Systems, methods, and computer program products for authenticating transactions based on behavioral biometric data

By using a behavioral biometrics data authentication system, which analyzes user behavior data using a behavioral biometrics server computer, the system solves the problems of difficult identity verification and wasted computing resources in existing transaction systems, and achieves more efficient transaction authentication and fraud prevention.

CN114245889BActive Publication Date: 2026-01-27VISA INTERNATIONAL SERVICE ASSOCIATION
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202080055268.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-09-10
Filing Date
2020-08-07
Publication Date
2026-01-27
Estimated Expiration
2040-08-07

AI Technical Summary

Technical Problem

Existing transaction systems struggle to effectively verify user identities, leading to fraudulent transactions. This is especially true when payment devices are lost, as user identities cannot be easily verified, increasing the likelihood of fraudulent transactions. Furthermore, the systems incur excessive computational resource and time overhead when processing transactions.

Method used

The behavioral biometrics data authentication system uses a behavioral biometrics server computer to collect and analyze user behavioral data, generate authenticity assessment responses, and use them to authenticate or reject transactions. This is combined with the authentication process of the merchant and issuer systems, reducing unnecessary computing resources and communication.

Benefits of technology

It improves the accuracy of transaction verification, reduces the occurrence of fraudulent transactions, saves computing resources and communication bandwidth, and improves the efficiency of transaction processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114245889B_ABST
    Figure CN114245889B_ABST
Patent Text Reader

Abstract

A system, method, and computer program product for authenticating a transaction based on behavioral biometric data are provided. The method includes receiving an authorization request message associated with a transaction between a merchant system and a payment device. The method also includes determining, based on transaction data, that an additional security authentication should be applied to the authorization request message. The method further includes transmitting a liveness assessment request to a behavioral biometric server computer and receiving, from the behavioral biometric server computer, a liveness assessment response generated based on at least a portion of the transaction data. The method also includes generating, based on the liveness assessment response, an authentication response message configured to authenticate or decline the transaction.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-referencing related applications

[0002] This application claims priority to U.S. Provisional Patent Application No. 62 / 884,069, filed August 7, 2019, and U.S. Provisional Patent Application No. 62 / 898,200, filed September 10, 2019, the entire disclosure of which is incorporated herein by reference. Technical Field

[0003] This disclosure generally relates to authentication, and in one particular non-limiting embodiment, to a system, method, and computer program product for authenticating transactions based on behavioral biometric data. Background Technology

[0004] A transaction may involve one or more users (who possess one or more payment devices) and one or more merchants. For example, one or more users may initiate a transaction online, such as via a webpage, at a point-of-sale terminal. During such transactions, the validity of the transaction initiated using the payment device can be verified by requesting a Card Verification Value (CVV) and / or similar information. However, requesting such additional information may not enable the system processing such transactions to verify the identity of the user possessing the payment device.

[0005] If an individual's identity is not easily obtained, it can increase the likelihood of fraudulent transactions. For example, if a payment device is lost and another user unrelated to the device attempts to use it, a fraudulent transaction could be initiated by the individual attempting to use the device. To address this, the system may also review transactions to determine their fraudulent nature, incurring additional overhead in computing resources and / or processing time. This can then affect subsequent transactions and, depending on transaction volume, may cause transactions that would otherwise be approved to be rejected. Summary of the Invention

[0006] Therefore, and generally, systems, methods, and computer program products are provided for the improved computer implementation of transactions based on behavioral biometric data that overcome some or all of the defects.

[0007] According to some non-limiting embodiments or aspects, a computer-implemented method for authenticating transactions based on behavioral biometric data is provided. The method includes receiving, using a transaction service provider system including at least one processor, an authorization request message associated with a transaction between a merchant system and a payment device. The authorization request message includes transaction data. The method includes using the at least one processor to determine, based on the transaction data, that additional security authentication should be applied to the authorization request message. The method further includes, in response to determining that the additional security authentication should be applied, transmitting an authenticity assessment request to a behavioral biometric server computer using the at least one processor, the authenticity assessment request including at least a portion of the transaction data. The method further includes, in response to the authenticity assessment request and based on the at least a portion of the transaction data, receiving, using the at least one processor, an authenticity assessment response generated by the behavioral biometric server computer. The method further includes using the at least one processor to generate an authentication response message configured to authenticate or reject the transaction based on the authenticity assessment response.

[0008] In another non-limiting embodiment or aspect, the authorization request message may be initiated by a user of the payment device via a merchant webpage or mobile application. While the user is responding to a second-factor authentication process on the merchant webpage or in the mobile application, the authenticity assessment request may be transmitted to the behavioral biometrics server computer. The method may include embedding behavioral biometric services into the merchant webpage or the mobile application based on a first URL and a second URL, wherein the first URL points to a domain of the issuing system and the second URL points to a domain of the behavioral biometrics server computer. The method may include, in response to the authenticity assessment response indicating that the user and / or the payment device lacks authenticity, transmitting an alert to at least one of the merchant webpage, the mobile application, and the issuing system.

[0009] In another non-limiting embodiment or aspect, the method may include using the at least one processor to transmit the authentication response message to an issuer system associated with the issuer of the payment device. The authentication response message may be configured to authenticate or reject the transaction when evaluated by the issuer system in conjunction with the user's response to the second factor authentication process.

[0010] In another non-limiting embodiment or aspect, the authentication assessment response may be based on behavioral biometric signals associated with the payment device and / or the user, which are collected by the behavioral biometric server computer in a separate communication channel to the transaction processing network of the transaction service provider system prior to initiating the transaction.

[0011] In another non-limiting embodiment or aspect, the method may include configuring the authentication response message to authenticate or reject the transaction based on a comparison of the authenticity assessment response with a predetermined threshold provided by the merchant system.

[0012] According to a non-limiting embodiment or aspect, a system for authenticating transactions based on behavioral biometric data is provided. The system includes at least one server computer, the at least one server computer including at least one processor. The at least one server computer is programmed and / or configured to receive an authorization request message associated with a transaction between the merchant system and a payment device. The authorization request message includes transaction data. The server computer is programmed and / or configured to determine, based on the transaction data, that additional security authentication should be applied to the authorization request message. The server computer is programmed and / or configured to, in response to determining that the additional security authentication should be applied, transmit an authenticity assessment request to the behavioral biometric server computer. The authenticity assessment request includes at least a portion of the transaction data. The server computer is programmed and / or configured to, in response to the authenticity assessment request and based on the at least a portion of the transaction data, receive from the behavioral biometric server computer an authenticity assessment response generated by the behavioral biometric server computer. The server computer is programmed and / or configured to, based on the authenticity assessment response, generate an authentication response message configured to authenticate or reject the transaction.

[0013] In another non-limiting embodiment or aspect, the authorization request message may be initiated by a user of the payment device via a merchant webpage or mobile application. While the user is responding to a second-factor authentication process on the merchant webpage or in the mobile application, the authenticity assessment request may be transmitted to the behavioral biometrics server computer. The server computer may also be programmed and / or configured to embed behavioral biometrics services into the merchant webpage or the mobile application based on a first URL and a second URL. The first URL may point to a domain of the issuing system, and the second URL may point to a domain of the behavioral biometrics server computer. The server computer may also be programmed and / or configured to, in response to the authenticity assessment response indicating that the user and / or the payment device lacks authenticity, transmit an alert to at least one of the merchant webpage, the mobile application, and the issuing system.

[0014] In another non-limiting embodiment or aspect, the server computer may also be programmed and / or configured to transmit the authentication response message to an issuing system associated with the issuer of the payment device. The authentication response message may be configured to authenticate or reject the transaction when evaluated by the issuing system in conjunction with the user's response to the second factor authentication process.

[0015] In another non-limiting embodiment or aspect, the authentication assessment response may be based on behavioral biometric signals associated with the payment device and / or the user, which are collected by the behavioral biometric server computer in a separate communication channel to the transaction processing network of the server computer prior to initiating the transaction.

[0016] In another non-limiting embodiment or aspect, the server computer may also be programmed and / or configured to configure the authentication response message to authenticate or reject the transaction based on a comparison of the authenticity assessment response with a predetermined threshold provided by the merchant system.

[0017] According to some non-limiting embodiments or aspects, a computer program product for authenticating transactions based on behavioral biometric data is provided. The computer program product includes at least one non-transitory computer-readable medium comprising program instructions that, when executed by at least one processor, cause the at least one processor to receive an authorization request message associated with a transaction between a merchant system and a payment device. The authorization request message includes transaction data. The program instructions cause the at least one processor to determine, based on the transaction data, that additional security authentication should be applied to the authorization request message. The program instructions cause the at least one processor, in response to determining that the additional security authentication should be applied, to transmit an authenticity assessment request to a behavioral biometric server computer. The authenticity assessment request includes at least a portion of the transaction data. The program instructions cause the at least one processor, in response to the authenticity assessment request and based on the at least a portion of the transaction data, to receive an authenticity assessment response generated by the behavioral biometric server computer. The program instructions cause the at least one processor to generate an authentication response message configured to authenticate or reject the transaction based on the authenticity assessment response.

