System, method and computer program product for dynamic cryptographic communications

Through dynamic password communication between merchant applications and issuer applications, the problem of MFA adding complexity in electronic payments is solved, enabling a more efficient and simple payment process.

CN118103860BActive Publication Date: 2025-05-09VISA INTERNATIONAL SERVICE ASSOCIATION
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202180101843.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-01
Publication Date
2025-05-09
Estimated Expiration
2041-09-01

AI Technical Summary

Technical Problem

Multi-factor authentication (MFA) increases the number of steps performed by a customer, the number of application calls, and the number of communications between transaction processing systems in electronic payments, resulting in a complexity in the payment process.

Method used

Through dynamic password communication between merchant applications and issuer applications, authorization requests and responses to transaction data are realized, simplifying the payment process.

Benefits of technology

Reduces the number of steps executed by customers to successfully complete the transaction, the number of application calls, and the number of communications between transaction processing systems, and improves the efficiency and user experience of the payment process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118103860B_ABST
    Figure CN118103860B_ABST
Patent Text Reader

Abstract

Systems, methods, and computer program products for dynamic password communication use a merchant application installed on a user device, the merchant application receiving transaction data associated with a transaction at a merchant system. The transaction data can include an account identifier associated with an account at an issuer system. The merchant application determines whether an issuer application associated with the issuer system is installed on the user device based on the account identifier. In response to determining that the issuer application is installed on the user device, the merchant application transmits a request for a dynamic password to the issuer application. The merchant application receives the dynamic password from the issuer application and transmits an authorization request including the account identifier and the dynamic password to the issuer system. The merchant application receives an authorization response from the issuer system authorizing or denying the transaction.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to electronic payment networks and, in some non-limiting embodiments or aspects, to dynamic cryptographic communications for frictionless multi-factor authentication (MFA) for electronic payments. Background Art

[0002] Multi-factor authentication (MFA) (or two-factor authentication) is an electronic authentication method in which a user is authorized only after successfully presenting two or more pieces of proof to an authentication authority, such as a user-controlled password with a dynamic password or a one-time password (OTP), etc. MFA protects users from unknown persons attempting to access and / or use their data (such as personal ID details or financial assets). For example, payment service requirements such as Strong Customer Authentication (SCA) may require the use of MFA to perform electronic payments to increase the security of electronic payments. However, the additional factors required for MFA may increase the number of steps a customer performs to successfully complete a transaction, increase the number of application calls after initiating a transaction, and / or increase the number of communications between transaction processing systems. Summary of the invention

[0003] Accordingly, improved systems, devices, products, apparatus and / or methods for dynamic cryptographic communications are provided.

[0004] According to some non-limiting embodiments or non-limiting aspects, a computer-implemented method is provided, comprising: utilizing at least one processor, utilizing a merchant application installed on a user device, receiving transaction data associated with a transaction at a merchant system, wherein the merchant application is associated with the merchant system, wherein the transaction data includes an account identifier associated with an account at an issuer system; utilizing at least one processor, utilizing the merchant application, determining whether the issuer application associated with the issuer system is installed on the user device based on the account identifier; in response to determining that the issuer application associated with the issuer system is installed on the user device, utilizing at least one processor to transmit a request for a dynamic password from the merchant application to the issuer application; utilizing at least one processor, utilizing the merchant application, receiving the dynamic password from the issuer application; utilizing at least one processor to transmit an authorization request requesting authorization of the transaction from the merchant application to the issuer system, wherein the authorization request includes the account identifier and the dynamic password; and utilizing at least one processor, utilizing the merchant application, receiving an authorization response from the issuer system to authorize or deny the transaction.

[0005] In some non-limiting embodiments or aspects, the method further includes: before receiving transaction data associated with a transaction at a merchant system using a merchant application installed on a user device, transmitting, using at least one processor, a request from the merchant application to the payment gateway system to register the merchant application installed on the user device with the payment gateway system; and in response to transmitting the request to register the merchant application installed on the user device, receiving, using at least one processor, a confirmation from the merchant application to the payment gateway system to register the merchant application with the payment gateway system.

[0006] In some non-limiting embodiments or aspects, determining whether an issuer application associated with an issuer system is installed on a user device includes: transmitting at least a portion of an account identifier from a merchant application to a payment gateway system; receiving, using the merchant application, an identification of the issuer application associated with the issuer system associated with the account identifier from the payment gateway system; and based on the identification, determining, using the merchant application, whether the issuer application associated with the issuer system associated with the account identifier is installed on the user device.

[0007] In some non-limiting embodiments or aspects, the at least one processor transmits the authorization request from the merchant application to the issuer system via the merchant system and the payment gateway system.

[0008] In some non-limiting embodiments or aspects, the at least one processor receives, utilizing a merchant application, an authorization response from an issuer system via a merchant system and a payment gateway system.

[0009] In some non-limiting embodiments or aspects, the method further includes: utilizing at least one processor to receive a request for a dynamic password from a merchant application utilizing an issuer application; and utilizing at least one processor to generate a dynamic password utilizing the issuer application in response to receiving the request for the dynamic password; and utilizing at least one processor to transmit the dynamic password from the issuer application to the merchant application.

[0010] In some non-limiting embodiments or aspects, the method further includes: before receiving transaction data associated with a transaction at a merchant system using a merchant application installed on a user device, transmitting, using at least one processor, a request from an issuer application to an issuer system to register the issuer application installed on the user device with the issuer system, wherein the request to register the issuer application includes a token associated with each of an account identifier and a device identifier associated with the user device, and wherein the token is configured to verify a dynamic password; and in response to transmitting the request to register the issuer application installed on the user device with the issuer system, receiving, using at least one processor, a confirmation of registering the issuer application with the issuer system from the issuer system using the issuer application.

[0011] According to some non-limiting embodiments or aspects, a system is provided, comprising: at least one processor, the at least one processor being programmed and / or configured to: receive transaction data associated with a transaction at a merchant system using a merchant application installed on a user device, wherein the merchant application is associated with the merchant system, wherein the transaction data includes an account identifier associated with an account at an issuer system; determine, using the merchant application, based on the account identifier, whether an issuer application associated with the issuer system is installed on the user device; in response to determining that the issuer application associated with the issuer system is installed on the user device, transmit a request for a dynamic password from the merchant application to the issuer application; receive the dynamic password from the issuer application using the merchant application; transmit an authorization request from the merchant application to the issuer system requesting authorization of the transaction, wherein the authorization request includes the account identifier and the dynamic password; and receive an authorization response from the issuer system authorizing or rejecting the transaction using the merchant application.

[0012] In some non-limiting embodiments or aspects, the at least one processor is further programmed and / or further configured to: transmit, from the merchant application to the payment gateway system, a request to register the merchant application installed on the user device with the payment gateway system before receiving, using the merchant application installed on the user device, transaction data associated with the transaction at the merchant system; and receive, using the merchant application, from the payment gateway system a confirmation to register the merchant application with the payment gateway system in response to transmitting the request to register the merchant application installed on the user device.

[0013] In some non-limiting embodiments or aspects, the at least one processor is programmed and / or configured to determine whether an issuer application associated with the issuer system is installed on the user device by: transmitting at least a portion of an account identifier from a merchant application to a payment gateway system; receiving, using the merchant application, an identification of the issuer application associated with the issuer system associated with the account identifier from the payment gateway system; and based on the identification, determining, using the merchant application, whether the issuer application associated with the issuer system associated with the account identifier is installed on the user device.

[0014] In some non-limiting embodiments or aspects, the at least one processor is further programmed and / or further configured to transmit the authorization request from the merchant application to the issuer system via the merchant system and the payment gateway system.

[0015] In some non-limiting embodiments or aspects, the at least one processor is further programmed and / or further configured to receive, utilizing the merchant application, an authorization response from the issuer system via the merchant system and the payment gateway system.

[0016] In some non-limiting embodiments or aspects, the at least one processor is further programmed and / or further configured to: receive a request for a dynamic password from a merchant application using an issuer application; generate a dynamic password using the issuer application in response to receiving the request for the dynamic password; and transmit the dynamic password from the issuer application to the merchant application.

[0017] In some non-limiting embodiments or aspects, the at least one processor is further programmed and / or further configured to: before receiving transaction data associated with a transaction at a merchant system using a merchant application installed on a user device, transmit from the issuer application to the issuer system a request to register the issuer application installed on the user device with the issuer system, wherein the request to register the issuer application includes a token associated with each of an account identifier and a device identifier associated with the user device, and wherein the token is configured to verify the dynamic password; and in response to transmitting the request to register the issuer application installed on the user device with the issuer system, receive, using the issuer application, a confirmation from the issuer system that the issuer application is registered with the issuer system.

