Application selection after device interaction
By allowing user devices to select applications based on transaction-specific criteria, the access device optimizes application usage, addressing the limitations of existing systems in selecting optimal applications for varying transaction scenarios.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-10-02
- Publication Date
- 2026-04-09
AI Technical Summary
Existing systems provide limited control over which application is utilized during access transactions, failing to account for varying circumstances such as location and resource provider, leading to suboptimal application selection.
An access device receives multiple application identifiers and credentials from a user device, prompting the user to select an application, and processes the transaction using the corresponding credential, allowing user control over application selection.
Enables user-controlled application selection based on specific transaction circumstances, optimizing the choice of application for enhanced transaction efficiency and security.
Smart Images

Figure US2025049275_09042026_PF_FP_ABST
Abstract
Description
PATENTAttorney Docket No.: 079900-1518522Client Ref. No.: 9729WO01APPLICATION SELECTION AFTER DEVICE INTERACTIONCROSS-REFERENCES TO RELATED APPLICATIONS
[0001] This application claims priority to and the benefit of the filing date of U.S. Provisional Application No. 63 / 702,842, filed on October 3, 2024, which is herein incorporated by reference in its entirety.BACKGROUND
[0002] During an interaction between a user device and an access device, a user device provides access data to the access device in order to conduct an access transaction. The user device may have multiple applications that include different sets of access data or that provide the access data in different formats. Typically, the user device provides a list of available applications, and the access device selects which application to use for a given access transaction.
[0003] However, different access transactions may involve different circumstances such as location and resource provider. Variations in circumstances across access transactions can affect which application is optimal or preferred from the user’s perspective, as different applications may provide data in a format that is configured for a certain network, different applications may have different authentication and verification processes, etc. Interaction communications and processing provide the user device little to no control over which application is utilized across different access transaction scenarios.
[0004] Embodiments of the invention address these and other problems, individually and collectively.1KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01SUMMARY
[0005] One embodiment includes a method comprising: receiving, by an access device from a user device for a transaction, a plurality of application identifiers corresponding to a plurality of applications; obtaining, by the access device from the user device in a single interaction with the user device, a plurality of credentials including, for each of the plurality of applications, a corresponding credential; prompting, by the access device, a user of the user device to select one of the plurality of applications; receiving, by the access device from the user, a selection of an application from the plurality of applications; and processing, by the access device, the transaction using a credential that corresponds to the selected application, the credential being one of the plurality of credentials.
[0006] Another embodiment of the invention includes an access device comprising: a processor; and a computer readable medium, the computer readable medium comprising code, executable by the processor, for performing the operations comprising: receiving, from a user device for a transaction, a plurality of application identifiers corresponding to a plurality of applications; obtaining, from the user device, a plurality of credentials including, for each of the plurality of applications, a corresponding credential; prompting a user of the user device to select one of the plurality of applications; receiving, from the user, a selection of an application from the plurality of applications; and processing the transaction using a credential that corresponds to the selected application, the credential being one of the plurality of credentials.
[0007] Another embodiment of the invention includes a method comprising: transmitting, by a user device to an access device for a transaction, a plurality of application identifiers corresponding to a plurality of applications; receiving, by the user device from the access device, one or more requests for a plurality of credentials including, for each of the plurality of applications, a corresponding credential; and transmitting, by the user device to the access device, the plurality of credentials including, for each of the plurality of applications, the corresponding credential, thereby causing the2KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 access device to prompt a user of the user device to select one of the plurality of applications, receive from the user a selection of an application from the plurality of applications, and process the transaction using a credential from the plurality of credentials that corresponds to the selected application.
[0008] These and other embodiments are described in further detail below.BRIEF DESCRIPTION OF THE DRAWINGS
[0009] FIG. 1 shows a system for processing a transaction, according to embodiments.
[0010] FIG. 2 shows a flow diagram of interaction processing between an access device and a user device, according to embodiments.
[0011] FIG. 3 shows a flow diagram of an exemplary method for processing a transaction based on a user-selected credential, according to embodiments.
[0012] FIG. 4A illustrates an example of a user device being presented for interacting with the access device, according to embodiments.
[0013] FIG. 4B shows an exemplary user interface displaying a list of selectable options, according to embodiments.
[0014] FIG. 4C illustrates an exemplary user interface of an access device during processing of a transaction, according to embodiments.
[0015] FIG. 5 illustrates a block diagram of an access device, according to embodiments.
[0016] FIG. 6 is a block diagram illustrating an example of a user device, according to embodiments.DESCRIPTION
[0017] Prior to discussing embodiments of the disclosure, some terms can be described in further detail.3KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01
[0018] A “user” may include an individual. In some embodiments, a user may be associated with one or more personal accounts and / or user devices. The user may also be referred to as a cardholder, account holder, or consumer in some embodiments.
[0019] A “user device” may be a device that is operated by a user. Examples of user devices may include a mobile phone, a smart phone, a card, a personal digital assistant (PDA), a laptop computer, a desktop computer, a server computer, a vehicle such as an automobile, a thin-client device, a tablet PC, etc. Additionally, user devices may be any type of wearable technology device, such as a watch, ring, bracelet, earpiece, glasses, etc. The user device may include one or more processors capable of processing user input. The user device may also include one or more input sensors for receiving user input. As is known in the art, there are a variety of input sensors capable of detecting user input, such as accelerometers, cameras, microphones, etc. The user input obtained by the input sensors may be from a variety of data input types, including, but not limited to, audio data, visual data, or biometric data. The user device may comprise any electronic device that may be operated by a user, which may also provide remote communication capabilities to a network. Examples of remote communication capabilities include using a mobile phone (wireless) network, wireless data network (e.g., 3G, 4G or similar networks), Wi-Fi, Wi-Max, or any other communication medium that may provide access to a network such as the Internet or a private network.
[0020] An “interaction” may include a reciprocal action or influence. An interaction can include a communication, contact, or exchange between parties, devices, and / or entities. Example interactions include a transaction between two parties and a data exchange between two devices. In some embodiments, an interaction can include a user requesting access to secure data, a secure webpage, a secure location, and the like. In other embodiments, an interaction can include a payment transaction in which two devices can interact to facilitate a payment.4KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01
[0021] “Transaction data” can include data related to and / or recorded during a transaction. In some embodiments, transaction data can include network data. Transaction data can comprise a plurality of data elements with data values.
[0022] An "application" may include any software module configured to perform a specific function or functions when executed by a processor of a computer. For example, a "payment application" may include any software, code, application, or any other module that is configured to store and provide payment information for a transaction when executed by a processor. For instance, a payment application may store sensitive payment information (e.g., account identifier, expiration date, card verification value (CW), etc.) on a secure memory or trusted execution environment (e.g., secure element). The sensitive payment information may be accessed by requesting the payment information from the payment application using an application identifier (“AID”) or other address information for accessing the correct payment application. Any number of communication protocols may be used to access the payment information from the payment application and use the received payment information in a payment transaction.
