Method and system for payment with secure credentials
Patent Information
- Application Number
- PCT/US2025/017008
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2026-08-27
Smart Images

Figure US2025017008_27082026_PF_FP_ABST
Abstract
Description
Attorney Docket No. 240027PCT-9327W001TITLE METHOD AND SYSTEM FOR PAYMENT WITH SECURE CREDENTIALSTECHNICAL FIELD
[0001] The following disclosure relates generally to systems and methods for processing contactless payment transactions.SUMMARY
[0002] One general aspect includes a computer-implemented method includes obtaining, through a single instance of contactless payment, a payment credential from a cardholder payment instrument. The method also includes authorizing, based on the single instance of contactless payment, a payment transaction using the payment credential. The method also includes generating, based on the single instance of contactless payment, a tokenized credential corresponding to the payment credential using a certified payment network tokenization service. The method also includes storing, based on the single instance of contactless payment, the tokenized credential in a credential-on-file database for subsequent payment transactions. Other embodiments of this aspect may include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices for performing one or more steps of the computer-implemented method.
[0003] Implementations of the computer-implemented may also include one or more of the following steps. The computer-implemented method may include prompting the cardholder to provide consent for storing the tokenized credential. Authorizing the payment transaction and generating the tokenized credential are performed concurrently based on the single instance of contactless payment.Obtaining the payment credential may include: wirelessly detecting the cardholder payment instrument via a contactless interface; authenticating the cardholder payment instrument; and receiving the payment credential from the cardholder payment instrument. The single instance of contactless payment may include a single tap payment by the cardholder payment instrument on a tap-to-phone device.1322566466.1Attorney Docket No. 240027PCT-9327W001Authorizing the payment transaction may include transmitting the payment credential to a payment network via an acquirer. The computer-implemented method may include initiating subsequent transactions using the tokenized credential stored in the credential-on-file database. The cardholder payment instrument may be a mobile device implementing a tokenized digital wallet. The computer-implemented method may include using the tokenized credential for subsequent payments initiated via a digital wallet. Storing the tokenized credential may include encrypting the credential for secure storage in compliance with payment network security standards.
[0004] One general aspect includes a system that includes a contactless payment terminal configured to: detect an instance of contactless payment by a payment instrument; and wirelessly obtain, in the instance of contactless payment, a payment credential from the payment instrument. The system is configured to initiate two transaction flows based on the payment credentials in the instance of contactless payment. The two transaction flows may include: a first transaction flow for authorizing a payment transaction based on the payment credential, and a second transaction flow for generating a tokenized credential corresponding to the payment credential for future instances of payment based on the payment credential. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices for implementing one or more configurations of the system.
[0005] Implementations of the system may include one or more of the following features. The system may include a user interface configured to prompt for consent to store the payment credential. The contactless payment terminal may include a tap-to-phone device. The contactless payment terminal is configured to concurrently engage the payment authorization module to authorize the payment transaction and the tokenization module to generate the tokenized credential. The system may include a credential storage module configured to store the tokenized credential in a credential-on-file database for the future instances of payment with the payment instrument. The credential storage module is configured to encrypt the tokenized credential before storage in the credential-on-file database.
[0006] One general aspect includes a computer-implemented method that includes obtaining, by an issuer system, first request data from a payment network to process a payment using a payment credential obtained during a single instance of 2322566466.1Attorney Docket No. 240027PCT-9327W001contactless payment by a payment instrument associated with the payment credential. The method also includes authorizing, by the issuer system, the payment based on the first request data. The method also includes obtaining, by the issuer system, second request data from a tokenization service to tokenize the payment credential obtained during the single instance of contactless payment. The method also includes authorizing, by the issuer system, the tokenization service to tokenize the payment credential for future instances of payment involving the payment credential. Other embodiments of this aspect may include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices for performing one or more steps of the computer-implemented method.
[0007] Implementations computer-implemented method may include one or more of the following steps: the computer-implemented method where obtaining, by the issuer system, the first request data is in a payment flow, where obtaining, by the issuer system, the second request data is in a provisioning flow, and where the payment flow and the provisioning flow are based on the single instance of contactless payment. The payment is separate from the provisioning flow.Authorizing, by the issuer system, the tokenization service to tokenize the payment credential is further based on the first request data.BRIEF DESCRIPTION OF THE DRAWINGS
[0008] In the description, for purposes of explanation and not limitation, specific details are set forth, such as particular aspects, procedures, techniques, etc. to provide a thorough understanding of the present technology. However, it will be apparent to one skilled in the art that the present technology may be practiced in other aspects that depart from these specific details.
[0009] The accompanying drawings, where like reference numerals refer to identical or functionally similar elements throughout the separate views, together with the detailed description below, are incorporated in and form part of the specification, and serve to further illustrate aspects of concepts that include the claimed disclosure and explain various principles and advantages of those aspects.
[0010] The systems and methods disclosed herein have been represented where 3322566466.1Attorney Docket No. 240027PCT-9327W001appropriate by conventional symbols in the drawings, showing only those specific details that are pertinent to understanding the various aspects of the present disclosure so as not to obscure the disclosure with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein.
[0011] FIG. 1 is a flow diagram illustrating a computer-implemented method, according to some aspects of the present disclosure.
[0012] FIG. 2 is a system, according to some aspects of the present disclosure.
[0013] FIG. 3 is a flow diagram illustrating a computer-implemented method, according to some aspects of the present disclosure.
[0014] FIG. 4 is a block diagram of a computer apparatus with data processing subsystems or components, according to at least one aspect of the present disclosure.
[0015] FIG. 5 illustrates a system according to some embodiments of the present disclosure.DESCRIPTION
[0016] The following disclosure may provide exemplary systems, devices, and methods for transaction data comparison. Although reference may be made to such financial transactions in the examples provided below, aspects are not so limited. That is, the systems, methods, and apparatuses may be utilized for any suitable purpose.
[0017] Before discussing specific embodiments, aspects, or examples, some descriptions of terms used herein are provided below.
