Integrated global tokenization system

By integrating a global tokenization coordination middleware, the data governance and compatibility issues of POS systems in different jurisdictions were resolved. This enabled secure coordination and real-time processing of credit card information and loyalty data, meeting legal and regulatory requirements and simplifying the complexity and integration of merchant systems.

CN121002525APending Publication Date: 2025-11-21FREEDOMPAY INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480026262.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-04-21
Filing Date
2024-04-19
Publication Date
2025-11-21

AI Technical Summary

Technical Problem

Existing POS systems face complex data governance, integration, and compatibility issues when storing and coordinating credit card information, especially under the legal and regulatory restrictions of different jurisdictions, making it difficult to securely transmit and store credit card account information and loyalty data.

Method used

An agnostic middleware solution is adopted, integrating a global tokenization coordination middleware. Through multiple interfaces and protocols, it seamlessly integrates POS, POI devices, network token service providers, and managed payment platforms to achieve secure coordination of global tokenization and loyalty data. This ensures that credit card account information is processed within a restricted jurisdiction and, when necessary, transmits merchant-specific global tokens across regions.

Benefits of technology

It reduces the complexity and number of integrations in merchant systems, improves security and data governance compliance, achieves seamless coordination and real-time user account functionality across different payment environments, and meets various legal and regulatory requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121002525A_ABST
    Figure CN121002525A_ABST
Patent Text Reader

Abstract

An integrated sales system platform includes a point-of-sale application and middleware to perform global tokenized coordination, which, in combination, provides credit card reading device-agnostic global token and provisioning operations. The middleware includes communication interfaces, each of which corresponds to a particular communication protocol. The middleware receives a token creation request from the point-of-sale application and transmits directly to the point-of-interaction payment device via one of the communication protocols to receive and securely encrypt the credit card number, and then sends the information to the hosted network token provisioning system to request the network token. Upon receiving the network token, the middleware communicates directly with the global merchant-tokenized host via one or more protocols to create a merchant-specific token that will be returned by the middleware to the point-of-sale client for use as a card archive payment method.
Need to check novelty before this filing date? Find Prior Art

Description

BACKGROUND

[0001] In the secure payment industry, there are two main types of channel categories. The first is considered customer / card present, which is physically on the premises or store. The second is considered customer / card not present, which is facilitated through a hosted online ecom or mobile application system. These systems are often referred to as point of sale (POS) not only to facilitate items, prices, inventory, and the creation of orders with the items the customer is purchasing, but also to have to support the execution and recording of payment for each of those orders. Many POS systems also have to store credit card account and account information for future purchases by the customer or merchant themselves. In a store customer, due to various international network credit card schemes requirements, must present their credit card to be read by a point of interaction (POI) device manufactured and certified to read a credit card inserted into the POI device and communicate with the microchip through near field communication (NFC), read a credit card swiped over the POI device through a magnetic stripe reader, or read a credit card manually entered using digital buttons on the POI device. The POI device securely encrypts the credit card information. The POI device can also be configured to prompt and securely obtain and encrypt a customer personal identification number (PIN) and provide this information to a software application that formulates a message and transmits the message to a hosted payment platform (also known as a gateway) or directly to the merchant's acquiring bank to coordinate payment from the customer's credit card account to the merchant. Some providers provide point-to-point encryption (P2PE) solutions to merchants that are Payment Card Industry (PCI) validated, which involves a secure and certified POI device that uses complex encryption methods to encrypt primary account number (PAN; e.g., credit card number) information that can only be decoded by a certified and secure hardware security module (HSM) within a PCI validated hosted environment. The payload is encrypted from the point of reading the card through the network to the point of the hosted platform to securely coordinate the payment.

[0002] Payments are coordinated differently with ecom and mobile systems. The customer manually enters their credit card into an ecom or mobile application, or uses their digital wallet to initiate a selection of a previously stored credit card, and the ecom or mobile system formulates a message and sends it to a hosted payment platform or acquirer. SUMMARY

[0003] According to one aspect, an integrated sales system platform having integrated global tokenization orchestration middleware includes a workstation comprising one or more processors; and a memory system comprising a plurality of instructions executable by the one or more processors to provide a point of sale (POS) application and middleware. Source code of the middleware can be configured to compile and run on various workstation operating systems. The middleware can include a plurality of communication interfaces, each of the plurality of communication interfaces corresponding to one of a plurality of communication protocols, and the middleware is POS and point of interaction (POI) device agnostic. The workstation can be configured to interface with a hosted platform and a hosted network token provisioning system, the hosted platform to perform both payment and global tokenization services, internally or externally of a restricted jurisdiction, for primary account number (PAN) export and storage. The middleware can be configured to receive a request from the POS application to obtain a global token from the hosted platform, receive a request to obtain a global token via one of the communication protocols by a POI device that reads and encrypts credit card data, and receive the request to obtain the global token and forward the request to obtain the global token to an in-region hosted system to decrypt the encrypted credit card data using a hardware security module that provisions network tokens for international credit card schemes. The middleware can also be configured to receive an international credit card scheme network token via one of the communication protocols, execute a request to the hosted platform provisioning merchant specific global tokens using the international credit card scheme network token, and receive the merchant specific global token and return the merchant specific global token to the POS application for storage and future use to orchestrate future payment authorization transactions via the merchant specific global token.

[0004] According to another aspect, a computer-implemented method of providing a credit card account linked to a user account within middleware of an integrated sales system platform can include sending a plurality of instructions to a hosted platform for merchant specific global token provisioning to identify a user account linked to a credit card account obtained from a point of interaction (POI) device using a network token when a token is requested, and subsequently communicating user account and payment information to the platform. The computer-implemented method can also include interrogating the user account and payment information to determine whether the user account is eligible to obtain accrual units and / or is eligible to redeem units based on information returned to the hosted platform, receiving information from the hosted platform regarding a plurality of options for accrual and / or redemption, and presenting one or more of the options to a customer associated with the credit card account.

[0005] According to one aspect, a computer program product includes a storage medium embodying computer program instructions that, when executed by one or more processors, cause the one or more processors to implement receiving, from a point of sale (POS) application, a request to obtain a global token from a hosting platform; receiving, via a communication protocol of a plurality of communication protocols supported by a middleware, a request to obtain a global token by a point of interaction (POI) device that reads and encrypts credit card data; and receiving the request to obtain a global token and forwarding the request to obtain a global token to an in-region hosting system to decrypt the encrypted credit card data using a hardware security module that provisions international credit card scheme network tokens. The computer program instructions, when executed by the one or more processors, can also cause the one or more processors to implement receiving, via one of the communication protocols, an international credit card scheme network token, executing the request to the hosting platform to provision a merchant-specific global token using the international credit card scheme network token, receiving the merchant-specific global token, and returning the merchant-specific global token to the POS application for storage and future use to coordinate future payment authorization transactions via the merchant-specific global token.

[0006] The foregoing features and advantages of the present disclosure, as well as other features and advantages, will be more fully understood and appreciated upon consideration of the following detailed description, with reference to the accompanying drawings, in which:

[0007] Brief Description of Several Views of the Drawings

[0008] The subject matter of the present disclosure is particularly pointed out and distinctly claimed in the concluding portion of the specification. The foregoing and other features and advantages of the embodiments herein will become more fully apparent from the following detailed description, in conjunction with the accompanying drawings, in which:

[0009] Figure 1 depicts a system in accordance with one or more embodiments;

[0010] Figure 2 depicts a process flow of an in-store POS system integrated to a middleware within a restricted jurisdiction as a PCI validated P2PE solution in accordance with one or more embodiments;

[0011] Figure 3 depicts a process flow of an in-store POS system integrated to a middleware within a restricted jurisdiction as a PCI validated P2PE solution in accordance with one or more embodiments;

[0012] Figure 4 depicts a process flow of an in-store POS system integrated to a middleware within a restricted jurisdiction as a PCI validated P2PE solution in accordance with one or more embodiments;

[0013] Figure 5Process flow of an online POS system (ecom or mobile) integrated to middleware outside of a restricted jurisdiction is depicted in accordance with one or more embodiments;

[0014] Figure 6 Process flow of a POS system integrated to middleware to process payments with global tokens within a restricted jurisdiction is depicted in accordance with one or more embodiments;

[0015] Figure 7 Process flow of an online POS system integrated to middleware to coordinate payments within a restricted jurisdiction is depicted in accordance with one or more embodiments;

[0016] Figure 8 Process flow of an online POS system integrated to middleware to coordinate payments regardless of location is depicted in accordance with one or more embodiments;

[0017] Figure 9 Process flow of a POS system integrated to middleware to coordinate earning or redemption units linked to a PAN within a restricted jurisdiction is depicted in accordance with one or more embodiments;

[0018] Figure 10 Process flow of an online POS system integrated to middleware to coordinate earning or redemption units linked to a PAN within a restricted jurisdiction is depicted in accordance with one or more embodiments;

[0019] Figure 11 Process flow of a POS system integrated to middleware to coordinate earning or redemption units linked to a PAN is depicted in accordance with one or more embodiments; and

[0020] Figure 12 Process flow is depicted in accordance with one or more embodiments.

