Electronic transaction method and apparatus using flexible transaction identifier
Patent Information
- Application Number
- CN202080051673.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-07-18
- Filing Date
- 2020-06-25
- Publication Date
- 2026-09-11
- Estimated Expiration
- 2040-06-25
AI Technical Summary
然而,这些可能性中的许多都是通过不再支持传统系统来采用的-在较新的和新兴的经济体中,这不会产生重大问题,因为他们使用传统系统和方法的消费者很少
Smart Images

Figure CN114127766B_ABST
Abstract
Description
[0001] Citation of relevant applications
[0002] This application claims priority to European Patent Application No. 19187159.9, filed on July 18, 2019. The full disclosure of the above-cited application is incorporated herein by reference. Technical Field
[0003] This disclosure generally relates to electronic transaction methods using flexible transaction identifiers. This disclosure also relates to devices for initiating electronic transactions according to one of these methods. Background Technology
[0004] Traditional electronic trading systems and methods, particularly electronic financial trading methods and systems, rely on high standardization to ensure high interoperability. Furthermore, supporting existing and traditional operations often requires technological improvements. However, this significantly limits the speed at which new developments can be introduced. On the other hand, high standardization reduces the likelihood of fraudulent transactions being approved, or even if approved, increases the likelihood of detecting and appropriately handling such fraud.
[0005] Traditional payment methods originated from agreements between consumers and banking institutions, using physical cards linked to accounts held at those institutions for electronic payment transactions. By providing the merchant with the card number and main account number (PAN), an electronic transaction is initiated, resulting in funds being transferred from the linked bank account to the merchant's bank account. A magnetic stripe reader is typically used to transmit the card number.
[0006] Currently, many aspects of electronic payment transactions have become digital, allowing them to be conducted online using mobile devices. For example, apps like WeChat Pay and Alipay facilitate payments for goods or services, or payments made to (or by) other account holders. However, many of these possibilities are adopted by no longer supporting traditional systems—this doesn't pose a significant problem in newer and emerging economies where fewer consumers use traditional systems and methods. But this lack of interoperability limits the adoption of systems and methods compatible with tradition. It also limits their adoption in other countries. Furthermore, the increasing use of payments through such electronic transactions increases the frequency and volume of fraudulent transactions.
[0007] The purpose of this invention is to provide additional electronic transaction possibilities suitable for financial or payment transactions, while maintaining a high degree of interoperability with conventional systems and providing strong fraud protection. Summary of the Invention
[0008] According to a first aspect of this disclosure, a computer-implemented electronic transaction method is provided, comprising: a user obtaining a serial number not directly associated with the user; the user providing a transaction identifier to an electronic transaction accepting environment to initiate an electronic transaction, the transaction identifier comprising: a routing identifier; the serial number not directly associated with the user; context information including one or more parameters associated with the generation of the transaction identifier; and verification information including a value determined using the serial number and the context information; the method further comprising: the electronic transaction accepting environment transmitting the transaction identifier to an authenticator using the routing identifier; the authenticator authenticating the transaction identifier using the verification information, the serial number, and the context information; and, if the transaction identifier is deemed authentic, allowing the initiation of the electronic transaction.
[0009] The authenticator has a high degree of freedom in defining the validity of the data content. The improved transaction identifier can be fully authenticated using the data and values contained within the improved transaction identifier itself. Optionally, additional external data or values (not included in the improved transaction identifier) can also be used.
[0010] By using serial numbers not directly associated with the user, more possibilities and flexibility are provided for initiating electronic transactions, especially electronic payment transactions. For example, a user can provide one or more transaction identifiers to another user, such as a parent providing one or more transaction identifiers to a child, or a company providing one or more transaction identifiers to an employee. This differs from PANs or credit card numbers—which can be considered traditional transaction identifiers—but are directly associated with the user because they use card numbers and / or account numbers.
[0011] According to a second aspect of this disclosure, a computer-implemented electronic transaction method is provided, wherein a user obtains the serial number contained in a transaction identifier.
[0012] While this method could be achieved by distributing serial numbers, distributing transaction identifiers is likely more secure. Additionally, it simplifies the hardware and / or software required for users to initiate electronic transactions.
[0013] According to another aspect of this disclosure, a computer-implemented electronic transaction method is provided, wherein the method further includes: a user providing an early-available serial number and / or an early-available transaction identifier to a transaction identifier generator; and the user obtaining the serial number and / or transaction identifier from the transaction identifier generator.
[0014] Providing a serial number and / or identifier linked to previously available numbers may be more convenient. For example, providing a specific user with a consecutive serial number. Alternatively, the use of a transaction identifier can simplify user authentication.
[0015] According to another aspect of this disclosure, a computer-implemented electronic transaction method is provided, wherein the method further includes: a user obtaining an additional serial number and / or an additional transaction identifier, and the user subsequently using the additional serial number and / or the additional transaction identifier to initiate another electronic transaction.
[0016] By allowing users to store one or more additional transaction identifiers, for example, on their associated mobile device (their mobile device), users can initiate electronic financial transactions offline using one or more of the stored enhanced transaction identifiers.
[0017] According to another aspect of this disclosure, a computer-implemented electronic transaction method is provided, wherein the method further includes: a user obtaining a transaction identifier generator; and using the transaction identifier generator to generate one or more serial numbers and / or one or more transaction identifiers for subsequently initiating one or more electronic transactions.
[0018] By providing a transaction identifier generator, users can be offered a higher level of security and independence. This can be achieved with any appropriate hardware and / or software included in (or working with) computing devices such as mobile devices.
[0019] Users may need to obtain verification information from a trusted source. Optionally, a transaction identifier generator can be configured and arranged to generate verification information, thereby further increasing the degree of operational independence.
[0020] According to another aspect of this disclosure, a computer-implemented electronic transaction method is provided, wherein the method further includes indirectly associating the serial number with a user.
[0021] While transaction identifiers are largely self-contained, allowing for a high degree of flexibility, it may be advantageous to indirectly associate one or more transaction identifiers with a user. For example, a list of users who have received a specific serial number and / or a specific transaction identifier could be maintained by the issuer and / or authenticator. Alternatively, the specific serial number and / or specific transaction identifier could be pre-approved for use by the issuer and / or authenticator. This indirect association can be achieved through, for example, issuing a serial number and / or transaction identifier to a user; making the serial number and / or transaction identifier available to the user for use in one or more electronic financial transactions; having the transaction identifier accepted by the authenticator for authentication after the user has used it in a financial transaction; having the transaction identifier authenticated by the authenticator for authentication after the user has used it in a financial transaction; and any combination thereof.
[0022] According to another aspect of this disclosure, a computer-implemented electronic transaction method is provided, wherein: an electronic transaction acceptance environment is configured and arranged to process transaction identifiers into standard-compliant transaction identifiers; the transaction identifiers are standard-compliant; the routing identifiers are standard-compliant; the standard is ISO-7812, EMV, or any combination thereof.
[0023] By transmitting the transaction identifier as a standard-compliant identifier, the transaction identifier can be transmitted to the authenticator using existing software and hardware.
[0024] Specifically, the routing identifier is standard-compliant because it includes routing instructions that allow the authenticator to reach the identifier. This is the minimum part that should conform to the standard. Optionally, the sequence number and / or authentication information are not standard-compliant—these parts of the identifier are not required when routing to the base address. However, the authenticator may optionally use one or more parts of the transaction identifier, other than the routing identifier, to internally route the transaction identifier to the correct processing environment.
[0025] According to another aspect of this disclosure, a computer-implemented electronic transaction method is provided, wherein the transaction identifier is similar to a master account (PAN).
[0026] The use of improved transaction identifiers, similar to PANs, can provide one of the highest levels of interoperability because the hardware and / or software that processes these numbers is widely available.
[0027] Alternatively, the transaction identifier may include the Luhn check bit.
[0028] This also provides a high degree of interoperability, as the hardware and / or software for handling such parity bits are also widely used.
[0029] According to another aspect of this disclosure, a computer-implemented electronic transaction method is provided, the method further comprising: after initiating an electronic transaction using the transaction identifier, or after an authenticator has permitted the initiation of an electronic transaction, making the serial number and / or transaction identifier unusable for subsequent use.
[0030] Improving transaction identifiers provides a highly flexible approach to electronic trading. Identifiers can be configured for single-use in any convenient way—for example, for a single use only to initiate an electronic transaction. However, since denying permission to initiate a transaction may be associated with communication problems, restricting usage to single-authorization may be more advantageous. This can optionally be combined with a default setting that allows reuse unless restricted. This restriction can optionally be made based on one or more parties involved and / or circumstances related to the transaction. The usage and reuse policy can optionally be changed at different times.
[0031] According to another aspect of this disclosure, a computer-implemented electronic transaction method is provided, the method further comprising: after initiating an electronic transaction using the transaction identifier, or after an authenticator has permitted the initiation of an electronic transaction, making the serial number and / or transaction identifier available for subsequent use.
[0032] Alternatively, this flexibility can be used in different ways. For example, the identifier can be configured for single use by allowing reuse after the electronic transaction is initiated. This can optionally be combined with a default setting that restricts reuse unless permitted. This restriction can optionally be made based on one or more parties involved and / or circumstances related to the transaction. The use and reuse policy can optionally be changed at different times.
[0033] According to another aspect of this disclosure, the computer-implemented electronic transaction method is provided as a non-alphanumeric representation to the electronic transaction acceptance environment.
[0034] The flexibility allowed by transaction identifiers allows the use of standardized representations, such as QR codes, 1D barcodes, and 2D barcodes, to transmit transaction identifiers to the receiving environment.
[0035] According to another aspect of this disclosure, the transaction identifier comprises no more than 19 characters, preferably no more than 18 characters, more preferably no more than 17 characters, and most preferably no more than 16 characters.
[0036] In particular, when provided as a representation of a QR code or 1D barcode, the number of digits may be limited by the standardization and / or the reduced recognizability and readability of the code as the number of digits increases. It is preferable to keep the number of digits to 19 or less. Shorter identifiers may also be advantageous because existing hardware and / or software may be able to recognize and process such lengths without requiring extensive updates and / or modifications.
[0037] Alternatively or alternatively, the serial number may be arranged to include no more than 9 digits, preferably no more than 8 digits, and most preferably no more than 7 digits.
[0038] According to another aspect of this disclosure, the method further includes: after the authenticator receives the transaction identifier, evaluating one or more parameters associated with the generation and / or use of the transaction identifier in the electronic transaction; and if the one or more parameters are evaluated as acceptable, allowing the initiation of the electronic transaction.
[0039] While transaction identifiers can be used and authenticated using only the data contained within them, it may be advantageous to further consider one or more parameters associated with the generation and / or use of the transaction identifier. This can reduce the risk of authenticating fraudulent transactions.