[0018] As used herein, the term “payment network” may refer to an electronic payment system used to accept, transmit, or process transactions made by payment devices for money, goods, or services. The payment network may transfer information and funds among issuers, acquirers, merchants, and payment device users. One illustrative non-limiting example of a payment network is VisaNet, which is operated by Visa, Inc.4322566466.1Attorney Docket No. 240027PCT-9327W001
[0019] As used herein, the term “acquirer system” may refer to one or more computer systems, computer devices, and / or the like operated by or on behalf of an acquirer. The transactions the acquirer may originate may include payment transactions (e.g., purchases, original credit transactions (OCTs), account funding transactions (AFTs), and / or the like). In some non-limiting embodiments or aspects, the acquirer may be authorized by the transaction service provider to assign merchant or service providers to originate transactions using a portable financial device of the transaction service provider. The acquirer may contract with payment facilitators to enable the payment facilitators to sponsor merchants. The acquirer may monitor compliance of the payment facilitators in accordance with regulations of the transaction service provider. The acquirer may conduct due diligence of the payment facilitators and ensure proper due diligence occurs before signing a sponsored merchant. The acquirer may be liable for all transaction service provider programs that the acquirer operates or sponsors. The acquirer may be responsible for the acts of the acquirer's payment facilitators, merchants that are sponsored by an acquirer's payment facilitator, and / or the like. In some non-limiting embodiments or aspects, an acquirer may be a financial institution, such as a bank.
[0020] As used herein “issuer system” or “issuer institution system” may refer to one or more systems operated by or operated on behalf of an issuer. For example, an issuer system may refer to a server executing one or more software applications associated with the issuer. In some non-limiting embodiments or aspects, an issuer system may include one or more servers (e.g., one or more authorization servers) for authorizing a payment transaction.
[0021] As used herein, a “mobile device” may comprise any electronic device that may be transported and operated by a user, which may also provide remote communication capabilities to a network. Examples of remote communication capabilities include using a mobile phone (wireless) network, wireless data network (e.g. 3G, 4G or similar networks), Wi-Fi, Wi-Max, or any other communication medium that may provide access to a network such as the Internet or a private network. Examples of mobile devices include mobile phones (e.g. cellular phones), PDAs, tablet computers, net books, laptop computers, personal music players, handheld specialized readers, etc. Further examples of mobile devices include wearable devices, such as smartwatches, fitness bands, ankle bracelets, rings, earrings, etc.,5322566466.1Attorney Docket No. 240027PCT-9327W001as well as automobiles with remote communication capabilities. A mobile device may comprise any suitable hardware and software for performing such functions, and may also include multiple devices or components (e.g. when a device has remote access to a network by tethering to another device — i.e. using the other device as a modem — both devices taken together may be considered a single mobile device). A mobile device may also comprise a verification token in the form of, for instance, a secured hardware or software component within the mobile device and / or one or more external components that may be coupled to the mobile device. A detailed description of an exemplary mobile device is provided below.
[0022] A “payment instrument” may refer to any device that may be used to conduct a financial transaction, such as to provide payment information to a merchant. A payment device may be in any suitable form. The payment device may be a software object, a hardware object, or a physical object. As examples of physical objects, the payment device may comprise a substrate such as a paper or plastic card, and information that is printed, embossed, encoded, or otherwise included at or near a surface of an object. A hardware object can relate to circuitry (e.g., permanent voltage values), and a software object can relate to non-permanent data stored on a device. For example, suitable payment devices can be hand-held and compact so that they can fit into a consumer's wallet and / or pocket (e.g., pocket-sized). They may include smart cards, debit devices (e.g., a debit card), credit devices (e.g., a credit card), stored value devices (e.g., a stored value card or “prepaid” card), magnetic stripe cards, keychain devices (such as the Speedpass™ commercially available from Exxon-Mobil Corp.), etc. Other examples of payment devices include cellular or wireless telephones (e.g., a smartphone), personal digital assistants (PDAs), portable computer (e.g. tablet or laptop computer), pagers, payment cards, security cards, access cards, smart media, transponders, 2-D barcodes, an electronic or digital wallet, and the like. If the payment device is in the form of a debit, credit, or smartcard, the payment device may also optionally have features such as magnetic stripes. Such devices can operate in either a contact or contactless mode. In some non-limiting embodiments or aspects, a payment device may include an electronic payment device, such as a smartcard, a chip card, integrated circuit card, and / or the like. An electronic payment device may include an embedded integrated circuit and the embedded integrated circuit may include a data6322566466.1Attorney Docket No. 240027PCT-9327W001storage medium (e.g., volatile and / or non-volatile memory) to store information associated with the payment device, such as an account identifier, a name of the account holder, and / or the like. The payment device may interface with an access device such as a point-of-sale device to initiate the transaction. In some embodiments or aspects, a mobile device can function as a payment device (e.g., a mobile device can store and be able to transmit payment credentials for a transaction). Further, a payment device may be associated with a value such as a monetary value, a discount, or store credit, and a payment device may be associated with an entity such as a bank, a merchant, a payment processing network, or a person. A payment device may be used to make a payment transaction.
[0023] As used herein, the term “payment gateway” may refer to an entity and / or a payment processing system operated by or on behalf of such an entity (e.g., a merchant service provider, a payment service provider, a payment facilitator, a payment facilitator that contracts with an acquirer, a payment aggregator, and / or the like), which provides payment services (e.g., transaction service provider payment services, payment processing services, and / or the like) to one or more merchants. The payment services may be associated with the use of portable financial devices managed by a transaction service provider. As used herein, the term “payment gateway system” may refer to one or more computer systems, computer devices, servers, groups of servers, and / or the like, operated by or on behalf of a payment gateway and / or to a payment gateway itself. The term “payment gateway mobile application” may refer to one or more electronic devices and / or one or more software applications configured to provide payment services for transactions (e.g., payment transactions, electronic payment transactions, and / or the like).
[0024] The terms “point-of-sale system,” “POS system,” or “POS terminal,” as used herein, may refer to one or more computers and / or peripheral devices used by a merchant to engage in payment transactions with customers, including one or more card readers, near-field communication (NFC) receivers, radio-frequency identification (RFID) receivers, and / or other contactless transceivers or receivers, contact-based receivers, payment terminals, computers, servers, input devices, and / or other like devices that can be used to initiate a payment transaction. A POS terminal may be located proximal to a user, such as at a physical store location, or a7322566466.1Attorney Docket No. 240027PCT-9327W001POS terminal may be remote from the user, such as a server interacting with a user browsing on their personal computer. POS terminals may include mobile devices.
