Systems and methods for ephemeral vcn provisioning

HK40137848APending Publication Date: 2026-09-18CAPITAL ONE SERVICES LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
HK62026126636
Authority / Receiving Office
HK · HK
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-07-20
Filing Date
2026-07-24
Publication Date
2026-09-18
Estimated Expiration
2044-07-17

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Example embodiments disclose systems and methods for configuring a virtual card number (VCN) directly to a merchant processor responsible for consumer transactions. The VCN may be constrained according to one or more constraints, and in some embodiments, the prediction model may generate one or more constraints.
Need to check novelty before this filing date? Find Prior Art

Description

(19) State Intellectual Property Office (12) Invention Patent Application (10) Application Publication Number (43) Application Publication Date (21) Application Number 202480045238.8 (22) Application Date 2024.07.18 (30) Priority Data 18 / 224,264 2023.07.20 US (85) PCT International Application Entering National Phase Date 2025.12.31 (86) PCT International Application Application Data PCT / US2024 / 038571 2024.07.18 (87) PCT International Application Publication Data WO2025 / 019689 EN 2025.01.23 (71) Applicant: Capital Services LLC Address: USA (72) Inventor: Jeffrey Rul Bob Uni Koshkori Chaisdrick Sch (74) Patent Agency: Beijing Pinyuan Patent Agency Co., Ltd. 11332 Patent Attorneys Tan Yingying and Hu Bin (51) Int.Cl. G06Q 20 / 22 (2006.01) G06Q 20 / 32 (2006.01) G06Q 20 / 34 (2006.01) G06Q 20 / 36 (2006.01) G06Q 20 / 38 (2006.01) G06Q 20 / 40 (2006.01) (54) Invention Title System and Method for Provisional VCN Configuration (57) Abstract Example Embodiments A system and method for configuring a virtual card number (VCN) directly to a merchant processor responsible for consumer transactions are disclosed. The VCN can be constrained according to one or more constraints, and in some embodiments, a predictive model can generate one or more constraints. Claims 2 pages, Description 22 pages, Drawings 10 pages, CN 121444115 A 2026.01.30 CN 1 21 44 41 15 A 1. A system for generating a virtual card number (VCN), the system comprising: a server including a banking application, wherein the banking application is configured to: receive one or more user identification data from a user device application; match the one or more user identification data with a user profile; send an authentication request to the user device application; receive authentication credentials from the user device application; retrieve one or more primary account numbers (PANs) associated with the user profile; send a prompt to the user device application to select one or more PANs to use for completing a transaction; receive a selection of one or more PANs from the user device application; generate a virtual card number (VCN) associated with the selected one or more PANs; and send the VCN to a merchant processor. 2. The system of claim 1, wherein the VCN is bound to one or more merchants.3. The system of claim 1, wherein the VCN is configured to expire after a predetermined time period. 4. The system of claim 1, wherein the VCN is restricted to a predetermined spending limit. 5. The system of claim 1, wherein the banking application is further configured to store the VCN in a data storage unit for later use when the VCN is generated. 6. The system of claim 1, wherein the VCN is constrained to one or more merchants and one or more merchant categories. 7. The system of claim 6, wherein the banking application is further configured to dynamically create merchant categories based on spending history associated with the user profile. 8. The system of claim 1, wherein the banking application is further configured to: retrieve user location data associated with the user profile from a database; analyze trends in the user location data; and generate a predictive model configured to determine constraints on the VCN, wherein the predictive model includes a model of one or more future spending habits predicted by a predetermined algorithm associated with the user profile. 9. The system of claim 1, wherein the banking application is further configured to: retrieve historical consumption data associated with the user profile from a database; analyze trends in the historical consumption data; and generate a predictive model configured to determine constraints on the VCN, wherein the predictive model includes a model of one or more future consumption habits predicted by a predetermined algorithm associated with the user profile. 10. The system of claim 1, wherein the banking application is further configured to: retrieve historical user fraud data associated with the user profile; analyze trends in the historical user fraud data; and generate a predictive model configured to determine constraints on the VCN, wherein the predictive model includes a model of one or more future consumption habits predicted by a predetermined algorithm associated with the user profile.11. A method for generating a virtual card number (VCN), the method comprising the steps of: receiving one or more user identification data by a banking application associated with a server; matching the one or more user identification data with a user profile by the banking application; sending an authentication request by the banking application to a user device application; receiving authentication credentials by the banking application from the user device application; retrieving one or more primary account numbers (PANs) associated with the user profile; sending a prompt to the user device application to select one or more PANs to use for completing transactions; receiving a selection of one or more PANs from the user device application; generating a virtual card number (VCN) associated with the selected one or more PANs by the banking application; and sending the VCN to a merchant processor by the banking application. 12. The method of claim 11, wherein the VCN is constrained to at least one of a predetermined time period, merchant, geographic location, or price. 13. The method of claim 12, wherein the predetermined constraint is dynamically changed by the banking application in response to one or more spending habits associated with the user profile. 14. The method of claim 11, further comprising the steps of: retrieving consumption history data associated with the user profile from a database; analyzing trends in the consumption history data; and generating a predictive model configured to determine constraints on the VCN, wherein the constraints are based on a predetermined set of merchant categories. 15. The method of claim 14, further comprising the steps of: generating the VCN upon receiving a selection of one or more PANs, wherein the VCN is bound to one or more selected PANs. 16. The method of claim 15, wherein the VCN is sent from the processor to the merchant processor without notifying the user of the existence of the VCN. 17. The method of claim 11, further comprising the steps of: receiving fraud detection associated with the VCN by the processor; and changing one or more constraints associated with the VCN by the processor in response to the fraud detection. 18. The method of claim 11, wherein the authentication credentials include a Short Message Service (SMS) One-Time Password (OTP), a password, biometrics, or a unique customer identifier. 19. The method of claim 18, wherein the authentication credential is transmitted via a communication field including Near Field Communication (NFC), Radio Frequency Identification (RFID), or Bluetooth.20. A computer-readable non-transitory medium including computer-executable instructions, which, when executed by a computer hardware device including a processor, cause the computer hardware device to perform the following processes: receiving one or more user identification data; matching the one or more user identification data with a user profile; sending an authentication request to a user device application; receiving authentication credentials from the user device application; retrieving one or more primary accounts (PANs) associated with the user profile; sending a prompt to the user device application to select one or more PANs to use for completing a transaction; receiving a selection of one or more PANs from the user device application; generating a virtual card number (VCN) associated with the selected one or more PANs; and sending the VCN to a merchant processor. Claims 2 / 2 Page 3 CN 121444115 A System and Method for Temporary VCN Configuration

[0001] Cross-Reference to Related Applications

[0002] This application claims priority to U.S. Patent Application No. 18 / 224,264, filed July 20, 2023, the entire contents of which are incorporated herein by reference. Technical Field

[0003] This disclosure relates to systems and methods for configuring a VCN without sharing the virtual card number (VCN) with the user. Background Art

[0004] Virtual card numbers (VCNs) are frequently used for customer transactions. VCNs are useful because they add an extra layer of security, especially for online transactions. By using a virtual card number, customers can prevent their actual credit or debit card information from being exposed to hackers, fraudsters, or other malicious actors.

[0005] However, VCNs still face the risk of malicious third-party fraud and privacy violations. Conventional systems and methods only allow the VCN to be sent to the merchant by the user, thus exposing the VCN to a greater risk of fraud.

[0006] These and other drawbacks exist. Therefore, there is a need to provide systems and methods for configuring VCNs that overcome these drawbacks. Summary of the Invention

[0007] Aspects of the disclosed embodiments include systems and methods for generating a VCN and sharing the VCN directly with a merchant processor.

[0008] In some aspects, the technology described herein relates to a system for generating a VCN, the system comprising: a server including a banking application, wherein the banking application is configured to: receive one or more user identification data from a user device application; match the one or more user identification data with a user profile; send an authentication request to the user device application; receive authentication credentials from the user device application; retrieve one or more primary account numbers (PANs) associated with the user profile; send a prompt to the user device application to select one or more PANs to use for completing a transaction; receive a selection of one or more PANs from the user device application; generate a VCN associated with the selected one or more PANs; and send the VCN to a merchant processor.

[0009] In some aspects, the technology described herein relates to a method for generating a VCN, the method comprising the steps of: receiving one or more user identification data by a banking application associated with a server; matching the one or more user identification data with a user profile by the banking application; sending an authentication request by the banking application to a user device application; receiving authentication credentials by the banking application from the user device application; retrieving one or more PANs associated with the user profile; sending a prompt to the user device application to select one or more PANs to use for completing a transaction; receiving a selection of one or more PANs from the user device application; generating a VCN associated with the selected one or more PANs by the banking application; and sending the VCN to a merchant processor by the banking application.

[0010] In some aspects, the technology described herein relates to a computer-readable non-transitory medium comprising computer-executable instructions that, when executed by a computer hardware device including a processor, cause the computer hardware device to perform the following processes, including: receiving one or more user identification data; matching one or more user identification data with a user profile; sending an authentication request to a user equipment application; receiving authentication credentials from the user equipment application; retrieving one or more PANs associated with the user profile; sending a prompt to the user equipment application to select one or more PANs to complete a transaction thereunder; receiving a selection of one or more PANs from the user equipment application; generating a VCN associated with the selected one or more PANs; and sending the VCN to a merchant processor.

[0011] Further features of the disclosed systems and methods and the advantages they provide will be explained in more detail below with reference to specific exemplary embodiments shown in the accompanying drawings. Brief Description of the Drawings

[0012] Reference is now made to the accompanying drawings for a fuller understanding of the invention. The drawings should not be construed as limiting the invention, but are merely intended to illustrate different aspects and embodiments of the invention.

[0013] FIG1 illustrates a system according to an exemplary embodiment.

[0014] FIG2 illustrates a card according to an exemplary embodiment.

[0015] FIG3 illustrates a contact pad of a card according to an exemplary embodiment.

[0016] FIG4 illustrates a virtual card number constraint according to an exemplary embodiment.

[0017] FIG5 illustrates a method according to an exemplary embodiment.