[0040] These one or more parameters can be communicated externally to the transaction identifier. Alternatively, the transaction identifier may include a pattern identifier for communicating to the authenticator one or more parameters regarding: the use of a server that generates one or more values in the corresponding transaction identifier; the use of a user device that generates one or more values in the corresponding transaction identifier; the use of user authentication prior to the generation of one or more values in the corresponding transaction identifier; the use of a amount for generating verification information; the use of a storage register for the corresponding transaction identifier; and any combination thereof.
[0041] According to another aspect of this disclosure, the transaction identifier may contain contextual information for conveying data to the authenticator about: the generation of the corresponding transaction identifier, the generation of any verification information contained in the corresponding transaction identifier, the algorithm for generating the corresponding transaction identifier, the hardware for generating the corresponding transaction identifier, the software for generating the corresponding transaction identifier, or any combination thereof.
[0042] The transaction identifier is flexible enough to convey additional data – this can be used for record keeping and / or authentication purposes. Alternatively, the transaction identifier may also include: a network identifier associated with the authenticator; a generator identifier associated with the generator of the transaction identifier; a processing indicator for influencing how the authenticator processes the transaction identifier; a mapping server identifier for instructing the authenticator on the server used for authentication; and any combination thereof.
[0043] According to another aspect of this disclosure, there is provided an apparatus associated with a user, configured and arranged to initiate any of the aforementioned electronic transaction methods, the apparatus comprising: a storage register for storing one or more transaction identifiers and enabling them to be subsequently used in one or more electronic transactions.
[0044] By using storage registers, offline use of transaction identifiers becomes more convenient.
[0045] A device associated with a user and configured and arranged to initiate electronic transactions in accordance with any of the foregoing aspects, the device comprising: an identifier generator for generating one or more serial numbers and / or one or more transaction identifiers, and enabling them to be subsequently used in financial transactions.
[0046] By using an identifier generator, the offline use of transaction identifiers becomes more convenient. Attached Figure Description
[0047] Features and advantages of some embodiments of the invention, and ways of implementing these features and advantages, will become more apparent when the following detailed description of the invention is taken in conjunction with the accompanying drawings, which illustrate preferred exemplary embodiments. The drawings are not necessarily drawn to scale. In the drawings: Figure 1 An electronic trading method using an improved transaction identifier is described; Figure 2 An improved method for generating transaction identifiers is described; Figure 3 The possible portions and types of information that can be included in the improved transaction identifier are illustrated. Figure 4 This describes yet another example of an electronic trading method that uses one or more improved trading identifiers; Figure 5 This describes yet another example of an electronic trading method that uses one or more improved transaction identifiers; Figure 6 This describes yet another example of an electronic trading method that uses one or more improved transaction identifiers. Detailed Implementation
[0048] Figure 1 An electronic transaction method 400 using an improved transaction identifier 150 is described. As a non-limiting example, it is applicable to financial transactions. In the context of this disclosure, payment is used as a non-limiting example. Those skilled in the art will recognize that the method can be used for any type of transaction, not only providing funds to a merchant in exchange for goods or services (payment), but also including any form of financial transaction between two parties. This includes: - Transferring funds between any two parties, including consumers; - Refund or discount transactions, where funds are transferred from the merchant to the consumer; and - Transferring funds between two accounts of the same party, such as topping up an e-wallet balance or topping up a credit balance that will be used in subsequent financial transactions.
[0049] Method 400 includes: a) Users such as consumers 210 provide POI 540 with 270 improved transaction identifiers 150.
[0050] In this context, POI 540 (Point of Interaction) is a hardware and / or software component that enables a user 210, such as a consumer, to initiate electronic transactions. Specifically, it allows for the initiation of financial or electronic payment transactions. For example, it can be manually operated, partially automated, or fully automated. It includes a processor programmed to receive and forward transaction identifiers 150 and 290.
[0051] For example, it can be included in point-of-sale devices (such as card readers). The newer generation POI 540 allows payments to be made using devices other than credit cards (such as payment apps on mobile devices), provided that the device ensures the same level of security.
[0052] User 210 can provide POI 540 with 270 improved transaction identifier 150 directly or through an intermediary to initiate electronic transactions.
[0053] As shown in the figure, a mobile device 200 provides an improved transaction identifier 150, which is associated with user 210. This is not necessary for method 400, but is one of the preferred embodiments—any suitable means of interaction and information transmission can be used. Any suitable computing device 200 can be configured and arranged to perform the method, such as a computer, laptop computer, tablet computer, or mobile phone.
[0054] For example, any suitable technology or transmission channel 270 can be used to provide the improved transaction identifier 150, such as using NFC to send a digital code. Other options include user interaction, manual input, electrical contact, tight coupling, electromagnetic radiation, induction, visible or invisible light, contactless magnetic stripe, RF, Bluetooth, WiFi, mobile data, LAN, USB, HTTP, HTTPS, XMPP, web sockets, FTP, e-commerce, or any combination thereof.
[0055] If mobile device 200 is used, images can be displayed on the screen for other devices, including POI 540, to read, such as other mobile devices that include cameras.
[0056] In the case of a mobile device 200 providing an improved transaction identifier 150, the mobile device 200 can first receive information from the POI 540 regarding any stringent requirements and / or preferences for electronic transactions. For example, if a Bluetooth-enabled transit gate is used, the receiving environment can push information (such as transit station or gate information) to any device within the Bluetooth range of the transit gate.
[0057] The improved transaction identifier 150 can be provided directly or as appropriate representations 350, 351, and 352. In this context, the distinction between the improved transaction identifier 150 and representations 350, 351, and 352 is not important—they can be considered functionally equivalent. If the improved transaction identifier 150 is a relatively simple code, that code itself can be used to transmit 270. However, by providing the improved transaction identifier 150 as one or more representations, such as a numeric representation, a non-numeric representation, and / or an alphanumeric representation 352, the reliability of transmitting 270 and, in some cases, the security, is improved.
[0058] The current trend of consumers carrying smart devices that include processing power, image capture devices (such as optical cameras), and image processing software is being used to represent codes 350, 351, and 352 that are displayed or reflected on other devices, stickers, decals, etc. Optical character recognition (OCR) can be used for representations 352 that include characters. Preferably, representations designed to be easily optically identifiable are 1D barcodes 351, or encrypted or unencrypted QR codes 350. These are non-alphanumeric representations. Other options can be used, such as EMV-compliant QR codes, EMV QRCPS-compliant QR codes, 2D barcodes, 2D dot codes, micro QR codes, IQR codes, HCC2D codes, SQRC codes, FrameQR codes, Anato dot matrix graphics, Aatec codes, CrontoSign, ColorCode, Color Construct Code, CyberCode, d-touch, DataGlyph, Data Matrix, Datastrip codes, Digimarc Barcode, DotCode, Dot Code, DWCode, EZcode, High CapacityColor Barcode, Han Xin Barcode, HueCode, InterCode, MaxiCode, MMCC, MPQR codes, NexCode, PDF417, Qode, AR Code, ShotCode, SnapCode, SPARQCode, VOICEYE, or any combination thereof.
[0059] POI 540 and the device for providing 270 Improved Transaction Identifier 150 and / or its representations 350, 351, 352 can both be included in one or more applications running on the mobile device. In some cases, it can be the same mobile device, and it can even be a mobile device 200 associated with user 210.
[0060] For many of these image-based representations, reading accuracy can be improved by keeping the complexity (e.g., the number of bits) in the improved transaction identifier 150 as low as possible. Preferably, 19 bits or less is preferred. More preferably, 16, 17, 18, or 19 bits are used, as this combines a high degree of data density with manageable representation complexity.
[0061] If only one improved transaction identifier 150 is available, then that is the transaction identifier provided. If more than one improved transaction identifier 150 is available, the improved transaction identifier 150 to be provided can be selected automatically, semi-automatically, manually, or in some combination thereof.
[0062] For example, device 200 may select the most appropriate (most suitable) improved transaction identifier 150, or it may select one randomly (pseudo-randomly). Alternatively, user 210 may indicate a preference. Factors that may be related to the selection include, for example, the time since the improved transaction identifier 150 was generated, any validity period associated with the improved transaction identifier 150, the complexity of the improved transaction identifier 150, the compatibility of the improved transaction identifier 150 with POI 540, and the data contained in the improved transaction identifier 150.
[0063] Optionally, user 210 may provide one or more improved transaction identifiers 150 to the intermediary. The intermediary may then provide one or more transaction identifiers 150 to the POI. The intermediary may be hardware, software, or some combination thereof. It may include one or more applications running on a mobile device. In some cases, it may be the same mobile device as the POI application, and it may even be a mobile device 200 associated with user 210.
[0064] If the Improved Transaction Identifier 150 requires some degree of modification or conversion before it can be suitable for acceptance by POI 540, then an intermediary may be advantageous – for example, converting (splitting) the 18-bit Improved Transaction Identifier 150 into PAN (15+1 Luhn bits) and CVC2 (3 bits). This will be explained in more detail below.
[0065] Method 400 also includes: b) POI 540 receives transaction identifier 150 and provides transaction identifier 150 to electronic transaction acceptance environment 500. POI 540 includes a processor or a portion of the available capabilities that can utilize a processor.
[0066] If transaction identifier 150 is provided as representation 350, 351, or 352, then POI 540 can further convert the received information into the format required by electronic transaction acceptance environment 500. Alternatively, those skilled in the art will also recognize that representations 350, 351, and 352 can be transmitted to the appropriately configured electronic transaction acceptance environment 500.
[0067] POI 540 can communicate with electronic transaction acceptance environment 500, and POI 540 can be included in electronic transaction acceptance environment 500, or some combination of the two.
[0068] Any suitable form of technology or communication channel 290 can be used (for example, see the list above for providing 270 improved transaction identifiers 150 to POI 540), and various combinations of forms can be used.
[0069] The electronic transaction acceptance environment 500 can be hardware, software, or some combination thereof. It can include one or more applications running on a mobile device. In some cases, it can be the same mobile device as the POI application, or even a mobile device 200 associated with user 210.
[0070] The electronic transaction acceptance environment 500 is configured and arranged to process the improved transaction identifier 150 into an ISO-7812 compliant transaction identifier. More specifically, the transaction identifier 150 is generally ISO-7812 compliant, so that it can be recognized by the electronic transaction acceptance environment 500 as ISO-7812 compliant and further transmitted (routed) for authentication. Therefore, the routing identifier 160 is also ISO-7812 compliant.
[0071] For the purposes of this disclosure, improving the ISO-7812 compliance of transaction identifier 150 means that transaction identifier 150 is suitable for interpretation in accordance with the ISO-7812 standard, and one or more of its components (or values) can be located and accessed for further interpretation. In this case, the value of routing identifier 160 can be located and accessed for further interpretation.
[0072] For example, the improved transaction identifier 150 could appear to be a master account (PAN) conforming to ISO-7812, and could be treated in this way for acceptance and routing. The validity of components (or values) such as customer account numbers is determined by the authenticator 600.
