Systems, methods, and devices for generating tokenized images

By encoding account tokens in image files to generate tokenized images, the problem of product identification and payment token leakage in retail environments is solved, and a safe and efficient product purchase and payment process is achieved.

CN113168621BActive Publication Date: 2025-08-22VISA INTERNATIONAL SERVICE ASSOCIATION
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN201880099533.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2018-11-16
Publication Date
2025-08-22
Estimated Expiration
2038-11-16

AI Technical Summary

Technical Problem

It is difficult to quickly identify product locations and purchase items in a retail environment, and there is a risk of disclosure of payment tokens, resulting in an increased risk of unauthorized transactions.

Method used

By encoding the account token in the image file, generating a tokenized image, and transmitting it to the transaction processing system using the processor, encoding it with RGB values ​​or encrypted data in the image, a fake token is generated to increase security, and automatically deactivating the payment token when a fake transaction is detected.

Benefits of technology

While seamlessly purchasing goods in a retail environment, it enhances the security and privacy protection of payment tokens, reduces the risk of payment token leakage, and improves the security and privacy of transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113168621B_ABST
    Figure CN113168621B_ABST
Patent Text Reader

Abstract

A system and computer-implemented method for encoding an account token in an image file are provided. The method includes: receiving an identification of at least one image from a user associated with an account identifier; generating at least one token based on the account identifier of the user; encoding the at least one token in the at least one image, thereby producing at least one tokenized image; and transmitting the at least one tokenized image to a transaction processing system, wherein the transaction processing system is configured to conduct a transaction based on the tokenized image.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates generally to image encoding and, in one non-limiting embodiment, to a system, method, and apparatus for generating tokenized images. Background Art

[0002] Consumers may find items inside or outside of a retail environment, such as a store, where they wish to purchase them. It can be difficult to identify the item and the location where it can be purchased simply by looking at it. Consequently, consumers must spend time searching, searching, and researching the item and its availability.

[0003] Furthermore, tokenized payments carry the risk of exposing the payment token. If compromised, thieves could potentially use it to conduct unauthorized transactions. Exposure risk exists every time a payment token is transferred. For example, this can occur when the payment token is attached to a user's phone, when it is transferred to a payment gateway or transaction processing system, or when it is transferred to some other user for authorized use. Summary of the Invention

[0004] In a non-limiting embodiment, a computer-implemented method for encoding an account token in an image file is provided, comprising: receiving an identification of at least one image from a user associated with an account identifier; generating at least one token based on the account identifier of the user using at least one processor; encoding the at least one token in the at least one image using at least one processor, thereby producing at least one tokenized image; and transmitting the at least one tokenized image to a transaction processing system using at least one processor, wherein the transaction processing system is configured to conduct a transaction based on the tokenized image.

[0005] In a non-limiting embodiment, the method further comprises extracting, using at least one processor, the at least one token from the tokenized image; and conducting, using at least one processor, a transaction based on the at least one token. In a non-limiting embodiment, encoding the at least one token comprises encoding the at least one token into RGB values ​​of the at least one image. In a non-limiting embodiment, encoding the at least one token comprises encrypting the at least one token to produce encrypted data; and encoding the encrypted data into the at least one image. In a non-limiting embodiment, the method further comprises generating at least one false token; and encoding the at least one false token into the at least one image. In a non-limiting embodiment, the method further comprises detecting a transaction request using a false token; and automatically deactivating a payment token in response to detecting the transaction request using the false token.

[0006] In a non-limiting embodiment, the method further comprises capturing an image using a camera of the client device; and generating the at least one image based on the image. In a non-limiting embodiment, the at least one image is a screenshot or an image downloaded from a webpage. In a non-limiting embodiment, the at least one image includes embedded merchant data or product data. In a non-limiting embodiment, the method further comprises transmitting, using at least one processor of the first client device, the at least one tokenized image to a second client device including at least one processor, wherein the at least one processor of the second client device transmits the at least one tokenized image to the transaction processing system.

[0007] According to another non-limiting embodiment, a system for encoding an account token in an image file is provided, comprising at least one processor programmed or configured to: receive an identification of at least one image from a user associated with an account identifier; generate at least one token based on the account identifier of the user; embed the at least one token in the at least one image, thereby producing at least one tokenized image; and transmit the at least one tokenized image to a transaction processing system, wherein the transaction processing system is configured to conduct a transaction based on the tokenized image.

[0008] In a non-limiting embodiment, the system further comprises the transaction processing system, wherein the transaction processing system is programmed or configured to: extract the at least one token from the tokenized image; and conduct a transaction based on the at least one token. In a non-limiting embodiment, encoding the at least one token comprises encoding the at least one token into RGB values ​​of the at least one image. In a non-limiting embodiment, the at least one processor embeds the at least one token by: encrypting the at least one token to generate encrypted data; and encoding the encrypted data into the at least one image. In a non-limiting embodiment, the at least one processor is further programmed or configured to generate at least one dummy token and encode the at least one dummy token into the at least one image.

