Managing communications of sensitive information

By using different communication channels to transmit in the transaction system and correlating sensitive information from different sources at the server, the problems of low security and efficiency in the transaction system are solved, and more efficient and secure information transmission is achieved.

CN114341911BActive Publication Date: 2025-10-03VISA EUROPE
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN201980099947.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-09-05
Publication Date
2025-10-03
Estimated Expiration
2039-09-05

AI Technical Summary

Technical Problem

Existing transaction systems are insecure and inefficient when transmitting transaction-related data, especially during communication between multiple entities, where there are problems of information leakage and redundant communication.

Method used

Use different communication channels to transmit sensitive information from different sources and associate them at a single server, reducing the number of direct communication channels and improving security and efficiency.

Benefits of technology

By reducing the number of communications and avoiding information storage on user devices, the security and efficiency of the system are enhanced, the risk of information leakage is reduced, and the interaction process of the transaction system is simplified.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114341911B_ABST
    Figure CN114341911B_ABST
Patent Text Reader

Abstract

Disclosed herein is a computer-implemented method for managing sensitive information and its communication. The method comprises: receiving, by a first server, first sensitive information related to a user having an account on the second server from a second server; receiving, by the first server, second sensitive information from a user device via a data entry page hosted by the first server, wherein the data entry page is configured to receive second sensitive data associated with the user, and the second sensitive information is different from the first sensitive information; and associating, by the first server, the first sensitive information with the second sensitive information. The first server and the second server communicate via a first communication channel, and the first server and the user device communicate via a second, different communication channel.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to managing communications of a networked system, and more particularly, to a server computer and a method for managing the transmission of sensitive information between multiple entities within such a system. Background Art

[0002] As technology advances, the number of cashless transactions being conducted continues to increase, resulting in an increasing amount of data associated with such transactions being transmitted across payment networks, which often include several different entities. A typical transaction system that is part of such a payment network allows a user to make payments using a payment card or computing device by obtaining information from the card or device and transmitting the transaction details and the obtained information to an entity within the system, such as a payment service provider, for further processing.

[0003] Some transaction systems include a third party with which the user has an account and with which communications regarding the transaction are exchanged in order to update the status of the user's account based on the details of the transaction.

[0004] Improvements to transaction systems for exchanging multiple communications related to transactions would be advantageous. Additionally, it would be advantageous to increase the security of communications sent to third parties within a transaction system. Summary of the Invention

[0005] According to a first aspect of the present disclosure, a computer-implemented method is provided. The method comprises: receiving, by a first server, first sensitive information related to a user having an account on the second server from a second server; receiving, by the first server, second sensitive information from a user device via a data input page hosted by the first server, wherein the data input page is configured to receive second sensitive data associated with the user, and the second sensitive information is different from the first sensitive information; and associating, by the first server, the first sensitive information with the second sensitive information. The first server and the second server communicate via a first communication channel, and the first server and the user device communicate via a second, different communication channel.

[0006] According to a second aspect of the present disclosure, a server computer is provided, comprising: a processor; and a computer-readable medium configured to store executable instructions, wherein the server computer is configured to communicate with a user device and a second server computer, and the processor is configured to execute the stored executable instructions to: receive first sensitive information related to a user having an account on the second server from the second server computer via a first communication channel; receive second sensitive data associated with the user from the user device, wherein the second sensitive information is different from the first sensitive information; receive second sensitive information from the user device via the data input page via a second, different communication channel; and associate the first sensitive information with the second sensitive information.

[0007] According to a third aspect of the present disclosure, a system is provided, which includes a client computer, a first server and a second server, wherein the first server is configured to: interact with the second server and the client computer via a corresponding data transmission channel; receive first sensitive information related to a user who has an account on the second server and is associated with the client computer from the second server via the corresponding data transmission channel; provide a data input page accessible by the client computer; receive second sensitive information associated with the user via the data input page from the client computer via the corresponding data transmission channel, wherein the second sensitive information is different from the first sensitive information; and link the first sensitive information with the second sensitive information; wherein the client computer is configured to: access the data input page to allow the user to enter the second sensitive information into the data input page; and provide the second sensitive information to the first server via the corresponding data transmission channel; wherein the second server is configured to: identify the account of the user; retrieve the first sensitive information related to the user using the identified account; and send the first sensitive information to the first server via the corresponding data transmission channel. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] The various features of the present disclosure will become apparent from the following detailed description taken in conjunction with the accompanying drawings. Figure 1 The invention is characterized by the following features, and wherein:

[0009] Figure 1 It is a schematic diagram of the trading system based on the example.