[0073] For the purposes of this disclosure, the ISO-7812 compliance of routing identifier 160 means that routing identifier 160 is suitable for interpretation in accordance with the ISO-7812 standard, and the values it contains can be interpreted and used in accordance with the ISO-7812 standard to route transaction identifier 150 for authentication.
[0074] For example, the improved transaction identifier 150 can appear to be a master account (PAN) conforming to ISO-7812 and can be treated in this way for acceptance and routing. The validity of the routing identifier 160, which may be included in the issuer identification number (IIN), is determined by the electronic transaction acceptance environment 500.
[0075] At least a portion (or value) of the improved transaction identifier 150 does not comply with ISO-7812. Preferably, the user 210 account identifier 174 and / or verification information 180 do not comply with ISO-7812. The remaining portion of the improved transaction identifier 150 may or may not comply with ISO-7812.
[0076] For the purposes of this disclosure, non-compliance with ISO-7812 of one or more components (or values) means that: - These values cannot be located or accessed according to the ISO-7812 standard for further interpretation; or These values can be located or accessed in accordance with the ISO-7812 standard for further interpretation, but the values it contains cannot be interpreted and / or used in accordance with the ISO-7812 standard.
[0077] For example, the improved transaction identifier 150 may resemble (or be) a master account (PAN) conforming to ISO-7812. In this case, the electronic transaction acceptance environment 500 simply routes the improved transaction identifier 150 according to the appearance of the routing identifier 160, which is also conforming to ISO-7812. Routing does not require the electronic transaction acceptance environment 500 to analyze or decode other parts of the improved transaction identifier 150.
[0078] Any other appropriate number / identifier and number / identifier format that allows routing in this manner through the Accept Environment 500 can be used.
[0079] It is not necessary for the receiving environment 500 to be fully compliant with ISO-7812 – as a minimum requirement, it should be able to recognize and route routing identifiers 160 that conform to ISO-7812. For the purposes of this disclosure, such a receiving environment 500 is considered to be compliant with ISO-7812.
[0080] For payments, systems compliant with ISO-7812 require a PAN (DE02) as part of the transaction data. This PAN field may consist of (or include) an Improved Transaction Identifier 150.
[0081] Those skilled in the art will also recognize that the same principle—providing non-compliant data within a compliant data container—can be used with the type of standardized transaction acceptance environment.
[0082] Method 400 also includes: c) The electronic transaction acceptance environment 500 uses the routing identifier 160 to transmit the improved transaction identifier 150 to the authenticator 600.
[0083] If transaction identifier 150 is provided by POI 540 as representation 350, 351, or 352, then electronic transaction acceptance environment 500 can further convert the received information into the format required by authenticator 600. Alternatively, those skilled in the art will also recognize that any representation 350, 351, or 352 received from POI 540 can be transmitted to the appropriately configured authenticator 600.
[0084] The electronic transaction acceptance environment 500 can communicate with the authenticator 600, which can be included in the electronic transaction acceptance environment 500, or a combination of the two.
[0085] Any suitable form of technology or communication channel 550 can be used (for example, see the list above for providing 270 improved transaction identifiers 150 to POI 540), and various combinations of forms can be used.
[0086] The authenticator 600 can be hardware, software, or some combination thereof. It can include one or more applications running on a mobile device. In some cases, it can be the same mobile device as a financial transaction acceptance application, or even a mobile device 200 associated with user 210.
[0087] The preferred method is to use the Internet Protocol to connect to the authenticator 600 contained in the online server. The electronic transaction acceptance environment 500 is configured and arranged to provide the improved transaction identifier 150 as an ISO-7812 compliant transaction identifier 550 (routing) to the authenticator 600.
[0088] Method 400 also includes: d) Authenticator 600 uses verification information 180 to authenticate 560 and improves transaction identifier 150; and e) If transaction identifier 150 is deemed genuine, then the initiation of electronic transaction 400 is permitted.
[0089] The authenticator 600 determines whether an electronic transaction 400 should be initiated. If the modified transaction identifier 150 is indicated to be genuine, the electronic transaction 400 is initiated and subsequently approved. If the modified transaction identifier 150 is indicated to be non-genuine, the electronic transaction 400 is not initiated and is not approved. This mechanism provides the authenticator 600 with a high degree of control over the acceptance of the modified transaction identifier 150.
[0090] In many cases, user 210 can have a financial relationship with authenticator 600. For example, user 210 can initiate a financial relationship with a credit card issuer. The issuer can then generate one or more modified transaction identifiers 150 associated with that user, or allow user 210 to generate them themselves (this will be explained in more detail below). In other cases, for example, user 210 can have a financial relationship with an intermediary, who in turn has a financial relationship with authenticator 600.
[0091] The authenticator 600 determines the rules and conditions for authentication and how these rules and conditions are applied to the authentication of a specific improved transaction identifier 150.
[0092] For example, authenticator 600 could be considered as follows: - A specific improved transaction identifier 150 is associated with user 210; - Specific improvements to the generation of transaction identifier 150; - User 210's previous usage; - The number of improved transaction identifiers 150 issued to users 210 and / or used for a period of time and / or not used for a period of time; - The number of Improved Transaction Identifier 150 currently in circulation; - Has the specific improved transaction identifier 150 been provided for authentication?
[0093] Because the number of bits included in the improved transaction identifier 150 may be limited by the standards followed in the operation, the number of different improved transaction identifiers 150 is limited. Alternatively, after the electronic transaction is permitted to be initiated or after the electronic transaction (400) is initiated, a particular (or specific) improved transaction identifier 150 may be made unavailable for subsequent use - this may allow for the "recycling" (or reuse) of the improved transaction identifier 150.
[0094] One of the underlying principles of this invention is that by adhering to minimum routing requirements, the possibilities within existing financial transaction systems can be expanded. Typically, routing is based on the first few digits of the transaction identifier 150. For example, the first 6 (or 8) digits of a Master Account (PAN) conforming to ISO-7812 represent the IIN (Issuer Identifier). The accepting environment 500 using it only needs these first few digits (or the first part of the IIN) to route the transaction identifier 150 to the desired server location determined by the issuer (this could be the issuer's authentication, or an independent authenticator controlled, operated, or licensed by the issuer). Thus, either party can determine the format and use of the second part of the IIN and / or the remainder of the PAN.
[0095] Because the content of the transaction identifier 150 can be configured to be highly dynamic, fraud issues can be reduced, as static numbers in circulation are rare (or even non-existent). The static / dynamic balance is fully configurable. Alternatively, the "card not found" problem is also avoided, since all transactions are initiated without a card, thus allowing the authenticator 600 to set appropriate authentication rules.
[0096] One or more improved transaction identifiers 150 are provided directly or indirectly from the authenticator 600 to the user 210.
[0097] Requirements regarding the use and acceptance of these Improved Transaction Identifiers 150 may include, for example, the authenticator 600's policies, applicable national or international laws, one or more geographic locations where the Improved Transaction Identifier 150 can be used, one or more types of POI 540, whether it is used online or offline, the method of generating the Improved Transaction Identifier 150, the associated transaction amount, information provided by the user 210 to the authenticator 600, previous use of the same Improved Transaction Identifier 150, and a clear usage agreement. Essentially, the issue between the user 210 and the authenticator 600 is whether the Improved Transaction Identifier 150 is authenticated—therefore, it is advantageous to make each Improved Transaction Identifier 150 similar to a number that would be accepted so that it can be routed from the user 210's point of use to the authenticator 600.
[0098] This also means that support for traditional systems may not need to be abandoned, or it can be phased out without affecting interoperability to the point of inconvenience.
[0099] For the purposes of this disclosure, ISO-7812 refers to the standard that can be used to make... www.iso.org ISO / IEC 7812 obtained Identification cards — Identification of issuers The current version consists of two parts: - ISO / IEC 7812-1:2017 Identification cards - Identification of issuers - Part 1: Numbering system; and - ISO / IEC 7812-2:2017 Identification cards - Identification of issuers - Part 2: Application and registration procedures.
[0100] The scope of this invention is not intended to be limited to the current version of this standard. Those skilled in the art will recognize that various future changes, modifications, and versions of this standard, including replacement with equivalent standards, will fall within the scope of the claims. For the current standard, ISO / IEC 7812-1:2017 appears to be most relevant to the implementation of this invention.
[0101] Although ISO-7812 is specified here as a standard, the same principles can be used for any other standard or protocol adopted by financial exchanges, and any other standard or protocol that allows routing through Accept Environment 500 in this manner can be used.
[0102] For example, instead of conforming to ISO-7812, routes can be made conforming to EMV. In this case... - One or more transaction identifiers 150 are EMV compliant; - Route identifier 160 is EMV compliant; - User 210 account identifier 174 and / or verification information 180 do not comply with EMV; and - The Electronic Transaction Acceptance Environment 500 processes the transaction identifier 150 into an EMV-compliant transaction identifier.
[0103] For the purposes of this disclosure, EMV refers to the ability to obtain from www.emvco.com Any standard of the protocol obtained by EMVCo.
[0104] The scope of this invention is not intended to be limited to the current versions of these standards. Those skilled in the art will recognize that various future changes, modifications, and versions of these standards, including replacement with equivalent standards, will fall within the scope of the claims.
[0105] It is not necessary for the receiving environment 500 to be fully EMV compliant – as a minimum requirement, it should be able to recognize and route EMV compliant route identifiers 160. For the purposes of this disclosure, such a receiving environment 500 is considered to be EMV compliant.
[0106] For payments, EMV-compliant systems require a PAN (DE02) as part of the transaction data. This PAN field can consist of (or include) an Improved Transaction Identifier 150.
[0107] Those skilled in the art will also recognize that the same principle—providing non-compliant data within a compliant data container—can be used with the type of standardized transaction acceptance environment.
[0108] You can use any other appropriate number that can be routed through the EMV system, such as the EMV-compliant route identifier 160.
[0109] A very high degree of interoperability can be achieved by ensuring compliance with both EMV and ISO-7812. Furthermore, since the ISO-7812 and / or EMV specifications are well-suited for including new features and possibilities, these features and possibilities can be provided much earlier by using this invention – eliminating the need to wait years or even decades before most hardware and / or software upgrades and / or updates in global financial trading systems.
[0110] Figure 2 An improved method 100 for generating transaction identifier 150 is described.
[0111] Device 200 associated with user 210 (not shown) is configured and arranged (preferably programmed as a software application) to communicate 250 with generator 300, which is configured and arranged to generate one or more improved transaction identifiers 150.
[0112] Generator 300 can be hardware, software, or some combination thereof. It can be provided as a remote server. It can include one or more applications running on a mobile device. In some cases, it can be the same mobile device as a POI application and / or an electronic transaction acceptance environment application and / or an authenticator application. It can even be a mobile device 200 associated with user 210, for example, implemented as an SDK and / or API. It can also be provided as a combination of generator elements 300 distributed across different devices and / or servers. An intermediary can be used in one or more steps of the method.
[0113] Electronic transactions can be initiated using device 200 (as mentioned above). Figure 1 Prior to this, at least one improved transaction identifier 150 is made available to user 210.