[0018] FIG6 illustrates a method according to an exemplary embodiment.

[0019] FIG7 illustrates a method according to an exemplary embodiment.

[0020] FIG8 illustrates a method according to an exemplary embodiment.

[0021] FIG9 illustrates a method according to an exemplary embodiment.

[0022] FIG10 illustrates a neural network according to an exemplary embodiment. Detailed Description

[0023] Exemplary embodiments of the invention will now be described to illustrate various features of the invention. The embodiments described herein are not intended to limit the scope of the invention, but are intended to provide examples of components, use, and operation of the invention.

[0024] Furthermore, the features, advantages, and characteristics described in the exemplary embodiments can be combined in any suitable manner. Those skilled in the art will recognize that embodiments can be practiced without one or more specific features or advantages of the embodiments, and that features, advantages, and characteristics of any example embodiment can be combined interchangeably with features, advantages, and characteristics of any other embodiment. In some embodiments, additional features and advantages that may not be present in all embodiments will be recognized.

[0025] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the invention. In this respect, each block in a flowchart or block diagram may represent a module, segment, or portion of instructions comprising one or more executable instructions for implementing one or more specified logical functions. In some alternative implementations, the functions described in a block may appear in the order shown in the figures. For example, depending on the functions involved, two blocks shown consecutively may actually be executed substantially simultaneously, or these blocks may sometimes be executed in reverse order. It will also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a system based on dedicated hardware that performs the specified function or action or executes a combination of dedicated hardware and computer instructions.

[0026] There is a high risk of fraud if the customer generates the VCN themselves or is able to see the VCN. For example, the customer may inadvertently disclose the VCN through a phishing scam or have it stolen in a data breach. Furthermore, if a customer generates a VCN (Version 5 CN 121444115 A, page 2 / 22 of the manual), they are more likely to reuse the same VCN for multiple transactions, which increases the risk of fraud if the VCN is leaked.Furthermore, if customers see the VCN, they are more likely to write it down or take a screenshot for future reference. This can make the VCN easier to steal, especially if the customer stores it in an insecure location.

[0027] As a solution to this problem, this disclosure explains how a VCN can be generated and sent directly to the merchant processor responsible for completing the transaction. Sending the VCN directly to the merchant for processing, rather than through the customer, provides several additional advantages. First, it eliminates the risk of the customer accidentally or intentionally sharing the VCN with unauthorized parties. This can significantly reduce the risk of fraud and unauthorized transactions. Second, it also simplifies the payment process for customers, as they do not need to manually type the VCN during the checkout process. This can make the payment process faster and more convenient, resulting in a better customer experience. Third, sending the VCN directly to the merchant for processing can help reduce the risk of errors during the payment process. If the customer types the VCN incorrectly or makes a mistake when entering other payment details, it can lead to delays or errors in processing the payment. This risk can be mitigated by eliminating the need for the customer to type the VCN. Overall, sending VCNs directly to merchants for processing provides customers with a streamlined and secure payment experience while reducing the risk of fraud and payment errors.

[0028] Furthermore, restricting VCNs to a specific set of merchant categories (such as grocery shopping and gas) offers several advantages. First, it helps reduce the risk of unauthorized transactions. Since VCNs are limited to specific merchant categories, they cannot be used for purchases at other types of merchants. This helps prevent fraudsters from using VCNs for unauthorized purchases, thereby reducing the risk of refunds and other payment disputes. Second, it helps simplify the tracking and management of VCNs. By restricting VCNs to specific merchant categories, transactions made using VCNs can be more easily tracked and managed. This helps streamline the reconciliation process and reduces the risk of errors. Overall, restricting VCNs to a specific set of merchant categories provides greater security, simplifies transaction management, and enhances customer confidence in the payment system.

[0029] In addition, the benefit of using predictive models or neural networks to determine how VCNs should be restricted is that it can provide a more accurate and effective way to detect and prevent fraud while still allowing legitimate transactions to pass through. By analyzing past transaction data and learning patterns from legitimate transactions, predictive models or neural networks can determine the most effective constraints for a VCN based on factors such as merchant category, transaction amount, and location. This helps prevent fraudulent transactions, as any transaction that does not conform to the established patterns or constraints can be flagged for further review or rejected outright.Furthermore, predictive models or neural networks can adapt to new patterns and trends in real time, allowing them to adjust constraints on the VCN as needed to stay ahead of evolving fraud techniques. This is especially important in today's ever-evolving digital environment, where fraudsters are constantly seeking new ways to exploit vulnerabilities in payment systems.

[0030] Finally, sending the VCN directly to the merchant can help protect network bandwidth. This is because sending the VCN to the customer first, and then having the customer submit it to the merchant, requires additional network traffic and data transmission. By eliminating this extra step, the process becomes more efficient and reduces network congestion, which can shorten transaction times and reduce costs for all parties involved.

[0031] Figure 1 illustrates a system 100 according to an exemplary embodiment. System 100 may include a user device 110, a card 120, a payment information processor 130, a network 140, a database 150, and a server 160. Although Figure 1 shows a single instance of the components of system 100, system 100 may include any number of components.

[0032] System 100 may include user device 110. User device 110 may be a network-enabled computer device. Exemplary network-enabled computer devices may include, but are not limited to, servers, web applications, personal computers, workstations, telephones, handheld personal computers, personal digital assistants, thin clients, fat clients, internet browsers, mobile devices, kiosks, cards (e.g., contactless cards, contact-based cards), automated teller machines (ATMs) or other computer or communication devices. For example, network-enabled computer devices may include Apple®'s iPhone, iPod, iPad and / or any other mobile device running Apple's iOS® operating system, any device running Microsoft's Windows® mobile operating system, any device running Google's Android® operating system and / or any other smartphone, tablet or similar wearable mobile device. Wearable smart devices may include, but are not limited to, smartwatches.

[0033] User device 110 may include a processor 111, memory 112 and applications 113. Processor 111 may be a processor, microprocessor or other processor, and user device 110 may include one or more of these processors. Processor 111 may include processing circuitry that may include additional components required to perform the functions described herein, including additional processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware.

[0034] Processor 111 may be coupled to memory 112.Memory 108 may be a read-only memory, a write-once-read-many memory, or a read / write memory, such as RAM, ROM, and EEPROM, and user equipment 110 may include one or more of these memories. Read-only memory can be programmed by the manufacturer to be read-only or programmable only once. One-time programmability provides the opportunity to write once and then read multiple times. Write-once / read-many memory can be programmed at a single point in time. Once programmed, memory cannot be rewritten but can be read multiple times. Read / write memory can be programmed and reprogrammed multiple times after leaving the factory. It can also be read multiple times. Memory 112 may be configured to store one or more software applications (such as application 113), as well as other data, such as user privacy data and financial account information.

[0035] Application 113 may include one or more software applications, such as mobile applications and web browsers, including instructions for execution on user equipment 110. In some examples, user equipment 110 may execute one or more applications (such as software applications) that are capable of, for example, communicating over a network with one or more components of system 100, sending and / or receiving data, and performing the functions described herein. After execution by processor 111, application 113 can provide the functions described in this specification, specifically, implement and perform the steps and functions in the processing flow described below. These processes can be implemented in software (such as software modules) for execution by a computer or other machine. Application 113 can provide a graphical user interface (GUI) through which a user can view and interact with other components and devices within system 100. The GUI can be formatted as, for example, Hypertext Markup Language (HTML), Extensible Markup Language (XML), or any other suitable form of web page, depending on the application used by the user to interact with system 100 and its presentation on the display device.

[0036] User equipment may also include display 114 and input device 115. Display 114 can be any type of device for presenting visual information (such as a computer monitor, flat panel display, and mobile device screen), including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. Input device 115 can include any device for inputting information into user equipment 110 that is available and supported by user equipment 110, such as a touch screen, keyboard, mouse, cursor control device, microphone, digital camera, video recorder, or portable video camera. These devices can be used to input information and interact with the software and other devices described herein.

[0037] System 100 may include one or more cards 120, which will be further explained below with reference to Figures 2 and 3. In some embodiments, card 120 may wirelessly communicate with user equipment 110 using NFC.

[0038] System 100 may include a payment information processor 130.The payment information processor 130 may be a network-enabled computer device. Exemplary network-enabled computer devices may include, but are not limited to, servers, web applications, personal computers, workstations, telephones, handheld personal computers, personal digital assistants, thin clients, fat clients, internet browsers, mobile devices, kiosks, cards (e.g., contactless cards, contact-based cards), automated teller machines (ATMs), or other computer or communication devices. For example, a network-enabled computer device may include Apple®'s iPhone, iPod, iPad, and / or any other mobile device running Apple's iOS® operating system, any device running Microsoft's Windows® mobile operating system, any device running Google's Android® operating system, and / or any other smartphone, tablet, or similar wearable mobile device.

[0039] The payment information processor 130 may include a processor 131, memory 132, and application 133. The processor 131 may be a processor, microprocessor, or other processor, and the payment information processor 130 may include one or more of these processors. Processor 131 may include processing circuitry that may include additional components, including additional processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware, as required to perform the functions described herein.

[0040] Processor 131 may be coupled to memory 132. Memory 132 may be read-only memory, write-once-read-many memory, or read / write memory, such as RAM, ROM, and EEPROM, and payment information processor 130 may include one or more of these memories. Read-only memory may be programmable by the manufacturer to be read-only or programmable only once. One-time programmability provides the opportunity to write once and then read multiple times. Write-once-read-many memory can be programmed at some point after the memory chip has been manufactured. Once the memory is programmed, it cannot be rewritten but can be read multiple times. Read / write memory can be programmed and reprogrammed multiple times after it has been manufactured. It can also be read multiple times. Memory 132 may be configured to store one or more software applications, such as application 133, as well as other data, such as user privacy data and financial account information.