[0018] According to some non-limiting embodiments or aspects, a computer program product is provided, the computer program product comprising at least one non-transitory computer-readable medium, the at least one non-transitory computer-readable medium comprising program instructions, the program instructions, when executed by at least one processor, causing the at least one processor to: receive transaction data associated with a transaction at a merchant system using a merchant application installed on a user device, wherein the merchant application is associated with the merchant system, wherein the transaction data includes an account identifier associated with an account at an issuer system; determine, using the merchant application, based on the account identifier, whether an issuer application associated with the issuer system is installed on the user device; in response to determining that the issuer application associated with the issuer system is installed on the user device, transmit a request for a dynamic password from the merchant application to the issuer application; receive the dynamic password from the issuer application using the merchant application; transmit an authorization request from the merchant application to the issuer system requesting authorization of the transaction, wherein the authorization request includes the account identifier and the dynamic password; and receive an authorization response from the issuer system authorizing or rejecting the transaction using the merchant application.

[0019] In some non-limiting embodiments or aspects, the program instructions, when executed by at least one processor, further cause the at least one processor to: transmit from the merchant application to the payment gateway system a request to register the merchant application installed on the user device with the payment gateway system before receiving, using the merchant application installed on the user device, transaction data associated with the transaction at the merchant system; and receive, using the merchant application, from the payment gateway system a confirmation to register the merchant application with the payment gateway system in response to transmitting the request to register the merchant application installed on the user device.

[0020] In some non-limiting embodiments or aspects, the program instructions, when executed by at least one processor, cause the at least one processor to determine whether an issuer application associated with an issuer system is installed on a user device by: transmitting at least a portion of an account identifier from a merchant application to a payment gateway system; receiving, using the merchant application, an identification of the issuer application associated with the issuer system associated with the account identifier from the payment gateway system; and based on the identification, determining, using the merchant application, whether the issuer application associated with the issuer system associated with the account identifier is installed on the user device.

[0021] In some non-limiting embodiments or aspects, the program instructions, when executed by at least one processor, further cause the at least one processor to: transmit an authorization request from a merchant application to an issuer system via a merchant system and a payment gateway system; and receive an authorization response from the issuer system via the merchant system and the payment gateway system using the merchant application.

[0022] In some non-limiting embodiments or aspects, the program instructions, when executed by at least one processor, further cause the at least one processor to: receive a request for a dynamic password from a merchant application using an issuer application; generate a dynamic password using the issuer application in response to receiving the request for a dynamic password; and transmit the dynamic password from the issuer application to the merchant application.

[0023] In some non-limiting embodiments or aspects, the program instructions, when executed by at least one processor, further cause the at least one processor to: transmit from the issuer application to the issuer system a request to register the issuer application installed on the user device with the issuer system before receiving transaction data associated with a transaction at a merchant system using a merchant application installed on the user device, wherein the request to register the issuer application includes a token associated with each of an account identifier and a device identifier associated with the user device, and wherein the token is configured to verify a dynamic password; and in response to transmitting the request to register the issuer application installed on the user device with the issuer system, receive, using the issuer application, a confirmation from the issuer system that the issuer application is registered with the issuer system.

[0024] Additional non-limiting embodiments or aspects are set forth in the following numbered clauses:

[0025] Clause 1. A computer-implemented method, comprising: utilizing at least one processor, utilizing a merchant application installed on a user device, receiving transaction data associated with a transaction at a merchant system, wherein the merchant application is associated with the merchant system, wherein the transaction data includes an account identifier associated with an account at an issuer system; utilizing the at least one processor, utilizing the merchant application, determining whether an issuer application associated with the issuer system is installed on the user device based on the account identifier; in response to determining that the issuer application associated with the issuer system is installed on the user device, utilizing the at least one processor to transmit a request for a dynamic password from the merchant application to the issuer application; utilizing the at least one processor, utilizing the merchant application to receive the dynamic password from the issuer application; utilizing the at least one processor to transmit an authorization request from the merchant application to the issuer system requesting authorization of the transaction, wherein the authorization request includes the account identifier and the dynamic password; and utilizing the at least one processor, utilizing the merchant application to receive an authorization response from the issuer system authorizing or denying the transaction.

[0026] Clause 2. The computer-implemented method as described in Clause 1 further includes: before utilizing the merchant application installed on the user device to receive the transaction data associated with the transaction at the merchant system, utilizing the at least one processor to transmit from the merchant application to the payment gateway system a request to register the merchant application installed on the user device with the payment gateway system; and in response to transmitting the request to register the merchant application installed on the user device, utilizing the at least one processor to receive from the payment gateway system a confirmation to register the merchant application with the payment gateway system utilizing the merchant application.

[0027] Clause 3. A computer-implemented method as described in Clause 1 or 2, wherein determining whether the issuer application associated with the issuer system is installed on the user device includes: transmitting at least a portion of the account identifier from the merchant application to the payment gateway system; receiving, using the merchant application, an identifier of the issuer application associated with the issuer system associated with the account identifier from the payment gateway system; and based on the identifier, determining, using the merchant application, whether the issuer application associated with the issuer system associated with the account identifier is installed on the user device.

[0028] Clause 4. The computer-implemented method of any of Clauses 1 to 3, wherein the at least one processor transmits the authorization request from the merchant application to the issuer system via the merchant system and the payment gateway system.

[0029] Clause 5. The computer-implemented method of any of Clauses 1 to 4, wherein the at least one processor receives, utilizing the merchant application, the authorization response from the issuer system via the merchant system.

[0030] Clause 6. The computer-implemented method as described in any one of Clauses 1 to 5, further comprising: utilizing the at least one processor to receive the request for the dynamic password from the merchant application utilizing the issuer application; and in response to receiving the request for the dynamic password, utilizing the at least one processor to generate the dynamic password utilizing the issuer application; and utilizing the at least one processor to transmit the dynamic password from the issuer application to the merchant application.

[0031] Clause 7. A computer-implemented method as described in any one of Clauses 1 to 6, further comprising: before receiving the transaction data associated with the transaction at the merchant system using the merchant application installed on the user device, transmitting, using the at least one processor, a request from the issuer application to the issuer system to register the issuer application installed on the user device with the issuer system, wherein the request to register the issuer application includes a token associated with each of the account identifier and a device identifier associated with the user device, and wherein the token is configured to verify the dynamic password; and in response to transmitting the request to register the issuer application installed on the user device with the issuer system, receiving, using the at least one processor, a confirmation from the issuer system to register the issuer application with the issuer system using the issuer application.

[0032] Clause 8. A system comprising: at least one processor, wherein the at least one processor is programmed and / or configured to: receive transaction data associated with a transaction at a merchant system using a merchant application installed on a user device, wherein the merchant application is associated with the merchant system, wherein the transaction data includes an account identifier associated with an account at an issuer system; determine, using the merchant application, based on the account identifier, whether an issuer application associated with the issuer system is installed on the user device; in response to determining that the issuer application associated with the issuer system is installed on the user device, transmit a request for a dynamic password from the merchant application to the issuer application; receive the dynamic password from the issuer application using the merchant application; transmit an authorization request from the merchant application to the issuer system requesting authorization of the transaction, wherein the authorization request includes the account identifier and the dynamic password; and receive an authorization response from the issuer system authorizing or denying the transaction using the merchant application.

[0033] Clause 9. A system as described in Clause 8, wherein the at least one processor is further programmed and / or further configured to: transmit a request from the merchant application installed on the user device to the payment gateway system to register the merchant application installed on the user device with the payment gateway system before receiving the transaction data associated with the transaction at the merchant system using the merchant application installed on the user device; and in response to transmitting the request to register the merchant application installed on the user device, receive confirmation from the payment gateway system using the merchant application to register the merchant application with the payment gateway system.

[0034] Clause 10. A system as described in Clause 8 or 9, wherein the at least one processor is programmed to and / or configured to determine whether the issuer application associated with the issuer system is installed on the user device by: transmitting at least a portion of the account identifier from the merchant application to the payment gateway system; receiving, using the merchant application, an identification of the issuer application associated with the issuer system associated with the account identifier from the payment gateway system; and based on the identification, determining, using the merchant application, whether the issuer application associated with the issuer system associated with the account identifier is installed on the user device.

[0035] Clause 11. The system of any of Clauses 8 to 10, wherein the at least one processor is further programmed and / or further configured to transmit the authorization request from the merchant application to the issuer system via the merchant system and the payment gateway system.