[0023] A “credential” may be any suitable information that serves as reliable evidence of worth, ownership, identity, or authority. A credential may be a string of numbers, letters, or any other suitable characters, as well as any object or document that can serve as confirmation. Examples of credentials include value credentials, payment credentials, identification cards, certified documents, access cards, passcodes, and other login information, etc.
[0024] "Payment credentials" or “payment information” may include any data that may be used to identify an account and / or use the account for a payment transaction. For example, payment credentials may a primary account identifier (PAN), expiration date, card verification value (CW), device authentication information (e.g., transaction cryptogram), dynamic authentication information (e.g., a dynamic cryptogram), etc.), personal information associated with a user or a consumer (e.g., name, billing address, residential address, date of birth, etc.), account information (e.g., issuer identifier (BIN),5KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 account issuance date, etc.), cardholder verification information (e.g., passcode, password, personal identification number (PIN), etc.), an indication of an authentication process for transaction processing (e.g., online PIN, signature, etc.) which may also be referred to as a cardholder verification method (CVM), and / or any other suitable or relevant information for performing a transaction.
[0025] An "application identifier" (AID) may include any information that may identify an application installed on a device. An AID can be in the form of a set of alphanumeric or numeric characters. In some embodiments, an AID may identify a payment application, and the AID can be associated with a set of features and / or services relating to how a transaction conducted using the corresponding payment application is processed. Furthermore, in some embodiments, the AID may be associated with account information provisioned into the payment application corresponding to the AID. An AID may also be associated with a particular processing scheme such as a domestic scheme or a non-domestic scheme. In some cases, an AID can also be associated with a processing network, such as a particular payment processing network (e.g., VisaNet™).
[0026] For instance, an AID may indicate to an access device which payment processing network (e.g., VisaNet™) should be used to process a transaction conducted with the payment application corresponding to the AID; a type of account or financial credentials associated with the payment application (e.g., debit, credit, loyalty, etc.); account-related information (e.g., platinum level account, gold level account, etc.); an account issuer (e.g., Bank A); and / or any other information about a payment application or underlying account data associated with the payment application.
[0027] In some embodiments, the AID may have a standardized format to include information about an application provider (e.g., payment network A, merchant B, etc.) and an application type (e.g., account or product type, account issuer, etc.) associated with each payment application. For example, a first portion of an AID may identify an application provider associated with card data provisioned on a device and a second portion may identify an account type associated with the application provider. For6KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 instance, the AID (e.g., A000000031010) can have a first portion (e.g., A00000003) that identifies an application provider (e.g., payment network A) and a second portion (e.g., 1010) that identifies a type of account provisioned into the identified payment application (e.g., debit or credit account). Further, in some embodiments, the second portion (or a third portion) could also identify an issuer associated with the provisioned account and / or payment application (e.g., Issuer B). Thus, the AID may be used by the access device to determine if the access device can support processing a transaction initiated using the payment application.
[0028] A "network-generic application identifier" or "multiple-network application identifier" may be an application identifier that is associated with a payment application with provisioned payment information that may be routed and / or processed using a variety of different payment networks. For example, in some embodiments, a networkgeneric AID may correspond to a payment application that includes payment information that may be used by two or more proprietary networks to process a transaction initiated by a payment application identified by the AID. The network-generic AID may identify an application storing network-generic payment information such that the payment credentials and / or account credentials may be recognized and / or processed by multiple payment networks. For instance, a "common debit account identifier" may identify a payment application including provisioned financial account information associated with a consumer's debit account. The common debit account identifier may indicate that the payment information stored in the payment application identified by the common debit account identifier may be processed by multiple debit account processing networks.
[0029] In some embodiments, when a consumer provisions a debit account to their payment device, two different payment applications may be installed with payment information associated with the debit account. A first payment application may be identified through a common debit application identifier (AID). The common debit AID may correspond to a payment application that stores payment information that is configured to be processed over multiple payment processors. A second payment application may be identified through a network-specific application identifier (e.g., a VisaNet™ specific7KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01AID). Payment processing networks are configured to process particular data formats and identify particular information. Thus, information provided by one network may not be understood by a second network. Accordingly, although both payment applications are associated with the same debit card, the payment information stored by each payment application may be different to allow for the network-generic application (corresponding to the network-generic AID) to be processed through multiple payment networks and the network-specific application (corresponding to the network-specific AID) to be processed by a particular payment network. Thus, the network-generic payment information may include a different format than any of the network-specific payment information. Instead, the payment information may include a format that a group of the payment processing networks have agreed upon, so that they can all process the payment information.
[0030] A "network-specific application identifier" may be an AID that is associated with a payment application with payment information that may be routed and / or processed using only a specific payment network. For example, a payment application that is configured to process payments through only one of, for example, VisaNet™, MasterCard™, or American Express™ payment networks may be identified using a network-specific AID. The network-specific AID may identify a payment application storing network-specific payment information such that the payment credentials and / or account credentials may only be recognized by a specific or particular payment network.
[0031] A "transaction payload" may include any transaction and / or payment information that may be used to process a transaction. For example, the transaction payload may include payment credentials and / or account information for identifying an account (e.g., account identifier (e.g., PAN), token, expiration date, etc.) and / or for validating the authenticity of a transaction initiated by a user device (e.g., card verification values (CW), cardholder verification results (CVR), validation data, etc.).
[0032] "Preparing a transaction payload" may include any process or action to prepare a transaction for processing. For example, preparing a transaction payload may include multiple steps including multiple communication requests and responses being8KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 sent between a user device and an access device to obtain payment credentials associated with a selected payment application. The received payment credentials and other payment information associated with the payment application may then be used in a transaction.
[0033] An “access device” may be any suitable device that provides access to a remote system. An access device may also be used for communicating with a coordination computer, a communication network, or any other suitable system. An access device may generally be located in any suitable location, such as at the location of a merchant. An access device may be in any suitable form. Some examples of access devices include POS or point of sale devices (e.g., POS terminals), cellular phones, personal digital assistants (PDAs), personal computers (PCs), tablet PCs, hand-held specialized readers, set-top boxes, electronic cash registers (ECRs), vending machines, automated teller machines (ATMs), virtual cash registers (VCRs), kiosks, security systems, access systems, and the like.
[0034] An access device may use any suitable contact or contactless mode of operation to send or receive data from, or associated with, a mobile communication or payment device. For example, access devices can have card readers that can include electrical contacts, radio frequency (RF) antennas, optical scanners, bar code readers, or magnetic stripe readers to interact with portable devices such as payment cards.
[0035] A “processor” may include a device that processes something. In some embodiments, a processor can include any suitable data computation device or devices. A processor may comprise one or more microprocessors working together to accomplish a desired function. The processor may include a CPU comprising at least one high-speed data processor adequate to execute program components for executing user and / or system-generated requests. The CPU may be a microprocessor such as AMD's Athlon, Duron, and / or Opteron; IBM and / or Motorola's PowerPC; IBM's and Sony's Cell processor; Intel's Celeron, Itanium, Pentium, Xeon, and / or XScale; and / or the like processor(s).9KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01
[0036] A “memory” may be any suitable device or devices that can store electronic data. A suitable memory may comprise a non-transitory computer readable medium that stores instructions that can be executed by a processor to implement a desired method. Examples of memories may comprise one or more memory chips, disk drives, etc. Such memories may operate using any suitable electrical, optical, and / or magnetic mode of operation.
