System and method for secure digital payment

The integration of a secure tokenization platform within a browsing environment addresses the challenges of manual payment entry and merchant integration in e-commerce, enhancing security and convenience through tokenized data autofill and streamlined checkout processes.

WO2026155742A1PCT designated stage Publication Date: 2026-07-23VISA INTERNATIONAL SERVICE ASSOCIATION
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
VISA INTERNATIONAL SERVICE ASSOCIATION
Filing Date
2025-01-17
Publication Date
2026-07-23

AI Technical Summary

Technical Problem

E-commerce checkout processes require manual entry of payment information, leading to friction and security risks, and existing solutions complicate merchant integration and scalability, especially in social platforms and in-app browsers.

Method used

A browsing environment integrates with a secure tokenization platform to detect payment fields, retrieve tokenized data, and autofill forms, using dynamic tokens and one-time passwords for authentication, eliminating the need for merchant-specific integration.

Benefits of technology

This approach enhances security and convenience by reducing manual entry, minimizing fraud risk, and simplifying merchant integration, providing a seamless and scalable checkout process across various platforms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2025012084_23072026_PF_FP_ABST
    Figure US2025012084_23072026_PF_FP_ABST
Patent Text Reader

Abstract

A method for facilitating online payments includes detecting, by a browsing environment, payment data input fields on a checkout page within the browsing environment; sending, by the browsing environment, a user identifier to a tokenization platform; retrieving, by the browsing environment, a tokenized payment data generated by the tokenization platform based on the user identifier; populating, by the browsing environment, the payment data input fields on the checkout page with values based on the retrieved tokenized payment data. The method also includes submitting, by the browsing environment, the values to a merchant backend system for processing. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the methods.
Need to check novelty before this filing date? Find Prior Art

Description

Attorney Docket No.: 240026PCT / 7913W001TITLESYSTEM AND METHOD FOR SECURE DIGITAL PAYMENTBACKGROUND

[0001] E-commerce checkout processes often require customers to manually enter payment information, creating friction and security risks. Existing browser autofill solutions may store sensitive data, raising PCI compliance concerns for browsers and merchants. Additionally, integrating individual merchants with secure payment platforms like Click to Pay presents scalability challenges. Social platforms and in-app browsers further complicate this landscape, as they often lack streamlined checkout options. There is a need for secure and frictionless guest checkout experiences, with reduced merchant integration requirements.SUMMARY

[0002] One general aspect includes a method for facilitating online payments. The method also includes detecting, by a browsing environment, payment data input fields on a checkout page within the browsing environment; sending, by the browsing environment, a user identifier to a tokenization platform; retrieving, by the browsing environment, a tokenized payment data generated by the tokenization platform based on the user identifier; populating, by the browsing environment, the payment data input fields on the checkout page with values based on the retrieved tokenized payment data. The method also includes submitting, by the browsing environment, the values to a merchant backend system for processing. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the methods.

[0003] One general aspect includes a system. The system also includes a tokenization platform; and a browsing environment configured to: load a checkout form; detect payment data input fields on the checkout form; transmit a user identifier associated with a user to the tokenization platform to obtain a tokenized payment data associated with the user identifier from the tokenization platform, the transmission contingent upon a log in status of the user within the browsing environment; and populate the payment data input fields on the checkout form with values based on the tokenized payment data. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the methods.- 1 - 322114733.1Attorney Docket No.: 240026PCT / 7913WG01

[0004] One general aspect includes a method. The method also includes storing, by a tokenization platform, in a database, user identifiers and corresponding tokens, the user identifiers associated with users authenticated by trusted browsing environments, and the corresponding tokens based on payment data associated with the users; receiving, by the tokenization platform, a user identifier from one of the trusted browsing environments; querying, by the tokenization platform, the database to retrieve a token based on the user identifier; requesting, by the tokenization platform, a token vault to generate a token cryptogram for verifying authenticity of the token during payment processing; and transmitting, by the tokenization platform, tokenized payment data to the one of the trusted browsing environments, the tokenized payment data may include the token and the token cryptogram. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the methods.BRIEF DESCRIPTION OF THE DRAWINGS

[0005] In the description, for purposes of explanation and not limitation, specific details are set forth, such as particular aspects, procedures, techniques, etc. to provide a thorough understanding of the present technology. However, it will be apparent to one skilled in the art that the present technology may be practiced in other aspects that depart from these specific details.