[0036] Clause 12. The system of any of Clauses 8 to 11, wherein the at least one processor is further programmed and / or further configured to receive the authorization response from the issuer system via the merchant system using the merchant application.

[0037] Clause 13. A system as described in any of Clauses 8 to 12, wherein the at least one processor is further programmed and / or further configured to: receive the request for the dynamic password from the merchant application using the issuer application; generate the dynamic password using the issuer application in response to receiving the request for the dynamic password; and transmit the dynamic password from the issuer application to the merchant application.

[0038] Clause 14. A system as described in any of Clauses 8 to 13, wherein the at least one processor is further programmed and / or further configured to: before receiving the transaction data associated with the transaction at the merchant system using the merchant application installed on the user device, transmit from the issuer application to the issuer system a request to register the issuer application installed on the user device with the issuer system, wherein the request to register the issuer application includes a token associated with each of the account identifier and a device identifier associated with the user device, and wherein the token is configured to verify the dynamic password; and in response to transmitting the request to register the issuer application installed on the user device with the issuer system, receive, using the issuer application, from the issuer system a confirmation of the registration of the issuer application with the issuer system.

[0039] Clause 15. A computer program product, comprising at least one non-transitory computer-readable medium, the at least one non-transitory computer-readable medium comprising program instructions, which, when executed by at least one processor, cause the at least one processor to: receive, using a merchant application installed on a user device, transaction data associated with a transaction at a merchant system, wherein the merchant application is associated with the merchant system, wherein the transaction data includes an account identifier associated with an account at an issuer system; determine, using the merchant application, based on the account identifier, whether an issuer application associated with the issuer system is installed on the user device; in response to determining that the issuer application associated with the issuer system is installed on the user device, transmit a request for a dynamic password from the merchant application to the issuer application; receive the dynamic password from the issuer application using the merchant application; transmit an authorization request from the merchant application to the issuer system requesting authorization of the transaction, wherein the authorization request includes the account identifier and the dynamic password; and receive, using the merchant application, an authorization response from the issuer system authorizing or denying the transaction.

[0040] Clause 16. A computer program product as described in Clause 15, wherein the program instructions, when executed by the at least one processor, further cause the at least one processor to: transmit a request from the merchant application installed on the user device to the payment gateway system to register the merchant application installed on the user device with the payment gateway system before receiving the transaction data associated with the transaction at the merchant system using the merchant application installed on the user device; and in response to transmitting the request to register the merchant application installed on the user device, receive confirmation from the payment gateway system using the merchant application to register the merchant application with the payment gateway system.

[0041] Clause 17. A computer program product as described in Clause 15 or 16, wherein the program instructions, when executed by the at least one processor, cause the at least one processor to determine whether the issuer application associated with the issuer system is installed on the user device by: transmitting at least a portion of the account identifier from the merchant application to the payment gateway system; receiving, using the merchant application, an identifier of the issuer application associated with the issuer system associated with the account identifier from the payment gateway system; and based on the identifier, determining, using the merchant application, whether the issuer application associated with the issuer system associated with the account identifier is installed on the user device.

[0042] Clause 18. A computer program product as described in any of Clauses 15 to 17, wherein the program instructions, when executed by the at least one processor, further cause the at least one processor to: transmit the authorization request from the merchant application to the issuer system via the merchant system and the payment gateway system; and utilize the merchant application to receive the authorization response from the issuer system via the merchant system.

[0043] Clause 19. A computer program product as described in any one of Clauses 15 to 18, wherein the program instructions, when executed by the at least one processor, further cause the at least one processor to: receive the request for the dynamic password from the merchant application using the issuer application; generate the dynamic password using the issuer application in response to receiving the request for the dynamic password; and transmit the dynamic password from the issuer application to the merchant application.

[0044] Clause 20. A computer program product as described in any of Clauses 15 to 19, wherein the program instructions, when executed by the at least one processor, further cause the at least one processor to: transmit from the issuer application to the issuer system a request to register the issuer application installed on the user device with the issuer system before receiving the transaction data associated with the transaction at the merchant system using the merchant application installed on the user device, wherein the request to register the issuer application includes a token associated with each of the account identifier and the device identifier associated with the user device, and wherein the token is configured to verify the dynamic password; and in response to transmitting the request to register the issuer application installed on the user device with the issuer system, receive, using the issuer application, from the issuer system a confirmation of the registration of the issuer application with the issuer system.

[0045] These and other features and characteristics of the present disclosure, as well as methods of operation and functions of combinations of related structural elements and parts and economies of manufacture, will become more apparent when considering the following description and the appended claims with reference to the accompanying drawings, all of which form a part of this specification, wherein like reference numerals indicate corresponding parts in the various figures. However, it is to be expressly understood that the figures are for illustration and description purposes only and are not intended as definitions of limitations. Unless the context clearly dictates otherwise, as used in this specification and claims, the singular forms "a", "an", and "the" include plural referents. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] Additional advantages and details are explained in more detail below with reference to exemplary embodiments shown in the schematic drawings, in which:

[0047] Figure 1A and Figure 1B are diagrams of non-limiting embodiments or aspects of environments in which the systems, devices, products, apparatuses, and / or methods described herein may be implemented;

[0048] Figure 2 yes Figure 1A and Figure 1B diagrams of non-limiting embodiments or aspects of one or more devices and / or components of one or more systems;

[0049] Figure 3A and Figure 3B is a flow chart of a non-limiting embodiment or aspect of a process for dynamic cryptographic communications; and

[0050] Figure 4 is a signal flow diagram of a non-limiting embodiment or aspect specific implementation of a process for dynamic cryptographic communications. DETAILED DESCRIPTION

[0051] It should be understood that, except where expressly specified to the contrary, the present disclosure may employ various alternative variations and step sequences. It should also be understood that the specific devices and processes shown in the accompanying drawings and described in the following specification are merely exemplary and non-limiting embodiments or aspects. Therefore, specific dimensions and other physical characteristics associated with the embodiments or aspects disclosed herein should not be considered limiting.

[0052] The aspects, parts, elements, structures, actions, steps, functions, instructions, etc. used herein should not be understood as critical or necessary unless explicitly described as such. Also, as used herein, the articles "a" and "an" are intended to include one or more items, and can be used interchangeably with "one or more" and "at least one". In addition, as used herein, the term "set" is intended to include one or more items (e.g., related items, unrelated items, a combination of related items and unrelated items, etc.), and can be used interchangeably with "one or more" or "at least one". In the case of wishing only one item, the term "one" or similar language is used. Moreover, as used herein, the term "having" etc. is intended to be an open term. In addition, unless otherwise explicitly stated, the phrase "based on" is intended to mean "based at least in part on".

[0053] As used herein, the term "communication" may refer to the reception, acceptance, transmission, transmission, provision, etc. of data (e.g., information, signals, messages, instructions, commands, etc.). A unit (e.g., a device, a system, a component of a device or system, a combination thereof, etc.) communicating with another unit means that the unit is able to directly or indirectly receive information from the other unit and / or transmit information to the other unit. This may refer to a direct or indirect connection (e.g., a direct communication connection, an indirect communication connection, etc.) that is wired and / or wireless in nature. In addition, although the information sent can be modified, processed, relayed and / or routed between the first unit and the second unit, the two units may also communicate with each other. For example, even if the first unit passively receives information and does not actively send information to the second unit, the first unit may communicate with the second unit. As another example, if at least one intermediate unit processes the information received from the first unit and transmits the processed information to the second unit, the first unit may communicate with the second unit.

[0054] Obviously, the systems and / or methods described herein can be implemented in different forms of hardware, software, or a combination of hardware and software. The actual dedicated control hardware or software code used to implement these systems and / or methods does not limit the implementation. Therefore, the operation and behavior of the systems and / or methods are described herein without reference to specific software code, and it should be understood that software and hardware can be designed to implement the systems and / or methods based on the description herein.

[0055] As used herein, the term "transaction service provider" may refer to an entity that receives transaction authorization requests from merchants or other entities and, in some cases, provides payment assurance through an agreement between the transaction service provider and the issuer organization. For example, a transaction service provider may include, for example , or any other entity that processes transactions. The term "transaction processing system" may refer to one or more computing devices operated by or on behalf of a transaction service provider, such as a transaction processing server that executes one or more software applications. A transaction processing system may include one or more processors and, in some non-limiting embodiments, may be operated by or on behalf of a transaction service provider.

[0056] As used herein, the term "account identifier" may include one or more primary account numbers (PANs), tokens, or other identifiers associated with a customer account. The term "token" may refer to an identifier used as a replacement or substitute identifier for an original account identifier such as a PAN. An account identifier may be alphanumeric, or any combination of characters and / or symbols. A token may be associated with a PAN or other original account identifier in one or more data structures (e.g., one or more databases, etc.) such that the token can be used to conduct transactions without directly using the original account identifier. In some instances, an original account identifier such as a PAN may be associated with multiple tokens for different individuals or purposes.