[0021] The diagrams depicted herein are illustrative. The diagram and / or operations described herein can vary from what is described. For example, the acts described can be performed in a different order than described and / or additional, fewer and / or different acts can be performed. Additionally, the term coupled and variations thereof describes having a communications path between two elements and does not imply a direct connection between the elements coupled DETAILED DESCRIPTION

[0022] The present disclosure relates to a fully integrated omnichannel commerce platform comprising a plurality of computer systems and software that, in combination, provide a global token solution that is POS agnostic, payment device agnostic, and payment acquirer agnostic within payment orchestration, and facilitates removal of merchants' systems from PCI scope in both on-premise and off-premise payment scenarios, while also complying with various global jurisdictional PAN handling laws and policies for transmitting and storing such data. Payment orchestration is a mechanism for enabling different (e.g., independent and separate) systems that are not normally in communication or interaction to be fully compatible and integrated without requiring extensive on-board programming. Embodiments disclosed herein can include systems, apparatuses, methods, and / or computer program products for enabling POS, POI device, and platform integration (which can be referred to herein as integrated sales systems).

[0023] To store a credit card in a POS, a merchant has two options, to store the PAN itself or to store a token that represents the PAN. To remain within reduced PCI security scope, a specific PCI validated index token must be used. Obtaining a token requires additional steps and technology integration from the POS to the hosting payment platform, acquirer, or separate certified token provider. Credit card issuing banks have partnered with many international card schemes to create and issue merchant specific network tokens. While these tokens reduce PCI scope, they are formatted in the same way as the PAN and, due to POS constraints that prevent storage of the PAN, the network token will not be able to be stored in the system as it will not pass system checks and constraints, thereby preventing the PAN or network token from being stored. Therefore, a merchant specific global index token can be used where the network token and / or PAN is linked to the token for payment orchestration. The network token can be used to facilitate payments, and in the same way, the PAN can be used in other scopes. In many countries, there are regional jurisdictions that have laws and regulations governing the transmission and storage of PAN data. In some jurisdictions, a PAN cannot be transmitted outside of that jurisdiction for any reason, including performing a payment or archiving the PAN for future use. In some regulations, the system is not allowed to archive the PAN for future use, even if the PAN was entered by the customer themselves through an ecom POS. In other scopes, new legislation and regulations are changing and being passed to further limit the use and storage of PAN information to prevent fraud and misuse of customers' credit card accounts. This limits the ability to store the PAN and create a token to be stored in the POS system for future use, and greatly increases the complexity whereby the POS that uses the token to orchestrate payments is likewise constrained.

[0024] Various types of user accounts can have a link established between the PAN and the user account to support purchases and other types of transactions. As an example, many loyalty providers work with merchants to link a PAN to a loyalty account for a particular customer, and when coordinating a payment, can also provide the customer the ability to earn or redeem loyalty units during that purchase experience. Issuing banks provide a primary account reference (PAR) linked to the PAN, as well as any device tokens obtained from a digital purse (DPAN) or network token that a customer can have. This PAR value is typically obtained when a network token is provisioned. Using the PAR is a common way to identify that any token that is archived or used in a payment has the same PAR value (linked to the same PAN) and can then be linked to a loyalty account. However, using the PAR value to likewise identify a loyalty account for a token also adds more complex data storage, system integration, and communication.

[0025] Accordingly, a POS system can coordinate multiple specific integrations and communications to provision a network token, securely transmit it outside of a restricted jurisdiction, exchange it for a PCI-validated globally unique merchant token, and save it for future use in the POS. Additionally, the PAR value linked to a loyalty account, also linked to the network token and the merchant-specific global token, is stored in addition to increase complexity for the addition of integrated and seamless loyalty offerings through the POS.

[0026] There are thousands of POS systems, hundreds of POI device manufacturers, thousands of hosted payment platforms or acquirers, and thousands of loyalty providers (and / or other types of user account support systems). To coordinate payment and / or loyalty provisioning, and securely tokenize, technical software integration is required between all systems and POI devices. This presents substantial challenges and limitations for each of the merchant, POS provider, hosted payment platform, acquirer, and loyalty provider. The software enhancements required to integrate the systems together are substantial, even for one end-to-end system (POS to device to network token provider to payment platform to loyalty provider). This document also describes an agnostic software middleware "integrated global tokenization middleware and platform" that coordinates seamless technical and functional integration across multiple interfaces with multiple POS, ecom / mobile POS, POI devices, loyalty providers, network token providers, and hosted payment platforms. This agnostic middleware coupled with a hosted service can be integrated by the POS to seamlessly coordinate global tokenization and linked loyalty across many providers. Such a solution can include integration to multiple jurisdictional network token providers to coordinate global tokenization whereby the PAN remains in the jurisdiction and a national card scheme network token can be sent and stored outside the jurisdiction in exchange for a merchant specific globally unique PCI validated index token that can be stored in the POS.

[0027] An agnostic middleware solution with multiple interfaces and protocols is integrated into one of any POS systems to facilitate agnostic and seamless integration into one of multiple POI devices supporting multiple protocols and card reading capabilities, one of multiple network token service providers supporting multiple protocols, one of multiple acquirers and / or payment service providers supporting multiple protocols to provide merchant specific global tokenization for payment orchestration, including a point-to-point encryption (P2PE) solution with POI integration and PCI validation. The middleware solution with integrated hosted platform services can be hosted and located within a restricted data management jurisdiction (“restricted jurisdiction”) ensuring that PANs are not externally transmitted or stored outside the restricted jurisdiction, ensuring that merchants comply with legal regulations for PAN usage and storage. Advantages of this solution can enable any POS to integrate into middleware using one of multiple protocols within one of multiple interfaces generalizing the POS from multiple POI devices, multiple hosted payment platforms and acquirer providers, and multiple network token service providers to obtain a global token for performing payments globally in any region. The same middleware solution can support multiple credit card input mechanisms, including manual entry by a user and digital wallet integration and communication. The same middleware can also support non-integrated POS orchestration whereby a user (e.g., POS operator) can securely obtain a global token with a user interface equipped with the middleware, enabling the user to receive the token and then manually enter it into the POS system. In all cases, the same middleware can be used to securely perform de-tokenization requests to obtain an underlying network token for payment orchestration as an integrated component of one or more of POS / ecom / mobile, POI devices, network service providers, and hosted payment platforms / acquirers.

[0028] Additional orchestration to seamlessly enable user account functionality in real-time with PAR values within the orchestration of payments and tokenization can increase utility for consumers and merchants. Additionally, with a hosted platform and middleware, real-time earning or redemption linked to units of the original underlying PAN for POS payments can be provided with one of multiple integrations to the system.

[0029] According to aspects described herein, the constraints and burdens on merchants and their sales systems in terms of complexity, number of integrations, proper security, data governance and regulatory compliance, enablement and timeliness, and overall technical challenges can be greatly reduced or eliminated.

[0030] Turning now to Figure 1FIG. 1, shows an integrated sales system (system 100) for implementing the teachings herein, in accordance with one or more embodiments. Generally, system 100 implements and manages payments for items, food, and / or services, whether a card is presented for payment or manually entered.