[0006] The accompanying drawings, where like reference numerals refer to identical or functionally similar elements throughout the separate views, together with the detailed description below, are incorporated in and form part of the specification, and serve to further illustrate aspects of concepts that include the claimed disclosure and explain various principles and advantages of those aspects.

[0007] The systems and methods disclosed herein have been represented where appropriate by conventional symbols in the drawings, showing only those specific details that are pertinent to understanding the various aspects of the present disclosure so as not to obscure the disclosure with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein.

[0008] FIG. 1 illustrates a method, according to at least one aspect of the present disclosure.

[0009] FIG. 2 illustrates a logic flow diagram of a system, according to at least one aspect of the present disclosure.-2 - 322114733.1Attorney Docket No.: 240026PCT / 7913WG01

[0010] FIG. 3 is a block diagram of a computer apparatus with data processing subsystems or components, according to at least one aspect of the present disclosure.

[0011] FIG. 4 is a diagrammatic representation of an example system that includes a host machine within which a set of instructions to perform any one or more of the methodologies discussed herein may be executed, according to at least one aspect of the present disclosure.DETAILED DESCRIPTION

[0012] In some embodiments, the present disclosure introduces a method for processing online payments by integrating a secure tokenization platform, e.g., Click to Pay, functionality directly within a browsing environment. The browsing environment may act as an intermediary, retrieving tokenized payment data from a secure tokenization platform, based on a user identifier (e.g., user's email or phone number). The tokenized data may then be used to autofill payment fields on merchant websites, eliminating the need for manual entry. In some embodiments, the present disclosure further introduces a system that executes one more of portions of the method and incorporates security measures such as one-time passwords (OTPs) for new / unrecognized devices and dynamic token verification values (DTVVs) to protect against fraud. This approach enhances security by avoiding the storage of sensitive payment information on either the browsing environment or merchant side. The browsing environment's ability to detect payment fields and autofill them with tokenized data simplifies the checkout process for both users and merchants.

[0013] Further to the above, the browsing environment based approach offers significant advantages over traditional merchant integration methods. By integrating with the browsing environment, the solution eliminates the need for individual merchants to implement Click to Pay, streamlining the adoption process and improving scalability. This approach also enhances security by using dynamic token data and reducing the risk of fraud. The system's convenience benefits users by eliminating manual payment entry and reducing cart abandonment. In some embodiments, the method and system may address the challenges of using payment systems on public computers by leveraging the user's browsing environment login to ensure secure transactions without sharing personal data with merchants, thereby providing a more secure, frictionless, and ubiquitous method and system for capturing card payment data online.

[0014] In one embodiment, a method 100 includes one or more of the steps illustrated in FIG. 1. In one embodiment, a system 200, as illustrated in FIG. 2, executes one or more of the steps of the method 100. In one aspect, the method 100 includes detecting 101 payment- 3 - 322114733.1Attorney Docket No.: 240026PCT / 7913W001data input fields on a checkout page 207 within a browsing environment and sending 102 a user identifier (e.g., an email address or phone number) from the browsing environment to a secure tokenization platform (e.g., Click to Pay, Secure Remote Commerce (SRC)). In one aspect, when a user encounters a checkout page within the browsing environment, a browsing environment 201 (e.g., browser, browser-like tool) may automatically detect the payment data input fields. Instead of prompting the user to manually enter their payment information, the browsing environment 201 may initiate a request to the secure tokenization platform 202, the request including the user identifier.

[0015] The method 100 may include determining that a user is logged into the browsing environment 201 , or prompting the user to log into the browsing environment 201. Sending the user identifier to the secure tokenization platform 202 may be contingent upon the user being logged into the browsing environment 201. Accordingly, the method 100 may leverage the browsing environment’s recognition / authentication of the user to initiate the request to the secure tokenization platform 202 without merchant integration.