[0025] An “application” may include any software module configured to perform a specific function or functions when executed by a processor of a computer. For example, a “mobile application” may include a software module that is configured to be operated by a mobile device. Applications may be configured to perform many different functions. For instance, a “payment application” may include a software module that is configured to store and provide account credentials for a transaction. A “wallet application” may include a software module with similar functionality to a payment application that has multiple accounts provisioned or enrolled such that they are usable through the wallet application. Further, an “application” or “application program interface” (API) refers to computer code or other data sorted on a computer-readable medium that may be executed by a processor to facilitate the interaction between software components, such as a client-side front-end and / or server-side back-end for receiving data from the client. An “interface” refers to a generated display, such as one or more graphical user interfaces (GUIs) with which a user may interact, either directly or indirectly (e.g., through a keyboard, mouse, touchscreen, etc.).
[0026] As used herein, the term “server” may include one or more computing devices which can be individual, stand-alone machines located at the same or different locations, may be owned or operated by the same or different entities, and may further be one or more clusters of distributed computers or “virtual” machines housed within a datacenter. It should be understood and appreciated by a person of skill in the art that functions performed by one “server” can be spread across multiple disparate computing devices for various reasons. As used herein, a “server” is intended to refer to all such scenarios and should not be construed or limited to one specific configuration. Further, a server as described herein may, but need not, reside at (or be operated by) a merchant, a payment network, a financial institution, a healthcare provider, a social media provider, a government agency, or agents of any of the aforementioned entities. The term “server” may also refer to or include one or more processors or computers, storage devices, or similar computer arrangements that are operated by or facilitate communication and processing for multiple parties in a network environment, such as the Internet, although it will be appreciated that8322566466.1Attorney Docket No. 240027PCT-9327W001communication may be facilitated over one or more public or private network environments and that various other arrangements are possible. Further, multiple computers, e.g., servers, or other computerized devices, e.g., point-of-sale devices, directly or indirectly communicating in the network environment may constitute a “system,” such as a merchant’s point-of-sale system. Reference to “a server” or “a processor,” as used herein, may refer to a previously recited server and / or processor that is recited as performing a previous step or function, a different server and / or processor, and / or a combination of servers and / or processors. For example, as used in the specification and the claims, a first server and / or a first processor that is recited as performing a first step or function may refer to the same or different server and / or a processor recited as performing a second step or function.
[0027] A “server computer” may typically be a powerful computer or cluster of computers. For example, the server computer can be a large mainframe, a minicomputer cluster, or a group of servers functioning as a unit. The server computer may be associated with an entity such as a payment processing network, a wallet provider, a merchant, an authentication cloud, an acquirer, or an issuer. In one example, the server computer may be a database server coupled to a Web server. The server computer may be coupled to a database and may include any hardware, software, other logic, or combination of the preceding for servicing the requests from one or more client computers. The server computer may comprise one or more computational apparatuses and may use any of a variety of computing structures, arrangements, and compilations for servicing the requests from one or more client computers. In some embodiments or aspects, the server computer may provide and / or support payment network cloud service.
[0028] As used herein, the term “system” may refer to one or more computing devices or combinations of computing devices (e.g., processors, servers, client devices, software applications, components of such, and / or the like).
[0029] A “token” or “payment token” may include an identifier for a payment account that is a substitute for an account identifier, such as a primary account number (PAN). For example, a token may include a series of numeric and / or alphanumeric characters that may be used as a substitute for an original account identifier. In some embodiments or aspects, a token may be “format preserving” and may have a numeric format that conforms to the account identifiers used in existing 9322566466.1Attorney Docket No. 240027PCT-9327W001payment processing networks. In some embodiments or aspects, a token may be used in place of a PAN to initiate, authorize, settle or resolve a payment transaction or represent the original credential in other systems where the original credential would typically be provided. In some embodiments or aspects, a token value may be generated such that the recovery of the original PAN or other account identifier from the token value may not be computationally derived. For example, a token may have a random association with a particular real PAN so that the real PAN is not computationally derivable from the token. A lookup table may be used to associate a real PAN and a corresponding random token. Further, in some embodiments or aspects, the token format may be configured to allow the entity receiving the token to identify it as a token and recognize the entity that issued the token.
[0030] “Tokenization” is a process by which data is replaced with substitute data. For example, a payment account identifier (e.g., a primary account number (PAN)) may be tokenized by replacing the primary account identifier with a substitute number (e.g. a token) that may be associated with the payment account identifier. Further, tokenization may be applied to any other information which may be replaced with a substitute value. Tokenization may be used to enhance transaction efficiency, improve transaction security, increase service transparency, or to provide a method for third-party enablement.
[0031] Contactless payment technologies, including tap-to-phone and mobile wallets, have become widely adopted for their convenience and efficiency. However, the process of securely managing payment credentials during such transactions remains a challenge. Conventional methods often require multiple interactions or compromise security standards when storing payment credentials. The present disclosure addresses these issues by providing a solution for securely authorizing and tokenizing payment credentials during a single instance of contactless payment and enabling their storage for future transactions.
[0032] FIG. 1 illustrates a computer-implemented method 10 for processing contactless payment transactions. One or more steps of the method 10 may be executed by one or more components of a payment network system 100 (FIG. 2). The method 10 includes obtaining 12, through a single instance of contactless payment, a payment credential from a cardholder payment instrument. Once the payment credential is obtained, the method 10 proceeds by authorizing 14, based on 10322566466.1Attorney Docket No. 240027PCT-9327W001the single instance of contactless payment, a payment transaction using the payment credential. The method 10 further includes generating 16, based on the single instance of contactless payment, a tokenized credential corresponding to the payment credential using a tokenization service (e.g., certified payment network tokenization service), and storing 18, based on the single instance of contactless payment, the tokenized credential in a credential-on-file database for subsequent payment transactions.
[0033] In one embodiment, the payment credential may be obtained through an application 112 such as, for example, a touch to pay (TTP) application. For example, Merchant system 108 may include a contactless payment terminal equipped with an NFC interface, which may wirelessly detect a cardholder payment instrument 110, such as an NFC-enabled card, a mobile device with a digital wallet, or a wearable device. The terminal may establish a secure communication session with the payment instrument, authenticates it, and retrieves a payment credential, which may include sensitive information such as the primary account number (PAN), expiration date, and / or dynamic security elements.