[0114] exist Figure 2 In the example shown, device 200 provides appropriate request 250 to generator 300 - for security reasons, it may be advantageous for user 210 to provide some form of identification to generator 300.
[0115] If user 210 and the operator of generator 300 have established a financial relationship, the generator can obtain sufficient details to include the corresponding user identifier 176 (not shown) in one or more modified transaction identifiers 150 generated for user 210. For example, user 210 can provide the device's phone number—then generator 300 can retrieve the necessary user 210 details from the operator's database and use the accessed data to generate one or more modified transaction identifiers 150 containing that user identifier 176. In this case, user 210 provides the corresponding user identifier 176, albeit indirectly.
[0116] A generator 300 that does not require the establishment of a financial relationship can also be provided. For example, if user 210 provides user identifier 176 directly to generator 300, generator 300 can use the provided user identifier 176 to generate one or more improved transaction identifiers 150 containing that user identifier 176.
[0117] In another example, a user can provide the server with a PAN (personal account), CVC2 code, and expiration date, and the server returns one or more Improved Transaction Identifiers 150.
[0118] The one or more improved transaction identifiers 150 are then made available to the user 210 for use in subsequent financial transactions 400.
[0119] For example, if at least one network connection to the Internet is available, and generator 300 is largely available when electronic payment transaction 400 is to be initiated, device 200 can be configured to request 250 improved transaction identifier 150 immediately before making payment using the improved transaction identifier. Generator 300 makes improved transaction identifier 150 immediately available by sending 260 to device 200 that requested it.
[0120] Alternatively or additionally, device 200 may also be configured to include suitable storage devices, such as suitable computer memory. Device 200 may be configured to request 250 one or more improved transaction identifiers 150 at some point before payment is made using the improved transaction identifier 150. Generator 300 makes the one or more improved transaction identifiers 150 immediately available by sending 260 to the requesting device 200, and device 200 stores the one or more improved transaction identifiers 150 for later use. This is particularly advantageous when the improved transaction identifier 150 will be used offline—in other words, when device 200 is not connected to the Internet and / or when the online generator 300 is unavailable.
[0121] Alternatively or additionally, generator 300 may also be configured to include suitable storage devices, such as suitable computer memory, within device 300. Device 200 may be configured to request 250 one or more improved transaction identifiers 150 at some point before payment is made using the improved transaction identifier 150. Generator 300 makes the improved transaction identifiers 150 immediately available by storing them in a suitable storage location associated with user 200. When device 200 is used to initiate an electronic transaction, request 250 is sent to generator 300, and generator immediately responds with one or more improved transaction identifiers. This is particularly advantageous when generator 300 has a limited ability to immediately generate improved transaction identifiers 150 due to processing limitations.
[0122] Figure 3 The illustration depicts the possible portions and types of information that may be contained in the improved transaction identifier 150. The improved transaction identifier 150 can be viewed as a digital container for the secure and orderly distribution and authentication of the information contained therein.
[0123] There are three main types that can be divided into three or more parts: - Routing information 160, configured and arranged such that the improved transaction identifier 150 can be routed from the electronic transaction acceptance environment 500 (not shown) to the authenticator 600 (not shown). Optionally, additional routing information may be provided for use by the authenticator 600 to provide additional internal or external routing; - Mapping information 170, which can be considered as information to be delivered by the improved transaction identifier 150; and - Verification information 180 associated with the corresponding improved transaction identifier 150 serves as a security measure to reduce the likelihood of fraud when generating and using the improved transaction identifier 150.
[0124] Routing information 160 contains numeric addressing so that the improved transaction identifier 150 can be delivered (routed) to the appropriate authenticator 600. It may include multiple addresses, which can be local and / or remote. Note that routing information 160 may be an encoding or representation of an address, rather than a complete address—for example, it may provide a centralized improved transaction identifier processing location that forwards the improved transaction identifier 150 to the authenticator 600's server based on the authenticator 600 identifier.
[0125] Mapping information 170 includes at least a transaction mapping identifier 174, which can be considered a serial number for the improved transaction identifier 50. It is used to generate one or more improved transaction identifiers 150. The transaction mapping identifier 174 can be of any length, but 7-bit, 8-bit, and 9-bit values are preferred because they allow for a wide range of different values (possible values from 10 million to 1 billion) within the preferred length of 16, 17, 18, or 19-bit improved transaction identifiers.
[0126] The serial number function of transaction mapping identifier 174 allows for tracking the generation and use of improved transaction identifier 150. It is not necessary to retain a portion of transaction mapping identifier 174 to identify authenticator 600, as it is included in routing information 160. Nor is it necessary to retain a portion of transaction mapping identifier 174 to identify its issuer. Furthermore, it is not necessary to retain a portion of transaction mapping identifier 174 to identify the issuer of improved transaction identifier 150.
[0127] Transaction mapping identifier 174 is directly associated with improved transaction identifier 150. This differs from PAN or credit card numbers—which can be considered traditional transaction identifiers but are directly associated with user 210 due to the use of card numbers and / or account numbers. Transaction mapping identifier 174 differs, at least in that it is not directly associated with user 210. Although in some embodiments, improved transaction identifier 150 may be configured similarly to PAN, transaction mapping identifier 174 is still not directly associated with user 210.
[0128] Transaction mapping identifier 174 can be indirectly associated with user 210, for example, by storing records of transaction mapping identifier 174 and / or improved transaction identifier 150, which, for example, have: - Published to user 210; - To make it available to user 210 in one or more financial transactions; - After a user uses it in one or more financial transactions, it is accepted by the authenticator 600 for authentication; - Authenticated by Authenticator 600 after the user has used it in one or more financial transactions; And any combination thereof.
[0129] Another difference from PAN is that, although PAN can include Luhn checksums, the Luhn value is determined only by other numbers included in PAN and does not use context information 190.
[0130] Transaction mapping identifier 174 can be provided in a non-contiguous order (as issued as improved transaction identifier 150). This order can also be randomized or pseudo-randomized.
[0131] The verification information can include a 184 verification code, which can be generated for example using the following: - Password generators on remote servers, directly or through intermediaries, - Password generator included in device 200 - A combination of password generator components distributed across different devices and / or servers.
[0132] The verification code generator can also be set up on the same server as the generator 300 of the improved transaction identifier 150. For example, the server providing the DSRP (Digital Secure Remote Payment) verification code can optionally use a DSRP binding component to verify the improved transaction identifier 150 before returning the associated DSRP password.
[0133] Other alternatives can also be used – for example, the improved transaction identifier 150 can be included in a list of credentials to be verified during a digital transaction, which can contain other data such as DSRP, 3DS and / or any other appropriate verification data.
[0134] Authentication 600 can be further improved by providing one or more communication channels with the corresponding generator 300. Generator 300 can provide appropriate verification information to authenticator 600. For example, the DSRP password associated with the improved transaction identifier 150 can be stored by generator 300 (since this is the generator 300 used to generate the specific improved transaction identifier 150) and subsequently accessed using an appropriate access key, such as the improved transaction identifier 150 itself. In practice, generator 300 and authenticator 600 are preferably located on the same server, adjacent servers, or servers with network connectivity to make this collaboration simpler and more efficient.
[0135] Additional data may be included in the mapping information 170, such as identifiers associated with blocks (groups) of sequence numbers, country, region, geographic area, backup facility, authenticator 600, generator, issuer, sub-issuer (e.g., if the issuer allows others to generate the improved transaction identifier 150), authentication category, or any combination thereof. Such data can be used for business purposes, such as analytics and accounting. It can also be used to help route the improved transaction identifier 150 to the authenticator 600, in which case it is also functionally included in the routing information 160.
[0136] The improved transaction identifier 150 is highly configurable for specific users 210, authenticators 600, issuers and / or generators 300.
[0137] Additional information and functionality can also be included in the data fields—for example, contextual information 190 can be provided to convey information about how the improved transaction identifier 150 was generated. This contextual information 190 can be used by the authenticator 600 to, for example, simplify authentication, improve security levels, or allow the improved transaction identifier 150 to be generated offline. The contextual information 190 can contain data about the generation (or selection) of verification information 180, the generation of the improved transaction identifier 150, or any combination thereof.
[0138] An improved transaction identifier 150 may contain data fields representing fixed and dynamic values—a fixed value means that the value will be the same for a large number of improved transaction identifiers 150, while a dynamic value means that the value is used only in a few improved transaction identifiers 150 in circulation. In some cases, a dynamic value may only be used in a single improved transaction identifier 150. If an improved transaction identifier 150 contains at least one dynamic value, then it is dynamic.
[0139] In this disclosure, there are at least 100 improved transaction identifiers 150. It is expected that at least 1000 improved transaction identifiers 150 will be available in practice.
[0140] The dynamism of the improved transaction identifier 150 can also be attributed to the preferred cryptographic operations performed when generating the verification code 184 contained in the verification information 180. The verification code 184 is typically different when different data is used to generate it. The transaction mapping identifier 174 is always used. Optionally, additional data contained in the improved transaction identifier 150, such as the network identifier 162 contained in the routing information 160 (see below), is also used. In some cases, the generated verification code 184 may also depend on the context (environment) in which it is generated.
[0141] Preferably, each improved transaction identifier 150 in circulation is unique; however, in some cases, such as in a merchant-initiated transaction, the improved transaction identifier 150 may be used more than once. In such cases, after the initiation of the electronic transaction is permitted or after the electronic transaction 400 is initiated using a specific transaction identifier, that specific transaction identifier 150 can be made available for subsequent use. Allowing a small number of identical improved transaction identifiers 150 may also be advantageous.
[0142] The extent to which the same improved transaction identifier 150 can be accepted for simultaneous circulation depends on the standards applicable to electronic payment transactions within the corresponding electronic transaction acceptance environment 500 at that time.
[0143] Since the improved transaction identifier 150 includes verification information 180 and optional context information 190, the similarity can be determined by the values contained in the various parts of the improved transaction identifier 150.
[0144] Since the generator 300 is limited only to the overall appearance of the improved transaction identifier 150 (which must be recognized as a valid transaction identifier by the corresponding electronic transaction acceptance environment 500) and the routing identifier 160 (which instructs the corresponding electronic transaction acceptance environment 500 where to send the transaction identifier), all other aspects (and contents) of improving the transaction identifier 150 are configurable to provide a number of desired results.
[0145] If only unique numbers are allowed, generator 300 can be configured to generate only improved transaction identifiers 150 with unique transaction mapping identifiers 174. This can be achieved, for example, by having only a single generator 300, a single issuer, by setting up a central registry, by assigning number ranges to each issuer / generator, and any combination thereof. In this case, many improved transaction identifiers 150 can circulate simultaneously—in some cases, a large number of identifiers 150 can be implemented.
[0146] Alternatively, an improved transaction identifier 150 with a limited validity period can be used—for example, valid for only 2 minutes. This reduces the risk that the same improved transaction identifier 150 may be in circulation simultaneously.