[0037] A “server computer” may include a powerful computer or cluster of computers. For example, the server computer can be a large mainframe, a minicomputer cluster, or a group of servers functioning as a unit. In one example, the server computer may be a database server coupled to a Web server. The server computer may comprise one or more computational apparatuses and may use any of a variety of computing structures, arrangements, and compilations for servicing the requests from one or more client computers.
[0038] An “authorization request message” may be an electronic message that requests authorization for an interaction. In some embodiments, it is sent to a transaction processing computer and / or an issuer of a payment card to request authorization for a transaction. An authorization request message according to some embodiments may comply with International Organization for Standardization (ISO) 8583, which is a standard for systems that exchange electronic transaction information associated with a payment made by a user using a payment device or payment account. The authorization request message may include an issuer account identifier that may be associated with a payment device or payment account. An authorization request message may also comprise additional data elements corresponding to “identification information” including, by way of example only: a service code, a CVV (card verification value), a dCW (dynamic card verification value), a PAN (primary account number or “account number”), a payment token, a username, an expiration date, etc. An authorization request message may also comprise “transaction information,” such as any information associated with a current transaction, such as the transaction value, merchant identifier, merchant location, acquirer bank identification number (BIN), card acceptor ID, information identifying items10KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 being purchased, etc., as well as any other information that may be utilized in determining whether to identify and / or authorize a transaction.
[0039] An “authorization response message” may be a message that responds to an authorization request. In some cases, it may be an electronic message reply to an authorization request message generated by an issuing financial institution or a transaction processing computer. The authorization response message may include, by way of example only, one or more of the following status indicators: Approval -- transaction was approved; Decline -- transaction was not approved; or Call Center -- response pending more information, merchant must call the toll-free authorization phone number. The authorization response message may also include an authorization code, which may be a code that a credit card issuing bank returns in response to an authorization request message in an electronic message (either directly or through the transaction processing computer) to the merchant's access device (e.g., PCS equipment) that indicates approval of the transaction. The code may serve as proof of authorization.
[0040] Embodiments of the invention provide methods for conducting an interaction between a user device and an access device to initiate a transaction based on a user-selected application. The user can present their user device to an access device, and the user device can interact with the access device to transmit a set of application identifiers and corresponding credentials to the access device. The access device can prompt the user to select an application via a user interface of the access device for use in the transaction. The access device can then process the transaction based on the selected application.
[0041] FIG. 1 shows a system diagram, according to embodiments. The system includes a user device 102 comprising a first application 120A and a second application 102B. The user device 102 can be under the control of a user.
[0042] In some embodiments, the first application 102A can be a first payment application, and the second application 102B can be a second payment application. For11KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 example, the first application 102A can be a network-generic application, and the second application 102B can be a network-specific application.
[0043] The access device 105 can interact with the user device 102. The access device 105 and the user device 102 can interact via a short range communication medium such as NFC (near field communication), Bluetooth™, or the like.
[0044] The access device 105 may be in communication with a resource provider computer 108, a transport computer 110, a processing network computer 112, and an authorizing entity computer 114. The resource provider computer 108 may operate a resource provider site (e.g., a merchant Website), and may provide data to and receive data from the transport computer 110. In some embodiments, the transport computer 110 can manage an account of the resource provider, and can be an acquirer computer. The processing network computer 112 may route transaction messages between various transport computers and authorizing entity computers. In some embodiments, the processing network computer may be in a payment processing network. The authorizing entity computer 114 may be an issuer computer which holds an account associated with a credential or a token on the portable device 103.
[0045] For simplicity of illustration, a certain number of components are shown in FIG. 1. It is understood, however, that embodiments of the invention may include more than one of each component. In addition, some embodiments of the invention may include fewer than or greater than all of the components shown in FIG. 1.
[0046] Messages between at least the devices illustrated in FIG. 1 can be transmitted using a secure communications protocol such as, but not limited to, File Transfer Protocol (FTP); HyperText Transfer Protocol (HTTP); Secure Hypertext Transfer Protocol (HTTPS), SSL, ISO (e.g., ISO 8583) and / or the like. The communications network may include any one and / or the combination of the following: a direct interconnection; the Internet; a Local Area Network (LAN); a Metropolitan Area Network (MAN); an Operating Missions as Nodes on the Internet (OMNI); a secured custom connection; a Wide Area Network (WAN); a wireless network (e.g., employing protocols12KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 such as, but not limited to a Wireless Application Protocol (WAP), l-mode, and / or the like); and / or the like. The communications network can use any suitable communications protocol to generate one or more secure communication channels. A communications channel may, in some instances, comprise a secure communication channel, which may be established in any known manner, such as through the use of mutual authentication and a session key, and establishment of a Secure Socket Layer (SSL) session.
[0047] FIG. 2 shows a flow diagram of interaction processing between an access device and a user device according to embodiments.
[0048] While multiple messages between the user device and access device are described below, they can all be considered parts of a single interaction. A single interaction can include a single presentation by a user of the user device to the access device, and / or a single predefined set of messages between the user device and the access device.
[0049] The user of the user device 102 may wish to access a resource (e.g., secure data, a secure location, a good or service, etc.) from a resource provider associated with the access device 105. The user may present a user device 102 for interacting with the access device 105.
[0050] At step 201 , a contactless reader of the access device 105 may be configured to identify the presence of a user device 102 within communication range. For example, a contactless interface of the user device 102 may ping or otherwise attempt to find suitable devices to communicate with periodically. When the access device 105 detects the presence of user device 102 in proximity to a contactless reader of the access device 105, for example, an application selection module of the access device 105 may initiate an interaction by sending a request for available account applications to the user device 102. The request for available applications is sent in order to obtain information regarding which mobile applications and corresponding account applications (e.g., a list of account application identifiers) may be available on the user device 102. In some embodiments, the request for available applications 201 may be in the form of a “select13KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 proximity payment system environment (PPSE)” command. In such embodiments, the request for available applications 201 may include a payment environment identifier (e.g., a PPSE name such as “2PAY.SYS.DDF01”) to identify the payment environment supported by the access device 105.
[0051] At step 202, upon receiving the available applications request 201 , the user device 102 may identify and process the request by recognizing the payment environment identifier (e.g., PPSE name) included in the request, and respond by sending an available applications response 202 back to access device 105. For example, the available applications response 202 may include a list of available account application identifiers (AIDs), a wallet identifier associated with a mobile application, application configuration options associated with the available AIDs, and / or may include the proximity payment environment identifier (e.g., PPSE name) as the dedicated file name.
