Method, system, and computer program product for securely sharing sensitive information between devices

The method of generating a machine-readable optical code for sensitive information addresses the insecurity of existing methods by enabling secure, indirect transfer between devices, thus reducing exposure risks.

WO2025122143A1PCT designated stage expired Publication Date: 2025-06-12VISA INTERNATIONAL SERVICE ASSOCIATION
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/US2023/082624
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-06
Publication Date
2025-06-12

AI Technical Summary

Technical Problem

Existing methods for sharing sensitive information between devices are insecure, as they often require manual display of information, which can lead to unintentional leakage and exposure to fraud.

Method used

A method involving the generation of a machine-readable optical code based on sensitive information, which is displayed on a first user device and scanned by a second user device, allowing secure communication of the sensitive information without direct exposure.

Benefits of technology

This approach enhances security by preventing direct display of sensitive information, reducing the risk of leakage and fraud, while allowing secure transfer between devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2023082624_12062025_PF_FP_ABST
    Figure US2023082624_12062025_PF_FP_ABST
Patent Text Reader

Abstract

Provided is a method for securely sharing sensitive information between devices. The method may include receiving a request to communicate sensitive information associated with a user from a first user device, generating a machine-readable optical code based on the sensitive information associated with the user, communicating the machine-readable optical code to the first user device to display the machine-readable optical code, receiving at least one message from a second user device based on the second user device scanning the machine-readable optical code displayed on the first user device, and communicating data associated with the sensitive information to the second user device. A system and computer program product are also disclosed.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD, SYSTEM, AND COMPUTER PROGRAM PRODUCT FOR SECURELY SHARING SENSITIVE INFORMATION BETWEEN DEVICESBACKGROUND1. Field

[0001] The disclosed subject matter relates generally to securely sharing sensitive information and, in some particular embodiments or aspects to a method, system, and computer program for securely sharing sensitive information between devices.2. Technical Considerations

[0002] User devices (e.g., mobile phones, smart watches, etc.) may store sensitive information (e.g., payment credentials, personal identifying information such as Social Security numbers or government-issued identification numbers, health information, etc.) and be used to communicate with other devices and / or systems based on the sensitive information. For example, a user device may communicate payment credentials (e.g., an account identifier) to a merchant point-of-sale (PCS) device to initiate a payment transaction. In some cases, a single user may possess multiple devices and each of which may be capable of storing sensitive information and communicating with other devices / systems based thereon.

[0003] However, not all devices of the user may have the sensitive information stored. For example, a first user device may store certain payment credentials, but a second user device may not currently have those payment credentials in storage. To transfer the sensitive information, a user must display the sensitive information on one device to manually transfer the sensitive information into the other device, which exposes the sensitive information to unintentional leakage and / or may accidentally reveal the sensitive information. Such risks expose the user’s sensitive information to fraud and misuse.

[0004] There is a need for a technical solution to allow for heightened security when transferring sensitive information between devices.SUMMARY

[0005] Accordingly, it is an object of the present disclosure to provide methods, systems, and computer program products for securely sharing sensitive information (e.g., that overcome some or all of the deficiencies identified above).

[0006] According to some non-limiting embodiments or aspects, provided is a computer implemented method for securely sharing sensitive information between devices. In some non-limiting embodiments or aspects, the method may include receiving a request to communicate sensitive information associated with a user from a first user device. A machine-readable optical code may be generated based on the sensitive information associated with the user. The machine-readable optical code may be communicated to the first user device to display the machine-readable optical code. The at least one message may be received from a second user device based on the second user device scanning the machine-readable optical code displayed on the first user device. Data associated with the sensitive information may be communicated to the second user device.

[0007] In some non-limiting embodiments or aspects, the method may further include retrieving partial data associated with a portion of the sensitive information and / or communicating the partial data to the first user device to display the partial data. Receiving the request to communicate the sensitive information may include receiving a communication from the first user device indicating selection of the partial data displayed by the user device.

[0008] In some non-limiting embodiments or aspects, the machine-readable optical code may be based on the partial data.

[0009] In some non-limiting embodiments or aspects, the machine-readable optical code may include at least one of a quick response code (e.g., a QR code), an App Clip Code, a two-dimensional matrix barcode, a matrix barcode, a barcode, or any combination thereof.

[0010] In some non-limiting embodiments or aspects, the second user device may include an augmented-reality device. The second application may be associated with the first application.

[0011] In some non-limiting embodiments or aspects, the method may further include receiving user login data via a first application of the first user device and / or receiving the user login data via a second application of the second user device.

[0012] In some non-limiting embodiments or aspects, the machine-readable optical code may be associated with the user login data. The method may further include authenticating the second user device in response to matching the machine-readable optical code and the user login data received from the second user device. A user login data may include a unique code, a password, biometric data, stored keys, or any combination thereof.

[0013] In some non-limiting embodiments or aspects, the at least one message may include an authentication message. The method may further include communicating identification data to the second user device in response to receiving the authentication message. The at least one message may further include a request for the sensitive information based on the identification data. Communicating the data associated with the sensitive information may include communicating the data associated with the sensitive information to the second user device in response to receiving the request for the sensitive information based on the identification data from the second user device.

[0014] According to some non-limiting embodiment or aspects, provided is a system for securely sharing sensitive information between devices. The system may comprise at least one processor and at least one non-transitory computer-readable medium including one or more instructions that, when executed by the at least one processor, direct the at least one processor to receive a request to communicate sensitive information associated with a user from a first user device. A machine-readable optical code may be generated based on the sensitive information associated with the user. The machine-readable optical code may be communicated to the first user device to display the machine-readable optical code. At least one message may be received from a second user device based on the second user device scanning the machine- readable optical code displayed on the first user device. Data associated with the sensitive information may be communicated to the second user device.

[0015] In some non-limiting embodiments or aspects, the system may further direct the at least one processor to retrieve partial data associated with a portion of the sensitive information and communicate the partial data to the first user device to display the partial data. Receiving the request to communicate the sensitive information may include receiving a communication from the first user device indicating selection of the partial data displayed by the user device.

[0016] In some non-limiting embodiments or aspects, the machine-readable optical code may be based on the partial data. The machine-readable optical code may include at least one of a quick response code (e.g., a QR code), an App Clip Code, a two-dimensional matrix barcode, a matrix barcode, a barcode, or any combination thereof. The second user device may include an augmented-reality device.

[0017] In some non-limiting embodiments or aspects, the system may direct the at least one processor to receive user login data via a first application of the first user device and receive the user login data via a second application of the second user device.

[0018] In some non-limiting embodiments or aspects, the second application may be associated with the first application. The machine-readable optical code may be associated with the user login data. The at least one processor of the system may be further directed to authenticate the second user device in response to matching the machine-readable optical code and the user login data received from the second user device. A user login data may include a unique code, a password, biometric data, stored keys, or any combination thereof.

[0019] In some non-limiting embodiments or aspects, the at least one message may include an authentication message. The at least one processor of the system may be further directed to communicate identification data to the second user device in response to receiving the authentication message, wherein the at least one message further includes a request for the sensitive information based on the identification data, and wherein communicating the data associated with the sensitive information includes communicating the data associated with the sensitive information to the second user device in response to receiving the request for the sensitive information based on the identification data from the second user device.

[0020] According to some non-limiting embodiment or aspects, provided is a computer program product for securely sharing sensitive information between devices. The computer program product may include at least one non-transitory computer- readable medium including one or more instructions that, when executed by at least one processor, may cause the at least one processor to receive a request to communicate sensitive information associated with a user from a first user device. A machine-readable optical code may be generated based on the sensitive information associated with the user. The machine-readable optical code may be communicated to the first user device to display the machine-readable optical code. At least onemessage may be received from a second user device based on the second user device scanning the machine-readable optical code displayed on the first user device. Data associated with the sensitive information may be communicated to the second user device.

[0021] In some non-limiting embodiments or aspects, the computer program product may further cause the at least one processor to retrieve partial data associated with a portion of the sensitive information and communicate the partial data to the first user device to display the partial data. Receiving the request to communicate the sensitive information may further include receiving a communication from the first user device indicating selection of the partial data displayed by the user device.

[0022] In some non-limiting embodiments or aspects, the machine-readable optical code may be based on the partial data. The machine-readable optical code may include at least one of a quick response code (e.g., a QR code), an App Clip Code, a two-dimensional matrix barcode, a matrix barcode, a barcode, or any combination thereof. The second user device may include an augmented-reality device.