[0016] The browsing environment 201 may detect 101 payment data input fields on the checkout page 207 by analyzing the HTML structure, attributes, and context of the elements on the page. Specific attributes such as type="text", type="number", or type="password" in input fields may be examined. Fields with attributes like name or id containing relevant keywords may be strong indicators. Further, autocomplete attributes (e.g., cc-number or cc-exp) may also be considered. Additionally, or alternatively, the browsing environment 201 may analyze surrounding elements, such as <label> tags, to understand the context. For instance, a label with text like "Credit Card Number" linked to an input field may be indicative of payment data input fields.

[0017] In one embodiment, the browsing environment 201 may use JavaScript APIs, such as the Payment Request API, which provide standardized methods for collecting payment data. Some websites use structured data markups, which may aid the browsing environment 201 in identifying payment forms. Advanced techniques, such as machine learning, may also be employed to recognize patterns in the Document Object Model (DOM) structure or field groupings that are typical of payment forms.

[0018] The method 100 may further include retrieving 103 tokenized payment data based on the user identifier. In one embodiment, the retrieved tokenized payment data includes a dynamic token and a token cryptogram. The cryptogram ensures the authenticity and integrity of the token, preventing unauthorized use.-4 - 322114733.1Attorney Docket No.: 240026PCT / 7913W001

[0019] In one embodiment, the secure tokenization platform 202 may query a database associated therewith to look up the user identifier and retrieve the token. If the request is from a new / unrecognized device, an OTP may be required. The payment network 204 sends an authentication request to the issuer 205, which then determines that OTP-based verification is necessary. The issuer 205 generates a unique OTP, typically using algorithms like HMAC-based One-Time Password (HOTP) or Time-Based One-Time Password (TOTP). These algorithms ensure that the OTP is unique and valid for only a short time window. The OTP is then securely delivered to the cardholder, commonly via SMS, email, or a mobile banking app push notification.

[0020] Simultaneously, the cardholder may be redirected to a secure 3D Secure page hosted by the issuing bank or its authentication service provider. On this page, the cardholder may be prompted to enter the OTP. Upon receiving the OTP, the issuer 205 may validate it by comparing it with the expected value, which was previously generated. If the OTP matches and is still within its validity period, the issuer 205 may confirm the authentication.

[0021] Once the cardholder is authenticated, the issuer 205 may transmit an authentication success response, signaling that the cardholder’s identity has been verified, and to proceed to authorize the transaction by submitting it for final processing through the payment network 204 to the issuer 205. If the transaction is approved by the issuer 205 based on sufficient funds and other internal checks, a confirmation is sent back to a merchant backend system 206, completing the purchase process. In cases where the OTP verification fails — due to an incorrect or expired OTP — the transaction is declined, and the cardholder is notified to try again or contact their bank for assistance

[0022] Referring primarily to FIGS. 1 and 2, based on validating the user identifier, the secure tokenization platform 202 may request, or call, a token vault 203 to generate the token cryptogram and may send the tokenized payment data (token and token cryptogram) to the browsing environment 201. Accordingly, the secure tokenized platform 202 may act as a central repository for sensitive payment data, eliminating the need for merchants or browsers to store this information locally. Said another way, the secure tokenization platform acts as a secure intermediary, protecting sensitive payment data while facilitating seamless transactions.

[0023] The system 200 utilizes tokenization to replace sensitive payment information with unique, dynamic tokens, minimizing the risk of exposure. These tokens may be generated on demand with limited validity. The system 200 also incorporates token cryptograms, which-5 - 322114733.1Attorney Docket No.: 240026PCT / 7913W001are used to verify the authenticity of the tokens during payment processing. This mechanism prevents unauthorized use of tokens and ensures that only legitimate transactions are processed.

[0024] The method 100 further includes populating 104 the payment data input fields on the checkout page 207 with values based on the retrieved tokenized payment data. The method 100 further includes submitting 105 the filled payment data to the merchant backend system 206 for processing. The dynamic token data autofill eliminates the static card data in remote e-commerce transaction, improves security and authentication success rate. Further, the dynamic token data autofill eliminates the manual payment data entry on web page, improves convenience and reduces cart abandonment.