[0057] As used herein, the terms "issuer institution", "portable financial device issuer", "issuer" or "issuer bank" may refer to one or more entities that provide one or more accounts to a user (e.g., a customer, consumer, organization, etc.) to conduct a transaction (e.g., a payment transaction), such as initiating a credit card payment transaction and / or a debit card payment transaction. For example, an issuer institution may provide an account identifier such as a PAN to a user that uniquely identifies one or more accounts associated with the user. The account identifier may be embodied on a portable financial device such as a physical financial instrument (e.g., a payment card), and / or may be electronic and used for electronic payments. In some non-limiting embodiments or aspects, an issuer institution may be associated with a bank identification number (BIN) that uniquely identifies the issuer institution. As used herein, an "issuer institution system" may refer to one or more computer systems operated by or on behalf of an issuer institution, such as a server computer that executes one or more software applications. For example, an issuer institution system may include one or more authorization servers for authorizing payment transactions.

[0058] As used herein, the term "merchant" may refer to an individual or entity that provides goods and / or services or access to goods and / or services to a user (e.g., a customer) based on a transaction (e.g., a payment transaction). As used herein, the term "merchant" or "merchant system" may also refer to one or more computer systems, computing devices, and / or software applications operated by or on behalf of a merchant, such as a server computer that executes one or more software applications. As used herein, a "point of sale (POS) system" may refer to one or more computers and / or peripherals used by a merchant to conduct payment transactions with a user, including one or more card readers, near field communication (NFC) receivers, radio frequency identification (RFID) receivers, and / or other contactless transceivers or receivers, contact-based receivers, payment terminals, computers, servers, input devices, and / or other similar devices that can be used to initiate payment transactions. A POS system may be part of a merchant system. A merchant system may also include a merchant plug-in for facilitating online Internet-based transactions through a merchant webpage or software application. A merchant plug-in may include software that runs on a merchant server or is hosted by a third party to facilitate such online transactions.

[0059] As used herein, the term "mobile device" may refer to one or more portable electronic devices configured to communicate with one or more networks. As an example, a mobile device may include a cellular phone (e.g., a smart phone or a standard cellular phone), a portable computer (e.g., a tablet computer, a laptop computer, etc.), a wearable device (e.g., a watch, glasses, lenses, clothing, etc.), a personal digital assistant (PDA), and / or other similar devices. As used herein, the terms "client device" and "user device" refer to any electronic device configured to communicate with one or more servers or remote devices and / or systems. Client devices or user devices may include mobile devices, network-enabled devices (e.g., network-enabled TVs, refrigerators, thermostats, etc.), computers, POS systems, and / or any other devices or systems capable of communicating with a network.

[0060] As used herein, the term "computing device" may refer to one or more electronic devices configured to process data. In some examples, a computing device may include the necessary components to receive, process, and output data, such as a processor, a display, a memory, an input device, a network interface, etc. A computing device may be a mobile device. For example, a mobile device may include a cellular phone (e.g., a smart phone or a standard cellular phone), a portable computer, a wearable device (e.g., a watch, glasses, lenses, clothing, and / or the like), a PDA, and / or other similar devices. A computing device may also be a desktop computer or other form of non-mobile computer.

[0061] As used herein, the terms "electronic wallet" and "electronic wallet application" refer to one or more electronic devices and / or software applications configured to initiate and / or conduct payment transactions. For example, an electronic wallet may include a mobile device executing an electronic wallet application, and may also include server-side software and / or databases for maintaining and providing transaction data to the mobile device. An "electronic wallet provider" may include an entity that provides and / or maintains electronic wallets for customers, such as Google Android Apple Samsung And / or other similar electronic payment systems. In some non-limiting examples, the issuing bank may be an electronic wallet provider.

[0062] As used herein, the term "payment device" may refer to a portable financial device, an electronic payment device, a payment card (e.g., a credit or debit card), a gift card, a smart card, smart media, a payroll card, a healthcare card, a wristband, a machine-readable medium containing account information, a key chain device or pendant, an RFID transponder, a retailer discount or membership card, a cellular phone, an electronic wallet mobile application, a PDA, a pager, a security card, a computer, an access card, a wireless terminal, a transponder, etc. In some non-limiting embodiments or aspects, a payment device may include volatile or non-volatile memory to store information (e.g., an account identifier, an account holder's name, etc.).

[0063] As used herein, the terms "server" and / or "processor" may refer to or include one or more computing devices that are operated by or facilitate communications and processing by multiple parties in a network environment such as the Internet, but it should be understood that communications may be facilitated through one or more public or private network environments, and that there may be various other arrangements. In addition, multiple computing devices (e.g., servers, POS devices, mobile devices, etc.) that communicate directly or indirectly in a network environment may constitute a "system." As used herein, references to "server" or "processor" may refer to previously described servers and / or processors, different servers and / or processors, and / or combinations of servers and / or processors that are stated to implement previous steps or functions. For example, as used in the specification and claims, a first server and / or first processor stated to implement a first step or function may refer to the same or different servers and / or processors stated to implement a second step or function.

[0064] As used herein, the term "acquirer" may refer to an entity that is licensed by a transaction service provider and / or approved by a transaction service provider to initiate a transaction using a portable financial device of a transaction service provider. An acquirer may also refer to one or more computer systems operated by or on behalf of an acquirer, such as a server computer (e.g., "acquirer server") that executes one or more software applications. An "acquirer" may be a merchant bank, or in some cases, a merchant system may be an acquirer. The transaction may include an original credit transaction (OCT) and an account funds transaction (AFT). The transaction service provider may authorize an acquirer to sign a merchant of the service provider to initiate a transaction using a portable financial device of a transaction service provider. The acquirer may sign a contract with a payment service provider to enable the service provider to sponsor a merchant. The acquirer may monitor the compliance of the payment service provider according to the regulations of the transaction service provider. The acquirer may perform due diligence on the payment service provider and ensure that appropriate due diligence is performed before signing a sponsored merchant. The acquirer may be responsible for all transaction service provider programs that they operate or sponsor. The acquirer may be responsible for the behavior of its payment service provider and the merchant sponsored by it or its payment service provider.

[0065] As used herein, the term "payment gateway" may refer to an entity and / or a payment processing system operated by or on behalf of such an entity, wherein the entity (e.g., a merchant service provider, a payment service provider, a payment facilitator, a payment facilitator contracted with an acquirer, a payment aggregator, etc.) provides payment services (e.g., a transaction service provider payment service, a payment processing service, etc.) to one or more merchants. The payment service may be associated with the use of a portable financial device managed by a transaction service provider. As used herein, the term "payment gateway system" may refer to one or more computer systems, computer devices, servers, server groups, etc. operated by or on behalf of a payment gateway.

[0066] As used herein, the term "application programming interface" (API) may refer to computer code that allows communication between different systems or (hardware and / or software) system components. For example, an API may include function calls, functions, subroutines, communication protocols, fields, etc. that can be used and / or accessed by other systems or other (hardware and / or software) system components.

[0067] As used herein, the term "user interface" or "graphical user interface" refers to a generated display, such as one or more graphical user interfaces (GUIs), with which a user can interact directly or indirectly (e.g., via keyboard, mouse, touch screen, etc.).

[0068] An improved system, device, product, apparatus and / or method for dynamic password communication is provided, which utilizes a merchant application installed on a user device to receive transaction data associated with a transaction at a merchant system, wherein the merchant application is associated with the merchant system, and wherein the transaction data includes an account identifier associated with an account at an issuer system; utilizes the merchant application to determine, based on the account identifier, whether an issuer application associated with the issuer system is installed on the user device; in response to determining that the issuer application associated with the issuer system is installed on the user device, transmits a request for a dynamic password from the merchant application to the issuer application; utilizes the merchant application to receive the dynamic password from the issuer application; transmits an authorization request from the merchant application to the issuer system requesting authorization of the transaction, wherein the authorization request includes the account identifier and the dynamic password; and utilizes the merchant application to receive an authorization response from the issuer system to authorize or deny the transaction.

[0069] In this way, the issuer SDK can be used for dynamic password generation, which can be securely transmitted to the merchant SDK, and the dynamic password can be included in the authorization request for use by the issuer system to verify the transaction, thereby achieving more frictionless multi-factor authentication (MFA) for electronic payment transactions by reducing the number of steps performed by the customer to successfully complete the transaction, reducing the number of application calls after initiating the transaction, and reducing the number of communications between transaction processing systems.