[0023] In some non-limiting embodiments or aspects, the computer program product may further direct the at least one processor to receive user login data via a first application of the first user device and receive the user login data via a second application of the second user device. The second application may be associated with the first application.

[0024] In some non-limiting embodiments or aspects, wherein the machine- readable optical code may be associated with the user login data, the computer program product may direct the at least one processor to authenticate the second user device in response to matching the machine-readable optical code and the user login data received from the second user device. A user login data may include a unique code, a password, biometric data, stored keys, or any combination thereof.

[0025] In some non-limiting embodiments or aspects, the at least one message may include an authentication message. The computer program product may further cause the at least one processor to communicate identification data to the second user device in response to receiving the authentication message, wherein the at least one message further includes a request for the sensitive information based on the identification data, and wherein communicating the data associated with the sensitive information includes communicating the data associated with the sensitive informationto the second user device in response to receiving the request for the sensitive information based on the identification data from the second user device.

[0026] Other non-limiting embodiments or aspects of the present disclosure will be set forth in the following numbered clauses.

[0027] Clause 1 : A computer-implemented method, comprising: receiving, with at least one processor, a request to communicate sensitive information associated with a user from a first user device; generating, with at least one processor, a machine- readable optical code based on the sensitive information associated with the user; communicating, with at least one processor, the machine-readable optical code to the first user device to display the machine-readable optical code; receiving, with at least one processor, at least one message from a second user device based on the second user device scanning the machine-readable optical code displayed on the first user device; and communicating, with at least one processor, data associated with the sensitive information to the second user device.

[0028] Clause 2: The computer-implemented method of clause 1 , further comprising: retrieving, with at least one processor, partial data associated with a portion of the sensitive information; and communicating, with at least one processor, the partial data to the first user device to display the partial data.

[0029] Clause 3: The computer-implemented method of clause 1 or clause 2, wherein receiving the request to communicate the sensitive information comprises: receiving a communication from the first user device indicating selection of the partial data displayed by the user device.

[0030] Clause 4: The computer-implemented method of any one of clauses 1 -3, wherein the machine-readable optical code is based on the partial data.

[0031] Clause 5: The computer-implemented method of any one of clauses 1 -4, wherein the machine-readable optical code comprises at least one of a quick response code (e.g., a QR code), an App Clip Code, a two-dimensional matrix barcode, a matrix barcode, a barcode, or any combination thereof.

[0032] Clause 6: The computer-implemented method of any one of clauses 1 -5, wherein the second user device comprises an augmented-reality device.

[0033] Clause 7: The computer-implemented method of any one of clauses 1 -6, further comprising: receiving, with at least one processor, user login data via a first application of the first user device; and receiving, with at least one processor, the user login data via a second application of the second user device.

[0034] Clause 8: The computer-implemented method of any one of clauses 1 -7, wherein the second application is associated with the first application.

[0035] Clause 9: The computer-implemented method of any one of clauses 1 -8, wherein the machine-readable optical code is associated with the user login data, the computer-implemented method further comprising: authenticating, with at least one processor, the second user device in response to matching the machine-readable optical code and the user login data received from the second user device.

[0036] Clause 10: The computer-implemented method of any one of clauses 1 -9, wherein user login data comprises a unique code, a password, biometric data, stored keys, or any combination thereof.

[0037] Clause 1 1 : The computer-implemented method of any one of clauses 1 -10, wherein the at least one message comprises an authentication message, the computer-implemented method further comprising communicating, with at least one processor, identification data to the second user device in response to receiving the authentication message, wherein the at least one message further comprises a request for the sensitive information based on the identification data, and wherein communicating the data associated with the sensitive information comprises communicating the data associated with the sensitive information to the second user device in response to receiving the request for the sensitive information based on the identification data from the second user device.

[0038] Clause 12: A system comprising: at least one processor; and at least one non-transitory computer-readable medium including one or more instructions that, when executed by the at least one processor, direct the at least one processor to: receive a request to communicate sensitive information associated with a user from a first user device; generate a machine-readable optical code based on the sensitive information associated with the user; communicate the machine-readable optical code to the first user device to display the machine-readable optical code; receive at least one message from a second user device based on the second user device scanning the machine-readable optical code displayed on the first user device; and communicate data associated with the sensitive information to the second user device.

[0039] Clause 13: The system of clause 12, wherein the one or more instructions, when executed by the at least one processor, further direct the at least one processor to: retrieve partial data associated with a portion of the sensitive information; and communicate the partial data to the first user device to display the partial data.

[0040] Clause 14: The system of clause 12 or clause 13, wherein receiving the request to communicate the sensitive information comprises: receiving a communication from the first user device indicating selection of the partial data displayed by the user device.

[0041] Clause 15: The system of any one of clauses 12-14, wherein the machine- readable optical code is based on the partial data.

[0042] Clause 16: The system of any one of clauses 12-15, wherein the machine- readable optical code comprises at least one of a quick response code (e.g., a QR code), an App Clip Code, a two-dimensional matrix barcode, a matrix barcode, a barcode, or any combination thereof.

[0043] Clause 17: The system of any one of clauses 12-16, wherein the second user device comprises an augmented-reality device.

[0044] Clause 18: The system of any one of clauses 12-17, wherein the one or more instructions, when executed by the at least one processor, further direct the at least one processor to: receive user login data via a first application of the first user device; and receive the user login data via a second application of the second user device.

[0045] Clause 19: The system of any one of clauses 12-18, wherein the second application is associated with the first application.

[0046] Clause 20: The system of any one of clauses 12-19, wherein the machine- readable optical code is associated with the user login data, and wherein the one or more instructions, when executed by the at least one processor, further direct the at least one processor to: authenticate the second user device in response to matching the machine-readable optical code and the user login data received from the second user device.

[0047] Clause 21 : The system of any one of clauses 12-20, wherein user login data comprises a unique code, a password, biometric data, stored keys, or any combination thereof.

[0048] Clause 22: The system of any one of clauses 12-21 , wherein the at least one message comprises an authentication message, and wherein the one or more instructions, when executed by the at least one processor, further direct the at least one processor to communicate identification data to the second user device in response to receiving the authentication message, wherein the at least one message further comprises a request for the sensitive information based on the identification data, and wherein communicating the data associated with the sensitive informationcomprises communicating the data associated with the sensitive information to the second user device in response to receiving the request for the sensitive information based on the identification data from the second user device.

[0049] Clause 23: A computer program product comprising at least one non- transitory computer-readable medium including one or more instructions that, when executed by at least one processor, cause the at least one processor to: receive a request to communicate sensitive information associated with a user from a first user device; generate a machine-readable optical code based on the sensitive information associated with the user; communicate the machine-readable optical code to the first user device to display the machine-readable optical code; receive at least one message from a second user device based on the second user device scanning the machine-readable optical code displayed on the first user device; and communicate data associated with the sensitive information to the second user device.

[0050] Clause 24: The computer program product of clause 23, wherein the one or more instructions, when executed by the at least one processor, further cause the at least one processor caused to: retrieve partial data associated with a portion of the sensitive information; and communicate the partial data to the first user device to display the partial data.

[0051] Clause 25: The computer program product of clause 23 or clause 24, wherein receiving the request to communicate the sensitive information comprises: receiving a communication from the first user device indicating selection of the partial data displayed by the user device.

[0052] Clause 26: The computer program product of any one of clauses 23-25, wherein the machine-readable optical code is based on the partial data.

[0053] Clause 27: The computer program product of any one of clauses 23-26, wherein the machine-readable optical code comprises at least one of a quick response code (e.g., a QR code), an App Clip Code, a two-dimensional matrix barcode, a matrix barcode, a barcode, or any combination thereof.

[0054] Clause 28: The computer program product of any one of clauses 23-27, wherein the second user device comprises an augmented-reality device.

[0055] Clause 29: The computer program product of any one of clauses 23-28, wherein the one or more instructions, when executed by the at least one processor, further cause the at least one processor to: receive user login data via a firstapplication of the first user device; and receive the user login data via a second application of the second user device.

[0056] Clause 30: The computer program product of any one of clauses 23-29, wherein the second application is associated with the first application.

[0057] Clause 31 : The computer program product of any one of clauses 23-30, wherein the machine-readable optical code is associated with the user login data, and wherein the one or more instructions, when executed by the at least one processor, further cause the at least one processor to: authenticate the second user device in response to matching the machine-readable optical code and the user login data received from the second user device.

[0058] Clause 32: The computer program product of any one of clauses 23-31 , wherein user login data comprises a unique code, a password, biometric data, stored keys, or any combination thereof.