[0009] In a non-limiting embodiment, the at least one processor is further programmed or configured to detect a transaction request using a false token, and in response to detecting the transaction request using the false token, automatically deactivate the payment token. In a non-limiting embodiment, the system further comprises a client device comprising the at least one processor, wherein the at least one processor is further programmed or configured to: capture a photograph using a camera of the client device; and generate the at least one image based on the photograph. In a non-limiting embodiment, the at least one image is a screenshot or an image downloaded from a web page. In a non-limiting embodiment, the at least one image comprises embedded merchant data or product data. In a non-limiting embodiment, the at least one processor is further programmed or configured to transmit the at least one tokenized image to a second client device comprising at least one processor, wherein the at least one processor of the second client device transmits the at least one tokenized image to the transaction processing system.

[0010] According to another non-limiting embodiment, a computer program product for encoding an account token in an image file is provided, comprising at least one non-transitory computer-readable medium, the at least one non-transitory computer-readable medium comprising program instructions that, when executed by at least one processor, cause the at least one processor to: receive an identification of at least one image from a user associated with an account identifier; generate at least one token based on the account identifier of the user; embed the at least one token in the at least one image, thereby producing at least one tokenized image; and transmit the at least one tokenized image to a transaction processing system, wherein the transaction processing system is configured to conduct a transaction based on the tokenized image.

[0011] Other non-limiting embodiments or aspects are set forth in the following numbered clauses:

[0012] Item 1: A computer-implemented method for encoding an account token in an image file, comprising: receiving an identification of at least one image from a user associated with an account identifier; generating, using at least one processor, at least one token based on the account identifier of the user; encoding, using at least one processor, the at least one token in the at least one image, thereby producing at least one tokenized image; and transmitting, using at least one processor, the at least one tokenized image to a transaction processing system, wherein the transaction processing system is configured to conduct a transaction based on the tokenized image.

[0013] Clause 2: The computer-implemented method of clause 1, further comprising: extracting, using at least one processor, the at least one token from the tokenized image; and conducting, using at least one processor, a transaction based on the at least one token.

[0014] Clause 3: The computer-implemented method of clause 1 or 2, wherein encoding the at least one token comprises encoding the at least one token into RGB values ​​of the at least one image.

[0015] Clause 4: The computer-implemented method of any one of clauses 1 to 3, wherein encoding the at least one token comprises: encrypting the at least one token to produce encrypted data; and encoding the encrypted data into the at least one image.

[0016] Clause 5: The computer-implemented method of any one of clauses 1 to 4, further comprising: generating at least one false token; and encoding the at least one false token into the at least one image.

[0017] Clause 6: The computer-implemented method of any one of clauses 1 to 5, further comprising: detecting a transaction request using a false token; and automatically deactivating the at least one token in response to detecting the transaction request using the false token.

[0018] Clause 7: The computer-implemented method of clauses 1 to 6, further comprising: capturing an image using a camera of the client device; and generating the at least one image based on the image.

[0019] Clause 8: The computer-implemented method of any one of clauses 1 to 7, wherein the at least one image is a screenshot or an image downloaded from a web page.

[0020] Clause 9: The computer-implemented method of any of clauses 1 to 8, wherein the at least one image includes embedded merchant data or product data.

[0021] Clause 10: The computer-implemented method of any one of clauses 1 to 9, further comprising transmitting, using at least one processor of a first client device, the at least one tokenized image to a second client device comprising at least one processor, wherein the at least one processor of the second client device transmits the at least one tokenized image to the transaction processing system.

[0022] Clause 11: A system for encoding an account token in an image file, comprising at least one processor programmed or configured to: receive an identification of at least one image from a user associated with an account identifier; generate at least one token based on the account identifier of the user; embed the at least one token in the at least one image, thereby producing at least one tokenized image; and transmit the at least one tokenized image to a transaction processing system, wherein the transaction processing system is configured to conduct a transaction based on the tokenized image.

[0023] Clause 12: The system of clause 11, further comprising the transaction processing system, wherein the transaction processing system is programmed or configured to: extract the at least one token from the tokenized image; and conduct a transaction based on the at least one token.

[0024] Clause 13: The system of clause 11 or 12, wherein encoding the at least one token comprises encoding the at least one token into RGB values ​​of the at least one image.

[0025] Clause 14: The system of any one of clauses 11 to 13, wherein the at least one processor embeds the at least one token by: encrypting the at least one token to produce encrypted data; and encoding the encrypted data into the at least one image.

[0026] Clause 15: The system of any of clauses 11 to 14, wherein the at least one processor is further programmed or configured to: generate at least one false token; and encode the at least one false token into the at least one image.

[0027] Clause 16: The system of any one of clauses 11 to 15, wherein the at least one processor is further programmed or configured to: detect a transaction request using a false token; and automatically deactivate the at least one token in response to detecting the transaction request using the false token.

[0028] Clause 17: The system of any one of clauses 11 to 16, further comprising a client device comprising the at least one processor, wherein the at least one processor is further programmed or configured to: capture a photograph using a camera of the client device; and generate the at least one image based on the photograph.

[0029] Clause 18: The system of any of clauses 11 to 17, wherein the at least one image is a screenshot or an image downloaded from a web page.

