Systems and methods for enhanced authorization messages
By generating session identifiers and associated with user interaction data, the problems of resource waste and authorization process delay in the prior art are solved, and a more efficient and reliable authorization process is achieved.
Patent Information
- Application Number
- CN201880098778.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2018-10-17
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2038-10-17
AI Technical Summary
The prior art is difficult to efficiently utilize authentication data for dynamic and reliable risk assessment when users interact with resource providers, resulting in resource waste and delays in authorization processes.
By generating session identifiers associated with user interaction data, stored in a supplementary database, and using processor computers and authorized computers for risk analysis, modifying authorization request messages to include session identifiers and related data, achieving a more efficient authorization process.
It improves the efficiency and reliability of the authorization process, reduces waste of resources, and improves the speed and accuracy of user interaction.
Smart Images

Figure CN112868005B_ABST
Abstract
Description
[0001] Cross-reference to related applications
[0002] none. Background Art
[0003] As users increasingly use portable computing devices (e.g., desktop computers, laptops, tablet computers, mobile phones, gaming devices, etc.) to interact with resource providers over networks including the Internet, the risk that an interaction may be a fraudulent interaction has increased for resource providers. It may be difficult for resource providers to distinguish which interactions are being performed by legitimate users and which interactions are being performed by people attempting to commit fraudulent activities. Data can be collected or aggregated from multiple sources, such as authentication services, to determine a single risk assessment based on the overall data available to the user and the user's interactions with the resource provider or other resources. However, using this data has several disadvantages. For example, unnecessary financial, system, and network resources may sometimes be required to collect and aggregate the data available about the user and their interactions.
[0004] However, authentication services may only utilize certain data points from a large collection of data to identify risk assessments, thereby unnecessarily utilizing resources to obtain and store data that is not helpful to the risk assessment process. Furthermore, static data points or models may be used by authentication services, making them unable to adapt to new fraudulent activity trends or new user data that may be obtained through their interactions with resource providers, thereby providing inaccurate risk assessment scores. During transactions or interactions with resource providers, authorization of the interaction may be performed, which may utilize risk analysis performed by the authentication service. However, implementing or appropriately utilizing risk analysis in authorization services may result in the use of additional financial, system, and network resources, thereby slowing down the authorization process to the point where user interactions are impacted and resource providers lose transactions. Therefore, there is a need for new, enhanced methods for modifying the authorization process that more efficiently utilize authentication data while providing a dynamic and reliable authorization service for interactions with resource providers. Summary of the Invention
[0005] Described herein are systems and techniques for authorizing transactions or interactions of a user, where the transactions or interactions are modified for the same user using authentication information. Data from an external entity, such as an authentication service, can be analyzed using a risk assessment model, and data points obtained from users interacting with a resource provider and / or the authentication service can be stored in a database (a supplemental database) along with a derived authentication risk assessment value or score. In embodiments, when a user interacts with a resource provider or otherwise conducts a transaction or utilizes an authentication service, a session identifier can be generated and associated with the data and authentication risk assessment value in the database. According to at least one embodiment, a resource provider or other entity, such as a transmission computer acting on behalf of the resource provider, can invoke the modified authorization features described herein by providing transaction information and a session identifier that matches a session identifier stored in a database in an authorization request message. A processor computer can receive the authorization request message and, using the session identifier, obtain a portion of the data stored in the database to perform a risk analysis on the authorization request message using the portion of the data. According to at least one embodiment, the authorization request message can be modified to represent the portion of the data obtained from the data store and the risk analysis score performed using the portion of the data. The processor computer may transmit the modified authorization request message and the portion of the data to an authorization computer, which may authorize or deny the transaction by generating an authorization response message.
[0006] One embodiment of the present disclosure relates to a computer-implemented method performed by a processing computer, the method comprising: receiving an authorization request message and a session identifier for a transaction from a transmitting computer or a resource provider computer, wherein the session identifier is generated by the resource provider computer and is associated with data of one or more interactions conducted by a user associated with the transaction stored in a supplemental database; obtaining, by the processing computer, a portion of pre-analyzed data about the user and the one or more interactions from the supplemental database based at least in part on the session identifier; performing, by the processing computer, a risk analysis on the transaction using the portion of the pre-analyzed data to generate a value, wherein the value represents the likelihood that the transaction is fraudulent; modifying, by the processing computer, the authorization request message to include the portion of the pre-analyzed data and the value; transmitting, by the processing computer, the modified authorization request message to an authorization computer, and transmitting an authorization response message from the authorization computer to the transmitting computer, wherein the authorization computer generates the authorization response message based on the modified authorization request message, the authorization response message approving or denying the transaction.
[0007] In some embodiments, the computer-implemented method may further include transmitting the portion of the pre-analysis data and the value to a transmitting computer. In an embodiment, the portion of the pre-analysis data is selected from a supplemental database based at least in part on a preference specified by the authorization computer. In an embodiment, modifying the authorization request message to include the portion of the pre-analysis data and the value comprises modifying a data field in the authorization request message. In an embodiment, the computer-implemented method may further include updating the supplemental database with the user's updated interactions by utilizing an application programming interface (API) call made by a resource provider to the supplemental database. In an embodiment, the session identifier may include at least a key or a unique user identifier. In an embodiment, generating the authorization response message by the authorization computer comprises the authorization computer not performing transaction analysis based at least in part on the modified authorization request message.
[0008] Another embodiment of the present disclosure relates to a server comprising a processor and a computer-readable medium coupled to the processor, the computer-readable medium comprising code executable by the processor to implement a method comprising: receiving an authorization request message and a session identifier for a transaction from a transmitting computer or a resource provider computer, wherein the session identifier is generated by an authentication requester and is associated with data of one or more interactions conducted by a user associated with the transaction stored in a database; obtaining a portion of pre-analyzed data about the user and the one or more interactions from the database based at least in part on the session identifier; performing a risk analysis on the transaction using the portion of the pre-analyzed data to generate a value, wherein the value represents a likelihood that the transaction is fraudulent; modifying the authorization request message to include the portion of the pre-analyzed data and the value; and transmitting the modified authorization request message to an authorization computer.
[0009] In some embodiments, the method implemented by the server further comprises transmitting an authorization response message from the authorization computer to the transmission computer, wherein the authorization computer generates the authorization response message based on the modified authorization request message, the authorization response message approving or denying the transaction. In some embodiments, the pre-analysis data is analyzed using one or more authentication risk models associated with a plurality of authentication requesters. In an embodiment, the pre-analysis data comprises one or more of a device identifier, transaction detail information, personal information of a user, Internet Protocol (IP) address information, website business, or website interaction information associated with the transaction. In an embodiment, modifying the authorization request message comprises setting one or more flags associated with the authorization request message for the transaction. In an embodiment, the method implemented by the server further comprises transmitting the portion and the value of the pre-analysis data to the transmission computer. In an embodiment, the portion of the pre-analysis data is selected from a supplemental database based at least in part on a priority specified by the authorization computer.