[0059] Clause 33: The computer program product of any one of clauses 23-32, wherein the at least one message comprises an authentication message, and wherein the one or more instructions, when executed by the at least one processor, further cause the at least one processor to communicate identification data to the second user device in response to receiving the authentication message, wherein the at least one message further comprises a request for the sensitive information based on the identification data, and wherein communicating the data associated with the sensitive information comprises communicating the data associated with the sensitive information to the second user device in response to receiving the request for the sensitive information based on the identification data from the second user device.

[0060] These and other features and characteristics of the present disclosure, as well as the methods of operation and functions of the related elements of structures and the combination of parts and economies of manufacture, will become more apparent upon consideration of the following description and the appended claims with reference to the accompanying drawings, all of which form a part of this specification, wherein like reference numerals designate corresponding parts in the various figures. It is to be expressly understood, however, that the drawings are for the purpose of illustration and description only and are not intended as a definition of the limits of the disclosed subject matter.BRIEF DESCRIPTION OF THE DRAWINGS

[0061] Additional advantages and details are explained in greater detail below with reference to the non-limiting, exemplary embodiments that are illustrated in the accompanying schematic figures, in which:

[0062] FIG. 1 is a schematic diagram of a system for securely sharing sensitive information between devices, according to some non-limiting embodiments or aspects;

[0063] FIG. 2 is a diagram of a non-limiting embodiment of components of one or more devices of FIG. 1 ;

[0064] FIG. 3 is a non-limiting embodiment of a process for securely sharing sensitive information between devices according to the principles of the presented disclosed subject matter;

[0065] FIG. 4 is a diagram of a non-limiting embodiment of an implementation of a non-limiting embodiment of the process shown in FIG. 3, according to the principles of the presently disclosure subject matter; and

[0066] FIG. 5 is a diagram of a non-limiting embodiment or aspect of an environment in which methods, systems, and / or computer program products, described herein, may be implemented according to the principles of the presently disclosed subject matter.DESCRIPTION OF THE INVENTION

[0067] For purposes of the description hereinafter, the terms “end”, “upper”, “lower”, “right”, “left”, “vertical”, “horizontal”, “top”, “bottom”, “lateral”, “longitudinal”, and derivatives thereof shall relate to the disclosed subject matter as it is oriented in the drawing figures. However, it is to be understood that the disclosed subject matter may assume various alternative variations and step sequences, except where expressly specified to the contrary. It is also to be understood that the specific devices and processes illustrated in the attached drawings, and described in the following specification, are simply exemplary embodiments or aspects of the disclosed subject matter. Hence, specific dimensions and other physical characteristics related to the embodiments or aspects disclosed herein are not to be considered as limiting unless otherwise indicated.

[0068] No aspect, component, element, structure, act, step, function, instruction, and / or the like used herein should be construed as critical or essential unless explicitlydescribed as such. Also, as used herein, the articles “a” and “an” are intended to include one or more items and may be used interchangeably with “one or more” and “at least one”. Furthermore, as used herein, the term “set” is intended to include one or more items (e.g., related items, unrelated items, a combination of related and unrelated items, and / or the like) and may be used interchangeably with “one or more” or “at least one”. Where only one item is intended, the term “one” or similar language is used. Also, as used herein, the terms “has”, “have”, “having”, or the like are intended to be open-ended terms. Further, the phrase “based on” is intended to mean “based at least partially on” unless explicitly stated otherwise.

[0069] As used herein, the terms “communication” and “communicate” may refer to the reception, receipt, transmission, transfer, provision, and / or the like of information (e.g., data, signals, messages, instructions, commands, and / or the like). For one unit (e.g., a device, a system, a component of a device or system, combinations thereof, and / or the like) to be in communication with another unit means that the one unit is able to directly or indirectly receive information from and / or transmit information to the other unit. This may refer to a direct or indirect connection (e.g., a direct communication connection, an indirect communication connection, and / or the like) that is wired and / or wireless in nature. Additionally, two units may be in communication with each other even though the information transmitted may be modified, processed, relayed, and / or routed between the first and second unit. For example, a first unit may be in communication with a second unit even though the first unit passively receives information and does not actively transmit information to the second unit. As another example, a first unit may be in communication with a second unit if at least one intermediary unit (e.g., a third unit located between the first unit and the second unit) processes information received from the first unit and communicates the processed information to the second unit. In some non-limiting embodiments, a message may refer to a network packet (e.g., a data packet and / or the like) that includes data. It will be appreciated that numerous other arrangements are possible.

[0070] As used herein, the term “computing device” may refer to one or more electronic devices configured to process data. A computing device may, in some examples, include the necessary components to receive, process, and output data, such as a processor, a display, a memory, an input device, a network interface, and / or the like. A computing device may be a mobile device. As an example, a mobile device may include a cellular phone (e.g., a smartphone or standard cellular phone), aportable computer (e.g., laptop computer, a tablet computer, and / or the like), a wearable device (e.g., watches, glasses, lenses, clothing, and / or the like), a personal digital assistant (PDA), and / or other like devices. A computing device may also be a desktop computer or other form of non-mobile computer.

[0071] As used herein, the terms “issuer institution,” “portable financial device issuer,” “issuer,” or “issuer bank” may refer to one or more entities that provide accounts to customers for conducting transactions (e.g., payment transactions), such as initiating credit and / or debit payments. For example, an issuer institution may provide an account identifier, such as a personal account number (PAN), to a customer that uniquely identifies one or more accounts associated with that customer. The account identifier may be embodied on a portable financial device, such as a physical financial instrument, e.g., a payment card, and / or may be electronic and used for electronic payments. The terms “issuer institution” and “issuer institution system” may also refer to one or more computer systems operated by or on behalf of an issuer institution, such as a server computer executing one or more software applications. For example, an issuer institution system may include one or more authorization servers for authorizing a transaction.

[0072] As used herein, the term “account identifier” may include one or more types of identifiers associated with a user account (e.g., a PAN, a primary account number, a card number, a payment card number, a token, and / or the like). In some non-limiting embodiments, an issuer institution may provide an account identifier (e.g., a PAN, a token, and / or the like) to a user that uniquely identifies one or more accounts associated with that user. The account identifier may be embodied on a physical financial instrument (e.g., a portable financial instrument, a payment card, a credit card, a debit card, and / or the like) and / or may be electronic information communicated to the user that the user may use for electronic payments. In some non-limiting embodiments, the account identifier may be an original account identifier, where the original account identifier was provided to a user at the creation of the account associated with the account identifier. In some non-limiting embodiments, the account identifier may be an account identifier (e.g., a supplemental account identifier) that is provided to a user after the original account identifier was provided to the user. For example, if the original account identifier is forgotten, stolen, and / or the like, a supplemental account identifier may be provided to the user. In some non-limiting embodiments, an account identifier may be directly or indirectly associated with anissuer institution such that an account identifier may be a token that maps to a PAN or other type of identifier. Account identifiers may be alphanumeric, any combination of characters and / or symbols, and / or the like. An issuer institution may be associated with a bank identification number (BIN) that uniquely identifies the issuer institution.

[0073] As used herein, the term “merchant” may refer to one or more entities (e.g., operators of retail businesses that provide goods and / or services, and / or access to goods and / or services, to a user (e.g., a customer, a consumer, a customer of the merchant, and / or the like) based on a transaction (e.g., a payment transaction)). As used herein, “merchant system” may refer to one or more computer systems operated by or on behalf of a merchant, such as a server computer executing one or more software applications. As used herein, the term “product” may refer to one or more goods and / or services offered by a merchant.

[0074] As used herein, a “point-of-sale (POS) device” may refer to one or more devices, which may be used by a merchant to initiate transactions (e.g., a payment transaction), engage in transactions, and / or process transactions. For example, a POS device may include one or more computers, peripheral devices, card readers, near-field communication (NFC) receivers, radio frequency identification (RFID) receivers, and / or other contactless transceivers or receivers, contact-based receivers, payment terminals, computers, servers, input devices, and / or the like.

[0075] As used herein, a “point-of-sale (POS) system” may refer to one or more computers and / or peripheral devices used by a merchant to conduct a transaction. For example, a POS system may include one or more POS devices and / or other like devices that may be used to conduct a payment transaction. A POS system (e.g., a merchant POS system) may also include one or more server computers programmed or configured to process online payment transactions through webpages, mobile applications, and / or the like.