[0025] The method 100 streamlines integration with various browsers through the use of existing autofill functionalities and standardized HTML tags for payment fields. The browsing environment 201 may detect these tags and initiate the token retrieval process from the secure tokenization platform 202. This approach eliminates the need for merchants to integrate directly with the secure tokenization platform 202, simplifying the adoption process and expanding the reach of the solution.

[0026] The browsing environment 201 may act as a bridge between a merchant's checkout page 207 and the secure tokenization platform 202, securely transmitting tokenized payment data without requiring any modifications to the merchant's backend systems 206.Accordingly, the method 100 is compatible with a wide range of browsers, including those embedded within smartphone applications, further enhancing its ubiquity. The browser's role as an intermediary simplifies the integration process and ensures compatibility across various platforms and merchant websites. This approach minimizes the development effort required for both merchants and browser developers, promoting wider adoption and a more seamless user experience.

[0027] The method 100 may further include completing 106 the transaction by forwarding the tokenized payment data to a payment processor. In one embodiment, the checkout page 207 submits the payment data input fields value to merchant backend system 206. The filled payment data, which is in tokenized form, is transmitted to the merchant backend for processing. The merchant, however, remains agnostic to the tokenization process and receives the data as if it were manually entered by the user. The merchant uses the received token data to start a remote ecommerce transaction with its payment service provider and acquirer through a Payment Service Provider (PSP) acquirer 209, for example. Acquirer sends the transaction to the payment network 204. Payment network 204 calls the token- 6 - 322114733.1Attorney Docket No.: 240026PCT / 7913W001vault 203 to detokenize the token and verify the token cryptogram. Additionally, the payment network 204 sends the transaction with de-tokenized PAN to issuer 205 for authorization.

[0028] One general aspect includes a method for facilitating online payments. The method also includes detecting, by a browsing environment, payment data input fields on a checkout page within the browsing environment; sending, by the browsing environment, a user identifier to a tokenization platform; retrieving, by the browsing environment, a tokenized payment data generated by the tokenization platform based on the user identifier; populating, by the browsing environment, the payment data input fields on the checkout page with values based on the retrieved tokenized payment data. The method also includes submitting, by the browsing environment, the values to a merchant backend system for processing. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the methods.

[0029] Implementations may include one or more of the following features. The method where the user identifier may include one or more of an email address, a phone number, or an account identifier. The method may include authenticating the user with a one-time password (otp) based determining that the user identifier is sent from an unrecognized device. The tokenized payment data may include: a token; and a token cryptogram to verify authenticity of the token during payment processing. The tokenized payment data may include a dynamic token that expires after a predefined period or a single-use. The tokenized payment data may include the token and the token cryptogram. Sending the user identifier is contingent upon the user being logged into the browsing environment. Implementations of the described techniques may include hardware, a method or process, or computer software on a computer-accessible medium.

[0030] One general aspect includes a system. The system also includes a tokenization platform; and a browsing environment configured to: load a checkout form; detect payment data input fields on the checkout form; transmit a user identifier associated with a user to the tokenization platform to obtain a tokenized payment data associated with the user identifier from the tokenization platform, the transmission contingent upon a log in status of the user within the browsing environment; and populate the payment data input fields on the checkout form with values based on the tokenized payment data. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the methods.- 7 - 322114733.1Attorney Docket No.: 240026PCT / 7913W001

[0031] Implementations may include one or more of the following features. The system where the user identifier may include one or more of an email address, a phone number, or an account identifier. The tokenization platform is configured to authenticate the user with a one-time password (otp) based determining that the user identifier is sent from an unrecognized device. The tokenized payment data may include: a token; and a token cryptogram to verify authenticity of the token during payment processing. The tokenized payment data may include a dynamic token that expires after a predefined period or a single-use. The tokenization platform is configured to: query a database to retrieve a token based on the user identifier; and request a token vault to generate a token cryptogram associated with the token, where the tokenized payment data may include the token and the token cryptogram. The browsing environment is configured to determine that the user is logged into the browsing environment, or prompt the user to log into the browsing environment, and where transmitting the user identifier is contingent upon the user being logged into the browser environment. The browsing environment is further configured to submit the values to a merchant backend system for processing. The tokenization platform may include a database storing tokens and corresponding user identifiers, and where the tokenization platform is configured to query a database to retrieve a token based on the user identifier. Implementations of the described techniques may include hardware, a method or process, or computer software on a computer-accessible medium.