[0031] System 100 has a workstation 201. Workstation 201 can be an electronic computer framework that includes and / or employs any number and combination of computing devices and networks utilizing various communication technologies, as described herein. Workstation 201 can be scalable, extensible, and modular, with the ability to change some features according to different services or reconfigure independent of other features. Examples of workstation 201 include, but are not limited to, a desktop computer, a laptop computer, a dedicated property management computer terminal, a point-of-sale computer, a tablet, a smartphone, and / or a computer hosted in a data center or store acting as a server. Workstation 201 includes a system bus 102 that couples processor 103 to memory 104 and various other components.

[0032] Processor 103 includes any processing hardware, software, or combination of hardware and software utilized by workstation 201 that executes computer-readable program instructions by performing arithmetic, logical, and / or input / output operations. For example, processor 103 (also referred to as processing circuitry, a microprocessor, or a computing unit) can include one or more central processing units. Examples of processor 103 include, but are not limited to: an arithmetic logic unit that performs arithmetic and logical operations; a control unit that fetches, decodes, and executes instructions from memory; and an array unit that utilizes multiple parallel computing elements.

[0033] Memory 104 is an example of a tangible device (e.g., a computer- readable storage medium) that retains and stores computer-readable program instructions (such as a computer program product) for use by processor 103 to perform the operations of the embodiments herein. A computer-readable storage medium can be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A computer-readable storage medium, as used herein, is not to be construed as being transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission media (e.g., light pulses passing through a fiber-optic cable), or electrical signals transmitted through a wire.

[0034] Memory 104 can also include a variety of computer system readable media. Such media can be any available media that is accessible by processing device and includes both volatile and non- volatile media, removable and non-removable media. Computer-readable storage media, as used herein, includes both volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. In this regard, computer-readable storage media includes, but is not limited to, RAM, ROM, EEPROM, solid state drives ("SSDs"), flash memory, phase-change memory ("PCM"), optical disks (e.g., compact disks, digital versatile disks, Blu-ray disks, etc.), magnetic disks (e.g., internal hard disks or removable disks), or other magnetic media, other optical media, or any other medium that can be used to store and access computer-readable instructions, data structures, program modules or other data. Figure 1As shown, the memory 104 includes read-only memory (ROM) and random access memory (RAM). The memory is coupled to the system bus 102 and can include a basic input / output system (BIOS) that controls certain basic functions of the system 100. The RAM is a read and write memory coupled to the system bus 102 for use by the processor 103. The workstation 201 also includes a hard disk 107, which is another example of a tangible device (e.g., computer-readable storage medium) that stores computer-readable program instructions that are executable by the processor 103. A non-exhaustive list of more specific examples of computer-readable storage media (i.e., memory 104) includes portable computer disks, erasable programmable read-only memories (EPROMs or Flash memories), static random access memories (SRAMs), portable compact disc read-only memories (CD-ROMs), digital versatile disks (DVDs), memory sticks, and any suitable combination thereof. The hard disk 107 stores software 108a, 108b (which can be collectively referred to as software 108). The software 108 is stored as instructions that are executed by the processor 103 within the system 100 (which accordingly performs operations and / or processes with the operating system, one or more application programs, other program modules, and data 109). The data 109 includes collections of values of qualitative or quantitative variables organized in various data structures to support operations of and used by the software 108. The software 108 can execute entirely on the workstation 201, partially on the workstation 201, as a stand-alone software package, partially on the workstation 201 and partially on a remote computer or server, or entirely on the remote computer or server. Thus, the software 108 and data 109, as configured herein, are necessarily rooted in the computational capabilities of the processor 103, the workstation 201, and / or components connected to it to overcome and solve the herein-described shortcomings of conventional multi-device POS or point-of-purchase systems conventional middleware. In this regard, the software 108 and data 109 replace conventional middleware and improve the computational operations of the processor 103, the workstation 201, and / or components connected thereto, thereby reducing errors and compatibility issues in conventional multi-device POS or point-of-purchase systems (thereby improving the efficiency of the system 100). Figure 1

[0035] Figure 1 ​The system 100 includes one or more adapters (e.g., hard disk controller, network adapter, graphics adapter, etc.) that interconnect and support communication between the processor 103, the memory 104, the hard disk 107, and other components of the system 100 (e.g., peripherals and external devices). In one or more embodiments, the one or more adapters can be connected to one or more I / O buses that are connected to the system bus 102 via an intermediate bus bridge, and the one or more I / O buses can utilize a common protocol, such as Peripheral Component Interconnect.

[0036] As shown, the workstation 201 includes a communication adapter 121 and an interface adapter 122. The communication adapter 121 interconnects the workstation 201 with the network 150 of the system 100, enabling the workstation to communicate with other systems, devices, data, and software, such as the payment gateway 402 and the POS server 199. The interface adapter 122 interconnects the workstation 201 with the POI device 160. The POI device 160 includes a processor 163, a memory 164, a reader 166, and a display 167. The processor 163 and the memory 164 can be similar to the processor 103 and the memory 104 described herein. The POI device is a PCI-validated device approved within the PCI-validated P2PE solution. Thus, the POI device securely reads and encrypts PAN data within a secure module within the device, a process that is coordinated between the reader 166, the processor 163, and the memory 164. The payment gateway 402, the token subsystem 401, the HSM 403, the hosting system 501, the HSM 502, the POS server 199, and / or the POI device 160 (as the workstation 201) can be an electronic computer framework that includes and / or employs any number and combination of computing devices and networks utilizing various communication technologies, while being scalable, extensible, and modular.

[0037] The payment gateway 402, for example, represents a computer system of a payment service provider and / or a bank that authorizes direct debit card or credit card payment processing for businesses, retailers, vendors, service providers, etc., whether online or in-store. The token sub-system represents a computing service that securely stores PAN data in a PCI DSS (Payment Card Industry Data Security Standard) verified and audited environment, computes a PCI-verified merchant-specific index-style globally unique token, and returns the token to the requesting system. The POS server 199 provides external processing power, data storage, networking, and graphical user interfaces to the system 100 for implementing payments and completing sales operations for purchasing items, services, etc. The POI device 160 can be any payment terminal that reads and encrypts credit card information. The token sub-system 401 represents a computing service within the platform 400 to securely store PAN and network token data, then compute and return a merchant-specific globally unique token. The hosted system 501 with HSM 502 represents a computing service within the system that securely decrypts encrypted PAN and PIN data, stores the PAN, and provisions an international credit card scheme merchant-specific network token and returns the token to the requesting system. The hosted system 501 also provides additional services specific to network tokenization, including but not limited to returning a payment account reference (PAR), exchanging a network token with a device token, exchanging a network token with a merchant-specific globally unique token, and returning attributes about the network token (BIN (Bank Identification Number) of the PAN, account type (credit, debit), issuing bank information, and card image). The hosted system 501 can also be located within a restricted data governance jurisdiction where PAN data is prohibited from being sent over the network to locations outside the jurisdiction and stored outside the jurisdiction. Note that the payment gateway 402, POS server 199, POI device 160, token sub-system 401, and hosted system 501 are distinct (e.g., independent and separate) systems that typically do not communicate or interact without conventional middleware, which has inherent technical compatibility and integration issues that require extensive on-board programming to integrate all systems and sub-systems to facilitate payment operations, tokenization, and PAN-linked loyalty. More specifically, each of the payment gateway 402, POS server 199, POI device 160, token sub-system 401, and hosted system 501 can require different communication protocols that are incompatible with the communication protocols of the other sub-systems. In turn, the technical effects and benefits of the middleware 250 include providing device-agnostic payment operations to improve the computing operations of the processor 103, workstation 201, payment gateway 402, POS server 199, token sub-system 401, hosted system 501, POI device 160, thereby eliminating concerns and added complexity of the software 108 and POS software 200 and the POS server 199.

