Merchant's payment acceptance voucher (MPPAC) audit verification system shown by merchant and method thereof

By generating and evaluating MPPAC identifiers through the merchant MPPAC audit and verification system, and combining this with digital photo verification, the problem of MPPAC being easily tampered with is solved, thus ensuring the security and reliability of the payment process.

CN121921024APending Publication Date: 2026-04-24VISA INTERNATIONAL SERVICE ASSOCIATION
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
VISA INTERNATIONAL SERVICE ASSOCIATION
Filing Date
2025-08-22
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

Existing Merchant Payment Acceptance Certificates (MPPACs) are susceptible to tampering, leading to fraudulent payment transactions. Therefore, it is necessary to improve the security and reliability of the payment process.

Method used

The merchant MPPAC audit and verification system is adopted to ensure the authenticity of MPPACs captured by merchants and customers by generating and evaluating MPPAC identifiers. MPPACs are generated using static and dynamic MPPAC generators, and the validity of MPPACs is verified through one-way functions and encoding techniques. The location matching of merchants and customers is verified by combining digital photos.

Benefits of technology

It effectively prevents fraudulent payment transactions, improves the security and reliability of the payment process, and ensures the authenticity and legality of MPPAC.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121921024A_ABST
    Figure CN121921024A_ABST
Patent Text Reader

Abstract

In some embodiments, a system includes a processor; the system includes a processor, and a non-transitory computer readable medium coupled to the processor, the non-transitory computer readable medium including code to: generate, at a payment network, a payment acceptance credential (MPPAC) presented by a merchant generated by the payment network, the MPPAC generated by the payment network configured for merchant MPPAC auditing of the merchant; providing the MPPAC generated by the payment network to the merchant for the merchant MPPAC auditing; receiving, at the payment network, a merchant captured MPPAC, the merchant captured MPPAC having been captured by the merchant for merchant MPPAC audit verification; and performing, at the payment network, the merchant MPPAC audit verification using the MPPAC generated by the payment network and the MPPAC captured by the merchant.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] The background description provided herein is for the purpose of generally presenting the context of this disclosure. To the extent described in this background section, the work of the currently identified inventors and aspects described at the time of filing that may not otherwise be considered prior art are neither expressly nor implied to be prior art to this disclosure.

[0002] A Merchant-Presented Payment Acceptance Certificate (MPPAC) typically refers to a digital credential used in the context of electronic payments in mobile and online transactions. Using an MPPAC in a payment transaction allows merchants to demonstrate payment acceptance to customers. MPPACs are typically presented by the merchant during a financial transaction and captured by the consumer to make payment using the captured digital credential. Examples of MPPACs include, for instance, Merchant-Presented Quick Response (MPQR) and NFC Data Exchange Format (NDEF) messages. An MPQR typically refers to a type of QR code used in payment systems, where a merchant generates a QR code that a customer scans with a mobile device to initiate a payment. An NDEF message typically refers to a standardized data format used in Near Field Communication (NFC) technology to exchange payment-related information between NFC-enabled devices or between an NFC device and an NFC tag. These types of MPPACs can be tampered with, for example, by overwriting a legitimate MPQR with a different MPQR containing a fraudulent credential (a URL pointing to a phishing accelerator or malicious website), or by replacing a legitimate NDEF tag with a fraudulent NDEF tag. Therefore, appropriate systems are needed to prevent fraudulent payment transactions and improve security and reliability during the payment process. Attached Figure Description

[0003] Figure 1 A block diagram of a system according to some embodiments is shown.

[0004] Figure 2 A block diagram is shown of a merchant-issued payment acceptance credential (MPPAC) audit and verification system in a payment network communicatively coupled to a customer's smartphone and / or a merchant's smartphone, according to some embodiments.

[0005] Figure 3 Illustrations based on some embodiments Figure 2 A block diagram of the merchant MPPAC audit verification system.

[0006] Figure 4 This is a flowchart illustrating a merchant MPPAC audit verification method according to some embodiments. Detailed Implementation

[0007] Figure 1A block diagram of an exemplary system 100 for implementing embodiments consistent with this disclosure is shown. In some non-limiting embodiments or aspects, system 100 may utilize a merchant-issued payment acceptance credential (MPPAC) audit verification system 150 to implement a method for performing merchant MPPAC audit verification, as further described herein. In some embodiments, to prevent customers from using fraudulent MPPACs displayed on an MPPAC display by malicious actors, system 100 of the payment network utilizes the merchant MPPAC audit verification system 150 to verify that the merchant has performed an MPPAC audit, as further described in detail herein. In some embodiments, processor 102 may include at least one data processor for executing program components for dynamic resource allocation at runtime. Processor 102 may include dedicated processing units, such as an integrated system (bus) controller, a memory management control unit, a floating-point unit, a graphics processing unit, a digital signal processing unit, etc.

[0008] In some embodiments, the processor 102 may be configured to communicate with one or more input / output (I / O) devices (not shown) via an I / O interface 101. The I / O interface 101 may employ communication protocols / methods, such as, but not limited to, audio, analog, digital, mono, RCA, stereo, IEEE-1394, serial bus, Universal Serial Bus (USB), infrared, PS / 2, BNC, coaxial, component, composite, digital video interface (DVI), high-definition multimedia interface (HDMi), RF antenna, S-Video, VGA, IEEE 802.1n / b / g / n / x, Cellular (e.g., Code Division Multiple Access (CDMA), High-Speed ​​Packet Access (HSPA+), Global System for Mobile Communications (GSM), Long Term Evolution (LTE)). etc.

[0009] In some embodiments, using I / O interface 101, system 100 can communicate with one or more I / O devices. For example, input device 110 may be an antenna, keyboard, mouse, joystick, (infrared) remote control, camera, card reader, fax machine, dongle, biometric reader, microphone, touchscreen, touchpad, trackball, stylus, scanner, storage device, transceiver, video device / source, etc. Output device 111 may be a printer, fax machine, video display (e.g., cathode ray tube (CRT), liquid crystal display (LCD), light-emitting diode (LED), plasma, plasma display panel (PDP), organic light-emitting diode display (OLED), etc.), audio speaker, etc.