[0030] Clause 19: The system of any of clauses 11 to 18, wherein the at least one image includes embedded merchant data or product data.

[0031] Clause 20: A system according to any one of clauses 11 to 19, wherein the at least one processor is further programmed or configured to transmit the at least one tokenized image to a second client device comprising at least one processor, wherein the at least one processor of the second client device transmits the at least one tokenized image to the transaction processing system.

[0032] Clause 21: A computer program product for encoding an account token in an image file, comprising at least one non-transitory computer-readable medium, the at least one non-transitory computer-readable medium including program instructions that, when executed by at least one processor, cause the at least one processor to: receive an identification of at least one image from a user associated with an account identifier; generate at least one token based on the account identifier of the user; embed the at least one token in the at least one image, thereby producing at least one tokenized image; and transmit the at least one tokenized image to a transaction processing system, wherein the transaction processing system is configured to conduct a transaction based on the tokenized image.

[0033] These and other features and characteristics of the present disclosure, as well as the methods of operation and function of the combinations of related structural elements and parts, and the economies of manufacture will become more apparent upon consideration of the following description and the appended claims with reference to the accompanying drawings, all of which form part of this specification, wherein like reference numerals indicate corresponding parts in the various figures. However, it should be expressly understood that the drawings are for illustration and description purposes only and are not intended to define limitations of the present invention. Unless the context clearly dictates otherwise, when used in this specification and claims, the singular forms "a," "an," and "the" include plural referents. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Additional advantages and details are explained in more detail below with reference to exemplary embodiments shown in the schematic drawings, in which:

[0035] Figure 1 is a schematic diagram of a system for generating a tokenized image according to a non-limiting embodiment;

[0036] Figure 2 is a schematic diagram of a client device used in a system for generating a tokenized image according to a non-limiting embodiment;

[0037] Figure 3 is a flow chart of a method for generating a tokenized image according to a non-limiting embodiment; and

[0038] Figure 4 is a flow chart of a method for generating a tokenized image according to a non-limiting embodiment. DETAILED DESCRIPTION

[0039] For purposes of the following description, the terms "end," "upper," "lower," "right," "left," "vertical," "horizontal," "top," "bottom," "lateral," "longitudinal," and their derivatives will be used relative to the orientation of the embodiments in the accompanying drawings. However, it will be understood that the embodiments may employ various alternative variations and step orders, except where expressly specified to the contrary. It will also be understood that the specific devices and processes shown in the accompanying drawings and described in the following specification are merely exemplary embodiments or aspects of the present invention. Accordingly, specific dimensions and other physical characteristics related to the embodiments or aspects disclosed herein should not be considered limiting.

[0040] As used herein, the terms "communication" and "transmission" may refer to the reception, acceptance, transmission, delivery, provision, and / or the like of information (e.g., data, signals, messages, instructions, commands, and / or the like). A unit (e.g., a device, a system, a component of a device or system, a combination thereof, etc.) communicating with another unit means that the unit is capable of receiving information from the other unit and / or transmitting information to the other unit, directly or indirectly. This may refer to a direct or indirect connection (e.g., a direct communication connection, an indirect communication connection, etc.) that is wired and / or wireless in nature. In addition, although the transmitted information may be modified, processed, relayed, and / or routed between the first unit and the second unit, the two units may also communicate with each other. For example, a first unit may communicate with a second unit even if the first unit passively receives information and does not actively transmit the information to the second unit. For another example, a first unit may communicate with a second unit if at least one intermediate unit (e.g., a third unit located between the first unit and the second unit) processes the information received from the first unit and transmits the processed information to the second unit. In some non-limiting embodiments, a message may refer to a network packet (eg, data packet, etc.) that includes data. It will be appreciated that many other arrangements are possible.

[0041] As used herein, the term "transaction service provider" may refer to an entity that receives transaction authorization requests from merchants or other entities and, in some cases, provides payment assurance through an agreement between the transaction service provider and an issuer institution. For example, a transaction service provider may include, for example, , or any other entity that processes transactions. The term "transaction processing system" may refer to one or more computer systems operated by or on behalf of a transaction service provider, such as a transaction processing server executing one or more software applications, a token service executing one or more software applications, etc. A transaction processing server may include one or more processors and, in some non-limiting embodiments, may be operated by or on behalf of a transaction service provider. A token service may include one or more computer systems and / or applications for generating tokens corresponding to user accounts issued by one or more issuing institutions.

[0042] As used herein, the term "issuer institution" may refer to one or more entities, such as a bank, that provide accounts to customers for conducting transactions (e.g., payment transactions), such as initiating credit and / or debit payments. For example, an issuer institution may provide customers with account identifiers, such as a primary account number (PAN), that uniquely identify one or more accounts associated with the customer. The account identifier may be implemented on a portable financial device, such as a physical financial instrument, such as a payment card, and / or may be electronic and used for electronic payments. The term "issuer system" refers to one or more computer systems operated by or on behalf of an issuer institution, such as a server computer that executes one or more software applications. For example, an issuer system may include one or more authorization servers for authorizing transactions.