[0010] Figure 2 is a schematic diagram of a first server computer according to an example.

[0011] Figure 3 It is based on examples Figure 1Schematic diagram of the trading system.

[0012] Figure 4 It is based on examples Figure 1 Schematic diagram of the trading system.

[0013] Figure 5 is a schematic diagram of a user device according to an example.

[0014] Figure 6 It is a schematic diagram of the trading system based on the example.

[0015] Figure 7 is a schematic representation of a database stored by a first server computer according to an example. DETAILED DESCRIPTION

[0016] Figure 1 A transaction system 100 is shown, to which the embodiments described herein have particular application.

[0017] Trading system 100 includes a first server computer 110, a second server computer 120, and a user device 130. First server computer 110 and second server computer 120 communicate via a first communication channel 210. First server computer 110 and user device 130 communicate via a second communication channel 220. In one example, first server computer 110 and second server computer 120 can receive, process, and maintain information related to users of user device 130 and any transactions conducted using that information. First communication channel 210 and second communication channel 220 can be communication channels across a network, such as the Internet or a private network.

[0018] The user device 130 may be a client computer, a portable electronic device, such as a smartphone, a smartwatch, a wearable device, or a tablet computer associated with a user. The user device 130 may execute a software application, such as an electronic mobile wallet application, that stores payment data associated with the user, which enables the user to conduct transactions using the device.

[0019] Figure 2 1. A first server computer 110 is shown, to which the embodiments described herein have particular application. The first server computer 110 includes a communication interface 111, a memory 112, and a processor 130. The communication interface 111 communicates with the server via a first communication channel 210 and a second communication channel 220 ( Figure 1) receives and sends communications, thereby interacting with the second server computer 120 and the user device 130. The communication interface 111 is coupled to the memory 112 and the processor 113 and forwards any received communications to the processor 113 via an internal bus (not shown). The memory 112 is coupled to the processor 113 and stores computer-readable instructions 114 that can be executed by the processor 113 to cause the first server computer 110 to perform one or more processes. For example, the processor 113 can execute computer-readable instructions of one or more software applications.

[0020] Linked Data

[0021] In one example, a user associated with a user device 130 may have an account on the second server computer 120. For example, the second server computer 130 may provide services to the user and maintain a record of the user, wherein the record contains sensitive information related to the user. In one example, the sensitive information may be the user's name, address, date of birth, account identifier, and historical transaction data. In addition, the user associated with the user device 130 may have one or more other accounts on the first server computer 110. For example, the first server computer 110 may host services accessible by the user device 130 and maintain a record of each service for the user, wherein the record contains sensitive information related to the user. In one example, the sensitive information may be payment information including payment card details (e.g., primary account number (PAN), card identifier, numbers from the card number, and card security code), the user's payment account details (e.g., bank name and account number), and the user's historical payment data.

[0022] In one example, the system 100 can use the first communication channel 210 and the second communication channel 220 to perform a data linking process for a user, which will be referred to below. Figure 3 As a result of this data linking process, associations can be defined between different sensitive information of the user from different sources, which can be used by other processes, which will be referred to in Figure 6 Describe in more detail.

[0023] Figure 3 Shown according to the example Figure 1 The system 100 and the communication flows exchanged between component parts of the system 100 as part of the data link process.

[0024] At step S301 , the first server computer 110 receives a first message M1 containing first sensitive information from the second server computer 120 . The first sensitive information relates to a user who has an account in the second server computer 120 .