[0018] In another non-limiting embodiment or aspect, the authorization request message may be initiated by a user of the payment device via a merchant webpage or mobile application. While the user is responding to a second-factor authentication process on the merchant webpage or in the mobile application, the authenticity assessment request may be transmitted to the behavioral biometrics server computer. The program instructions may cause the at least one processor to embed the behavioral biometrics service into the merchant webpage or the mobile application based on a first URL and a second URL. The first URL may point to a domain of the issuing system, and the second URL may point to a domain of the behavioral biometrics server computer. The program instructions may cause the at least one processor, in response to the authenticity assessment response indicating that the user and / or the payment device lacks authenticity, to transmit an alert to at least one of the merchant webpage, the mobile application, and the issuing system.

[0019] In another non-limiting embodiment or aspect, the program instructions may cause the at least one processor to transmit the authentication response message to an issuing system associated with the issuer of the payment device. The authentication response message may be configured to authenticate or reject the transaction when evaluated by the issuing system in conjunction with the user's response to the second factor authentication process.

[0020] In another non-limiting embodiment or aspect, the authentication assessment response may be based on behavioral biometric signals associated with the payment device and / or the user, which are collected by the behavioral biometric server computer in a separate communication channel to the transaction processing network of the server computer prior to initiating the transaction.

[0021] According to a non-limiting embodiment or aspect, a computer-implemented method for authenticating transactions based on behavioral biometric data is provided. The computer-implemented method includes storing behavioral biometric data using at least one processor of a behavioral biometric server computer, the behavioral biometric data including at least one of: transaction data associated with multiple transactions between at least one merchant and at least one payment device; activity data associated with at least one user of the at least one payment device; or any combination thereof. The method further includes receiving, using the at least one processor, an authenticity assessment request including at least a portion of the transaction data during transaction processing at a transaction service provider system. The method further includes generating an authenticity assessment based on the at least a portion of the transaction data using the at least one processor, utilizing a behavioral biometric model and the stored behavioral biometric data. The method further includes transmitting an authenticity assessment response, including at least a portion of the authenticity assessment, to the transaction service provider system using the at least one processor, the authenticity assessment response being configured to cause the transaction service provider to authenticate or reject the transaction.

[0022] Other embodiments or aspects are described in the following numbered clauses.

[0023] Clause 1: A computer-implemented method includes: receiving, using a transaction service provider system including at least one processor, an authorization request message associated with a transaction between a merchant system and a payment device, the authorization request message including transaction data; determining, using the at least one processor, based on the transaction data, that additional security authentication should be applied to the authorization request message; in response to determining that the additional security authentication should be applied, transmitting an authenticity assessment request to a behavioral biometrics server computer using the at least one processor, the authenticity assessment request including at least a portion of the transaction data; in response to the authenticity assessment request and based on the at least a portion of the transaction data, receiving, using the at least one processor, an authenticity assessment response generated by the behavioral biometrics server computer; and generating, using the at least one processor, an authentication response message configured to authenticate or reject the transaction based on the authenticity assessment response.

[0024] Clause 2: The computer-implemented method according to Clause 1, wherein the authorization request message is initiated by a user of the payment device via a merchant webpage or mobile application, and wherein the authenticity assessment request is transmitted to the behavioral biometric server computer while the user is responding to a second-factor authentication process in the merchant webpage or the mobile application.

[0025] Clause 3: The computer-implemented method according to Clause 1 or 2 further includes embedding the behavioral biometrics service into the merchant's webpage or the mobile application based on a first URL and a second URL, wherein the first URL points to a domain of the issuer's system and the second URL points to a domain of the behavioral biometrics server computer.

[0026] Clause 4: The computer-implemented method according to any one of Clauses 1 to 3 further includes, in response to the authenticity assessment response indicating that the user and / or the payment device lacks authenticity, transmitting an alert to at least one of the merchant webpage, the mobile application, and the issuer system.

[0027] Clause 5: The computer-implemented method according to any one of Clauses 1 to 4 further includes using the at least one processor to transmit the authentication response message to an issuer system associated with the issuer of the payment device, the authentication response message being configured to authenticate or reject the transaction when evaluated by the issuer system in conjunction with the user's response to the second factor authentication process.

[0028] Clause 6: A computer-implemented method according to any one of Clauses 1 to 5, wherein the authentication assessment response is based on behavioral biometric signals associated with the payment device and / or the user, the behavioral biometric signals being collected by the behavioral biometric server computer in a separate communication channel to the transaction processing network of the transaction service provider system prior to initiating the transaction.

[0029] Clause 7: The computer-implemented method according to any one of Clauses 1 to 6 further includes configuring the authentication response message to authenticate or reject the transaction based on a comparison of the authenticity assessment response with a predetermined threshold provided by the merchant system.

[0030] Clause 8: A system including at least one server computer, the at least one server computer including at least one processor, the at least one server computer being programmed and / or configured to: receive an authorization request message associated with a transaction between a merchant system and a payment device, the authorization request message including transaction data; determine, based on the transaction data, that additional security authentication should be applied to the authorization request message; in response to determining that the additional security authentication should be applied, transmit an authenticity assessment request to a behavioral biometric server computer, the authenticity assessment request including at least a portion of the transaction data; in response to the authenticity assessment request and based on the at least a portion of the transaction data, receive an authenticity assessment response generated by the behavioral biometric server computer; and generate, based on the authenticity assessment response, an authentication response message configured to authenticate or reject the transaction.

[0031] Clause 9: In the system described in Clause 8, the authorization request message is initiated by the user of the payment device through a merchant webpage or mobile application, and the authenticity assessment request is transmitted to the behavioral biometric server computer while the user is responding to a second-factor authentication process in the merchant webpage or the mobile application.

[0032] Clause 10: The system according to Clause 8 or 9, wherein the server computer is further programmed and / or configured to embed the behavioral biometrics service into the merchant webpage or the mobile application based on a first URL and a second URL, wherein the first URL points to a domain of the issuer system and the second URL points to a domain of the behavioral biometrics server computer.

[0033] Clause 11: The system pursuant to any one of Clauses 8 to 10, wherein the server computer is further programmed and / or configured to, in response to the authenticity assessment response indicating that the user and / or the payment device lacks authenticity, transmit an alert to at least one of the merchant webpage, the mobile application, and the issuer system.

[0034] Clause 12: The system according to any one of Clauses 8 to 11, wherein the server computer is further programmed and / or configured to transmit the authentication response message to an issuer system associated with the issuer of the payment device, the authentication response message being configured to authenticate or reject the transaction when evaluated by the issuer system in conjunction with the user's response to the second factor authentication process.

[0035] Clause 13: The system according to any one of Clauses 8-12, wherein the authentication assessment response is based on behavioral biometric signals associated with the payment device and / or the user, the behavioral biometric signals being collected by the behavioral biometric server computer in a separate communication channel to the transaction processing network of the server computer prior to initiating the transaction.

[0036] Clause 14: The system according to any one of Clauses 8 to 13, wherein the server computer is further programmed and / or configured to configure the authentication response message to authenticate or reject the transaction based on a comparison of the authenticity assessment response with a predetermined threshold provided by the merchant system.

[0037] Clause 15: A computer program product comprising at least one non-transitory computer-readable medium, the at least one non-transitory computer-readable medium comprising program instructions that, when executed by at least one processor, cause the at least one processor to: receive an authorization request message associated with a transaction between a merchant system and a payment device, the authorization request message including transaction data; determine, based on the transaction data, that additional security authentication should be applied to the authorization request message; in response to determining that the additional security authentication should be applied, transmit an authenticity assessment request to a behavioral biometric server computer, the authenticity assessment request including at least a portion of the transaction data; in response to the authenticity assessment request and based on the at least a portion of the transaction data, receive from the behavioral biometric server computer an authenticity assessment response generated by the behavioral biometric server computer; and generate, based on the authenticity assessment response, an authentication response message configured to authenticate or reject the transaction.

[0038] Clause 16: The computer program product according to Clause 15, wherein the authorization request message is initiated by the user of the payment device through a merchant webpage or mobile application, and wherein the authenticity assessment request is transmitted to the behavioral biometric server computer while the user is responding to a second-factor authentication process in the merchant webpage or the mobile application.