[0043] As used herein, the term "account identifier" may include one or more PANs, tokens, or other identifiers associated with a customer account. The term "token" may refer to an identifier that is used as a replacement or substitute identifier for an original account identifier such as a PAN. An account identifier may be alphanumeric or any combination of characters and / or symbols. A token may be associated with a PAN or other original account identifier in one or more data structures (e.g., one or more databases, etc.) such that the token can be used to conduct transactions without directly using the original account identifier. In some instances, an original account identifier such as a PAN may be associated with multiple tokens used for different individuals or purposes.

[0044] As used herein, the term "merchant" may refer to a person or entity that provides goods and / or services, or access to goods and / or services, to a customer based on a transaction, such as a payment transaction. The term "merchant" or "merchant system" may also refer to one or more computer systems operated by or on behalf of a merchant, such as a server computer that executes one or more software applications. As used herein, a "point of sale (POS) system" may refer to one or more computers and / or peripheral devices used by a merchant to conduct payment transactions with customers, including one or more card readers, near field communication (NFC) receivers, RFID receivers and / or other contactless transceivers or receivers, contact-based receivers, payment terminals, computers, servers, input devices, and / or other similar devices that can be used to initiate payment transactions.

[0045] As used herein, the term "user device" may refer to one or more electronic devices configured to communicate with one or more networks. As examples, user devices may include desktop computers, cellular phones (e.g., smartphones or standard cellular phones), portable computers (e.g., tablet computers, laptop computers, etc.), wearable devices (e.g., watches, glasses, lenses, clothing, etc.), personal digital assistants (PDAs), POS systems, network-enabled appliances (e.g., televisions, cars, washing machines, thermostats, refrigerators, etc.), and / or other similar devices.

[0046] As used herein, the terms "electronic wallet" and "electronic wallet application" refer to one or more electronic devices and / or software applications configured to initiate and / or conduct payment transactions. For example, an electronic wallet may include a mobile device executing an electronic wallet application, and may further include server-side software and / or databases for maintaining and providing transaction data to the mobile device. An "electronic wallet provider" may include an entity that provides and / or maintains electronic wallets for customers, such as Google Wallet. TM 、Android Apple Samsung And / or other similar electronic payment systems. In some non-limiting examples, the issuing bank may be an electronic wallet provider.

[0047] As used herein, the term "payment gateway" may refer to an entity and / or a payment processing system operated by or on behalf of such an entity (e.g., a merchant service provider, a payment service provider, a payment facilitator, a payment facilitator contracted with an acquirer, a payment aggregator, etc.) that provides payment services (e.g., transaction service provider payment services, payment processing services, etc.) to one or more merchants. The payment services may be associated with the use of a portable financial device managed by a transaction service provider. As used herein, the term "payment gateway system" may refer to one or more computer systems, computer devices, servers, server groups, etc. operated by or on behalf of a payment gateway.

[0048] As used herein, the term "account data" refers to any data about one or more accounts of one or more users. Account data may include, for example, one or more account identifiers, user identifiers, transaction history, balances, credit limits, issuer institution identifiers, etc.

[0049] As used herein, the term "server" may refer to or include one or more processors or computers, storage devices, or similar computer arrangements operated by or facilitating communications and processing by multiple parties in a network environment, such as the Internet, but it should be understood that communications may be facilitated through one or more public or private network environments, and that various other arrangements are possible. In addition, multiple computers, such as servers, or other computerized devices, such as POS devices, that communicate directly or indirectly in a network environment may constitute a "system," such as a merchant's POS system. As used herein, references to a "server" or "processor" may refer to a previously described server and / or processor, a different server and / or processor, and / or a combination of servers and / or processors that are stated to perform a previous step or function. For example, as used in the specification and claims, a first server and / or first processor stated to perform a first step or function may refer to the same or a different server and / or processor stated to perform a second step or function.

[0050] Non-limiting embodiments of systems and methods for generating tokenized images allow users to seamlessly purchase products by capturing an image of the product. Using a unique token generation process to generate the tokenized image, the image of the purchased product can be used and processed as a payment token for the transaction. In this way, users can share tokenized images with each other as a means of authorizing transactions and / or providing gifts, without risking exposing their original account identifiers when conducting transactions. This provides enhanced security for transactions and enhances the privacy of user account identifiers and associated payment tokens. Various other advantages are provided and discussed herein.

[0051] Now refer to Figure 1 , shows a system 1000 for generating a tokenized image according to a non-limiting embodiment. A user device 105 communicates with a merchant system 108 via a network environment 112, such as the Internet or a local network, or may communicate via radio frequency, etc. The merchant system 108 may include, for example, a merchant POS system, a merchant web server, an e-commerce system operated on behalf of the merchant, etc. The merchant system 108 communicates with the transaction processing system 102 via the network environment 112 or some other network environment. In some examples, the merchant system 108 communicates with the transaction processing system 102 via a payment gateway 111, such as, but not limited to, an acquirer system or a third-party gateway. The transaction processing system 102 communicates with an account database 110 and one or more issuer systems 104. It should be understood that other arrangements are possible for implementing the non-limiting embodiments of the system for generating a tokenized image.