[0076] As used herein, the term “transaction service provider” may refer to an entity that receives transaction authorization requests from merchants or other entities and provides guarantees of payment, in some cases through an agreement between the transaction service provider and the issuer institution. In some non-limiting embodiments, a transaction service provider may include a credit card company, a debit card company, and / or the like. As used herein, the term “transaction service provider system” may also refer to one or more computer systems operated by or on behalf of a transaction service provider, such as a transaction processing serverexecuting one or more software applications. A transaction processing server may include one or more processors and, in some non-limiting embodiments, may be operated by or on behalf of a transaction service provider.

[0077] As used herein, the term “acquirer” may refer to an entity licensed by the transaction service provider and approved by the transaction service provider to originate transactions (e.g., payment transactions) using a portable financial device associated with the transaction service provider. As used herein, the term “acquirer system” may also refer to one or more computer systems, computer devices, and / or the like operated by or on behalf of an acquirer. The transactions the acquirer may originate may include payment transactions (e.g., purchases, original credit transactions (OCTs), account funding transactions (AFTs), and / or the like). In some non-limiting embodiments, the acquirer may be authorized by the transaction service provider to assign merchant or service providers to originate transactions using a portable financial device of the transaction service provider. The acquirer may contract with payment facilitators to enable the payment facilitators to sponsor merchants. The acquirer may monitor compliance of the payment facilitators in accordance with regulations of the transaction service provider. The acquirer may conduct due diligence of the payment facilitators and ensure that proper due diligence occurs before signing a sponsored merchant. The acquirer may be liable for all transaction service provider programs that the acquirer operates or sponsors. The acquirer may be responsible for the acts of the acquirer’s payment facilitators, merchants that are sponsored by an acquirer’s payment facilitators, and / or the like. In some non-limiting embodiments, an acquirer may be a financial institution, such as a bank.

[0078] As used herein, the terms “electronic wallet,” “electronic wallet mobile application,” and “digital wallet” may refer to one or more electronic devices and / or one or more software applications configured to initiate and / or conduct transactions (e.g., payment transactions, electronic payment transactions, and / or the like). For example, an electronic wallet may include a user device (e.g., a mobile device) executing an application program and server-side software and / or databases for maintaining and providing transaction data to the user device. As used herein, the term “electronic wallet provider” may include an entity that provides and / or maintains an electronic wallet and / or an electronic wallet mobile application for a user (e.g., a customer). Examples of an electronic wallet provider include, but are not limited to, Google Wallet™, Android Pay®, Apple Pay®, and Samsung Pay®. In some non-limiting examples, a financial institution (e.g., an issuer institution) may be an electronic wallet provider. As used herein, the term “electronic wallet provider system” may refer to one or more computer systems, computer devices, servers, groups of servers, and / or the like operated by or on behalf of an electronic wallet provider.

[0079] As used herein, the term “portable financial device” may refer to a payment card (e.g., a credit or debit card), a gift card, a smartcard, smart media, a payroll card, a healthcare card, a wrist band, a machine-readable medium containing account information, a keychain device or fob, an RFID transponder, a retailer discount or loyalty card, a cellular phone, an electronic wallet mobile application, a personal digital assistant (PDA), a pager, a security card, a computer, an access card, a wireless terminal, a transponder, and / or the like. In some non-limiting embodiments, the portable financial device may include volatile or non-volatile memory to store information (e.g., an account identifier, a name of the account holder, and / or the like).

[0080] As used herein, the terms “client” and “client device” may refer to one or more client-side devices or systems (e.g., remote from a transaction service provider) used to initiate or facilitate a transaction (e.g., a payment transaction). As an example, a “client device” may refer to one or more POS devices used by a merchant, one or more acquirer host computers used by an acquirer, one or more mobile devices used by a user, and / or the like. In some non-limiting embodiments, a client device may be an electronic device configured to communicate with one or more networks and initiate or facilitate transactions. For example, a client device may include one or more computers, portable computers, laptop computers, tablet computers, mobile devices, cellular phones, wearable devices (e.g., watches, glasses, lenses, clothing, and / or the like), PDAs, and / or the like. Moreover, a “client” may also refer to an entity (e.g., a merchant, an acquirer, and / or the like) that owns, utilizes, and / or operates a client device for initiating transactions (e.g., for initiating transactions with a transaction service provider).

[0081] As used herein, the term “server” may refer to one or more computing devices (e.g., processors, storage devices, similar computer components, and / or the like) that communicate with client devices and / or other computing devices over a network (e.g., a public network, the Internet, a private network, and / or the like) and, in some examples, facilitate communication among other servers and / or client devices. It will be appreciated that various other arrangements are possible. As used herein, the term “system” may refer to one or more computing devices or combinations ofcomputing devices (e.g., processors, servers, client devices, software applications, components of such, and / or the like). Reference to “a device,” “a server,” “a processor,” and / or the like, as used herein, may refer to a previously-recited device, server, or processor that is recited as performing a previous step or function, a different server or processor, and / or a combination of servers and / or processors. For example, as used in the specification and the claims, a first server or a first processor that is recited as performing a first step or a first function may refer to the same or different server or the same or different processor recited as performing a second step or a second function.

[0082] Non-limiting embodiments of the present invention are directed to methods, systems, and computer program products for securely sharing sensitive information between devices. In some non-limiting embodiments or aspects, a method may include receiving a request to communicate sensitive information associated with a user from a first user device, generating a machine-readable optical code based on the sensitive information associated with the user, communicating the machine- readable optical code to the first user device to display the machine-readable optical code, receiving, with at least one processor, at least one message from a second user device based on the second user device scanning the machine-readable optical code displayed on the first user device, and communicating data associated with the sensitive information to the second user device. In this way, embodiments or aspects of the present invention are effective at securely sharing sensitive information between devices. Accordingly, sensitive information may be shared without having been fully displayed on a device. Additionally, the sensitive information may be shared between devices without direct communication between the devices. For example, security for data transfer may be heightened by allowing transmission of sensitive information indirectly between two devices of a single user via machine-readable optical codes and / or one or more servers. Such indirect transmission of data prevents any unintended leakage of sensitive information from direct transmission of data (e.g., in clear text). By virtue of using machine-readable optical codes, the devices of the user must be located at the same time and place to allow the transfer of sensitive data. Additionally, the user may be required to be logged into corresponding applications on the devices. Optionally, the scanning of machine-readable codes to an AR application and specific type of machine-readable code (e.g., App Clip QR code) intended for AR,security may be further enhanced because the sensitive information may never be displayed in plain text on the screen, thereby preventing screen-scraping attacks.

[0083] Referring to FIG. 1 , FIG. 1 is a schematic diagram of an example environment 100 in which devices, systems, and / or methods, described herein, may be implemented. As shown in FIG. 1 , environment 100 may include first user device 102a, second user device 102b, sensitive information server 104, optical server 106, authentication server 108, and / or communication network 1 10.

[0084] First user device 102a may include one or more devices capable of receiving information from and / or communicating information to second user device 102b, sensitive information server 104, optical code server 106, and / or authentication server 108 (e.g., via communication network 1 10). For example, first user device 102a may include at least one computing device, such as a mobile device, a cellular phone (e.g., a smartphone), a portable computer, a wearable device, a personal digital assistant (PDA), and / or the like. In some non-limiting embodiments or aspects, the first user device 102a may or may not be capable receiving information via a short range wireless communication connection (e.g., an NFC communication connection, an RFID communication connection, a Bluetooth® communication connection, and / or the like) and / or communicating information via a short range wireless communication connection. The first user device 102a may be capable of receiving information or communicating information via an application or programming installed on the first user device 102a. In some non-limiting embodiments or aspects, first user device 102a may be a client device and / or the like.

[0085] Second user device 102b may include one or more devices capable of receiving information from and / or communicating information to first user device 102a, sensitive information server 104, optical code server 106, and / or authentication server 108 (e.g., via communication network 1 10). For example, second user device 102b may include at least one computing device, such as a mobile device, a cellular phone (e.g., a smartphone), a portable computer, a wearable device, a personal digital assistant (PDA), and / or the like. In some non-limiting embodiments or aspects, the second user device 102b may or may not be capable receiving information via a short range wireless communication connection (e.g., an NFC communication connection, an RFID communication connection, a Bluetooth® communication connection, and / or the like) and / or communicating information via a short range wireless communication connection. The second user device 102b may be capable of receiving information orcommunicating information via an application or programming installed on the second user device 102b. In some non-limiting embodiments or aspects, second user device 102b may be an augmented reality device. Additionally, second user device 102b may be a client device and / or the like.