[0038] According to one or more embodiments, the workstation 201 can be connected to the payment gateway 402, the token subsystem 401, the hosting system 501, and the POS server 199 through any type of network 150, including a local area network (LAN) or a wide area network (WAN), the Internet, a virtual private network, or can be connected to external computers (e.g., through the use of an Internet service provider's Internet). In one or more embodiments, the internal operations of the software 108 and data 109 can be implemented on the network 150 to provide platform as a service, software as a service, and / or infrastructure as a service. The middleware 250 is unique software that integrates separate systems together to coordinate tokenization and linked loyalty. The reader 166 can be, for example, a device that interfaces with a payment card to read a credit card PAN and data to facilitate an electronic funds transfer from that credit card account (e.g., via a tap (near field communication), insertion, swipe, or manual card information entry action) to a merchant's account. The display 167 can include any visual device for providing a user interface, and can include, for example, a graphics controller to provide graphics capabilities such as the display and management of a graphical user interface.

[0039] Turning now to Figure 2 , a system 1002 for implementing card present payments and tokenization processes is depicted that is fully integrated between the POS 200, the middleware 250, the POI device 160, the hosting system 501, and the platform 400, securely sending the PAN 500 or DPAN 503 when a credit card is read and encrypted, utilizing point-to-point encryption from the point of entry to the secure HSM 502, exchanging a network token 600 and a PAR 601 within a restricted jurisdiction, then the network token and the PAR can be used to exchange a merchant's global token 700 with the platform 400, whereby the network token is exported outside the jurisdiction and stored in the platform 400, instead of the PAN, it is noted that the platform 400 is outside the restricted jurisdiction. The system 1002 is an example configuration of the system 100. Figure 1

[0040] The system 1002 has a workstation 201. In Figure 2 ​In the example of FIG. 1, the POS 200 software resides on and runs on the workstation 201 that performs the POS functions. The POS 200 software communicates with the middleware 250 to perform a fully integrated end-to-end process whereby the POI device 160, the hosting system 501, and the platform 400 are integrated together to perform global tokenization and return the results to the POS 200 software. The POS 200 software communicates a message to the middleware 250 to in turn communicate with the POI device 160 to prepare for accepting a credit card read. The customer 10 inserts, taps, or manually enters their credit card, or taps their phone in the case of a digital wallet, to proceed with token provisioning. The POI device 160 securely obtains the PAN 500 or DPAN 503, encrypts the PAN 500 or DPAN 503, and provides the encrypted data to the middleware 250. The middleware 250 forms a specific message and communicates to the hosting system 501 in the jurisdiction. The hosting system 501 securely decrypts the PAN 500 or DPAN 503 using the hardware security module HSM 502. The hosting system 501 then provisions a network token and returns the token 600 and PAR 601, and additional information, to the middleware 250. Next, the middleware 250 forms a specific message and communicates to the platform 400 to obtain the merchant's global token. The platform 400 utilizes the token subsystem 401 to securely store the network token 600 and PAR 601, and loyalty account if provided by the POS, and provision a merchant-specific global token 700. The global token subsystem 401 returns the global token 700 to the middleware 250. The middleware 250 in turn returns the global token 700 to the POS 200 software for storage and future use. In the case where the merchant's location is in a restricted jurisdiction, the hosting system 501 and HSM 502 will be located in that restricted jurisdiction, thereby ensuring that the PAN 500 or DPAN 503 will not be transmitted over the network outside of that jurisdiction. The merchant-specific network token 600 and PAR 601 can be transmitted and stored outside of the restricted jurisdiction in the platform 400 to produce the merchant's global token 700, in accordance with regulations.

[0041] Turning now to Figure 3depicts a system 1003 for implementing a card present payment and tokenization process that is fully integrated between the POS 200, POI device 160, hosted middleware 250, hosting system 501, and platform 400, thereby securely transmitting the PAN 500 or DPAN 503 when a credit card is read and encrypted, exchanging a network token 600 and PAR 601 outside of a restricted jurisdiction using point-to-point encryption from the entry point to the secure HSM 403, and then a merchant's global token 700 can be exchanged with the platform 400 using the network token and PAR, whereby the network token is stored instead of the PAN. The system 1003 is an example configuration of the system 100 of Figure 1

[0042] The system 1003 has a workstation 201. The POS 200 software resides on and runs on the workstation 201 that performs the POS functions. The POS 200 software communicates with the middleware 250 to perform a fully integrated end-to-end process whereby the POI device 160, hosting system 501, and platform 400 are integrated together to perform global tokenization and return a global token 700 to the POS 200 software. The POS 200 software communicates a message to the middleware 250 to in turn communicate with the POI device 160 to be ready to accept a credit card read. The customer 10 inserts, taps, or manually enters their credit card, or taps their phone in the case of a digital wallet, to make a token provision. The POI device 160 securely obtains the PAN 500 or DPAN 503, encrypts the PAN 500 or DPAN 503, and provides the encrypted data to the middleware 250. The middleware 250 forms a specific message and communicates the encrypted data and instructions to provision a network token to the platform 400. The platform 400 securely decrypts the PAN 500 or DPAN 503 using the HSM 403, communicates the PAN 500 or DPAN 503 to the hosting system 501. The hosting system 501 then provisions a network token and returns a merchant specific network token 600 and PAR 601 and additional information to the platform 400. Next, the platform 400 securely stores the network token 600 and PAR 601 and loyalty account if provided by the POS, and provisions a merchant specific global token 700 using the token subsystem 401. The global token subsystem 401 returns the global token 700 to the platform 400, which in turn returns the global token 700 to the middleware 250. The middleware 250 in turn returns the global token 700 to the POS 200 software for storage and future use. The platform 400 and hosting system 501 will be located outside of a restricted jurisdiction.

[0043] Turning now to Figure 4 ​depicts a system 1004 for implementing online card not present processing for ecom and mobile applications that is fully integrated between the POS 200, middleware 250, customer's computing device 161 (similar to workstation 201 described herein), web browser software or mobile application software 162, hosting system 501, and platform 400, securely transmitting the PAN 500 or DPAN 503 within a restricted jurisdiction to exchange a network token 600 and a PAR 601 that can then be used with the network token and PAR to exchange a merchant's global token 700 with the platform 400. The system 1004 is an example configuration of the system 100 of Figure 1

[0044] ​The system 1004 has an application server 101. For simplicity, the application server 101 is analogous to the workstation 201 defined herein as hosting a computing system. The POS 200 software resides on and runs on the application server 101 that performs the POS functions. The POS 200 software can be a web application that interacts with a web browser on the computing device 161, or can be a server-side application that communicates with the mobile application 162 on the computing device 161 to interface with the customer 10. The customer 10 enters their PAN 500, or selects a credit card from a digital wallet that produces a DPAN 503, which are communicated back to the POS 200 running on the application server 101 by the web browser or mobile application 162. The POS 200 communicates the PAN 500 or DPAN 503 and optionally the loyalty account number to the middleware 250 also running on the application server 101, which forms a specific message and communicates to the hosting system 501 in the jurisdiction. The hosting system 501 then provisions a network token, and returns that token 600 and PAR 601 and additional information back to the middleware 250. Next, the middleware 250 forms a specific message and communicates to the platform 400 to obtain a global token for the merchant. The platform 400 utilizes the token subsystem 401 to securely store the network token 600 and PAR 601 and loyalty account (if provided by the POS), and provisions a merchant-specific global token 700. The global token subsystem 401 returns the global token 700 to the middleware 250. The middleware 250 in turn returns the global token 700 to the POS 200 software for storage and future use. In the case where the merchant's location is in a restricted jurisdiction, the hosting system 501 will be located in that restricted jurisdiction, ensuring that the PAN 500 or DPAN 503 will not be transmitted over the network outside of that jurisdiction. The network token 600 and PAR 601 can be transmitted and stored outside of the restricted jurisdiction in the platform 400 for the purpose of generating the global token 700 for the merchant, ensuring that the merchant complies with data governance regulations and laws.