[0070] Reference now Figure 1A and Figure 1B , Figure 1A and Figure 1B 1 is a diagram of an example environment 100 in which the devices, systems, methods, and / or products described herein may be implemented. Figure 1A and Figure 1B As shown, the environment 100 includes a transaction processing network 101, a user device 112, and / or a communication network 114. The transaction processing network may include a merchant system 102, a payment gateway system 104, an acquirer system 106, a transaction service provider system 108, and an issuer system 110. The transaction processing network 101, the merchant system 102, the payment gateway system 104, the acquirer system 106, the transaction service provider system 108, the issuer system 110, and / or the user device 112 may be interconnected (e.g., establish a connection for communication, etc.) via a wired connection, a wireless connection, or a combination of a wired connection and a wireless connection.

[0071] The merchant system 102 may include one or more devices that are capable of receiving information and / or data from the payment gateway system 104, the acquirer system 106, the transaction service provider system 108, the issuer system 110, and / or the user device 112 via the communication network 114, and / or transmitting information and / or data to the payment gateway system 104, the acquirer system 106, the transaction service provider system 108, the issuer system 110, and / or the user device 112 via the communication network 114. The merchant system 102 may include a communication connection (e.g., an NFC communication connection, an RFID communication connection, The merchant system 102 may include a device that receives information and / or data from the user device 112 and / or transmits information and / or data to the user device 112 through the communication connection, etc. For example, the merchant system 102 may include a computing device, such as a server, a server group, a client device, a client device group, and / or other similar devices. In some non-limiting embodiments or aspects, the merchant system 102 may be associated with the merchants described herein. In some non-limiting embodiments or aspects, the merchant system 102 may include one or more devices that can be used by merchants to conduct payment transactions with users, such as computers, computer systems, and / or peripheral devices. For example, the merchant system 102 may include a POS device and / or a POS system.

[0072] The payment gateway system 104 may include one or more devices capable of receiving information and / or data from the merchant system 102, the acquirer system 106, the transaction service provider system 108, the issuer system 110, and / or the user device 112 via the communication network 114, and / or transmitting information and / or data to the merchant system 102, the acquirer system 106, the transaction service provider system 108, the issuer system 110, and / or the user device 112 via the communication network 114. For example, the payment gateway system 104 may include a computing device, such as a server, a server group, and / or other similar devices. In some non-limiting embodiments or aspects, the payment gateway system 104 is associated with the payment gateway described herein.

[0073] The acquirer system 106 may include one or more devices capable of receiving information and / or data from the merchant system 102, the payment gateway system 104, the transaction service provider system 108, the issuer system 110, and / or the user device 112 via the communication network 114, and / or transmitting information and / or data to the merchant system 102, the payment gateway system 104, the transaction service provider system 108, the issuer system 110, and / or the user device 112 via the communication network 114. For example, the acquirer system 106 may include a computing device, such as a server, a server group, and / or other similar devices. In some non-limiting embodiments or aspects, the acquirer system 106 may be associated with an acquirer as described herein.

[0074] The transaction service provider system 108 may include one or more devices capable of receiving information and / or data from the merchant system 102, the payment gateway system 104, the acquirer system 106, the issuer system 110, and / or the user device 112 via the communication network 114, and / or transmitting information and / or data to the merchant system 102, the payment gateway system 104, the acquirer system 106, the issuer system 110, and / or the user device 112 via the communication network 114. For example, the transaction service provider system 108 may include a computing device, such as a server (e.g., a transaction processing server, etc.), a server group, and / or other similar devices. In some non-limiting embodiments or aspects, the transaction service provider system 108 may be associated with a transaction service provider described herein. In some non-limiting embodiments or aspects, the transaction service provider system 108 may include and / or access one or more internal and / or external databases, including transaction data.

[0075] The issuer system 110 may include one or more devices that are capable of receiving information and / or data from the merchant system 102, the payment gateway system 104, the acquirer system 106, the transaction service provider system 108, and / or the user device 112 via the communication network 114, and / or transmitting information and / or data to the merchant system 102, the payment gateway system 104, the acquirer system 106, the transaction service provider system 108, and / or the user device 112 via the communication network 114. For example, the issuer system 110 may include a computing device, such as a server, a server group, and / or other similar devices. In some non-limiting embodiments or aspects, the issuer system 110 may be associated with an issuer organization described herein. For example, the issuer system 110 may be associated with an issuer organization that issues a payment account or instrument (e.g., a credit account, a debit account, a credit card, a debit card, etc.) to a user (e.g., a user associated with the user device 112, etc.).

[0076] In some non-limiting embodiments or aspects, the transaction processing network 101 includes multiple systems in a communication path for processing transactions. For example, the transaction processing network 101 may include a merchant system 102, a payment gateway system 104, an acquirer system 106, a transaction service provider system 108, and / or an issuer system 110 in a communication path (e.g., a communication path, a communication channel, a communication network, etc.) for processing electronic payment transactions. For example, the transaction processing network 101 may process (e.g., initiate, conduct, authorize, etc.) electronic payment transactions via the communication path between the merchant system 102, the payment gateway system 104, the acquirer system 106, the transaction service provider system 108, and / or the issuer system 110.

[0077] The user device 112 may include one or more devices that are capable of receiving information and / or data from the merchant system 102, the payment gateway system 104, the acquirer system 106, the transaction service provider system 108, and / or the issuer system 110 via the communication network 114, and / or transmitting information and / or data to the merchant system 102, the payment gateway system 104, the acquirer system 106, the transaction service provider system 108, and / or the issuer system 110 via the communication network 114. For example, the user device 112 may include a client device, etc. In some non-limiting embodiments or aspects, the user device 112 is capable of communicating with the merchant system 102, the payment gateway system 104, the acquirer system 106, the transaction service provider system 108, and / or the issuer system 110 via a short-range wireless communication connection (e.g., an NFC communication connection, an RFID communication connection, communication connection, etc.) (e.g., from merchant system 102, etc.), and / or transmit information via a short-range wireless communication connection (e.g., to merchant system 102).

[0078] like Figure 1B As shown in , in some non-limiting embodiments or aspects, the user device 112 may include one or more applications associated with the user device 112, such as applications stored, installed and / or executed on the user device 112 (e.g., mobile device applications, native applications for mobile devices, mobile cloud applications for mobile devices, e-wallet applications, peer-to-peer payment transfer applications, merchant applications, issuer applications, etc.).

[0079] For example, the user device 112 may include a merchant application associated with the merchant system 102. The merchant application may be usable by the user to conduct electronic payment transactions with the merchant system 102. A merchant software development kit (SDK) may be integrated into the merchant application on the user device 112. The merchant SDK may be Development Kit, Framework SDK, One of the SDKs, etc.

[0080] As an example, the user device 112 may include an issuer application associated with the issuer system 110. The issuer SDK may be integrated into the issuer application on the user device 112. The issuer SDK may be Development Kit, Framework SDK, SDK, etc. The issuer SDK may be configured to generate a dynamic password or a one-time password (OTP) that can be used by the issuer system 110 to verify an electronic payment transaction using a merchant application on a user device 112 using an account associated with the issuer system 110. For example, the issuer SDK may bind or link a token to the user device 112 (e.g., bind or link to a device identifier associated with the user device 112, etc.), an issuer application installed on the user device 112 (e.g., bind to an application identifier associated with the issuer application, etc.), and / or an account identifier associated with an account, and register the token at the issuer system 110 to verify the dynamic password. As an example, the merchant SDK in the merchant application may be configured to communicate with the issuer SDK in the issuer application, and in response to receiving a request from the merchant SDK, the issuer SDK may securely transmit the dynamic password generated on the issuer application using the issuer SDK to the merchant SDK in the issuer application. In this example, the merchant SDK may provide the issuer system 110 with a dynamic password with an authorization request requesting authorization of the electronic payment transaction.

[0081] The communication network 114 may include one or more wired and / or wireless networks. For example, the communication network 114 may include a cellular network (e.g., a long term evolution (LTE) network, a third generation (3G) network, a fourth generation (4G) network, a code division multiple access (CDMA) network, etc.), a public land mobile network (PLMN), a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a telephone network (e.g., a public switched telephone network (PSTN), a private network, an ad hoc network, an intranet, the Internet, a fiber-optic-based network, a cloud computing network, etc., and / or a combination of these or other types of networks.