[0052] Still refer to Figure 1 , a user of user device 105 may attempt to purchase item 107. Item 107 may be an item on a shelf in a retail store, an item identified by the user in any physical environment, an item identified by the user in a website, mobile application, or virtual environment, etc. For example, the user may see item 107 for sale inside or outside a retail environment. The user may use the camera of user device 105 to take a photo of item 107. The user may also take a screenshot on user device 105 of a web page or graphical user interface (GUI) showing item 107. Taking a photo of item 107 generates an image 109 of item 107, which may be stored as one or more files on user device 105 or on a remote system in communication with user device 105. User device 105 may execute an application, such as a wallet application, a merchant application, an issuer application, etc., that presents one or more GUIs 106 on user device 105 that is configured to receive an image identification (e.g., select a file, URL, screenshot, etc.) and / or capture a photo.

[0053] Continue to refer Figure 1In some non-limiting embodiments, image 109 is transmitted from user device 105 to merchant system 108 or some other remote system to identify product 107 and information corresponding to product 107. For example, user device 105 or an application executing thereon may use one or more application programming interfaces (APIs) to query one or more merchant systems 108, a central database, a third-party service, etc. to identify product 107. Product 107 may be identified using image processing and recognition techniques known to those skilled in the art. For example, image 109 may be processed to identify a profile of product 107, generate a feature vector, and compare the feature vector to feature vectors of known products using one or more machine learning algorithms. In some instances, optical character recognition (OCR) technology may be used to process text on a label or product packaging and identify product 107 based on the information. As another example, metadata for a captured screenshot or webpage, visible URLs or text on the screenshot or webpage, etc. may be analyzed and used to identify product 107. Various other techniques may be used to identify product 107. In some non-limiting embodiments, an image 109 from an online source, such as a social media service, can be associated with one or more tags identifying the product 107. In some instances, a merchant can provide the image 109 through its webpage, social media post, or advertisement including embedded metadata to facilitate identification of the product 107. Various other techniques can be used. The product 107 can be identified by name, universal product code (UPC), description, brand, etc.

[0054] Still refer to Figure 1 Once item 107 is identified, information about item 107 is determined. For example, one or more merchants selling item 107 may be determined, including information about item 107, its price, availability, shipping time, and the like. In some non-limiting examples where a single merchant system 108 is queried, it may be determined whether item 107 is available from the merchant. In some non-limiting embodiments, if it is determined that item 107 is unavailable, one or more alternative items may be identified. In non-limiting embodiments where multiple items and / or merchants are identified, the user may be presented with options via GUI 106 to select an item to purchase and / or a merchant from which to make the purchase. It should be understood that information about item 107 may be queried from a central database containing information about multiple items, from a database specific to the item 107 or item type, or dynamically determined based on one or more web bots and / or historical transaction information from other users. In some examples, information about item 107 may be determined from image 109 itself, via text on or near item 107, the geographic location of the user device when image 109 was captured, metadata associated with image 109, or other contextual information.

[0055] Continue to refer Figure 1 , once the item 107 is identified and the information corresponding to the item 107 is determined, a payment token is generated, received, or identified. In some non-limiting embodiments, the user device 105 will have a payment token stored thereon, which may be provisioned to the user device 105 by the issuer system 104, an e-wallet provider, or the like. In other non-limiting embodiments, the user device 105 may communicate with a remote system, such as the issuer system 104, the transaction processing system 102, a token service, or the like, to obtain a payment token corresponding to the user's account. The payment token may be an alphanumeric identifier that may be used like a PAN or other account identifier. In some non-limiting examples, the payment token may be a limited-use token that may be used for a single use, a single purchase, a limited number of uses and purchases, one or more purposes from a specific merchant, or the like.

[0056] Still refer to Figure 1 Once the payment token is obtained, various techniques may be used to generate a tokenized image based on the payment token and the image 109 of the commodity 107. For example, the payment token may be encoded into image data based on the image 109. This may be accomplished, for example, using any steganographic technique known to those skilled in the art. In some non-limiting embodiments, for example, the color space information associated with the image 109 may be modified by adjusting the color space values ​​at predetermined locations in the image data based on the payment token. For example, the RGB values ​​at the beginning, middle, end, or random locations in the image data may be adjusted by numerical values ​​corresponding to each character, number, or bit of the payment token. As another example, the payment token may also be encoded into the image data using the CMYK color model. In some instances, the color space values ​​associated with a single pixel or block of pixels may be adjusted based on the character values ​​of the payment token. It should be understood that any type of image file, whether compressed (e.g., JPEG, TIFF, PNG, etc.) or uncompressed (e.g., BMP), may be encoded with the payment token using steganographic techniques.

[0057] In some non-limiting embodiments, one or more false payment tokens may be encoded in the tokenized image along with the real payment token. In this way, the theft of the payment tokens may be made more difficult because the potential thief will not know which token is the real payment token. In instances where the thief may have access to the original image, image analysis techniques can reveal which pixels have been altered. Thus, including false payment tokens or randomly adjusting other image data values ​​can mislead potential thieves and enhance the security of the tokenized image. The false tokens may also be associated with an alarm event such that an alarm event is triggered if one or more false tokens are used to conduct a transaction. In non-limiting embodiments, the alarm event may notify the user, notify the issuer or another party, mark the account as committing fraud, mark the device as committing fraud, and / or automatically deactivate the real payment token that is also encoded into the image.