[0052] In some embodiments, the available applications response 202 may be in the form of a “select PPSE” response and may include PPSE file control information (FCI). For example, the available applications response 202 may include a directory entry for each available AID on the user device 102 with a wallet identifier associated with each available AID. Each directory entry may include information such as the AID, an application label associated with the AID (e.g., a mnemonic associated with the AID), a wallet identifier (WID) associated with the mobile application, an application priority indicator indicating the priority of the AID, a kernel identifier indicating the application's kernel preference, and / or additional information relating to the particular AID. The available applications response 202 may also include other data such as FCI issuer discretionary data or any other relevant information.
[0053] At step 203, the access device 105 may determine a supported account application based on the received available application identifiers and may send an “application selection” command 203 including the selected AID to the user device 102.
[0054] Additionally, in some embodiments, upon receiving the application selection message 203, at step 204, the user device 102 may send a terminal transaction data14KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 request 204 to request transaction data from access device 105 which may be needed to execute the transaction using the selected application associated with the selected AID. In some embodiments, the terminal transaction data request 204 may be in the form of a “Select AID Response” and may include application identifier (AID) file control information (FCI) with the selected AID as the dedicated file name. The terminal transaction data request may include a list of transaction data identifiers to request the appropriate data from the access device 105, and the list of transaction data identifiers can be in the form of a processing options data object list (PDOL).
[0055] The transaction data requested by, for example, the mobile application for the transaction may include an entity identifier associated with the access device 105 (e.g., a merchant identifier (MID)), terminal processing options (TPO), authorized amount, other amount, terminal country code, terminal verification results, transaction currency code, transaction data, transaction type, and / or an unpredictable number. The terminal transaction data request may also include other data such as FCI issuer discretionary data, application program identifier, and language preference. In other embodiments, the transaction information may be provided as part of the application selection message 203 and / or as part of the available applications request message 201.
[0056] At step 205, after receiving the terminal transaction data request 204, the access device 105 may send to the user device 102, the terminal transaction data in 205 requested by the mobile application. In some embodiments, the terminal transaction data in 205 may be sent in the form of a get processing options (GPO) command, and may include the requested terminal transaction data in 205 in a processing options data object list (PDOL). In some embodiments, the terminal transaction data in 205 (e.g., Transaction Processing Options (TPO)) may include a TPO indicator that indicates which transaction data types the access device 105 supports.
[0057] At step 206, once the selected application of the user device 102 receives the terminal transaction data in 205, the user device 102 obtains the relevant account credentials from the selected application as well as any other relevant payment15KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 information and may send a set of transaction processing information in 206 including the account credentials and any other relevant transaction processing information to the access device 105. In some embodiments, the transaction processing information in 206 can be sent in the form of a “get processing options” (GPO) response. In some embodiments, the transaction processing information may include one or more application file locators (AFLs) that can be used as file addresses by access device 105 to read account data stored on the user device 102, and an application interchange profile (AIP) that can be used to indicate the capabilities of the payment application.
[0058] For example, the transaction processing information may include any credentials for the transaction including a transaction cryptogram generated using transaction information, a PAN, Track-2 equivalent data, and / or additional data. The transaction processing information may include issuer application data (IAD), a form factor indicator (FFI), card transaction qualifiers (CTQ), cryptogram information data (CID), an application transaction counter (ATC), and / or an application PAN sequence number (PSN). In some embodiments, the issuer application data (IAD) may include a length indicator indicating the length of the IAD, cryptogram version number (CVN) indicating the version of the transaction cryptogram, a derived key indicator (DKI) that can be used to identify a master key (e.g. a master key associated with the issuer), and / or card verification results (CVR).
[0059] It should be understood that in some embodiments, the transaction processing information in 206 being sent from user device 102 to access device 105 may include some or all of the information described above, and in some embodiments, may include additional information not specifically described.
[0060] At step 207, after the access device 105 receives the transaction processing information in 206, the access device 105 may send an account data request 207 to the user device 102 to read additional account data in 208 that may be stored on the user device 102. In some embodiments, the account data request 207 may be in the form of a “read record” command, and may include an application file locator (AFL) indicating the16KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 location of the account data that access device 105 is attempting to read. The AFL included in the account data request 207 may correspond to an AFL in the transaction processing information in 206 that was provided to access device 105 from user device 102
[0061] At step 208, in response to receiving the account data request 207 from the access device 105, the user device 102 may send the account data in 208 stored at the location indicated by the AFL to access device 105. In some embodiments, the account data in 208 may be sent in the form of a “read record” response. The account data 208 may include, for example, application usage control that indicates the issuer's restrictions on the usage and services allowed for the application, the cardholder's name, customer exclusive data, issuer country code, and / or other account related data that is accessible at the AFL location and is stored in the user device 102.
[0062] It should be understood that in some embodiments, the account data in 208 being sent from user device 102 to access device 105 may include some or all of the information describe above, and in some embodiments, may include additional information not specifically described. Further, any and all of this information may be provided in response to receiving a selection message and / or obtaining payment credentials.
[0063] In some embodiments, the series of communications described with respect to steps 201-208 can be part of an EMV ("Europay, Mastercard, and Visa) communication exchange and may comply with any suitable EMV standards. For example, the ISO / IEC 7816 standard for contact cards or the ISO / IEC 14443 standard for contactless cards.
[0064] In some embodiments, after 208, the access device 105 can generate an authorization request message and then provide the authorization request message to a resource provider computer associated with the access device 105. The resource provider computer can provide the authorization request message to a transport computer that can provide the authorization request message to a network processing computer.17KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01The network processing computer can provide the authorization request message to an authorizing entity computer. The authorizing entity computer can determine whether or not to authorize the interaction between, for example, the user of the user device 102 and a resource provider of the resource provider computer associated with the access device 105. The authorizing entity computer can generate an authorization response message comprising an indication of whether or not the interaction is authorized.
[0065] The authorizing entity computer can provide the authorization response message to the resource provider computer via the network processing computer and the transport computer. In some embodiments, the resource provider computer can provide the authorization response message to the access device which can provide the user device with the indication of whether or not the interaction is authorized. In other embodiments, the resource provider computer can provide the indication of whether or not the interaction is authorized to the user of the user device and / or the user device 102 itself.
[0066] At the end of the day or any other suitable period of time, a clearing and / or settlement process between the relevant parties can take place.
[0067] Although the steps in the flowcharts and process flows described above are illustrated or described in a specific order, it is understood that embodiments of the invention may include methods that have the steps in different orders. In addition, steps may be omitted or added and may still be within embodiments of the invention.
[0068] Embodiments include an improved version of the interaction flow discussed above in FIG. 2 where the user device 102 can provide multiple credentials to the access device 105 and a user can select at the access device 105 which credential to use for a transaction between the user and the resource provider. Such a modified interaction flow is described below with respect to FIG. 3.
[0069] FIG. 3 shows a flowchart illustrating an exemplary method for processing a transaction based on a user-selected credential, according to embodiments. As18KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 mentioned above, FIG. 3 may have various similarities to FIG. 2, and certain steps discussed below with respect to FIG. 3 will reference corresponding steps of FIG. 2.