[0010] Another embodiment of the present disclosure relates to an authorization computer comprising a processor and a computer-readable medium coupled to the processor, the computer-readable medium comprising code executable by the processor to implement a method comprising: receiving, by the processor computer, an authorization request message and a session identifier for a transaction from a transmission computer or a resource provider computer, the session identifier being generated by an authentication requester and associated with data of one or more interactions performed by a user associated with the transaction stored in a database; obtaining, by the processor computer, a portion of pre-analyzed data about the user and the one or more interactions from the database based at least in part on the session identifier; performing, by the processor computer, a risk analysis on the transaction using the portion of the pre-analyzed data to generate a value representing the likelihood that the transaction is a fraudulent transaction; modifying, by the processor computer, the authorization request message to include the portion of the pre-analyzed data and the value; and transmitting, by the processor computer, the modified authorization request message to the authorization computer. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] Figure 1 Describes several components that may be involved in a system for implementing at least some embodiments of the present disclosure;
[0012] Figure 2 Describes several components that may be involved in a system for implementing at least some embodiments of the present disclosure;
[0013] Figure 3 Describes an example system architecture that may be implemented to provide a modified authorization request feature according to embodiments of the present disclosure;
[0014] Figure 4 a flowchart depicting a process for implementing a modified authorization request feature according to at least some embodiments; and
[0015] Figure 5 A flow diagram depicts a process for implementing a modified authorization request feature in accordance with at least some embodiments. DETAILED DESCRIPTION
[0016] Before discussing the embodiments of the present invention, some terms may be described in further detail.
[0017] A "server computer" may include a powerful computer or computer cluster. For example, a server computer may be a mainframe, a cluster of minicomputers, or a group of servers operating as a unit. In one example, a server computer may be a database server coupled to a network server. A server computer may include one or more computing devices and may use any of a variety of computing structures, arrangements, and compilations to service requests from one or more client computers.
[0018] "Memory" may be any suitable device or devices that can store electronic data. Suitable memory may include non-transitory computer-readable media that stores instructions executable by a processor to implement the desired method. Examples of memory may include one or more memory chips, disk drives, etc. Such memory may operate using any suitable electrical, optical, and / or magnetic operating modes.
[0019] "Processor" may refer to any suitable data computing device or devices. A processor may include one or more microprocessors that work together to perform the desired functions. A processor may include a CPU that includes at least one high-speed data processor sufficient to execute program components for executing user and / or system generated requests. The CPU may be a microprocessor such as AMD's Athlon, Duron, and / or Opteron; IBM and / or Motorola's PowerPC; IBM and Sony's Cell processor; Intel's Celeron, Itanium, Pentium, Xeon, and / or XScale; and / or similar processors.
[0020] A "resource" generally refers to any asset that can be used or consumed. For example, a resource can be a computer resource (such as stored data or a networked computer account), a physical resource (such as a tangible object or physical location), or other electronic resources or communications between computers (such as a communication signal corresponding to an account used to perform a transaction). Some non-limiting examples of resources may include goods or services, physical buildings, computer accounts or files, or payment accounts. In some embodiments, a resource may refer to a financial product, such as a loan or line of credit.
[0021] A "resource provider" may be an entity that can provide resources such as goods, services, information, and / or access. Examples of resource providers include merchants, access devices, secure data access points, etc. A "merchant" may generally be an entity that participates in a transaction and can sell goods or services or provide access to goods or services.
[0022] An "acquirer" may be an entity that owns something. An acquirer may be a business entity (e.g., a commercial bank) that has a business relationship with a particular resource provider, merchant, or other entity. An acquirer may operate an acquirer computer, which may be referred to as a "transmitting computer."
[0023] A "remote server computer" may include a computer that is remotely located relative to a client computer. In some embodiments, the remote server computer may be part of a payment processing network. The remote server computer may include data processing subsystems, networks, and operations to support and deliver authorization services, exception file services, and clearing and settlement services. Exemplary payment processing networks may include VisaNet TM For example, VisaNet TM Payment processing networks such as VisaNet can process credit card transactions, debit card transactions and other types of commercial transactions. TM Specifically, it includes the VIP system (Visa Integrated Payment System) that processes authorization requests, and the Base II system that performs clearing and settlement services. The payment processing network can use any suitable wired or wireless network, including the Internet.
[0024] An "authorizing entity" is an entity that can authorize or approve an interaction. An authorizing entity may generally refer to a business entity (e.g., a bank) that maintains a user's account and is able to authorize interactions, such as the purchase of goods or services from a merchant. An authorizing entity may operate an "authorizing computer." Examples of authorizing entities may be issuers, government agencies, document repositories, access administrators, and the like. An "issuer" may generally refer to a business entity (e.g., a bank) that maintains a user account associated with a client device, such as an account registered in a mobile application installed on the client device. The authorizing entity may also send account parameters associated with the account to the client device. The authorizing entity may be associated with a host system that performs some or all of the functions of the issuer on behalf of the authorizing entity.
[0025] An "authorization request message" may be an electronic message requesting authorization for an interaction. In some embodiments, the authorization request message may be sent to an authorization computer and / or the issuer of a payment card to request authorization for the transaction. According to some embodiments, the authorization request message may comply with ISO 8583, a standard for systems for exchanging electronic transaction information associated with payments made by a user using a payment device or payment account. The authorization request message may include an issuer account identifier that may be associated with the payment device or payment account. The authorization request message may also include additional data elements corresponding to "identification information" or "user information," including, by way of example only: a service code, a CVV (card verification value), a dCVV (dynamic card verification value), a PAN (primary account number or "account number"), an access token, a user identifier (e.g., a username), an expiration date, etc. The authorization request message may also include "transaction information," such as any information associated with the current transaction, such as the transaction amount, merchant identifier, merchant location, acquirer bank identification number (BIN), card acceptor ID, information identifying the item being purchased, etc., as well as any other information that may be used to identify and / or determine whether to authorize the transaction.
[0026] An "authorization response message" can be a message in response to an authorization request. In some cases, the authorization response message can be an electronic message generated by the issuing financial institution or an authorization computer in response to the authorization request message. The authorization response message can include, for example, one or more of the following status indicators: approved - the transaction was approved; rejected - the transaction was not approved; or call center - more information is pending and the merchant must call a toll-free authorization number. The authorization response message can also include an authorization code, which can be a code returned by the credit card issuing bank to the merchant's access device (e.g., a POS device) in response to the authorization request message in an electronic message (directly or through a transaction processing computer), indicating approval of the transaction. The code can serve as proof of authorization.
[0027] A "supplemental database" may be a database that stores supplemental information. In some embodiments, the supplemental database may be a database that the processor computer accesses in response to receiving an authorization request message and a session identifier. In some cases, if the session identifier is not associated with the authorization request message or is not provided in conjunction with the authorization request message, the processor computer may not access the supplemental database to obtain data for analyzing the authorization request message. In embodiments, the supplemental database may store a number of data points, metrics, or attributes for use in authentication analysis performed by a dynamic network analysis system or for modifying the authorization request message, as described herein. The supplemental database may store transaction information, device information, Internet Protocol (IP) information of devices associated with transactions (device data), personal information of users associated with transactions (consumer data), interaction data or interactions, website business or website interaction information, such as membership in a particular program provided by a resource provider. In embodiments, the supplemental database may store information identifying specific analysis models, data, and, if any, which party performed the external risk analysis during the authentication process.