[0082] Figure 1A and Figure 1B The number and arrangement of devices and systems shown in the drawings are provided as examples. Additional devices and / or systems, fewer devices and / or systems, different devices and / or systems, or devices and / or systems of the same or different configurations may be present. Figure 1A and 1B The devices and / or systems shown in the figure may be arranged in different ways. In addition, the invention may be implemented in a single device and / or system. Figure 1A and 1BTwo or more devices and / or systems shown, or Figure 1A and 1B The single device and / or system shown may be implemented as multiple distributed devices and / or systems. Additionally or alternatively, a set of devices and / or systems (e.g., one or more devices or systems) of environment 100 may perform one or more functions described as being performed by another set of devices and / or systems of environment 100.

[0083] Reference now Figure 2 , Figure 2 is a diagram of example components of device 200. Device 200 may correspond to one or more devices of merchant system 102, one or more devices of payment gateway system 104, one or more devices of acquirer system 106, one or more devices of transaction service provider system 108, one or more devices of issuer system 110, and / or user device 112 (e.g., one or more devices of a system of user device 112, etc.). In some non-limiting embodiments or aspects, one or more devices of merchant system 102, one or more devices of payment gateway system 104, one or more devices of acquirer system 106, one or more devices of transaction service provider system 108, one or more devices of issuer system 110, and / or user device 112 (e.g., one or more devices of a system of user device 112, etc.) may include at least one device 200 and / or at least one component of device 200. Figure 2 As shown, device 200 may include a bus 202 , a processor 204 , a memory 206 , a storage component 208 , an input component 210 , an output component 212 , and a communication interface 214 .

[0084] The bus 202 may include components that permit communication between components of the device 200. In some non-limiting embodiments or aspects, the processor 204 may be implemented in hardware, software, or a combination of hardware and software. For example, the processor 204 may include a processor (e.g., a central processing unit (CPU), a graphics processing unit (GPU), an accelerated processing unit (APU), etc.), a microprocessor, a digital signal processor (DSP), and / or any processing component that can be programmed to perform a function (e.g., a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), etc.). The memory 206 may include a random access memory (RAM), a read-only memory (ROM), and / or another type of dynamic or static storage device (e.g., flash memory, magnetic memory, optical memory, etc.) that stores information and / or instructions for use by the processor 204.

[0085] Storage component 208 may store information and / or software associated with the operation and use of device 200. For example, storage component 208 may include a hard disk (e.g., magnetic disk, optical disk, magneto-optical disk, solid-state disk, etc.), a compact disk (CD), a digital versatile disk (DVD), a floppy disk, a cassette, a tape, and / or another type of computer-readable medium, and a corresponding drive.

[0086] Input components 210 may include components that permit device 200 to receive information, such as via user input (e.g., a touch screen display, a keyboard, a keypad, a mouse, buttons, switches, a microphone, etc.). Additionally or alternatively, input components 210 may include sensors for sensing information (e.g., a global positioning system (GPS) component, an accelerometer, a gyroscope, an actuator, etc.). Output components 212 may include components that provide output information from device 200 (e.g., a display, a speaker, one or more light emitting diodes (LEDs), etc.).

[0087] The communication interface 214 may include transceiver-like components (e.g., a transceiver, a separate receiver and a transmitter, etc.) that enable the device 200 to communicate with other devices, such as via a wired connection, a wireless connection, or a combination of a wired connection and a wireless connection. The communication interface 214 may permit the device 200 to receive information from another device and / or provide information to another device. For example, the communication interface 214 may include an Ethernet interface, an optical interface, a coaxial interface, an infrared interface, a radio frequency (RF) interface, a universal serial bus (USB) interface, Interface, cellular network interface, etc.

[0088] The device 200 may perform one or more processes described herein. The device 200 may perform these processes based on the processor 204 executing software instructions stored by a computer-readable medium such as the memory 206 and / or the storage component 208. A computer-readable medium (e.g., a non-transitory computer-readable medium) is defined herein as a non-transitory memory device. A non-transitory memory device includes a memory space located within a single physical storage device or a memory space spread across multiple physical storage devices.

[0089] The software instructions may be read into the memory 206 and / or storage component 208 from another computer-readable medium or from another device via the communication interface 214. When executed, the software instructions stored in the memory 206 and / or storage component 208 may cause the processor 204 to perform one or more processes described herein. Additionally or alternatively, hard-wired circuitry may be used in place of or in combination with software instructions to perform one or more processes described herein. Therefore, the embodiments or aspects described herein are not limited to any specific combination of hardware circuitry and software.

[0090] The memory 206 and / or storage component 208 may include a data storage device or one or more data structures (e.g., a database, etc.). The device 200 can receive information from, store information in, transfer information to, or search for information stored in the data storage device or one or more data structures in the memory 206 and / or storage component 208.

[0091] supply Figure 2 The number and arrangement of components shown in FIG. 2 are provided as examples. In some non-limiting embodiments or aspects, the device 200 may include additional components, fewer components, different components, or components in a manner similar to that of FIG. Figure 2 Additionally or alternatively, one set of components (eg, one or more components) of device 200 may perform one or more functions described as being performed by another set of components of device 200.

[0092] Reference now Figure 3A and Figure 3B , Figure 3A and Figure 3B 300 for dynamic password communication. In some non-limiting embodiments or aspects, one or more of the steps of process 300 may be performed by user device 112 (e.g., one or more devices of the system of user device 112) (e.g., completely, partially, etc.). In some non-limiting embodiments or aspects, one or more of the steps of process 300 may be performed by another device or a group of devices (e.g., completely, partially, etc.) that is separate from or includes user device 112, such as merchant system 102 (e.g., one or more devices of merchant system 102), payment gateway system 104 (e.g., one or more devices of payment gateway system 104), acquirer system 106 (e.g., one or more devices of acquirer system 106), transaction service provider system 108 (e.g., one or more devices of transaction service provider system 108, etc.) and / or issuer system 110 (e.g., one or more devices of issuer system 110).

[0093] like Figure 3A As shown in , at step 302, process 300 includes transmitting a request to register a merchant application with a payment gateway system. For example, a user device 112 may transmit a request from a merchant application installed on the user device 112 to the payment gateway system 104 to register the merchant application installed on the user device 112 with the payment gateway system 104.

[0094] Also refer to Figure 4 , Figure 44 is a signal flow diagram of a non-limiting embodiment or aspect of a specific implementation 400 of a process for dynamic cryptographic communication. Figure 4 , at reference numeral 402, the merchant application can request and receive a token (e.g., a JSON web token, etc.) from the merchant system 102, and provide the token associated with the merchant system 102 to the merchant SDK at reference numeral 404. At reference numeral 406, the merchant SDK can transmit the token with a request to register the merchant application with the payment gateway system to the payment gateway system.

[0095] like Figure 3A As shown in , at step 304, process 300 includes receiving a confirmation to register the merchant application with the payment gateway system. For example, user device 112 may receive a confirmation to register the merchant application with payment gateway system 104 using the merchant application in response to transmitting a request to register the merchant application installed on user device 112. As an example and as shown in FIG. Figure 4 As shown in , at reference numeral 408 , the merchant SDK can receive confirmation of registration of the merchant application with the payment gateway system 104 and provide the confirmation to the merchant application at reference numeral 410 .

[0096] like Figure 3A As shown in , at step 306, process 300 includes transmitting a request to register an issuer application with an issuer system. For example, user device 112 may transmit from an issuer application to issuer system 110 a request to register an issuer application installed on user device 112 with issuer system 110. The request to register the issuer application may include a token associated with each of an account identifier and a device identifier associated with user device 112. The token may be configured to verify a dynamic password.

[0097] As an example and Figure 4As shown in FIG. 4 , at reference numeral 412, the issuer application may (e.g., in response to a user logging into the issuer application, etc.) request the issuer SDK to initialize registration with the issuer system 110, and in response thereto, at reference numeral 414, the issuer SDK may transmit to the issuer system 110 a request to register the issuer application installed on the user device 112 with the issuer system 110. In such an example, the issuer SDK may bind or link a token to the user device 112 (e.g., bound to a device identifier associated with the user device 112, etc.), the issuer application installed on the user device 112 (e.g., bound to an application identifier associated with the issuer application, etc.), and / or an account identifier associated with an account associated with the installed issuer application, and transmit the token with the request to register the issuer application installed on the user device 112 with the issuer system 110. The token may be stored and / or registered by the issuer system 110 in association with the account identifier for use in verifying a dynamic password generated by the issuer SDK in association with an electronic payment transaction using the account identifier.

[0098] like Figure 3A As shown in FIG. 3 , at step 308, process 300 includes receiving a confirmation to register the publisher application with the publisher system. For example, user device 112 may receive a confirmation from publisher system 110 to register the publisher application installed on user device 112 with publisher system 110 using the publisher application. As an example and as shown in FIG. Figure 4 As shown in , at reference numeral 416 , the merchant SDK can receive a confirmation from the issuer system 110 that the issuer application is registered with the issuer system 110 .