[0034] In one embodiment, the terminal transmit may transmit the payment credential to an acquirer system 102, which forwards it to the payment network 104 for further processing. The payment network 104 routes the transaction request to an issuer system 106, which evaluates it based on factors such as fund availability, validation of dynamic security data, and / or fraud detection. Upon approval, the issuer system 106 may send an authorization response back through the payment network 104 and acquirer 102, completing the transaction, as illustrated in the payment flow branch of FIG. 2.
[0035] Concurrently or subsequently, the method 10 generates 16 a tokenized credential corresponding to the payment credential. The terminal or backend system may submit a tokenization request to a certified payment network tokenization service, which replaces the sensitive payment data with a unique token. The tokenized credential may be a random alphanumeric string associated with the original credential and may include metadata such as expiration dates or usage constraints. The tokenization service transmits the tokenized credential back to the terminal or backend system, ensuring enhanced security since the token cannot be used in isolation for fraudulent activities.11322566466.1Attorney Docket No. 240027PCT-9327W001
[0036] Furthermore, the tokenized credential may be stored 18 in a credential-on-file (COF) database for future transactions. Prior to storage, the tokenized credential may be encrypted using advanced cryptographic techniques, such as AES with a 256-bit key, to comply with payment network security standards.
[0037] The stored tokenized credential may be used for recurring billing, subscription payments, or one-click purchases, eliminating the need for the cardholder to re-enter payment details. By integrating authorization, tokenization, and storage into a single instance of contactless payment, the method 10 enhances security, improves efficiency, and ensures scalability and compliance with industry standards.
[0038] In some embodiments, the method 10 may include prompting 19 for consent for storing the tokenized credential. After the payment credential is obtained and the tokenized credential is generated, the system 100 may display a user interface, such as a prompt on the contactless payment terminal or the cardholder's device, requesting explicit consent to store the tokenized credential. This prompt may include details about the purpose of storage, security measures in place, and terms of use. The cardholder can then accept or decline the request. If consent is provided, the system 100 securely stores the tokenized credential in the credential-on-file (COF) database. If consent is denied, the tokenized credential is securely discarded, ensuring compliance with data privacy regulations and user preferences.
[0039] In one embodiment, the method 10 may perform the step of authorizing the payment transaction and generating the tokenized credential concurrently, based on the single instance of contactless payment. Upon obtaining the payment credential from the cardholder's payment instrument, the system 100 initiates two parallel flows. The first flow involves transmitting the payment credential to the acquiring system for transaction authorization, while the second flow sends the payment credential to a certified payment network tokenization service for token generation.
[0040] In one embodiment, obtaining 12 the payment credential is achieved by wirelessly detecting the payment instrument 110 via a contactless interface, such as an NFC (Near Field Communication) interface, embedded in a payment terminal. Once the payment instrument is detected, it is authenticated to verify its legitimacy and ensure compliance with applicable security protocols. Authentication may involve validating the payment instrument’s unique identifier or cryptographic keys.12322566466.1Attorney Docket No. 240027PCT-9327W001Following authentication, the payment credential may be securely received from the payment instrument, using encrypted communication channels to protect the integrity and confidentiality of the data.
[0041] In one embodiment, the method 10 further includes initiating 17 subsequent transactions using the tokenized credential stored in the credential-on-file (COF) database. Once the tokenized credential is securely stored, it can be retrieved to facilitate future payments without requiring the payment instrument 110 to transmit the payment credential.
[0042] Referring to FIG. 2, the payment network system 100 executes provisioning and payment flows based on the single instance of payment by the payment instrument 110. The payment network system 100 may include a payment network 104, an issuer system 106, a payment instrument 110, a merchant system 108, and an acquirer system 102.
[0043] A communication network may provide communication pathways between one or more components of the payment network system 100. As used herein, the term “communication” and “communicate” may refer to the reception, receipt, transmission, transfer, provision, and / or the like of information (e.g., data, signals, messages, instructions, calls, commands, and / or the like). A communication may use a direct or indirect connection and may be wired and / or wireless in nature. As an example, for one unit (e.g., a device, a system, a component of a device or system, combinations thereof, and / or the like) to communicate with another unit means that the one unit is able to directly or indirectly receive information from and / or transmit information to the other unit. The one unit may communicate with the other unit even though the information may be modified, processed, relayed, and / or routed between the one unit and the other unit. In one example, a first unit may communicate with a second unit even though the first unit receives information and does not communicate information to the second unit. For example, a first unit may be in communication with a second unit even though the first unit passively receives data and does not actively transmit data to the second unit. As another example, a first unit may communicate with a second unit if an intermediary unit (e.g., a third unit located between the first unit and the second unit) receives information from the first unit, processes the information received from the first unit to produce processed information, and communicates the processed information to the second unit. In13322566466.1Attorney Docket No. 240027PCT-9327W001some non-limiting embodiments or aspects, a message may refer to a packet (e.g., a data packet, a network packet, and / or the like) that includes data. It will be appreciated that numerous other arrangements are possible.
[0044] In some embodiments, as illustrated in FIG. 2, the payment network system 100 further includes a payment service provider (PSP) system 114 may facilitate electronic payment transactions by acting as an intermediary between merchants and financial institutions, enabling businesses to accept various payment methods such as credit cards, debit cards, bank transfers, digital wallets, and alternative payment options. The PSP system may include a payment gateway, which serves as the front-end interface for capturing and encrypting payment details from customers using industry-standard security protocols. The payment gateway may route transaction data to back-end systems for further processing, offering integration through APIs, hosted checkout pages, or software development kits (SDKs). The PSP system may also incorporate a payment processor responsible for transaction validation, authorization, and settlement. The payment processor may communicate with acquiring banks, issuing banks, and payment networks to execute payment workflows efficiently. It may further employ tokenization and other security measures to safeguard sensitive data, while enabling the management of refunds, reversals, and chargebacks.
[0045] In one embodiment, the merchant application 112 wirelessly obtains 201 a payment credential associated with the payment instrument 110 and initiates a provisioning flow 206 and a payment flow 202 based on the received payment credential. In the payment flow 202, the merchant application 112 transmits a payment authorization payload to the acquirer system 102 that passes the payload, or information based on the payload, to the payment network 104 that, in turn passes the payload, or information based on the payload, to the issuer system 106 for payment authorization.