[0032] One general aspect includes a method. The method also includes storing, by a tokenization platform, in a database, user identifiers and corresponding tokens, the user identifiers associated with users authenticated by trusted browsing environments, and the corresponding tokens based on payment data associated with the users; receiving, by the tokenization platform, a user identifier from one of the trusted browsing environments; querying, by the tokenization platform, the database to retrieve a token based on the user identifier; requesting, by the tokenization platform, a token vault to generate a token cryptogram for verifying authenticity of the token during payment processing; and transmitting, by the tokenization platform, tokenized payment data to the one of the trusted browsing environments, the tokenized payment data may include the token and the token cryptogram. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the methods.

[0033] Implementations may include one or more of the following features. The method may include: determining, by the tokenization platform, that the user identifier is from an unrecognized device; and based on the determination, performing, by the tokenization-8 - 322114733.1Attorney Docket No.: 240026PCT / 7913WG01platform, a one-time password (OTP) authentication. The user identifier may include one or more of an email address, a phone number, or an account identifier. Implementations of the described techniques may include hardware, a method or process, or computer software on a computer-accessible medium.

[0034] The aforementioned systems and methods may be deployed and executed by one or more servers or computer apparatuses shown in FIGS. 3 and 4 and described in the accompanying text.

[0035] FIG. 3 is a block diagram of a computer apparatus 800 with data processing subsystems or components, according to at least one aspect of the present disclosure. The subsystems are interconnected via a system bus 810. Additional subsystems such as a printer 818, keyboard 826, fixed disk 828 (or other memory comprising computer readable media), monitor 822, which is coupled to a display adapter 820, and others are shown. Peripherals and input / output (I / O) devices, which couple to an I / O controller 812 (which can be a processor or other suitable controller), can be connected to the computer system by any number of means known in the art, such as a serial port 824. For example, the serial port 824 or external interface 830 can be used to connect the computer apparatus to a wide area network such as the Internet, a mouse input device, or a scanner. The interconnection via system bus allows the central processor 816 to communicate with each subsystem and to control the execution of instructions from system memory 814 or the fixed disk 828, as well as the exchange of information between subsystems. The system memory 814 and / or the fixed disk 828 may embody a computer readable medium.

[0036] FIG. 4 is a diagrammatic representation of an example system 900 that includes a host machine 902 within which a set of instructions to perform any one or more of the methodologies discussed herein may be executed, according to at least one aspect of the present disclosure. In various aspects, the host machine 902 operates as a standalone device or may be connected (e.g., networked) to other machines. In a networked deployment, the host machine 902 may operate in the capacity of a server or a client machine in a server-client network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. The host machine 802 may be a computer or computing device, a personal computer (PC), a tablet PC, a set-top box (STB), a personal digital assistant (PDA), a cellular telephone, a portable music player (e.g., a portable hard drive audio device such as an Moving Picture Experts Group Audio Layer 3 (MP3) player), a web appliance, a network router, switch or bridge, or any machine capable of executing a set of instructions (sequential or otherwise) that specify actions to be taken by that machine.Further, while only a single machine is illustrated, the term “machine” shall also be taken to -9 - 322114733.1Attorney Docket No.: 240026PCT / 7913W001include any collection of machines that individually or jointly execute a set (or multiple sets) of instructions to perform any one or more of the methodologies discussed herein.

[0037] The example system 900 includes the host machine 902, running a host operating system (OS) 904 on a processor or multiple processor(s) / processor core(s) 906 (e.g., a central processing unit (CPU), a graphics processing unit (GPU), or both), and various memory nodes 908. The host OS 904 may include a hypervisor 910 which is able to control the functions and / or communicate with a virtual machine (“VM”) 912 running on machine readable media. The VM 912 also may include a virtual CPU or vCPU 914. The memory nodes 908 may be linked or pinned to virtual memory nodes or vNodes 916. When the memory node 908 is linked or pinned to a corresponding vNode 916, then data may be mapped directly from the memory nodes 908 to their corresponding vNodes 916.