[0045] Turning now to Figure 5depicts a system 1005 for implementing online card not present for ecom and mobile applications that is fully integrated between the POS 200, middleware 250, customer's computing device 161, web browser or mobile application software 162, hosting system 501 and platform 400, securely sending the PAN 500 or DPAN 503 outside of a restricted jurisdiction to exchange a network token 600 and PAR 601 that can then be used with the platform 400 to exchange a merchant's global token 700. In the case where the PAN is issued by a credit card issuer within a restricted jurisdiction, the middleware 250 will communicate with the hosting system 501 within that jurisdiction. The system 1005 is an example configuration of the system 100 of Figure 1

[0046] The system 1005 has an application server 101. The POS 200 software resides on and runs on the application server 101 that performs the POS functions. The POS 200 software can be a web application that interacts with the web browser on the computing device 161 or can be a server side application that communicates with the mobile application 162 on the computing device 161 to interface with the customer 10. The customer 10 enters their PAN 500 or selects a credit card from a digital wallet that produces a DPAN 503 that is communicated back to the POS 200 running on the application server 101 by the web browser or mobile application 162. The POS 200 communicates the PAN 500 or DPAN 503 and optionally a loyalty account to the middleware 250, in this case, the middleware is hosted outside of the application server, which forms a specific message and communicates to the hosting system 501. The hosting system 501 then provisions a network token and returns the token 600 and PAR 601 and additional information to the middleware 250. Next, the middleware 250 forms a specific message and communicates with the platform 400 to obtain a merchant's global token, communicating the network token 600, PAR 601 and loyalty account if it was provided by the POS 200. The platform 400 utilizes the token subsystem 401 to securely store the network token 600 and PAR 601 and loyalty account if provided by the POS, then provisions a merchant specific global token 700 that is returned to the middleware 250, which in turn returns the global token 700 to the POS 200 for storage and future use. In the case where the PAN is issued by a bank within the jurisdiction and regulations prohibit storing the PAN outside of the jurisdiction, the hosting system 501 can also need to be located within the restricted jurisdiction. The middleware 250 is configured to communicate with multiple hosting systems 501 in multiple regions.

[0047] Turning now to​Figure 6 depicts a system 1006 for enabling payment orchestration in a store within a restricted jurisdiction that is fully integrated between the POS 200, middleware 250, POS server 199, POI device 160, platform 400, payment service provider (PSP) system 300 (typically a payment gateway), and acquirer 203 for exchanging a global token 700 into a network token 600 to facilitate credit card payments. The system 1006 is an example configuration of the system 100 of Figure 1 .

[0048] The system 1006 has a workstation 201. The POS 200 software resides on and runs on the workstation 201 that performs the POS functions. The POS 200 software communicates with the middleware 250 to exchange the global token 700 into a network token 600. The middleware 250 formulates messages and communicates with the platform 400, transmitting the global token 700, which in turn communicates with the token subsystem 401, exchanging the global token 700 into a network token 600. The platform 400 then returns the network token 600 to the middleware 250. Depending on the type of PSP integration, the middleware 250 or the POS 200 will then formulate messages and transmit the network token 600 to the PSP system 300 to orchestrate the credit card payment. The PSP system 300 formulates messages with the network token 600 and communicates with the acquirer 203 to orchestrate the payment. The results of the payment are returned through the chain of components back to the POS 200.

[0049] Turning now to Figure 7 , depicts a system 1007 for enabling online card not present processing for ecom and mobile applications that is fully integrated between the POS 200, middleware 250, customer’s computing device 161, web browser or mobile application 162, platform 400, payment service provider (PSP) system 300, and acquirer 203 for exchanging a global token 700 into a network token 600 to facilitate credit card payments from a restricted jurisdiction. The system 1007 is an example configuration of the system 100 of Figure 1 .

[0050] The system 1007 has an application server 101. The POS 200 software resides on and runs on the application server 101 that performs the POS functions. The POS 200 software can be a web application that interacts with the web browser on the computing device 161 or can be a server-side application that communicates with the mobile application 162 on the computing device 161 to interface with the customer 10. The customer 10 initiates a payment request to the POS 200 application. The POS 200 software communicates with the middleware 250 to exchange the global token 700 for a network token 600. The middleware 250 formulates a message and communicates with the platform 400, transmitting the global token 700, which in turn communicates with the token subsystem 401, exchanging the global token 700 for a network token 600. The platform 400 then returns the network token 600 to the middleware 250. Depending on the type of PSP integration, the middleware 250 or the POS 200 will then formulate a message and transmit the network token 600 to the PSP system 300 to coordinate a credit card payment. The PSP system 300 formulates a message with the network token 600 and communicates with the acquirer 203 to coordinate the payment. The results of the payment are returned through the chain of components to the POS 200.

[0051] Turning now to Figure 8 , a system 1008 is depicted for implementing online card not present processing for ecom and mobile applications that is fully integrated between the POS 200, the middleware 250, the customer's computing device 161, the web browser or mobile application 162, the platform 400 with payment gateway 402, and the acquirer 203 for exchanging the global token 700 for a network token 600 to facilitate credit card payments outside of restricted jurisdictions. The system 1008 is an example configuration of the system 100. Figure 1

[0052] ​The system 1008 has an application server 101. The POS 200 software resides on and runs on the application server 101 that performs the POS functions. The POS 200 software can be a web application that interacts with a web browser on the computing device 161 or can be a server-side application that communicates with the mobile application 162 on the computing device 161 to interface with the customer 10. The customer 10 initiates a payment request to the POS 200 application. The POS 200 software communicates with the middleware 250 hosted on a platform external to the application server 101 to perform the payment by communicating the global token 700. The middleware 250 formulates messages and communicates with the platform 400 to communicate the global token 700 and instructions to perform the payment with the network token 600. The platform 400 in turn communicates with the payment gateway 402 which in turn communicates with the token subsystem 401 to exchange the global token 700 for the network token 600. The token subsystem 401 returns the network token 600 to the payment gateway 402 which in turn formulates messages and communicates to the acquirer 203 to communicate the network token 600 to perform the credit card payment. The results of the payment are returned through the chain of components to the POS 200.

[0053] Turning now to Figure 9 , a system 1009 is depicted for implementing payment orchestration that is fully integrated between the POS 200, middleware 250, POS server 199, POI device 160, platform 400, payment service provider (PSP) system 300, and acquirer 203 for exchanging the global token 700 for the network token 600 to facilitate credit card payments from restricted jurisdictions as well as loyalty transactions. The system 1009 is an example configuration of the system 100. Figure 1

[0054] ​The system 1009 has a workstation 201. The POS 200 software resides on and runs on the workstation 201 that performs the POS functions. The POS 200 software communicates with the middleware 250 to exchange the global token 700 for a network token 600. The middleware 250 formulates messages and communicates with the platform 400, passing the global token 700, which in turn communicates with the token subsystem 401, exchanging the global token 700 for a network token 600. The platform 400 then returns the network token 600 to the middleware 250. Depending on the type of PSP integration, the middleware 250 or the POS 200 will then formulate messages and pass the network token 600 to the PSP system 300 to coordinate a credit card payment. The PSP system 300 formulates messages with the network token 600 and communicates with the acquirer 203 to coordinate the payment. The results of the payment operation are returned to the middleware 250 and / or the POS 200. The middleware 250, configured to also perform loyalty transactions, will formulate messages and communicate with the platform 400, passing the same global token 700, with instructions to perform a loyalty transaction, such as earning points. The platform 400 uses the global token 700 to retrieve the loyalty account from the token subsystem 401 and in turn formulates messages and passes to the loyalty provider 310 to perform the loyalty transaction. The results of the loyalty transaction are returned through the chain of components to the POS 200. Prior to the loyalty transaction request, the loyalty account must have been provisioned at the time the global token was supplied from the network token.