[0147] Alternatively, after allowing the initiation of electronic transaction 400 or after initiating electronic transaction 400 using a specific transaction identifier, the specific transaction identifier 150 can be made unavailable for subsequent use. Then, by allowing the identifier generator to return 260 of the specific transaction identifier 150 after the generated request 250, the specific transaction identifier 150 can be recycled (reused). Advantageously, for a fixed number of bits in the improved transaction identifier 150, this can provide a greater number of concurrent and unique improved transaction identifiers 150 in circulation.
[0148] The appropriate improved transaction identifier 150 used for the disclosed method may, for example, include 18 bits, and may further include:
[0149] Method 400 can be modified based on, for example, the number of improved transaction identifiers 150 to be allowed to circulate, the number of issuers of improved transaction identifiers 150, the number of generators 300 of improved transaction identifiers, the number of expected users, and the expected number of electronic payment transactions. For example: - The issuer (or generator 300) of the improved transaction identifier 150 can generate and publish the improved transaction identifier 150.
[0150] Each issuer can be assigned a range of transaction mapping identifiers 174 to reduce the chance of identical or nearly identical modified transaction identifiers circulating simultaneously. Alternatively or additionally, a centralized register can be set up so that each issuer can check whether it is possible to issue a modified transaction identifier 150 containing a specific transaction mapping identifier 174.
[0151] - The issuer of the improved transaction identifier 150 can also act as an authenticator 600 to process authentication requests 550.
[0152] If a centralized register is set up, each issuer can be allowed to check the feasibility of the improved transaction identifier 150 based on the improved transaction identifier 150 and / or the transaction mapping identifier 174.
[0153] Alternatively, more than one improved transaction identifier 150 (pre-generated) can be provided to the user, allowing the improved transaction identifier 150 to be stored in a properly configured memory included in device 200. If the server-based generator 300 is unavailable (offline mode), one or more electronic payment transactions can still be initiated. References to the improved transaction identifier counter cover: - The improved transaction identifier counter is configured to generate an improved transaction identifier 150 as a true counter. It can be processed sequentially, incrementing by an appropriate interval (e.g., 1) each time an improved transaction identifier is generated. If no initial value is provided, it can start from 1 or from a random (or pseudo-random) value. A starting value is preferred (usually provided by the issuer). - Configuration that periodically synchronizes the improved transaction identifier counter with improved transaction identifier counters included in other generators 300 and / or improved transaction identifier authenticators 600; and - The improved transaction identifier counter only stores the configuration of one or more improved transaction identifiers 150 (or transaction mapping identifiers 174 and other data that may be used to generate improved transaction identifiers 150) provided by other generators 300; - The configuration whereby the improved transaction identifier counter generates a random number (or pseudo-random number) for each improved transaction identifier 150; Alternatively, numerous further measures can be taken to allow for extended periods of offline use of device 200. It is preferable to control and monitor the use of any offline mode. For example, the improved transaction identifier 150 authenticator 600 can use information carried by the electronic transaction to determine whether the use of the improved transaction identifier 150 generated "offline" is acceptable.
[0154] User equipment 200 may be further configured and arranged to generate improved transaction identifiers 150 via a generator 300 and a storage device for one or more improved transaction identifier counters, each improved transaction identifier counter being configured to store transaction mapping identifiers 174. User equipment 200 may also include a verification code 184 generator.
[0155] Offline use can be advantageous when traveling: - Device 200 may lack internet connectivity when users commute between home and work and data connectivity is limited.
[0156] For domestic transactions, users may have sufficient connectivity, but due to cost considerations, they may choose to stop using their data while roaming, or their mobile data contracts may be invalid abroad.
[0157] Many implementations of this method are possible, but some form of risk management is preferred. For example, generator 300 and authenticator 600 can be configured and arranged to maintain an improved transaction identifier counter and periodically synchronize the value of the improved transaction identifier counter. Preferably, they are synchronized when each improved transaction identifier 150 is generated. This provides robust control over the improved transaction identifiers 150 entering circulation.
[0158] If device 200 includes generator 300, and device 200 and authenticator 600 are unable to communicate for an extended period, the improved transaction identifier 150 value (or transaction mapping identifier 174) may be lost, potentially causing desynchronization of the improved transaction identifier counters between generator 300 and authenticator 600. In environments with multiple generators 300 and / or authenticators 600, the risk of desynchronization becomes even higher—generators 300 and authenticators 600 may decide to continue incrementing their improved transaction identifier counters, and continue generating improved transaction identifier 150 even when one or more generators 300 / improved transaction identifier authenticators 600 are offline. The encryption result (associated verification code 184) may be affected by desynchronization.
[0159] For example, authenticator 600 can be configured and arranged to accept multiple improved transaction identifiers 150 generated on device 200 during offline periods, such as up to three. Authentication of the fourth and subsequent improved transaction identifiers 150 can then be rejected. If more than three improved transaction identifiers 150 were used offline, authenticator 600 can also be further configured and arranged to require communication between generator 300 and authenticator 600 to resynchronize the improved transaction identifier counter.
[0160] For example, improved transaction identifier generation can be supported both online and offline: - Device 200 will improve transaction identifier counter #1 for the first offline improved transaction identifier generation (on device 200). Device 200 will use Improved Transaction Identifier Counter #2 for the second offline Improved Transaction Identifier generation (on the device), unless a new set of values is provided after the new Improved Transaction Identifier generation (on the server). - If no new value is provided after the new improved transaction identifier is generated (on the server), device 200 will use the improved transaction identifier counter #3 for the next offline improved transaction identifier generation (on the device) and increment the improved transaction identifier counter #3 (by 1). - More than three improved transaction identifier counters can be set on device 200. In this case, it is preferable to use improved transaction identifier counter #1 and improved transaction identifier counter #2, because using improved transaction identifier counter #3 and improved transaction identifier counters with higher numbers may introduce a greater risk of losing the improved transaction identifier 150 value.
[0161] If an improved transaction identifier counter of 3 or higher is used to generate the improved transaction identifier 150, resynchronization between the generator 300 and the authenticator 600 may be required - the correct improved transaction identifier counter is needed to successfully verify the generated verification code 184.
[0162] - Optionally, the authentication server 600 may also use the information delivered when authenticating the improved transaction identifier 150, as well as any other information provided, to manage risk, such as transaction data, merchant category code, location, type of transaction, POS input mode, acceptance-related information, type of terminal, amount and / or currency.
[0163] - Optionally, the method and device / server can be configured to allow the use of a larger number of improved transaction identifier counters, such as 10 to 100. This can significantly increase the tolerable duration of 200 user devices being offline.
[0164] In this case, it may be advantageous to include the number of improved transaction identifier counters used in the context information 190 conveyed in the improved transaction identifier 150.
[0165] Alternatively, when generating the CAPTCHA 184, an improved transaction identifier (EMI) counter may be considered. Subsequent verification (authentication) on different devices 200 and / or servers 600 subsequently requires this context information 190. If provided as part of the improved transaction identifier 150, the improved transaction identifier authenticator will automatically receive it. The number of improved transaction identifier counters is generally used to enhance the security strength of the improved transaction identifier method, making it more difficult for attackers to pre-compute data or brute-force the system.
[0166] For example, transaction pattern identifier 182 can be implemented using code as follows, for example: 0: Improved transaction identifier 150 generated on server 300; 1: In the case of (no CDCVM and no amount), use counter #1 to generate the improved transaction identifier 150 on device 200; 2: In the case of (with CDCVM and no amount), use counter #1 to generate the improved transaction identifier 150 on device 200; 3: In the case of (having CDCVM and having a amount), use counter #1 to generate the improved transaction identifier 150 on device 200; 4: In the case of (no CDCVM and no amount), use counter #2 to generate the improved transaction identifier 150 on device 200; 5: In the case of (with CDCVM and no amount), use counter #2 to generate the improved transaction identifier 150 on device 200; 6: In the case of (having CDCVM and having a amount), use counter #2 to generate the improved transaction identifier 150 on the device; 7: In the case of (no CDCVM and no amount), use counter #3 to generate the improved transaction identifier 150 on the device; 8: In the case of (with CDCVM and no amount), use counter #3 to generate the improved transaction identifier 150 on the device; and 9: In the case of (having CDCVM and having amount), use counter #3 to generate improved transaction identifier 150 on the device.
[0167] Using more than one digit, such as two digits, to convey more contextual information via an extended codebook can also be advantageous.190 For example, this allows for the communication of more contextual information about improving the transaction identifier counter.190
[0168] In another example, the 18-bit improved transaction identifier 150 may include:
[0169] or:
[0170] or:
[0171] or:
[0172] or:
[0173] or
[0174] The generation of the improved transaction identifier 150 involves two main steps: - Generate (or provide) transaction mapping identifier 174 - Use transaction mapping identifier 174 and one or more optional values included in improved transaction identifier 150 to generate verification code 184.
[0175] CAPTCHA 184 is an encryption key (or encrypted material or encrypted asset) – an encrypted value generated using keyed hashes, signatures, or any appropriate encryption processing, with or without an encryption mechanism. For example, encryption processing can be used to calculate a MAC (Message Authentication Code).
[0176] This process is deterministic so that authenticator 600 can subsequently use the input data used to generate verification code 184 to verify (authenticate) the value. The encryption process requires a list of data and access to an encryption key (here, the improved transaction identifier encryption key). The improved transaction identifier encryption key is shared between the entity responsible for generating 300 and the entity responsible for authenticating 600.
[0177] For successful authentication, the CAPTCHA generator 320 and the authenticator 600 should use the same input data. If only the data contained in the improved transaction identifier 150 is used, defining a default set of data to use may be sufficient—for example: - Only transaction mapping identifier 174 - Transaction mapping identifier 174 and mapping server identifier 172 - Transaction mapping identifier 174, mapping server identifier 172, and network identifier 162 - Transaction mapping identifier 174, mapping server identifier 172, and transaction mode identifier 182 Optionally, context information 190 may also be included in the improved transaction identifier 150, and this may be added to the data. Alternatively, additional parameters and data may be exchanged between the code generator 320 and the authenticator 600 to match code generation and authentication processes.
[0178] In this example, following ISO / IEC 9797-1, an improved transaction identifier encryption key is used to generate the cipher as the MAC (Message Authentication Code). For example, algorithm number 1 and padding method (pad) number 3 (80 padding).
[0179] The password can then be converted into, for example, a 4-digit verification code 184. Since binary information is converted to decimal values, it is preferable not to use the entire range (0000–9999). For example, 13 bits of the generated password are converted to 4-bit values (0000–8191), with 18% of the value range unused (8192–9999). A 5-bit value (00000–65535) can carry a 16-bit generated password, with 35% of the value range unused (65536–99999), while a 3-bit value (000–511) can only carry a 9-bit generated password, with 49% of the value range unused (512–999).