[0038] All the various components shown in host machine 902 may be connected with and to each other, or communicate to each other via a bus (not shown) or via other coupling or communication channels or mechanisms. The host machine 902 may further include a video display, audio device or other peripherals 918 (e.g., a liquid crystal display (LCD), alphanumeric input device(s) including, e.g., a keyboard, a cursor control device, e.g., a mouse, a voice recognition or biometric verification unit, an external drive, a signal generation device, e.g., a speaker,) a persistent storage device 920 (also referred to as disk drive unit), and a network interface device 922. The host machine 902 may further include a data encryption module (not shown) to encrypt data. The components provided in the host machine 902 are those typically found in computer systems that may be suitable for use with aspects of the present disclosure and are intended to represent a broad category of such computer components that are known in the art. Thus, the system 900 can be a server, minicomputer, mainframe computer, or any other computer system. The computer may also include different bus configurations, networked platforms, multi-processor platforms, and the like. Various operating systems may be used including UNIX, LINUX, WINDOWS, QNX ANDROID, IOS, CHROME, TIZEN, and other suitable operating systems.

[0039] The disk drive unit 924 also may be a Solid-state Drive (SSD), a hard disk drive (HDD) or other includes a computer or machine-readable medium on which is stored one or more sets of instructions and data structures (e.g., data / instructions 926) embodying or utilizing any one or more of the methodologies or functions described herein. The data / instructions 926 also may reside, completely or at least partially, within the main memory node 908 and / or within the processor(s) 906 during execution thereof by the host machine 902. The data / instructions 926 may further be transmitted or received over a- 10 - 322114733.1Attorney Docket No.: 240026PCT / 7913W001network 928 via the network interface device 922 utilizing any one of several well-known transfer protocols (e.g., Hyper Text Transfer Protocol (HTTP)).

[0040] The processor(s) 906 and memory nodes 908 also may comprise machine-readable media. The term "computer-readable medium" or “machine-readable medium” should be taken to include a single medium or multiple medium (e.g., a centralized or distributed database and / or associated caches and servers) that store the one or more sets of instructions. The term "computer-readable medium" shall also be taken to include any medium that is capable of storing, encoding, or carrying a set of instructions for execution by the host machine 902 and that causes the host machine 902 to perform any one or more of the methodologies of the present application, or that is capable of storing, encoding, or carrying data structures utilized by or associated with such a set of instructions. The term ’’computer-readable medium” shall accordingly be taken to include, but not be limited to, solid-state memories, optical and magnetic media, and carrier wave signals. Such media may also include, without limitation, hard disks, floppy disks, flash memory cards, digital video disks, random access memory (RAM), read only memory (ROM), and the like. The example aspects described herein may be implemented in an operating environment comprising software installed on a computer, in hardware, or in a combination of software and hardware.

[0041] One skilled in the art will recognize that Internet service may be configured to provide Internet access to one or more computing devices that are coupled to the Internet service, and that the computing devices may include one or more processors,buses, memory devices, display devices, input / output devices, and the like. Furthermore, those skilled in the art may appreciate that the Internet service may be coupled to one or more databases, repositories, servers, and the like, which may be utilized to implement any of the various aspects of the disclosure as described herein.