[0058] In a non-limiting embodiment, a tokenized image is generated using least significant bit (LSB) steganography and fake tokens. For example, N tokens can be generated, where N-1 tokens are fake tokens and 1 token is a real token. In an RGB embodiment, where each pixel is associated with three bytes, one byte for each of R (red), G (green), and B (blue), the N tokens can be encoded into the last bit of each RGB value. For example, the bit value can be encoded into one bit of each RGB byte, such as the LSB or another bit. In this way, each pixel can have three bits encoded therein. However, it will be appreciated that various other methods are possible, and any number of bits can be encoded into any number of pixels or color space values.

[0059] In some non-limiting embodiments, the encoding can be replicated. In some non-limiting embodiments, each portion of the image data in which the payment token information is to be encoded can be randomized to prevent reverse analysis by checking for modified bits. The order of the tokens (e.g., the placement of a real payment token within a fake token) can be predetermined, or can be based on one or more inherent image qualities or image parameters. For example, size, aspect ratio, color range, contrast, brightness, etc. can be used to influence the order of tokens in an image so that a transaction processing system with a configured algorithm can process the image, determine the quality or parameters, and identify the correct payment token in the image. As another example, the color values ​​of predetermined pixels or blocks of pixels can be used to determine the order of the tokens.

[0060] In a non-limiting embodiment, one or more cryptographic techniques may also be used to encrypt the payment token encoded into image 109 and / or to encrypt image 109 itself. For example, image 109 may be encrypted using elliptic curve cryptography or other asymmetric techniques, symmetric cryptography, or a combination of both. Furthermore, image 109 may be processed using one or more consensus algorithms (e.g., a spline consensus algorithm) to prevent transmission losses. It will be appreciated that various other techniques may be used, such as calculating a cyclic redundancy check (CRC) on image 109.

[0061] The tokenized image can be used by the user to conduct a transaction, or can be shared with another user to allow that user to conduct a transaction. For example, the tokenized image can be transmitted via email, text message, social media message, etc., and can be used by anyone to conduct a transaction. In a non-limiting embodiment where the payment token is a limited-use token, the tokenized image can be used only to conduct specific transactions, such as transactions for specific goods, transactions with specific merchants, transactions by specific users, transactions of a specific value or less, etc. In this way, the tokenized image can be given to another user as a gift, rather than a physical item.

[0062] Continue to refer Figure 1 In a non-limiting embodiment, the tokenized image can be transmitted from the user device 105 or another user device that received the tokenized image to the merchant system 108 to make a purchase. For example, the tokenized image can be scanned from the user device at the POS system, wirelessly transmitted at the POS system via radio frequency or by any other means, uploaded from the user device to the merchant system 108, or provided to the merchant system 108 in any other manner. The merchant system 108 can then generate a transaction request directly or through the payment gateway 111 and transmit the transaction request to the transaction processing system 102. The transaction processing system 102, the issuer system 104, or some other service can decrypt the tokenized image if it is encrypted, identify and extract the payment token from the tokenized image, and complete the transaction using the extracted payment token. It should be understood that the tokenized image can be processed by any entity, including but not limited to a separate token service, the payment gateway 111, the transaction processing system 102, the merchant system 108, the issuer system 104, and / or any combination of such systems.

[0063] In a non-limiting embodiment, one or more smart contracts can be used within a blockchain network to make payments using tokenized images. For example, a node of the blockchain network can process a transaction request including a tokenized image, a merchant identifier, and a user identifier by first decrypting the tokenized image (if encrypted) and authenticating the merchant and user via public-private key cryptography. In this way, the tokenized image can be pushed to and stored on the blockchain network, encapsulating the various parameters and other metadata of the transaction into a secure data package. Performing processing on the blockchain network can ensure increased integrity and violation checks in the tasks performed by the nodes. The data can include a digital signature confirming that the user and / or merchant possesses the public key corresponding to the public key identified in the transaction request. A smart contract can then be created between the user and the merchant for the purchase. In some non-limiting embodiments, the tokenized image can also include a separate authentication token, PIN, or password used to authenticate the user of the smart contract.

[0064] Payment can be made through smart contracts in a variety of ways. For example, a smart contract can include logic that triggers payment using a tokenized image (and the payment token encoded therein) in response to goods being shipped and / or received. In other instances, the merchant can initiate a standard transaction using the extracted account identifier, and the settlement of the transaction can complete the smart contract. As another example, payment can be initiated by the user upon receipt of a purchase, such as by implementing a push payment by scanning a QR code or other data carrier that includes the merchant's payment information. In this way, the smart contract can be completed when the push payment is completed. Various other arrangements may use smart contracts and blockchain networks to securely implement transactions using tokenized images.