[0055] Turning now to Figure 10 , a system 1010 for implementing online card not present processing for ecom and mobile applications is depicted that is fully integrated between the POS 200, middleware 250, customer's computing device 161, web browser or mobile application 162, platform 400, payment service provider (PSP) system 300, and acquirer 203 for exchanging a global token 700 for a network token 600 to facilitate credit card payments from restricted jurisdictions as well as loyalty transactions. The system 1010 is an example configuration of the system 100. Figure 1

[0056] ​The system 1010 has an application server 101. The POS 200 software resides on and runs on the application server 101 that performs the POS functions. The POS 200 software can be a web application that interacts with the web browser on the computing device 161 or can be a server-side application that communicates with the mobile application 162 on the computing device 161 to interface with the customer 10. The customer 10 initiates a payment request to the POS 200 application. The POS 200 software communicates with the middleware 250 to exchange the global token 700 for a network token 600. The middleware 250 formulates a message and communicates with the platform 400, transmitting the global token 700, which in turn communicates with the token subsystem 401, exchanging the global token 700 for a network token 600. The platform 400 then returns the network token 600 to the middleware 250. Depending on the type of PSP integration, the middleware 250 or the POS 200 will then formulate a message and transmit the network token 600 to the PSP system 300 to coordinate a credit card payment. The PSP system 300 formulates a message with the network token 600 and communicates with the acquirer 203 to coordinate the payment. The results of the payment operation are returned to the middleware 250 and / or the POS 200. The middleware 250, configured to also perform loyalty transactions, will formulate a message and communicate with the platform 400, transmitting the same global token 700, with instructions to perform a loyalty transaction, such as earning points. The platform 400 uses the global token 700 to retrieve the loyalty account from the token subsystem 401 and in turn formulates a message and transmits to the loyalty provider 310 to perform the loyalty transaction. The results of the loyalty transaction are returned through the chain of components to the POS 200. Prior to the loyalty transaction request, the loyalty account must have been provisioned at the time the global token was supplied from the network token.

[0057] Turning now to Figure 11 , a system 1011 for implementing a card present payment and tokenization process coupled with a loyalty transaction is depicted that is fully integrated between the POS 200, the middleware 250, the POI device 160, the hosting system 501, and the platform 400 and the acquirer 203, synchronously, when a credit card is read and encrypted, the PAN 500 or DPAN 503 is securely transmitted with PCI validation using P2PE. The system 1011 is an example configuration of the system 100. Figure 1

[0058] ​The system 1011 has a workstation 201. The POS 200 software conveys the payment, loyalty, and global tokenization messages all together to the middleware 250 to in turn to the POI device 160 to be ready to accept a credit card read. The customer 10 inserts, taps, or manually enters their credit card, or in the case of a digital wallet taps their phone to perform the POS 200 request. The POI device 160 securely obtains the PAN 500 or DPAN 503, encrypts the PAN 500 or DPAN 503, and provides the encrypted data to the middleware 250. The middleware 250 forms a specific message and conveys to the platform 400. The platform 400 decrypts the payload from the HSM 403 that retrieves the PAN 500 or DPAN 503 with the payment gateway 402, then formulates a message and conveys to the acquirer 203, thereby conveying the PAN 500 or DPAN 503 to perform the payment. The result of the payment is returned to the payment gateway 402, and if it is successfully accepted by the acquirer, the payment gateway 402 then communicates with the token subsystem 401 to provision a network token 600, and returns a merchant specific global token 700. The token subsystem formulates a message and conveys to the hosting system 501, thereby conveying the PAN 500 or DPAN 503. The hosting system 501 provisions a network token 600, and returns the network token 600 and PAR 601 to the token subsystem 401. The token subsystem 401 stores the network token 600, PAR 601, then generates a global token 700 and returns the global token to the payment gateway 402, which in turn returns the payment result and global token 700 to the middleware 250. The middleware 250 that has been configured for loyalty and has received the initial POS 200 message to perform the loyalty, will formulate a message and convey the loyalty transaction request with the global token 700 to the platform 400. The platform 400 formulates a message and conveys to the token subsystem, thereby passing the global token 700. The token subsystem retrieves the PAR value linked to the global token 700 from the previously provisioned network token 600, and uses the PAR value to look up the loyalty account, and returns the loyalty account to the payment gateway 402. The payment gateway formulates a message and conveys the loyalty transaction with the loyalty account to the loyalty provider 310. The result of the loyalty transaction is returned through the chain of components to the middleware 250, which in turn returns the payment result, global token 700, and loyalty transaction result to the POS 200. When the customer has had their credit card on file for future use in the token subsystem 401, the loyalty account must be provided in the previous operation. The PAR value will also be provided and stored, also linked to the loyalty account.

[0059] Loyalty accounts can represent any type of user tracking and affiliation system with secure transaction support. Such user tracking and affiliation systems can manage various types of units associated with a user account and can increase or decrease based on various types of actions.

[0060] Turning now to Figure 12 , a flow diagram of a method 800 is generally shown, in accordance with one or more aspects. All or a portion of method 800 can be a computer-implemented method implemented, for example, by all or a portion of a system of Figures 1 to 11 .

[0061] At block 802, the middleware 250 can receive a request from the POS application 200 to obtain a global token from a hosting platform. At block 804, the middleware 250 can receive a request to obtain a global token from a POI device that reads and encrypts credit card data via one of a plurality of communication protocols supported by the middleware 250. At block 806, the middleware 250 can receive the request to obtain a global token and forward the request to obtain a global token to an in-region hosting system to decrypt the encrypted credit card data using a hardware security module that provisions international credit card scheme network tokens. At block 808, the middleware 250 can receive an international credit card scheme network token via one of the communication protocols and use the international credit card scheme network token to perform a request for a vendor-specific global token to the hosting platform. At block 810, the middleware 250 can receive a merchant-specific global token and return the merchant-specific global token to the POS application 200 for storage and future use to coordinate future payment authorization transactions via the merchant-specific global token.

[0062] In some aspects, the POS application 200 and the middleware 250 can be executable by the workstation 201.

[0063] In some aspects, the workstation 201 can be configured to interface with a hosting platform and a hosting network token provisioning system, the hosting platform for performing both payment and global tokenization services within or outside of a restricted jurisdiction for primary account number (PAN) export and storage.

[0064] In some aspects, the computer program instructions, when executed by one or more processors (e.g., processor 103), can cause the one or more processors to implement: receiving an encrypted credit card number from a POI device 160, the POI device identifying a POI device type, automatically connecting and communicating based on the POI device type, initiating a command to accept a credit card number read or manually entered, and encrypting the credit card number within a Payment Card Industry (PCI) validated Point-to-Point Encryption (P2PE) solution; identifying a communication protocol of a hosted network token provisioning system; constructing information including the encrypted card number; and sending the information to the hosted network token provisioning system to decrypt the information and provision a network token, and in turn be exchanged for a merchant-specific global token.

[0065] In some aspects, the source code of the middleware 250 can be configured to compile and run on various workstation operating systems.

[0066] In some aspects, the middleware 250 can include a plurality of communication interfaces, each of the plurality of communication interfaces corresponding to one of a plurality of communication protocols.

[0067] In some aspects, the middleware 250 can be POS and POI device agnostic.

[0068] In some aspects, the POS application 200 and the middleware 250 can be executable by the application server 101.

[0069] In some aspects, the computer program instructions, when executed by one or more processors (e.g., processor 103), can cause the one or more processors to implement: when a token is requested, sending a plurality of instructions to a hosted platform for merchant-specific global token provisioning to identify a user account linked with a credit card account obtained from a POI device using a network token, and subsequently communicating the user account and payment information to the platform; querying the user account and payment information to determine whether the user account is eligible to accrue units and / or is eligible to redeem units based on information returned to the hosted platform; receiving information from the hosted platform regarding a plurality of options for accrual and / or redemption; and presenting one or more of the options to a customer associated with the credit card account.

[0070] In some aspects, one or more of the options can include presenting a number of units earned for an associated payment transaction to the customer associated with the credit card account, such as on the display 167.

[0071] In some aspects, one or more of the options can include redeeming or accruing units instead of, or in addition to, completing a credit card payment.

[0072] In some aspects, the computer program instructions, when executed by one or more processors (e.g., processor 103), can cause the one or more processors to implement receiving input from a customer, sending a billing or redemption request back to a hosting platform to subsequently transmit billed or redeemed units to the platform, receiving a response back from the hosting platform, displaying the number of billed or redeemed units on the POI device, and returning the results to the POS application for addition to the order and receipt.

[0073] Figure 12 The illustrated process is not intended to indicate that operations are to be executed in any particular order, or that all of the Figure 12 operations illustrated are to be included in every case. Figure 12 The illustrated process can include any suitable number of additional operations.