[0010] In some embodiments, processor 102 may be configured to communicate with a communication network via network interface 103. Network interface 103 may communicate with the communication network. Network interface 103 may employ connectivity protocols, including but not limited to direct connection, Ethernet (e.g., twisted pair 10 / 100 / 1000Base T), Transmission Control Protocol / Internet Protocol (TCP / IP), Token Ring, IEEE 802.11a / b / g / n / x, etc. Communication networks may include, but are not limited to, direct interconnect, e-commerce networks, peer-to-peer (P2P) networks, local area networks (LANs), wide area networks (WANs), wireless networks (e.g., using Wireless Application Protocol), the Internet, etc. Using network interface 103 and a communication network, system 100 can communicate with one or more service operators or other computers or customer smartphones 230 and / or merchant smartphones 240, as further described herein.

[0011] In some non-limiting embodiments or aspects, processor 102 may be configured to communicate with memory 105 (e.g., RAM, ROM, etc.) via storage interface 104. In some embodiments, storage interface 104 may be connected to memory 105, including but not limited to memory drives, removable optical disc drives, etc., the memory employing a connectivity protocol such as Serial Advanced Technology Attachment (SATA), Integrated Electronic Drive (IDE), IEEE-1394, Universal Serial Bus (USB), Fibre Channel, Small Computer System Interface (SCSI), etc. Memory drives may also include drums, disk drives, magneto-optical drives, optical disc drives, redundant arrays of independent optical discs (RAID), solid-state storage devices, solid-state drives, etc.

[0012] In some embodiments, memory 105 may store a collection of program or database components, including but not limited to a user interface, operating system 107, data repository 130, web server, processes 120, merchant MPPAC audit verification system 150, etc., as described further in detail herein. In some non-limiting embodiments or aspects, system 100 may store user / application data, such as data, variables, records, customer data, merchant data, customer smartphone data, merchant smartphone data, MPPAC data, merchant MPPAC audit verification data, customer-based MPPAC audit data, etc., as described in this disclosure. Such a database may be implemented as a fault-tolerant, relational, scalable, and / or secure database, such as Oracle or Sybase, and / or a non-relational database, such as NoSQL.

[0013] In some embodiments, the operating system 107 may facilitate resource management and operation of the system 100. Examples of operating systems include, but are not limited to, those mentioned above. OS UNIX-like system distribution (e.g., BERKELEY) (BSD) OPENBSD, etc. Distirizations (e.g., RED) wait), OS / ( (7 / 8, 10, etc.) Google TM ANDROID TM etc.

[0014] In some non-limiting embodiments or aspects, system 100 may implement a program component stored in a web browser (not shown). The web browser (not shown) may be a hypertext viewing application, such as Microsoft... INTERNET Google TM CHROME TM , Secure web browsing can be provided using protocols such as Hypertext Transfer Security (HTTPS), Secure Sockets Layer (SSL), and Transport Layer Security (TLS). Web browsers can utilize technologies such as AJAX, DHTML, etc. Facilities such as application programming interfaces (APIs).

[0015] Furthermore, embodiments consistent with this disclosure may be implemented using one or more computer-readable storage media. In some embodiments, a computer-readable storage medium refers to any type of physical memory that can store information or data readable by a processor. Therefore, a computer-readable storage medium may store instructions executable by one or more processors, including instructions causing the processor to perform steps or stages consistent with the embodiments described herein. The term "computer-readable medium" should be understood to include tangible items and exclude carrier waves and transient signals, such as non-transient signals. Examples include random access memory (RAM), read-only memory (ROM), volatile memory, non-volatile memory, hard disk drives, optical disc (CD) ROMs, digital video discs (DVDs), flash drives, magnetic disks, and any other known physical storage media.

[0016] Figure 2A block diagram is shown of a merchant MPPAC audit verification system 150 in a payment network 220 communicatively coupled to a merchant smartphone 240 of merchant 271 and a customer smartphone 230 of customer 261, according to some embodiments, designed to prevent MPPAC-based fraudulent payment transactions. In some embodiments, the payment network 220 is configured to utilize the merchant MPPAC audit verification system 150 in system 100 to perform merchant MPPAC audit verification for merchant 271 and customer-based MPPAC audit for customer 261 of MPPAC 252 displayed on an MPPAC display 250. In some embodiments, the MPPAC display 250 is a physical or electronic display configured for merchant 271 to display the MPPAC generated by the merchant MPPAC audit verification system 150 of the payment network 220. In some embodiments, customer smartphone 230 is a smartphone associated with customer 261, configured to scan MPPAC 252 or capture a photo of MPPAC 252 or the location of MPPAC display 250 for use by merchant MPPAC audit and verification system 150 of payment network 220, as described in further detail herein. In some embodiments, merchant smartphone 240 is a smartphone associated with merchant 271, configured to scan MPPAC 252 or capture a photo of MPPAC 252 or the location of merchant 271 for use by merchant MPPAC audit and verification system 150 of payment network 220, as described in further detail herein. In some embodiments, MPPAC 252 is an MPPAC displayed on MPPAC display 250. In some embodiments, merchant-captured MPPAC 241 is an MPPAC captured by merchant 271 from MPPAC display 250 for auditing and verification by merchant MPPAC audit and verification system 150 using merchant smartphone 240. In some embodiments, the customer-captured MPPAC 231 is an MPPAC captured by customer 261 using customer smartphone 230 from MPPAC display 250. In some embodiments, such as when MPPAC display 250 is a digital or electronic display, payment network 220 may also be communicatively coupled to MPPAC display 250. In some embodiments, payment network 220 utilizes merchant MPPAC audit verification system 150 of system 100 to perform merchant MPPAC audit verification to prevent customer 261 from using fraudulent MPPACs to conduct MPPAC-based payment transactions associated with merchant 271, as described in further detail herein.