[0041] Application 133 may include one or more software applications that include instructions for execution on payment information processor 130. In some examples, payment information processor 130 may execute one or more applications (such as software applications) that are capable of, for example, communicating with one or more components of system 100 via a network, sending and / or receiving data, and performing the functions described herein.When processor 131 executes, application 133 may provide the functionality described herein, specifically implementing and performing the steps and functions in the processing flow described below. These processes may be implemented in software (such as software modules) for execution by a computer or other machine. Application 133 may provide a GUI through which a user can view and interact with other components and devices within system 100. The GUI may be formatted as, for example, Hypertext Markup Language (HTML), Extensible Markup Language (XML), or any other suitable form of web page, depending on the application used by the user to interact with system 100 and its presentation on the display device.

[0042] Payment information processor 130 may also include display 134 and / or input device 134. Display 134 may be any type of device for presenting visual information (such as a computer monitor, flat panel display, and mobile device screen), including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. Input device 135 may include any device available to and supported by payment information processor 130 for inputting information into payment information processor 130, such as touchscreen, keyboard, mouse, cursor control device, microphone, digital camera, video recorder, or portable video camera. These devices may be used to input information and interact with the software and other devices described herein.

[0043] System 100 may include one or more networks 140. In some examples, network 140 may be one or more of a wireless network, a wired network, or any combination of wireless and wired networks, and may be configured to connect user equipment 110, card 120, payment information processor 130, database 150, and server 160. For example, network 140 may include one or more of the following: fiber optic network, passive optical network, cable network, Internet, satellite network, wireless local area network (LAN), Global System for Mobile Communications (GSMO), personal communication service, personal area network, wireless application protocol, multimedia messaging service, enhanced messaging service, short message service, time division multiplexing-based system, code division multiple access-based system, D-AMPS, Wi-Fi, fixed wireless data, IEEE 802.11b, 802.15.1, 802.11n and 802.11g, Bluetooth, NFC, radio frequency identification (RFID), Wi-Fi and / or the like.

[0044] Furthermore, network 140 may include, but is not limited to, telephone lines, fiber optics, IEEE Ethernet 902.3, wide area network, wireless personal area network, LAN or global network such as the Internet. In addition, network 140 may support the Internet, wireless communication network, cellular network, etc., or any combination thereof.Network 140 may also include a single network, or any number of exemplary types of networks described above, operating as independent networks or cooperating with each other. Network 140 may utilize one or more protocols of one or more network elements to which they are communicatively coupled. Network 140 may convert or adapt from other protocols to one or more protocols of network devices. Although network 140 is depicted as a single network, it should be understood that, according to one or more examples, network 140 may include multiple interconnected networks, such as the Internet, a service provider's network, a cable television network, a corporate network (such as a credit card association network), and a home network. Network 140 may also include or be configured to create one or more front channels that are publicly accessible and through which communications can be observed, and one or more secure back channels that are not publicly accessible and through which communications cannot be observed.

[0045] System 100 may include database 150. Database 150 may be one or more databases configured to store data, including but not limited to user privacy data, user financial accounts, user identity, user transactions, and authenticated and unauthenticated documents. Database 150 may include relational databases, non-relational databases, or other database implementations and any combination thereof, including multiple relational databases and non-relational databases. In some examples, database 150 may include a desktop database, a mobile database, or an in-memory database. Furthermore, database 150 may be hosted internally by server 160, or it may be hosted externally by server 160, such as by a server, a cloud-based platform, or any storage device communicating with server 160.

[0046] Server 160 may be a network-enabled computer device. Exemplary network-enabled computer devices may include, but are not limited to, servers, web applications, personal computers, workstations, telephones, handheld personal computers, personal digital assistants, thin clients, fat clients, internet browsers, mobile devices, kiosks, cards (e.g., contactless cards, contact-based cards), automatic teller machines (ATMs), or other computer or communication devices. For example, network-enabled computer devices may include Apple®'s iPhone, iPod, iPad, and / or any other mobile device running Apple's iOS® operating system, any device running Microsoft's Windows® mobile operating system, any device running Google's Android® operating system, and / or any other smartphone, tablet, or similar wearable mobile device.

[0047] Server 160 may include processor 161, memory 162, and application 163. Processor 161 may be a processor, microprocessor, or other processor, and server 160 may include one or more of these processors. Server 160 may be on-site, off-site, stand-alone, networked, online, or offline.

[0048] Processor 161 may include processing circuitry that may include additional components, including additional processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware, as required to perform the functions described herein.

[0049] Processor 161 may be coupled to memory 162. Memory 162 may be read-only memory, write-once-read-many memory, or read / write memory, such as RAM, ROM, and EEPROM, and server 160 may include one or more of these memories. Read-only memory may be programmable by the manufacturer to be read-only or programmable only once. One-time programmability provides the opportunity to write once and then read multiple times. Write-once-read-many memory can be programmed at some point after the memory chip has been manufactured. Once the memory is programmed, it cannot be rewritten but can be read multiple times. Read / write memory can be programmed and reprogrammed multiple times after it has been manufactured. It can also be read multiple times. Memory 162 may be configured to store one or more software applications, such as application 163, as well as other data, such as user privacy data and financial account information.

[0050] Application 163 may include one or more software applications that include instructions for execution on server 160. In some examples, server 160 may execute one or more applications (such as software applications) that are capable, for example, of communicating with one or more components of system 100 via a network, sending and / or receiving data, and performing the functions described herein. When executed by processor 161, application 163 may provide the functions described herein, specifically implementing and performing the steps and functions in the processing flow described below. These processes may be implemented in software (such as software modules) for execution by a computer or other machine. Application 163 may provide a GUI through which a user can view and interact with other components and devices within system 100. The GUI may be formatted as, for example, Hypertext Markup Language (HTML), Extensible Markup Language (XML), or any other suitable form of web page, depending on the application used by the user to interact with system 100 and its presentation on the display device.

[0051] Server 160 may also include a display 164 and / or an input device 165. The display 164 can be any type of device used to present visual information, such as a computer monitor, flat panel display, and mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays.Input device 165 may include any device available and supported by payment information processor 130 for inputting information into payment information processor 130, such as touchscreen, keyboard, mouse, cursor control device, microphone, digital camera, video recorder, or portable video camera. These devices may be used to input information and interact with the software and other devices described herein.

[0052] In some examples, exemplary processes according to this disclosure may be performed by processing means and / or computing means (e.g., computer hardware means). Such processing / computing means may be, for example, all or part of a computer / processor, or include, but are not limited to, a computer / processor that may include, for example, one or more microprocessors and uses instructions stored on a non-transitory computer-accessible medium (e.g., RAM, ROM, hard disk drive, or other storage device). For example, the computer-accessible medium may be part of the memory of user equipment 110, card 120, payment information processor 130, network 140, database 150, and server 160 or other computer hardware means.

[0053] In some examples, a computer-accessible medium (e.g., a storage device such as a hard disk, floppy disk, memory stick, CD-ROM, RAM, ROM, etc., or a collection thereof, as described herein) may be provided (e.g., for communication with a processing device). Executable instructions may be contained on the computer-accessible medium. Additionally or alternatively, a storage device may be provided separately from the computer-accessible medium, which may provide instructions to the processing device to configure the processing device to perform certain exemplary programs, processes, and methods, such as as described above.

[0054] FIG2 illustrates a card 200 according to an exemplary embodiment. Card 200 may include a payment card, such as a credit card, debit card, or gift card, issued by a service provider 205 displayed on the front or back of card 200. In some examples, the payment card may include a dual-interface contactless payment card. In some examples, card 200 is not related to a payment card and may include, but is not limited to, identity cards, membership cards, loyalty cards, transportation cards, and access point cards.

[0055] Card 200 may include a substrate 210, which may include a single layer or one or more laminates composed of plastics, metals, and other materials. Exemplary substrates include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium, palladium, gold, carbon, paper, and biodegradable materials. In some examples, card 200 may have physical properties conforming to the ID-1 format of ISO / IEC 7810, and the card may otherwise conform to the ISO / IEC 14443 standard. However, it should be understood that card 200 according to this disclosure may have different properties, and this disclosure does not require implementation of a card in a payment card.

[0056] Card 200 may also include identification information 215 displayed on the front and / or back of the card and contact pad 220. Contact pad 220 may be configured to establish contact with another communication device, such as a user equipment, smartphone, laptop, desktop, smartwatch, some other wearable device, or tablet. Card 200 may also include processing circuitry, an antenna, and other components not shown in FIG2. These components may be located behind contact pad 220 or elsewhere on substrate 210. Card 200 may also include a magnetic stripe or magnetic tape, which may be located on the back of the card (not shown in FIG2). Specification 7 / 22 pages 10 CN 121444115 A

[0057] FIG3 illustrates a contact pad of a card according to an exemplary embodiment.

[0058] As shown in FIG3, contact pad 305 may include processing circuitry 310 for storing and processing information, including microprocessor 320 and memory 325. It should be understood that the processing circuitry 310 may include additional components, including a processor, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware, as required to perform the functions described herein.

[0059] The memory 325 may be a read-only memory, a write-once-read-many memory, or a read / write memory, such as RAM, ROM, and EEPROM, and the card 200 may include one or more of these memories. Read-only memory may be programmable by the manufacturer to be read-only or read-once. Read-once programmability provides the opportunity to write once and then read multiple times. Write-once / read-many memory can be programmed at some point after the memory chip has been manufactured. Once the memory is programmed, it cannot be rewritten but can be read multiple times. Read / write memory can be programmed and reprogrammed multiple times after it has been manufactured. It can also be read multiple times.

[0060] The memory 325 may be configured to store one or more applets 330, one or more counters 335, and a customer identifier 340. One or more applets 330 may include one or more software applications, such as the Java Card applet, configured to run on one or more cards. However, it should be understood that applet 330 is not limited to the Java Card applet, but can be any software application operable on a card or other device with limited memory. One or more counters 335 may include numeric counters sufficient to store integers. Customer identifier 340 may include a unique alphanumeric identifier assigned to the user of card 200, and this identifier can distinguish the card user from other card users. In some examples, customer identifier 340 may identify the customer and the account assigned to that customer, and may also identify the card associated with the customer's account.

[0061] The processor and memory elements of the foregoing exemplary embodiments are described with reference to the contact pad, but this disclosure is not limited thereto. It should be understood that these elements may be implemented outside of or completely separated from the contact pad 305, or implemented as additional elements besides the processor 320 and memory 325 elements located within the contact pad 305.