[0039] Clause 17: A computer program product pursuant to Clause 15 or 16, wherein the program instructions further cause the at least one processor to embed the behavioral biometrics service into the merchant webpage or the mobile application based on a first URL and a second URL, wherein the first URL points to a domain of the issuer system and the second URL points to a domain of the behavioral biometrics server computer.

[0040] Clause 18: A computer program product pursuant to any one of Clauses 15 to 17, wherein the program instructions further cause the at least one processor to transmit an alert to at least one of the merchant webpage, the mobile application, and the issuing system in response to the authenticity assessment response indicating that the user and / or the payment device lacks authenticity.

[0041] Clause 19: A computer program product according to any one of Clauses 15 to 18, wherein the program instructions further cause the at least one processor to transmit the authentication response message to an issuer system associated with the issuer of the payment device, the authentication response message being configured to authenticate or reject the transaction when evaluated by the issuer system in conjunction with the user's response to the second factor authentication process.

[0042] Clause 20: A computer program product according to any one of Clauses 15 to 19, wherein the authentication assessment response is based on behavioral biometric signals associated with the payment device and / or the user, the behavioral biometric signals being collected by the behavioral biometric server computer in a separate communication channel to the transaction processing network of the server computer prior to initiating the transaction.

[0043] Clause 21: A computer-implemented method comprising: storing behavioral biometric data using at least one processor of a behavioral biometric server computer, the behavioral biometric data including at least one of: transaction data associated with a plurality of transactions between at least one merchant and at least one payment device, activity data associated with at least one user of the at least one payment device, or any combination thereof; during transaction processing at a transaction service provider system: receiving, using the at least one processor, an authenticity assessment request including at least a portion of the transaction data; generating an authenticity assessment based on the at least a portion of the transaction data using the at least one processor, employing a behavioral biometric model and the stored behavioral biometric data; and transmitting, using the at least one processor, an authenticity assessment response including at least a portion of the authenticity assessment to the transaction service provider system, the authenticity assessment response being configured to cause the transaction service provider to authenticate or reject the transaction.

[0044] The features and characteristics of this disclosure, as well as the operational methods and functions of combinations of related structural elements and parts, and the economics of manufacture, will become more apparent when considered in conjunction with the accompanying drawings, all of which form part of this specification, wherein similar reference numerals in the drawings denote corresponding parts. However, it should be clearly understood that the drawings are for illustrative and descriptive purposes only and are not intended to be construed as limiting the scope of this disclosure. Unless the context clearly requires otherwise, the singular forms “a” and “described” as used in this specification and claims include plural indicators. Attached Figure Description

[0045] Additional advantages and details of this disclosure are explained in more detail below with reference to exemplary embodiments illustrated in the accompanying drawings, in which:

[0046] Figure 1 These are illustrations of non-limiting embodiments of environments in which the systems, devices, and / or methods described herein may be implemented;

[0047] Figure 2 This is a flowchart illustrating a non-limiting embodiment of a method for authenticating transactions based on behavioral biometric data, in accordance with the principles of this disclosure;

[0048] Figure 3 This is a flowchart illustrating a non-limiting embodiment of a method for authenticating transactions based on behavioral biometric data, according to the principles of this disclosure; and

[0049] Figure 4 yes Figure 1 Illustrations of non-limiting embodiments of components of one or more devices. Detailed Implementation

[0050] For descriptive purposes, the terms “end,” “upper,” “lower,” “right,” “left,” “vertical,” “horizontal,” “top,” “bottom,” “lateral,” “longitudinal,” and their derivatives are intended to refer to the orientation of this disclosure as shown in the accompanying drawings. However, it should be understood that this disclosure may take various alternative variations and sequences of steps, except where explicitly specified otherwise. It should also be understood that the specific apparatus and processes illustrated in the drawings and described in the following description are merely exemplary embodiments or aspects of this disclosure. Therefore, unless otherwise indicated, specific dimensions and other physical characteristics associated with the embodiments or aspects of the embodiments disclosed herein should not be considered limiting.

[0051] The terms "aspect," "component," "element," "structure," "action," "step," "function," and "instruction" used herein should not be construed as critical or essential unless explicitly stated otherwise. Furthermore, as used herein, the article "a" is intended to include one or more items and may be used interchangeably with "one or more" and "at least one." Additionally, as used herein, the term "set" is intended to include one or more items (e.g., related items, unrelated items, a combination of related and unrelated items, etc.) and may be used interchangeably with "one or more" or "at least one." Where only one item is desired, the term "a" or similar language is used. Also, as used herein, the terms "having" and similar expressions are intended to be open-ended terms. Furthermore, unless explicitly stated otherwise, the phrase "based on" is intended to mean "at least partially based on."

[0052] As used herein, the terms "communication" and "transmission" can refer to the receipt, acceptance, transmission, delivery, provision, etc., of information (e.g., data, signals, messages, instructions, commands, etc.). Communication between one unit (e.g., apparatus, system, component of an apparatus or system, combination thereof, etc.) and another unit means that the first unit is able to receive information directly or indirectly from and / or send (e.g., transmit) information to the other unit. This can refer to a direct or indirect connection that is inherently wired and / or wireless. Furthermore, the two units can communicate with each other even if the transmitted information may be modified, processed, relayed, and / or routed between the first and second units. For example, the first unit can communicate with the second unit even if it passively receives information and does not actively send information to the second unit. As another example, the first unit can communicate with the second unit if at least one intermediate unit (e.g., a third unit located between the first and second units) processes information received from the first unit and sends the processed information to the second unit. In some non-limiting embodiments or aspects, a message can refer to a network packet (e.g., a data packet, etc.) that includes data.

[0053] As used herein, the terms “issuer,” “issuer institution,” “issuer bank,” or “payment device issuer” can refer to one or more entities that provide accounts for individuals (e.g., users, customers, etc.) to conduct payment transactions such as credit card payment transactions and / or debit card payment transactions. For example, an issuer institution may provide a customer with an account identifier, such as a primary account number (PAN), that uniquely identifies one or more accounts associated with said customer. In some non-limiting embodiments or aspects, an issuer may be associated with a bank identification number (BIN) that uniquely identifies an issuer institution. As used herein, “issuer system” can refer to one or more computer systems operated by or on behalf of an issuer, such as a server executing one or more software applications. For example, an issuer system may include one or more authorization servers for authorizing transactions.

[0054] As used herein, the term "account identifier" can include one or more types of identifiers associated with an account (e.g., a PAN associated with an account, a card number associated with an account, a payment card number associated with an account, a token associated with an account, etc.). In some non-limiting embodiments or aspects, the issuer may provide an account identifier (e.g., a PAN, a token, etc.) to a user (e.g., an account holder) that uniquely identifies one or more accounts associated with that user. The account identifier may be embodied in a payment device (e.g., a physical instrument for making payment transactions, such as a payment card, credit card, debit card, gift card, etc.) and / or may be electronic information transmitted to a user that the user can use for electronic payment transactions. In some non-limiting embodiments or aspects, the account identifier may be an original account identifier, wherein the original account identifier is provided to the user when an account associated with the account identifier is created. In some non-limiting embodiments or aspects, the account identifier may be a supplementary account identifier, which may include an account identifier provided to the user after the original account identifier has been provided to the user. For example, a supplementary account identifier may be provided to the user if the original account identifier has been forgotten, stolen, etc. In some non-limiting embodiments or aspects, the account identifier may be directly or indirectly associated with an issuing authority, such that the account identifier may be a token mapped to a PAN or other type of account identifier. The account identifier may be any combination of alphanumeric characters, characters, and / or symbols, etc.

[0055] As used herein, the term "token" can refer to an account identifier used as a substitute or replacement for another account identifier (e.g., a PAN). A token can be associated with a PAN or another original account identifier in one or more data structures (e.g., one or more databases, etc.) such that the token can be used for payment transactions without directly using the original account identifier. In some non-limiting embodiments or aspects, an original account identifier such as a PAN can be associated with multiple tokens for different individuals or purposes. In some non-limiting embodiments or aspects, a token can be associated with a PAN or other account identifiers in one or more data structures such that the token can be used for transactions without directly using the PAN or other account identifiers. In some examples, an account identifier such as a PAN can be associated with multiple tokens for different uses or purposes.

[0056] As used herein, the term "merchant" can refer to one or more entities (e.g., operators of retail businesses) that provide goods, services, and / or access to goods and / or services to users (e.g., customers, clients, etc.) based on transactions such as payment transactions. As used herein, the term "merchant system" can refer to one or more computer systems operated by or on behalf of a merchant, such as servers executing one or more software applications. As used herein, the term "product" can refer to one or more goods and / or services offered by a merchant.