[0017] Figure 3A block diagram of a merchant MPPAC audit verification system 150 according to some embodiments is shown. In some embodiments, the merchant MPPAC audit verification system 150 is executable code and / or equivalent hardware configured to perform merchant MPPAC audit verification of merchant 271 and customer-based MPPAC verification of the MPPAC displayed by merchant 271 to customer 261. In some embodiments, merchant MPPAC audit verification is a verification of merchant 271 to ensure that merchant 271 has audited the MPPAC displayed by merchant 271 on MPPAC display 250, preventing the MPPAC displayed by merchant 271 from being used for fraudulent purposes. In some embodiments, customer-based MPPAC verification utilizes MPPAC verification of the MPPAC displayed on MPPAC display 250, which is configured to ensure that the MPPAC captured by customer 261 is a valid MPPAC. In some embodiments, the merchant MPPAC audit verification system 150 includes an MPPAC generation unit 360, an MPPAC evaluation unit 390, a merchant and customer digital photo evaluation unit 340, and an MPPAC identifier evaluation unit 350. In some embodiments, the MPPAC evaluation unit 390 includes a merchant-captured MPPAC evaluation unit 320 and a customer-captured MPPAC evaluation unit 330. In some embodiments, the MPPAC generation unit 360 includes a static MPPAC generator 370 and a dynamic MPPAC generator 380. In some embodiments, the MPPAC identifier evaluation unit 350 includes a merchant-captured MPPAC identifier evaluation unit 351 and a customer-captured MPPAC identifier evaluation unit 352. In some embodiments, the merchant MPPAC audit verification system 150 utilizes the MPPAC generation unit 360, the MPPAC evaluation unit 390, the merchant and customer digital photo evaluation unit 340, and / or the MPPAC identifier evaluation unit 350 to perform merchant MPPAC audit verification and / or customer-based MPPAC verification for merchant 271, as further described herein.

[0018] In some embodiments, during operation, the merchant MPPAC audit verification system 150 of payment network 220 generates MPPAC 361 using MPPAC generation unit 360. In some embodiments, MPPAC 361 is an MPPAC generated by MPPAC generation unit 360, configured not only to perform conventional MPPAC transactions but also for use by the merchant MPPAC audit verification system 150 to perform merchant MPPAC audit verification for merchant 271 and customer-based MPPAC verification of the MPPAC displayed for customer 261 on MPPAC display 250. In some embodiments, MPPAC generation unit 360 is executable code configured to generate MPPAC 361 using static MPPAC generator 370 or dynamic MPPAC generator 380 for use by payment network 220 to perform merchant MPPAC audit verification and / or customer-based MPPAC verification for merchant 271. In some embodiments, the MPPAC 361 generated by the MPPAC generation unit 360 may be a static MPPAC 371 or a dynamic MPPAC 381. In some embodiments, the static MPPAC generator 370 is executable code configured to generate a static MPPAC 371. In some embodiments, the static MPPAC 371 is a static MPPAC configured for use by the merchant MPPAC audit verification system 150 to perform merchant MPPAC audit verification and customer-based MPPAC verification. In some embodiments, the static MPPAC generator 370 generates the static MPPAC 371 by configuring predefined payment network settings, merchant account details, transaction parameters, and security credentials into a fixed account structure for payment processing. In some embodiments, the static MPPAC 371 is configured to include a merchant audit static MPPAC identifier 372. In some embodiments, the merchant audit static MPPAC identifier 372 is an MPPAC identifier in the static MPPAC 371 specifically configured to perform merchant MPPAC audit verification and / or customer-based MPPAC verification for the merchant 271.

[0019] In some embodiments, the dynamic MPPAC generator 380 is executable code configured to generate a dynamic MPPAC 381. In some embodiments, the dynamic MPPAC 381 is a dynamic MPPAC configured for use by the merchant MPPAC audit verification system 150 to perform merchant MPPAC audit verification and customer-based MPPAC verification. In some embodiments, the dynamic MPPAC 381 is configured to include a merchant audit dynamic MPPAC identifier 382. In some embodiments, the merchant audit dynamic MPPAC identifier 382 is an MPPAC identifier in the dynamic MPPAC 381 specifically configured to perform merchant MPPAC audit verification and customer-based MPPAC verification for merchant 271. In some embodiments, the dynamic MPPAC generator 380 generates the dynamic MPPAC in, for example, the following manner: 381: Prepare input data and perform a sequence number-based concatenation (e.g., sequence number('900000001234') || increment-only counter('00000050') || seed('0123456789ABCDEF')). Then, execute a one-way function on the input data, such as SHA256('900000001234000000500123456789ABCDEF') = 'ad2a3335ecc5175f55e337ee704004d84a7f099c6a8dc8d9195'). The input data (without a seed) and the result of the one-way function are encoded using base64 encoding (e.g., BASE64Encode('90000000123400000050ad2a3335ecc5175f55e337ee704004d84a7f099c6a8dc8d9195e2e6acdb44323') = kAAAABI0AAAAUK0qMzXsxRdfVeM37nBABNhKfwmcao3I2RleLmrNtEMj), and an MPPAC is created using the previous output, such as https: / / vi.sa / pay?ref = kAAAABI0AAAAUK0qMzXsxRdfVeM37nBABNhKfwmcao3I2RleLmrNtEMj). In some embodiments, after the MPPAC generation unit 360 generates a dynamic MPPAC 381 or a static MPPAC 371 as MPPAC 361, the MPPAC generation unit 360 provides the MPPAC 361 to the merchant smartphone 240 associated with the merchant 271.

[0020] In some embodiments, a merchant smartphone 240 associated with merchant 271 receives an MPPAC 361 from a merchant MPPAC audit and verification system 150 for merchant 271 to display as MPPAC 252 on, for example, an MPPAC display 250. In some embodiments, merchant 271 displays MPPAC 361 on the MPPAC display 250, enabling customer 261 to scan MPPAC 361 to conduct financial, payment, or other MPPAC-based transactions. In some embodiments, the MPPAC-based transaction is a financial or other type of transaction based on the MPPAC displayed by merchant 271 on the MPPAC display 250, which may be, for example, MPPAC 361 displayed as MPPAC 252. In some embodiments, after displaying MPPAC 361 on the MPPAC display 250, merchant 271 uses merchant smartphone 240 to capture the displayed MPPAC 252 as merchant-captured MPPAC 241. In some embodiments, as previously stated, the merchant-captured MPPAC 241 is an MPPAC (e.g., MPPAC 252) determined or captured by the merchant 271 via an MPPAC display (e.g., MPPAC display 250) for auditing and verification by the merchant MPPAC audit and verification system 150. In some embodiments, the merchant-captured MPPAC 241 is determined by the merchant 271 using, for example, a camera located on the merchant's smartphone 240. In some embodiments, after capturing the displayed MPPAC 252 as the merchant-captured MPPAC 241, the merchant 271 provides the merchant-captured MPPAC 241 to the merchant MPPAC audit and verification system 150 of the payment network 220 via the merchant's smartphone 240.