[0028] The term "data analyzer module" may include a software component that analyzes data. In some embodiments, the data analyzer module may include a software component for a risk assessment system within a dynamic network analysis system. In embodiments, the data analyzer module electronically receives a data message (authentication request) from a data requester and attempts to answer queries contained in the data message. In embodiments, the data analyzer module and / or the dynamic network analysis system is configured to generate risk assessments regarding interactions and transactions by evaluating past transaction data and past user interaction data. To answer queries contained in the data message, the data analyzer module may access a risk analysis algorithm or a dynamic risk table, as well as query one or more of a plurality of external data sources.
[0029] The term "data message" may include a message including data. In some embodiments, a data message may include a message sent as part of a process for determining the risk of an interaction with a resource provider. In some embodiments, a data message may include device data, consumer data, interaction data, and transaction data as part of a query sent from a data requester to a dynamic network analysis system. In some embodiments, a data message may also be an authentication message or an authentication request message.
[0030] The term "external data source" may include an external source that may provide data. In embodiments, an external data source may be physically external to the system (e.g., in a separate physical location or on a separate computer), or may be located at a different location within a physical memory component within the system. In embodiments, an external data source may refer to a source within the system that requires additional authentication procedures or credentials to access. An external data source may be a source outside the system firewall or located outside the network of a company, system, or entity. In embodiments, an external data source may include a third-party vendor that collects, analyzes, and provides risk assessment data.
[0031] The term "device data" may include data related to a device. In some embodiments, device data may include data that can be used to perform a risk assessment. Device data may refer to data about a portable computing device, such as a computer or mobile phone. Examples of device data may include a unique identifier for the computer or mobile phone, an Internet Protocol (IP) address, SIM card data, and device make and model data. Device data may also include the device's MSISDN, or Mobile Subscriber Integrated Services Digital Network Number, which is a number that uniquely identifies a subscription in a mobile network.
[0032] The term "consumer data" or "user data" may include data related to a user. In some embodiments, consumer data or user data may include data that can be used to conduct a risk assessment. Consumer data may include name, mailing address, shipping address, phone number, payment account number, date of birth, marital status, income, social security number, demographic data, etc. In some embodiments, consumer data may also include consumer preferences, notification methods, and previous transaction history. In some embodiments, consumer data may be stored in supplemental databases and used as part of risk analysis.
[0033] The term "interaction" may include actions performed by a user or consumer. In an embodiment, a user or consumer interacts with a resource provider, such as a merchant website. Typical interactions with a merchant system may include, but are not limited to, connecting to a merchant website, presenting authentication data to log into an account on the merchant website, modifying account settings on the merchant website, requesting authentication data, viewing products on the merchant website, and conducting financial transactions. Interactions are typically performed using a computing device capable of connecting to a resource provider (e.g., a desktop computer, laptop computer, tablet computer, mobile phone with Internet capabilities, etc.).
[0034] The term "interaction data" may refer to data that can be used to conduct a risk assessment. Interaction data may include data based on the types of interactions performed by a user. Interaction data may also include the length of the interaction, the time of the interaction data, and the like. Interaction data may be used as part of a risk assessment because different interactions may have different risk levels associated with them. For example, the risk of a user connecting to a merchant website may be considered to involve a lower risk interaction than a user attempting to complete a financial transaction. In embodiments, interaction data may be used to establish an initial risk assessment before a dynamic network analysis system retrieves and analyzes the stored and retrieved data. In embodiments, the interaction data may be stored in a supplemental database. The stored interaction data may be used as part of a risk analysis to determine a history of past interactions associated with a user or device.
[0035] The term "transaction data" may include data associated with a transaction. In some embodiments, transaction data may include data that can be used to conduct a risk assessment. Transaction data may include data related to a particular transaction, including the items purchased, item price, total cost, shipping address, payment method, authentication data, merchant data, and the like. In some embodiments, transaction data may be generated only when a user or consumer attempts to submit a transaction for processing. In some embodiments, transaction data may be generated by a resource provider based on items added to a user's shopping cart and provided to a risk analysis system. In some embodiments, transaction data may be stored in a supplemental database and used as part of a risk analysis to determine past transaction history associated with a user or device.
[0036] The term "interaction history" may refer to a history of previous interactions (one or more interactions). In some embodiments, previous interactions performed by a user are stored in a supplemental database and accessed by the dynamic network analysis system and the processor computer. The interaction history of a particular user or consumer may be used as part of a risk analysis of a current interaction for that particular user or consumer. In an embodiment, the interaction history of similar consumers may be used as part of a risk analysis of a current interaction. For example, a user may have previously logged into a merchant's website to modify the shipping address associated with a particular user account. Since it is considered a single interaction between the user and the resource provider system, the modification of the shipping address may have a low risk level associated with it. However, by retrieving and analyzing the user's interaction history, changing the shipping address in a first interaction and then purchasing an expensive item in a second interaction at a later time may indicate the presence of fraudulent activity and / or may increase the risk level associated with the interaction.
[0037] The term "consumer" may refer to an individual or entity. A consumer may be associated with a financial account and a user account with a resource provider. The consumer's financial account may be used to conduct financial transactions with the resource provider. In some embodiments, the consumer conducts non-transaction-related interactions with the resource provider. A consumer may be an individual who attempts to commit fraud by using fraudulent or stolen authentication data to interact with the resource provider. The term "user" may be used interchangeably with the term "consumer."
[0038] The term "session identifier" may include an identifier associated with an interaction session. In some embodiments, a session identifier may include a unique identifier for one or more interactions of a user with an authentication entity and / or a resource provider. In embodiments, a session identifier may be associated with a set of data or attributes, such as interactions, transaction data, consumer data, and stored with such data in a supplemental database. In embodiments, a session identifier may include a unique key or a unique user identifier (UUID). In embodiments, the session identifier may be transmitted by the authentication system to the resource provider and / or the transmitting computer prior to the generation of an authorization request message for the transaction. In some embodiments, the resource provider and / or the transmitting computer generates the session identifier in response to an interaction with the dynamic network analysis system.
[0039] "Authentication" or "authenticating" can be the process of proving or verifying certain information and / or the identity of the source of the information. For example, a user may provide authentication data that is unique to the user or known only to the user to prove the user's identity. Examples of different types of authentication data may include biometrics (e.g., fingerprints, palm prints, facial recognition, iris and / or retinal recognition, voice recognition, gait, or other human characteristics), passwords, PINs, answers to security questions, cryptographic responses to challenges, human and / or device signatures, etc.
[0040] An "access control server" may include a server computer that provides authentication services to authenticate users conducting online transactions. The access control server may perform requested authentication services for an issuer or other entity and provide a digitally signed response to the entity requesting authentication. An access control server may be shared or used by multiple entities. An entity may also have multiple access control servers, each associated with a different subset of users. In some embodiments, the access control server is operated by the issuer.
[0041] A "directory server" may include a server computer that can be used to post messages in the transaction system. In some embodiments, messages posted by the directory server may contain registration and authentication information between the merchant plug-in (MPI) and the issuer access control server. The directory server may also determine whether an account can utilize authentication services. In some embodiments, the directory server may be operated by a transaction service provider. According to various embodiments, the directory server may also be capable of tokenizing account data or detokenizing tokens.