[0025] At step S302, first server computer 110 receives a second message M2 containing second sensitive information from user device 130. The second sensitive information is received via a data input page hosted by first server computer 110 and transmitted to first server computer 110. The data input page is configured to receive second sensitive data associated with the user. The second sensitive information is different from the first sensitive information. In one example, after receiving the second sensitive information, first server computer 110 may verify the second sensitive information before associating the second sensitive information with the first sensitive information.

[0026] In some examples, step S301 is triggered by the user device 130 accessing a webpage hosted by the second server computer 120, e.g., accessing a user account as a result of a user interacting with the user device 130 and navigating to their account using a web browser on the device 130. In some cases, step S130 may be triggered without user involvement, e.g., by the user device 130 connecting to a network, such as a Wi-Fi network, associated with the second server computer 120.

[0027] After 302, the first server computer 110 makes the database ( Figure 7 ) is associated with the second sensitive information within a database. For example, the associating of the first sensitive information and the second sensitive information can be storing the first information and the second information together with the same user identifier, storing the first information and the second information in a single record maintained by the first server computer 110 and associated with the user, and storing the first sensitive information and the second sensitive information in separate records that include pointers to each other. In each instance, any future access request, such as a read request, that specifies the common user identifier or identifies one of the first sensitive information and the second sensitive information to the or each record may result in the retrieval or at least identification of the first sensitive information and the second sensitive information.

[0028] In one example, after receiving the second sensitive information, the first server computer 110 can verify the second sensitive information before associating the second sensitive information with the first sensitive information.

[0029] In one instance, you can repeatedly refer to Figure 3 The process described is to link other sensitive information with the first sensitive information in a many-to-one relationship.

[0030] Using different communication channels to transmit the respective sensitive information enables secure reception of different sensitive information from different sources at a single location, namely, first server computer 110: in this example, second server computer 120 and user device 130. Specifically, because (i) the first sensitive information is transmitted directly from second server computer 120 to first server computer 110 and is not shared with user device 130, and (ii) the second sensitive information is transmitted directly from user device 130 to first server computer 110 and is not shared with second server computer 120, the number of separate communications containing sensitive information is reduced compared to a system that does not have two different direct communication channels between the information source and the information destination. This increases the security and efficiency of system 100.

[0031] Additionally, the amount of sensitive information per communication is reduced, thereby improving security because if any one communication is intercepted by an unauthorized third party, only one piece of sensitive information will be revealed.

[0032] Furthermore, the association between the first sensitive information and the second sensitive information and the direct communication between the first server computer 110 and the second server computer 120 increases the efficiency of processes performed by the second server computer 120 using the first sensitive information, because the processes are automatically initiated by another process performed by the first server computer 110 using the second sensitive information, and vice versa. Furthermore, the association means that there is no need to provide the first sensitive information or the second sensitive information to the first server computer 110 in order to initiate any subsequent processes using the respective information, because the first server already stores the association and the first and second sensitive information.

[0033] Furthermore, direct communication 210 between second server computer 120 and first server computer 110 has the following effect: user device 130 is not involved in generating the first sensitive information or providing the first sensitive information to first server computer 110. In this way, the user device is not involved in the first sensitive information, which: (i) eliminates the risk of incorrectly entering the information at user device 130 (thereby increasing the reliability of the information); and (ii) avoids storing the first sensitive information on user device 130, such as in browser history or web logs, which a browser operating on user device 130 may store insecurely. Furthermore, the number of communications containing the first sensitive information is reduced, thereby reducing the risk of interception of the first sensitive information.

[0034] Figure 4 Shown according to the example Figure 1 system 100 and the communication flows between the component parts of system 100. Figure 4 Provided Figure 3 Additional details of the instance.

[0035] Regarding step S301, at step S401, first server computer 110 receives a first message M11 from second server computer 120 that includes first sensitive information, where the first sensitive information relates to a user who has an account with second server computer 120. In one example, second server computer 120 maintains a database including information related to multiple users. Each user may have an account with second server computer 120, such as an online account, whereby the user has previously provided specific information to second server computer 120 and obtained services, where the provided information is stored in a database record corresponding to their account. Second server computer 120 may store information related to each user in a corresponding record in the database to facilitate accessing the user's account to obtain the first sensitive information. In one example, second server computer 120 may search its database using an identifier associated with the user to locate the corresponding account information. User device 130 may provide the identifier to second server computer 120. In some examples, message M11 also includes a redirection URL generated by second server computer 120, and the redirection URL is forwarded to the user device at a later point in time (step S406).