[0021] In some embodiments, the merchant-captured MPPAC evaluation unit 320 in the MPPAC evaluation unit 390 receives merchant-captured MPPAC 241 from merchant 271 via merchant smartphone 240. In some embodiments, the MPPAC evaluation unit 390 may receive merchant-captured MPPAC 241 from another device, such as a laptop computer or satellite system configured to capture, verify, and / or deliver merchant-captured MPPAC 241. In some embodiments, the MPPAC evaluation unit 390 is executable code configured to perform an MPPAC evaluation of merchant-captured MPPAC 241 received from merchant 271 via merchant smartphone 240 or customer-captured MPPAC 231 received from customer 261 via customer smartphone 230, respectively, using merchant-captured MPPAC evaluation unit 320 or customer-captured MPPAC evaluation unit 330. In some embodiments, the MPPAC evaluation performed by the MPPAC evaluation unit 390 is an evaluation of an MPPAC (e.g., merchant-captured MPPAC 241 and / or customer-captured MPPAC 231) (merchant-captured MPPAC evaluation or customer-captured MPPAC evaluation), which is configured to identify and confirm the MPPAC identifier (merchant-captured MPPAC identifier 321 and / or customer-captured MPPAC identifier 331) of the MPPAC received from the merchant's smartphone 240 and / or the customer's smartphone 230, as further described herein.

[0022] In some embodiments, as previously stated, the merchant-captured MPPAC evaluation unit 320 receives merchant-captured MPPAC 241 from the merchant's smartphone 240. In some embodiments, the merchant-captured MPPAC evaluation unit 320 is executable code configured to perform a merchant-captured MPPAC evaluation on the merchant-captured MPPAC 241. In some embodiments, the merchant-captured MPPAC evaluation is an evaluation of the merchant-captured MPPAC 241 configured to identify and verify a merchant-captured MPPAC identifier 321 for the merchant-captured MPPAC 241. In some embodiments, the merchant-captured MPPAC identifier 321 is an MPPAC identifier associated with the merchant-captured MPPAC 241, used by the merchant MPPAC audit verification system 150 to determine whether the merchant 271 associated with the merchant-captured MPPAC 241 has audited the MPPAC displayed by the merchant 271 on the MPPAC display 250 for use by the customer 261. In some embodiments, the merchant-captured MPPAC identifier 321 may be, for example, a merchant-captured MPPAC URL or a merchant-captured MPPAC string associated with merchant-captured MPPAC 241. In some embodiments, the merchant-captured MPPAC evaluation unit 320 performs merchant-captured MPPAC evaluation by scanning merchant-captured MPPAC 241 and identifies and determines the merchant-captured MPPAC identifier 321 of merchant-captured MPPAC 241. In some embodiments, after determining the merchant-captured MPPAC identifier, the merchant-captured MPPAC evaluation unit 320 provides the merchant-captured MPPAC identifier 321 to the MPPAC identifier evaluation unit 350.

[0023] In some embodiments, the merchant-captured MPPAC identifier evaluation unit 351 of the MPPAC identifier evaluation unit 350 receives the merchant-captured MPPAC identifier 321 from the MPPAC evaluation unit 390. In some embodiments, the MPPAC identifier evaluation unit 350 is executable code configured to perform MPPAC identifier evaluation on the MPPAC identifier associated with the merchant-captured MPPAC 241 or the customer-captured MPPAC 231. In some embodiments, the MPPAC identifier evaluation unit 350 utilizes the merchant-captured MPPAC identifier evaluation unit 351 or the customer-captured MPPAC identifier evaluation unit 352 to perform MPPAC identifier evaluation. In some embodiments, the merchant-captured MPPAC identifier evaluation unit 351 is executable code configured to perform merchant-captured MPPAC identifier evaluation on the merchant-captured MPPAC identifier 321 associated with the merchant-captured MPPAC 241. In some embodiments, the merchant-captured MPPAC identifier evaluation unit 351 in the MPPAC identifier evaluation unit 350 performs merchant-captured MPPAC identifier evaluation by comparing the merchant-captured MPPAC identifier 321 provided from the merchant-captured MPPAC evaluation unit 320 with the merchant audit dynamic MPPAC identifier 382 generated at the MPPAC generation unit 360. In some embodiments, when the merchant-captured MPPAC identifier evaluation unit 351 determines that the merchant-captured MPPAC identifier 321 matches the merchant audit dynamic MPPAC identifier 382, ​​the merchant MPPAC audit verification system 150 provides a notification to the merchant 271 via the merchant's smartphone 240, indicating that the MPPAC 252 is a valid MPPAC (e.g., a non-fraudulent MPPAC) and does not need to be replaced. In some embodiments, when the MPPAC identifier evaluation unit 350 determines that the merchant-captured MPPAC identifier 321 does not match the merchant audit dynamic MPPAC identifier 382, ​​the merchant MPPAC audit verification system 150 provides a notification to the merchant 271 via the merchant's smartphone 240, indicating that MPPAC 252 is not a valid MPPAC and should be replaced to prevent fraudulent transactions based on MPPAC. In some embodiments, MPPAC 252 may be replaced with MPPAC 361 or a new MPPAC generated by the merchant MPPAC audit verification system 150. In some embodiments, the merchant MPPAC audit verification system 150 provides a notification to the merchant 271 to perform confirmation verification on the MPPAC 252 displayed on the MPPAC display 250, and provides the merchant MPPAC audit verification system 150 with an additional merchant-captured MPPAC 241.In some embodiments, the merchant MPPAC audit verification system 150 receives the merchant-captured MPPAC 241 and repeats the merchant MPPAC audit verification until the merchant-captured MPPAC 241 is verified.

[0024] In some embodiments, regarding the customer-captured MPPAC evaluation unit 330, the customer-captured MPPAC evaluation unit 330 in the merchant MPPAC audit verification system 150 receives customer-captured MPPAC 231 from the customer's smartphone 230. In some embodiments, the customer-captured MPPAC evaluation unit 330 is executable code configured to perform a customer-captured MPPAC evaluation on the customer-captured MPPAC 231. In some embodiments, the customer-captured MPPAC evaluation is an evaluation of the customer-captured MPPAC 231, which is configured to identify and verify the customer-captured MPPAC identifier 331 of the customer-captured MPPAC 231. In some embodiments, the customer-captured MPPAC evaluation unit 330 performs the customer-captured MPPAC evaluation by scanning the customer-captured MPPAC 231 and identifying and determining the customer-captured MPPAC identifier 331. In some embodiments, the customer-captured MPPAC identifier 331 is an MPPAC identifier from the customer-captured MPPAC 231 that is used, for example, by the payment network 220 to identify the customer-captured MPPAC 231 for customer-based MPPAC verification. In some embodiments, the customer-captured MPPAC identifier 331 may be, for example, a customer-captured MPPAC URL or a customer-captured MPPAC string associated with the customer-captured MPPAC 231, configured to perform customer-based MPPAC verification on the customer-captured MPPAC 231. In some embodiments, after determining the customer-captured MPPAC identifier 331, the customer-captured MPPAC evaluation unit 330 provides the customer-captured MPPAC identifier 331 to the MPPAC identifier evaluation unit 350.