[0046] In the provisioning flow 206, the merchant application 112 may transmit a provisioning payload to the PSP system 114. The PSP system 114 may be certified token requestor and may transmit 207 a token request to a token service 116 based on the provisioning payload. As described above, the token may include an identifier for a payment account that is a substitute for an account identifier, such as a primary account number (PAN).14322566466.1Attorney Docket No. 240027PCT-9327W001
[0047] Like the payment flow, the provisional flow 206 reaches the issuer system 106 for provisioning 208 authorization. At this point, the payment credential has already been verified through the payment flow 202. Additional risk information captured during payment authorization, may be utilized to categorize the payment credential as authenticated. Accordingly, the payment flow 202 may be utilized in an authentication associated with the provisioning flow 206 at the issuer system 106.
[0048] Once account verification is completed, the issuer system transmits 209 an authorization message to the token service 116 to generate and transmit 210 the token and associated meta-data to the PSP system 114 for sharing with the merchant system 108.
[0049] In one embodiment, the provisioning flow 206 may include a consent request for storing the tokenized credential for future transactions. The merchant application 112 may utilize a user interface at the payment terminal to secure the consent or may wirelessly transmit 205 a consent message to the payment instrument 110. If consent is provided, the system 100 securely stores the tokenized credential in the credential-on-file (COF) database. If consent is denied, the tokenized credential is securely discarded, ensuring compliance with data privacy regulations and user preferences.
[0050] Referring to FIG. 3, a computer-implemented method 300, which may be executed in whole or part by one or more components of the system 100, includes obtaining 302, by an issuer system 106, first request data from a payment network 104 to process a payment using a payment credential obtained during a single instance of contactless payment by a payment instrument 110 associated with the payment credential. The method 300 further includes authorizing 304, by the issuer system, the payment based on the first request data. The method 300 further includes obtaining 306, by the issuer system, second request data from a tokenization service to tokenize the payment credential obtained during the single instance of contactless payment, and authorizing 308, by the issuer system, the tokenization service to tokenize the payment credential for future instances of payment involving the payment credential.
[0051] In one embodiment, obtaining, by the issuer system, the first request data is in a payment flow, and obtaining, by the issuer system, the second request data is in a provisioning flow. Further, the payment flow and the provisioning flow may be 15322566466.1Attorney Docket No. 240027PCT-9327W001based on the same single instance of contactless payment. Moreover, the payment flow may be separate from the provisioning flow. In one embodiment, authorizing, by the issuer system, the tokenization service to tokenize the payment credential is further based on the first request data.
[0052] The systems and methods, as described in connection with FIGS. 1-3 may include, or make use of, a number of computer apparatuses, computer systems, or the like. In other words, to utilize the systems and methods disclosed herein, at least one of a computer apparatus, computer system, or the like may be implemented. Each of these computer apparatuses, computer systems, or the like are described in greater detail below with respect to the computer apparatus 800 shown in FIG. 4 and the example system 900 shown in FIG. 5, which provide a connection between the solution disclosed herein and how such a solution may be implemented within a business entity, such as a payment network, a processing network, a payment processing network, or the like.
[0053] FIG. 4 is a block diagram of a computer apparatus 800 with data processing subsystems or components, according to at least one aspect of the present disclosure. The subsystems shown in FIG. 4 are interconnected via a system bus 810. Additional subsystems such as a printer 818, keyboard 826, fixed disk 828 (or other memory comprising computer-readable media), monitor 822 (which is coupled to a display adapter 820), and others are shown. Peripherals and input / output (I / O) devices, which couple to an I / O controller 812 (which can be a processor or other suitable controller), can be connected to the computer system by any number of means known in the art, such as a serial port 824. For example, the serial port 824 or external interface 830 can be used to connect the computer apparatus to a wide area network such as the Internet, a mouse input device, or a scanner. The interconnection via system bus 810 allows the central processor 816 to communicate with each subsystem and to control the execution of instructions from system memory 814 or the fixed disk 828, as well as the exchange of information between subsystems. The system memory 814 and / or the fixed disk 828 may embody a computer-readable medium.
[0054] FIG. 5 is a diagrammatic representation of an example system 900 that includes a host machine 902 within which a set of instructions to perform any one or16322566466.1Attorney Docket No. 240027PCT-9327W001more of the methodologies discussed herein may be executed, according to at least one aspect of the present disclosure. In various aspects, the host machine 902 operates as a stand-alone device or may be connected (e.g., networked) to other machines. In a networked deployment, the host machine 902 may operate in the capacity of a server or a client machine in a server-client network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. The host machine 902 may be a computer or computing device, a personal computer (PC); a tablet PC; a set-top box; a personal digital assistant; a cellular telephone; a portable music player (e.g., a portable hard drive audio device, such as an Moving Picture Experts Group Audio Layer 3 (MP3) player); a web appliance; a network router, switch, or bridge; or any machine capable of executing a set of instructions (sequential or otherwise) that specify actions to be taken by that machine. Further, while only a single machine is illustrated, the term “machine” shall also be taken to include any collection of machines that individually or jointly execute a set (or multiple sets) of instructions to perform any one or more of the methodologies discussed herein.
[0055] The example system 900 includes the host machine 902, running a host operating system (OS) 904 on a processor or multiple processor(s) / processor core(s) 906 (e.g., a central processing unit (CPU), a graphics processing unit, or both), and various memory nodes 908. The host OS 904 may include a hypervisor 910, which is able to control the functions and / or communicate with a virtual machine (VM) 912 running on machine-readable media. The VM 912 also may include a virtual CPU or vCPU 914. The memory nodes 908 may be linked or pinned to virtual memory nodes or vNodes 916. When the memory node 908 is linked or pinned to a corresponding vNode 916, then data may be mapped directly from the memory nodes 908 to their corresponding vNodes 916.
[0056] All the various components shown in host machine 902 may be connected with and to each other or communicate to each other via a bus (not shown) or via other coupling or communication channels or mechanisms. The host machine 902 may further include a video display, audio device, or other peripherals 918 (e.g., a liquid crystal display; alpha-numeric input device(s) including, e.g., a keyboard; a cursor control device, e.g., a mouse; a voice recognition or biometric verification unit;17322566466.1Attorney Docket No. 240027PCT-9327W001an external drive; a signal generation device, e.g., a speaker); a persistent storage device 920 (also referred to as disk drive unit); and a network interface device 922. The host machine 902 may further include a data encryption module (not shown) to encrypt data. The components provided in the host machine 902 are those typically found in computer systems that may be suitable for use with aspects of the present disclosure and are intended to represent a broad category of such computer components that are known in the art. Thus, the system 900 can be a server, minicomputer, mainframe computer, or any other computer system. The computer may also include different bus configurations, networked platforms, multi-processor platforms, and the like. Various OSs may be used, including UNIX, LINUX, WINDOWS, QNX ANDROID, IOS, CHROME, TIZEN, and other suitable OSs.
