, other data values ​​and data items can be used to perform [the task]. Figure 6 The steps in the process. For example, when a user initiates an interaction with a resource provider, step 615 can be performed. The interaction between the user and the resource provider can be a transaction. The user can select the data value they want to purchase.

[0127] At step 615, user device 602 can transmit a data packet to access device 604. The data packet may include multiple data values. For example, the data packet may include data values ​​such as "APPL04", "ORNG01", and "TV02", which may correspond to the data items "grocery SKU", "grocery SKU", and "electronic device SKU", respectively. For example, a user can try to purchase Fuji apples, navel oranges, and a 40-inch LCD TV.

[0128] At step 620, after receiving the data packet, the access device 604 can transmit the data packet to the data distribution computer 606. At step 625, after receiving the data packet, the data distribution computer 606 can determine the data item for each of a plurality of data values. For example, the data distribution computer 606 can store a lookup table that associates data values ​​with data items. The data distribution computer 606 can determine that the data value “APPL04” is associated with the data item “grocery SKU” in the lookup table. Similarly, the data distribution computer 606 can determine that the data value “ORNG01” is associated with the data item “grocery SKU” in the lookup table, and can determine that the data value “TV02” is associated with the data item “electronic device SKU”.

[0129] At step 630, the data distribution computer 606 may then associate each data value with a processing computer using the data item for each data value. The data distribution computer 606 may determine the processing computer associated with a specific data item in a lookup table or database as described herein. For example, the data distribution computer 606 may determine that two data values ​​for a grocery SKU are associated with a first processing computer, and that the data value for an electronic device SKU is associated with a second processing computer.

[0130] At step 635, after associating each data value with a processing computer, the data distribution computer 606 may generate multiple authorization request messages, each including at least one data value, as described herein. At steps 640 and 645, the data distribution computer 606 may transmit the multiple authorization request messages to multiple processing computers 608. For example, the data distribution computer 606 may transmit one authorization request message to each of the processing computers associated with the data value. It should be noted that in this example, there are two processing computers instead of three, so step 650 may not be performed.

[0131] At steps 655 and 660, after receiving multiple authorization request messages, each of the multiple processing computers 608 can process the authorization request messages. It should be noted that in this example, there are two processing computers instead of three, so step 665 may not be performed.

[0132] A first processing computer among multiple processing computers 608 can receive an authorization request message including the data values ​​"APPL04" and "ORNG01". The first processing computer can determine that the transaction fraud risk is high probability or low probability. For example, the first processing computer can determine that the two data values ​​of the data item "grocery SKU" have a low probability of being fraudulently purchased by a malicious party. In some embodiments, the first processing computer can perform evaluations in association with the data values. For example, the data value "APPL04" can be associated with the amount "$1.23", while the data value "ORNG" can be associated with the amount "$0.86". The first processing computer can determine that the total amount "$2.09" is less than a predetermined threshold. The predetermined threshold could be, for example, groceries of $1000, because a total amount of groceries less than $1000 has a low probability of fraud.

[0133] A second processing computer among the plurality of processing computers 608 can receive an authorization request message including the data value "TV02". The second processing computer can perform more rigorous fraud analysis than the first processing computer because electronic devices can have a higher rate of fraudulent purchases than groceries. The second processing computer can perform any suitable fraud analysis known to those skilled in the art.

[0134] At steps 675 and 680, each of the plurality of processing computers 608 may forward multiple authorization request messages to the authorization computer 610. Note that in this example, there are two processing computers instead of three, so step 670 may not be performed. At step 685, after receiving the multiple authorization request messages, the authorization computer 610 may determine whether interactive authorization is possible. The authorization computer 610 may determine whether authorization can be granted for each of the authorization request messages.

[0135] In some embodiments, the authorizing computer 610 may include dynamic rules that can determine which user account is associated with the authorization request message based on data values ​​in the authorization request message. For example, dynamic rules may include a rule that the data value of the data item electronic device SKU will charge a user's checking account an amount greater than $1,000.