[0062] In some examples, the card 200 may include one or more antennas 315. One or more antennas 315 may be placed within the card 200 and around the processing circuitry 310 of the contact pad 305. For example, one or more antennas 315 may be integrated with the processing circuitry 310, and one or more antennas 315 may be used in conjunction with an external boost coil. As another example, one or more antennas 315 may be external to the contact pad 305 and the processing circuitry 310.

[0063] In embodiments, the coil of the card 200 may act as the secondary coil of an air-core converter. The terminal may communicate with the card 200 by cutting off power or amplitude modulation. Card 200 can infer data transmitted from the terminal using gaps in the card's power connection, which can be functionally maintained by one or more capacitors. Card 200 can communicate in reverse by switching the load or load modulation on the card's coil. Load modulation can be detected in the terminal's coil by interference.

[0064] As explained above, card 200 can be built on a software platform operable on a smart card or other device with limited memory, such as a JavaCard, and one or more applications or applets can be securely executed. Applets can be added to the card to provide a one-time password (OTP) for multifactor authentication (MFA) in various mobile application-based use cases. Applets can be configured to respond to one or more requests (such as near-field data exchange requests) from a reader (such as a mobile NFC reader) and generate an NDEF message that includes a password-secure OTP encoded as an NDEF text tag.

[0065] Figure 4 illustrates a virtual payment card or virtual payment number. A virtual payment card is a unique payment card that allows a user to complete transactions on a primary payment card account associated with one or more of their financial accounts. In some examples, a virtual payment card may be limited to one-time use. In other examples, a virtual payment card may be limited to a predetermined number of uses and / or an unlimited number of uses within a predetermined time period. It should be understood that a virtual payment card may have other characteristics and features as described herein.

[0066] Figure 400 illustrates an example of a virtual payment card. The virtual payment card may be generated by a third-party mobile application or a banking application. The virtual payment card may be sent via wired or wireless network.The virtual card may contain information present on the physical card 415 discussed in Figures 2 and 3.

[0067] To protect user information, the virtual payment card may have some limitations. In element 420, the card may be time-limited. The virtual payment card may expire after a certain amount of time, such as fifteen minutes. It should be understood that the amount of time can be greatly extended or shortened. In element 425, the virtual payment card may be geographically limited. If the user device leaves the predetermined geographical area, the virtual payment card may expire. This predetermined area may be determined by an administrator processing system, an account processing system, or the user himself. Geographical areas may vary greatly. For example, the virtual card may be limited to a small area around a particular storefront.

[0068] In element 430, the virtual payment card may be limited by the vendor to only one or more vendors. For example, the card may be limited to a single vendor in a single location. Alternatively, the virtual card may be limited to vendors in a designated area (such as a shopping mall, market, or flea market). In another example, the virtual card may be limited to the entire franchise—that is, the card can be used in any store associated with a particular franchise. In element 435, the virtual payment card may be subject to a limit on the amount available on the card. The card may have a certain upper limit, such as $100. This amount may vary considerably. This amount may be determined by a user, administrator processing system, or account processing system. It should be understood that the virtual payment card may combine one or more of these limits. The limits and security features listed above may be added, reduced, or otherwise changed. These changes may be implemented by the user or bank processor.

[0069] Figure 5 is a sequence diagram illustrating a method according to an exemplary embodiment. The sequence may include, but is not limited to, a server and / or a banking application, wherein the banking application may be associated with the server, or in some embodiments, independent of the server. The server itself may be associated with one or more banks and one or more banking applications. The sequence may also include, further referring at least to the user device and merchant processor discussed in Figure 1.

[0070] In action 505, the banking application may receive one or more user identification data from the user device. This data may be received via a wired or wireless network or via a communication field. User identification data may include, but is not limited to, name, telephone number, email address, card information, unique user identifier, or biometrics. In some embodiments, more than one user identification data may be received by the banking application via one or more networks or communication fields. Upon receiving user identification data, in Action 510, the banking application can match that data against a user profile. A user profile can be a profile associated with a user or owner of one or more transaction accounts. Transaction accounts can include, but are not limited to, checking accounts, savings accounts, growth accounts, or hybrid accounts. Transaction accounts can also include any account associated with a debit or credit card.Each user profile can be associated with one or more transaction accounts.

[0071] In action 515, the banking application can send an authentication request to the user device. In response, in action 520, the banking application can receive authentication credentials from the user device. These credentials can be received via a network or communication field. The authentication credentials can include, but are not limited to, a Short Message Service (SMS) One-Time Password (OTP), a password, a biometric, or a unique customer identifier. In some embodiments, the banking application may require multiple authentication credentials sent via one or more networks and communication fields. After receiving the authentication credentials, the banking application can retrieve one or more PANs associated with the user profile. For example, the banking application can retrieve two credit card PANs and one debit card PAN. If the banking application retrieves only one PAN—for example, if the user only has one debit card—then the banking application will generate a VCN based on only a single PAN. In most cases where the user profile is associated with multiple PANs, in action 530, the banking application will send a prompt to the user device allowing the user to select a PAN they prefer. The prompt can be generated by the banking application and include the PAN in the selectable list on page 9 / 22 of the specification, CN 121444115 A. The prompt may appear on the user device's display, and the user can click or tap the PAN they wish to use.

[0072] In action 535, the banking application receives the selection of the PAN from the user device via the network. After receiving the PAN selection, in action 540, the banking application generates a VCN associated with the selected PAN. The VCN and its constraints will be further discussed with reference to Figures 4 and 6-10. After generating the VCN, the banking application can send the VCN directly to the merchant processor associated with the transaction involving the user device. The banking application does not send the VCN to the user device itself to protect the user's security and privacy. The VCN can be sent via a wireless network.

[0073] Figure 6 illustrates a method in which the banking application can dynamically create merchant categories and generate VCNs based on the dynamically created categories. The banking application can also store the VCNs in a data storage unit.

[0074] In action 605, the banking application can receive one or more user identification data from the user device. This data can be received via a wired or wireless network or via a communication field. The user identification data may include, but is not limited to, name, telephone number, email address, card information, unique user identifier, or biometrics. In some embodiments, more than one set of user identification data may be received by the banking application through one or more networks or communication fields. Upon receiving the user identification data, in action 610, the banking application may match the data with a user profile.A user profile can be a profile associated with a user or owner of one or more transaction accounts. Transaction accounts can include, but are not limited to, checking accounts, savings accounts, growth accounts, or hybrid accounts. Transaction accounts can also include any account associated with a debit card or credit card. Each user profile can be associated with one or more transaction accounts.

[0075] In action 625, the banking application can send an authentication request to the user device. In response, in action 630, the banking application can receive authentication credentials from the user device. These credentials can be received via a network or communication field. These authentication credentials can include, but are not limited to, SMS OTP, password, biometrics, or a unique customer identifier. In some embodiments, the banking application may require multiple authentication credentials sent via one or more networks and communication fields. After receiving the authentication credentials, the banking application can retrieve one or more PANs associated with the user profile. For example, the banking application can retrieve two credit card PANs and one debit card PAN. In the case where the banking application retrieves only one PAN—for example, the user only has one debit card—then the banking application will generate a VCN based only on the single PAN. In most cases where the user profile is associated with multiple PANs, in action 640, the banking application will send a prompt to the user device allowing the user to select using their preferred PAN. The prompt can be generated by the banking application and include the PAN in a selectable list. The prompt can appear on the user's device display, and the user can click or tap the PAN they want to use.

[0076] In action 645, the banking application receives the selection of the PAN from the user's device via the network. After receiving the selection of the PAN, in action 650, the banking application generates a VCN associated with the selected PAN. The VCN and its constraints will be further discussed with reference to Figures 4 and 6-10. Constraints on the VCN can include one or more constraints based on one or more merchant categories. Merchant categories include various types of merchants, including but not limited to grocery stores, banks, restaurants, online merchants, and clothing stores. Constraining the VCN to one or more of these categories can ensure that the VCN is unlikely to be used for malicious or fraudulent purposes. For example, a VCN constrained only to grocery store payments would not be usable in a clothing store. After matching the user identifier with the user profile, in action 615, the banking application can retrieve the spending history associated with the user profile.The consumption history can span any time period and may include, but is not limited to, transaction details, including the date and time of the transaction, merchant name and location, payment method used (credit card and / or debit card, cash, etc.), and the amount spent in the transaction; consumption categories, including food, entertainment, transportation, clothing, and other categories commonly used in customer consumption; monthly summaries, including an overview of the total amount spent by the user in a specific month or other predetermined time period; location data, including physical location information of each transaction; and payment history, including payment due dates, payment amounts, and information such as bills for rentals, utilities, and credit card payments.

[0077] Based on this information, in action 620, the banking application can dynamically create merchant categories based on the retrieved consumption history. This merchant category will restrict the VCN to use only at merchants within that category. When the user requests more VCNs, the banking application can dynamically generate VCNs based on one or more updated user data associated with the user profile. The dynamic nature of this action ensures that the VCN is always constrained based on the most relevant and up-to-date elements of the user data. The size of the merchant category may vary. As a non-limiting example, the merchant category may include grocery stores, entertainment, travel, leisure, pharmacies, furniture and appliances, rentals, utilities, Wi-Fi, and other merchant categories.

[0078] After generation, in action 655, the VCN may be stored in a database or data storage unit for long-term storage and / or later use. This action may be performed by the banking application. After the VCN is generated, in action 660, the banking application may send the VCN directly to the merchant processor associated with the transaction involving the user device. The banking application does not send the VCN to the user device itself to protect the user's security and privacy. The VCN may be sent via a wireless network.

[0079] Figure 7 is a diagram of a method for a banking application to generate a predictive model and determine appropriate VCN constraints based on the model. This sequence may include, but is not limited to, a server and / or a banking application, wherein the banking application may be associated with a server, or in some embodiments, independent of a server. The server itself may be associated with one or more banks and one or more banking applications. This sequence may also include, further at least with reference to the user device and merchant processor discussed in Figure 1.