[0057] As used herein, the term "point-of-sale (POS) device" can refer to one or more electronic devices that a merchant can use to conduct transactions (e.g., payment transactions) and / or process transactions. Alternatively or additionally, a POS device may include peripheral devices, card readers, scanning devices (e.g., barcode scanners, etc.). Communication receivers, near field communication (NFC) receivers, radio frequency identification (RFID) receivers and / or other contactless transceivers or receivers, contact-based receivers, payment terminals, etc.

[0058] As used herein, the term "point-of-sale (POS) system" can refer to one or more client devices and / or peripheral devices used by a merchant to conduct transactions. For example, a POS system may include one or more POS devices, and / or other similar devices that can be used to conduct payment transactions. In some non-limiting embodiments or aspects, a POS system (e.g., a merchant POS system) may include one or more server computers programmed or configured to process online payment transactions via web pages, mobile applications, etc.

[0059] As used herein, the term "transaction service provider" can refer to an entity that receives transaction authorization requests from merchants or other entities and, in some cases, provides payment guarantees through an agreement between the transaction service provider and the issuing institution. In some non-limiting embodiments or aspects, the transaction service provider may include credit card companies, debit card companies, payment networks (e.g., This refers to a transaction service provider system or any other entity that processes transactions. As used herein, the term "transaction service provider system" can refer to one or more computer systems operated by or on behalf of a transaction service provider, such as a transaction service provider system executing one or more software applications. A transaction service provider system may include one or more processors and, in some non-limiting embodiments or aspects, may be operated by or on behalf of a transaction service provider.

[0060] As used herein, the term "payment gateway" can refer to an entity and / or a payment processing system operated by or on behalf of such an entity (e.g., a merchant service provider, payment service provider, payment servicer, payment aggregator, payment aggregator, etc., contracted with an acquirer) that provides payment services (e.g., transaction service provider payment services, payment processing services, etc.) to one or more merchants. Payment services may be associated with the use of portable financial devices managed by a transaction service provider. As used herein, the term "payment gateway system" can refer to one or more computer systems, computer devices, servers, server clusters, etc., operated by or on behalf of a payment gateway.

[0061] As used herein, the term "computing device" can refer to one or more electronic devices configured to process data. In some examples, a computing device may include the necessary components for receiving, processing, and outputting data, such as a processor, display, memory, input device, network interface, etc. A computing device can be a mobile device. As examples, a mobile device may include a cellular phone (e.g., a smartphone or standard cellular phone), a portable computer, a wearable device (e.g., a watch, glasses, lenses, clothing, etc.), a personal digital assistant (PDA), and / or other similar devices. A computing device can also be a desktop computer or other forms of non-mobile computer.

[0062] As used herein, the terms "client" and "client device" can refer to one or more computing devices that access services provided by a server. In some non-limiting embodiments or aspects, "client device" can refer to one or more devices that facilitate payment transactions, such as one or more POS devices used by a merchant. In some non-limiting embodiments or aspects, a client device may include computing devices configured to communicate with one or more networks and / or facilitate payment transactions, such as, but not limited to, one or more desktop computers, one or more mobile devices, and / or other similar devices.

[0063] As used herein, the term "server" may refer to or include one or more computing devices operated by or facilitating communication and processing among multiple parties in a network environment such as the Internet, but it should be understood that communication may be facilitated through one or more public or private network environments, and various other arrangements may be possible. Furthermore, multiple computing devices (e.g., servers, POS devices, mobile devices, etc.) communicating directly or indirectly in a network environment may constitute a "system." As used herein, references to "server" or "processor" may refer to a previously stated server and / or processor, different servers and / or processors, and / or combinations of servers and / or processors that implement a prior step or function. For example, as used in the specification and claims, a first server and / or first processor that implements a first step or function may refer to the same or different servers and / or processors that implement a second step or function.

[0064] As used herein, the term "domain" refers to one or more networks or network hosts within the same physical or logical infrastructure. Domains can be identified by domain names, network addresses, etc.

[0065] As used herein, the term "behavioral biometrics" can refer to the measurement of human behavioral patterns and their use in verifying and authenticating users requesting transactions or computer activities. In some non-limiting embodiments or aspects, such human behavioral patterns may include, but are not limited to, transaction data patterns of payment device users, network communication data patterns of computing device users, device usage patterns (e.g., movement of input devices, key presses, etc.), and other behavioral patterns that can be monitored on computing devices.

[0066] Non-limiting embodiments or aspects of this disclosure relate to systems, methods, and computer program products for authenticating transactions based on behavioral biometric data. By means of the features described in this disclosure, systems processing payment transactions (e.g., transaction service provider systems, payment gateway systems, issuer systems, etc.) can more quickly determine the identity of the user initiating the transaction (e.g., a payment transaction). In some non-limiting embodiments or aspects, the system processing the payment transaction can determine the identity of the user initiating the transaction, and based on this determination, approve or disapprove the transaction before obtaining additional time or sending additional communication to authenticate the transaction, and / or continue sending the final authorization response message to the merchant system. By determining the identity of the individual, such systems processing such payment transactions can waive the sending of authorization request messages, in which case the transaction will not be approved even if approval is obtained. Therefore, computational resources are saved because unnecessary communication between systems is abandoned if the transaction is identified as potentially fraudulent. Computational resources can also be saved by performing behavioral biometric analysis in parallel with other authentication processes.

[0067] In some non-limiting embodiments, the system processing such payment transactions can forward data, including indications of whether a transaction is fraudulent or not, thereby reducing the burden on other systems (e.g., issuing system). Since a transaction service provider system may have access to more transaction data than a single issuing system, it can determine whether a transaction is fraudulent without requesting additional information, whereas an issuing system might need to request additional information from one or more other issuing systems (e.g., in cases where the issuing system involved in an immediate transaction needs to analyze a low number of historical transactions to determine whether it is fraudulent). Therefore, system resources and communication (e.g., bandwidth) between systems in the electronic payment processing network can be saved, freeing up such resources for subsequently received transactions.

[0068] For reference Figure 1 The diagram illustrates an example environment 100 in which the apparatuses, systems, and / or methods described herein may be implemented. Figure 1As shown, environment 100 includes a payment device 104 for user 102, a merchant system 106, a transaction service provider system 108, a directory server 110 associated with the transaction service provider system 108, a behavioral biometric server computer 112 (e.g., associated with a behavioral biometric system that may be integrated with the transaction service provider system 108 or a separate, independent system), a user interface 114 (e.g., a computing device, mobile application, etc., that executes a merchant webpage), and an issuer system 116. It should be understood that environment 100 may include many different issuer systems, behavioral biometric server computers, and / or other components.

[0069] Payment device 104 may include one or more means capable of communicating with merchant system 106 and / or behavioral biometric server computer 112. Payment device 104 may communicate with merchant system 106 and behavioral biometric server computer 112 in a shared communication channel (e.g., using the same communication channel), which can reduce the computing resources required for system implementation. Alternatively, payment device 104 may communicate with merchant system 106 in a first communication channel (e.g., within the electronic payment processing network) and with behavioral biometric server computer 112 in a second communication channel (e.g., outside the electronic payment processing network), which can reduce the total processing time by providing parallel processing efficiency through dividing the total processing time into separate processing channels. Payment device 104 may be associated with user 102 and may include computing devices configured to operate and display user interface 114. Payment device 104 is also capable of communicating via a short-range wireless communication connection.

[0070] Merchant system 106 may include computing devices, such as servers, server clusters, client devices, client device clusters, and peripheral devices that can be used by the merchant to conduct transactions C with user 102, such as POS devices and / or POS systems and / or other similar devices. Merchant system 106 may include one or more devices capable of communicating with payment device 104, transaction service provider system 108, behavioral biometric server computer 112, etc. Payment device 104 may communicate with merchant system 106 (e.g., via a network connection associated with user interface 114) to generate transaction requests to complete transaction C between merchant system 106 and payment device 104. Merchant system 106 may also communicate via short-range wireless communication connections.

[0071] The issuer system 116 may include one or more devices capable of communicating with the transaction service provider system 108, payment device 104, and / or merchant system 106. For example, the issuer system 116 may include computing devices, such as servers, server clusters, and / or other similar devices. In some non-limiting embodiments, the issuer system 116 may be associated with an issuer institution as described herein. For example, the issuer system 116 may be associated with an issuer institution that issues credit accounts, debit accounts, credit cards, debit cards, etc., associated with user 102's payment device 104.