[0042] Embodiments of the present invention provide methods and systems for enhancing conventional authorization processes on behalf of resource providers and / or transmission computers via a processor computer and an authorization computer in an authorization message request and response system. Embodiments of the present invention enable the processor computer to enhance and provide more reliable and up-to-date authorization analysis features for transactions associated with resource providers or transmission computers. According to at least one embodiment, a session identifier may be generated during an authentication risk analysis program performed by a dynamic network analysis system. The session identifier is associated with a set of data or attributes, such as a user's interactions with a resource provider. Data used to perform the authentication risk analysis program and the session identifier associated with the data and the results of the risk analysis program may be stored in a supplemental database. Subsequently, a resource provider associated with the authentication risk analysis program or a transmission computer associated with the authentication risk analysis program may generate an authorization request message for a user transaction, including the session identifier. The processor computer may receive the authorization request message and, based on the received session identifier, obtain the data or a portion thereof from a supplemental database associated with the user. The processor computer may perform enhanced authorization process analysis and / or modify the authorization request message to include the session identifier and the data from the supplemental database. The modified authorization request message can be transmitted to an authorization computer for enhanced analysis using the transaction information included in the authorization request message and additional data obtained from the supplemental database. The authorization computer can use the data from the supplemental database and one or more authorization models to determine whether to approve or deny the transaction.
[0043] Embodiments of the present invention offer advantages over conventional authorization processing techniques. For example, previous authorization processes may have required multiple data requests to one or more parties to obtain the appropriate amount and type of data to perform the enhanced authorization process. This conventional message request and response structure can add several seconds to each transaction request, even without considering that certain sources may be unavailable to provide the data. When processing thousands of transactions per minute, each additional second delays the authorization process, thereby degrading the user experience. In the present disclosure, additional improvements can be achieved by using a session identifier and authorization computer-specified preferences to request only a portion of the user's associated data from a supplemental database. For example, instead of providing a large amount of data that may be largely useless to certain authorized entities, each authorized entity in a transaction can specify which portion of data is most applicable and request it from the supplemental database via the processor computer. Similarly, time savings can be achieved because the authorization computer can more efficiently authorize or deny transactions using a smaller subset of data than all available data stored in the supplemental database, based on its own preferences. For example, before a transaction is completed, an authorized entity can rely heavily on the authentication score generated for the user by the authentication system to authorize the transaction, thereby relying on fewer attributes or data to complete the transaction authorization process. Other authorization entities may implement their own authorization techniques, including using authorization models, and discover that certain subsets of data associated with a user are more necessary than other subsets of data to authorize or deny a transaction.
[0044] Figure 1 Describes several components that may be involved in a system for implementing at least some embodiments of the present disclosure; Figure 1In the example embodiment, one or more authentication systems, such as authentication system A 100 and authentication system B 102, may provide authentication requests for one or more users participating in transactions or interacting with the authentication system and / or resource providers (e.g., resource provider websites). For example, authentication system A 100 may be configured to receive and process multiple authentication requests on behalf of a resource provider participating in an interaction or transaction with a user or consumer (not shown). According to at least one embodiment, the authentication systems (100 and 102) may request to interact or otherwise communicate with the dynamic network analysis system 106 to request or generate a session identifier associated with data (e.g., transaction information, personal information, device information) used by the authentication systems 100 and 102 in generating risk analysis values or scores. The dynamic network analysis system 106 may be configured to associate the session identifier with the received data and the calculated score and store the session identifier, the received data, and the calculated score (which may be collectively referred to as pre-analysis data) in a supplemental database 108. In an embodiment, authentication systems 100 and 102 may generate session identifiers by utilizing a specific application programming interface (API) when requesting risk analysis to be performed by dynamic network analysis system 106 or providing data and risk analysis results to dynamic network analysis system 106 .
[0045] Figure 1 An external data source 104 is included, which performs a risk analysis process or operation and provides a calculated risk analysis score or value to a dynamic network analysis system 106. In embodiments, the external data source 104 transmits any data utilized in the risk analysis, such as transaction information, personal information, device information, the calculated risk analysis score or value, and a generated session identifier associated with the data and score, to the dynamic network analysis system 106. The dynamic network analysis system 106 is configured to store data received from authentication system A 100, authentication system B 102, and the external data source 104 in a supplemental database 108 and associate any generated session identifiers with the appropriate data set and risk analysis score. In embodiments, the generated session identifiers are unique per transaction, per user device, or per user. According to at least one embodiment, a user or user device may be associated with one or more unique session identifiers, wherein a first unique session identifier is generated for a transaction or interaction between the user and a resource provider or another entity, and a second unique session identifier is used to aggregate all session identifiers for the user or user device for overall data analysis.
[0046] Figure 1Transmission computer 110 is depicted, which may receive and / or generate authorization requests for transactions processed by an associated resource provider (not shown). Transmission computer 110 may communicate with one or more other components described herein for implementing the enhanced authorization feature, including processor computer 112 and authorization computer 114. In an embodiment, transmission computer 110 may provide an authorization request message and a received or obtained session identifier to processor computer 112. Processor computer 112 may be configured to identify the inclusion of the session identifier and request or obtain a portion of data associated with the session identifier from supplemental database 108. According to at least one embodiment, processor computer 112 may transmit the portion of data retrieved using the session identifier from transmission computer 110 to analysis engine 116 for authorization risk analysis. Analysis engine 116 may be configured to generate a value corresponding to a likelihood that a current transaction is fraudulent using the received data, including the current transaction data from transmission computer 110 in the authorization request message. For example, analysis engine 116 may utilize one or more authorization risk analysis models to identify whether the current transaction is fraudulent and generate a value representing the likelihood that the current transaction is fraudulent.
[0047] The processor computer 112 may be configured to transmit the value generated by the analysis engine 116 and the data retrieved from the supplemental database 108 to the authorization computer 114. In embodiments, the data retrieved from the supplemental database 108 may include the results of the authentication risk analysis performed by the dynamic network analysis system 106 and associated with the session identifier. According to at least one embodiment, the authorization computer 114 may use the data retrieved from the supplemental database 108 and the generated value to determine whether to authorize or deny a transaction. According to at least one embodiment, the authorization computer 114 may receive the data retrieved from the supplemental database 108 using the session identifier to determine whether to authorize or deny a transaction without further analysis or value generation by the analysis engine 116. It should be understood that for simplicity of illustration, Figure 1 However, some embodiments may include more than one of each component, and some embodiments may include fewer or more than one of each component. Figure 1 Components specifically shown in FIG.