[0025] In some embodiments, the customer-captured MPPAC identifier evaluation unit 352 in the MPPAC identifier evaluation unit 350 receives the customer-captured MPPAC identifier 331 from the MPPAC evaluation unit 390. In some embodiments, the customer-captured MPPAC identifier evaluation unit 352 is executable code configured to perform customer-captured MPPAC identifier evaluation on the customer-captured MPPAC identifier 331 associated with the customer-captured MPPAC 231. In some embodiments, the customer-captured MPPAC identifier evaluation unit 352 in the MPPAC identifier evaluation unit 350 performs customer-captured MPPAC identifier evaluation by comparing the customer-captured MPPAC identifier 331 provided from the customer-captured MPPAC evaluation unit 330 with the merchant audit dynamic MPPAC identifier 382 of the dynamic MPPAC 381 (or the merchant audit static MPPAC identifier 372 of the static MPPAC 371 generated at the MPPAC generation unit 360). In some embodiments, when the customer-captured MPPAC identifier evaluation unit 352 determines that the customer-captured MPPAC identifier 331 matches the merchant audit dynamic MPPAC identifier 382 (merchant audit static MPPAC identifier 372 of static MPPAC 371), the merchant MPPAC audit verification system 150 provides a notification to the customer 261 via the customer's smartphone 230, indicating that the customer-captured MPPAC (e.g., MPPAC 252 of MPPAC display 250) is a valid MPPAC (e.g., a non-fraudulent MPPAC) and can be used for financial or other types of MPPAC-based transactions associated with the customer-captured MPPAC. In some embodiments, when the MPPAC identifier evaluation unit 350 determines that the MPPAC identifier 331 captured by the customer does not match the merchant audit dynamic MPPAC identifier 382 (or the merchant audit static MPPAC identifier 372 of the static MPPAC 371), the merchant MPPAC audit verification system 150 provides a notification to the customer 261 via the customer's smartphone 230, indicating that the MPPAC 231 captured by the customer (e.g., the MPPAC 252 of the MPPAC display 250) is not a valid MPPAC (e.g., fraudulent) and is not authorized for use in MPPAC-based transactions, thereby preventing fraudulent transactions based on MPPAC.

[0026] In some embodiments, the MPPAC evaluation unit 390 of the merchant MPPAC audit verification system 150 may be configured to perform dynamic MPPAC verification on a merchant-captured dynamic MPPAC 241 or a customer-captured dynamic MPPAC 231. For example, in some embodiments, for a dynamic MPPAC (e.g., a dynamic MPPAC 381 provided to the merchant's smartphone 240 as MPPAC 361 and displayed on the MPPAC display 250), the merchant MPPAC audit verification system 150 may perform dynamic MPPAC verification (for merchant MPPAC audit verification of the merchant-captured MPPAC 241 or customer-based MPPAC verification of the customer-captured MPPAC 231). In some embodiments, as part of dynamic MPPAC verification, the merchant MPPAC audit verification system 150 decodes the merchant-captured MPPAC 241 or customer-captured MPPAC 231 that has been Base64 encoded (e.g., BASE64Decode(kAAAABI0AAAAUK0qMzXsxRdfVeM37nBABNhKfw mcao3I2RleLmrNtEMj) = '90000000123400000050ad2a3335ecc5175f55e337ee704004d84a7f099c6a8dc8d9195e2e6acdb44323').

[0027] In some embodiments, after decoding the Base64-encoded merchant-captured MPPAC 241 or customer-captured MPPAC 231, the merchant MPPAC audit verification system 150 extracts a sequence number from the merchant-captured MPPAC 241 or customer-captured MPPAC 231 to retrieve a seed value (e.g., seed value '0123456789ABCDEF'). In some embodiments, after the merchant MPPAC audit verification system 150 extracts the sequence number from the merchant-captured MPPAC 241 or customer-captured MPPAC 231 to retrieve the seed value, the merchant MPPAC audit verification system 150 performs an increment-only counter value evaluation. In some embodiments, as part of the increment-only counter value evaluation, the merchant MPPAC audit verification system 150 determines whether the increment-only counter value associated with the merchant-captured MPPAC 241 or the customer-captured MPPAC 231 (e.g., increment-only counter value = '00000050') is greater than a previous serial number (e.g., a previous value of the serial number used by the merchant MPPAC audit verification system 150). In some embodiments, when the merchant MPPAC audit verification system 150 determines that the increment-only counter value is greater than the previous serial number, the merchant MPPAC audit verification system 150 saves the value as the latest maximum value of the increment-only counter value associated with the serial number. In some embodiments, when the merchant MPPAC audit verification system 150 determines that the increment-only counter value does not exceed the previous serial number, the merchant MPPAC audit verification system 150 does not save the value as the latest maximum value of the increment-only counter value associated with the serial number.