[0070] In some embodiments, the access device 105 may determine that the user device is within communication proximity (e.g., close enough for short range communications, or responsive to a communication ping). Then, the access device 105 may establish a connection with the user device 102. For example, the access device 105 and user device 102 may establish connection that is a secure communication channel by exchanging one or more keys and / or generating a session key.
[0071] The access device 105 may initiate an interaction between the user device 102 and the access device 105 by sending a request for available account applications to the user device 102 in order to conduct a transaction. In some embodiments, the request for available account applications may be an initial communication that establishes the connection between the access device 105 and the user device 102.
[0072] The user device 102 may determine a set of application identifiers associated with mobile payment applications that are provisioned on the user device 102 or otherwise available at the user device 102. The user device 102 may then transmit a list of available application identifiers to the access device 150 as a part of an interaction between the user device 102 and access device 150. Each of the applications may be configured for providing credentials that can be used for a transaction between a user (e.g., via a user’s account) associated with the user device 102 and a resource provider (e.g., via a resource provider’s account) associated with the access device 150.
[0073] At step S301, which may be similar to step 202 described above with respect to FIG. 2, the access device 105 may receive a plurality of application identifiers corresponding to a plurality of applications from the user device 102. The access device 105 may receive the application identifiers via PPSE response, which may be transmitted via short range communications (e.g., NFC).
[0074] As an example, the plurality of application identifiers may include a first application identifier and a second application identifier. The first application identifier19KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 may be associated with a network-specific application, and the second application identifier may be associated with a network-generic application.
[0075] At step S302, the access device 105 can determine which of the plurality of applications are supported by the access device. For example, a subset of the plurality of applications (e.g., 2 out of 3 applications) available at the user device 102 may be supported by the access device 105.
[0076] Additionally, in some embodiments, the access device 105 may determine a ranking of the plurality of applications based on one or more priorities of the access device 105 and / or resource provider. For example, the access device 105 may determine that a first application of the plurality of applications has a highest rank above the remaining applications based on a predefined set of priorities.
[0077] The priorities and / or preferences may be determined using any suitable method and using any suitable information including authentication and configuration options of the payment applications (e.g., type of authentication and / or level of authentication performed by the application), geographical restrictions associated with the access device 150 (e.g., international vs. domestic transaction for the payment application), based on transaction specific information (e.g., a transaction amount threshold or limit, time limit, etc.), or based on any other suitable information associated with the account, consumer, merchant, user device 110, transaction information, or any information available. Accordingly, the priority ranking of each payment application may be based on the preferences of the access device 150, the mobile application 113 and / or user device 110, relationship information between particular selected AIDs, configuration options of the applications (e.g., CVMs associated with the AID, restrictions associated with the AIDs, etc.), or any other information available to the access device 150.
[0078] At step S303, the access device 105 can obtain from the user device 102, a plurality of credentials. The plurality of credentials can include a corresponding credential for each of the plurality of applications.20KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01
[0079] For example, the access device 105 can send to the user device 102 one or more requests for credentials corresponding to each of the plurality of applications. The user device 102 can receive the one or more requests, and then transmit the plurality of credentials to the access device 105. The access device 105 can thereby receive the plurality of credentials during a single interaction with the user device 102 via short range communications. While the access device 105 may receive a plurality of credentials (e.g., corresponding to different accounts) during a single interaction related to a single transaction, the access device 105 may utilize only one of the credentials (e.g., one account) for processing the transaction, as discussed below with respect to step S311.
[0080] According to embodiments, the process of obtaining the plurality of credentials in step S303 can encapsulate or involve aspects of several steps described above with respect to FIG. 2, such as steps 203 through 208. As discussed above with respect to FIG. 2, a single interaction between the user device 102 and access device 105 can involve a number of rapid communications to exchange various data. Step S303 for obtaining credentials can include any of the communications of steps 203 through 208 and / or any other suitable communications.
[0081] As an example, the one or more requests for credentials can be similar to step 203 described above with respect to FIG. 2. For example, the access device 105 may send an application selection command to the user device 102. However, instead of sending a single application selection command with a single selected application identifier, the access device 105 may send multiple application selection commands each including a different application identifier. The access device 105 can send a different application selection command for each of the plurality of application identifiers, and thereby request credentials for each of the plurality of applications. In other embodiments, the access device 105 may send a single application selection command to the user device 102, but the application selection command may include more than one application identifier. The application selection command may include some or all of the plurality of application identifiers stored on the user device 102.21KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01
[0082] As another example, the user device 102 may transmit the plurality of credentials to the access device 105 via one or more GPO response messages similar to in step 206. A single GPO response may include the plurality of credentials, or a plurality of GPO responses can each include one or the plurality of credentials.
[0083] According to embodiments, in addition to the credentials, the access device 105 can obtain any other suitable information for each of the applications. For example, for each application at the user device 102, the access device 105 can receive a set of transaction processing information as discussed in step 206 and / or additional account data as discussed in step 207.
[0084] In some embodiments, the access device 105 may only request and receive credentials for a subset of the plurality of applications that are supported by the access device 105, as previously determined in step S302.
[0085] According to some embodiments, after steps S301-S303, the interaction between the user device 102 and the access device 105 may be complete. For example, the access device 105 may have received from the user device 102 any information necessary for conducting a transaction, and the access device 105 can continue to execute the transaction without any further communications with or information from the user device 102. FIG. 4A illustrates an example of a user presenting the user device 102 for interacting with the access device 105 in order to conduct a transaction, according to embodiments. While the user presents the user device 102 to the access device 105, steps S301-S303 can be performed and any other suitable information can be exchanged.
[0086] In some embodiments, the access device 105 may terminate the connection with the user device. For example, the access device 105 may terminate the connection after receiving the plurality of credentials. Also or instead, the user can remove the user device 102 from the access device, which can terminate the connection (e.g., by removing the user device 102 from short range communication range). The user may remove the user device 102 in response to an indication from the user device 102 and / or access22KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 device 105, such as an audio alert, visual indication, haptic feedback, or any other suitable indication, which may be provided after the access device 105 receives the plurality of credentials. As a result, the user device 102 may no longer be in communication with the access device 105 for the subsequent steps, including processing of the transaction.
[0087] At step S304, the access device 105 can store the plurality of credentials in a memory. The access device 105 can also store, for each credential, an associated application identifier, transaction processing information, information about the cardholder verification method associated with the application identifier, and / or any other suitable information. The plurality of credentials may be temporarily stored until the transaction is processed in step S311 or at any other suitable time.
[0088] At step S305, the access device 105 can prompt a user of the user device 102 to select one of the plurality of applications. Prompting may include displaying information associated with the plurality of applications on a user interface of the access device 105, emitting a sound (e.g., chime), illuminating one or more buttons or selectable areas of a touchscreen, etc.
[0089] For example, the access device 105 may display a list of selectable options. Each option can include displayed information such as an application identifier, some or all of a credential (e.g., last 4 digits of a PAN), an account name or nickname, a processing network name, and / or any other suitable information associated with an account, an application, or an application identifier. FIG. 4B illustrates an example of an access device 105 displaying a list of selectable options including a first application 111 and a second application 112, according to embodiments. The first application 111 may be a network-specific application, and the second application 112 may be a networkgeneric application.