[0036] At step S402, the first server computer 110 generates a second message M12 including a session identifier and sends the second message to the second server computer 120. In some examples, the second message M12 may be embedded in the first token. The first token may be used as a replacement or substitute for the session identifier.

[0037] At step S403, second server computer 120 generates a third message M13 that forwards the session identifier and the URL of a data entry page associated with the session identifier to user device 130. The URL is generated by second server computer 120 and is specific to the user of user device 130, allowing second server computer 120 to identify the user to whom any communications sent to the URL are addressed. Second server computer 120 may provide the session identifier to user device 130 using the first token. For example, the session identifier may be embedded within or appended to the first token. The URL and session identifier enable the user device to access the corresponding data entry page hosted by first server computer 110 and provide the second sensitive information to first server computer 110 via the data entry page.

[0038] At step S404, in response to receiving a request from user device 130 using the URL and session identifier, first server computer 110 may provide, for example, a web data entry page to the browser on user device 130, as included in a fourth message M14. In some examples, the data entry page is opened as an iFrame within the browser. In some examples, first server computer 110 sends a second token with the data entry page, where the first token is different from the second token. The second token can be used to submit data to the data entry page.

[0039] Using the first token and the second token provides another way to verify the integrity of the received data and thus makes it easier to identify intercepted communications if the tokens have been modified. In one example, the first token and the second token can be JSON Web Tokens (JWTs) that are one-time use tokens and are locked to a specific resource. Figure 4 In an example, the specific resource is the session identifier of the first token and the submission data of the second token. The JWT can be present in the header of an HTTP request between corresponding entities in system 100 and is used to verify the source of the data or message accompanying the JWT. In one example, the JWT is generated using an asymmetric algorithm such as the RSA256 algorithm.

[0040] At step S405, first server computer 110 receives a fifth message M15 from user device 130 via the data input page, including a second token, the second token including a session identifier and second sensitive information. The session identifier provides a way for user device 130 to identify the second sensitive information sent by user device 130 to first server computer 110. In some examples, first server computer 110 verifies the second sensitive information by forwarding it to an account verification entity.

[0041] After verifying the second information, the first server computer 110 associates the second sensitive information with the first sensitive information.

[0042] At step S406, the first server computer 110 provides the redirection URL in a seventh message M17 to the user device 130. The redirection URL causes the browser of the user device 130 to automatically access the web page associated with the second server computer 120 and identified by the redirection URL.

[0043] In one example, reference Figure 4The described process can be repeated using other server computers in direct communication with the first server computer 110, such that the first server computer 110 links other sensitive information received from the respective other servers with the second sensitive information. Thus, the second sensitive information can be linked to information provided by multiple sources, thereby forming a many-to-one relationship. Consequently, a request to access the second sensitive information submitted to the database of the first server computer 110 can return some or all of the sensitive information previously associated with the second sensitive information by the first server computer 110.

[0044] Figure 5 A user device 130 is shown. The user device 130 may be running a web browser 132, which accesses a web page hosted by the second server computer 120 to access the web page. Figure 4 The data link process is initiated at step S401 of the web browser 132. Figure 4 The web browser 132 accesses the data input page 134 hosted by the first server computer 110 at step S404. The web browser 132 accesses the data input page 134 by providing a session identifier to the first server computer 110, wherein the session identifier is Figure 4 The web browser 132 can then access the data stored in the server computer 110 via the second server computer 120 at step S403. Figure 4 At step S406 , a web page associated with the redirection URL is provided to the user device 130 .

[0045] Use Case - Linked Data

[0046] In some instances, the link or associated sensitive information maintained by the first server computer 110 may be an association between different sources, such as an association between an e-wallet application executing on a user device and a loyalty scheme account of a loyalty scheme provider, and used to process transactions involving the user device.