[0099] like Figure 3A As shown in FIG. 3 , at step 310, process 300 includes receiving transaction data associated with a transaction. For example, user device 112 may receive transaction data associated with a transaction at merchant system 102 using a merchant application installed on user device 112. The merchant application may be associated with merchant system 102. The transaction data may include an account identifier (e.g., PAN, BIN, etc.) associated with an account at issuer system 110.

[0100] As an example and Figure 4 As shown in , at reference numeral 418, the merchant application can receive and / or determine parameters associated with the transaction based on user input from the user to the merchant application, and provide one or more of the parameters (e.g., BIN, etc.) to the merchant SDK at reference numeral 420.

[0101] In some non-limiting embodiments or aspects, the transaction data may include parameters associated with the transaction, such as an account identifier (e.g., PAN, etc.), transaction amount, transaction date and time, type of product and / or service associated with the transaction, currency exchange rate, currency type, merchant type, merchant name, merchant location, merchant, MCG, MCC, etc.

[0102] like Figure 3A As shown in , at step 312, process 300 includes determining whether an issuer application is installed on the user device. For example, the user device 112 may determine, using a merchant application, whether an issuer application associated with the issuer system 110 is installed on the user device 112 based on the account identifier. As an example, the user device 112 may transmit at least a portion of the account identifier from the merchant application to the payment gateway system 104, receive, using the merchant application, an identification of the issuer application associated with the issuer system 110 associated with the account identifier from the payment gateway system 104, and determine, based on the identification, using the merchant application, whether the issuer application associated with the issuer system 110 associated with the account identifier is installed on the user device 112.

[0103] In this example and if Figure 4 , at reference numeral 422, the merchant SDK may transmit the BIN to the payment gateway system 104, and at reference numeral 424, the merchant SDK may receive an identification of an issuer application associated with the BIN (e.g., the name of the issuer application, the name of the issuer associated with the issuer system 110, etc.). At reference numeral 426, the merchant SDK may scan the user device 112 for the identified issuer application and / or verify whether the issuer application includes the issuer SDK integrated within the issuer application.

[0104] like Figure 3A As shown in , at step 314, process 300 includes transmitting a request for a dynamic password. For example, user device 112 may transmit a request for a dynamic password from a merchant application to an issuer application in response to determining that an issuer application associated with issuer system 110 is installed on user device 112. As an example and as shown in Figure 4 As shown in , at reference numeral 428, in response to determining that an issuer application associated with the issuer system 110 is installed on the user device 112 and includes an issuer SDK, the merchant SDK can transmit a request for a dynamic password to the issuer SDK. In this example, the merchant SDK can communicate directly with the issuer SDK.

[0105] like Figure 3BAs shown in FIG. 3 , at step 316, process 300 includes receiving a request for a dynamic password. For example, user device 112 may utilize an issuer application to receive a request for a dynamic password from a merchant application. As an example and as shown in FIG. Figure 4 As shown in , again at reference numeral 428, the issuer SDK may receive a request for a dynamic password from the merchant SDK. In this example, the request for a dynamic password may include an account identifier and / or a device identifier associated with the user device 112.

[0106] like Figure 3B As shown in FIG. 3 , at step 318, process 300 includes generating a dynamic password. For example, user device 112 may generate a dynamic password using an issuer application in response to receiving a request for a dynamic password. As an example and as shown in FIG. Figure 4 As shown in , at reference numeral 430, the issuer SDK can generate a dynamic password based on the account identifier and / or the device identifier. In this example, the dynamic password can be configured to be used for verification using a token registered in association with the account identifier at the issuer system 110.

[0107] like Figure 3B As shown in FIG. 3 , at step 320, process 300 includes transmitting a dynamic password. For example, user device 112 may transmit a dynamic password from an issuer application to a merchant application. As an example and as Figure 4 As shown in , at reference numeral 432, the issuer SDK can transmit the dynamic password to the merchant SDK. In this example, the issuer SDK can communicate directly with the merchant SDK.

[0108] like Figure 3B As shown in FIG. 3 , at step 322, process 300 includes receiving a dynamic password. For example, user device 112 may utilize a merchant application to receive a dynamic password from an issuer application. As an example and as shown in FIG. Figure 4 As shown in , again at reference numeral 432 , the merchant SDK may receive a dynamic password from the issuer SDK.

[0109] like Figure 3B As shown in , at step 324, process 300 includes transmitting an authorization request. For example, user device 112 may transmit an authorization request from a merchant application to issuer system 110 requesting authorization of a transaction. The authorization request may include an account identifier and a dynamic password. In this example, user device 112 may transmit the authorization request from the merchant application to issuer system 110 via merchant system 102, payment gateway system 104, acquirer system 106, and / or transaction service provider system 108 (e.g., via transaction processing network 101, etc.).

[0110] As an example and Figure 4 As shown in FIG. 4 , at reference numeral 434, the merchant SDK may bundle and encrypt the dynamic password with other authentication parameters and / or transaction parameters (e.g., username, password, pin, CVV, PAN, etc.), and at reference numeral 436, provide the bundled and encrypted data to the merchant application. At reference numeral 438, the merchant application may transmit the bundled and encrypted data to the merchant system 102, and at reference numeral 440, the merchant system 102 may transmit the bundled and encrypted data to the payment gateway system 104. At reference numeral 442, the payment gateway system 104 may decrypt the data to recover the dynamic password, and at reference numeral 444, transmit the dynamic password to the transaction service provider system 108 as part of the authorization request. At reference numeral 446, the transaction service provider system 108 may transmit risk data associated with the predicted risk of the transaction together with the authorization request including the dynamic password to the issuer system 110. At reference numeral 448, the issuer system 110 may receive the authorization request and determine whether to authorize or reject the transaction based on the risk data and / or the dynamic password.

[0111] like Figure 3B , at step 326, process 300 includes receiving an authorization response. For example, user device 112 may utilize a merchant application to receive an authorization response from issuer system 110 authorizing or denying the transaction. In such an example, user device 112 may utilize a merchant application to receive an authorization response from issuer system 110 via merchant system 102, payment gateway system 104, acquirer system 106, and / or transaction service provider system 108 (e.g., via transaction processing network 101, etc.).

[0112] As an example and Figure 4 , at reference numeral 450, the issuer system 110 may transmit the authorization response to the transaction service provider system 108, and at reference numeral 452, the transaction service provider system 108 may transmit the authorization response to the payment gateway system 104. At reference numeral 454, the payment gateway system 104 may transmit the authorization response to the merchant system 102, and at reference numeral 456, the merchant system 102 may transmit the authorization response to the merchant application, which may provide the authorization response to the user via the user device 112, including the authorization or denial of the transaction.

[0113] Although embodiments or aspects have been described in detail for purposes of illustration and description, it will be understood that such detail is intended solely for that purpose and that the embodiments or aspects are not limited to the disclosed embodiments or aspects, but, on the contrary, are intended to cover modifications and equivalent arrangements within the spirit and scope of the appended claims. For example, it will be understood that the present disclosure contemplates that, to the extent possible, one or more features of any embodiment or aspect may be combined with one or more features of any other embodiment or aspect. Indeed, any of these features may be combined in a manner not specifically recited in the claims and / or disclosed in the specification. Although each dependent claim listed below may be directly dependent on only one claim, the disclosure of possible implementations includes each dependent claim in combination with each other claim in the claim set.

Claims

1. A computer-implemented method comprising: transmitting, with at least one processor, with an issuer application installed on a user device, to an issuer system a request to register the issuer application installed on the user device with the issuer system, wherein the request to register the issuer application includes a token bound by the issuer application to each of an account identifier associated with an account at the issuer system and a device identifier associated with the user device; receiving, with the at least one processor, from the issuer system a confirmation of registering the issuer application installed on the user device with the issuer system in response to transmitting a request to register the issuer application installed on the user device with the issuer system; receiving, with the at least one processor, transaction data associated with a transaction at a merchant system using a merchant application installed on the user device, wherein the merchant application is associated with the merchant system, wherein the transaction data includes the account identifier associated with the account at the issuer system; scanning, with the at least one processor, the user device with the merchant application installed on the user device to determine whether the issuer application associated with the issuer system is installed on the user device; in response to determining that the issuer application associated with the issuer system is installed on the user device, transmitting, with the at least one processor, a request for a one-time password using the merchant application installed on the user device directly to the issuer application installed on the user device; receiving, with the at least one processor, a request for the one-time password directly from a merchant application installed on the user device using the issuer application installed on the user device; generating, with the at least one processor, the one-time password based on the account identifier and the device identifier using the issuer application installed on the user device, wherein the one-time password is configured for verification using a token registered at the issuer system in association with the account identifier and the device identifier; transmitting, with the at least one processor, the one-time password directly to a merchant application installed on the user device using the issuer application installed on the user device; receiving, with the at least one processor, the one-time password directly from the issuer application using the merchant application installed on the user device; bundling and encrypting, with the at least one processor, the one-time password and the account identifier into an authorization request requesting authorization of a transaction using the merchant application installed on the user device; transmitting, with the at least one processor, the authorization request requesting authorization of the transaction to the issuer system using the merchant application installed on the user device, wherein the authorization request includes the bundled and encrypted account identifier and the one-time password; and An authorization response is received, utilizing the at least one processor, from the issuer system utilizing the merchant application installed on the user device, authorizing or denying the transaction.