[0180] Alternatively, a retry mechanism can be used to utilize a 9-bit container to carry 10-bit missing values (1000–1023) that can be compensated for by retrying, while also being able to carry values (512–999).
[0181] The improved transaction identifier 150 can be configured to resemble a traditional transaction identifier, enabling it to be accepted and routed by the electronic transaction acceptance environment 500. In other words, different standardized formats can be used.
[0182] For example: 1. As a PAN value (19 bits): • PAN numbers [1-18] = Improved Transaction Identifier 150 - Numbers [1-18] · PAN number
[19] = Luhn checksum calculated for improved transaction identifier 150 - number [1-18] The PAN value can be represented using a 1D barcode 351, QR 350, NFC tag, or the like.
[0183] 2. PAN value (16 bits) + CVC (3 bits), which is generally used for e-commerce and online payments.
[0184] • PAN number [1-15] = Improved Transaction Identifier 150 - number [1-15]
[0185] · PAN number
[16] = Luhn checksum calculated for improved transaction identifier 150 - number [1-15]
[0186] CVC numbers [1-3] = Improved Transaction Identifier 150 - Numbers [16-18]
[0187] It is obvious to a technician that the device 200 can store multiple different modified transaction identifiers 150 in a variety of different modified transaction identifier 150 formats in the memory of the modified transaction identifier storage device 220 configured appropriately.
[0188] According to ISO / IEC 7813, the improved transaction identifier 150 can be stored as follows: 1. Magnetic track data as a contactless magnetic strip or NFC tag Example using track 2 data of a 16-bit PAN, where track 2 is defined as ·ppppppppppppppppDxxxxyyyzvvvwwwwwwwwwF or ppppppppppppppppDxxxxyyyzvvv0F o pppppppppppppppp: Improved Transaction Identifier - Numbers [1-15] op: Luhn check for improved transaction identifier 150 - numbers [1-15] calculation o D: Delimiter o xxxx: Validity period (any valid value) o yyy: Service code (any valid value) oz: PAN serial number (any valid value) o vvv: Improved Transaction Identifier 150 - Number [16-18] o wwwwwwwww: Do not use or fill in any numbers o F: Number of fills - Service codes are components of Track 2 data used to carry information about the transactions used / supported. - The PAN serial number (or PSN) is used to distinguish cards that share the same PAN number.
[0189] 2. Example of using track 2 data of a 16-bit PAN, where track 2 is defined as
[0190] ·ppppppppppppppppDxxxxyyyzvvwwwwwwwwwwF or ppppppppppppppppDxxxxyyyzvvF
[0191] o pppppppppppppppp: Improved Transaction Identifier 150 - Numbers [1-15]
[0192] op: Luhn check for improved transaction identifier 150 - numbers [1-15] calculation
[0193] o D: Delimiter
[0194] o xxxx: Validity period (any valid value)
[0195] o yyy: Service code (any valid value)
[0196] oz: Improved transaction identifier 150 - number
[16]
[0197] o vv: Improved Transaction Identifier 150 - Number [17-18]
[0198] o wwwwwwwwww: Do not use or fill in any numbers
[0199] o F: Number of paddings
[0200] 3. Magnetic track data as a contactless magnetic strip or NFC tag
[0201] Use 13-bit PAN An example of track 2 data, where track 2 is defined as
[0202] ·pppppppppppppDxxxxyyyzvvvvvvwwwwwwF or pppppppppppppDxxxxyyyzvvvvvv0F
[0203] o ppppppppppppp: Improved Transaction Identifier 150 - Number [1-12]
[0204] op: Luhn check for improved transaction identifier 150 - numbers [1-12] calculation
[0205] o D: Delimiter
[0206] o xxxx: Validity period (any valid value)
[0207] o yyy: Service code (any valid value)
[0208] oz PAN serial number (any valid value)
[0209] o vvvvvv: Improved transaction identifier 150 - number [13-18]
[0210] o wwwwww: Do not use or fill in any numbers
[0211] o F: Number of fills
[0212] Alternative options: For example, 13 digits - the number of digits can be less or more. z can be used to carry the improved transaction identifier 150 - number
[13] - while vvvvv is used to carry the improved transaction identifier 150 - number [14-18] 4. Example of using track 2 data of a 19-bit PAN, where track 2 is defined as ·ppppppppppppppppppDxxxxyyyzwwwwwwwwwwF or ppppppppppppppppppDxxxxyyyz0F o ppppppppppppppppppp: Improved Transaction Identifier 150 - Number [1-18] op: Luhn checksum for improved transaction identifier 150 - number [1-18] calculation o D: Delimiter o xxxx: Validity period (any valid value) o yyy: Service code (any valid value) oz: PAN serial number (any valid value) o wwwwwwwww: Do not use or fill in any numbers o F: Number of paddings Figure 4 describe Another example 700 of an electronic transaction method using one or more improved transaction identifiers 150. The generator 320 for CAPTCHA 184 (e.g., generating DSRP CAPTCHA) and the generator 300 for improved transaction identifiers 150 are typically set up on a server by the issuer of the improved transaction identifiers 150. In this example, the server also includes an authenticator 600.
[0213] User equipment 200 is provided for initiating transactions by providing an improved transaction identifier 150 to an electronic transaction acceptance environment 500. This can be provided via a Point of Interest (POI) (not shown) or directly – this is not depicted for clarity. In this case, user equipment 200 includes memory 220, which serves as a storage device for one or more improved transaction identifiers. User equipment 200 is connected to a server via a network, for example, using mobile data. User equipment 200 is configured to provide the improved transaction identifier 150 to the electronic transaction acceptance environment 500, for example, via display representations 350, 351, 352.
[0214] The electronic transaction acceptance environment 500 is typically connected to the acquirer 520 via a network. The acquirer 520 provides an interface between the merchant / payment service provider (included within the electronic transaction acceptance environment 500) and the payment scheme network (operated by the issuer in this case, although it can be operated by another party acting on behalf of the issuer). The acquirer 520 connects to a server via a network, such as through the web (Internet). The acquirer 520 provides a processor to authenticate 600 electronic transactions.
[0215] In this example, an improved transaction identifier 150 is generated immediately before the electronic transaction is initiated.
[0216] • Device 200 initiates contact with the receiving environment 500. Optionally, the receiving environment 500 may provide information to device 200 before initiating the transaction process to notify device 200 of any special requirements for the transaction, such as user authentication requirements. Possible forms and channels of interaction may also be provided.
[0217] For example, if a high-value transaction is to be conducted, the user may need to authenticate with server 710 – this can be done directly on device 200, such as CDCVM, or by entering an online PIN into the merchant's keypad.
[0218] 1. Device 200 (e.g., via API) requests generator 300 to provide an improved transaction identifier 150. Optionally, device 200 may provide the last improved transaction identifier 150 value used by device 200 from improved transaction identifier storage device 220 as part of request 250. If it is the first time using the device, or if the issuer does not require the last improved transaction identifier 150 value, generator 300 determines a transaction mapping identifier 174 to be used to generate the improved transaction identifier 150. Optionally, authentication information may also be provided.
[0219] 2. By using transaction mapping identifier 174, routing information 160, and optional context information 190, CAPTCHA generator 320 generates verification information 180 on the server, including CAPTCHA 184 - in this case, the DSRP password.
[0220] 3. Generator 300 uses transaction mapping identifier 174, routing information 160, and verification information 180 to generate improved transaction identifier 150 on the server. Optionally, context information 190 may also be used.
[0221] 4. The server uses the modified transaction identifier 150 as an access key to store the verification code 184 (DSRP cipher).
[0222] 5. The server returns an improved transaction identifier (260) to device 200. Optionally, additional information such as the improved transaction identifier encryption key and the improved transaction identifier counter may also be provided to device 200.
[0223] Device 200 stores the modified transaction identifier 150 along with any additional information, such as the modified transaction identifier encryption key and the modified transaction identifier counter, in the modified transaction identifier storage device 220. In this case, device 200 is configured to store only a single modified transaction identifier 150, thereby deleting the last modified transaction identifier used from the modified transaction identifier storage device 220. Alternatively, the history of used modified transaction identifiers 150 can be maintained in different memory storage locations.
[0224] 6. Device 200 delivers the improved transaction identifier 150 from the improved transaction identifier storage device 220 to the electronic transaction acceptance environment 500. For example, 1D or 2D code representations 350, 351 can be displayed on the screen of device 200 and read using a merchant's camera included in the electronic transaction acceptance environment 500.
[0225] 7. Request the acquirer 520 to authorize 550 the improved transaction identifier containing the improved transaction identifier 150.
[0226] 8. Use the acquirer 520's processor to begin processing electronic payment transactions.
[0227] 9. Use the acquirer's 520 processor to begin the verification (authentication) of the electronic payment transaction.
[0228] 10. The processor of acquirer 520 invokes improved transaction identifier authenticator 600 by providing improved transaction identifier 730 containing improved transaction identifier 150. Authenticator 600 extracts improved transaction identifier 150 from improved transaction identifier and verifies improved transaction identifier 150.
[0229] 11. The authenticator 600 uses a valid modified transaction identifier 150 to retrieve the verification code 184, which in this case is the DSRP cipher.
[0230] 12. Optionally, the authenticator 600 may request additional authentication from the device 200 and / or the user 740. As described above, the user authenticates with the server 710 if necessary.
[0231] 13. The authenticator 600 receives and processes the additional authentication information.
[0232] 14. The authenticator 600 returns verification information 180 to the acquirer 520. Optionally, context information 190 may also be provided.
[0233] Verification information 180 includes verification code 184 (DSRP password). Acquiring party 520 processes this information to verify the DSRP password and authorize the electronic transaction (this may optionally require communication with the issuer).
[0234] 15. After completing the authorization process, prepare the authorization response.
[0235] 16. Authorization response 560 is sent back to the electronic transaction acceptance environment 500.
[0236] 17. Acquiring parties and merchants may retain information related to electronic transactions. Acquiring parties may need to take further action to complete settlement, or they may need to provide evidence in the event of a dispute. Merchants may need to initiate related merchant-initiated transactions, such as reversals, cancellations, refunds, or partial shipments.
[0237] Figure 5 describe Another example 800 of an electronic transaction method using one or more improved transaction identifiers 301. A verification code 184 generator 320 (e.g., generating DSRP verification codes) is set on device 200; generator 300 is typically set on a server by the issuer of the improved transaction identifier 150. The server also contains an improved transaction identifier authenticator 600. Thus, the server and... Figure 4 The server shown is different in that it does not contain a CAPTCHA generator.
[0238] User equipment 200 is provided for initiating transactions by providing an improved transaction identifier 150 to an electronic transaction acceptance environment 500. User equipment 200 includes a memory serving as an improved transaction identifier storage device 220 and a verification code 184 generator 320. Thus, user equipment 200 is connected to... Figure 4 The difference in the user equipment 200 shown is that it includes a verification code generator 320. User equipment 200 connects to a server via a network, for example, using mobile data. User equipment 200 is configured to provide an improved transaction identifier 150 to an electronic transaction acceptance environment 500, for example, through display representations 350, 351, and 352.