[0090] In some embodiments, the access device 105 may display information indicating only a subset of the plurality of applications, such as application that are supported by the access device 105.23KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01
[0091] In some embodiments, displaying includes visually emphasizing (e.g., highlighting, bolding, underlining, different color, increased brightness, outlined, etc.) one or more applications that are ranked with a higher priority (e.g., as discussed above with respect to step S302). For example, a subset of information (e.g., application name or application identifier) associated with a first application may be emphasized in response to determining that the first application has the highest rank.
[0092] At step S306, the access device 105 can receive from the user a selection of an application from the plurality of applications. The selection of the application may be received via a user interface of the access device 105. For example, the user may press a keypad button or contact a portion of a touchscreen associated with the application, speak a voice command, etc. Accordingly, a selection of an application, application identifier, and / or account can be received via the access device 105 after the access device 105 receives the options from the user device 102. This may be in contrast with step 203 of FIG. 2, where the access device automatically selects the application without a user input.
[0093] The user may select an application based on any suitable considerations. For example, for a given transaction, the user may prefer a certain application or account that is associated with a certain cardholder verification method, a certain level of security, a certain processing network (e.g., which may involve certain fees, processing speeds, configuration options), a certain processing scheme (e.g., network-specific, networkgeneric, domestic, or non-domestic), a certain reward (e.g., points for a certain type of transaction), a lack of foreign transaction fees, etc. A user’s preferences may be based on authentication and configuration options of the payment applications (e.g., type of authentication and / or level of authentication performed by the application), geographical restrictions (e.g., international vs. domestic transaction for the payment application), based on transaction specific information (e.g., a transaction amount threshold or limit, time limit, etc.), or based on any other suitable information associated with the account, consumer, merchant, user device 110, transaction information, or any information available.24KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01
[0094] At step S307, the access device 105 can retrieve, from the memory, a credential that corresponds to the selected application in response to the user input selecting the application. The access device 105 may also retrieve any other suitable information, associated with the selected application, such as transaction processing information and / or cardholder verification method information. The access device 105 does not need to communicate with the user device 102 at this point to obtain the credential, as the access device 105 has already obtained the credential from the user device 102 as one of the plurality of credentials obtained at step S303.
[0095] At step S308, the access device 105 can determine a verification method associated with the selected application. For example, a cardholder verification method (CVM) associated with the application can be identified from the memory. In some embodiments, different applications can be associated with different CVMs.
[0096] At step S309, the access device 105 can execute the verification method. For example, the access device 105 may authenticate the consumer by collecting and / or authentication a PIN, signature, cardholder device passcode, etc. The access device 105 may also check restrictions associated with the transaction data (e.g., transaction limit, geographical limitations, etc.), obtain user authorization / approval, provide processing options to the user (e.g., indicate available transaction options to consumer), and perform any other validation and / or processing actions.
[0097] At step S310, the access device 105 can purge (also referred to as delete, erase, or remove), from the memory, each remaining credential of the plurality of credentials other than the credential that corresponds to the selected application. The access device 105 may discard or purge any information associated with other applications that were not selected, such as transaction processing information, application identifiers, etc. According to embodiments, the access device 105 may purge the unused application information immediately after the application selection of step S306, before processing the transaction at step S311 , or at any other suitable time. Discarding or purging the non-selected application information can free storage space at25KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 the memory and / or reduce security vulnerabilities by reducing the amount of stored sensitive data.
[0098] At step S311 , the access device 105 can process the transaction using the credential that corresponds to the selected application (e.g., the user input selecting the application). FIG. 4C illustrates an example of an access device 105 processing the transaction, according to embodiments.
[0099] Processing the transaction may include generating an authorization request message including the credential, a transaction amount, and / or any other suitable transaction processing information. The access device 105 can then transmit the authorization request message to a processing computer of a payment processing network. For example, the authorization request message may be transmitted to an authorizing entity computer (e.g., an issuer computer), via a processing network computer and a transport computer (e.g., an acquirer computer) for authorization. At the end of the day or some other period of time, the transaction can be cleared and settled. In some embodiments, the access device 105 can provide the credential, a transaction amount, and / or any other suitable transaction processing information to a resource provider computer, and the resource provider computer can generate and transmit the authorization request message.
[0100] Accordingly, the transaction can be processed based on only one of a plurality of applications and only one of the plurality of credentials provided to the access device 105 by the user device 102. The user device 102 may no longer be in communication with the access device 105 during the processing the transaction, as the user device 102 may have been removed from the access device 105 after step S303.
[0101] Embodiments include a number of additions and alternatives to the method illustrated in FIG. 3. For example, in some embodiments, the access device 105 may preemptively generate a plurality of authorization request messages and / or prepare a plurality of transaction payloads (e.g., credentials and / or transaction processing information that is re-formatted or otherwise prepared to conform to a predetermined26KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 communication protocol (e.g., ISO message format) for delivery to a payment processing network). This can include generating, for the same transaction, a different authorization request message and / or payload for each of the plurality of applications and / or plurality of credentials. These messages can be generated and stored as a part of step S304 before the application is selected at step S306 or at any other suitable time. As a result, the access device 105 can be prepared to quickly retrieve and submit a prepared authorization request message and / or payload at steps S307 and S311 after the application is selected at step S306. Additionally, step S310 can include purging each remaining authorization request message of the plurality of authorization request messages other than the authorization request message that corresponds to the selected application.
[0102] The access device 105 may be in any suitable form. Some examples of access devices include POS devices, cellular phones, PDAs, personal computers (PCs), tablet PCs, hand-held specialized readers, set-top boxes, electronic cash registers (ECRs), automated teller machines (ATMs), virtual cash registers (VCRs), kiosks, security systems, access systems, Websites, and the like. Typically, an access device 105 may use any suitable contact or contactless mode of operation to send or receive data from a user device 102.
[0103] FIG. 5 illustrates a block diagram of an access device 500 according to embodiments. The access device 500 may comprise a processor 502, which may be coupled to a computer readable medium 504, a memory 506, a network interface 508, a user interface 510, and a reader 512.
[0104] The memory 506 may contain data such as application identifiers, credentials, transaction processing information, transaction payloads, authorization request messages, etc.
[0105] The user interface 510 can include input elements (e.g., touchscreen, keypad, buttons or the like) and output elements (e.g., a display, a speaker, etc.). The27KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 reader 512 can include a contact chip reader, a contactless reader, and / or a magnetic stripe reader.
[0106] The network interface 508 may include an interface that can allow the access device 500 to communicate with external computers. Some examples of the network interface 508 may include a modem, a physical network interface (such as an Ethernet card or other Network Interface Card (NIC)), a virtual network interface, a communications port, a Personal Computer Memory Card International Association (PCMCIA) slot and card, or the like.