2. The computer-implemented method of claim 1 , further comprising: prior to receiving, with the merchant application installed on the user device, the transaction data associated with the transaction at the merchant system, transmitting, with the at least one processor, from the merchant application to a payment gateway system a request to register the merchant application installed on the user device with the payment gateway system; as well as In response to transmitting the request to register the merchant application installed on the user device, receiving, with the at least one processor, a confirmation from the payment gateway system to register the merchant application with the payment gateway system using the merchant application.

3. The computer-implemented method of claim 2, wherein: Scanning the user device with the merchant application installed on the user device to determine whether the issuer application associated with the issuer system is installed on the user device includes: transmitting, using the merchant application installed on the user device, at least a portion of the account identifier to the payment gateway system; receiving, using the merchant application installed on the user device, from the payment gateway system an identification of the issuer application associated with the issuer system associated with the account identifier; and The user device is scanned for the identified issuer application using the merchant application installed on the user device.

4. The computer-implemented method of claim 3, wherein the at least one processor transmits the authorization request from the merchant application to the issuer system via the merchant system and the payment gateway system.

5. The computer-implemented method of claim 3, wherein the at least one processor receives the authorization response from the issuer system via the merchant system utilizing the merchant application.

6. A system comprising: at least one processor programmed and / or configured to: transmitting, with an issuer application installed on a user device, to an issuer system a request to register the issuer application installed on the user device with the issuer system, wherein the request to register the issuer application includes a token bound by the issuer application to each of an account identifier associated with an account at the issuer system and a device identifier associated with the user device; receiving, in response to transmitting a request to register an issuer application installed on the user device with the issuer system, a confirmation from the issuer system to register the issuer application with the issuer system using the issuer application installed on the user device; receiving, with a merchant application installed on the user device, transaction data associated with a transaction at a merchant system, wherein the merchant application is associated with the merchant system, wherein the transaction data includes the account identifier associated with the account at the issuer system; scanning the user device with the merchant application installed on the user device to determine whether the issuer application associated with the issuer system is installed on the user device; in response to determining that the issuer application associated with the issuer system is installed on the user device, transmitting, with the merchant application installed on the user device, a request for a one-time password directly to the issuer application installed on the user device; receiving, with the issuer application installed on the user device, a request for the one-time password directly from a merchant application installed on the user device; generating, using the issuer application installed on the user device, the one-time password based on the account identifier and the device identifier, wherein the one-time password is configured for verification using a token registered at the issuer system in association with the account identifier and the device identifier; transmitting, using the issuer application installed on the user device, the one-time password directly to a merchant application installed on the user device; receiving the one-time password directly from the issuer application installed on the user device using the merchant application installed on the user device; bundling and encrypting the one-time password and the account identifier into an authorization request requesting authorization of a transaction using the merchant application installed on the user device; transmitting, using the merchant application installed on the user device, the authorization request to the issuer system requesting authorization of the transaction, wherein the authorization request includes the bundled and encrypted account identifier and the one-time password; and An authorization response is received from the issuer system authorizing or denying the transaction using the merchant application installed on the user device.

7. The system of claim 6, wherein the at least one processor is further programmed and / or further configured to: prior to receiving, with the merchant application installed on the user device, the transaction data associated with the transaction at the merchant system, transmitting from the merchant application to a payment gateway system a request to register the merchant application installed on the user device with the payment gateway system; and Responsive to transmitting the request to register the merchant application installed on the user device, receiving, using the merchant application, from the payment gateway system a confirmation to register the merchant application with the payment gateway system.

8. The system of claim 7, wherein the at least one processor is programmed and / or configured to scan the user device with the merchant application installed on the user device to determine whether the issuer application associated with the issuer system is installed on the user device by: transmitting, using the merchant application installed on the user device, at least a portion of the account identifier to the payment gateway system; receiving, using the merchant application installed on the user device, from the payment gateway system an identification of the issuer application associated with the issuer system associated with the account identifier; as well as The user device is scanned for the identified issuer application using the merchant application installed on the user device.

9. The system of claim 8, wherein the at least one processor is further programmed and / or further configured to transmit the authorization request from the merchant application to the issuer system via the merchant system and the payment gateway system.

10. The system of claim 8, wherein the at least one processor is further programmed and / or further configured to receive the authorization response from the issuer system via the merchant system utilizing the merchant application.

11. A computer program product comprising at least one non-transitory computer-readable medium, the at least one non-transitory computer-readable medium comprising program instructions that, when executed by at least one processor, cause the at least one processor to: utilizing an issuer application installed on a user device, transmitting to an issuer system a request to register the issuer application installed on the user device with the issuer system, wherein: the request to register the issuer application includes a token bound by the issuer application to each of an account identifier associated with an account at the issuer system and a device identifier associated with the user device; receiving, in response to transmitting a request to register an issuer application installed on the user device with the issuer system, a confirmation from the issuer system to register the issuer application with the issuer system using the issuer application installed on the user device; receiving, with a merchant application installed on the user device, transaction data associated with a transaction at a merchant system, wherein the merchant application is associated with the merchant system, wherein the transaction data includes the account identifier associated with the account at the issuer system; scanning the user device with the merchant application installed on the user device to determine whether an issuer application associated with the issuer system is installed on the user device; in response to determining that the issuer application associated with the issuer system is installed on the user device, transmitting, using the merchant application installed on the user device, a request for a one-time password directly to the issuer application; receiving, with the issuer application installed on the user device, a request for the one-time password directly from a merchant application installed on the user device; generating, using the issuer application installed on the user device, the one-time password based on the account identifier and the device identifier, wherein the one-time password is configured for verification using a token registered at the issuer system in association with the account identifier and the device identifier; transmitting, using the issuer application installed on the user device, the one-time password directly to a merchant application installed on the user device; receiving the one-time password directly from the issuer application installed on the user device using the merchant application installed on the user device; bundling and encrypting the one-time password and the account identifier into an authorization request requesting authorization of a transaction using the merchant application installed on the user device; transmitting, using the merchant application installed on the user device, the authorization request to the issuer system requesting authorization of the transaction, wherein the authorization request includes the bundled and encrypted account identifier and the one-time password; and An authorization response is received from the issuer system authorizing or denying the transaction using the merchant application installed on the user device.

12. The computer program product of claim 11, wherein the program instructions, when executed by the at least one processor, further cause the at least one processor to: prior to receiving, with the merchant application installed on the user device, the transaction data associated with the transaction at the merchant system, transmitting from the merchant application to a payment gateway system a request to register the merchant application installed on the user device with the payment gateway system; and Responsive to transmitting the request to register the merchant application installed on the user device, receiving, using the merchant application, from the payment gateway system a confirmation to register the merchant application with the payment gateway system.

13. The computer program product of claim 12, wherein the program instructions, when executed by the at least one processor, cause the at least one processor to scan the user device with the merchant application installed on the user device to determine whether the issuer application associated with the issuer system is installed on the user device by: transmitting at least a portion of the account identifier to the payment gateway system with the merchant application installed on the user device; receiving, using the merchant application installed on the user device, from the payment gateway system an identification of the issuer application associated with the issuer system associated with the account identifier; as well as The user device is scanned for the identified issuer application using the merchant application installed on the user device.

14. The computer program product of claim 13, wherein the program instructions, when executed by the at least one processor, further cause the at least one processor to: transmitting the authorization request from the merchant application to the issuer system via the merchant system and the payment gateway system; and The authorization response is received, utilizing the merchant application, from the issuer system via the merchant system.

Citation Information

Patent Citations

  • Method And System For Authorizing A Transaction Using A Dynamic Authorization Code

    US20080040285A1