[0072] Transaction service provider system 108 may include computing devices, such as servers, server clusters, and / or other similar devices. In some non-limiting embodiments, transaction service provider system 108 may be associated with a transaction service provider described herein. In some non-limiting embodiments or aspects, transaction service provider system 108 may be associated with and / or communicate with an entity that provides payment services to one or more merchants as described herein. In some non-limiting embodiments, transaction service provider system 108 is capable of communicating with a data storage device, which may be local or remote to transaction service provider system 108. In some non-limiting embodiments, transaction service provider system 108 is capable of receiving information from a data storage device, storing information in a data storage device, transmitting information to a data storage device, or searching for information stored in a data storage device. In some non-limiting embodiments or aspects, transaction service provider system 108 may be associated with and / or include a behavioral biometric server computer 112, a directory server computer 110, and / or other similar computing devices and / or systems.

[0073] Transaction service provider system 108 can receive an authorization request message D associated with transaction C between merchant system 106 and payment device 104 from merchant system 106. The authorization request message D may include communications within the electronic payment processing network, including transaction data related to the transaction between the merchant and the user (e.g., where such transaction data is used to authorize the transaction). The authorization request message may include a 3-D security (3DS) authentication request including a transaction identifier. The authorization request message D may include transaction data, which may include, but is not limited to: payment device identifier, user identifier, merchant system identifier, transaction time, transaction amount, transaction type, transaction description, merchant type, payment device type, etc.

[0074] Transaction service provider system 108 can determine, based on transaction data, that additional security authentication should be applied to authorization request message D. This determination may be based on one or more portions of the transaction data. Initial security authentication may include proof of ownership, proof of knowledge, or inherent proof on behalf of user 102 (e.g., to satisfy a 3-D secure transaction scheme). For example, initial security authentication may include, but is not limited to, providing a password, providing an identifier of the payment device and / or user, providing a Card Verification Value (CVV) code, a two-factor authentication process (e.g., a one-time password), etc. Additional security authentication may include a process of authenticating user 102 using behavioral biometric data. Transaction service provider system 108 may, in response to determining that additional security authentication should be applied, transmit an authenticity assessment request E to behavioral biometric server computer 112. Authenticity assessment request E may include at least a portion of the transaction data (e.g., payment device identifier, user identifier, etc.). Authenticity assessment request E may be transmitted to behavioral biometric server computer 112 while user 102 is responding to a second-factor authentication process in user interface 114 (e.g., a merchant webpage, mobile application, etc.). For example, transaction service provider system 108, issuer system 116, or merchant system 106 can transmit proof of knowledge challenge (e.g., a password request) or proof of ownership challenge (e.g., a one-time password sent to user 102's mobile device) to user 102 via user interface 114, during which time behavioral biometric server computer 112 can transmit an authenticity assessment request E. The parallel processing of multiple transaction authentication processes provided above reduces overall computer processing time and resources.

[0075] Directory server computer 110 may include computing devices such as servers, server groups, client devices, client device groups, peripheral devices and / or other similar devices that can be used by transaction service providers to transmit authenticity assessment requests to behavioral biometric server computer 112. Directory server computer 110 may be included in transaction service provider system 108. Directory server computer 110 may include one or more devices capable of communicating with merchant system 106, behavioral biometric server computer 112, issuer system 116, etc. Directory server computer 110 may be programmed and / or configured to update authorization request message D or authorization response message G based on authenticity assessments from behavioral biometric server computer 112. For example, if an authenticity assessment indicates that transaction C may be fraudulent, directory server computer 110 may remove the card verification value (CVV) from authorization request message D. Alternatively or concurrently, directory server computer 110 may insert authenticity assessment data from behavioral biometric server computer 112 into messages transmitted to issuer system 116 (e.g., authorization request message H).

[0076] The behavioral biometric server computer 112 can communicate with payment device 104, user interface 114, and / or another computing device associated with user 102 to collect behavioral biometric signals based on activity data. These behavioral biometric signals may include, but are not limited to, transaction activities (e.g., transaction data history, including transaction location, transaction time, transaction amount, transaction type, merchant type, etc.) or other user activities (e.g., user computing device location data, user computing device communication time, user network activity, etc.). The behavioral biometric server computer 112 may include one or more devices capable of communicating with payment device 104, merchant system 106, user interface 114, transaction service provider system 108, directory server computer 110, and / or issuer system 116. The behavioral biometric server computer 112 may be associated with a behavioral biometric system and one or more non-transient computer storage devices (e.g., a database of behavioral biometric data). The behavioral biometric server computer 112 may store behavioral biometric data of the behavioral biometric signals, which may include, but are not limited to, transaction data associated with multiple transactions between one or more merchants and one or more payment devices, activity data associated with one or more users, etc.

[0077] Behavioral biometrics server computer 112 can receive an authenticity assessment request E from transaction service provider system 108. The authenticity assessment request E can be received during the processing of transaction C between payment device 104 and merchant system 106 by transaction service provider system 108 (e.g., after receiving authorization request message D from merchant system 106, but before sending authorization response message G to merchant system 106). Behavioral biometrics server computer 112 can use a behavioral biometrics model and stored behavioral biometrics data to generate an authenticity assessment based on at least a portion of the transaction data. The behavioral biometrics model can apply one or more machine learning techniques executed by one or more processors to identify one or more patterns in activity data (e.g., transaction activity and / or user activity) and generate profiles indicating such patterns of genuine user / payment device behavior. If transaction C exhibits a type of transaction activity and / or user activity consistent with the profile generated by the user / payment device, the behavioral biometrics model can assess transaction C as genuine (e.g., generating metrics, parameters, values, etc., indicating that transaction C is unlikely to be fraudulent). If transaction C exhibits transaction activity and / or user activity type that is inconsistent with the profile generated by the user / payment device, the behavioral biometric model may assess transaction C as authentic (e.g., generating metrics, parameters, values, etc. that indicate transaction C may be fraudulent).

[0078] In some non-limiting embodiments or aspects, the authenticity assessment of a transaction can be determined based on a behavioral biometric model, wherein the behavioral biometric model is a machine learning model generated at least in part based on transaction data associated with multiple transactions (e.g., trained). In some non-limiting embodiments or aspects, the behavioral biometric model can be trained based on historical transaction data associated with one or more historical transactions involving multiple payment devices (e.g., by the behavioral biometric server computer 112). For example, the behavioral biometric model can be trained based on historical transaction data associated with one or more historical transactions involving one or more payment devices (e.g., by the behavioral biometric server computer 112), wherein the multiple payment devices include payment device 104 associated with user 102.

[0079] The behavioral biometrics server computer 112 can transmit an authenticity assessment response F to the transaction service provider system 108. The authenticity assessment response F may include at least a portion of the authenticity assessment (e.g., a measure, parameter, value, etc. indicating the likelihood that transaction C is fraudulent or not fraudulent). The authenticity assessment response F can be configured to cause the transaction service provider system 108 to authenticate or reject transaction C. For example, the transaction service provider system 108 can reject or authenticate transaction C based on the measure, parameter, value, etc. indicating the likelihood that transaction C is fraudulent or not fraudulent transmitted in the authenticity assessment response F. The transaction service provider system 108 can generate an authentication response message G based on the authenticity assessment response F. The authentication response message G can be configured to authenticate or reject transaction C. The transaction service provider system 108 can transmit an authorization request message H to the issuer system 116 before or after sending an authenticity assessment request E or receiving an authenticity assessment response F. In this way, the evaluation of the behavioral biometrics can be performed before or after the issuer system 116 requests authorization for transaction C, but before the final settlement and approval of transaction C at the transaction service provider system 108.

[0080] In some non-limiting embodiments or aspects, the transaction service provider system 108 may authenticate or reject a transaction based on an authenticity assessment associated with an authenticity assessment response F. The authenticity assessment may be a binary determination of whether a transaction is fraudulent or not, and the transaction service provider system 108 may take direct action based on this binary determination. Alternatively or additionally, the transaction service provider system 108 may compare the authenticity assessment to a threshold to determine whether the assessment meets the threshold (e.g., whether a predicted value of the likelihood of authenticity is greater than, equal to, or less than the threshold). In this example, the threshold may be associated with a value that indicates a valid transaction when met and a fraudulent transaction when not met. In some non-limiting embodiments or aspects, the threshold may be a predetermined threshold provided by the merchant system 106. For example, the merchant system 106 may receive input from a merchant specifying at least one predetermined threshold associated with a value that, when met by the authenticity assessment, the merchant will approve the transaction (the transaction may be approved by the merchant if it is associated with a prediction such as a 90% or higher probability that the transaction is not fraudulent, or an 80% or higher probability that the transaction is not fraudulent).