[0107] The computer readable medium 504 may comprise executable code for performing a method. The method comprises: receiving, by an access device from a user device for a transaction, a plurality of application identifiers corresponding to a plurality of applications; obtaining, by the access device from the user device in a single interaction with the user device, a plurality of credentials including, for each of the plurality of applications, a corresponding credential; prompting, by the access device, a user of the user device to select one of the plurality of applications; receiving, by the access device from the user, a selection of an application from the plurality of applications; and processing, by the access device, the transaction using a credential that corresponds to the selected application, the credential being one of the plurality of credentials.
[0108] The computer readable medium 504 may comprise a number of software modules including a communication module 504A, an authorization module 504B, and an application selection module 504C.
[0109] The communication module 504A may comprise code that causes the processor 502 to generate, forward, reformat, and receive messages, and / or otherwise communicate with other entities. For example, the communication module 504A can comprise code that enables the processor 502 to receive transaction processing information from the user device and transmit data and information requests to a resource provider computer or a user device.28KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01
[0110] The authorization module 504B comprises code, executable by the processor 502 to perform authorization processing. Authorization processing can include generating authorization request messages, processing authorization request messages, sending authorization request messages, and receiving authorization request messages.
[0111] The application selection module 504C can comprise code, executable by the processor 502 to receive an application selection from a user. For example, the application selection module 504C can comprise code that enables the processor 502 to display a list of applications to a user and receive a user’s selection of one of the displayed applications via a user interface.
[0112] FIG. 6 is a block diagram illustrating an example of a user device 600. The user device 600 can be a user device (e.g., mobile phone) with a computer readable medium 604. The user device 600 may include device hardware 608 coupled to a system memory 602.
[0113] Device hardware 608 may include a processor 610, input elements 612, a short range antenna 614, a user interface 616, output elements 618, and a long range antenna 620. Examples of input elements may include microphones, keypads, touchscreens, sensors, etc. Examples of output elements may include speakers, display screens, and tactile devices. The processor 610 can be implemented as one or more integrated circuits (e.g., one or more single core or multicore microprocessors and / or microcontrollers), and is used to control the operation of the user device 600. The processor 610 can execute a variety of programs in response to program code or computer-readable code stored in the system memory 602, and can maintain multiple concurrently executing programs or processes.
[0114] The long range antenna 620 may include one or more RF transceivers and / or connectors that can be used by the user device 600 to communicate with other devices and / or to connect with external networks. The input and output elements 618, 618 allow a user to interact with and invoke the functionalities of the user device 600. The short range antenna 614 may be configured to communicate with external devices29KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 through a short range communication medium (e.g., using Bluetooth, Wi-Fi, infrared, NFC, etc.). The long range antenna 620 may be configured to communicate with a remote base station and a remote cellular or data network, over the air.
[0115] The system memory 602 can be implemented using any combination of any number of non-volatile memories (e.g., flash memory) and volatile memories (e.g., DRAM, SRAM), or any other non-transitory storage medium, or a combination thereof media.
[0116] The system memory 602 can comprise a computer readable medium 604 comprise a first application 604A and a second application 602A. The first application 604A can be a first payment application and / or network-generic application. The second application 602B can be a second payment application and / or network-specific application.
[0117] The computer readable medium 604 can comprise code, executable by the processor 610 to perform operations comprising: transmitting, by a user device to an access device for a transaction, a plurality of application identifiers corresponding to a plurality of applications; receiving, by the user device from the access device, one or more requests for a plurality of credentials including, for each of the plurality of applications, a corresponding credential; and transmitting, by the user device to the access device, the plurality of credentials including, for each of the plurality of applications, the corresponding credential, thereby causing the access device to prompt a user of the user device to select one of the plurality of applications, receive from the user a selection of an application from the plurality of applications, and process the transaction using a credential from the plurality of credentials that corresponds to the selected application.
[0118] In some embodiments, a user device (e.g., the user device 102 in FIG. 1) can take the form of a card. For example, a smart card, such as a credit card or a debit card, including an integrated circuit (e.g., microprocessor and / or antennae). The user device can be configured for contact and / or contactless communications with an access device. As discussed above, the user device can store multiple payment applications30KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 and / or credentials. For example, the user device can be a co-badged credit or debit card that includes different payment application corresponding to different processing networks and / or issuers.
[0119] Embodiments of the invention provide a number of technical advantages. For example, embodiments enable a user to select an application for a transaction, instead of an access device or resource provider automatically performing an application selection without the user’s input via a typical EMV communication exchange.
[0120] Embodiments enable the user to select the application via a user interface of the access device. As a result, embodiments provide a more streamlined manner of selecting the application than, for example, the user manually selecting via the user device an application before presenting the user device to the access device. Manual selection via the user device may undesirably involve a more cumbersome device operating process where the user navigates to a correct wallet application, reviews options, and pre-selects a payment application for the next interaction with an access device. Such a process may be too complex for users, and users may forget to pre-select an application before presenting the user device to the access device.
[0121] Additionally, embodiments allow the user device to take the form of a mobile device (e.g., smartphone) as well as a card (e.g., credit card) without a user interface, as the user can provide selection via the user interface of the access device.
[0122] Further, embodiments allow the access device to request, receive from the user device, and store multiple credentials for multiple applications. As a result, the user device can transmit information about multiple applications efficiently via a single data transmission communication. Additionally, the user device can transmit credentials for each application in a single bulk transmission in response to a request from the access device for multiple credentials (e.g., where only one of the credentials will be utilized for a transaction based on a subsequent user selection). In addition to efficient electronic communications between the user device and access device, this also enables the user to perform a single presentation (e.g., physically bring near) of the user device to the31KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 access device, as opposed to the user having to present the user device to the access device for a second interaction after the user selects the application. Thereby, embodiments provide a streamlined and efficient interaction process with reduced friction, reduced communications, reduced data processing, and reduced user effort.
[0123] Further, embodiments allow multiple authorization requests to be generated for a transaction, with each authorization request message including a different credential. The access device may only submit a single authorization request message after the user selects a payment application for the transaction. Having the prepared set of authorization request messages can enable the access device to submit the selected authorization request message as soon as possible and / or immediately after the user makes the selection of payment application. Thereby, the transaction can be processed more quickly and an authorization result can be received at an earlier time.
[0124] Embodiments also provided for efficient data storage, any used payment applications, credentials, and / or prepared authorization request messages can be purged after the user selects a payment application for the transaction. Accordingly, the benefits from providing the multiple applications can be achieved without creating an increased data storage burden.
[0125] Additionally, the access device can first filter a set of applications by determining which applications are supported by the access device before presenting selectable options to the user. As a result, embodiments avoid the possibility of a user selecting an application that is not supported by the access device (e.g., which could happen if the user pre-selected an application via the user device). Additionally, priorities of the resource provider and user can both be considered, as the access device can emphasize preferred applications for the user to consider.
[0126] Furthermore, embodiments improve security and efficiency by promptly discarding data associated with unselected applications.