[0136] Figure 7 A flowchart illustrating an authorization response message method according to an embodiment of the present invention is shown. It will be described in the context of user-resource provider interaction. Figure 7The method described herein. Users can submit data packets including multiple data values ​​associated with authentication data. For example, a user can be authenticated before accessing a secure location. However, it should be understood that the invention can be applied to other types of interactions (i.e., data interactions, payment interactions, secure webpage interactions, etc.). Although the steps are shown in a specific order, it should be understood that embodiments of the invention may include methods with steps performed in a different order. Furthermore, steps may be omitted or added, and these steps may still be within the scope of embodiments of the invention. Steps 715 to 755 may be performed after steps 615 to 685, as... Figure 6 As described in the text.

[0137] At step 715, the authorization computer 710 may generate multiple authorization response messages. Each authorization response message may approve or reject the interaction. The authorization computer 710 may generate multiple authorization response messages based on corresponding analysis of multiple authorization request messages. An authorization response message may correspond to one of the authorization request messages. In some embodiments, an authorization request message may include a data value. In other embodiments, an authorization request message may further include a data header and / or a result.

[0138] At steps 720, 725, and 730, the authorizing computer 710 may transmit multiple authorization response messages to multiple processing computers 708. The authorizing computer 710 may transmit authorization response messages to processing computers, and the authorizing computer 710 may receive authorization request messages from the processing computers. For example, the authorizing computer 710 may receive a first authorization request message from a first processing computer and a second authorization request message from a second processing computer. The authorizing computer 710 may generate two authorization response messages, including a first authorization response message and a second authorization response message. The first authorization response message may be a response corresponding to the first authorization request message, and the second authorization response message may be a response corresponding to the second authorization request message.

[0139] At steps 735, 740, and 745, after receiving multiple authorization response messages, the multiple processing computers 708 may forward the multiple authorization response messages to the data distribution computer 706. In some embodiments, each of the processing computers may perform any suitable fraud risk analysis on the authorization response messages.

[0140] At step 750, after receiving multiple authorization response messages, the data distribution computer 706 may forward the multiple authorization response messages to the access device 704. In some embodiments, the data distribution computer 706 may receive each of the authorization response messages at different times. The data distribution computer 706 may forward each of the authorization response messages after receiving and possibly processing them.

[0141] In other embodiments, the data distribution computer 706 may wait until it has received all authorization response messages from the multiple processing computers 708. The data distribution computer 706 may then transmit all authorization response messages at the same time or substantially at the same time. In other embodiments, the data distribution computer 706 may aggregate all received authorization response messages into a single authorization response message and then transmit the authorization response message to the access device 704.

[0142] At step 755, after receiving multiple authorization response messages, access device 704 may forward the multiple authorization response messages or derivatives thereof to user device 702. Access device 704 may, for example, notify the user whether to authorize the interaction via a message transmitted to user device 702.

[0143] In some embodiments, access device 704 can determine whether each authorization response message indicates that the interaction is authorized or denied. In some embodiments, if at least one of the authorization response messages indicates that the interaction is denied, then access device 704 can determine that the entire interaction is denied. In other embodiments, if at least one of the authorization response messages indicates "denied," then access device 704 can determine that a portion of the interaction is denied, and if at least one of the authorization response messages indicates "authorized," then access device 704 can determine that a portion of the interaction is authorized.

[0144] For example, the resource provider could be a merchant from which a user is attempting to purchase groceries and a television. If an authorization response message corresponding to a data value representing the groceries is authorized, then access device 704 (or, in some embodiments, the resource provider's computer) can determine that the user can receive the groceries. If an authorization response message corresponding to a data value representing the television is rejected, then access device 704 can determine that the user is not authorized to receive the television. The resource provider may make groceries, rather than a television, available to the user.