[0048] For illustrative purposes, Figure 1 Also includes Figure 1 One or more operations performed by the components of the system, said operations being included in the enhanced authorization features described herein. Figure 1In operations 1a, 1b, and 1c, authentication system A 100, authentication system B 102, and external data source 104 may generate and transmit to dynamic network analysis system 106 session identifiers and data for one or more transactions or interactions between a user and a resource provider or other entity. For example, authentication system A 100 may be requested by a resource provider computer (e.g., a merchant computer) during a transaction to analyze a user's computer system to determine whether the user's computer system may be on a blacklist or otherwise unassociated with a legitimate user. Authentication system B 101 may be requested by a resource provider computer during the same transaction to assess the risk that the current user conducting the transaction is not a legitimate user. This may be accomplished by checking an external data source that may be able to verify that the account being used is legitimate (e.g., by checking it against a blacklist). Additionally, external data source 104 may be requested by a resource provider computer during the same transaction to provide data that may be useful in assessing the likelihood of fraud in the current transaction (e.g., a past fraud score associated with the account being used). In each instance, the resource provider computer or a transmission computer associated with the resource provider computer may provide a session identifier, and each of the authentication system A 100, the authentication system B 102, and the external data source 104 may provide the requested data and the session identifier to the dynamic network analysis system 106. In some embodiments, the external data source 104 may provide the generated authentication risk analysis score and the session identifier to the dynamic network analysis system 106.
[0049] At operation 2, the dynamic network analysis system 106 may invoke one or more authentication models to generate an authentication risk value on behalf of the authentication systems 100 and 102. In an embodiment, the dynamic network analysis system 106 may use data received from the authentication systems 100 and 102 and data received from the external data source 104 (e.g., personal information, transaction information, device information, etc.) to invoke the authentication models and generate the authentication risk value.
[0050] exist Figure 1 At operation 3 of the present invention, the dynamic network analysis system 106 may store the authentication risk value, the data used to generate the authentication risk value, and the session identifier associated with the authentication risk value and the data in the supplemental database 108. In an embodiment, the transmission computer 110 may obtain the session identifier involved in the authentication described above with reference to operations 1a, 1b, or 1c, 2, and 3 from the resource provider.
[0051] exist Figure 1 In operation 4, the transmission computer 110 may generate and transmit an authorization request message and the received or obtained session identifier to the processor computer 112. In an embodiment, the authorization request message may be generated by a resource provider associated with a user conducting a transaction or requesting access to a location or data.
[0052] According to at least one embodiment, at operation 5, the processor computer 112 may retrieve all or a portion of the data associated with the received session identifier from the supplemental database 108. In an embodiment, the authorization entity (authorization computer 114) may specify one or more preferences regarding which and how much data associated with an interaction or transaction conducted by a user is appropriate for determining whether to authorize or deny a transaction. The processor computer 112 may identify which policies or preferences apply to which authorization computer 114 and select or request a portion of the data associated with the session identifier stored in the supplemental database 108.
[0053] exist Figure 1 In operation 6, processor computer 112 transmits the portion of data stored in supplemental database 108 based on the session identifier and information from the current transaction (e.g., the data included in the authorization request message from transmission computer 110 at operation 4) to analysis engine 116. According to at least one embodiment, analysis engine 116 is configured to generate a value representing the likelihood of a fraudulent transaction using the data from supplemental database 108 and the information included in the authorization request message for the authorization request message. In an embodiment, analysis engine 116 may be configured to generate the value using one or more authorization risk models.
[0054] At operation 7, the processor computer 112 may modify the authorization request message to include the data retrieved from the supplemental database 108 and the values generated by the analysis engine 116, and transmit the modified authorization request message to the authorization computer 114. The authorization request message may be modified by setting values representing the type of data retrieved and the values generated by the analysis engine 116. In some embodiments, a flag or indicia may be set or associated with the authorization request message that indicates the retrieval of data from the supplemental database 108 and the analysis performed by the analysis engine 116.
[0055] At operation 8, authorization computer 114 uses the modified authorization request to authorize or deny the transaction associated with the authorization request. At operation 8, authorization computer 114 generates an authorization response message indicating approval or denial of the transaction and transmits the authorization response message to processor computer 112. In an embodiment, at operation 9, processor computer 112 transmits the authorization response message to transfer computer 110 along with data retrieved from supplemental database 108 using the session identifier. According to at least one embodiment, processor computer 112 may transmit the data used to authorize or deny the transaction (data from supplemental database 108) to a resource provider computer (e.g., via transfer computer 110) for further analysis or reporting by the resource provider computer.
[0056] At the end of the day, or at any other suitable time period, a clearing and settlement process may occur between the processor computer 112 , the authorization computer 114 , and the transmission computer 110 .
[0057] Figure 2 Depicts several components that may be involved in a system for implementing at least some embodiments of the present disclosure. Figure 2 It includes a resource provider authentication service 200, a directory server (DS) 202, an access control server (ACS) 204, a dynamic network analysis system 106, a supplementary database 108, a transmission computer 110, a processor computer 112, an authorization computer 114 and an analysis engine 116. It should be understood that for the sake of simplicity of explanation, Figure 1 However, some embodiments may include more than one of each component, and some embodiments may include fewer or more than one of each component. Figure 1 Components specifically shown in FIG. Figure 2 The components of show an embodiment including one or more different entities for authenticating a user's interaction with a resource provider and populating the supplemental database 108 with data about the interaction and a score or value representing an authentication risk analysis performed by the dynamic network analysis system 106 and / or the ACS 204 and associated with a session identifier.
[0058] exist Figure 2 At operation 1a, the resource provider authentication service 200 may generate and transmit an authentication request message (e.g., a request sent to a DS) associated with a transaction to the directory server 202. The transaction may be conducted between a user and a resource provider computer (not shown). The authentication request message at 1a may include user information (personal information), device data, transaction information, IP address information, etc. associated with the transaction. For example, a user may attempt to authenticate themselves to gain access to a restricted area or restricted data.
[0059] exist Figure 2 At operation 1b, the resource provider authentication service 200 may transmit the data included in the authentication request message to the dynamic network analysis system 106. The resource provider authentication service 200 may generate a session ID by communicating with the dynamic network analysis system 106, and the session ID may be used to associate the data or payload included in the authentication request message. At operation 1c, the directory server 202 may transmit the authentication request message (the request sent to the ACS) to the access control server 204.
[0060] In an embodiment, ACS 204 may be configured to utilize data included in the authentication request message to authenticate a user attempting to conduct a transaction, access data, or perform some other interaction.
[0061] exist Figure 2 At operation 2, directory server 202 receives and transmits the result of the authentication request message (authentication response message) to dynamic network analysis system 106 and, optionally, resource provider authentication service 200. Dynamic network analysis system 106 may be configured to store the result of the authentication analysis performed by ACS 204 using the session identifier of the data included in the authentication request message.
[0062] According to at least one embodiment, at operation 3, the dynamic network analysis system 106 may be configured to generate an authentication risk analysis score or value using the data associated with the authentication request message and the results or other analysis performed by the ACS 204. In an embodiment, the dynamic network analysis system 106 associates the authentication risk analysis score with the data for the transaction or authentication request message using a session identifier.
[0063] The dynamic network analysis system 106 is configured to transmit and store the data included in the authentication request message, the analysis performed by the ACS 204, and the authentication risk analysis score in the supplemental database 108 at operation 4, and associate the aforementioned attributes or metrics with the session identifier for later retrieval by the processor computer 112 when processing the authorization request message.