[0028] In some embodiments, after performing an increment-only counter value evaluation, the merchant MPPAC audit verification system 150 prepares the input data and performs a sequence number-based concatenation (e.g., sequence number ('900000001234') || increment-only counter ('00000050') || seed ('0123456789ABCDEF')). In some embodiments, after performing the sequence number-based concatenation, the merchant MPPAC audit verification system 150 performs a one-way function on the input data (e.g., SHA256('900000001234000000500123456789ABCDEF') = 'ad2a3335ecc5175f55e337ee704004d84a7f099c6a8dc8d9195e2e6acdb44323'). In some embodiments, the one-way function may be a SHA256 one-way function. In some embodiments, after executing the one-way function, the merchant MPPAC audit verification system 150 compares the result of the one-way function execution with the decoded result of the Base64 encoded merchant-captured MPPAC 241 (e.g., comparing 'ad2a3335ecc5175f55e337ee704004d84a7f099c6a8dc8d9195e2e6acdb44323' with '90000000123400000050ad2a3335ecc5175f55e337ee704004d84a7f099c6a8dc8d9195e2e6acdb44323'). In some embodiments, when the merchant MPPAC audit and verification system 150 determines that the result of the one-way function execution is embedded in the decoded result of the Base64-encoded merchant-captured MPPAC 241, the merchant-captured MPPAC 241 is considered a valid, non-fraudulent MPPAC and can be used by the customer 261 for payment transactions. In some embodiments, when the merchant MPPAC audit and verification system 150 determines that the result of the one-way function execution is not embedded in the decoded result of the Base64-encoded merchant-captured MPPAC 241, the merchant-captured MPPAC 241 is considered invalid and fraudulent, and cannot be used by the customer 261 for payment transactions.

[0029] In some embodiments, in addition to receiving customer-captured MPPAC 231 and merchant-captured MPPAC 241, the merchant MPPAC audit verification system 150 (via the merchant and customer digital photo evaluation unit 340) receives merchant-captured digital photos 242 from the merchant's smartphone 240 and customer-captured digital photos 232 from the customer's smartphone 230. In some embodiments, the merchant and customer digital photo evaluation unit 340 is executable code configured to perform digital photo evaluation on the merchant-captured digital photos 242 and customer-captured digital photos 232. In some embodiments, the merchant-captured digital photo 242 is a digital photo of the merchant's location associated with the merchant 271, captured by the merchant 271 using the merchant's smartphone 240, and provided to the merchant and customer digital photo evaluation unit 340. In some embodiments, the customer-captured digital photo 232 is a digital photo of the location of MPPAC 252, captured by the customer 261 using the customer's smartphone 230, and provided to the merchant and customer digital photo evaluation unit 340. In some embodiments, the merchant and customer digital photo evaluation unit 340 performs digital photo evaluation by comparing the location of the customer-captured digital photo associated with the customer-captured digital photo 232 with the location of the merchant-captured digital photo associated with the merchant-captured digital photo 242. In some embodiments, the location of the merchant-captured digital photo is the location of the merchant 271 associated with the merchant-captured digital photo 242, such as the merchant's location and / or geographic location. In some embodiments, the location of the customer-captured digital photo is the location of the MPPAC 252 and the customer 261 associated with the customer-captured digital photo 232, such as the customer's location and / or geographic location. In some embodiments, the merchant-captured digital photo 242 and the customer-captured digital photo 232 may include metadata, such as an exchangeable image file format (EXIF) including geographic location information. In some embodiments, the EXIF ​​may include a digital signature included on the merchant's smartphone 240 or the customer's smartphone 230. In some embodiments, the digital signature can be used to verify the EXIF ​​or confirm that the merchant-captured digital photo 242 has not been tampered with. In some embodiments, to confirm the location of the customer-captured digital photo, the customer-captured digital photo 232 may provide location information similar to that provided by the merchant-captured digital photo 242.

[0030] In some embodiments, as part of a digital photo evaluation, when the merchant and customer digital photo evaluation unit 340 determines that the location of a digital photo captured by a customer does not match the location of a digital photo captured by a merchant, the merchant and customer digital photo evaluation unit 340 disallows MPPAC-based transactions using the displayed MPPAC 252 located at the location of the customer's captured digital photo and notifies the customer 261 and merchant 271 that no transactions related to MPPAC 252 can be conducted until MPPAC 252 is replaced with a valid MPPAC. In some embodiments, as part of a digital photo evaluation of the MPPAC display 250 located at the merchant 271's location, when the merchant and customer digital photo evaluation unit 340 determines that the location of a digital photo captured by a customer does indeed match the location of a digital photo captured by a merchant, the merchant and customer digital photo evaluation unit 340 allows MPPAC-based transactions using the displayed MPPAC 252 located at the location of the customer's captured digital photo and notifies the customer 261 and merchant 271 that the associated MPPAC 252 is not fraudulent and that MPPAC 252 does not currently need to be replaced. In some embodiments, the Merchant MPPAC Audit Verification System 150 may provide a digital photograph 242 captured by the merchant to a customer 261 for the customer to verify the merchant premises or location of the merchant 271 associated with the MPPAC 252. In some embodiments, the customer 261 may download and view the merchant location associated with the digital photograph 242 captured by the merchant, thus visually verifying the merchant 271.

[0031] Figure 4 A merchant MPPAC audit verification method 400 according to some embodiments is illustrated. In some embodiments, the merchant MPPAC audit verification method 400 is configured to verify that the merchant has performed an audit on the MPPAC displayed by merchant 271 on MPPAC display 250. In some embodiments, the merchant MPPAC audit verification method 400 is performed by a merchant MPPAC audit verification system 150. Figure 4 The methods, process steps, or stages illustrated may be implemented as independent routines or processes, or as part of a larger routine or process. It should be noted that in other embodiments, each depicted process step or stage may be implemented as an apparatus, method, or system including a processor executing a set of instructions. In some embodiments, reference is made to… Figures 1-4 Describe the merchant's MPPAC audit verification method 400.

[0032] In some embodiments, reference Figure 1-4At operation 410, the MPPAC generation unit 360 of the payment network 220 generates MPPAC 361. In some embodiments, at operation 420, the MPPAC generation unit 360 of the payment network 220 provides MPPAC 361 to the merchant 271 via the merchant's smartphone 240. In some embodiments, as previously stated, MPPAC 361 is configured for use by the merchant MPPAC audit verification system 150 for merchant MPPAC audit verification. In some embodiments, at operation 430, the MPPAC evaluation unit 390 of the payment network 220 receives the merchant-captured MPPAC 241 from the merchant's smartphone 240. In some embodiments, the merchant-captured MPPAC 241 is available to the merchant 271 for performing merchant MPPAC audit verification. In some embodiments, at operation 440, the merchant MPPAC audit verification system 150 of the payment network 220 uses MPPAC 361 and the merchant-captured MPPAC 241 to verify that the merchant 271 has audited the MPPAC displayed by the merchant 271 on the MPPAC display 250.