[0086] Sensitive information server 104 may include one or more devices capable of receiving information and / or communicating information to first user device 102a, second user device 102b, optical code server 106, and / or authentication server 108 (e.g., via communication network 1 10). For example, the sensitive information server 104 may include a computing device, such as a server, a group of servers, and / or other like devices. In some non-limiting embodiments or aspects, the sensitive information server 104 may be associated with a transaction service provider system, an issuer system, a merchant system, and / or the like, as described herein. In some non-limiting embodiments or aspects, sensitive information server 104 may be in communication with a data storage device, which may be local or remote to the sensitive information server 104. In some non-limiting embodiments or aspects, sensitive information server 104 may be capable of receiving information from, storing information in, communicating information to, or searching information stored in the data storage device.

[0087] Optical code server 106 may include one or more devices capable of receiving information and / or communicating information to first user device 102a, second user device 102b, sensitive information server 104, and / or authentication server 108 (e.g., via communication network 1 10). For example, the optical code server 106 may include a computing device, such as a server, a group of servers, and / or like devices. In some non-limiting embodiments or aspects, the optical code server 106 may be associated with transaction service provider system, an issuer system, a merchant system, and / or the like, as described herein. In some non-limiting embodiments or aspects, the optical code server 106 may be in communication with a data storage device, which may be local or remote to the optical code server 106. In some non-limiting embodiments or aspects, the optical code server 106 may be capable of receiving information from, storing information in, communicating information to, or searching information stored in the data storage device.

[0088] Authentication server 108 may include one or more devices capable of receiving information and / or communicating information to first user device 102a, second user device 102b, sensitive information server 104, and / or optical code server106 (e.g., via communicating network 1 10). For example, the authentication server 108 may include a computing device, such as a server, a group of servers, and / or like devices. In some non-limiting embodiments or aspects, the authentication server 108 may be associated with transaction service provider system, an issuer system, a merchant system, and / or the like, as described herein. In some non-limiting embodiments or aspects, the authentication server 108 may be in communication with a data storage device, which may be local or remote to the authentication server 108. In some non-limiting embodiments or aspects, the authentication server 108 may be capable of receiving information from, storing information in, communicating information to, or searching information stored in the data storage device.

[0089] In some non-limiting embodiments or aspects, at least two of (e.g., all of) sensitive information server 104, optical code server 106, and / or authentication server 108 may be the same device (e.g., same server) and / or part of the same system. In some non-limiting embodiments or aspects, sensitive information server 104, optical code server 106, and authentication server 108 may all be separate devices (e.g., separate servers).

[0090] Communication network 1 10 may include one or more devices capable of receiving information from and / or communicating information to first user device 102a, second user device 102b, sensitive information server 104, optical code server 106, and / or authentication server 108. For example, communication network 1 10 may include a computing device, such as a server, a group of servers, and / or like devices. In some non-limiting embodiments or aspects, communication network 1 10 may be in communication with a data storage device, which may be local or remote to communication network 1 10. In some non-limiting embodiments or aspects, communication network 1 10 may be capable of receiving information from, storing information in, communicating information to, or searching information stored in the data storage device.

[0091] In some non-limiting embodiments or aspects, sensitive information server 104, optical server 106, authentication server 108, and communication network 1 10 may interact via wired connections, wireless connections, or a combination of wired and wireless connections. In some non-limiting embodiments or aspects, first user device 102a and second user device 102b may communicate with communication network 1 10 via wired connections, wireless connections, or a combination of wired and wireless connections.

[0092] The number and arrangement of systems, devices, servers, and / or networks shown in FIG. 1 are provided as an example. There may be additional systems, devices, servers, and / or networks; fewer systems devices, servers, and / or networks; and / or different arranged systems, devices, servers, and / or networks than those shown in FIG. 1. Furthermore, two or more systems, servers, devices, or networks shown in FIG. 1 may be implemented within a single system, server, network, or device, or a single system, network, server, or device shown in FIG. 1 may be implemented as multiple, distributed systems, networks, servers or devices. Additionally or alternatively, a set of systems (e.g., one or more systems), a set of servers (e.g., one or more servers), or a set of networks (e.g. one or more networks), or a set of devices (e.g., one or more devices) of environment 100 may perform one or more functions described as being performed by another set of systems, another set of severs, another set of networks, or another set of devices of environment 100.

[0093] Referring now to FIG. 2, FIG. 2 is a diagram of example components of a device 200. Device 200 may correspond to one or more devices first user device 102a, second user device 102b, one or more devices of sensitive information server 104, optical code server 106, authentication server, and / or one or more devices of communication network 1 10. In some non-limiting embodiments, first user device 102a, second user device 102b, sensitive information server 104, optical code server 106, authentication server 108, and / or communication network 1 10 may include at least one device 200 and / or at least one component of device 200. As shown in FIG. 2, device 200 may include bus 202, processor 204, memory 206, storage component 208, input component 210, output component 212, and communication interface 214.

[0094] Bus 202 may include a component that permits communication among the components of device 200. In some non-limiting embodiments, processor 204 may be implemented in hardware, a combination of hardware and firmware, and / or a combination of hardware and software. For example, processor 204 may include a processor (e.g., a central processing unit (CPU), a graphics processing unit (GPU), an accelerated processing unit (APU), and / or the like), a microprocessor, a digital signal processor (DSP), and / or any processing component (e.g., a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), and / or the like), and / or the like, which can be programmed to perform a function. Memory 206 may include random access memory (RAM), read only memory (ROM), and / or another type of dynamic or static storage device (e.g., flash memory, magnetic memory, opticalmemory, and / or the like) that stores information and / or instructions for use by processor 204.

[0095] Storage component 208 may store information and / or software related to the operation and use of device 200. For example, storage component 208 may include a hard disk (e.g., a magnetic disk, an optical disk, a magneto-optic disk, a solid state disk, and / or the like), a compact disc (CD), a digital versatile disc (DVD), a floppy disk, a cartridge, a magnetic tape, and / or another type of computer-readable medium, along with a corresponding drive.

[0096] Input component 210 may include a component that permits device 200 to receive information, such as via user input (e.g., a touch screen display, a keyboard, a keypad, a mouse, a button, a switch, a microphone, a camera, and / or the like). Additionally or alternatively, input component 210 may include a sensor for sensing information (e.g., a global positioning system (GPS) component, an accelerometer, a gyroscope, an actuator, and / or the like). Output component 212 may include a component that provides output information from device 200 (e.g., a display, a speaker, one or more light-emitting diodes (LEDs), and / or the like).

[0097] Communication interface 214 may include a transceiver-like component (e.g., a transceiver, a receiver and transmitter that are separate, and / or the like) that enables device 200 to communicate with other devices, such as via a wired connection, a wireless connection, or a combination of wired and wireless connections. Communication interface 214 may permit device 200 to receive information from another device and / or provide information to another device. For example, communication interface 214 may include an Ethernet interface, an optical interface, a coaxial interface, an infrared interface, a radio frequency (RF) interface, a universal serial bus (USB) interface, a Wi-Fi® interface, a Bluetooth® interface, a Zigbee® interface, a cellular network interface, and / or the like.

[0098] Device 200 may perform one or more processes described herein. Device 200 may perform these processes based on processor 204 executing software instructions stored by a computer-readable medium, such as memory 206 and / or storage component 208. A computer-readable medium (e.g., a non-transitory computer-readable medium) is defined herein as a non-transitory memory device. A non-transitory memory device includes memory space located inside of a single physical storage device or memory space spread across multiple physical storage devices.

[0099] Software instructions may be read into memory 206 and / or storage component 208 from another computer-readable medium or from another device via communication interface 214. When executed, software instructions stored in memory 206 and / or storage component 208 may cause processor 204 to perform one or more processes described herein. Additionally or alternatively, hardwired circuitry may be used in place of or in combination with software instructions to perform one or more processes described herein. Thus, embodiments described herein are not limited to any specific combination of hardware circuitry and software.

[0100] The number and arrangement of components shown in FIG. 2 are provided as an example. In some non-limiting embodiments, device 200 may include additional components, fewer components, different components, or differently arranged components than those shown in FIG. 2. Additionally or alternatively, a set of components (e.g., one or more components) of device 200 may perform one or more functions described as being performed by another set of components of device 200.