[0081] In some non-limiting embodiments or aspects, the transaction service provider system 108 may authenticate or reject transactions based on a multi-factor authentication process. In this example, the transaction service provider system 108 may receive data from one or more environmental systems 100 and / or request data from one or more environmental systems 100. In this example, the data received and / or requested by the transaction service provider system 108 may include, but is not limited to, behavioral biometric measurement data associated with behavioral biometric measurements of a user associated with payment device 104, user interface 114, and / or another computing device (e.g., where the behavioral biometric measurements are measured by payment device 104, user interface 114, another computing device, and / or merchant system 106). In another example, the transaction service provider system 108 may send an out-of-band message to the computing device of user 102 to determine whether the user 102 associated with the computing device is the user 102 controlling the computing device. For example, the transaction service provider system 108 may send a message to the computing device of user 102 (e.g., the computing device executing user interface 114) so ​​that the computing device displays a graphical user interface (GUI) prompting user 102 to provide input (e.g., physical biometric measurement, PIN, password, etc.) to verify that the user 102 operating the computing device is the user 102 associated with the computing device (e.g., payment device 104, user interface 114, and / or other computing device).

[0082] User interface 114 may be associated with (e.g., may include or communicate with) a computing device that operates a merchant webpage, mobile application, etc. The behavioral biometrics service may be embedded in user interface 114 based on a first URL pointing to the domain of issuer system 116 and a second URL pointing to the domain of behavioral biometrics server computer 112. For example, if user interface 114 is presented in a web browser, the webpage may be configured with one or more frames pointing to different domains (e.g., the first URL and the second URL). The first URL may allow communication with issuer system 116, thus enabling further authentication tests (e.g., proof of knowledge, proof of ownership, etc.). The second URL may allow communication with behavioral biometrics server computer 112, for example, to collect behavioral biometric data from user 102. In other examples, the behavioral biometrics service may be invoked as a background service on a mobile device and / or a client script that communicates with issuer system 116 and / or behavioral biometrics server computer 112 via one or more APIs.

[0083] Provided as an example Figure 1 The number and arrangement of devices and networks shown are illustrated. There may be [something related to...]. Figure 1 The devices and / or networks shown are those that, compared to additional devices and / or networks, fewer devices and / or networks, different devices and / or networks, or devices and / or networks arranged differently. Furthermore, Figure 1 The two or more devices shown can be implemented within a single device, or Figure 1 The single device shown may be implemented as multiple distributed devices. Alternatively, a group of devices in environment 100 (e.g., one or more devices) may perform one or more functions described as being performed by another group of devices in environment 100.

[0084] Now for reference Figure 2The diagram illustrates a flowchart of a non-limiting embodiment of a process 200 for authenticating transactions based on behavioral biometric data. It should be understood that, in non-limiting embodiments, process 200 may include additional, fewer, and / or different steps, as well as different sequences of steps. In some non-limiting embodiments, one or more steps of process 200 may be performed (e.g., wholly, partially, etc.) by transaction service provider system 108 (e.g., one or more devices of transaction service provider system 108, such as directory server computer 110). In some non-limiting embodiments, one or more steps of process 200 may be performed (e.g., wholly, partially, etc.) by another device or group of devices independent of or including transaction service provider system 108, such as payment device 104 (e.g., one or more devices of payment device 104), merchant system 106 (e.g., one or more devices of merchant system 106), behavioral biometric server computer 112 (e.g., one or more devices of behavioral biometric server computer 112), and / or issuer system 116 (one or more devices of issuer system 116).

[0085] like Figure 2 As shown, at step 202, the transaction service provider system receives an authorization request message associated with a transaction between the merchant system and the payment device. The authorization request message can be initiated by the user of the payment device through a user interface (e.g., a merchant webpage, mobile application, etc.). In this example, the transaction service provider system can receive the transaction authorization request from the merchant system. In some non-limiting embodiments or aspects, the transaction service provider system can receive the transaction authorization request from the merchant system based on the user associated with the payment device initiating the transaction. For example, the user associated with the payment device can initiate a transaction by engaging the payment device with the merchant system (e.g., by having a mobile device with an e-wallet and / or by bringing an application associated with the e-wallet stored thereon close to a POS terminal to initiate payment during a transaction, by providing input to a laptop computer during an e-commerce transaction to initiate a transaction, etc.). The authorization request message includes transaction data.

[0086] In some non-limiting embodiments or aspects, the merchant system may generate a transaction authorization request based on transaction data associated with a transaction. For example, the merchant system may receive user data associated with a user linked to a payment device. The user data may include account data associated with a payment account (e.g., a PAN, PIN, token, etc. associated with the payment account). In some non-limiting embodiments or aspects, when generating a transaction authorization request, the merchant system may include merchant system data associated with the merchant system (e.g., a POS identifier specifying the POS device, a transaction identifier associated with the new transaction, etc.). In some non-limiting embodiments or aspects, the merchant system data associated with the merchant system may include merchant system type data associated with an indication of the type of merchant system involved in the new transaction (e.g., whether the merchant system is a POS terminal installed in a physical location, a website hosted by the merchant system and / or on behalf of the merchant system, etc.). In some non-limiting embodiments or aspects, the merchant system may generate a transaction authorization request to initiate a new transaction based on data received from the payment device. For example, the merchant system may generate a transaction authorization request. Transaction authorization requests may include transaction data associated with the transaction, user data associated with the user, account data associated with the payment account, and merchant system data associated with the merchant system.

[0087] like Figure 2 As shown, at step 204, the transaction service provider system determines, based on transaction data, that additional security authentication should be applied to the authorization request message. For example, the transaction service provider system may use a payment device identifier to determine that the payment device of the transaction is associated with a second-form issuing authority authenticated by a designated behavioral biometric application. The transaction service provider system may also identify the transaction as having a transaction data profile indicating that additional security authentication is required (e.g., determined by a fraud prevention system). The transaction service provider system may determine that additional security authentication should be applied based on the processing of the transaction authorization request (e.g., during the processing of the transaction authorization request). For example, the transaction service provider system may determine that additional security authentication should be applied before and / or after sending the authorization request message to the issuing system, where the issuing system maintains the user's payment account. Alternatively or additionally, the transaction service provider system may determine that additional security authentication should be applied based on (e.g., in response to) receiving a request from the issuing system and / or the merchant system to determine an assessment of the authenticity of a new transaction.

[0088] At step 206, the transaction service provider transmits an authenticity assessment request to the behavioral biometrics server computer. This communication may be in response to a determination that additional security authentication should be applied. The authenticity assessment request may include at least a portion of the transaction data, including but not limited to payment device identifiers, user identifiers, issuing institution identifiers, etc. At step 208, the transaction service provider system receives from the behavioral biometrics server computer an authenticity assessment response generated by the behavioral biometrics server computer in response to the authenticity assessment request. The authenticity assessment response may be based on part or all of the transaction data transmitted to the behavioral biometrics server computer.

[0089] At step 210, the transaction service provider system generates an authentication response message configured to authenticate or reject the transaction. The authentication response message is based on (e.g., at least in part on) an authenticity assessment response. For example, the authentication assessment may indicate the likelihood that the transaction is genuine, making it highly probable that the transaction is not fraudulent when assessed by the transaction service provider system in conjunction with second-factor authentication (e.g., a one-time password). Based on this combined assessment, the transaction service provider system can authenticate the transaction. In another example, if the authenticity assessment indicates a high probability that the transaction was not authorized by the user, the transaction service provider system may reject the transaction even if it passes the second-factor authentication test.

[0090] Now for reference Figure 3 The diagram illustrates a flowchart of a non-limiting embodiment of a process 300 for authenticating transactions based on behavioral biometric data. It should be understood that, in non-limiting embodiments, process 300 may include additional, fewer, and / or different steps, as well as different sequences of steps. In some non-limiting embodiments, one or more steps of process 300 may be performed (e.g., wholly, partially, etc.) by transaction service provider system 108 (e.g., one or more devices of transaction service provider system 108, such as directory server computer 110). In some non-limiting embodiments, one or more steps of process 300 may be performed (e.g., wholly, partially, etc.) by another device or group of devices independent of or including transaction service provider system 108, such as payment device 104 (e.g., one or more devices of payment device 104), merchant system 106 (e.g., one or more devices of merchant system 106), behavioral biometric server computer 112 (e.g., one or more devices of behavioral biometric server computer 112), and / or issuer system 116 (one or more devices of issuer system 116).

[0091] like Figure 3As shown, at step 208, the transaction service provider system receives from the behavioral biometrics server computer an authenticity assessment response generated by the behavioral biometrics server computer in response to the authenticity assessment request. The authenticity assessment response may be based on part or all of the transaction data transmitted to the behavioral biometrics server computer. At step 302, in response to the authenticity assessment response indicating a lack of user authenticity (e.g., the transaction requester is unauthorized or the user is actually associated with the payment device) and / or a lack of payment device authenticity (e.g., the payment device is an unauthorized copy, the payment device has been stolen, etc.), the transaction service provider system may send an alert to the user interface (e.g., merchant website, mobile application, etc.), the issuing system, and / or the merchant system. The alert may be a communication identifying the transaction and may further prompt the recipient to implement fraud prevention measures (e.g., locking the account, preventing future transactions associated with the payment device, etc.).