[0033] In some embodiments, the MPPAC identifier (e.g., Merchant Audit Static MPPAC Identifier 372 and / or Merchant Audit Dynamic MPPAC Identifier 382) may include Merchant MPPAC audit verification information (e.g., Merchant MPPAC audit verification label (e.g., numeric or alphanumeric label)) configured to indicate to the Merchant MPPAC audit verification system 150 that the Merchant MPPAC audit is performed by the Merchant 271 and that the Merchant MPPAC audit verification system 150 will perform the Merchant MPPAC audit verification.

[0034] In some embodiments, the MPPAC identifier (e.g., Merchant Audit Static MPPAC Identifier 372 and / or Merchant Audit Dynamic MPPAC Identifier 382) may include customer-based MPPAC verification information (e.g., customer-based MPPAC verification label (e.g., numeric or alphanumeric label)) configured to indicate to the Merchant MPPAC Audit Verification System 150 that the customer-based MPPAC verification was initiated and requested by the customer 261 and that the Merchant MPPAC Audit Verification System 150 will perform the customer-based MPPAC verification.

[0035] In some embodiments, the Merchant MPPAC Audit and Verification System 150 is an optimization of other computer systems because it optimizes, for example, authentication and transaction processes, thereby reducing the need for additional equipment required to enhance security and reduce fraud risk. In some embodiments, by evaluating and utilizing the simplified methods provided by the Merchant MPPAC Audit and Verification System 150, it minimizes inefficiencies and potential vulnerabilities, thereby enabling more efficient resource management and data processing. The improvements provided by the Merchant MPPAC Audit and Verification System 150 contribute to increased system reliability and better compliance with security standards, thereby enhancing the overall system.

[0036] In some embodiments, the Merchant MPPAC Audit Verification System 150 may be configured to perform Merchant MPPAC audit verification using an MPPAC based on the NFC Data Exchange Format (NDEF). For example, the Merchant MPPAC Audit Verification System 150 may be configured to perform Merchant MPPAC audit verification using an NFC tag. In some embodiments, the NFC tag may be displayed on a display configured to hold or embed the NFC tag. In some embodiments, the NFC tag may be displayed on the display, enabling the Merchant MPPAC Audit Verification System 150 to perform Merchant MPPAC audit verification using the NFC tag. In some embodiments, Merchant 271 may scan the NFC tag using an NFC reader. In some embodiments, in addition to the standard NFC tag transaction information provided in a conventional NFC tag transaction, the NFC reader also provides Merchant MPPAC audit verification information (e.g., a Merchant MPPAC audit verification tag (e.g., a numeric or alphanumeric tag)), which is configured to instruct the Merchant MPPAC Audit Verification System 150 that the Merchant MPPAC audit is performed by Merchant 271 and that the Merchant MPPAC Audit Verification System 150 will perform the Merchant MPPAC audit verification.

[0037] In some embodiments, a computer-implemented method includes: generating a payment acceptance certificate (MPPAC) presented by a merchant at a payment network, the MPPAC generated by the payment network being configured for merchant MPPAC auditing; providing the MPPAC generated by the payment network to the merchant for merchant MPPAC auditing; receiving an MPPAC captured by the merchant at the payment network, the merchant-captured MPPAC having been captured by the merchant for merchant MPPAC auditing verification; and performing the merchant MPPAC auditing verification at the payment network using the MPPAC generated by the payment network and the MPPAC captured by the merchant.

[0038] In some embodiments, the computer-implemented method further includes: performing an MPPAC identifier evaluation on the MPPAC generated by the payment network and the MPPAC captured by the merchant as part of the merchant's MPPAC audit verification.

[0039] In some embodiments of the computer-implemented method, as part of the MPPAC identifier evaluation, an MPPAC identifier comparison is performed at the payment network.

[0040] In some embodiments of the computer-implemented method, as part of the MPPAC identifier comparison, a merchant-captured MPPAC identifier associated with the merchant-captured MPPAC is compared with a payment network-generated MPPAC identifier associated with the payment network-generated MPPAC.

[0041] In some embodiments of the computer-implemented method, when the MPPAC identifier captured by the merchant and the MPPAC identifier generated by the payment network do not match as the result of the MPPAC identifier comparison, the merchant is notified to perform the merchant MPPAC audit.

[0042] In some embodiments of the computer-implemented method, the merchant-captured MPPAC identifier is a merchant-captured MPPAC URL, and the MPPAC identifier generated by the payment network is an MPPAC URL generated by the payment network.

[0043] In some embodiments of the computer-implemented method, the merchant-captured MPPAC identifier is a merchant-captured MPPAC string, and the MPPAC identifier generated by the payment network is an MPPAC string generated by the payment network.

[0044] In some embodiments of the computer-implemented method, the MPPAC generated by the payment network is a dynamically generated MPPAC by the payment network.

[0045] In some embodiments, a system includes: a processor; and a non-transient computer-readable medium coupled to the processor, the non-transient computer-readable medium including code configured to: generate at a payment network a payment acceptance credential (MPPAC) presented by a merchant and generated by the payment network, the MPPAC being configured for merchant MPPAC auditing; provide the payment network-generated MPPAC to the merchant for merchant MPPAC auditing; receive at the payment network a merchant-captured MPPAC, the merchant-captured MPPAC having been captured by the merchant for merchant MPPAC auditing verification; and perform the merchant MPPAC auditing verification at the payment network using the payment network-generated MPPAC and the merchant-captured MPPAC.

[0046] In some embodiments, the system further includes code for performing an MPPAC identifier evaluation on the MPPAC generated by the payment network and the MPPAC captured by the merchant, as part of the merchant's MPPAC audit verification.

[0047] In some embodiments of the system, MPPAC identifier comparison is performed at the payment network as part of the MPPAC identifier evaluation.

[0048] In some embodiments, the system further includes code for comparing, as part of the MPPAC identifier comparison, a merchant-captured MPPAC identifier associated with the merchant-captured MPPAC and a payment network-generated MPPAC identifier associated with the payment network-generated MPPAC.

[0049] In some embodiments, the system further includes code for: when the MPPAC identifier captured by the merchant and the MPPAC identifier generated by the payment network do not match as the MPPAC identifier comparison result, notifying the merchant to perform the merchant MPPAC audit.

[0050] In some embodiments of the system, the MPPAC identifier captured by the merchant is the MPPAC URL captured by the merchant, and the MPPAC identifier generated by the payment network is the MPPAC URL generated by the payment network.

[0051] In some embodiments of the system, the MPPAC identifier captured by the merchant is an MPPAC string captured by the merchant, and the MPPAC identifier generated by the payment network is an MPPAC string generated by the payment network.