[0064] According to at least one embodiment, the dynamic network analysis system 106 may be configured to not store the data included in the authentication request message in the supplemental database 108 in response to the ACS not authenticating the authentication request message at operation 5. At operation 6, the dynamic network analysis system 106 may store the data and the authentication risk analysis score in the supplemental database 108, along with an indicator indicating that the ACS 204 has indeed authenticated the transaction. In embodiments, different indicators or flags may be associated with the data and session identifier stored in the supplemental database 108 to determine whether the data should be transmitted to the processor computer 112 for processing certain types of authorization request messages. For example, a policy or preference from the authorization computer 114 may dictate that data should be retrieved from the supplemental database 108 by the processor computer 112 only for transactions in which the ACS 204 has authenticated the transaction. Another authorization computer 114 may dictate that data should be retrieved from the supplemental database 108 by the processor computer 112 only for transactions in which the PAN and CAVV were provided in the authentication request message from the resource provider authentication service 200.
[0065] In operation 7, the transport computer 110 may generate and transmit an authorization request message and the received or obtained session identifier to the processor computer 112. In embodiments, the transport computer 110 may receive or request the session identifier from the resource provider authentication service 200 or the dynamic network analysis system 106. In embodiments, the authorization request message may be generated by a resource provider associated with a user conducting a transaction or requesting access to a location or data. For example, the resource provider may be associated with a user making an authentication request via the resource provider authentication service 200. In some embodiments, the resource provider and the transport computer 110 communicate with the resource provider authentication service 200 and request the authentication request as part of the transaction process.
[0066] According to at least one embodiment, at operations 8a and 8b, the processor computer 112 may retrieve all or a portion of the data associated with the received session identifier from the supplemental database 108. As described herein, the processor computer 112 may implement or utilize various rules or policies to determine whether and what portion of the data to retrieve from the supplemental database 108. For example, the processor computer 112 may retrieve data from the supplemental database 108 if the session identifier is included in the authorization request message, or may request data from the supplemental database 108 only if the CAVV is included in the authorization request message.
[0067] In an embodiment, the authorization entity (authorization computer 114) may specify one or more preferences regarding which and how much data associated with an interaction or transaction conducted by a user is appropriate for determining whether to authorize or deny a transaction. The processor computer 112 may identify which policies or preferences apply to which authorization computer 114 and select or request a portion of the data associated with the session identifier stored in the supplemental database 108.
[0068] At operation 9, processor computer 112 transmits the portion of data stored in supplemental database 108 based on the session identifier and information from the current transaction (e.g., the data included in the authorization request message from transmission computer 110 at operation 7) to analysis engine 116. According to at least one embodiment, analysis engine 116 is configured to generate a value representing the likelihood of a fraudulent transaction using the data from supplemental database 108 and the information included in the authorization request message for the authorization request message. In embodiments, analysis engine 116 may be configured to generate the value using one or more authorization risk models.
[0069] At operation 10, the processor computer 112 may modify the authorization request message to include the data retrieved from the supplemental database 108 and the values generated by the analysis engine 116, and transmit the modified authorization request message to the authorization computer 114. The authorization request message may be modified by setting values representing the type of data retrieved and the values generated by the analysis engine 116. In some embodiments, a flag or indicia may be set or associated with the authorization request message that indicates the retrieval of data from the supplemental database 108 and the analysis performed by the analysis engine 116.
[0070] At operation 11, the authorization computer 114 uses the modified authorization request to authorize or deny the transaction associated with the authorization request. The authorization computer 114 generates an authorization response message indicating approval or denial of the transaction and transmits the authorization response message to the processor computer 112, which then transmits the authorization response message to the transmission computer 110. Figure 1 According to at least one embodiment, the processor computer 112 may communicate with the analysis engine 116 and / or the supplemental database 108 to store the results of the authorization request message / authorization response message processed by the authorization computer 114.
[0071] At the end of the day, or at any other suitable time period, a clearing and settlement process may occur between the processor computer 112 , the authorization computer 114 , and the transmission computer 110 .
[0072] Figure 3 Depicts an example system architecture that may be implemented to provide a modified authorization request feature according to embodiments of the present disclosure. In embodiments, a processor computer 300 may communicate with one or more authentication systems 302, dynamic network analysis systems 304, and supplemental databases 306 via a network connection 308. The network connection 308 may include at least one transaction processing network. In some embodiments, the processor computer 300 may be Figure 1 and 2 An example of a processor computer 112 .
[0073] In an embodiment, the processor computer 300 may include at least one memory 310 and one or more processing units (or processors) 312. The processor 312 may be implemented in hardware, computer-executable instructions, firmware, or a combination thereof, as appropriate. The computer-executable instructions of the firmware embodiment of the processor 312 may include computer-executable instructions or machine-executable instructions written in any suitable programming language for performing the various functions described.
[0074] The memory 310 can store program instructions that can be loaded and executed on the processor 312, as well as data generated during the execution of these programs. Depending on the configuration and type of the processor computer 300, the memory 310 can be volatile (e.g., random access memory (RAM)) and / or non-volatile (e.g., read-only memory (ROM), flash memory, etc.). The processor computer 300 may also include additional storage devices 314, such as removable storage devices or non-removable storage devices, including but not limited to magnetic storage devices, optical disks, and / or tape storage devices. The disk drive and its associated computer-readable media can provide non-volatile storage of computer-readable instructions, data structures, program modules, and other data from the processor computer 300. In some embodiments, the memory 310 may include multiple different types of memory, such as static random access memory (SRAM), dynamic random access memory (DRAM), or ROM.
[0075] Turning to more detail regarding memory 310, memory 310 may include an operating system and one or more applications or services for implementing the features disclosed herein, including at least one module for performing transaction authorization using data from supplemental database 306 (authorization module 316), a module for analyzing data from supplemental database 306 and one or more analytical models from analytical model data 320 to generate a value or score representing the likelihood of a fraudulent transaction (analysis engine 318), and a module for modifying an authorization request message to include data retrieved from supplemental database 306 and any values or scores generated by analysis engine 316 (message modification module 322). In embodiments, the scores or values and the models used to generate them may be stored or accessed by analysis engine 318 from analytical model database 320. According to at least one embodiment, preferences, rules, or policies specified by the authorization computer may be stored in an authorization entity preferences database 324 for use by the processor computer in requesting a portion of the data stored in supplemental database 306 to process an authorization request from a transmitting computer (not shown).
[0076] In some embodiments, authorization module 316, analysis engine 318, and message modification module 322, in conjunction with processor 312, may be configured to receive an authorization request message and a session identifier to modify the authorization request message and provide additional data for use by an authorized entity, such as an authorization computer, to authorize or deny a transaction. In some embodiments, processor computer 300 and authorization module 316 may use the received session identifier and one or more rules, preferences, or policies in authorization entity preference database 324 to retrieve a portion of the data stored in supplemental database 306. In some embodiments, processor computer 300 and analysis engine 318 may use one or more risk analysis models stored in analysis model database 320 to generate a value or score indicating the likelihood that a transaction associated with the authorization request message is fraudulent. In some embodiments, message modification module 322 and processor computer 300 may be configured to modify the authorization request message to include the data retrieved from supplemental database 306 and any scores or values generated by analysis engine 318. According to at least one embodiment, the score or value generated by analysis engine 318 may be stored and associated with a user or user device based on the session identifier received along with the authorization request message.