[0074] According to aspects, an integrated sales system platform can include a point of sale application and global tokenization coordination middleware to perform global tokenization coordination that, in combination, provide global token and provisioning operations that are agnostic to credit card reading devices and / or credit card linked loyalty operations. The middleware includes a communication interface, each of the communication interfaces corresponding to a particular communication protocol. The middleware receives a token creation request from the point of sale application and directly communicates to an interaction point payment device via one of the communication protocols to receive and securely encrypt a credit card number, which is then sent to a hosting network token provisioning system to request a network token. Upon receiving the network token, the middleware directly communicates with a global merchant tokenization host via one or more protocols to create a merchant specific token that will be returned by the middleware to the point of sale client for use as a card-on-file payment method. Through the same protocol, the middleware can instruct the global token host to also use the network token and primary account reference value to retrieve a loyalty account linked to that credit card, communicate with a third system to determine loyalty unit billing and / or redemption options, and return that information to the middleware for coordinating a specific quantity of loyalty billing or redemption based on customer input. The middleware also includes a method for receiving a merchant specific global token, de-tokenizing that token with the global merchant tokenization host, receiving back a network token associated with that merchant token for then use in credit card payment authorization from any location globally, thereby ensuring that the merchant is in compliance with all local and regional data governance laws with respect to sending and storing credit card account numbers.

[0075] In some aspects, a computer-implemented method of providing a credit card account linked with a loyalty account within middleware of an integrated sales system platform can include sending a plurality of instructions to a hosted platform for a merchant-specific global token supply to identify a loyalty account linked with a credit card account obtained from a point of interaction (POI) device using a network token when a token is requested, and subsequently communicating the loyalty account and payment information to a loyalty platform. The computer-implemented method can also include interrogating the loyalty account and payment information to determine whether the loyalty account is eligible for loyalty units and / or eligible to redeem loyalty units based on information returned to the hosted platform. The computer-implemented method can also include receiving information from the hosted platform regarding options for loyalty accrual and / or redemption. The computer-implemented method can additionally include presenting a customer associated with the credit card account with a number of loyalty units automatically earned for an associated payment transaction, or presenting the customer with an option to redeem or accrue loyalty units instead of, or in addition to, completing a credit card payment, thereby completing an order at a POS. This can help ensure that merchants comply with all local and regional data governance laws in accordance with sending and storing credit card accounts, while providing secure transactions.

[0076] In some aspects, the computer-implemented method can include receiving input from a customer and sending a loyalty accrual or redemption request back to the hosted platform to subsequently communicate the accrued or redeemed loyalty units to the loyalty platform. The computer-implemented method can also include receiving a returned response from the hosted platform, displaying a number of the accrued or redeemed loyalty units on the POI device, and returning the results to a point of sale (POS) application for addition to an order and a receipt.

[0077] Aspects disclosed herein can be a system, a method, and / or a computer program product at any possible technical detail level of integration. The computer program product can include a computer readable storage medium (or media) having computer readable program instructions thereon for causing a processor to carry out aspects.

[0078] A computer readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device. The computer readable storage medium can be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of the computer readable storage medium includes the following: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanically encoded device such as punch cards or raised structures in grooves of a groove having instructions recorded thereon, and any suitable combination of the foregoing. A computer readable storage medium, as used herein, is not to be construed as being transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission media (e.g., light pulses passing through a fiber-optic cable), or electrical signals transmitted through a wire.

[0079] Computer readable program instructions described herein can be downloaded to respective computing / processing devices from a computer readable storage medium or to an external computer or external storage device via a network, for example, the Internet, a local area network, a wide area network and / or a wireless network. The network can comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and / or edge servers. A network adapter card or network interface in each computing / processing device receives computer readable program instructions from the network and forwards the computer readable program instructions for storage in a computer readable storage medium within the respective computing / processing device.

[0080] Computer readable program instructions for carrying out operations of the present disclosure can be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine dependent instructions, microcode, firmware instructions, state setting data, integrated circuit configuration data, or any combination of source code or object code in any combination of one or more programming languages including an object oriented programming language such as Smalltalk, C++, or the like, a high-level programming language such as Python, C-Sharp (C#), Java, Swift, Objective C, and the like, and a procedural programming language such as the "C" programming language or similar programming languages. The computer readable program instructions can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider). In some aspects, electronic circuitry including, for example, programmable logic circuitry, field-programmable gate array (FPGA), or programmable logic array (PLA) can execute the computer readable program instructions by utilizing state information of the computer readable program instructions to personalize the electronic circuitry, in order to perform aspects of the present disclosure.

[0081] Aspects are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems) and computer program products according to aspects of the present disclosure. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer readable program instructions.

[0082] These computer readable program instructions can be provided to a processor of a computer, or other programmable data processing apparatus, to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. These computer readable program instructions can also be stored in a computer readable storage medium that can direct a computer, a programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer readable storage medium having instructions stored therein comprises an article of manufacture including

[0083] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process, such that the instructions which execute on the computer, other programmable apparatus, or other device implement the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0084] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process, such that the instructions which execute on the computer, other programmable apparatus, or other device implement the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0085] The description of aspects has been presented for purposes of illustration and description, but is not intended to be exhaustive or limited to the aspects disclosed. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described aspects. The terminology used herein was chosen to best explain the principles of the aspects, the practical application or technical improvement over technologies found in the marketplace, or to enable others skilled in the art to understand the aspects described herein.

[0086] Aspects are described herein with reference to the related drawings. Alternative aspects can be devised without departing from the scope of the disclosure. Various connections and positional relationships (e.g., over, below, beside, etc.) are set forth in the description and drawings to illustrate examples of the aspects. Such connections and / or positional relationships can be direct or indirect, and the order of the description is not intended to be construed as a specific order of implementation. Accordingly, the coupling of entities can be direct or indirect, and the positional relationships between entities can be direct or indirect. Moreover, the various tasks and process steps described herein can be incorporated in a more comprehensive process or process suite having additional steps or functions not described in detail herein.

[0087] The following definitions and abbreviations are to be used for interpretation of the claim terminology and document herein. As used herein, the terms “comprises,” “comprising,” “includes,” “including,” “has,” “having,” “contains” or “containing,” or any other variation thereof, are intended to cover a non-exclusive inclusion. For example, a composition, a mixture, a process, a method, an article, or an apparatus that comprises a list of elements is not necessarily limited to those elements but can include other elements not expressly listed or inherent to such composition, mixture, process, method, article, or apparatus.

[0088] Further, use of the term “exemplary” in this document is used as an example, instance, or illustration. Any aspect or design described herein as “exemplary” is not necessarily to be construed as preferred or advantageous over other aspects or designs. The terms “at least one” and “one or more” can be understood to include any integer greater than or equal to one, i.e., one, two, three, four, etc. The term “plurality” can be understood to include any integer greater than or equal to two, i.e., two, three, four, five, etc. The term “connected” can be used herein to include both an indirect “connection” and a direct “connection.”

[0089] The terms “about,” “substantially,” “approximately,” and variations thereof, are intended to include the degree of error associated with measurements that can be expected to vary from experiment to experiment under similar conditions due to reasonable variability in the equipment used for measuring the particular quantity. For example, “about” can include a range of ± 8% or 5%, or 2% of a given value.

[0090] For the sake of brevity, conventional techniques related to manufacturing and use of aspects can or can not be described in detail herein. In particular, various integrating systems and specific computer programs for implementing the various features described herein are well known. Accordingly, in the interest of brevity, many conventional implementation details are only mentioned briefly or are omitted entirely without providing the well-known system and / or process details.

[0091] It should be understood that various aspects and / or portions of aspects disclosed herein can be combined in different combinations than the combinations specifically presented in the specification and drawings. It should also be understood that depending on the example, certain acts or events of any of the processes described herein can be performed in a different sequence, can be added, merged, or left out altogether (e.g., all described acts or events can not be necessary to carry out the techniques). In addition, while a particular aspect described herein can be set forth in the context of a single

[0092] In one or more examples, the described techniques can be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functions can be stored as one or more instructions or code on a computer-readable medium and executed by a hardware-based processing unit. Computer-readable media can include non-transitory computer-readable media, which corresponds to a tangible medium such as data storage media (e.g., RAM, ROM, EEPROM, flash memory or any other medium that can be used to store desired program code in the form of instructions or data structures and that can be accessed by a computer).