[0101] Referring now to FIG. 3, FIG. 3 is a flowchart of a non-limiting embodiment of a process 300 for securely sharing sensitive information between devices. In some non-limiting embodiments or aspects, one or more steps of the process 300 may be performed (e.g., completely, partially, and / or the like) by at least one server (e.g., sensitive information server 104, optical code server 106, and / or authentication server 108). In some non-limiting embodiments or aspects, one or more steps of the process 300 may be performed (e.g., completely, partially, and / or the like) by another system, another device, another server, another network, another set of systems, another set of devices, another set of servers, or another set of networks, separate from or including the server(s) (e.g., sensitive information server 104, optical code server 106, and / or authentication server 108), such as first user device 102a, second user device 102b, and / or the like. The steps shown in FIG. 3 are for example purposes only. It will be appreciated that additional, fewer, different, and / or different order of steps may be used in non-limiting embodiments or aspects.

[0102] As shown in FIG. 3, at step 302, the process 300 may include receiving a request to communicate sensitive information. For example, a server (e.g., sensitive information server 104, optical code server 106, and / or authentication server 108) may receive a request to communicate the sensitive information from first user device 102a. For the purpose of illustration, first user device 102a may transmit a request to communicate the sensitive information to optical code server 106. Additionally oralternatively, first user device 102a may transmit a request to communicate the sensitive information to sensitive information server 104, which may transmit (e.g., forward) the request to optical code server 106.

[0103] In some non-limiting embodiments or aspects, the request to communicate the sensitive information may be generated by first user device 102a. For example, the request to communicate the sensitive information may be generated by a first application installed on first user device 102. For example, the first application may be associated with sensitive information server 104, optical code server 106, and / or authentication server 108 (and / or associated with the same system as one or more of these servers).

[0104] In some non-limiting embodiments or aspects, first user device 102a may store the sensitive information. For example, the first application installed on first user device 102a may be store the sensitive information. The first application may be configured to receive information from or communicate information to sensitive information server 104, optical code server 106, and / or authentication server 108. In some non-limiting embodiments or aspects, the user may access the sensitive information by logging into the first application installed on first user device 102a.

[0105] In some non-limiting embodiments or aspects, the server(s) (e.g., authentication server 108) may receive user login data via the first application of the first user device 102a. For example, the server(s) (e.g., authentication server 108) may receive the user login data via the first application of the first user device in response to the user inputting the user login data into the first application of first user device 102a. The user login data may include a unique code and / or password, biometric data, stored keys, any combination thereof, and / or the like.

[0106] In some non-limiting embodiments or aspects, in response to receiving the user login data, the server(s) (e.g., sensitive information server 104 and / or optical code server 106) may communicate the sensitive information to first user device 102a. For example, the sensitive information may include one or more payment credentials, primary account numbers, account identifiers, payment tokens, personal identifying information (e.g., a Social Security number or government-issued identification number), health information, and / or the like. In some non-limiting embodiments or aspects, the server(s) (e.g., sensitive information server 104 and / or optical code server 106) may communicate partial data associated with a portion of the sensitive information. For example, the portion of the sensitive information may include a portionof (e.g., certain digits and / or alphanumeric characters of) a payment credential, a primary account number, an account identifier, a payment token, personal identifier information, health information, and / or the like. The server(s) (e.g., sensitive information server 104 and / or optical code server 106) may retrieve the partial data associated with the portion of the sensitive information (e.g., before communicating the partial data to first user device 102). For example, optical code server 106 may retrieve the partial data associated with the portion of the sensitive information from the sensitive information server 104. The server(s) (e.g., sensitive information server 104 and / or optical code server 106) may communicate the partial data to first user device 102a.

[0107] In some non-limiting embodiments or aspects, the server(s) (e.g., sensitive information server 104 and / or optical code server 106) may communicate the partial data to first user device 102a to display the partial data on first user device 102a. In response to receiving the partial data, first user device 102a may display the partial data. For example, a portion of a primary account number, an account identifier, a payment token, a personal identifier information, health information, and / or the like may be displayed.

[0108] In some non-limiting embodiments or aspects, the server(s) (e.g., sensitive information server 104 and / or optical code server 106) may receive a communication from first user device 102a indicating selection of the partial data displayed on first user device 102a. For example, the communication indicating the selection of the partial data may be generated by first user device 102a. For example, the communication may be generated by first user device 102a in response to the user selecting the partial data displayed on first user device 102a.

[0109] As shown in FIG. 3, at step 304, the process 300 may include generating a machine-readable optical code. For example, a server (e.g., sensitive information server 104, optical code server 106, and / or authentication server 108) may generate the machine-readable optical code based on the sensitive information associated with the user. For the purpose of illustration, the machine-readable optical code may be generated by optical code server 106. The machine-readable optical code may be generated in response to receiving the communication indicating selection of the partial data from first user device 102a. The communication indicating the selection of the partial data may be communicated to the optical code server 106. Optical code server 106 may receive the communication indicating the selection of the partial datafrom first user device 102a. The machine-readable code may be generated in response to receiving the communication indicating the selection of the partial data.

[0110] In some non-limiting embodiments or aspects, the machine readable optical code may be based on the partial data selected by the user on first user device 102a. The machine readable-code may be associated with the user login data. The machine readable-code may comprise a quick response code (e.g., a QR code), an App Clip Code, a two-dimensional matrix barcode, a matrix barcode, a barcode, or any combination thereof.

[0111] As shown in FIG. 3, at step 306, the process 300 may include communicating the machine-readable optical code. For example, a server (e.g., sensitive information server 104, optical code server 106, and / or authentication server 108) may communicate the machine-readable optical code to first user device 102a. For the purpose of illustration, optical code server 106 may communicate the machine- readable optical code to first user device 102a. In response to receiving the machine- readable optical code, first user device 102a may display the machine-readable optical code.

[0112] In some non-limiting embodiments or aspects, the user may login on second user device 102b. Second user device 102b may have a second application installed. The second application may be associated with sensitive information server 104, optical code server 106, and / or authentication server 108. The second application may be associated with the first application installed on first user device 102a. The user may log in the second application on second user device 102b by inputting the user login data into the second application of second user device 102b. The user login data inputted in second user device 102b may be identical to the user login data inputted in first user device 102a.

[0113] In some non-limiting embodiments or aspects, the user may scan the machine-readable optical code displayed on first user device 102a. For example, the user may scan the machine-readable code displayed on first user device 102a with second user device 102b. The second application installed on second user device 102b may allow the user to scan the machine-readable code.

[0114] As shown in FIG. 3, at step 308, the process 300 may include receiving at least one message. For example, a server (e.g., sensitive information server 104, optical code server 106, and / or authentication server 108) may receive the at least one message from second user device 102b based on second user device 102bscanning the machine-readable optical code displayed on the first user device 102a. Authentication server 108 may receive the at least one message from second user device 102b based on second user device 102b scanning the machine-readable optical code displayed on first user device 102a.

[0115] In some non-limiting embodiments or aspects, in response to the user scanning the machine-readable optical code with second user device 102b, second user device 102b may send at least one message to communication network 1 10, which, then, may forward the at least one message to authentication server 108. Alternatively, second user device 102b may send the at least one message to authentication server 108 in response to the user scanning the machine-readable code. The at least one message may comprise an authentication message, a request for the sensitive information, and the scanned machine-readable optical code.

[0116] In some non-limiting embodiments or aspects, the request for the sensitive information may be a request for the partial data associated with the machine-readable optical code. A server, (e.g., sensitive information server 104, optical code server 106, and / or authentication server 108) may authenticate the user by matching the machine- readable optical code communicated to first user device 102a and the machine- readable optical code received from second user device 102b. For the purpose illustration, authentication server 108 may authenticate the user by matching the machine-readable optical code communicated to first user device 102a and the machine-readable optical code received from second user device 102b.

[0117] In some non-limiting embodiments or aspects, a server (e.g., sensitive information server 104, optical code server 106, and / or authentication server 108) may communicate an identification data to second user device 102b in response to authenticating the user. For the purpose of illustration, authentication server 108 may communicate the identification data to second user device 102b in response to authenticating the user. The identification data may indicate that the user is authenticated. The identification data may be based on the request for sensitive information. The request for sensitive information may be a request for the partial data. Second user device 102b may communicate the identification data to communication network 1 10, which, then, may communicate the identification data to sensitive information server 104, or sensitive information server 104.

[0118] As shown in FIG. 3, at step 310, the process 300 may include communicating data associated with the sensitive information. For example, a server(e.g., sensitive information server 104, optical code server 106, and / or authentication server 108) may communicate data associated with the sensitive information to the second user device 102b. For the purpose of illustration, sensitive information server 104 may communicate the data associated with the sensitive information to second user device 102b. The data associated with the sensitive information may be communicated in response to receiving the request for the sensitive information based on the identification data from second user device 102b. The data associated with the sensitive information may associated with the partial data selected by the user on first user device 102a.