[0065] Now refer to Figure 2 , shows a user device 105 according to a non-limiting embodiment. The user device 105 includes a processor 206 in communication with a network interface 205, a camera unit 208, and an image encoding engine 210. The image encoding engine 210 can be a mobile application such as an e-wallet application executable by the user device 105, can be a standalone mobile application, and / or can be one or more functions of an application that communicates with a remote system that provides the image encoding engine 210 as software as a service (SaaS). It should be understood that various other arrangements are possible, and Figure 2 The components of user device 105 shown are for example purposes only. User device 105 may also include a data storage device (memory) 204, a display device (not shown), an input device (not shown), a transponder (not shown), and / or other components.

[0066] Continue to refer Figure 2, the camera unit 208 of the user device 105 is used to capture an image 209 that is input into the image encoding engine 210. The token 207 stored on the memory 204 is also input into the image encoding engine 210. The token 207 can also be stored elsewhere, can be generated upon request, etc. The image encoding engine 210 then generates a tokenized image 211 based on the image 209 and the token 207, and transmits the tokenized image 211 to a remote system via the network interface 205. For example, the tokenized image 211 can be transmitted to a merchant system, a payment gateway, a transaction processing system, an issuer system, another user device, etc. In some non-limiting embodiments, the tokenized image 211 can be stored on the data storage device 204 for later use by the user device 105 and can be transmitted via the transponder ( Figure 2 The tokenized image is transmitted to the local POS system (not shown) or by some other means to request a transaction.

[0067] In non-limiting embodiments, multiple tokenized images can be used for each of multiple items purchased from a merchant. For example, a non-limiting embodiment can be used at a merchant's retail location by capturing images of the items as they are placed in a shopping cart or basket. In some instances, the images can be captured using a user device, while in other instances, one or more merchant devices located at the retail location and / or in the shopping cart or basket can be used. In some non-limiting embodiments, a tokenized image can be generated for each item upon retrieval or when the user leaves the retail location. By generating a separate tokenized image for each item, merchants and other entities involved in the transaction can more easily process returns or payment reversals, reduce fraud, and improve the ability to track transaction activity. Furthermore, separate tokenized images allow the transaction processing system to attribute payments for multiple items in a shopping cart to a single item corresponding to that item, thereby providing the transaction processing system with enhanced item-by-item data that it may not normally have access to. The tokenized image can be used to conduct transactions with a remote POS system upon the user's departure from the retail location, as determined by one or more sensors within the retail location, the location of the user device, and the like. Additionally, one or more merchant cameras or sensors may be used to confirm what the user has picked up and purchased to ensure that the user does not take away more than what was purchased. The location of the user device, whether determined by data, cell data, or any other means, may be used to determine at which merchant location the user is shopping so that the user device can identify the correct merchant system to conduct the transaction.

[0068] Now refer to Figure 3, illustrates a method for generating a tokenized image according to a non-limiting embodiment. At a first step 300, an image of an item is received from a user. This may include the user selecting an image from a file menu, the user taking a photo using a camera, the user capturing a screenshot, the user entering a URL for an image, and the like. It should be understood that, in non-limiting embodiments, the image may not be an image of an item, but may instead be any type of image. At step 302, in embodiments where the image is an image of an item, the item may be determined based on the image. For example, one or more image processing techniques and / or optical character recognition techniques may be used to determine the item depicted in the image. As explained herein, the item may be determined from a central database, multiple merchant databases, or in any other similar manner. At step 304, information associated with the item is determined. For example, one or more merchants offering the item for sale may be determined, the price of each item may be determined, purchase options (e.g., type, model, color, etc.) may be determined, and the like. As explained herein, the information associated with the item may be determined in any manner.

[0069] Continue to refer Figure 3 , at step 306, a payment token is generated based on the user's account identifier. In some non-limiting instances, the payment token can be pre-generated and provided to a client device owned by the user. In some non-limiting examples, the payment token can be generated after the image is received at step 300. The payment token can be generated by a transaction processing system, an issuer system, or a separate token service based on the user's account identifier. At step 308, one or more false payment tokens are generated. As an example, one or more payment tokens having the same size and structure as a real payment token can be generated by a client device, a transaction processing system, an issuer system, or a separate token service. At step 310, the real payment token and the false token are encoded in the image using steganography. It should be understood that in some non-limiting embodiments, the payment token can be encoded into the image without using any false tokens.

[0070] Now refer to Figure 4 , shows a method for generating a tokenized image according to a non-limiting embodiment. At a first step 400, as combined with Figure 3 As described in step 300 of the embodiment, an image of a product is received from a user. In step 402, in an embodiment where the image is an image of a product, as in combination with Figure 3As described in step 302, the product can be determined based on the image. At step 404, multiple merchants that offer the product for purchase are determined. This determination can also identify prices, purchase options, and other information associated with the product from each of the multiple merchants. In some non-limiting embodiments, the merchants can be notified and provided with the opportunity to provide one or more offers, such as price adjustments, discounts, coupons, etc. to the user. In some non-limiting embodiments, the merchant can submit one or more bids to a bidding platform that determines which merchant to present to the user. The bidding platform can be used to optimize transactions based on price, geographic location, and / or merchant category, and help prevent abusive activities, such as spamming or malicious merchant processing. In this way, and at step 406, a GUI with multiple purchase options for the product can be presented to the user. At step 408, a selection of a purchase option or a specific merchant is received from the user via the GUI presented in step 406. At step 410, as combined Figure 3 As described in step 310 , the token is encoded into the image.