[0093] Instructions can be executed by one or more processors, such as one or more digital signal processors (DSPs), graphics processing units (GPUs), microprocessors, application-specific integrated circuits (ASICs), field programmable logic arrays (FPGAs), or other equivalent integrated or discrete logic circuitry. Accordingly, the term "processor," as used herein can refer to any of the foregoing structure or any other physical structure suitable for implementation of the described techniques. Also, the techniques could be fully implemented in one or more circuits or logic elements.

[0094] While the application has been described with reference to various aspects, it will be understood that those skilled in the art will be able to devise various arrangements which, although not explicitly described or shown herein, embody the principles of the application and, as such, within the scope of the application. Further, while the application has been described herein with reference to particular aspects, it will be understood that aspects of the application can be combined, combined, modified, or sub-divided, in whole or in part, without departing from the scope of the application. In addition, many modifications can be made to adapt a particular situation or material to the teachings of the application without departing from the scope thereof. Therefore, it is intended that the application not be limited to the particular aspects disclosed as the embodiments of the application, but that the application will include all aspects falling within the scope of the appended claims. Moreover, unless specifically stated otherwise, any use of the terms first, second, etc., does not indicate any order or importance, but the terms first, second, etc., are used to distinguish one element from another.

Claims

1. An integrated sales system platform having integrated global tokenization orchestration middleware, the integrated sales system platform comprising: a workstation comprising one or more processors and a memory system, the memory system comprising a plurality of instructions executable by the one or more processors to provide a point of sale (POS) application and middleware, wherein source code of the middleware is configured to compile and run on a variety of workstation operating systems, and the middleware comprises a plurality of communication interfaces, each of the plurality of communication interfaces corresponding to one of a plurality of communication protocols, and the middleware is POS and point of interaction (POI) device agnostic; wherein the workstation is configured to interface with a hosted platform for performing both payment and global tokenization services, both within and outside of a restricted jurisdiction, for primary account number (PAN) export and storage; and wherein the middleware is configured to: receive a request from the POS application to obtain a global token from the hosted platform; receive a request via one of the communication protocols to obtain the global token by a POI device reading and encrypting credit card data; receive the request to obtain the global token and forward the request to obtain the global token to an in-region hosted system to decrypt the encrypted credit card data using a hardware security module that supplies international credit card scheme network tokens; receive the international credit card scheme network token via one of the communication protocols; execute a request to the hosted platform to supply a merchant specific global token using the international credit card scheme network token; and receive the merchant specific global token and return the merchant specific global token to the POS application for storage and future use to orchestrate future payment authorization transactions via the merchant specific global token.

2. The integrated sales system platform of claim 1, wherein, the middleware is further configured to: receive an encrypted credit card number from the POI device, the POI device identifying a POI device type, automatically connecting and communicating based on the POI device type, initiating a command to accept a credit card number read or manually entered, and encrypting the credit card number within a payment card industry (PCI) validated point-to-point encryption (P2PE) solution; identify a communication protocol of the hosted network token supply system; construct information, the information comprising the encrypted card number; and send the information to the hosted network token supply system to decrypt the information and supply a network token, and in turn be exchanged for the merchant specific global token.

3. A computer-implemented method of providing a credit card account linked to a user account within middleware of an integrated sales system platform, the computer-implemented method comprising: when a token is requested, sending a plurality of instructions to a hosted platform for merchant specific global token supply to identify a user account linked to the credit card account obtained from a point of interaction (POI) device using a network token, and subsequently communicating user account and payment information to a platform; querying the user account and payment information to determine whether the user account qualifies for accrual units and / or qualifies for redemption units based on information returned to the hosting platform; receiving information from the hosting platform regarding a plurality of options for accrual and / or redemption; and presenting one or more of the options to a customer associated with the credit card account.

4. The computer-implemented method of claim 3, wherein, The one or more of the options includes presenting the customer associated with the credit card account with a number of units earned for an associated payment transaction.

5. The computer-implemented method of claim 3, wherein, The one or more of the options includes redeeming or accruing units instead of, or in addition to, completing a credit card payment.

6. The computer-implemented method of claim 3, further comprising: receiving input from the customer; sending an accrual or redemption request back to the hosting platform to subsequently transmit accrual or redemption units to the platform; receiving a response returned from the hosting platform; displaying the number of accrued or redeemed units on a POI device; and returning the results to a point of sale (POS) application for addition to an order and receipt.

7. A computer program product, the computer program product comprising a storage medium embodying computer program instructions, the computer program instructions, when executed by one or more processors, cause the one or more processors to implement: receiving a request from a point of sale (POS) application to obtain a global token from a hosting platform; receiving a request to obtain the global token via an interaction point (POI) device that reads and encrypts credit card data through one of a plurality of communication protocols supported by middleware; receiving the request to obtain the global token and forwarding the request to obtain the global token to an in-region hosting system to decrypt the encrypted credit card data using a hardware security module that provisions international credit card scheme network tokens; receiving the international credit card scheme network token via one of the communication protocols; executing a request for a merchant-specific global token provisioned by the hosting platform using the international credit card scheme network token; receiving the merchant-specific global token; and returning the merchant-specific global token to the POS application for storage and future use to coordinate future payment authorization transactions via the merchant-specific global token.

8. The computer program product of claim 7, wherein, The POS application and the middleware are executable by a workstation.

9. The computer program product of claim 8, wherein, The workstation is configured to interface with the hosting platform and a hosting network token provisioning system, the hosting platform for performing both payment and global tokenization services within or outside of a restricted jurisdiction for primary account number (PAN) export and storage.

10. The computer program product of claim 9, further comprising computer program instructions, which when executed by the one or more processors, cause the one or more processors to implement: receiving an encrypted credit card number from a POI device, the POI device identifying a POI device type, automatically connecting and communicating based on the POI device type, initiating a command to accept a credit card number read or manually entered, and encrypting the credit card number within a Payment Card Industry (PCI) validated Point-to-Point Encryption (P2PE) solution; identifying a communication protocol of the hosted network token provisioning system; constructing information, the information including the encrypted card number; and sending the information to the hosted network token provisioning system to decrypt the information and provision a network token, and in turn exchanged for the merchant-specific global token.

11. The computer program product of claim 8, wherein, The source code of the middleware is configured to compile and run on various workstation operating systems.

12. The computer program product of claim 8, wherein, The middleware includes a plurality of communication interfaces, each of the plurality of communication interfaces corresponding to one of the plurality of communication protocols.

13. The computer program product of claim 12, wherein, The middleware is POS and POI device agnostic.

14. The computer program product of claim 7, wherein, The POS application and the middleware are executable by an application server.

15. The computer program product of claim 7, further comprising computer program instructions that, when executed by the one or more processors, cause the one or more processors to implement: when a token is requested, sending a plurality of instructions to the hosted platform for merchant-specific global token provisioning to identify a user account linked with a credit card account obtained from a POI device using a network token, and subsequently communicating user account and payment information to the platform; inquiring the user account and payment information to determine whether the user account is eligible for accrual units and / or eligible to redeem units based on information returned to the hosted platform; receiving information from the hosted platform regarding a plurality of options for accrual and / or redemption; and presenting one or more of the options to a customer associated with the credit card account.

16. The computer program product of claim 15, wherein, The one or more of the options include presenting the customer associated with the credit card account with a number of units earned for an associated payment transaction.

17. The computer program product of claim 15, wherein, The one or more of the options include redeeming or accruing units instead of, or in addition to, completing a credit card payment.

18. The computer program product of claim 15, further comprising computer program instructions that, when executed by the one or more processors, cause the one or more processors to implement: receiving input from the customer; sending an accrual or redemption request back to the hosted platform to subsequently communicate accrual or redemption units to the platform; receiving a response returned from the hosted platform; displaying a number of accrued or redeemed units on the POI device; and returning the results to the POS application for addition to an order and a receipt.