[0077] In an embodiment, for a user interacting or otherwise attempting to conduct a transaction processed by the authentication system 302, a session identifier may be generated for an authentication request message on behalf of a resource provider operating a resource provider computer and / or a transmitting computer. The authentication system 302 may include an authentication application 326 configured to communicate with the dynamic network analysis system 304 via the network 308 to generate a session identifier for the authentication request message. According to at least one embodiment, the dynamic network analysis system 304 may include a data analyzer module 328 configured to generate an authentication risk analysis score, receive an authentication response message from an access control server, authenticate the user associated with the transaction using data included in the authentication request message, and store the data from the authentication request message, the authentication risk analysis score, and the results from the access control server in the supplemental database 306. The authentication risk analysis score, the results from the access control server (if available), and the data included in the authentication request message are associated with a session identifier in the supplemental database 306, which is used by the processor computer 300 to retrieve or obtain a portion of the data stored in the supplemental database 306 for one or more interactions or transactions between the user or user device and the authentication system 302.
[0078] The processor computer 300 may also include a communication interface 330 that enables the processor computer 300 to communicate with a stored database, another computing device or server, one or more remote devices, other application servers, and / or any other suitable electronic device. In some embodiments, the communication interface 330 may enable the processor computer 300 to communicate with other electronic devices on a network (e.g., a private network). The processor computer 300 may also include input / output (I / O) devices and / or ports 332, such as for enabling connections to a keyboard, mouse, pen, voice input device, touch input device, display, speaker, printer, etc. The authentication system 302 may be from Figure 1 and 2 The dynamic network analysis system 304 may be an example of an authentication system A 100, an authentication system B 102, an external data source 104, or a resource provider authentication service 200. Figure 1 and 2 An example of a dynamic network analysis system 106 .
[0079] Figure 4 A flow diagram depicts a process for implementing a modified authorization request feature in accordance with at least some embodiments. Figure 4 Show that it can be Figure 1-3 The processor computer depicted in FIG. 4 performs the process 400 .
[0080] Process 400 may begin at 402 by receiving an authorization request message and a session identifier for a transaction. As described herein, the session identifier may be generated by an authentication request system and / or a dynamic network analysis system on behalf of a resource provider and / or a transmitting computer in response to receiving or processing the authentication request message. Process 400 may include, at 404, obtaining a portion of pre-analysis data about the user of the transaction based on the session identifier. In embodiments, the processor computer may request or otherwise obtain a portion, or all, of the data points or attributes associated with the session identifier and stored in a supplemental database. Process 400 may include, at 406, performing a risk analysis on the transaction using the portion of the pre-analysis data to generate a value. In embodiments, the processor computer may interact or otherwise communicate with an analysis engine to generate a value using the portion of the pre-analysis data associated with the session identifier, the value indicating the likelihood that the transaction associated with the authorization request is fraudulent. An authorizing entity, such as an authorization computer, which may subsequently authorize or deny a transaction, may specify preferences or rules indicating specific data or attributes to be included in the supplemental database and associated with the session identifier used for retrieval and analysis by the processor computer and analysis engine.
[0081] Process 400 may include, at 408, modifying the authorization request message to include the portion of pre-analysis data and the value. In an embodiment, the processor computer may modify or set one or more values included in the authorization request message to indicate the inclusion of certain attributes associated with the session identifier and obtained from the supplemental database and the analysis of the attributes. Process 400 may include, at 410, transmitting the modified authorization request message to the authorization computer. According to at least one embodiment, process 400 may conclude at 412 by transmitting an authorization response message from the authorization computer to the transmitting computer, approving or denying the transaction. In an embodiment, the processing computer may store the result of the authorization request message from the authorization computer (e.g., the authorization response message) in the supplemental database and associate the result with the session identifier.
[0082] Figure 5 A flow diagram depicts a process for implementing a modified authorization request feature in accordance with at least some embodiments. Figure 5 Show that it can be Figure 1-3 The processor computer performs the process 500 depicted in FIG.
[0083] Process 500 may begin at 502 by receiving an authorization request message for a transaction and a session identifier. In embodiments, the authorization request message may be received from a transmission computer or a resource provider computer. Process 500 may include, at 504, obtaining a portion of pre-analysis data about the user of the transaction based on the session identifier. According to at least one embodiment, a number of attributes, metrics, or data may be stored in a supplemental database and associated with the session identifier, corresponding to one or more interactions performed by the user or user device with the resource provider, the transmission computer, and / or the authentication system. Process 500 may include, at 506, performing a risk analysis on the transaction using the portion of the pre-analysis data to generate a value. Process 500 may include, at 508, modifying the authorization request message to include the portion of the pre-analysis data and the value. Process 500 may conclude at 510 by transmitting the modified authorization request message to an authorization computer to approve or deny the transaction associated with the authorization request message. According to at least one embodiment, the authorization computer may not perform analysis and authorization of the transaction, but instead rely on a processor computer and the generated value to determine whether to approve or deny the transaction associated with the authorization request message.
[0084] Any computer system mentioned herein can use any suitable number of subsystems. In some embodiments, the computer system includes a single computer device, wherein the subsystem can be a component of the computer device. In other embodiments, the computer system can include multiple computer devices, each of which is a subsystem with internal components.
[0085] A computer system may include multiple components or subsystems connected together, for example, by external interfaces or by internal interfaces. In some embodiments, the computer systems, subsystems, or devices may communicate over a network. In such cases, one computer may be considered a client and another computer may be considered a server, where each computer may be part of the same computer system. The client and server may each include multiple systems, subsystems, or components.
[0086] It should be understood that any embodiment of the present invention can be implemented in the form of control logic using hardware (e.g., an application specific integrated circuit or a field programmable gate array) and / or using computer software, wherein a general-purpose programmable processor is modular or integrated. As used herein, a processor includes a single-core processor, a multi-core processor on the same integrated chip, or a plurality of processing units on a single circuit board or networked. Based on the present disclosure and the teachings provided herein, those of ordinary skill in the art will know and understand other ways and / or methods of implementing embodiments of the present invention using hardware and combinations of hardware and software.
[0087] Any software component or functionality described in this application can be implemented as software code executed by a processor using any suitable computer language such as Java, C, C++, C#, Objective-C, Swift, or a scripting language such as Perl or Python using, for example, conventional or object-oriented techniques. The software code can be stored as a series of instructions or commands on a computer-readable medium for storage and / or transmission, suitable media including random access memory (RAM), read-only memory (ROM), magnetic media such as a hard drive or floppy disk, or optical media such as a compact disk (CD) or digital versatile disk (DVD), flash memory, etc. The computer-readable medium can be any combination of such storage or transmission devices.
[0088] Such program can also be used to be adapted for encoding and transmitting via the wired, optical and / or wireless network that meets multiple protocols including the Internet.Therefore, the computer-readable medium according to an embodiment of the present invention can be used to create with the data signal of such program encoding.The computer-readable medium encoded with program code can be encapsulated with compatible devices or provided separately with other devices (for example, via the Internet download).Any such computer-readable medium can reside on or in a single computer product (for example, hard disk drive, CD or whole computer system), and can be present on or in the different computer products in a system or network.A computer system may include a monitor, printer or other suitable display for providing any result mentioned herein to the user.