[0119] Referring now to FIG. 4, FIG. 4 is a non-limiting embodiment or aspects of an example implementation 400 of a method or process for securely sharing sensitive information between devices. In some non-limiting embodiments or aspects, implementation 400 may be performed by first user device 102a, second user device 102b, sensitive information server 104, authentication server 108, optical code server 106, and / or the like. The steps shown in FIG. 4 are for example purposes only. It will be appreciated that additional, fewer, different, and / or different order of steps may be used in non-limiting embodiments or aspects.

[0120] As shown in FIG. 4, at step 401 , first user device 102a may communicate user login data to the authentication server 108. The user may input the user login data into the first application installed on first user device 102a in order to log into the first application.

[0121] As shown in FIG. 4, at step 402, the authentication server 108 may authenticate the user. For example, authentication server 108 may authenticate the user by authenticating the user login data associated with the user. In response to authentication server 108 authenticating the user login data, authentication server 108 may transmit a message to the first user device 102a that allows the user to log into the first application.

[0122] As shown in FIG. 4, at step 403, the sensitive information server 104 may communicate sensitive information and / or partial data associated with a portion of the sensitive information to the first user device 102a. For example, first user device 102a may retrieve (e.g., communicate a request for) the sensitive information from the sensitive information server 104 (e.g., which may communicate the sensitive information to first user device 102a based on receiving the request). Additionally oralternatively, first user device 102a may have the sensitive information and / or partial data stored thereon.

[0123] As shown in FIG. 4, at step 404, the first user device 102a may communicate a request to communicate the sensitive information to the sensitive information server 104 and / or optical code server 106. For example, if first user device 102a communicated the request to sensitive information server 104, then, at step 405, sensitive information server 104 may communicate (e.g., forward) the request to communicate sensitive information to optical code server 106 (e.g., in response to receiving the request from first user device 102a). Alternatively, first user device 102a may communicate the request to communicate sensitive information to the optical code server 106. The request to communicate sensitive information may be based on the user’s selection of the partial data associated with the sensitive information, as described herein.

[0124] As shown in FIG. 4, at step 406, optical code server 106 may communicate a machine-readable optical code to first user device 102a. For example, optical code server 106 may generate the machine-readable optical code in response to receiving the request to communicate the sensitive information. In response to receiving the machine-readable optical code, first user device 102a may display the machine- readable optical code.

[0125] As shown in FIG. 4, at step 407, second user device 102b may communicate user login data to the authentication server 108. For example, the user may input the user login data into a second application installed on second user device 102b. For example, the user login data inputted into second user device 102b may be identical to the user login data inputted into first user device 102a.

[0126] As shown in FIG. 4, at step 408, authentication server 108 may authenticate the login data. For example, authentication server 108 may authenticate the user in response to receiving the user login data. After authenticating the user, authentication server 108 may transmit a message to second user device 102b that allows the user to log into the second application. After logging into second user device 102b, the user may scan the machine-readable optical code displayed on first user device 102a with second user device 102b.

[0127] As shown in FIG. 4, at step 409, second user device 102b may communicate at least one message to authentication server 108. For example, the message(s) begenerated by second user device 102 based on scanning the machine-readable optical code displayed on first user device 102a, as described herein.

[0128] As shown in FIG. 4, at step 410, authentication server 108 may communicate identification data to second user device 102b in response to authenticating the at least one message.

[0129] As shown in FIG. 4, at step 411 , second user device 102b may communicate the identification data to the sensitive information server 104.

[0130] As shown in FIG. 4, at step 412, sensitive information server 104 may communicate the sensitive information to second user device 102b in response to receiving the identification data.

[0131] Referring now to FIG. 5, FIG. 5 is a diagram of a non-limiting embodiment or aspect of an environment 500 in which systems, products, and / or methods, as described herein, may be implemented. As shown in FIG. 5, environment 500 includes transaction service provider system 502, issuer system 504, customer device 506, merchant system 508, acquirer system 510, and communication network 512. In some non-limiting embodiments or aspects, at least one of (e.g., all of) sensitive information server 104, optical server 106, and / or authentication server 108 of FIG. 1 may be implemented by (e.g., part of) transaction service provider system 502, issuer system 504, and / or merchant system 508. In some non-limiting embodiments or aspects, at least one of (e.g., both of) first user device 102a and second user device 102b may be the same as or similar to customer device 506.

[0132] Transaction service provider system 502 may include one or more devices capable of receiving information from and / or communicating information to issuer system 504, customer device 506, merchant system 508, and / or acquirer system 510 via communication network 512. For example, transaction service provider system 502 may include a computing device, such as a server (e.g., a transaction processing server), a group of servers, and / or other like devices. In some non-limiting embodiments or aspects, transaction service provider system 502 may be associated with a transaction service provider as described herein. In some non-limiting embodiments or aspects, transaction service provider system 502 may be in communication with a data storage device, which may be local or remote to transaction service provider system 502. In some non-limiting embodiments or aspects, transaction service provider system 502 may be capable of receiving information from,storing information in, communicating information to, or searching information stored in the data storage device.

[0133] Issuer system 504 may include one or more devices capable of receiving information and / or communicating information to transaction service provider system 502, customer device 506, merchant system 508, and / or acquirer system 510 via communication network 512. For example, issuer system 504 may include a computing device, such as a server, a group of servers, and / or other like devices. In some non-limiting embodiments or aspects, issuer system 504 may be associated with an issuer institution as described herein. For example, issuer system 504 may be associated with an issuer institution that issued a credit account, debit account, credit card, debit card, and / or the like to a user associated with customer device 106.

[0134] Customer device 506 may include one or more devices capable of receiving information from and / or communicating information to transaction service provider system 502, issuer system 504, merchant system 508, and / or acquirer system 510 via communication network 512. Additionally or alternatively, each customer device 506 may include a device capable of receiving information from and / or communicating information to other customer devices 506 via communication network 512, another network (e.g., an ad hoc network, a local network, a private network, a virtual private network, and / or the like), and / or any other suitable communication technique. For example, customer device 506 may include a client device and / or the like. In some non-limiting embodiments or aspects, customer device 506 may or may not be capable of receiving information (e.g., from merchant system 508 or from another customer device 506) via a short-range wireless communication connection (e.g., an NFC communication connection, an RFID communication connection, a Bluetooth® communication connection, a Zigbee® communication connection, and / or the like), and / or communicating information (e.g., to merchant system 508) via a short-range wireless communication connection.

[0135] Merchant system 508 may include one or more devices capable of receiving information from and / or communicating information to transaction service provider system 502, issuer system 504, customer device 506, and / or acquirer system 510 via communication network 512. Merchant system 508 may also include a device capable of receiving information from customer device 506 via communication network 512, a communication connection (e.g., an NFC communication connection, an RFID communication connection, a Bluetooth® communication connection, a Zigbee®communication connection, and / or the like) with customer device 506, and / or the like, and / or communicating information to customer device 506 via the network, the communication connection, and / or the like. In some non-limiting embodiments or aspects, merchant system 508 may include a computing device, such as a server, a group of servers, a client device, a group of client devices, and / or other like devices. In some non-limiting embodiments or aspects, merchant system 508 may be associated with a merchant as described herein. In some non-limiting embodiments or aspects, merchant system 508 may include one or more client devices. For example, merchant system 508 may include a client device that allows a merchant to communicate information to transaction service provider system 502. In some nonlimiting embodiments or aspects, merchant system 508 may include one or more devices, such as computers, computer systems, and / or peripheral devices capable of being used by a merchant to conduct a transaction with a user. For example, merchant system 508 may include a POS device and / or a POS system.

[0136] Acquirer system 510 may include one or more devices capable of receiving information from and / or communicating information to transaction service provider system 502, issuer system 504, customer device 506, and / or merchant system 508 via communication network 512. For example, acquirer system 510 may include a computing device, a server, a group of servers, and / or the like. In some non-limiting embodiments or aspects, acquirer system 510 may be associated with an acquirer as described herein.

[0137] Communication network 512 may include one or more wired and / or wireless networks. For example, network 512 may include a cellular network (e.g., a long-term evolution (LTE) network, a third generation (3G) network, a fourth generation (4G) network, a code division multiple access (CDMA) network, and / or the like), a public land mobile network (PLMN), a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a telephone network (e.g., the public switched telephone network (PSTN)), a private network (e.g., a private network associated with a transaction service provider), an ad hoc network, an intranet, the Internet, a fiber optic-based network, a cloud computing network, and / or the like, and / or a combination of these or other types of networks.