[0057] The disk drive unit 924 also may be a solid-state drive, a hard disk drive, or other drive that includes a computer or machine-readable medium on which is stored one or more sets of instructions and data structures (e.g., data / instructions 926) embodying or utilizing any one or more of the methodologies or functions described herein. The data / instructions 926 also may reside, completely or at least partially, within the main memory node 908 and / or within the processor(s) 906 during execution thereof by the host machine 902. The data / instructions 926 may further be transmitted or received over a network 928 via the network interface device 922 utilizing any one of several well-known transfer protocols (e.g., Hyper Text Transfer Protocol (HTTP)).
[0058] The processor(s) 906 and memory nodes 908 also may comprise machine-readable media. The term “computer-readable medium” or “machine-readable medium” should be taken to include a single medium or multiple medium (e.g., a centralized or distributed database and / or associated caches and servers) that store the one or more sets of instructions. The term “computer-readable medium” shall also be taken to include any medium that is capable of storing, encoding, or carrying a set of instructions for execution by the host machine 902 and that causes the host machine 902 to perform any one or more of the methodologies of the present application or that is capable of storing, encoding, or carrying data structures utilized by or associated with such a set of instructions. The term “computer-readable medium” shall accordingly be taken to include, but not be limited18322566466.1Attorney Docket No. 240027PCT-9327W001to, solid-state memories, optical and magnetic media, and carrier wave signals. Such media may also include, without limitation, hard disks, floppy disks, flash memory cards, digital video disks, random access memory (RAM), read-only memory (ROM), and the like. The example aspects described herein may be implemented in an operating environment comprising software installed on a computer, in hardware, or in a combination of software and hardware.
[0059] One skilled in the art will recognize that Internet service may be configured to provide Internet access to one or more computing devices that are coupled to the Internet service and that the computing devices may include one or more processors, buses, memory devices, display devices, I / O devices, and the like.Furthermore, those skilled in the art may appreciate that the Internet service may be coupled to one or more databases, repositories, servers, and the like, which may be utilized to implement any of the various aspects of the disclosure as described herein.
[0060] The computer program instructions also may be loaded onto a computer, a server, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable apparatus, or other devices to produce a computer-implemented process such that the instructions that execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0061] Suitable networks may include or interface with any one or more of, for instance, a local intranet; a personal area network (PAN); a local area network (LAN); a wide area network (WAN); a metropolitan area network (MAN); a virtual private network (VPN); a storage area network (SAN); a frame relay connection; an advanced intelligent network (AIN) connection; a synchronous optical network (SONET) connection; a digital T1, T3, E1, or E3 line; a digital data service (DDS) connection; a digital subscriber line (DSL) connection; an Ethernet connection; an integrated services digital network (ISDN) line; a dial-up port, such as a V.90, V.34, or V.34bis analog modem connection; a cable modem; an Asynchronous Transfer Mode (ATM) connection; or an Fiber Distributed Data Interface (FDDI) or Copper Distributed Data Interface (CDDI) connection. Furthermore, communications may 19322566466.1Attorney Docket No. 240027PCT-9327W001also include links to any of a variety of wireless networks, including Wireless Application Protocol (WAP), General Packet Radio Service (GPRS), Global System for Mobile Communication (GSM), Code Division Multiple Access (CDMA) or Time Division Multiple Access (TDMA), cellular phone networks, global positioning system (GPS), cellular digital packet data (CDPD), Research in Motion, Limited (RIM) duplex paging network, Bluetooth radio, or an Institute of Electrical and Electronics Engineers (IEEE) 802.11 -based radio frequency (RF) network. The network 928 can further include or interface with any one or more of an RS-232 serial connection, an IEEE-1394 (Firewire) connection, a Fiber Channel connection, an IrDA (infrared (IR)) port, a Small Computer Systems Interface (SCSI) connection, a Universal Serial Bus (USB) connection or other wired or wireless, digital, or analog interface or connection, mesh, or Digi® networking.
[0062] In general, a cloud-based computing environment is a resource that typically combines the computational power of a large grouping of processors (such as within web servers) and / or that combines the storage capacity of a large grouping of computer memories or storage devices. Systems that provide cloud-based resources may be utilized exclusively by their owners or such systems may be accessible to outside users who deploy applications within the computing infrastructure to obtain the benefit of large computational or storage resources.
[0063] The cloud is formed, for example, by a network of web servers that comprise a plurality of computing devices, such as the host machine 902, with each server 930 (or at least a plurality thereof) providing processor and / or storage resources. These servers manage workloads provided by multiple users (e.g., cloud resource customers or other users). Typically, each user places workload demands upon the cloud that vary in real-time, sometimes dramatically. The nature and extent of these variations typically depends on the type of business associated with the user.
[0064] It is noteworthy that any hardware platform suitable for performing the processing described herein is suitable for use with the technology. The terms “computer-readable storage medium” and “computer-readable storage media” as used herein refer to any medium or media that participate in providing instructions to a CPU for execution. Such media can take many forms, including, but not limited to,20322566466.1Attorney Docket No. 240027PCT-9327W001non-volatile media, volatile media, and transmission media. Non-volatile media include, for example, optical or magnetic disks, such as a fixed disk. Volatile media include dynamic memory, such as system RAM. Transmission media include coaxial cables, copper wire and fiber optics, among others, including the wires that comprise one aspect of a bus. Transmission media can also take the form of acoustic or light waves, such as those generated during RF and IR data communications. Common forms of computer-readable media include, for example, a flexible disk, a hard disk, magnetic tape, any other magnetic medium, a compact disc ROM (CD-ROM) disk, digital video disc, any other optical medium, any other physical medium with patterns of marks or holes, a RAM, a programmable ROM, an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), a FLASH EPROM, any other memory chip or data exchange adapter, a carrier wave, or any other medium from which a computer can read.
[0065] Various forms of computer-readable media may be involved in carrying one or more sequences of one or more instructions to a CPU for execution. A bus carries the data to system RAM, from which a CPU retrieves and executes the instructions. The instructions received by system RAM can optionally be stored on a fixed disk either before or after execution by a CPU.