[0089] Any method described herein can be performed completely or in part with a computer system comprising one or more processors that can be configured to perform these steps. Therefore, an embodiment may relate to a computer system that is configured to perform the steps of any method described herein, may have different components that perform corresponding steps or corresponding step groups. Although presented as numbered steps, the steps of the method herein can be performed simultaneously or in different orders. In addition, the part of these steps can be used together with the part of other steps from other methods. Equally, all or part of a step can be optional. In addition, any step of any method can be performed with a module, a circuit or other means for performing these steps.
[0090] Without departing from the spirit and scope of the embodiments of the present invention, the specific details of the specific embodiments can be combined in any suitable manner. However, other embodiments of the present invention may relate to specific embodiments related to each individual aspect, or specific combinations of these individual aspects. The above description of exemplary embodiments of the present invention has been presented for the purpose of illustration and description. It is not intended to be exhaustive or to limit the present invention to the precise form described, and many modifications and variations are possible in light of the teachings above. These embodiments are selected and described in order to best explain the principles of the present invention and their practical application, so that those skilled in the art can best utilize the present invention in various embodiments and make various modifications suitable for the intended specific use.
[0091] Unless expressly indicated to the contrary, the recitation of "a" or "the" is intended to mean "one or more." Unless expressly indicated to the contrary, the use of "or" is intended to mean an inclusive or rather than an exclusive or.
[0092] All patents, patent applications, publications, and descriptions mentioned herein are incorporated by reference in their entirety for all purposes. No admission is made that they are prior art.
Claims
1. A computer-implemented method comprising: receiving, by a processor computer, from a transmitting computer or a resource provider computer, an authorization request message for a transaction and a session identifier generated by the resource provider computer and associated with data in a supplemental database of one or more previous interactions with a user associated with the transaction; obtaining, by the processor computer, a portion of pre-analysis data from the supplemental database based at least in part on the session identifier, the pre-analysis data comprising data regarding the user and the one or more previous interactions, the data pre-analyzed and stored in the supplemental database in association with the session identifier; performing, by the processor computer, a risk analysis on the transaction using the portion of the pre-analyzed data to generate a value representing a likelihood that the transaction is fraudulent; modifying, by the processor computer, the authorization request message to include the portion of the pre-analysis data and the value; transmitting, by the processor computer, a modified authorization request message to an authorization computer; as well as transmitting, by the processor computer, to the transmitting computer, an authorization response message from the authorization computer, the authorization computer generating the authorization response message based on the modified authorization request message, the authorization response message approving or denying the transaction, wherein the portion of the pre-analyzed data includes specific data points designated for retrieval by an authorized computer. 2 . The computer-implemented method of claim 1 , further comprising transmitting, by the processor computer, the portion of pre-analysis data and the value to the resource provider computer. 3 . The computer-implemented method of claim 1 , wherein a session identifier provided in the authorization request message matches a session identifier stored in the supplemental database. 4 . The computer-implemented method of claim 1 , wherein modifying the authorization request message to include the portion of pre-analysis data and the value comprises modifying a data field in the authorization request message. 5 . The computer-implemented method of claim 1 , further comprising updating the supplemental database with the user's updated interactions by utilizing application programming interface (API) calls made by the resource provider to the supplemental database. The computer-implemented method of claim 1 , wherein the session identifier comprises at least a key or a unique user identifier.
7. The computer-implemented method of claim 1, wherein generating, by the authorization computer, the authorization response message comprises the authorization computer not performing analysis of the transaction based at least in part on a modified authorization request message.
8. A server comprising: processor; as well as A computer-readable medium coupled to the processor, the computer-readable medium comprising code executable by the processor to perform a method comprising: receiving, from a transmitting computer or a resource provider computer, an authorization request message for a transaction and a session identifier generated by an authentication requestor and associated with data in a database of one or more previous interactions with a user associated with the transaction; obtaining, from the database, a portion of pre-analysis data based at least in part on the session identifier, the pre-analysis data comprising data regarding the user and the one or more previous interactions, the data pre-analyzed and stored in the database in association with the session identifier; performing a risk analysis on the transaction using the portion of the pre-analyzed data to generate a value representing a likelihood that the transaction is fraudulent; modifying the authorization request message to include the portion of the pre-analysis data and the value; transmitting the modified authorization request message to the authorizing computer; and transmitting to the transmitting computer an authorization response message received from the authorization computer, the authorization computer generating the authorization response message based on the modified authorization request message, the authorization response message approving or denying the transaction, wherein the portion of the pre-analyzed data includes specific data points designated for retrieval by the authorized computer.
9. The server of claim 8, wherein the pre-analysis data is analyzed using one or more authentication risk models associated with a plurality of authentication requesters.
10. The server of claim 8, wherein the pre-analysis data comprises one or more of a device identifier associated with the transaction, transaction detail information, personal information of the user, Internet Protocol (IP) address information, website traffic, or website interaction information.
11. The server of claim 8, wherein modifying the authorization request message comprises setting one or more flags associated with the authorization request message for the transaction.
12. The server of claim 8, wherein the method further comprises transmitting the portion of pre-analysis data and the value to the transmitting computer.
13. The server of claim 8, wherein the session identifier provided in the authorization request message matches a session identifier stored in the database.
14. A processor computer comprising: processor; as well as A computer-readable medium coupled to the processor, the computer-readable medium comprising code executable by the processor to perform a method comprising: receiving, from a transmitting computer or a resource provider computer, an authorization request message for a transaction and a session identifier generated by an authentication requestor and associated with data in a database of one or more previous interactions with a user associated with the transaction; obtaining, from the database, a portion of pre-analysis data based at least in part on the session identifier, the pre-analysis data comprising data regarding the user and the one or more previous interactions, the data pre-analyzed and stored in the database in association with the session identifier; performing a risk analysis on the transaction using the portion of the pre-analyzed data to generate a value representing a likelihood that the transaction is fraudulent; modifying the authorization request message to include the portion of the pre-analysis data and the value; transmitting the modified authorization request message to the authorizing computer; and transmitting an authorization response message from the authorization computer to the transmitting computer, the authorization computer generating the authorization response message based on the modified authorization request message, the authorization response message approving or denying the transaction, wherein the portion of the pre-analyzed data includes specific data points for retrieval by the authorized computer.
15. The processor computer of claim 14, wherein the method further comprises transmitting the portion of pre-analysis data and the value to a resource provider associated with the transmitting computer.
16. The processor computer of claim 14, wherein the session identifier provided in the authorization request message matches a session identifier stored in the database.
17. The processor computer of claim 14, wherein modifying the authorization request message to include the portion of pre-analysis data and the value comprises modifying a data field in the authorization request message.
18. The processor computer of claim 14, wherein the method further comprises generating, by the authorization computer, the authorization response message by performing additional analysis of the transaction based at least in part on the modified authorization request message.
Citation Information
Patent Citations
Authentication Process Using Search Technology
US20110258118A1
Online payment transaction fraud detection utilizing delivery information
US20170243221A1