[0145] Figure 8 A flowchart illustrating an authorization response message method according to an embodiment of the present invention is shown. It will be described in the context of user-resource provider interaction. Figure 8 The method described herein. Users can submit data packets including multiple data values ​​associated with authentication data. For example, a user can be authenticated before accessing a secure location. However, it should be understood that the invention can be applied to other types of interactions (i.e., data interactions, payment interactions, secure webpage interactions, etc.). Although the steps are shown in a specific order, it should be understood that embodiments of the invention may include methods with steps performed in a different order. Furthermore, steps may be omitted or added, and these steps may still be within the embodiments of the invention. Steps 815 to 830 may be performed after steps 615 to 685, as... Figure 6 As described in the text.

[0146] At step 815, after analyzing each authorization request message and determining whether to grant interactive authorization (at step 685), the authorization computer 810 may generate multiple authorization request messages, similar to step 715 described above.

[0147] At step 820, after generating multiple authorization response messages, the authorization computer 810 may transmit the multiple authorization response messages to the data distribution computer 806. In some embodiments, the authorization computer 810 may transmit the multiple authorization response messages when the analysis of the corresponding authorization request message is completed. In other embodiments, the authorization computer 810 may transmit the multiple authorization response messages at the same time or approximately at the same time.

[0148] At step 825, after receiving multiple authorization response messages, the data distribution computer 806 may forward the multiple authorization response messages to the access device 804.

[0149] At step 830, in some embodiments, access device 804 may forward multiple authorization response messages to user device 802. In other embodiments, access device 804 may notify user device 802 whether the interaction between the user and the resource provider is authorized by authorization computer 810.

[0150] In some embodiments, at least one authorization response message (i.e., a denied authorization response message) may indicate that the authorization has been denied. For example, the data values ​​in a denied authorization response message may include a username and password. The username and / or password may have been entered incorrectly by the user, thus resulting in a denied interaction. The user can re-enter the username and password into the user device 802.

[0151] User device 802 may transmit a second data packet, including data values ​​(e.g., username and password) associated with a denied authorization response message, to access device 804. The second data packet may be in response to a second interaction between the resource provider and the user. Access device 804 may forward the second data packet to data distribution computer 806.

[0152] After receiving the second data packet, the data distribution computer 806 can determine the data item associated with each of the data values ​​in the second data packet. The data distribution computer 806 can then perform any suitable processing of the data packet as described herein. For example, the processing can be similar to steps 615 to 685 and 715 to 755 or 815 to 830.

[0153] Users and resource providers may only need to perform a second interaction using the data values ​​associated with the denied authorization response message, rather than reusing all data values. For example, a user may not need to re-enter their fingerprint biometric sample because the authorization computer 810 has already authorized the authorization request message associated with the fingerprint biometric template. In other embodiments, users and resource providers may determine the restricted interaction based on which data values ​​are associated with the authorized authorization response message.

[0154] In some embodiments, multiple data values ​​may be associated with a data item “Product Data” (e.g., SKU Data). SKU Data may be Level 1 (L1) SKU Data, Level 2 (L2) SKU Data, or Level 3 (L3) SKU Data. L1 Data may include the transaction amount (i.e., the sum) and the date. L2 Data may include L1 Data along with tax, customer code (e.g., a 30-character string), merchant postal code, tax identification code, merchant minority code, and merchant status code. L3 Data may include L2 Data along with the shipping postal code, destination postal code, invoice number, order number, product code, commodity code, commodity description, commodity quality, commodity unit of measurement, commodity extended amount, shipping cost, and customs duty amount.