[0127] Further details supporting embodiments of the invention can be found U.S. Patent No. 10,445,718, which is incorporated by reference herein for all purposes.32KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01
[0128] Any of the software components or functions described in this application may be implemented as software code to be executed by a processor using any suitable computer language such as, for example, Java, C, C++, C#, Objective-C, Swift, or scripting language such as Perl or Python using, for example, conventional or object- oriented techniques. The software code may be stored as a series of instructions or commands on a computer readable medium for storage and / or transmission, suitable media include random access memory (RAM), a read only memory (ROM), a magnetic medium such as a hard-drive or a floppy disk, or an optical medium such as a compact disk (CD) or DVD (digital versatile disk), flash memory, and the like. The computer readable medium may be any combination of such storage or transmission devices.
[0129] Such programs may also be encoded and transmitted using carrier signals adapted for transmission via wired, optical, and / or wireless networks conforming to a variety of protocols, including the Internet. As such, a computer readable medium according to an embodiment of the present invention may be created using a data signal encoded with such programs. Computer readable media encoded with the program code may be packaged with a compatible device or provided separately from other devices (e.g., via Internet download). Any such computer readable medium may reside on or within a single computer product (e.g., a hard drive, a CD, or an entire computer system), and may be present on or within different computer products within a system or network. A computer system may include a monitor, printer, or other suitable display for providing any of the results mentioned herein to a user.
[0130] The above description is illustrative and is not restrictive. Many variations of the invention will become apparent to those skilled in the art upon review of the disclosure. The scope of the invention should, therefore, be determined not with reference to the above description, but instead should be determined with reference to the pending claims along with their full scope or equivalents.
[0131] One or more features from any embodiment may be combined with one or more features of any other embodiment without departing from the scope of the invention.33KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01
[0132] As used herein, the use of "a," "an," or "the" is intended to mean "at least one," unless specifically indicated to the contrary.34KILPATRICK TOWNSEND 80080722 1
Claims
PATENTAttorney Docket No.: 079900-1518522 Client Ref. No.:9729WO01WHAT IS CLAIMED IS1 . A method comprising: receiving, by an access device from a user device for a transaction, a plurality of application identifiers corresponding to a plurality of applications; obtaining, by the access device from the user device in a single interaction with the user device, a plurality of credentials including, for each of the plurality of applications, a corresponding credential; prompting, by the access device, a user of the user device to select one of the plurality of applications; receiving, by the access device from the user, a selection of an application from the plurality of applications; and processing, by the access device, the transaction using a credential that corresponds to the selected application, the credential being one of the plurality of credentials.
2. The method of claim 1 , further comprising: storing, by the access device, the plurality of credentials in a memory; in response to receiving the selection of the selected application, retrieving, by the access device, from the memory, the credential that corresponds to the selected application; and after receiving the selection of the selected application, purging, by the access device, from the memory, each remaining credential of the plurality of credentials other than the credential that corresponds to the selected application.
3. The method of claim 1 , wherein prompting includes displaying information associated with the plurality of applications on a user interface of the access device.
4. The method of claim 3, further comprising:35KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522 Client Ref. No.:9729WO01 determining that a first application of the plurality of applications has a highest rank based on a predefined set of priorities, and wherein displaying includes visually emphasizing a subset of information associated with the first application in response to determining that the first application has the highest rank.
5. The method of claim 3, further comprising: determining, by the access device, which of the plurality of applications are supported by the access device, wherein only information associated with supported applications is displayed.
6. The method of claim 1 , wherein the selection of the selected application is received via a user interface of the access device.
7. The method of claim 1 , further comprising: determining, by the access device, a verification method associated with the selected application, wherein at least two of the plurality of applications are associated with different verification methods; and executing, by the access device, the verification method.
8. The method of claim 1 , wherein processing the transaction includes: generating, by the access device, an authorization request message including the credential; and transmitting, by the access device, the authorization request message to a processing computer.
9. The method of claim 1 , further comprising:36KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522Client Ref. No.:9729WO01 before receiving the selection of the selected application, generating, by the access device, for the transaction, a plurality of authorization request messages each including a different one of the plurality of credentials; wherein processing the transaction includes transmitting, by the access device to a processing computer, an authorization request message from the plurality of authorization request messages that corresponds to the selected application; and after receiving the selection of the selected application, purging, by the access device, each remaining authorization request message of the plurality of authorization request messages other than the authorization request message that corresponds to the selected application.
10. The method of claim 1 , further comprising: determining, by the access device, that the user device is within communication proximity; establishing, by the access device, a connection with the user device before receiving the plurality of application identifiers; and terminating the connection after receiving the plurality of credentials, wherein the user device is no longer in communication with the access device during the processing the transaction.11 . The method of claim 1 , wherein the transaction is processed using only one of the plurality of applications and only one of the plurality of credentials.
12. The method of claim 1 , wherein obtaining the plurality of credentials includes: sending, by the access device to the user device, for each of the plurality of applications, a request for the corresponding credential; and receiving, by the access device from the user device, the plurality of credentials.37KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522 Client Ref. No.:9729WO0113. The method of claim 12, wherein each request for the corresponding credential includes application selection message including a corresponding one of the plurality of application identifiers.
14. The method of claim 1 , wherein each of the plurality of credentials is received via short range communications during the single interaction with the user device.
15. The method of claim 1 , wherein at least two of the plurality of applications are associated with different processing networks.
16. The method of claim 1 , wherein the plurality of applications includes a first application and a second application, wherein the first application and the second application are both associated with a same credential from the plurality of credentials.
17. The method of claim 16, wherein the first application is configured to provide information in a first format, and the second application is configured to provide information in a second format that is different from the first format.
18. An access device comprising: a processor; and a computer readable medium, the computer readable medium comprising code, executable by the processor, for performing the method according to any of claims 1 -17.
19. A method comprising: transmitting, by a user device to an access device for a transaction, a plurality of application identifiers corresponding to a plurality of applications; receiving, by the user device from the access device, one or more requests for a plurality of credentials including, for each of the plurality of applications, a corresponding credential; and38KILPATRICK TOWNSEND 80080722 1PATENTAttorney Docket No.: 079900-1518522 Client Ref. No.:9729WO01 transmitting, by the user device to the access device in a single interaction with the access device, the plurality of credentials including, for each of the plurality of applications, the corresponding credential, thereby causing the access device to prompt a user of the user device to select one of the plurality of applications, receive from the user a selection of an application from the plurality of applications, and process the transaction using a credential from the plurality of credentials that corresponds to the selected application.
20. The method of claim 19, further comprising: receiving, by the user device from the access device, a first request for the plurality of application identifiers, wherein the one or more requests for the plurality of credentials includes, for each of the plurality of applications, an application selection message including a corresponding one of the plurality of application identifiers, and wherein the plurality of credentials is transmitted via short range communications during the single interaction with the access device.39KILPATRICK TOWNSEND 80080722 1
Citation Information
Patent Citations
Processing transactions with an extended application id and dynamic cryptograms
US20120317035A1
Mobile terminal and method of performing NFC payment using the mobile terminal
US20140040120A1
Processing a transaction using multiple application identifiers
US20150186864A1
Contactless data exchange between mobile devices and readers involving value information not necessary to perform a transaction
US20190074866A1
Non-default payment application selection during EMV-compliant payment transaction method
US20200134587A1