[0066] Computer program code for carrying out operations for aspects of the present technology may be written in any combination of one or more programming languages, including an object-oriented programming language such as Java, Smalltalk, C++, or the like and conventional procedural programming languages, such as the “C” programming language, Go, Python, or other programming languages, including assembly languages. The program code may execute entirely on the user’s computer, partly on the user’s computer, as a stand-alone software package, partly on the user’s computer and partly on a remote computer, or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the user’s computer through any type of network, including a LAN or a WAN, or the connection may be made to an external computer (for example, through the Internet using an Internet service provider).
[0067] The foregoing detailed description has set forth various forms of the systems and / or processes via the use of block diagrams, flowcharts, and / or21322566466.1Attorney Docket No. 240027PCT-9327W001examples. Insofar as such block diagrams, flowcharts, and / or examples contain one or more functions and / or operations, it will be understood by those within the art that each function and / or operation within such block diagrams, flowcharts, and / or examples can be implemented, individually and / or collectively, by a wide range of hardware, software, firmware, or virtually any combination thereof. Those skilled in the art will recognize that some aspects of the forms disclosed herein, in whole or in part, can be equivalently implemented in integrated circuits as one or more computer programs running on one or more computers (e.g., as one or more programs running on one or more computer systems), as one or more programs running on one or more processors (e.g., as one or more programs running on one or more microprocessors), as firmware, or as virtually any combination thereof, and that designing the circuitry and / or writing the code for the software and or firmware would be well within the skill of one of skilled in the art in light of this disclosure. In addition, those skilled in the art will appreciate that the mechanisms of the subject matter described herein are capable of being distributed as one or more program products in a variety of forms, and an illustrative form of the subject matter described herein applies regardless of the particular type of signal-bearing medium used to actually carry out the distribution.
[0068] Instructions used to program logic to perform various disclosed aspects can be stored within a memory in the system, such as dynamic RAM, cache, flash memory, or other storage. Furthermore, the instructions can be distributed via a network or by way of other computer-readable media. Thus a machine-readable medium may include any mechanism for storing or transmitting information in a form readable by a machine (e.g., a computer), including, but not limited to, floppy diskettes, optical disks, CD-ROMs, magneto-optical disks, ROM, RAM, EPROM, EEPROM, magnetic or optical cards, flash memory, or a tangible, machine-readable storage used in the transmission of information over the Internet via electrical, optical, acoustical, or other forms of propagated signals (e.g., carrier waves, IR signals, digital signals). Accordingly, the non-transitory computer-readable medium includes any type of tangible machine-readable medium suitable for storing or transmitting electronic instructions or information in a form readable by a machine (e.g., a computer).22322566466.1Attorney Docket No. 240027PCT-9327W001
[0069] Any of the software components or functions described in this application may be implemented as software code to be executed by a processor using any suitable computer language, such as, for example, Python, Java, C++, or Perl, using, for example, conventional or object-oriented techniques. The software code may be stored as a series of instructions or commands on a computer-readable medium, such as RAM, ROM, a magnetic medium such as a hard drive or a floppy disk, or an optical medium such as a CD-ROM. Any such computer-readable medium may reside on or within a single computational apparatus and may be present on or within different computational apparatuses within a system or network.
[0070] As used in any aspect herein, the term “logic” may refer to an app, software, firmware, and / or circuitry configured to perform any of the aforementioned operations. Software may be embodied as a software package, code, instructions, instruction sets, and / or data recorded on a non-transitory computer-readable storage medium. Firmware may be embodied as code, instructions, instruction sets, and / or data that are hard-coded (e.g., non-volatile) in memory devices.
[0071] As used in any aspect herein, the terms “component,” “system,” “module,” and the like can refer to a computer-related entity, either hardware, a combination of hardware and software, software, or software in execution.
[0072] A network may include a packet-switched network. The communication devices may be capable of communicating with each other using a selected packet-switched network communications protocol. One example communications protocol may include an Ethernet communications protocol, which may be capable of permitting communication using a Transmission Control Protocol / lnternet Protocol. The Ethernet protocol may comply or be compatible with the Ethernet standard published by the IEEE titled “IEEE 802.3 Standard,” published in December 2008 and / or later versions of this standard. Alternatively, or additionally, the communication devices may be capable of communicating with each other using an X.25 communications protocol. The X.25 communications protocol may comply or be compatible with a standard promulgated by the International Telecommunication Union-Telecommunication Standardization Sector. Alternatively, or additionally, the communication devices may be capable of communicating with each other using a frame relay communications protocol. The frame relay communications protocol may 23322566466.1Attorney Docket No. 240027PCT-9327W001comply or be compatible with a standard promulgated by Consultative Committee for International Telegraph and Telephone and / or the American National Standards Institute. Alternatively, or additionally, the transceivers may be capable of communicating with each other using the ATM communications protocol. The ATM communications protocol may comply or be compatible with an ATM standard published by the ATM Forum titled “ATM-MPLS Network Interworking 2.0,” published August 2001 , and / or later versions of this standard. Of course, different and / or afterdeveloped connection-oriented network communication protocols are equally contemplated herein.
[0073] Unless specifically stated otherwise as apparent from the foregoing disclosure, it is appreciated that, throughout the present disclosure, discussions using terms such as “processing,” “computing,” “calculating,” “determining,” “displaying,” or the like refer to the action and processes of a computer system, or similar electronic computing device, that manipulates and transforms data represented as physical (electronic) quantities within the computer system’s registers and memories into other data similarly represented as physical quantities within the computer system memories, registers, or other such information storage, transmission, or display devices.
[0074] One or more components may be referred to herein as “configured to,” “configurable to,” “operable / operative to,” “adapted / adaptable,” “able to,” “conformable / conformed to,” etc. Those skilled in the art will recognize that “configured to” can generally encompass active-state components, inactive-state components, and / or standby-state components, unless context requires otherwise.