[0155] After the data distribution computer receives a data packet containing data values ​​from the access device, it can determine that the data item associated with the data value is product data. The data item can be product data of a specific type. For example, the data item could be data for electronic products, jewelry, groceries, clothing, pet supplies, children's toys, or any other suitable type of product data. The data distribution computer can then associate each data value with a processing computer (e.g., a network computer). For example, the data distribution computer can send the data value associated with the SKU data of "electronic device" to a first processing computer in a first authorization request message. The data distribution computer can further send the data value associated with the SKU data of "groceries" to a second processing computer in a second authorization request message. Each processing computer can forward the authorization request message to an authorization computer. The authorization computer can then analyze each authorization request message to authorize or deny the interaction. The authorization computer can then generate multiple authorization response messages corresponding to the multiple authorization request messages and transmit them to the data distribution computer. The data distribution computer can then forward each of the authorization response messages to the access device.

[0156] Embodiments of the present invention offer several advantages. For example, data packets can be split based on underlying data values. Data values ​​extracted from the data packets can be transmitted to various processing computers in an authorization request message. Each processing computer can have different capabilities for processing the received data values. Instead of a single processing computer processing each data value in the data packet, each processing computer can process the received data values ​​in parallel, thus improving the overall computation time.

[0157] Furthermore, because multiple data values ​​are transmitted to different processing computers, the security of the data values ​​is improved. A single data breach at a processing computer may not affect all data values. Data values ​​received only by a compromised processing computer may be compromised.

[0158] Any software component or function described in this application may be implemented as software code to be executed by a processor using any suitable computer language such as Java, C, C++, C#, Objective-C, Swift, or a scripting language such as Perl or Python, employing techniques such as conventional or object-oriented methods. The software code may be stored as a series of instructions or commands on a computer-readable medium for storage and / or transmission. Suitable media include random access memory (RAM), read-only memory (ROM), magnetic media such as hard disk drives or floppy disks, or optical media such as optical discs (CDs) or digital versatile discs (DVDs), flash memory, and the like. The computer-readable medium may be any combination of such storage or transmission means.

[0159] Such programs can also be encoded and transmitted using carrier signals adapted for transmission via wired, optical, and / or wireless networks conforming to various protocols, including the Internet. Therefore, computer-readable media according to embodiments of the invention can be created using data signals encoded with such programs. Computer-readable media encoded with program code can be packaged with compatible devices or provided separately from other devices (e.g., downloaded via the Internet). Any such computer-readable medium can reside on or within a single computer product (e.g., a hard disk drive, CD, or an entire computer system) and can exist on or within different computer products within a system or network. A computer system may include a monitor, printer, or other suitable display for providing any of the results mentioned herein to a user.

[0160] The above description is illustrative and not restrictive. Many variations of the invention will become apparent to those skilled in the art upon reading this disclosure. Therefore, the scope of the invention should not be determined by reference to the foregoing description, but rather by reference to the pending claims and their full scope or equivalents.

[0161] Without departing from the scope of the invention, one or more features of any embodiment may be combined with one or more features of any other embodiment.

[0162] As used herein, unless explicitly indicated otherwise, the terms “a,” “an,” or “the” are intended to mean “at least one.”

Claims

1. A method for data value routing, the method comprising: receiving, by a data distribution computer, a data packet comprising a plurality of data values in response to an interaction between a resource provider and a user; determining, by the data distribution computer, a data item for each data value of the plurality of data values; associating, by the data distribution computer, each data value with a processing computer using the data item for each data value; generating, by the data distribution computer, a plurality of authorization request messages comprising at least one data value; and transmitting, by the data distribution computer, the plurality of authorization request messages to a plurality of processing computers adapted to process the data value in the respective authorization request message, wherein the plurality of processing computers processes the data value in the respective authorization request message, wherein the plurality of authorization request messages are subsequently forwarded to an authorization computer, wherein the authorization computer analyzes each authorization request message to authorize or deny the interaction, wherein the authorization computer generates a plurality of authorization response messages based on respective analysis of the plurality of authorization request messages, wherein each authorization response message corresponds to one of a plurality of authorization request messages, and the authorization computer transmits the plurality of authorization response messages to the plurality of processing computers, respectively, wherein the plurality of processing computers forwards the plurality of authorization response messages to the data distribution computer, wherein the method further comprises: receiving, by the data distribution computer, the plurality of authorization response messages from the plurality of processing computers.