[0071] Although non-limiting embodiments have been described in detail for purposes of illustration based on what are presently considered to be the most practical and preferred embodiments, it should be understood that such details are used solely for that purpose and that the invention is not limited to the disclosed embodiments, but, on the contrary, is intended to cover modifications and equivalent arrangements within the spirit and scope of the appended claims. For example, it should be understood that the present invention contemplates that, to the extent possible, one or more features of any embodiment can be combined with one or more features of any other embodiment.

Claims

1. A computer-implemented method for encoding an account token in an image file, comprising: receiving an identification of an image from a user associated with the account identifier; generating, using at least one processor, at least one token based on the account identifier of the user; generating at least one false token using at least one processor; encoding, using at least one processor, the at least one token and the at least one dummy token in the image, thereby producing a tokenized image comprising the at least one token and the at least one dummy token; as well as transmitting, using at least one processor, the tokenized image to a transaction processing system, wherein the transaction processing system is configured to conduct a transaction using the at least one token based on the tokenized image, The image includes an image of a commodity associated with the transaction.

2. The computer-implemented method of claim 1 , further comprising: extracting the at least one token from the tokenized image using at least one processor; as well as A transaction is conducted based on the at least one token using at least one processor. 3 . The computer-implemented method of claim 1 , wherein encoding the at least one token comprises encoding the at least one token into RGB values ​​of the image.

4. The computer-implemented method of claim 1 , wherein encoding the at least one token comprises: encrypting the at least one token to produce encrypted data; as well as The encrypted data is encoded into the image.

5. The computer-implemented method of claim 1 , further comprising: detecting a transaction request using the at least one false token; as well as In response to detecting the transaction request using the at least one false token, the at least one token is automatically deactivated.

6. The computer-implemented method of claim 1 , further comprising: capturing a photo using a camera of the client device; as well as The image is generated based on the photograph. The computer-implemented method of claim 1 , wherein the image is a screenshot or an image downloaded from a web page.

8. The computer-implemented method of claim 1, wherein the image further comprises embedded merchant data or product data.

9. The computer-implemented method according to claim 1 further includes using at least one processor of a first client device of a first user to transmit the tokenized image to a second client device of a second user different from the first user including at least one processor, wherein the at least one processor of the second client device transmits the tokenized image to the transaction processing system.

10. A system for encoding an account token in an image file, comprising at least one processor programmed or configured to: receiving an identification of an image from a user associated with the account identifier; generating at least one token based on the account identifier of the user; Generate at least one fake token; embedding the at least one token and the at least one false token into the image, thereby generating a tokenized image including the at least one token and the at least one false token; and transmitting the tokenized image to a transaction processing system, wherein the transaction processing system is configured to conduct a transaction using the at least one token based on the tokenized image, The image includes an image of a commodity associated with the transaction.

11. The system of claim 10, further comprising the transaction processing system, wherein the transaction processing system is programmed or configured to: extracting the at least one token from the tokenized image; and A transaction is conducted based on the at least one token.

12. The system of claim 10, wherein encoding the at least one token comprises encoding the at least one token into RGB values ​​of the image.

13. The system of claim 10, wherein the at least one processor embeds the at least one token by: encrypting the at least one token to generate encrypted data; and The encrypted data is encoded into the image.

14. The system of claim 10, wherein the at least one processor is further programmed or configured to: detecting a transaction request using the at least one false token; and In response to detecting the transaction request using the at least one false token, the at least one token is automatically deactivated.

15. The system of claim 10, further comprising a client device comprising the at least one processor, wherein the at least one processor is further programmed or configured to: capturing a photo using a camera of the client device; and The image is generated based on the photograph.

16. The system of claim 10, wherein the image is a screenshot or an image downloaded from a web page.

17. The system of claim 10, wherein the image further comprises embedded merchant data or product data.

18. A system according to claim 11, wherein the at least one processor is further programmed or configured to transmit the tokenized image using at least one processor of a first client device of a first user to a second client device of a second user different from the first user including at least one processor, wherein the at least one processor of the second client device transmits the tokenized image to the transaction processing system.

19. A computer program product for encoding an account token in an image file, comprising at least one non-transitory computer-readable medium including program instructions that, when executed by at least one processor, cause the at least one processor to: receiving an identification of an image from a user associated with the account identifier; generating at least one token based on the account identifier of the user; Generate at least one fake token; embedding the at least one token and the at least one false token into the image, thereby generating a tokenized image including the at least one token and the at least one false token; and transmitting the tokenized image to a transaction processing system, wherein the transaction processing system is configured to conduct a transaction using the at least one token based on the tokenized image, The image includes an image of a commodity associated with the transaction.

Citation Information

Patent Citations

  • User interest-based product information recommendation system

    CN105378782A

  • Method of generating secure tokens and transmission based on (TRNG) generated tokens and split into shares and the system thereof

    US20140341374A1

  • Using steganography to perform payment transactions through insecure channels

    US20150006390A1