[0052] In some embodiments of the system, the MPPAC generated by the payment network is a dynamically generated MPPAC by the payment network.

[0053] In some embodiments, a method includes: generating a dynamic merchant-captured payment acceptance credential (MPPAC) presented by a merchant at a payment network, the dynamic MPPAC being configured for dynamic MPPAC audit verification; providing the dynamic MPPAC to a merchant; receiving the merchant-captured dynamic MPPAC at the payment network; and performing dynamic MPPAC audit verification using the dynamic MPPAC and the merchant-captured dynamic MPPAC, the dynamic MPPAC audit verification being configured to verify that the merchant has performed an MPPAC audit.

[0054] In some embodiments of the method, as part of the dynamic MPPAC audit verification, dynamic MPPAC code comparison is used to verify the dynamic MPPAC code associated with the dynamic MPPAC.

[0055] In some embodiments of the method, after verifying the dynamic MPPAC audit verification, the payment network uses a photograph of the merchant's premises provided by the merchant to allow customers to verify the merchant.

[0056] In some embodiments of the method, the payment network verifies the merchant for the customer by comparing a digital photo of the merchant's premises taken by the customer with a photo of the merchant's premises provided by the merchant.

Claims

1. A computer-implemented method comprising: A payment acceptance credential (MPPAC) generated by the payment network and presented by the merchant is generated at the payment network, and the MPPAC generated by the payment network is configured for merchant MPPAC auditing. The MPPAC generated by the payment network is provided to the merchant for the merchant's MPPAC audit; The payment network receives the merchant-captured MPPAC, which has been captured by the merchant for merchant MPPAC audit verification. as well as The payment network utilizes the MPPAC generated by the payment network and the MPPAC captured by the merchant to perform merchant MPPAC audit verification.

2. The computer-implemented method according to claim 1, further comprising: As part of the merchant's MPPAC audit verification, an MPPAC identifier evaluation is performed on the MPPAC generated by the payment network and the MPPAC captured by the merchant.

3. The computer-implemented method according to claim 2, wherein: As part of the evaluation of the MPPAC identifier, an MPPAC identifier comparison is performed at the payment network.

4. The computer-implemented method according to claim 3, wherein: As part of the MPPAC identifier comparison, the merchant-captured MPPAC identifier associated with the merchant-captured MPPAC is compared with the payment network-generated MPPAC identifier associated with the payment network-generated MPPAC.

5. The computer-implemented method according to claim 4, wherein: When the comparison result of the MPPAC identifier used as the comparison is that the MPPAC identifier captured by the merchant and the MPPAC identifier generated by the payment network do not match, the merchant is notified to perform the merchant MPPAC audit.

6. The computer-implemented method according to claim 5, wherein: The MPPAC identifier captured by the merchant is the MPPAC URL captured by the merchant, and the MPPAC identifier generated by the payment network is the MPPAC URL generated by the payment network.

7. The computer-implemented method according to claim 5, wherein: The MPPAC identifier captured by the merchant is an MPPAC string captured by the merchant, and the MPPAC identifier generated by the payment network is an MPPAC string generated by the payment network.

8. The computer-implemented method according to claim 7, wherein: The MPPAC generated by the payment network is a dynamic MPPAC generated by the payment network.

9. A system comprising: processor; as well as A non-transient computer-readable medium coupled to the processor, the non-transient computer-readable medium including code for: A payment acceptance credential (MPPAC) generated by the payment network and presented by the merchant is generated at the payment network, and the MPPAC generated by the payment network is configured for merchant MPPAC auditing. The MPPAC generated by the payment network is provided to the merchant for the merchant's MPPAC audit; The payment network receives the merchant-captured MPPAC, which has been captured by the merchant for merchant MPPAC audit verification. as well as The payment network utilizes the MPPAC generated by the payment network and the MPPAC captured by the merchant to perform merchant MPPAC audit verification.

10. The system of claim 9, further comprising code for: As part of the merchant's MPPAC audit verification, an MPPAC identifier evaluation is performed on the MPPAC generated by the payment network and the MPPAC captured by the merchant.

11. The system according to claim 10, wherein: As part of the evaluation of the MPPAC identifier, an MPPAC identifier comparison is performed at the payment network.

12. The system of claim 11, further comprising code for: As part of the MPPAC identifier comparison, the merchant-captured MPPAC identifier associated with the merchant-captured MPPAC is compared with the payment network-generated MPPAC identifier associated with the payment network-generated MPPAC.

13. The system of claim 12, further comprising code for: When the comparison result of the MPPAC identifier used as the comparison is that the MPPAC identifier captured by the merchant and the MPPAC identifier generated by the payment network do not match, the merchant is notified to perform the merchant MPPAC audit.

14. The system according to claim 13, wherein: The MPPAC identifier captured by the merchant is the MPPAC URL captured by the merchant, and the MPPAC identifier generated by the payment network is the MPPAC URL generated by the payment network.

15. The system according to claim 14, wherein: The MPPAC identifier captured by the merchant is an MPPAC string captured by the merchant, and the MPPAC identifier generated by the payment network is an MPPAC string generated by the payment network.

16. The system according to claim 15, wherein: The MPPAC generated by the payment network is a dynamic MPPAC generated by the payment network.

17. A method comprising: A dynamic merchant-captured payment acceptance credential (MPPAC) is generated at the payment network, and the dynamic MPPAC is configured for dynamic MPPAC audit verification. Provide the dynamic MPPAC to the merchant; Receive the dynamic MPPAC captured by the merchant at the payment network; as well as Dynamic MPPAC audit verification is performed using the dynamic MPPAC and the dynamic MPPAC captured by the merchant, and the dynamic MPPAC audit verification is configured to verify that the merchant has performed an MPPAC audit.

18. The method of claim 17, wherein: As part of the dynamic MPPAC audit verification, dynamic MPPAC code comparison is used to verify the dynamic MPPAC code associated with the dynamic MPPAC.

19. The method of claim 18, wherein: After verifying the dynamic MPPAC audit verification, the payment network uses the merchant's location photos provided by the merchant to allow customers to verify the merchant.

20. The method of claim 19, wherein: The payment network verifies the merchant for the customer by comparing a digital photo of the merchant's premises taken by the customer with a photo of the merchant's premises provided by the merchant.