2. The method of claim 1, wherein the data packet is received from an access device.

3. The method of claim 2, wherein the method further comprises: forwarding, by the data distribution computer, the plurality of authorization response messages to the access device.

4. The method of claim 1, wherein the data item comprises a biometric template, a phone number, product data, a name, a user credential, a security code, a location access code, a physical address, a location, an IP address, an email address, a user identifier, and / or a device identifier.

5. The method of claim 1, wherein the plurality of processing computers comprises an authentication processing computer and / or a network computer.

6. The method of claim 1, wherein each processing computer of the plurality of processing computers determines a result after processing the data value in the respective authorization request message and transmits the result to the authorization computer, wherein the authorization computer further analyzes the result received from each processing computer.

7. The method of claim 1, wherein the authorization computer analyzes each authorization request message based on the at least one data value.

8. The method of claim 7, wherein the authorization computer determines a user account associated with each authorization request message based on the at least one data value.

9. The method of claim 1, wherein at least one authorization response message indicates that the interaction is denied, wherein the method further comprises: ​ receiving, by the data distribution computer, a second data package comprising data values associated with the at least one authorization response message in response to a second interaction between the resource provider and the user.

10. A data distribution computer comprising: a processor; a memory device; and a computer readable medium coupled to the processor, the computer readable medium comprising code, executable by the processor, to implement a method comprising: receiving, in response to an interaction between a resource provider and a user, a data package comprising a plurality of data values; determining a data item for each data value of the plurality of data values; associating each data value with a processing computer using the data item for each data value; generating a plurality of authorization request messages comprising at least one data value; transmitting the plurality of authorization request messages to a plurality of processing computers adapted to process the data values in the respective authorization request messages, wherein the plurality of processing computers processes the data values in the respective authorization request messages, wherein the plurality of authorization request messages are subsequently forwarded to an authorization computer, wherein the authorization computer analyzes each authorization request message to authorize or deny the interaction, wherein the authorization computer generates a plurality of authorization response messages based on respective analyses of the plurality of authorization request messages, wherein each authorization response message corresponds to one of the plurality of authorization request messages, and the authorization computer transmits the plurality of authorization response messages to the plurality of processing computers, respectively, wherein the plurality of processing computers forwards the plurality of authorization response messages to the data distribution computer, wherein the method further comprises: receiving the plurality of authorization response messages from the plurality of processing computers.

11. The data distribution computer of claim 10, wherein the data package is received from an access device.

12. The data distribution computer of claim 11, wherein the method further comprises: forwarding the plurality of authorization response messages to the access device.

13. The data distribution computer of claim 10, wherein the data item comprises a biometric template, a phone number, product data, a name, a user credential, a security code, a location access code, a physical address, a location, an IP address, an email address, a user identifier, and / or a device identifier.

14. The data distribution computer of claim 10, wherein the plurality of processing computers comprises an authentication processing computer and / or a network computer.

15. The data distribution computer of claim 10, wherein each processing computer of the plurality of processing computers determines a result after processing the data values in the respective authorization request messages, and transmits the result to the authorization computer, wherein the authorization computer further analyzes the result received from each processing computer.

16. The data distribution computer of claim 10, wherein the authorization computer analyzes each authorization request message based on the at least one data value.

17. The data-dispensing computer of claim 16, wherein the authorization computer determines a user account associated with each authorization request message based on the at least one data value.

18. The data-dispensing computer of claim 10, wherein at least one authorization response message indicates that the interaction is declined, wherein the method further comprises: receiving a second data packet comprising a data value associated with the at least one authorization response message in response to a second interaction between the resource provider and the user.

Citation Information

Patent Citations

  • Server based biometric authentication

    US9847997B2

  • System and method for new execution and management of financial and data transactions

    US20150186889A1