[0042] The computer program instructions also may be loaded onto a computer, a server, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable apparatus or other devices to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0043] Suitable networks may include or interface with any one or more of, for instance, a local intranet, a PAN (Personal Area Network), a LAN (Local Area Network), a WAN (Wide Area Network), a MAN (Metropolitan Area Network), a virtual private network (VPN), a - 11 - 322114733.1Attorney Docket No.: 240026PCT / 7913WG01storage area network (SAN), a frame relay connection, an Advanced Intelligent Network (AIN) connection, a synchronous optical network (SONET) connection, a digital T1, T3, E1 or E3 line, Digital Data Service (DDS) connection, DSL (Digital Subscriber Line) connection, an Ethernet connection, an ISDN (Integrated Services Digital Network) line, a dial-up port such as a V.90, V.34 or V.34bis analog modem connection, a cable modem, an ATM (Asynchronous Transfer Mode) connection, or an FDDI (Fiber Distributed Data Interface) or CDDI (Copper Distributed Data Interface) connection. Furthermore, communications may also include links to any of a variety of wireless networks, including WAP (Wireless Application Protocol), GPRS (General Packet Radio Service), GSM (Global System for Mobile Communication), CDMA (Code Division Multiple Access) orTDMA (Time Division Multiple Access), cellular phone networks, GPS (Global Positioning System), CDPD (cellular digital packet data), RIM (Research in Motion, Limited) duplex paging network, Bluetooth radio, or an IEEE 802.11 -based radio frequency network. The network 930 can further include or interface with any one or more of an RS-232 serial connection, an IEEE-1394 (Firewire) connection, a Fiber Channel connection, an IrDA (infrared) port, a SCSI (Small Computer Systems Interface) connection, a USB (Universal Serial Bus) connection or other wired or wireless, digital or analog interface or connection, mesh or Digi® networking.

[0044] In general, a cloud-based computing environment is a resource that typically combines the computational power of a large grouping of processors (such as within web servers) and / or that combines the storage capacity of a large grouping of computer memories or storage devices. Systems that provide cloud-based resources may be utilized exclusively by their owners or such systems may be accessible to outside users who deploy applications within the computing infrastructure to obtain the benefit of large computational or storage resources.

[0045] The cloud is formed, for example, by a network of web servers that comprise a plurality of computing devices, such as the host machine 902, with each server 930 (or at least a plurality thereof) providing processor and / or storage resources. These servers manage workloads provided by multiple users (e.g., cloud resource customers or other users). Typically, each user places workload demands upon the cloud that vary in real-time, sometimes dramatically. The nature and extent of these variations typically depends on the type of business associated with the user.

[0046] It is noteworthy that any hardware platform suitable for performing the processing described herein is suitable for use with the technology. The terms “computer-readable storage medium” and “computer-readable storage media” as used herein refer to any medium or media that participate in providing instructions to a CPU for execution. Such- 12 - 322114733.1Attorney Docket No.: 240026PCT / 7913W001media can take many forms, including, but not limited to, non-volatile media, volatile media, and transmission media. Non-volatile media include, for example, optical or magnetic disks, such as a fixed disk. Volatile media include dynamic memory, such as system RAM.Transmission media include coaxial cables, copper wire and fiber optics, among others, including the wires that comprise one aspect of a bus. Transmission media can also take the form of acoustic or light waves, such as those generated during radio frequency (RF) and infrared (IR) data communications. Common forms of computer-readable media include, for example, a flexible disk, a hard disk, magnetic tape, any other magnetic medium, a CD-ROM disk, digital video disk (DVD), any other optical medium, any other physical medium with patterns of marks or holes, a RAM, a PROM, an EPROM, an EEPROM, a FLASH EPROM, any other memory chip or data exchange adapter, a carrier wave, or any other medium from which a computer can read.

[0047] Various forms of computer-readable media may be involved in carrying one or more sequences of one or more instructions to a CPU for execution. A bus carries the data to system RAM, from which a CPU retrieves and executes the instructions. The instructions received by system RAM can optionally be stored on a fixed disk either before or after execution by a CPU.

[0048] Computer program code for carrying out operations for aspects of the present technology may be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++, or the like and conventional procedural programming languages, such as the "C" programming language, Go, Python, or other programming languages, including assembly languages. The program code may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (for example, through the Internet using an Internet Service Provider).- 13 - 322114733.1

Claims

Attorney Docket No.: 240026PCT / 7913W001CLAIMSWhat is claimed is:

1. A method for facilitating online payments, the method comprising:detecting, by a browsing environment, payment data input fields on a checkout page within the browsing environment;sending, by the browsing environment, a user identifier to a tokenization platform; retrieving, by the browsing environment, a tokenized payment data generated by the tokenization platform based on the user identifier;populating, by the browsing environment, the payment data input fields on the checkout page with values based on the retrieved tokenized payment data; and submitting, by the browsing environment, the values to a merchant backend system for processing.