[0080] In action 705, the banking application may receive one or more user identification data from the user device. This data may be received via a wired or wireless network or via a communication field. User identification data may include, but is not limited to, name, telephone number, email address, card information, unique user identifier, or biometrics. In some embodiments, more than one set of user identification data may be received by the banking application via one or more networks or communication fields.Upon receiving user identification data, in action 710, the banking application can match the data with a user profile. A user profile can be a profile associated with a user or owner of one or more transaction accounts. Transaction accounts can include, but are not limited to, checking accounts, savings accounts, growth accounts, or hybrid accounts. Transaction accounts can also include any account associated with a debit card or credit card. Each user profile can be associated with one or more transaction accounts.

[0081] In action 735, the banking application can send an authentication request to the user device. In response, in action 740, the banking application can receive authentication credentials from the user device. These credentials can be received via a network or communication field. These authentication credentials can include, but are not limited to, SMS OTP, password, biometrics, or a unique customer identifier. In some embodiments, the banking application may require multiple authentication credentials sent via one or more networks and communication fields. Upon receiving the authentication credentials, in action 745, the banking application can retrieve one or more PANs associated with the user profile. For example, the banking application can retrieve two credit card PANs and one debit card PAN. If the banking application retrieves only one PAN—for example, if the user only has one debit card—then the banking application will generate a VCN based solely on the single PAN. In most cases where a user profile is associated with multiple PANs, in action 750, the banking application sends a prompt to the user device allowing the user to select a PAN they prefer. The prompt may be generated by the banking application and include the PAN in a list of selectable PANs. The prompt may appear on the user device's display, and the user can click or tap the PAN they wish to use. In action 755, the banking application receives the PAN selection from the user device via the network.

[0082] Upon receiving the PAN selection, in action 760, the banking application generates a VCN associated with the selected PAN. The VCN and its constraints will be further discussed with reference to Figures 4 and 6-10. Constraints on the VCN may include one or more constraints based on one or more merchant categories. Merchant categories include various types of merchants, including but not limited to grocery stores, banks, restaurants, online merchants, and clothing stores. Constraining the VCN on one or more of these categories ensures that the VCN is unlikely to be used for malicious or fraudulent purposes. For example, a VCN constrained only to grocery store payments would not be usable in a clothing store. Instruction manual 11 / 22 pages 14 CN 121444115 A

[0083] After matching the user identifier with the user profile, in action 715, the banking application can retrieve the consumption history associated with the user profile.The consumption history can span any time period and may include, but is not limited to, transaction details, including the date and time of the transaction, merchant name and location, payment method used (credit and / or debit card, cash, etc.), and the amount spent in the transaction; consumption categories, including food, entertainment, transportation, clothing, and other categories commonly used in customer consumption; monthly summaries, including an overview of the total amount spent by the user in a specific month or other predetermined time period; location data, including physical location information of each transaction; and payment history, including payment due dates, payment amounts, and information on bills such as rentals, utilities, and credit card payments.

[0084] Based on this information, in action 720, the banking application can analyze trends in the user data. This action may include identifying one or more patterns in the user data that change over time. In the context of a user's consumption history, trend analysis involves examining the consumption behavior of a specific user or user group over time to identify recurring patterns, changes in consumption habits, and potential insights. The analysis may include identifying seasonal trends, cyclical trends, trend lines, and outliers. For example, the banking application may notice that consumption patterns repeat periodically, such as increased spending during holidays or specific months of the year. As another non-limiting example, the banking application may notice fluctuations occurring over a period of time, such as alternating periods of high and low spending. As another non-limiting example, the banking application may notice overall trends in the data that may indicate a general increase or decrease in spending over time. As another non-limiting example, the banking application may notice data points that exceed expected ranges and may indicate unusual spending behavior.

[0085] After analyzing one or more of these trends, in action 725, the banking application may generate a predictive model configured to determine constraints on the VCN that are best suited for the purpose of curbing fraud while maintaining the usefulness of the VCN. The predictive model may include a model of one or more future spending habits predicted by a predetermined algorithm and associated with a user profile. The predictive model may be a machine learning model, a neural network, or some combination thereof. The predictive model will be further discussed with reference to Figures 9 and 10. After generating the predictive model, in action 730, the banking application may determine appropriate VCN constraints, which may include any constraints discussed herein and with reference to Figure 4. When a user requests more VCNs, the banking application can dynamically generate VCNs based on one or more updated user data associated with the user profile. This dynamic nature ensures that the VCN is always constrained by the most relevant and up-to-date elements of the user data.

[0086] After generating the VCN, in action 765, the banking application can send the VCN directly to the merchant processor associated with the transaction involving the user's device. The banking application does not send the VCN to the user's device itself to protect the user's security and privacy.VCNs can be transmitted via a wireless network. VCNs can be stored in a database or data storage unit for later use or long-term storage.

[0087] FIG8 is a method diagram illustrating a method according to an exemplary embodiment. The sequence may include, but is not limited to, a server and / or a banking application, wherein the banking application may be associated with the server, or in some embodiments, independent of the server. The server itself may be associated with one or more banks and one or more banking applications. The sequence may also include a user device and a merchant processor further discussed with reference to FIG1. ​​

[0088] In action 805, the banking application may receive one or more user identification data from the user device. The data may be received via a wired or wireless network or via a communication field. User identification data may include, but is not limited to, name, telephone number, email address, card information, unique user identifier, or biometrics. In some embodiments, more than one user identification data may be received by the banking application via one or more networks or communication fields. Upon receiving the user identification data, in action 810, the banking application may match the data with a user profile. The user profile may be a profile associated with a user or owner of one or more transaction accounts. Transaction accounts may include, but are not limited to, checking accounts, savings accounts, growth accounts, or hybrid accounts. Transaction accounts may also include any account associated with a debit or credit card (see page 12 / 22, CN 121444115 A). Each user profile may be associated with one or more transaction accounts.

[0089] In action 845, the banking application may send an authentication request to the user device. In response, in action 850, the banking application may receive authentication credentials from the user device. These credentials may be received via a network or communication field. The authentication credentials may include, but are not limited to, SMS OTP, password, biometrics, or a unique customer identifier. In some embodiments, the banking application may require multiple authentication credentials sent via one or more networks and communication fields. Upon receiving the authentication credentials, in action 855, the banking application may retrieve one or more PANs associated with the user profile. For example, the banking application may retrieve two credit card PANs and one debit card PAN. In the case where the banking application retrieves only one PAN—for example, the user has only one debit card—then the banking application will generate a VCN based only on the single PAN. In most cases where the user profile is associated with multiple PANs, in action 860, the banking application will send a prompt to the user device allowing the user to select using their preferred PAN. The prompt can be generated by the banking app and include the PAN in a selectable list. The prompt can appear on the user's device display, and the user can click or tap the PAN they want to use.In action 865, the banking application receives a PAN selection from the user device via the network. Upon receiving the PAN selection, in action 870, the banking application generates a VCN associated with the selected PAN. The VCN and its constraints will be further discussed with reference to Figures 4 and 6-10.

[0090] Constraints on the VCN may include one or more constraints based on one or more merchant categories. Merchant categories include various types of merchants, including but not limited to grocery stores, banks, restaurants, online merchants, and clothing stores. Constraining the VCN to one or more of these categories ensures that the VCN is unlikely to be used for malicious or fraudulent purposes. For example, a VCN constrained only to grocery store payments would not be usable in a clothing store. After matching the user identifier with the user profile, in action 815, the banking application can retrieve the spending history associated with the user profile. The consumption history can span any time period and may include, but is not limited to, transaction details, including the date and time of the transaction, merchant name and location, payment method used (credit and / or debit card, cash, etc.), and the amount spent in the transaction; consumption categories, including food, entertainment, transportation, clothing, and other categories commonly used in customer consumption; monthly summaries, including an overview of the total amount spent by the user in a specific month or other predetermined time period; location data, including physical location information of each transaction; and payment history, including payment due dates, payment amounts, and information on bills such as rentals, utilities, and credit card payments.

[0091] Based on this information, in action 820, the banking application can analyze trends in the user data. This action may include identifying one or more patterns of change in the user data over time. In the context of a user's consumption history, trend analysis involves examining the consumption behavior of a specific user or user group over time to identify recurring patterns, changes in consumption habits, and potential insights. The analysis may include identifying seasonal trends, cyclical trends, trend lines, and outliers. For example, the banking application may notice that consumption patterns repeat periodically, such as increased spending during holidays or specific months of the year. As another non-restrictive example, a banking application may notice fluctuations occurring over a period of time, such as alternating periods of high and low spending. As another non-restrictive example, a banking application may notice overall trends in the data that indicate a general increase or decrease in spending over time. As another non-restrictive example, a banking application may notice data points that exceed expected ranges and may indicate unusual spending behavior. After analyzing one or more of these trends, in Action 825, the banking application may generate a predictive model configured to determine constraints on the VCN that are best suited for the purpose of curbing fraud while maintaining the usefulness of the VCN. The predictive model may include models of one or more future spending habits predicted by a predetermined algorithm and associated with user profiles.The prediction model can be a machine learning model, a neural network, or some combination thereof. The prediction model will be further discussed with reference to Figures 9 and 10. After generating the prediction model, in action 830, the banking application can determine appropriate VCN constraints, which can include any constraints discussed herein and with reference to Figure 4. When a user requests more VCNs, the banking application can dynamically generate VCNs based on one or more updated user data associated with the user profile (page 13 / 22, CN 121444115 A). The dynamic nature of this action ensures that the VCN is always constrained based on the most relevant and up-to-date elements of the user data.

[0092] In some cases, the banking application can detect fraud associated with the user profile. For example, in action 835, the banking application can receive a notification that a PAN associated with a user account has just been flagged as fraudulent. The banking application can receive one or more notifications. In response to this notification, in action 840, the banking application can change or adjust the VCN constraints. As a non-limiting example, the banking application can restrict the VCN to fewer merchant categories or spending limits. Alternatively, the VCN may be constrained to a certain location radius. Any constraints mentioned here and in Figure 4 can be changed or adjusted in response to fraud detection. Similarly, the dynamic nature of this action ensures that the VCN is always constrained based on the most relevant and up-to-date elements of the user data.