[0047] Figure 6 Shown according to the example Figure 1 The system 100 and the communication flows transmitted between component parts of the system 100 as part of the process of using link data.

[0048] In this example, system 100 is communicatively coupled to a merchant point of sale (POS) device 150. POS device 150 is associated with a merchant that provides goods and / or services, or access thereto, to a user based on a transaction.

[0049] To initiate this transaction, at step S601, a user device 130, such as a mobile phone, executing an e-wallet application, provides sensitive information to a POS device 150. In one embodiment, the sensitive information includes payment card details or payment account details. At step S602, the POS device 150 transmits the sensitive information and corresponding transaction data to the first server computer 110. In one embodiment, the corresponding transaction data includes the transaction amount. In one embodiment, the POS device 150 communicates with another computing entity that processes the payment and / or transaction data before forwarding it to the first server computer 110.

[0050] The first server computer 110 maintains a database 700 ( Figure 7 ), the database contains sensitive information of multiple users each of whom has an account on the first server computer 110.

[0051] exist Figure 7 In the example of FIG, the database 700 has five columns: record ID; last name; loyalty card ID; payment card ID; and account number, and maintains a plurality of records 730, each corresponding to a respective user. The loyalty card ID column contains first sensitive information 710 previously provided by the second server computer 120 to the first server computer 110 as part of the data linking process (see FIG. Figure 1-Figure 5 The payment card ID column and the account number column contain second sensitive information 720 previously provided by the user device 130 to the first server computer 110 as part of the data linking process (see Figure 1-Figure 5 describe).

[0052] Based on the sensitive information received at step S601, such as payment card details or payment account details, first server computer 110 identifies a record associated with user device 130 from a plurality of records in database 700. In this example, the sensitive information includes payment card identifier "3003." Therefore, identifier "3003" is used as the basis for a search within database 700. A search based on "3003" will identify a record with record ID "3" in database 700. First server computer 110 proceeds to retrieve, from the identified record "3," other sensitive information previously associated with sensitive information "3003" received during the data linking process, such as loyalty card ID number "67832," at least some of which was previously provided by second server computer 120 according to steps 301 and 401 described above.

[0053] Return to Figure 6At step S603, first server computer 110 transmits the transaction data and at least some sensitive information, including at least the loyalty card ID "67832" within the identified record "3," to second server computer 120, where the user of user device 130 has an account. Second server computer 120 identifies the user's account using the loyalty card ID "67832" and updates the user's account based on the transaction data.

[0054] In some examples, after step S603 , the second server computer 120 sends a communication to the user device 130 to notify the user that their account at the second server computer 120 has been updated based on the transaction.

[0055] In other examples, the first server computer 110 may be queried by the second server computer 120 to retrieve details of associations between accounts maintained by the second server computer 120 and one or more accounts maintained by the first server computer 110 , for example.

[0056] Implementation Example

[0057] refer to Figure 1-Figure 7 The described system 100 may have particular application in a transaction system, wherein a first server computer 110 is a payment processing server and a second server computer 120 is a loyalty scheme server. The payment processing server 110 may include, or be in communication with, a transaction service provider and / or issuer server to process transaction and payment data to enable transactions between users and merchants to be authorized and completed. The loyalty scheme server 120 maintains loyalty accounts for multiple users and updates the status of each account based on and in response to transactions conducted by the corresponding user at a merchant location, such as a merchant's POS device, which may be located in a store or implemented as software on the merchant's website. Thus, the loyalty scheme server 120 and the payment processing server 130 have a common interest in user transactions.

[0058] As described above, different sensitive information related to a user and received from different sources may be linked or associated with each other. In the aforementioned transaction system example, the payment processing server 110 receives sensitive information related to the user (e.g., a loyalty scheme identifier) ​​from the loyalty scheme server 120 and receives sensitive information related to the user (e.g., payment card details) from the user device 130, and defines an association between the loyalty identifier and the payment card details, and thus for the user's loyalty account, the user may have a physical or electronic loyalty account card, and for the user's payment account, the user may have a physical or electronic payment card. Therefore, the association between the user's loyalty account and the user's payment account should be understood as the association between the user's loyalty account card and the user's payment account card. In one instance, a user may define a loyalty scheme identifier and a payment card by repeatedly referring to the loyalty scheme server 120. Figure 3 and Figure 4 The method described links multiple payment cards to a single loyalty account card. Figure 7 In the example, the database will contain a single "loyalty card ID" column and multiple "payment card ID" columns, such as "1st payment card ID", "2nd payment card ID", etc.