[0092] At step 304, the transaction service provider system may transmit an authentication response message to an issuer system associated with the issuer of the payment device. The authentication response message may be configured to authenticate or reject the transaction when evaluated by the issuer system in conjunction with the user's response to the second-factor authentication process. For example, the user interface may prompt the user to complete second-factor authentication provided by a first URL pointing to the issuer system's domain. The issuer system may receive the user's second-factor authentication attempt and compare the submission with the authentication response message received from the transaction service provider system. If the combination of authentication tests indicates a possibility of fraud or inauthenticity, the transaction may be rejected at the issuer system. Similarly, if the combination of authentication tests indicates a possibility of a genuine authorized transaction, the transaction may be approved at the issuer system.

[0093] At step 306, the transaction service provider system can compare the authentication assessment response with a predetermined threshold provided by the merchant system. For example, if the authenticity assessment is configured to output the percentage probability that a transaction is authorized by the user, the merchant can set a threshold percentage to trigger transaction approval when the authenticity assessment meets the threshold percentage. Similarly, a transaction can be automatically rejected if the predetermined threshold is not met. The establishment of predetermined thresholds provides less communication between the computer systems used for authenticating transactions, thereby reducing the overall network processing resources and bandwidth required. At step 308, the transaction service provider system can configure the authentication response message to authenticate or reject the transaction based on the comparison between the authenticity assessment response and the predetermined threshold provided by the merchant system.

[0094] For reference Figure 4The illustration shows an example component of device 400. Device 400 may correspond to one or more of the following: payment device 104, merchant system 106, transaction service provider system 108, directory server computer 110, behavioral biometric server computer 112, user interface 114, and / or issuer system 116. In some non-limiting embodiments or aspects, one or more of the following devices may include at least one device 400 and / or at least one component of device 400. Figure 4 As shown, the device 400 may include a bus 402, a processor 404, a memory 406, a storage unit 408, an input unit 410, an output unit 412, and a communication interface 414.

[0095] Bus 402 may include components that enable communication between parts of device 400. In some non-limiting embodiments or aspects, processor 404 may be implemented in hardware, software, or a combination of hardware and software. For example, processor 404 may include a processor (e.g., a central processing unit (CPU), graphics processing unit (GPU), accelerated processing unit (APU), etc.), microprocessor, digital signal processor (DSP), and / or any processing component that can be programmed to perform functions (e.g., a field-programmable gate array (FPGA), application-specific integrated circuit (ASIC), etc.). Memory 406 may include random access memory (RAM), read-only memory (ROM), and / or another type of dynamic or static storage device (e.g., flash memory, magnetic memory, optical memory, etc.) that stores information and / or instructions for use by processor 404.

[0096] Storage component 408 may store information and / or software related to the operation and use of device 400. For example, storage component 408 may include hard disks (e.g., magnetic disks, optical disks, magneto-optical disks, solid-state disks, etc.), compressed optical disks (CDs), digital versatile optical disks (DVDs), floppy disks, cassettes, magnetic tapes, and / or other types of computer-readable media, as well as corresponding drives.

[0097] Input component 410 may include a component that allows device 400 to receive information, such as through user input (e.g., touchscreen display, keyboard, keypad, mouse, button, switch, microphone, camera, etc.). Alternatively, input component 410 may include sensors for sensing information (e.g., Global Positioning System (GPS) component, accelerometer, gyroscope, actuator, etc.). Output component 412 may include a component that provides output information from device 400 (e.g., display, speaker, one or more light-emitting diodes (LEDs), etc.).

[0098] Communication interface 414 may include transceiver components (e.g., transceivers, separate receivers and transmitters, etc.) that enable device 400 to communicate with other devices, for example, via a wired connection, a wireless connection, or a combination of wired and wireless connections. Communication interface 414 may allow device 400 to receive information from another device and / or provide information to another device. For example, communication interface 414 may include an Ethernet interface, an optical interface, a coaxial interface, an infrared interface, a radio frequency (RF) interface, a universal serial bus (USB) interface, etc. Interfaces, cellular network interfaces, etc.

[0099] Apparatus 400 can perform one or more processes described herein. Apparatus 400 can perform these processes based on software instructions stored in a computer-readable medium such as memory 406 and / or storage unit 408, executed by processor 404. Computer-readable medium (e.g., non-transient computer-readable medium) is defined herein as a non-transient memory device. A non-transient memory device includes memory space located within a single physical memory device or memory space distributed across multiple physical memory devices.

[0100] Software instructions can be read from another computer-readable medium or from another device into memory 406 and / or storage unit 408 via communication interface 414. When executed, the software instructions stored in memory 406 and / or storage unit 408 cause processor 404 to perform one or more processes described herein. Alternatively or additionally, hard-wired circuitry may be used in place of or in combination with the software instructions to perform one or more processes described herein. Therefore, the embodiments or aspects described herein are not limited to any particular combination of hardware circuitry and software.

[0101] The memory 406 and / or storage component 408 may include a data storage device or one or more data structures (e.g., a database). The device 400 is capable of receiving information from the data storage device or one or more data structures in the memory 406 and / or storage component 408, storing information in the data storage device or one or more data structures, transmitting information to the data storage device or one or more data structures, or searching for information stored therein. For example, the information may include encrypted data, input data, output data, transaction data, account data, or any combination thereof.

[0102] supply Figure 4 The number and arrangement of components shown are for illustrative purposes only. In some non-limiting embodiments or aspects, with Figure 4Compared to those shown, device 400 may include additional components, fewer components, different components, or components arranged in a different manner. Alternatively or additionally, a set of components of device 400 (e.g., one or more components) may perform one or more functions described as being performed by another set of components of device 400.

[0103] Referring further to the foregoing figures, in a non-limiting embodiment, the described systems and methods can be provided in the form of a Behavioral Biometric Cloaking Service (BBCS), where "cloaking" can refer to providing an additional layer of authentication. BBCS can be applied in a 3D-Security (3DS) context to meet the stringent Customer Authentication (SCA) requirements of the revised Payment Services Directive (PSD2). However, BBCS is not limited to this use case and can be provided outside the PSD2 SCA context, allowing issuers to enhance their digital transaction authentication without requiring significant technical updates to their issuer access control servers (ACS). Issuers also do not need to provide separate computing resources for BBCS signal collection, decision-making, and response.

[0104] SCA requirements include authentication steps based on proof of knowledge, proof of ownership, and inherent proof. BBCS can be used to allow issuers to comply with two or more of these authentication steps. BBCS can be adopted on top of existing upgraded authentication services (e.g., one-time passwords). BBCS provides efficient, time-saving authentication while allowing modular, independent integration with existing authentication systems. BBCS can provide multi-factor compliance in 3DS 2.x and 3DS 1.0 environments. BBCS can be used in web applications, native applications, and other channels.

[0105] BBCS can be offered as a standalone service, such as part of a transaction service provider system, like a directory server service. BBCS can be offered directly to publishers / ACS providers. BBCS provides the ability to collect behavioral biometric signals for a given 3DS transaction. BBCS provides the ability to evaluate and make decisions based on these behavioral biometric signals. BBCS also provides the ability to combine the success / failure of another authentication process (e.g., a one-time password) with behavioral biometric authentication to provide a final response to components within the 3DS ecosystem (e.g., directory servers, 3DS servers, merchant systems, etc. of the transaction processing system).

[0106] In the 3DS 2.x web browser processing flow, the directory server can register method URL endpoints supporting behavioral biometrics code and method URLs from the publisher / ACS provider. In the 3DS 2.x native application flow, a software development kit (SDK) can be provided for first-party or third-party behavioral biometrics. This SDK collects signals and sends them to the BBCS server, along with device data collected according to EMV specifications. In the 3DS 1.0 process flow, a publisher ACS upgrade window can be built within a URL provided by BBCS, potentially allowing signal collection code to run during the upgrade certification process.