[0093] After the VCN is generated, in action 875, the banking application can send the VCN directly to the merchant processor associated with the transaction involving the user's device. The banking application does not send the VCN to the user's device itself to protect the user's security and privacy. The VCN can be sent via a wireless network.

[0094] Figure 9 is a flowchart illustrating the generation of the predictive model and the calculation of the coverage amount.

[0095] Process 900 describes the training process for an exemplary predictive model or neural network suitable for predicting and calculating the coverage amount associated with a lease-applicant. This process can begin with action 905 when raw data is collected. Raw data may include, but is not limited to, the user's spending history. Spending history can span any time period and may include, but is not limited to, transaction details, including the date and time of the transaction, merchant name and location, payment method used (credit and / or debit card, cash, etc.), and the amount spent in the transaction; spending categories, including food, entertainment, transportation, clothing, and other categories commonly used by customers; monthly summaries, including an overview of the total amount spent by the user in a specific month or other predetermined time period; location data, including the physical location information of each transaction; and payment history, including payment due dates, payment amounts, and information on bills such as rentals, utilities, and credit card payments.The collection of raw data can be performed by a processor or application associated with a user device or server. The raw data can be transmitted via a wired or wireless network. The data may have been pre-collected and stored in a database or data storage unit, in which case the processor or application can retrieve the data from the data storage unit.

[0096] At action 910, the processor or application can organize the raw data into identifiable categories. The size of the business categories may vary. As a non-limiting example, business categories may include grocery stores, entertainment, travel, leisure, pharmacies, furniture and appliances, rentals, utilities, Wi-Fi, and other business categories. Categories may be pre-determined by the user or created by a predictive model. At action 915, the organized or raw data can be transmitted to a data storage unit. The data storage unit may be associated with a user device or server. The raw or organized data can be transmitted via a wired network, a wireless network, or one or more high-speed buses. The database may include a relational database, a non-relational database, or other database implementations and any combination thereof, including multiple relational and non-relational databases. In some examples, the database may include a desktop database, a mobile database, or an in-memory database. Furthermore, the database can be hosted internally by the server, or it can be hosted externally by the server, a cloud-based platform, or any storage device that communicates with the server.

[0097] After the data is organized into one or more categories, in actions 920 to 940, the processor or application can continue training the predictive model. The training portion can have any number of iterations. The predictive model can include one or more neural networks, further referred to FIG. 10.

[0098] The training portion can begin with action 920 when the weights and input values ​​are set by the user or by the model itself. Furthermore, the weights can be predetermined connections between the input and the hidden layer, further referred to FIG. 10. The input values ​​are the values ​​fed into the neural network. The input values ​​can be identified by the different categories created in action 910, but other different input values ​​can also be identified. Inputs can include, but are not limited to, historical information related to consumption and fraud, as well as other user data discussed herein. In action 925, the data is input into the neural network, and in action 930, the neural network analyzes the data according to the weights and other parameters set by the user. As a non-restrictive example, a user or banking application could create a rule that spending limits for any VCN will not exceed $500. In Action 935, review the output. The output may include one or more VCN constraints, further referenced in Figure 4 and elsewhere. In Action 940, the predictive model can be updated with new data and parameters. The processor can collect new data in a manner similar to Actions 905 and 910.Although retraining the prediction model is not required in this exemplary embodiment, the prediction model can be retrained any number of times, repeating actions 925 to 940 until a satisfactory output is achieved or certain other parameters are satisfied. As a non-limiting example, the user can update the input with new consumption and fraud data. As another non-limiting example, the user can adjust the weighting relationship between the input layer and one or more hidden layers of the neural network discussed further with reference to FIG10. If a satisfactory output has been recorded, one or more prediction models can be generated in action 945. It should be understood that once the prediction model is generated, it can be further trained as in actions 920 to 945. After generating the prediction model, in action 950, given a unique input value collected from the user, the model can generate one or more VCN constraints.

[0099] FIG10 is a diagram illustrating a neural network as an exemplary embodiment of a prediction model.

[0100] A neural network is a series of algorithms that can identify relationships between one or more variables under predetermined training constraints. A neuron in a neural network is a mathematical function that collects and classifies information according to a specific form set by the user. A neural network can be divided into three main components: an input layer, a processing layer or hidden layer, and an output layer. The input layer includes a dataset selected to be inserted into the neural network for analysis. The hidden layer includes one or more neurons that can classify the input according to parameters set by the user. The hidden layer can include multiple consecutive layers, with a first layer immediately following the input layer and a last layer immediately preceding the output layer. The hidden layer immediately following the input layer can be connected to the input layer via predetermined weights or emphasis. These weights can be assigned according to the modeler's agenda. Alternatively, the model itself can determine the optimal weights between layers such that a predetermined result, error range, or minimum data point is achieved.

[0101] The predictive model can include a neural network 1000. The neural network can be integrated into a server, user device, or some other computer device suitable for neural network analysis. The server can be associated with a software application such as a banking application. The neural network can include an input layer 1005, one or more hidden layers 1025, and an output layer 1035. Although only a certain number of nodes are depicted in Figure 10, it should be understood that the neural network according to the disclosed embodiments can include fewer or more nodes in each layer. Furthermore, the hidden layers may include more or fewer layers than depicted in Figure 10. It is also understood that predetermined weights can be assigned to the connections between each layer based on manual changes by the user or based on some weight values ​​generated by the neural network itself. The input layer may include a dataset collected from an external source. The neural network may include, but is not limited to, consumption history 1010, fraud history 1015, and information about the current transaction 1020.Other inputs not depicted in Figure 10 may include merchant categories, such as grocery stores, entertainment, travel, leisure, pharmacies, furniture and appliances, rentals, utilities, Wi-Fi, and other merchant categories. After analyzing the input via one or more hidden layers, the neural network may create one or more file variables 1040. It should be understood that one or more neural networks or some combination of neural networks can be trained according to an individual user. It should be understood that any neural network described herein can be trained or iterated any number of times. In some embodiments, the neural network may be retrained and / or updated after each new transaction or fraud notification is recorded. In other embodiments, the neural network may be trained until a sufficient level of accuracy is reached. The neural network can be trained to draw any number of conclusions, including whether VCN constraints are compatible with the current transaction and which VCN constraints should be applied.

[0102] In some embodiments, the application may use a predictive model to analyze biometrics, including but not limited to recursive neural networks (RNNs), convolutional neural networks (CNNs), artificial neural networks (ANNs), or some other neural networks. The predictive models described herein may utilize Bidirectional Encoder Representations from Transformer (BERT) models. BERT models utilize multiple layers of so-called “attention mechanisms” to process text data and make predictions. These attention mechanisms effectively allow the BERT model to learn and assign greater importance to words in the text input that are more important when attempting to make any inferences.

[0103] Exemplary systems, methods, and computer-readable media may utilize various neural networks, such as CNNs or RNNs, to generate exemplary models. A CNN may include one or more convolutional layers (e.g., typically with subsampling steps), followed by one or more fully connected layers, just like a standard multilayer neural network. CNNs can utilize local connections and can have bound weights, followed by some form of pooling, which can produce translation-invariant features.

[0104] RNNs are a class of artificial neural networks in which connections between nodes form a directed graph along a sequence. This helps to determine the temporal dynamics of a time series. Unlike feedforward neural networks, RNNs can use their internal states (e.g., memories) to process the input sequence. RNNs can generally refer to two main classes of networks with similar general structures: finite impulse and infinite impulse.Both types of networks exhibit time-dynamic behavior. Finite-impulse recurrent networks can be or may include directed aperiodic graphs that can be unfolded and replaced with strictly feedforward neural networks, while infinite-impulse recurrent networks can be or may include directed periodic graphs that may not be unfolded. Both finite-impulse and infinite-impulse recurrent networks can have additional storage states, and the storage can be under the direct control of the neural network. The storage can also be replaced by another network or graph that may contain time delays or may have feedback loops. Such controlled states can be referred to as gated states or gated memories, and can be part of long short-term memory networks (LSTM) and gated recurrent units.

[0105] RNNs can be analogous to networks of neuron-like nodes organized into successive "layers," where each node in a given layer is directed connected to every other node in the next successive layer, for example, a (unidirectional) connection. Each node (e.g., a neuron) can have time-varying real-valued activations. Each connection (e.g., a synapse) can have modifiable real-valued weights. Nodes can be (i) input nodes (e.g., receiving data from outside the network), (ii) output nodes (e.g., producing results), or (iii) hidden nodes (e.g., modifying data during the process from input to output). An RNN can accept an input vector x and output a vector y. However, the output vector is based not only on the input just provided but also on the entire history of inputs that have been provided in the past.

[0106] For supervised learning in a discrete-time setting, a sequence of real-valued input vectors can arrive at the input node one vector at a time. At any given time step, each non-input unit can compute its current activation (e.g., the result) as a nonlinear function of the weighted sum of the activations of all units connected to it. At some time steps, a target activation given by the supervisor can be provided to some output units. For example, if the input sequence is a speech signal corresponding to a spoken digit, the final target output at the end of the sequence could be a label classifying that digit. In a reinforcement learning environment, no teacher provides the target signal. Instead, a fitness function or reward function can be used to evaluate the performance of the RNN, which can be influenced by the input stream of the output units connected to actuators that may influence the environment. Each sequence may produce an error, which is the sum of the deviations of all target signals from the corresponding activations computed by the network. For a training set of multiple sequences, the total error may be the sum of the errors of all individual sequences.

[0107] The model described herein can be trained on one or more training datasets, each of which may include one or more types of data. In some examples, the training dataset may include previously collected data, such as data collected from previous use of the same type of system described herein and data collected from different types of systems.In other examples, the training dataset may include continuously collected data based on the current operation of the instantaneous system and continuously collected data from the operation of other systems (see page 16 / 22 of CN 121444115 A). In some examples, the training dataset may include anticipated data for the instantaneous system and / or other systems, such as anticipated future workloads, currently planned workloads, and planned future workloads. In other examples, the training dataset may include previous predictions for the instantaneous system and other types of systems, and may also include outcome data indicating the accuracy of previous predictions. Based on these examples, the predictive model described herein can be trained before use, and training can continue using an updated dataset reflecting additional information.