[0059] As reference Figure 6 and Figure 7 As described, based on the association between different sensitive information associated with a single user, transaction data can be monitored and communicated directly from payment processing server 110 to loyalty scheme server 120, allowing the user's account maintained by loyalty scheme server 120 to be updated while the payment processing server 110 is processing the transaction without requiring user intervention or further communication with user device 130. For example, the user need not interact with the merchant's POS device 150 using their loyalty account card and their payment account card separately. In effect, a single interaction between POS device 150 and the user's payment account card facilitates updating the user's loyalty account, which simplifies the transaction system 100 and its interactions, as described above.

[0060] The transaction data may be sent to the loyalty scheme provider 120 along with sensitive information previously received by the loyalty scheme server 120 (e.g., a loyalty account identifier or a corresponding loyalty card number) to enable the loyalty scheme provider 120 to identify the associated user account. The transaction data may include one or more of the following: a unique payment account or card identifier; a verification code; a transaction identifier; a transaction amount; a transaction currency; a transaction date and time; a merchant descriptor name; and a merchant identifier.

[0061] The loyalty program server 120 analyzes the transaction data to determine any updates to be made to the corresponding user account. This analysis may include comparing the transaction data with merchant-related data stored by the loyalty program server 120 or provided by the merchant's POS device 150 to determine whether the transaction data qualifies as a basis for updating the user's loyalty account.

[0062] In one example, the loyalty scheme provider may update the user account by increasing a counter value based on the received transaction data. For example, a number of points may be awarded to the user's loyalty account based on the monetary value of the transaction.

[0063] Less communication is used within the transaction system 100, and therefore less sensitive information is transmitted within the system, which means that the loyalty scheme server 120 and the transaction system 100 as a whole operate in a more efficient and secure manner. In addition, in some instances, the loyalty scheme server 120 may not be compliant with the Payment Card Industry Data Security Standard (PCI DSS) and may therefore be referred to as being out of "PCI scope." Therefore, the transaction system 100 enables the loyalty scheme server 120 to receive details about transactions from the payment processing server 110 without having to become PCI compliant.

[0064] In the foregoing description, for the purpose of explanation, many specific details of certain examples are set forth. References in the specification to "example" or similar language mean that a particular feature, structure or characteristic described in conjunction with the example is included in at least one example, but not necessarily in other examples.

[0065] Although at least some aspects of the embodiments described herein with reference to the accompanying drawings comprise computer processes executed in a processing system or processor, the invention also extends to computer programs suitable for putting the invention into practice, in particular computer programs on or in a carrier. The program may be in the form of non-transient source code, object code, intermediate source code, and object code, for example in partially compiled form or in any other non-transient form suitable for implementing the process according to the invention. The carrier may be any entity or device capable of carrying the program. For example, the carrier may include a storage medium, such as a solid state drive (SSD) or other semiconductor-based RAM; a ROM, such as a CD ROM or semiconductor ROM; a magnetic recording medium, such as a floppy disk or hard disk; a general optical memory device; etc.

[0066] The above examples should be understood as illustrative. It should be understood that any feature described with respect to any one example may be used alone or in combination with other features described, and may also be used in combination with one or more features of any other example, or in combination with any combination of any other examples. In addition, equivalents and modifications not described above may also be employed.

Claims

1. A computer-implemented method, comprising: receiving, by the first server from the second server, first sensitive information related to a user having an account on the second server; sending, by the first server, a session identifier and a first network token to the second server in response to receiving the first sensitive information, wherein the second server forwards the session identifier to a user device so that the user device can access a data entry page; providing, by the first server, a second network token and the data entry page to the user device, wherein the second network token is used to provide second sensitive information to the first server; receiving, by the first server, the second sensitive information from the user device via the data input page, wherein the second sensitive information is different from the first sensitive information; as well as Associating, by the first server, the first sensitive information with the second sensitive information; The first server and the second server communicate via a first communication channel, and the first server and the user device communicate via a second different communication channel. 2 . The computer-implemented method of claim 1 , wherein the first network token and the second network token are different network tokens.