[0239] Electronic transaction acceptance environment 500 is typically connected to acquirer 520 via a network. Acquirer 520 provides an interface between the merchant / payment service provider (included in electronic transaction acceptance environment 500) and the payment scheme network (operated by the issuer or other party acting on behalf of the issuer). Acquirer 520 connects to a server via a network, such as via the web (Internet). Acquirer 520 provides a processor to verify electronic transactions. Electronic transaction acceptance environment 500 and acquirer 520 are interconnected... Figure 4 The same as shown.
[0240] In this example, the improved transaction identifier 150 is also generated immediately before the electronic transaction is initiated.
[0241] · As for Figure 4 The device 200 initiates a connection with the receiving environment 500. Optionally, the user may be required to authenticate with the server 710.
[0242] 1. The user authenticates, for example, through a CDCVM or by entering a PIN into device 200, to access the CAPTCHA generator 320 (in this case, the DSRP generator 320) contained within device 200. This step is not included in... Figure 5 As shown in the image.
[0243] The CAPTCHA generator 320 generates a CAPTCHA 184 in the desired format so that it can be included in the improved transaction identifier 150 to be generated.
[0244] 2. Device 200 (e.g., via API) requests generator 300 to provide an improved transaction identifier 150. Optionally, device 200 can provide a final improved transaction identifier value, such as regarding... Figure 4Optionally, any authentication information may be provided. In this case, device 200 also provides 250 verification codes 184 (DSRP ciphers) to be included in the improved transaction identifier 150. More generally, 250 verification information 180 may be provided from device 200 to the server. Optionally, 250 contextual information 190 regarding the generation of the verification code 184 may also be provided.
[0245] 3. Generator 300 determines the transaction mapping identifier 174 to be used to generate the improved transaction identifier 150. Using the transaction mapping identifier 174, routing information 160, and verification information 180, generator 300 generates the improved transaction identifier 150 on the server.
[0246] Verification information 180 includes a verification code 184 generated by the code generator 320 on device 200. Optionally, context information 190 may also be used.
[0247] 4. The server uses the modified transaction identifier 150 as an access key to store the verification code 184 (DSRP cipher).
[0248] 5. The server returns an improved transaction identifier 150 to device 200. Optionally, additional information such as the improved transaction identifier encryption key and the improved transaction identifier counter may also be provided to device 200 at 260.
[0249] Device 200 stores the improved transaction identifier 150, along with any additional information such as the improved transaction identifier encryption key and the improved transaction identifier counter, in the improved transaction identifier storage device 220, as per [relevant information]. Figure 4 As stated above.
[0250] 6. The device 200 delivers the improved transaction identifier 150 as an improved transaction identifier from the improved transaction identifier storage device 220 to the electronic transaction acceptance environment 500.
[0251] The remainder of the authorization and processing of electronic transactions and Figure 4 The same as that shown above. 7.)
[0253] Figure 6 describe Another example 900 uses a payment method employing one or more improved transaction identifiers 150. A generator 300 is set up on device 200. An improved authenticator 600 is typically set up on a server by the issuer of the improved transaction identifier 150. A verification code generator 320 (e.g., generating DSRP verification codes) is also set up on the server. Thus, the server and... Figure 5 The server shown is different in that it does not contain a generator, but it does contain a CAPTCHA generator 320.
[0254] User equipment 200 is provided for initiating transactions by providing an improved transaction identifier 150 to an electronic transaction acceptance environment 500. User equipment 200 includes a memory serving as a storage device 220 for storing a portion of the transaction identifier, and a generator 300. Thus, user equipment 200 and... Figure 5 The difference with the user device 200 shown is that it includes a generator 300, but it does not include a CAPTCHA generator - so it can only generate a partially improved transaction identifier 150.
[0255] User equipment 200 connects to a server via a network, for example, using mobile data. User equipment 200 is configured to provide an improved transaction identifier 150 to electronic transaction acceptance environment 500, for example, through display representations 350, 351, and 352.
[0256] Generator 300 is generally provided by the issuer of improved transaction identifier 150 and is configured to determine transaction mapping identifier 174 that will be used to generate part of improved transaction identifier 150.
[0257] Alternatively, the device may also include a generator storage unit 230, which includes memory for one or more improved transaction identifier counters, each configured to store a transaction mapping identifier 174. This allows improved transaction identifier generation to occur even if the device cannot contact the issuer of the improved transaction identifier 150 (offline). The generator storage unit 230 may also include memory for one or more improved transaction identifier encryption keys—although the device 200 does not include a CAPTCHA generator, it is preferable that one or more improved transaction identifier encryption keys provide the partial improved transaction identifier code 150 when transmitting partial improved transaction identifier code 150 for authentication. Different improved transaction identifier encryption keys may be used for each partial improved transaction identifier 150, or multiple partial improved transaction identifiers may be associated with a single improved transaction identifier encryption key.
[0258] Device 200 is also configured to provide routing information 160 to generator 300. Device 200 may be configured to generate one or more partially improved transaction identifiers 150 offline, or to require periodic synchronization with the issuer of the improved transaction identifiers 150 to ensure that generator parameters and data are up-to-date and valid.
[0259] The electronic transaction acceptance environment 500 is typically connected to the acquirer 520 via a network. The electronic transaction acceptance environment 500 and the acquirer 520 are connected... Figure 4 and Figure 5 The same as shown.
[0260] In this example, a partially improved transaction identifier 150 is generated immediately before the electronic transaction is initiated.
[0261] · As for Figure 4 and Figure 5 The device 200 initiates and receives communication with the environment 500.
[0262] 1. The user authenticates, for example, via CDCVM or by entering a PIN into device 200, to access generator 300 contained within device 200. This step is not included in... Figure 6 As shown in the image.
[0263] 2. Device 200 requests generator 300 on device 200 to provide a partially improved transaction identifier 150. Optionally, device 200 can provide a final partially improved transaction identifier value, such as regarding... Figure 4 and Figure 5 In this case, device 200 does not provide the verification code to be included in the partially improved transaction identifier 150.
[0264] 3. Generator 300 determines a transaction mapping identifier 174 to be used to generate the partially improved transaction identifier 150 – this can be done using an algorithm, and / or can be selected from one of the improved transaction identifier counters in generator storage device 230. Using the determined transaction mapping identifier 174 and routing information 160, generator 300 on device 200 generates the partially improved transaction identifier 150. Optionally, context information 190 regarding the generation of the improved transaction identifier may be included.
[0265] 4. After use, device 200 can delete the improved transaction identifier key and transaction mapping identifier 174 (improved transaction identifier counter content) from generator storage device 230.
[0266] The partially improved transaction identifier 150 is stored in the partially improved transaction identifier storage device 220.
[0267] Device 200 delivers a portion of the modified transaction identifier 150 as an improved transaction identifier from the improved transaction identifier storage device 220 to the electronic transaction acceptance environment 500, as described above for the fully modified transaction identifier 150. Figure 4 and Figure 5 However, in this case, device 200 also provides an improved transaction identifier encryption key associated with 970.
[0268] 5. The acquirer 520 is requested to authorize the improved transaction identifier 950, which includes a portion of the improved transaction identifier 150. Additionally, in this case, the electronic transaction acceptance environment 500 also provides the acquirer 520 with the encryption key for the improved transaction identifier associated with 950.
[0269] 6. Use the acquirer 520's processor to begin processing the electronic payment transaction.
[0270] 7. Use the acquirer's 520 processor to begin the verification (authentication) of the electronic payment transaction.
[0271] 8. The processor of acquirer 520 invokes authenticator 600 by providing an improved transaction identifier containing a portion of the improved transaction identifier 150. Authenticator 600 extracts the portion of the improved transaction identifier 150 from the improved transaction identifier and verifies the portion of the improved transaction identifier 150.
[0272] 9. The authenticator 600 provides the valid partial modified transaction identifier 150 to the CAPTCHA generator 320 on the server, and the CAPTCHA generator 320 generates verification information 180 including CAPTCHA 184 - in this case, the DSRP password.
[0273] 10. The authenticator 600 returns verification information 180 (here, the DSRP password as verification code 184) to the acquirer 520. Optionally, context information 190 may also be provided.
[0274] Optionally, the acquirer 520's processor can re-verify (re-authenticate) the verification code (DSRP password).
[0275] 11. The acquirer 520 processes this information to verify the DSRP password and authorize the electronic transaction (which may optionally require communication with the issuer).
[0276] 12. After completing the authorization process, prepare the authorization response.
[0277] 13. Authorization response 560 is sent back to the electronic transaction acceptance environment 500.
[0278] 14. As mentioned above Figure 4 and Figure 5 As stated, acquirers and merchants can retain relevant information about electronic transactions.
[0279] Similarly, Figure 6 The device 200 shown can also be configured and arranged to include a verification code 184 generator 320, such as Figure 5 As shown in the diagram. In this case, a fully improved transaction identifier 150 can be generated. Device 200 is also configured and arranged as follows: - Enables the CAPTCHA 184 generator to communicate with the improved transaction identifier generator 300; - Enables the improved transaction identifier generator 300 to associate the transaction mapping identifier 174 and other data from the improved transaction identifier with the verification code 184 to generate one or more improved transaction identifiers 150; - Use identifier generator 300 to generate one of a large number of improved transaction identifiers 150, the generated identifiers including: verification information 180 including the generated verification code 184; one or more transaction mapping identifiers 174 used to generate the verification code 184; and routing information 160 from the issuer.
[0280] The device 200 also includes one or more storage registers for the transaction mapping identifier 174, and the device 200 is also configured and arranged for offline use; The method also includes: - Receive one or more transaction mapping identifiers 174 from the issuer and store the one or more identifiers 174 in the one or more storage registers 230; - Receive routing information 160 from the issuer; and - Generate a verification code 184 associated with one of the transaction mapping identifiers 174 from storage register 230.
[0281] When device 200 is online, it can receive one or more transaction mapping identifiers 174 and store them in one or more storage registers 230, and when offline, use these identifiers 174 to generate improved transaction identifiers. Alternatively or additionally, one or more storage registers 230 can be configured as one or more improved transaction identifier counters, thereby enabling offline generation of transaction mapping identifiers 174 and other relevant portions of improved transaction identifiers 150 on device 200. Periodic synchronization with the issuer of improved transaction identifiers 150 may be required to ensure that device 200 parameters and data are up-to-date and valid.
[0282] The term “processor” as used herein and in the appended claims should be understood to include a single processor or two or more processors communicating with each other.
[0283] In one or more places within the described method, the user may use any appropriate authentication: - PIN (Personal Identification Number) entered on device 200 - Biometric parameters or identification detected or read by device 200 - Locally verified CDCVM (Consumer Device Cardholder Verification Method) - Any other method of authenticating users, such as mobile PIN supported when using MCBP (Mastercard Cloud Payment). For example, authentication may be required to generate improved transaction identifiers, generate CAPTCHAs, provide representations 350, 351, 352, initiate electronic transactions, or any combination thereof. Authentication can be used to access generators (on a server and / or on a device) and / or DSRP generators (on a server) and / or devices.