[0108] In some aspects, the technology described herein relates to a system for generating a VCN, the system comprising: a server including a banking application, wherein the banking application is configured to: receive one or more user identification data from a user device application; match the one or more user identification data with a user profile; send an authentication request to the user device application; receive authentication credentials from the user device application; retrieve one or more master accounts (PANs) associated with the user profile; send a prompt to the user device application to select one or more PANs to use for completing a transaction; receive a selection of one or more PANs from the user device application; generate a VCN associated with the selected one or more PANs; and send the VCN to a merchant processor.

[0109] In some aspects, the technology described herein relates to a system wherein the VCN is bound to one or more merchants.

[0110] In some aspects, the technology described herein relates to a system wherein the VCN is configured to expire after a predetermined period of time.

[0111] In some aspects, the technology described herein relates to a system wherein the VCN is restricted to a predetermined spending limit.

[0112] In some aspects, the technology described herein relates to a system in which the banking application is further configured to store the VCN in a data storage unit for later use when the VCN is generated.

[0113] In some aspects, the technology described herein relates to a system in which the VCN is constrained to one or more merchants and one or more merchant categories.

[0114] In some aspects, the technology described herein relates to a system in which the banking application is further configured to dynamically create merchant categories based on spending history associated with the user profile.

[0115] In some aspects, the technology described herein relates to a system in which the banking application is further configured to: retrieve user location data associated with the user profile from a database; analyze trends in the user location data; and generate a predictive model configured to determine constraints on the VCN, wherein the predictive model includes a model of one or more future consumption habits predicted by a predetermined algorithm associated with the user profile.

[0116] In some aspects, the technology described herein relates to a system in which the banking application is further configured to: retrieve historical consumption data associated with the user profile from a database; analyze trends in the historical consumption data; and generate a predictive model configured to determine constraints on the VCN, wherein the predictive model includes a model of one or more future consumption habits predicted by a predetermined algorithm associated with the user profile.

[0117] In some aspects, the technology described herein relates to a system in which the banking application is further configured to: retrieve user fraud history data associated with the user profile; analyze trends in the user fraud history data; and generate a predictive model configured to determine constraints on the VCN, wherein the predictive model includes a model of one or more future spending habits predicted by a predetermined algorithm and associated with the user profile.

[0118] In some aspects, the technology described herein relates to a method for generating a VCN, the method comprising the steps of: receiving one or more user identification data by a banking application associated with a server; matching the one or more user identification data with a user profile by the banking application; sending an authentication request by the banking application to a user device application specification page 17 / 22 20 CN 121444115 A; receiving authentication credentials by the banking application from the user device application; retrieving one or more master accounts (PANs) associated with the user profile; sending a prompt to the user device application to select one or more PANs to use for completing a transaction; receiving a selection of one or more PANs from the user device application; generating a VCN associated with the selected one or more PANs by the banking application; and sending the VCN to a merchant processor by the banking application.

[0119] In some aspects, the technology described herein relates to a method wherein the VCN is constrained to at least one of a predetermined time period, merchant, geographic location, or price.

[0120] In some aspects, the technology described herein relates to a method in which the predetermined constraints are dynamically changed by the banking application in response to one or more spending habits associated with the user profile.

[0121] In some aspects, the technology described herein relates to a method, wherein the method further includes the steps of: retrieving consumption history data associated with the user profile from a database; analyzing trends in the consumption history data; and generating a predictive model configured to determine constraints on the VCN, wherein the constraints are based on a predetermined set of merchant categories.

[0122] In some aspects, the technology described herein relates to a method, wherein the method further includes the steps of: generating the VCN upon receiving a selection of one or more PANs, wherein the VCN is bound to one or more selected PANs.

[0123] In some aspects, the technology described herein relates to a method in which the VCN is sent from the processor to a merchant processor without notifying the user of the existence of the VCN.

[0124] In some aspects, the technology described herein relates to a method, wherein the method further includes the steps of: receiving fraud detection associated with the VCN by the processor; and changing the constraints associated with the VCN by the processor in response to the fraud detection.

[0125] In some aspects, the techniques described herein relate to a method in which the authentication credentials include a Short Message Service (SMS) One-Time Password (OTP), a password, a biometric feature, or a unique customer identifier.

[0126] In some aspects, the techniques described herein relate to a method in which the authentication credentials are transmitted via a communication field including Near Field Communication (NFC), Radio Frequency Identification (RFID), or Bluetooth.

[0127] In some aspects, the techniques described herein relate to a computer-readable non-transitory medium comprising computer-executable instructions that, when executed by a computer hardware device including a processor, cause the computer hardware device to perform a process including: receiving one or more user identification data; matching the one or more user identification data with a user profile; sending an authentication request to a user device application; receiving authentication credentials from the user device application; retrieving one or more main accounts (PANs) associated with the user profile; sending a prompt to the user device application to select one or more of the PANs to complete a transaction; receiving a selection of one or more PANs from the user device application; generating a VCN associated with the selected one or more PANs; and sending the VCN to a merchant processor.

[0128] Although embodiments of the invention have been described herein in the context of specific implementations for specific purposes in specific settings, those skilled in the art will recognize that their usefulness is not limited thereto, and that embodiments of the invention may be advantageously implemented in other relevant settings for similar purposes.Therefore, the present invention should not be limited to the embodiments, methods, and examples described above, but rather to all embodiments within the claimed scope and spirit of the invention.

[0129] As used herein, user information, personal information, and sensitive information may include any information relating to a user, such as privacy information and non-privacy information. Privacy information may include any sensitive data, including financial data (e.g., account information, account balance, account activity), personal information / personally identifiable information (e.g., social security number, home or work address, date of birth, telephone number, email address, passport number, driver's license number), access information (e.g., password, security code, authorization code, biometric data), and any other information that the user may wish to avoid disclosing to unauthorized persons. Non-privacy information may include any data that is well-known or otherwise not intended to be kept confidential.

[0130] The predictive model described herein may utilize a transformer-based bidirectional encoder representation (BERT) model. The BERT model utilizes multiple layers of so-called “attention mechanisms” to process textual data and make predictions. These attention mechanisms effectively allow the BERT model to learn and assign greater importance to words in the text input that are more important when attempting to make any inferences.

[0131] Exemplary systems, methods, and computer-readable media can utilize various neural networks, such as convolutional neural networks (CNNs) or recurrent neural networks (RNNs), to generate exemplary models. A CNN may include one or more convolutional layers (e.g., typically with subsampling steps), followed by one or more fully connected layers, much like a standard multilayer neural network. CNNs may utilize local connections and may have bound weights, followed by some form of pooling, which can produce translation-invariant features.

[0132] An RNN is a class of artificial neural networks in which connections between nodes form a directed graph along a sequence. This helps to determine the temporal dynamics of a time series. Unlike feedforward neural networks, RNNs can use their internal states (e.g., memories) to process the input sequence. RNNs can generally refer to two main classes of networks with similar general structures, one being finite impulse and the other infinite impulse. Both classes of networks exhibit temporal dynamics. Finite impulse recurrent networks (FCRs) can be or may include directed aperiodic graphs, which can be unfolded and replaced with strictly feedforward neural networks, while infinite impulse recurrent networks (IRRCs) can be or may include directed periodic graphs that may not be unfolded. Both FCRs and IIRs can have additional stored states, and the storage can be under the direct control of the neural network. The storage can also be replaced by another network or graph, which may include time delays or have feedback loops.This controlled state can be referred to as a gated state or a gated memory, and can be part of a Long Short-Term Memory (LSTM) network and a gated recurrent unit.

[0133] An RNN can be analogous to a network of neuron-like nodes organized into successive "layers," where each node in a given layer is directed to every other node in the next successive layer, for example, a (unidirectional) connection. Each node (e.g., a neuron) can have time-varying real-valued activations. Each connection (e.g., a synapse) can have modifiable real-valued weights. A node can be (i) an input node (e.g., receiving data from outside the network), (ii) an output node (e.g., producing a result), or (iii) a hidden node (e.g., capable of modifying data from input to output). An RNN can accept an input vector x and output an output vector y. However, the output vector is based not only on the input just provided but also on the entire history of inputs that have been provided in the past.

[0134] For supervised learning in a discrete-time setting, a sequence of real-valued input vectors can arrive at the input node one vector at a time. At any given time step, each non-input unit can compute its current activation (e.g., the result) as a nonlinear function of the weighted sum of the activations of all units connected to it. At some time steps, a target activation given by a supervisor can be provided to some output units. For example, if the input sequence is a speech signal corresponding to a spoken digit, the final target output at the end of the sequence could be a label for classifying that digit. In a reinforcement learning environment, no teacher provides the target signal. Instead, a fitness function or reward function can be used to evaluate the performance of the RNN, which can be influenced by the output units connected to the actuators that may influence the environment, affecting their input stream. Each sequence may produce an error, which is the sum of the deviations of all target signals from the corresponding activations computed by the network. For a training set consisting of multiple sequences, the total error can be the sum of the errors of all individual sequences.

[0135] The model described herein can be trained on one or more training datasets, each of which may include one or more types of data. In some examples, the training dataset may include previously collected data, such as data collected from previous use of the same type of system described herein and data collected from different types of systems. In other examples, the training dataset may include continuously collected data based on the current operation of the instantaneous system and continuously collected data from the operation of other systems. In some examples, the training dataset may include anticipated data for the instantaneous system and / or other systems, such as anticipated future workloads, currently planned workloads, and planned future workloads. In other examples, the training dataset may include previous predictions for the instantaneous system and other types of systems, and may also include outcome data indicating the accuracy of previous predictions.Based on these examples, the predictive models described herein can be trained before use, and training can continue using updated datasets that reflect additional information.

[0136] Furthermore, it should be understood that the terminology used herein is only for describing particular embodiments and is not intended to be limiting. The term “a” or “an” as used herein is defined as one or more. The term “a plurality” as used herein is defined as two or more. The term “another” as used herein is defined as at least two or more. The terms “comprising” and / or “having” as used herein are defined as including (i.e., open language).