2. The method of claim 1, wherein the user identifier comprises one or more of an email address, a phone number, or an account identifier.

3. The method of claim 1, further comprising authenticating the user with a one-time password (OTP) based determining that the user identifier is sent from an unrecognized device.

4. The method of claim 1, wherein the tokenized payment data comprise:a token; anda token cryptogram to verify authenticity of the token during payment processing.

5. The method of claim 1, wherein the tokenized payment data comprises a dynamic token that expires after a predefined period or a single-use.

6. The method of claim 1 , further comprising:querying a database associated with the tokenization platform to retrieve a token based on the user identifier; andrequesting a token vault to generate a token cryptogram, wherein the tokenized payment data comprise the token and the token cryptogram.

7. The method of claim 1 , further comprising:- 14 - 322114733.1Attorney Docket No.: 240026PCT / 7913W001determining that a user is logged into the browsing environment, or prompting the user to log into the browsing environment, wherein sending the user identifier is contingent upon the user being logged into the browsing environment.

8. A system, comprising:a tokenization platform; anda browsing environment configured to:load a checkout form;detect payment data input fields on the checkout form;transmit a user identifier associated with a user to the tokenization platform to obtain a tokenized payment data associated with the user identifier from the tokenization platform, the transmission contingent upon a log in status of the user within the browsing environment; andpopulate the payment data input fields on the checkout form with values based on the tokenized payment data.

9. The system of Claim 8, wherein the user identifier comprises one or more of an email address, a phone number, or an account identifier.

10. The system of claim 8, wherein the tokenization platform is configured to authenticate the user with a one-time password (OTP) based determining that the user identifier is sent from an unrecognized device.

11. The system of claim 8, wherein the tokenized payment data comprise:a token; anda token cryptogram to verify authenticity of the token during payment processing.

12. The system of claim 8, wherein the tokenized payment data comprises a dynamic token that expires after a predefined period or a single-use.

13. The system of claim 8, further comprising a token vault, wherein the tokenization platform is configured to:query a database to retrieve a token based on the user identifier; andrequest a token vault to generate a token cryptogram associated with the token, wherein the tokenized payment data comprise the token and the token cryptogram.- 15 - 322114733.1Attorney Docket No.: 240026PCT / 7913W00114. The system of claim 8, wherein the browsing environment is configured to determine that the user is logged into the browsing environment, or prompt the user to log into the browsing environment, and wherein transmitting the user identifier is contingent upon the user being logged into the browser environment.

15. The system of Claim 8, wherein the browsing environment is further configured to submit the values to a merchant backend system for processing.

16. The system of claim 8, wherein the tokenization platform comprises a database storing tokens and corresponding user identifiers, and wherein the tokenization platform is configured to query a database to retrieve a token based on the user identifier.

17. A method, comprising:storing, by a tokenization platform, in a database, user identifiers and corresponding tokens, the user identifiers associated with users authenticated by trusted browsing environments, and the corresponding tokens based on payment data associated with the users;receiving, by the tokenization platform, a user identifier from one of the trusted browsing environments;querying, by the tokenization platform, the database to retrieve a token based on the user identifier;requesting, by the tokenization platform, a token vault to generate a token cryptogram for verifying authenticity of the token during payment processing; and transmitting, by the tokenization platform, tokenized payment data to the one of the trusted browsing environments, the tokenized payment data comprising the token and the token cryptogram.

18. The method of Claim 17, further comprising:determining, by the tokenization platform, that the user identifier is from an unrecognized device; andbased on the determination, performing, by the tokenization platform, a one-time password (OTP) authentication.

19. The method of claim 17, wherein the user identifier comprises one or more of an email address, a phone number, or an account identifier.- 16 - 322114733.1Attorney Docket No.: 240026PCT / 7913W00120. The method of Claim 17, wherein the token is a dynamic token that expires after a predefined period or a single-use.- 17 - 322114733.1