[0138] The number and arrangement of systems, devices, and / or networks shown in FIG. 5 are provided as an example. There may be additional systems, devices, and / or networks; fewer systems, devices, and / or networks; different systems, devices,and / or networks; and / or differently arranged systems, devices, and / or networks than those shown in FIG. 5. Furthermore, two or more systems or devices shown in FIG. 5 may be implemented within a single system or device, or a single system or device shown in FIG. 5 may be implemented as multiple, distributed systems or devices. Additionally or alternatively, a set of systems (e.g., one or more systems) or a set of devices (e.g., one or more devices) of environment 500 may perform one or more functions described as being performed by another set of systems or another set of devices of environment 500.

[0139] Although the disclosed subject matter has been described in detail for the purpose of illustration based on what is currently considered to be the most practical and preferred embodiments or aspects, it is to be understood that such detail is solely for that purpose and that the disclosed subject matter is not limited to the disclosed embodiments or aspects, but, on the contrary, is intended to cover modifications and equivalent arrangements that are within the spirit and scope of the appended claims. For example, it is to be understood that the presently disclosed subject matter contemplates that, to the extent possible, one or more features of any embodiment can be combined with one or more features of any other embodiment.

Claims

THE INVENTION CLAIMED IS1 . A computer-implemented method, comprising: receiving, with at least one processor, a request to communicate sensitive information associated with a user from a first user device; generating, with at least one processor, a machine-readable optical code based on the sensitive information associated with the user; communicating, with at least one processor, the machine-readable optical code to the first user device to display the machine-readable optical code; receiving, with at least one processor, at least one message from a second user device based on the second user device scanning the machine-readable optical code displayed on the first user device; and communicating, with at least one processor, data associated with the sensitive information to the second user device.

2. The computer-implemented method of claim 1 , further comprising: retrieving, with at least one processor, partial data associated with a portion of the sensitive information; and communicating, with at least one processor, the partial data to the first user device to display the partial data.

3. The computer-implemented method of claim 2, wherein receiving the request to communicate the sensitive information comprises: receiving a communication from the first user device indicating selection of the partial data displayed by the user device.

4. The computer-implemented method of claim 2, wherein the machine-readable optical code is based on the partial data.

5. The computer-implemented method of claim 1 , wherein the machine-readable optical code comprises at least one of a quick response code (e.g., a QR code), an App Clip Code, a two-dimensional matrix barcode, a matrix barcode, a barcode, or any combination thereof.

6. The computer-implemented method of claim 1 , wherein the second user device comprises an augmented-reality device.

7. The computer-implemented method of claim 1 , further comprising: receiving, with at least one processor, user login data via a first application of the first user device; and receiving, with at least one processor, the user login data via a second application of the second user device.

8. The computer-implemented method of claim 7, wherein the second application is associated with the first application.

9. The computer-implemented method of claim 7, wherein the machine-readable optical code is associated with the user login data, the computer- implemented method further comprising: authenticating, with at least one processor, the second user device in response to matching the machine-readable optical code and the user login data received from the second user device.

10. The computer-implemented method of claim 7, wherein user login data comprises a unique code, a password, biometric data, stored keys, or any combination thereof.1 1 . The computer-implemented method of claim 1 , wherein the at least one message comprises an authentication message, the computer-implemented method further comprising communicating, with at least one processor, identification data to the second user device in response to receiving the authentication message, wherein the at least one message further comprises a request for the sensitive information based on the identification data, and wherein communicating the data associated with the sensitive information comprises communicating the data associated with the sensitiveinformation to the second user device in response to receiving the request for the sensitive information based on the identification data from the second user device.

12. A system comprising: at least one processor; and at least one non-transitory computer-readable medium including one or more instructions that, when executed by the at least one processor, direct the at least one processor to: receive a request to communicate sensitive information associated with a user from a first user device; generate a machine-readable optical code based on the sensitive information associated with the user; communicate the machine-readable optical code to the first user device to display the machine-readable optical code; receive at least one message from a second user device based on the second user device scanning the machine-readable optical code displayed on the first user device; and communicate data associated with the sensitive information to the second user device.

13. The system of claim 12, wherein the one or more instructions, when executed by the at least one processor, further direct the at least one processor to: retrieve partial data associated with a portion of the sensitive information; and communicate the partial data to the first user device to display the partial data.

14. The system of claim 13, wherein receiving the request to communicate the sensitive information comprises: receiving a communication from the first user device indicating selection of the partial data displayed by the user device.

15. The system of claim 13, wherein the machine-readable optical code is based on the partial data.

16. The system of claim 12, wherein the machine-readable optical code comprises at least one of a quick response code (e.g., a QR code), an App Clip Code, a two-dimensional matrix barcode, a matrix barcode, a barcode, or any combination thereof.

17. The system of claim 12, wherein the second user device comprises an augmented-reality device.

18. The system of claim 12, wherein the one or more instructions, when executed by the at least one processor, further direct the at least one processor to: receive user login data via a first application of the first user device; and receive the user login data via a second application of the second user device.

19. The system of claim 18, wherein the second application is associated with the first application.

20. The system of claim 18, wherein the machine-readable optical code is associated with the user login data, and wherein the one or more instructions, when executed by the at least one processor, further direct the at least one processor to: authenticate the second user device in response to matching the machine-readable optical code and the user login data received from the second user device.

21. The system of claim 18, wherein user login data comprises a unique code, a password, biometric data, stored keys, or any combination thereof.

22. The system of claim 12, wherein the at least one message comprises an authentication message, and wherein the one or more instructions,when executed by the at least one processor, further direct the at least one processor to communicate identification data to the second user device in response to receiving the authentication message, wherein the at least one message further comprises a request for the sensitive information based on the identification data, and wherein communicating the data associated with the sensitive information comprises communicating the data associated with the sensitive information to the second user device in response to receiving the request for the sensitive information based on the identification data from the second user device.

23. A computer program product comprising at least one non- transitory computer-readable medium including one or more instructions that, when executed by at least one processor, cause the at least one processor to: receive a request to communicate sensitive information associated with a user from a first user device; generate a machine-readable optical code based on the sensitive information associated with the user; communicate the machine-readable optical code to the first user device to display the machine-readable optical code; receive at least one message from a second user device based on the second user device scanning the machine-readable optical code displayed on the first user device; and communicate data associated with the sensitive information to the second user device.

24. The computer program product of claim 23, wherein the one or more instructions, when executed by the at least one processor, further case the at least one processor to: retrieve partial data associated with a portion of the sensitive information; and communicate the partial data to the first user device to display the partial data.

25. The computer program product of claim 23, wherein receiving the request to communicate the sensitive information comprises: receiving a communication from the first user device indicating selection of the partial data displayed by the user device.

26. The computer program product of claim 23, wherein the machine- readable optical code is based on the partial data.

27. The computer program product of claim 23, wherein the machine- readable optical code comprises at least one of a quick response code (e.g., a QR code), an App Clip Code, a two-dimensional matrix barcode, a matrix barcode, a barcode, or any combination thereof.

28. The computer program product of claim 23, wherein the second user device comprises an augmented-reality device.

29. The computer program product of claim 23, wherein the one or more instructions, when executed by the at least one processor, further case the at least one processor to: receive user login data via a first application of the first user device; and receive the user login data via a second application of the second user device.

30. The computer program product of claim 29, wherein the second application is associated with the first application.31 . The computer program product of claim 29, wherein the machine- readable optical code is associated with the user login data, and wherein the one or more instructions, when executed by the at least one processor, further case the at least one processor to: authenticate the second user device in response to matching the machine-readable optical code and the user login data received from the second user device.

32. The computer program product of claim 29, wherein user login data comprises a unique code, a password, biometric data, stored keys, or any combination thereof.

33. The computer program product of claim 23, wherein the at least one message comprises an authentication message, and wherein the one or more instructions, when executed by the at least one processor, further cause the at least one processor to communicate identification data to the second user device in response to receiving the authentication message, wherein the at least one message further comprises a request for the sensitive information based on the identification data, and wherein communicating the data associated with the sensitive information comprises communicating the data associated with the sensitive information to the second user device in response to receiving the request for the sensitive information based on the identification data from the second user device.

Citation Information

Patent Citations

  • Secure and anonymized digital transactions

    US11531952B1

  • Method and system for providing a secure communication channel to portable privatized data

    US20160080364A1

  • Address exchange systems and methods

    US20230145741A1