[0137] Various embodiments have been described in this invention with reference to the accompanying drawings. However, it will be apparent that various modifications and changes can be made thereto, and additional embodiments can be implemented without departing from the broader scope of the invention as set forth in the following claims. Therefore, the invention and the drawings should be regarded as illustrative rather than restrictive.

[0138] The invention is not limited to the specific embodiments described herein, which are intended to illustrate various aspects. Many modifications and variations can be made without departing from its spirit and scope. In addition to those listed herein, functionally equivalent systems, processes, and apparatuses within the scope of the invention may be apparent from the representative description herein. Such modifications and variations are intended to fall within the scope of the appended claims. The invention is limited only by the terms of the appended claims and the full scope of their equivalents.

[0139] It should also be noted that the systems and methods described herein can be tangibly embodied in one or more physical media, such as, but not limited to, optical discs (CDs), digital versatile optical discs (DVDs), floppy disks, hard disks, read-only memory (ROMs), random access memory (RAMs), and other physical media capable of storing data. For example, data storage devices may include random access memory (RAMs) and read-only memory (ROMs) that can be configured to access and store data and information, as well as computer program instructions. Data storage devices may also include storage media or other suitable types of memory (e.g., RAM, ROM, programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), disks, optical discs, floppy disks, hard disks, removable disk enclosures, flash drives, any type of tangible and non-transitory storage media), in which files including operating systems, applications including, for example, web browser applications, email applications, and / or other applications, and data files can be stored.Data storage devices for network-enabled computer systems may include electronic information, files, and documents stored in various ways, including, for example, flat files, indexed files, hierarchical databases, relational databases (such as databases created and maintained using software from, for example, Oracle® Corporation), Microsoft® Excel files, Microsoft® Access files, solid-state storage devices (which may include flash arrays, hybrid arrays, or server-side products), enterprise storage devices (which may include online or cloud storage), or any other storage mechanism. Furthermore, these figures illustrate various components (e.g., servers, computers, processors, etc.). Functions described as performing at various components may perform at other components, and the components may be combined or separated. Other modifications may also be made.

[0140] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a corresponding computing / processing device, or via a network to an external computer or external storage device, such as the Internet, a local area network, a wide area network, and / or a wireless network. This network may include copper transmission cables, optical fiber transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device receives computer-readable program instructions from the network and forwards them to a computer-readable storage medium within the corresponding computing / processing device.

[0141] The computer-readable program instructions used to perform the operations of the present invention may be assembly instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, status setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​(such as Java, Smalltalk, C++, etc.) and conventional procedural programming languages ​​(such as the "C" programming language or similar programming languages). The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer can connect to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can connect to an external computer (e.g., via the Internet provided by an Internet service provider).In some embodiments, electronic circuits including, for example, programmable logic circuits, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs) can execute computer-readable program instructions to personalize the electronic circuits to perform aspects of the invention by utilizing state information of the computer-readable program instructions.

[0142] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified herein. These computer-readable program instructions can also be stored in a computer-readable storage medium that can instruct a computer, programmable data processing apparatus, and / or other device to operate in a certain manner, such that a computer-readable storage medium having instructions stored therein includes an article of manufacture that includes instructions for implementing aspects of the functions specified herein.

[0143] The computer-readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus, or other device to produce a computer-implemented process, such that the instructions, which execute on the computer, other programmable apparatus, or other device, implement the functions specified herein.

[0144] Implementations of the various techniques described herein can be implemented in digital electronic circuits, or in computer hardware, firmware, software, or combinations thereof. Implementations can be implemented as computer program products, i.e., computer programs tangibly embodied in an information carrier (e.g., in a machine-readable storage device or in a propagating signal) for execution or control of their operation by a data processing apparatus (e.g., a programmable processor, a computer, or multiple computers). Computer programs (such as one or more of the above-described computer programs) can be written in any form of programming language (including compiled or interpreted languages) and can be deployed in any form, including as standalone programs or as modules, components, subroutines, or other units suitable for use in a computing environment. Computer programs can be deployed to execute on a single computer or multiple computers at a single site, or distributed across multiple sites and interconnected via a communication network.

[0145] Method steps can be executed by one or more programmable processors that execute the computer program to perform functions by manipulating input data and generating outputs. Method steps can also be executed by dedicated logic circuits, and apparatus can be implemented as dedicated logic circuits, such as FPGAs (Field-Programmable Gate Arrays) or ASICs (Application-Specific Integrated Circuits).

[0146] The foregoing description of exemplary embodiments provides non-limiting representative examples of reference figures to particularly describe the features and teachings of different aspects of the invention.The described embodiments should be considered as being able to be implemented separately or in combination with other embodiments described in the embodiment description. Those skilled in the art who review the description of the embodiments should be able to learn and understand the different descriptive aspects of the invention as presented on pages 21 / 22 of this specification (CN 121444115 A). The description of the embodiments is intended to facilitate an understanding of the invention, enabling those skilled in the art, upon reading the description of the embodiments, to understand other implementations not specifically covered but falling within their knowledge, all of which should be considered consistent with the application of the invention. Instruction manual, page 22 / 22; Figure 1 (CN 121444115 A); Figure 2 (CN 121444115 A); Figure 3 (CN 121444115 A); Figure 4 (CN 121444115 A); Figure 5 (CN 121444115 A); Figure 6 (CN 121444115 A); Figure 7 (CN 121444115 A); Figure 8 (CN 121444115 A); Figure 9 (CN 121444115 A); Figure 10 (CN 121444115 A) The instruction manual includes attached figures on page 10 / 10, document number 35, CN 121444115 A.

Claims

1. A system for generating a virtual card number (VCN), the system comprising: a server comprising a bank application, wherein the bank application is configured to: receive one or more user identification data from a user device application; match the one or more user identification data with a user profile; send an authentication request to the user device application; receive authentication credentials from the user device application; retrieve one or more primary account numbers (PANs) associated with the user profile; send a prompt to the user device application to select one or more PANs to utilize to complete a transaction; receive a selection of one or more PANs from the user device application; generate a virtual card number (VCN) associated with the selected one or more PANs; and send the VCN to a merchant processor.

2. The system of claim 1, wherein the VCN is constrained to one or more merchants.

3. The system of claim 1, wherein the VCN is configured to expire after a predetermined time period.

4. The system of claim 1, wherein the VCN is limited to a predetermined spending limit.

5. The system of claim 1, wherein the bank application is further configured to store the VCN in a data storage unit for later use upon generation of the VCN.

6. The system of claim 1, wherein the VCN is constrained to one or more merchants and one or more merchant categories.

7. The system of claim 6, wherein the bank application is further configured to dynamically create merchant categories based on a spending history associated with the user profile.

8. The system of claim 1, wherein the bank application is further configured to: retrieve user location data associated with the user profile from a database; analyze trends in the user location data; and generate a predictive model configured to determine constraints on the VCN, wherein the predictive model comprises a model of one or more future spending habits associated with the user profile expected by a predetermined algorithm.

9. The system of claim 1, wherein the bank application is further configured to: retrieve spending history data associated with the user profile from a database; analyze trends in the spending history data; and generate a predictive model configured to determine constraints on the VCN, wherein the predictive model comprises a model of one or more future spending habits associated with the user profile expected by a predetermined algorithm.

10. The system of claim 1, wherein the bank application is further configured to: retrieve user fraud history data associated with the user profile; analyze trends in the user fraud history data; and generate a predictive model configured to determine constraints on the VCN, wherein the predictive model comprises a model of one or more future spending habits associated with the user profile expected by a predetermined algorithm.

11. A method for generating a virtual card number (VCN), the method comprising the steps of: receiving, by a bank application associated with a server, one or more user identification data; matching, by the bank application, the one or more user identification data with a user profile; sending, by the bank application, an authentication request to a user device application; receiving, by the bank application, an authentication credential from the user device application; retrieving one or more primary account numbers (PANs) associated with the user profile; sending, to the user device application, a prompt to select one or more PANs with which to complete a transaction; receiving, from the user device application, a selection of one or more PANs; generating, by the bank application, a virtual card number (VCN) associated with the selected one or more PANs; and sending, by the bank application, the VCN to a merchant processor.

12. The method of claim 11, wherein the VCN is constrained to at least one of a predetermined time period, merchant, geographic location, or price.

13. The method of claim 12, wherein, the predetermined constraint is dynamically changed by the bank application in response to one or more spending habits associated with the user profile.

14. The method of claim 11, wherein the method further comprises the steps of: retrieving, from a database, spending history data associated with the user profile; analyzing trends in the spending history data; and generating a predictive model configured to determine a constraint on the VCN, wherein the constraint is based on a predetermined set of merchant categories.

15. The method of claim 14, wherein the method further comprises the steps of: generating the VCN upon receiving the selection of one or more PANs, wherein the VCN is bound to the one or more selected PANs.

16. The method of claim 15, wherein, the VCN is sent from the processor to the merchant processor without notifying the user of the existence of the VCN.

17. The method of claim 11, wherein the method further comprises the steps of: receiving, by the processor, a fraud detection associated with the VCN; and changing, by the processor, one or more constraints associated with the VCN in response to the fraud detection.

18. The method of claim 11, wherein the authentication credential comprises a short message service (SMS) one-time password (OTP), a password, a biometric, or a unique customer identifier.

19. The method of claim 18, wherein, the authentication credential is sent through a communication field comprising near field communication (NFC), radio frequency identification (RFID), or Bluetooth.

20. A computer-readable non-transitory medium comprising computer- executable instructions that, when executed by a computer hardware apparatus comprising a processor, cause the computer hardware apparatus to perform processes comprising: receiving one or more user identification data; matching the one or more user identification data with a user profile; sending an authentication request to a user device application; receiving an authentication credential from the user device application; retrieving one or more primary account numbers (PANs) associated with the user profile; sending, to the user device application, a prompt to select one or more PANs with which to complete a transaction; receiving, from the user device application, a selection of one or more PANs; generating a virtual card number (VCN) associated with the selected one or more PANs; and sending the VCN to a merchant processor.