[0107] In non-limiting embodiments, behavioral biometric signal-based evaluation and decision-making can be performed based on a technical framework used in BBCS implementations, such as a local or remote call to a technology provider. The BBCS can be a learning system where profiles of behavioral biometric data can be maintained and improved over time. Depending on the integration point of the BBCS, different approaches can be taken to combine responses from the BBCS and alternative authentication methods (e.g., one-time passwords) and provide results. For example, transaction identifiers captured during behavioral biometric signal collection can be provided to a directory server, which can update transaction requests or responses based on decisions from the BBCS server and abandon the Cardholder Validation Value (CVV) if the transaction fails the BBCS evaluation. Alternatively, the URL for BBCS integration can be overridden to allow updating transaction request values ​​based on behavioral biometric decision-making. Alternatively, the directory server can initiate a request to the BBCS server and receive the decisions, which can be passed to the authentication response from the directory server to the ACS. This information can be added as an extension to the issuer authentication request. Alternatively, the BBCS server can proxy 3DS messages between the directory server and the ACS, and update transaction request or authentication response messages appropriately. The proxy can reside between the 3DS server and the directory server, and update the responses appropriately.

[0108] Although this disclosure has been described in detail based on embodiments currently considered to be most practical and preferred for illustrative purposes, it should be understood that such details are for the purposes described only, and that this disclosure is not limited to the disclosed embodiments, but rather is intended to cover modifications and equivalent arrangements within the scope of the appended claims. For example, it should be understood that this disclosure contemplates, as far as possible, that one or more features of any embodiment may be combined with one or more features of any other embodiment.

Claims

1. A computer-implemented method, comprising: The behavioral biometrics service is embedded in the merchant webpage or mobile application by configuring one or more frames and using a first URL and a second URL, wherein the first URL points to the domain of the issuer system and the second URL points to the domain of the behavioral biometrics server computer. A transaction service provider system including at least one processor receives an authorization request message from a user computing device operating the merchant's webpage or the mobile application, the authorization request message being associated with a transaction between the merchant system and a payment device, the authorization request message including transaction data; The at least one processor uses the transaction data to determine that additional security authentication should be applied to the authorization request message; In response to determining that the additional security authentication should be applied, the at least one processor transmits an authenticity assessment request to the behavioral biometrics server computer, the authenticity assessment request including at least a portion of the transaction data; The authenticity assessment request is received by the behavioral biometrics server computer; The behavioral biometric server computer generates an authentication assessment response based on at least a portion of the transaction data, and also based on behavioral biometric signals associated with the payment device and / or user collected by the behavioral biometric server computer in a separate communication channel to the transaction processing network of the transaction service provider system. The behavioral biometrics server computer transmits an authenticity assessment response to the transaction service provider system, the authenticity assessment response including at least a portion of the authenticity assessment; The at least one processor is used to receive the authenticity assessment response generated by the behavioral biometrics server computer from the behavioral biometrics server computer. as well as The at least one processor generates an authentication response message configured to authenticate or reject the transaction based on the authenticity assessment response.

2. The computer-implemented method of claim 1, wherein the authorization request message is initiated by a user of the payment device through the merchant webpage or the mobile application, and wherein the authenticity assessment request is transmitted to the behavioral biometrics server computer while the user is responding to a second-factor authentication process in the merchant webpage or the mobile application.

3. The computer-implemented method of claim 2, further comprising, in response to the authenticity assessment response indicating that the user and / or the payment device lacks authenticity, transmitting an alert to at least one of the merchant's webpage, the mobile application, or the issuing system.

4. The computer-implemented method of claim 2, further comprising using the at least one processor to transmit the authentication response message to an issuer system associated with the issuer of the payment device, the authentication response message being configured to authenticate or reject the transaction when evaluated by the issuer system in conjunction with the user's response to the second factor authentication process.

5. The computer-implemented method of claim 1, wherein the behavioral biometric signals associated with the payment device and / or the user are collected prior to initiating the transaction.

6. The computer-implemented method of claim 1, further comprising configuring the authentication response message to authenticate or reject the transaction based on a comparison of the authenticity assessment response with a predetermined threshold provided by the merchant system.

7. A system comprising at least one server computer of a transaction service provider system, said at least one server computer including at least one processor, said at least one server computer being programmed and / or configured to: The behavioral biometrics service is embedded in the merchant webpage or mobile application by configuring one or more frames and using a first URL and a second URL, wherein the first URL points to the domain of the issuing system and the second URL points to the domain of the behavioral biometrics server computer; an authorization request message is received from a user computing device operating the merchant webpage or the mobile application, the authorization request message being an authorization request message associated with a transaction between the merchant system and the payment device, the authorization request message including transaction data; Based on the transaction data, it is determined that additional security authentication should be applied to the authorization request message; In response to determining that the additional security authentication should be applied, an authenticity assessment request is transmitted to the behavioral biometrics server computer, the authenticity assessment request including at least a portion of the transaction data; Receive a realism assessment response generated by the behavioral biometrics server computer from the behavioral biometrics server computer; and Based on the authenticity assessment response, an authentication response message is generated that is configured to authenticate or reject the transaction; as well as The behavioral biometric server computer is programmed and / or configured to: Receive the authenticity assessment request; An authentication assessment response is generated based on at least a portion of the transaction data, and also based on behavioral biometric signals associated with the payment device and / or user collected by the behavioral biometric server computer in a separate communication channel to the transaction processing network of the transaction service provider system. The system transmits an authenticity assessment response to the transaction service provider system, the authenticity assessment response including at least a portion of the authenticity assessment.

8. The system of claim 7, wherein the authorization request message is initiated by the user of the payment device through the merchant webpage or the mobile application, and wherein the authenticity assessment request is transmitted to the behavioral biometric server computer while the user is responding to a second-factor authentication process in the merchant webpage or the mobile application.

9. The system of claim 8, wherein the server computer is further programmed and / or configured to send an alert to at least one of the merchant webpage, the mobile application, or the issuing system in response to the authenticity assessment response indicating that the user and / or the payment device lacks authenticity.

10. The system of claim 8, wherein the server computer is further programmed and / or configured to transmit the authentication response message to the issuing system associated with the issuer of the payment device, the authentication response message being configured to authenticate or reject the transaction when evaluated by the issuing system in conjunction with the user's response to the second factor authentication process.

11. The system of claim 7, wherein the behavioral biometric signals associated with the payment device and / or the user are collected prior to initiating the transaction.

12. The system of claim 7, wherein the server computer is further programmed and / or configured to configure the authentication response message to authenticate or reject the transaction based on a comparison of the authenticity assessment response with a predetermined threshold provided by the merchant system.

13. A computer program product comprising at least one non-transitory computer-readable medium, said at least one non-transitory computer-readable medium comprising program instructions that, when executed by at least one processor of a transaction service provider system, cause said at least one processor to: The behavioral biometrics service is embedded in the merchant webpage or mobile application by configuring one or more frames and using a first URL and a second URL, wherein the first URL points to the domain of the issuer system and the second URL points to the domain of the behavioral biometrics server computer. Receive an authorization request message from a user computing device operating the merchant webpage or the mobile application, the authorization request message being an authorization request message associated with a transaction between the merchant system and the payment device, the authorization request message including transaction data; Based on the transaction data, it is determined that additional security authentication should be applied to the authorization request message; In response to determining that the additional security authentication should be applied, an authenticity assessment request is transmitted to the behavioral biometrics server computer, the authenticity assessment request including at least a portion of the transaction data; Receive a realism assessment response generated by the behavioral biometrics server computer from the behavioral biometrics server computer; and Based on the authenticity assessment response, an authentication response message is generated that is configured to authenticate or reject the transaction; as well as The behavioral biometric server computer is programmed and / or configured to: Receive the authenticity assessment request; An authentication assessment response is generated based on at least a portion of the transaction data, and also based on behavioral biometric signals associated with the payment device and / or user collected by the behavioral biometric server computer in a separate communication channel to the transaction processing network of the transaction service provider system. The system transmits an authenticity assessment response to the transaction service provider system, the authenticity assessment response including at least a portion of the authenticity assessment.

14. The computer program product of claim 13, wherein the authorization request message is initiated by the user of the payment device through the merchant webpage or the mobile application, and wherein the authenticity assessment request is transmitted to the behavioral biometric server computer while the user is responding to a second-factor authentication process in the merchant webpage or the mobile application.

15. The computer program product of claim 14, wherein the program instructions further cause the at least one processor to transmit an alert to at least one of the merchant webpage, the mobile application, or the issuing system in response to the authenticity assessment response indicating that the user and / or the payment device lacks authenticity.

16. The computer program product of claim 14, wherein the program instructions further cause the at least one processor to transmit the authentication response message to the issuing system associated with the issuer of the payment device, the authentication response message being configured to authenticate or reject the transaction when evaluated by the issuing system in conjunction with the user's response to the second factor authentication process.

17. The computer program product of claim 13, wherein the behavioral biometric signals associated with the payment device and / or the user are collected prior to initiating the transaction.

Citation Information

Patent Citations

  • Systems and methods for consumer authentication using behavioral biometrics

    US20150363785A1