3. The computer-implemented method of claim 1 , further comprising: Receiving, by the first server, a redirection URL from the second server; as well as The redirection URL is provided by the first server to the user device, so that the browser of the user device automatically accesses resources associated with the second server using the redirection URL after the second sensitive information has been entered into the data entry page.

4. The computer-implemented method of claim 1 , further comprising: accessing the account of the user by the second server; as well as The first sensitive information is obtained.

5. The computer-implemented method of claim 1 , further comprising: An identifier of the user is received by the second server, wherein the identifier is associated with the account of the user.

6. A computer-readable medium comprising instructions executable by a processor to cause the processor to perform the computer-implemented method according to claim 1.

7. A server computer comprising: processor; as well as a computer-readable medium configured to store executable instructions, wherein the server computer is configured to communicate with the user device and the second server computer, and the processor is configured to execute stored executable instructions to: receiving, from the second server computer via the first communication channel, first sensitive information related to a user having an account at the second server computer; sending a session identifier and a first network token to the second server computer in response to receiving the first sensitive information, wherein the second server computer forwards the session identifier to the user device so that the user device can access a data entry page; providing a second network token and the data entry page to the user device, wherein the second network token is used to provide second sensitive information to the server computer; receiving the second sensitive information from the user device via the data entry page and the session identifier, wherein the second sensitive information is different from the first sensitive information; wherein the second sensitive information is received via the data input page and a second different communication channel; as well as The first sensitive information is associated with the second sensitive information.

8. The server computer according to claim 7, configured to: The data entry page is hosted, accessible by the user device and configured to receive the second sensitive information.

9. The server computer of claim 7, wherein the first network token and the second network token are different network tokens.

10. The server computer of claim 7, wherein the processor is configured to execute the stored executable instructions to: receiving a redirection URL from the second server computer via the first communication channel; and The redirect URL is provided to the user device via a second, different communication channel, such that a browser of the user device automatically accesses resources associated with the second server computer using the redirect URL after the second sensitive information has been entered into the data entry page.

11. A system comprising a client computer, a first server and a second server, The first server includes a first processor and a first non-transitory computer-readable medium, wherein the first non-transitory computer-readable medium includes code executable by the first processor to: interacting with the second server and the client computer via corresponding data transmission channels; receiving, from the second server via the corresponding data transmission channel, first sensitive information related to a user having an account at the second server and associated with the client computer; sending a session identifier and a first network token to the second server in response to receiving the first sensitive information, wherein the second server forwards the session identifier to the client computer so that the client computer can access a data entry page; providing a second network token and the data entry page accessible by the client computer to the client computer, wherein the second network token is used to provide second sensitive information to the first server; providing said data entry page accessible by said client computer; receiving, from the client computer via the corresponding data transmission channel, the second sensitive information associated with the user via the data input page and the session identifier, wherein the second sensitive information is different from the first sensitive information; and linking the first sensitive information with the second sensitive information; wherein the client computer includes a third processor and a third non-transitory computer-readable medium, the third non-transitory computer-readable medium including code executable by the third processor to: accessing the data input page to allow the user to input the second sensitive information into the data input page; and providing the second sensitive information to the first server via the corresponding data transmission channel; wherein the second server comprises a second processor and a second non-transitory computer-readable medium, the second non-transitory computer-readable medium comprising code executable by the second processor to: identifying the account of the user; Retrieving the first sensitive information related to the user using the identified account; and The first sensitive information is sent to the first server via the corresponding data transmission channel.

12. The system of claim 11, wherein: The client computer is configured to: The second sensitive information is provided to the first server using the second network token.

Citation Information

Patent Citations

  • Method, System, and Computer Program Product for Communicating Loyalty Program Identification Data

    US20190180310A1