[0284] Routing information 160 can be configured to allow the use of network identifier 162 to identify the owner of the processing network. This owner can allocate a portion of the ISO / IEC 7812 scope, used only for issuing the Improved Transaction Identifier 150. The value of this scope can be identified (and routed) using routing information 160 – network identifier 162 and Improved Transaction Identifier indicator 164.
[0285] Generally, a server configured to provide multiple appropriate services may include: - Supports inbound API requests 250 from device 200 to generate and provide 260 or more improved transaction identifiers 150. - Supports generating DSRP-related data, including DSRP passwords; - Supports outbound API protocols to contact device 200 for additional authentication (e.g., in the case of high-value transactions when device 200 or the user does not provide CDCVM (Consumer Device Cardholder Verification Method)). The flowcharts and descriptions herein should not be construed as specifying a fixed order in which the method steps described herein are performed. Rather, the method steps can be performed in any feasible order. Similarly, the examples used to explain the methods and apparatus are not intended to represent the only implementation of these methods and apparatus—those skilled in the art will be able to conceive of many different ways to achieve the same functionality provided by the embodiments described herein.
[0286] Although the invention has been described in conjunction with specific exemplary embodiments, it should be understood that various changes, substitutions, and modifications that are obvious to those skilled in the art may be made to the disclosed embodiments without departing from the spirit and scope of the invention as defined in the appended claims.
[0287] Figure Labels
[0288] 100 Improved methods for generating transaction identifiers
[0289] 150 Improved Transaction Identifiers
[0290] 160 Routing Information
[0291] 162 Network Identifier
[0292] 164 Improved Transaction Identifier Indicator
[0293] 170 Mapping Information
[0294] 172 Mapping server identifier
[0295] 174 Transaction Mapping Identifier
[0296] 176 User Identifier
[0297] 180 Verification Message
[0298] 182 Transaction Pattern Identifier
[0299] 184 verification code
[0300] 190 Contextual Information
[0301] 200 mobile devices
[0302] 210 Users, such as consumers
[0303] 220 Improved Transaction Identifier Storage Device
[0304] 230 Generator storage device
[0305] 250 Improved Transaction Identifier Generation Request
[0306] 260 Improved Transaction Identifier Generation Response
[0307] 270 Provides improved data representation of transaction identifiers.
[0308] 290 Provides improved transaction identifiers
[0309] 300 Improved Transaction Identifier Generator
[0310] 320 CAPTCHA Generator
[0311] 350 as an improved transaction identifier for QR codes
[0312] 351 as an improved transaction identifier representation of 1D barcodes
[0313] 351 as an improved transaction identifier representation of 1D barcodes
[0314] 400 Electronic payment transaction methods using improved transaction identifiers
[0315] 500 Electronic Transaction Acceptance Environment
[0316] 520 Order Collector
[0317] 540 POI
[0318] 550 Authentication Request
[0319] 560 Authentication Response
[0320] 600 Improved Transaction Identifier Authenticator - Operated as a Server by the Authenticator (Issuer)
[0321] 700 Examples of electronic payment transaction methods using improved transaction identifiers
[0322] 710 Authentication from Device to Server
[0323] Additional improved transaction identifier information provided by 720
[0324] 730 acquirers invoke authenticators by providing improved transaction identifiers.
[0325] The 740 authenticator requests additional authentication from the device.
[0326] The 750 authenticator returns verification information to the acquirer.
[0327] 800 Examples of electronic payment transaction methods using improved transaction identifiers
[0328] 900 Examples of electronic payment transaction methods using improved transaction identifiers
[0329] 950 Improved Transaction Identifier Authentication Request with Encryption Key
[0330] 970 provides a data representation (for improved transaction identifiers) and associated cryptographic keys.
Claims
1. A computer-implemented electronic transaction method (400), comprising: - The user (210) obtains a serial number (174) that is not directly associated with the user (210); - The user (210) provides (270) a transaction identifier (150) to the electronic transaction acceptance environment (500) to initiate an electronic transaction, the transaction identifier (150) including: - Route identifier (160); - The serial number (174) that is not directly associated with the user (210); - Context information (190) including one or more parameters associated with the generation of the transaction identifier (150); - Verification information (180) containing a value determined using the serial number (174) and context information (190); The method further includes: - The electronic transaction acceptance environment (500) uses the routing identifier (160) to transmit (550) the transaction identifier (150) to the authenticator (600); - The authenticator (600) uses the verification information (180), serial number (174), and context information (190) to authenticate (560) the transaction identifier (150); and - If the transaction identifier (150) is deemed genuine, the initiation of the electronic transaction is permitted. The context information (190) is used to convey to the authenticator (600) any of the following data: - The generation of the corresponding transaction identifier (150), the generation of any verification information (180) contained in the corresponding transaction identifier (150), the algorithm for generating the corresponding transaction identifier (150), the hardware for generating the corresponding transaction identifier (150), the software for generating the corresponding transaction identifier (150), or any combination thereof.
2. The method according to claim 1, wherein the method (400) further comprises: - The user (210) provides the transaction identifier generator (300) with an early-available serial number (174) and / or an early-available transaction identifier (150); and - The user (210) obtains the serial number (174) and / or transaction identifier (150) from the transaction identifier generator (300).
3. The method according to claim 1 or 2, wherein the method (400) further comprises: - The user (210) obtains an additional serial number (174) and / or an additional transaction identifier (150), and the user (210) then uses the additional serial number (174) and / or the additional transaction identifier (150) to initiate another electronic transaction.
4. The method according to claim 1 or 2, wherein the method further comprises: - The user (210) obtains the transaction identifier generator (300); as well as - Use the transaction identifier generator (300) to generate one or more serial numbers (174) and / or one or more transaction identifiers (150) for subsequently initiating one or more electronic transactions.
5. The method according to claim 4, wherein the method further comprises: - Use the transaction identifier generator (300) to generate verification information (180) suitable for inclusion in one or more transaction identifiers (150).
6. The method according to claim 1 or 2, wherein the method (400) further comprises: This indirectly associates the serial number (174) with the user (210).
7. The method according to claim 6, wherein the indirect association is achieved by: - Publish the serial number (174) and / or transaction identifier (150) to the user (210); - Make the serial number (174) and / or transaction identifier (150) available to the user (210) for use in one or more financial transactions; - After the user (210) uses it in a financial transaction, the authenticator (600) accepts the transaction identifier (150) for authentication; - After the user (210) uses it in a financial transaction, the transaction identifier (150) is authenticated by the authenticator (600) for authentication; And any combination thereof.
8. The method according to claim 1 or 2, wherein: - The electronic transaction acceptance environment (500) is configured and arranged to process the transaction identifier (150) into a standard-compliant transaction identifier; - The transaction identifier (150) is compliant with standards; - The routing identifier (160) is compliant with standards; and The standard is ISO-7812, EMV, or any combination thereof.
9. The method according to claim 8, wherein: - The serial number (174) and / or verification information (180) do not conform to the standard.
10. The method according to claim 1 or 2, wherein: - The transaction identifier (150) is similar to the main account (PAN).
11. The method according to claim 1 or 2, wherein: - The transaction identifier (150) includes the Luhn check bit.
12. The method according to claim 1 or 2, wherein: - The electronic transaction acceptance environment (500) includes a POI with a processor programmed to receive the transaction identifier (150) and forward (290) the transaction identifier (150); The method (400) further includes: - The user (210) provides the transaction identifier (150) to the POI (540) directly or through an intermediary to initiate an electronic transaction.
13. The method according to claim 1 or 2, further comprising: - After the electronic transaction is initiated using the transaction identifier (150), or after the authenticator (600) allows the initiation of the electronic transaction, the serial number (174) and / or the transaction identifier (150) shall be made unavailable for subsequent use.
14. The method according to claim 1 or 2, further comprising: - After the electronic transaction is initiated using the transaction identifier (150), or after the authenticator (600) allows the initiation of the electronic transaction, the serial number (174) and / or the transaction identifier (150) shall be made available for subsequent use.
15. The method according to claim 1 or 2, wherein the transaction identifier (150) is provided as a non-alphanumeric representation (350, 351) to the electronic transaction acceptance environment (500).
16. The method according to claim 1 or 2, wherein the transaction identifier (150) is no more than 19 bits.
17. The method according to claim 1 or 2, wherein the transaction identifier (150) is no more than 18 bits.
18. The method according to claim 1 or 2, wherein the transaction identifier (150) is no more than 17 bits.
19. The method according to claim 1 or 2, wherein the transaction identifier (150) is no more than 16 bits.
20. The method according to claim 1 or 2, wherein the serial number (174) does not exceed 9 digits.
21. The method according to claim 1 or 2, wherein the serial number (174) does not exceed 8 digits.
22. The method according to claim 1 or 2, wherein the serial number (174) does not exceed 7 digits.
23. The method according to claim 1 or 2, wherein the method further comprises: - After the authenticator (600) receives the transaction identifier (150), it evaluates one or more parameters associated with the generation and / or use of the transaction identifier (150) in the electronic transaction; as well as - If one or more of the parameters are assessed as acceptable, the initiation of the electronic transaction is permitted.
24. The method according to claim 23, wherein the transaction identifier (150) includes a pattern identifier (182) for conveying to the authenticator (600) one or more parameters regarding: - The use of a server to generate one or more values in the corresponding transaction identifier (150); - Use of a user device (200) to generate one or more values in the corresponding transaction identifier (150); - Use of user authentication prior to the generation of one or more values in the corresponding transaction identifier (150); - The amount used to generate the verification information (180); - Use of the storage register (230) for the corresponding transaction identifier (150); And any combination thereof.
25. The method according to claim 1 or 2, wherein the transaction identifier (150) comprises: - A network identifier (162) associated with the authenticator (600); - Generator identifier associated with the generator of the transaction identifier (150); - A processing indicator (164) for influencing how the authenticator (600) processes the transaction identifier (150); - A mapped server identifier (172) used to indicate to the authenticator (600) the server to be authenticated; And any combination thereof.
26. A device (200) associated with a user (210) and configured and arranged to initiate an electronic transaction according to any of the preceding claims, the device comprising: - Storage registers are used to store one or more transaction identifiers (150) and make them available for use in one or more electronic transactions.
27. A device (200) associated with a user (210) and configured and arranged to initiate an electronic transaction according to any of the preceding claims, the device (200) comprising: - Identifier generator (300) for generating one or more serial numbers (174) and / or one or more transaction identifiers (150) and making them available for use in financial transactions.
Citation Information
Patent Citations
Payment method using one-time card information
US20140258135A1
Personal security system
US5361062A
Provisioning account numbers and cryptographic tokens
US9741036B1
One-time credit card number generator and single round-trip authentication
WO2003038719A1