[0075] Those skilled in the art will recognize that, in general, terms used herein, and especially in the appended claims (e.g., bodies of the appended claims) are generally intended as “open” terms (e.g., the term “including” should be interpreted as “including, but not limited to”; the term “having” should be interpreted as “having at least”; the term “includes” should be interpreted as “includes, but is not limited to”). It will be further understood by those within the art that if a specific number of an introduced claim recitation is intended, such an intent will be explicitly recited in the claim, and in the absence of such recitation, no such intent is present. For example, as an aid to understanding, the following appended claims may contain usage of the 24322566466.1Attorney Docket No. 240027PCT-9327W001introductory phrases “at least one” and “one or more” to introduce claim recitations. However, the use of such phrases should not be construed to imply that the introduction of a claim recitation by the indefinite articles “a” or “an” limits any particular claim containing such introduced claim recitation to claims containing only one such recitation, even when the same claim includes the introductory phrases “one or more” or “at least one” and indefinite articles such as “a” or “an” (e.g., “a” and / or “an” should typically be interpreted to mean “at least one” or “one or more”); the same holds true for the use of definite articles used to introduce claim recitations.
[0076] In addition, even if a specific number of an introduced claim recitation is explicitly recited, those skilled in the art will recognize that such recitation should typically be interpreted to mean at least the recited number (e.g., the bare recitation of “two recitations,” without other modifiers, typically means at least two recitations, or two or more recitations). Furthermore, in those instances where a convention analogous to “at least one of A, B, and C, etc.” is used, in general, such a construction is intended in the sense one having skill in the art would understand the convention (e.g., “a system having at least one of A, B, and C” would include, but not be limited to, systems that have A alone, B alone, C alone, A and B together, A and C together, B and C together, and / or A, B, and C together). In those instances where a convention analogous to “at least one of A, B, or C, etc.” is used, in general, such a construction is intended in the sense one having skill in the art would understand the convention (e.g., “a system having at least one of A, B, or C” would include, but not be limited to, systems that have A alone, B alone, C alone, A and B together, A and C together, B and C together, and / or A, B, and C together). It will be further understood by those skilled in the art that typically a disjunctive word and / or phrase presenting two or more alternative terms, whether in the description, claims, or drawings, should be understood to contemplate the possibilities of including one of the terms, either of the terms, or both terms unless context dictates otherwise. For example, the phrase “A or B” will be typically understood to include the possibilities of “A,” “B,” or “A and B.”
[0077] With respect to the appended claims, those skilled in the art will appreciate that recited operations therein may generally be performed in any order. Also, although various operational flow diagrams are presented in sequence(s), it should25322566466.1Attorney Docket No. 240027PCT-9327W001be understood that the various operations may be performed in other orders than those that are illustrated or may be performed concurrently. Examples of such alternate orderings may include overlapping, interleaved, interrupted, reordered, incremental, preparatory, supplemental, simultaneous, reverse, or other variant orderings, unless context dictates otherwise. Furthermore, terms like “responsive to,” “related to,” or other past-tense adjectives are generally not intended to exclude such variants, unless context dictates otherwise.
[0078] It is worthy to note that any reference to “one aspect,” “an aspect,” “an exemplification,” “one exemplification,” and the like means that a particular feature, structure, or characteristic described in connection with the aspect is included in at least one aspect. Thus, appearances of the phrases “in one aspect,” “in an aspect,” “in an exemplification,” and “in one exemplification” in various places throughout the specification are not necessarily all referring to the same aspect. Furthermore, the features, structures, or characteristics may be combined in any suitable manner in one or more aspects.
[0079] As used herein, the singular form of “a,” “an,” and “the” include the plural references unless the context clearly dictates otherwise.
[0080] In summary, numerous benefits have been described that result from employing the concepts described herein. The foregoing description of the one or more forms has been presented for purposes of illustration and description. It is not intended to be exhaustive or limiting to the precise form disclosed. Modifications or variations are possible in light of the above teachings. The one or more forms were chosen and described to illustrate principles and practical application to thereby enable one of ordinary skill in the art to utilize the various forms with various modifications as are suited to the particular use contemplated. It is intended that the claims submitted herewith define the overall scope.26322566466.1
Claims
Attorney Docket No. 240027PCT-9327W001CLAIMS WHAT IS CLAIMED IS:
1. A computer-implemented method, comprising:obtaining, through a single instance of contactless payment, a payment credential from a cardholder payment instrument;authorizing, based on the single instance of contactless payment, a payment transaction using the payment credential;generating, based on the single instance of contactless payment, a tokenized credential corresponding to the payment credential using a certified payment network tokenization service; andstoring, based on the single instance of contactless payment, the tokenized credential in a credential-on-file database for subsequent payment transactions.
2. The computer-implemented method of Claim 1 , further comprising prompting the cardholder to provide consent for storing the tokenized credential.
3. The computer-implemented method of Claim 1 , wherein authorizing the payment transaction and generating the tokenized credential are performed concurrently based on the single instance of contactless payment.
4. The computer-implemented method of Claim 1 , wherein obtaining the payment credential comprises:wirelessly detecting the cardholder payment instrument via a contactless interface;authenticating the cardholder payment instrument; andreceiving the payment credential from the cardholder payment instrument.27322566466.1Attorney Docket No. 240027PCT-9327W0015. The computer-implemented method of Claim 1 , wherein the single instance of contactless payment comprises a single tap payment by the cardholder payment instrument on a tap-to-phone device.
6. The computer-implemented method of Claim 1 , wherein authorizing the payment transaction comprises transmitting the payment credential to a payment network via an acquirer.
7. The computer-implemented method of Claim 1 , further comprising initiating subsequent transactions using the tokenized credential stored in the credential-on-file database.
8. The computer-implemented method of Claim 1 , wherein the cardholder payment instrument is a mobile device implementing a tokenized digital wallet.
9. The computer-implemented method of Claim 1 , wherein storing the tokenized credential comprises encrypting the credential for secure storage in compliance with payment network security standards.
10. The computer-implemented method of Claim 8, further comprising using the tokenized credential for subsequent payments initiated via a digital wallet.
11. A system, comprising:a contactless payment terminal configured to:detect an instance of contactless payment by a payment instrument; andwirelessly obtain, in the instance of contactless payment, a payment credential from the payment instrument; and28322566466.1Attorney Docket No. 240027PCT-9327W001wherein the system is configured to initiate two transaction flows based on the payment credentials in the instance of contactless payment, the two transaction flows comprising:a first transaction flow for authorizing a payment transaction based on the payment credential; anda second transaction flow for generating a tokenized credential corresponding to the payment credential for future instances of payment based on the payment credential.
12. The system of Claim 11 , further comprising a user interface configured to prompt for consent to store the payment credential.
13. The system of Claim 11 , wherein the contactless payment terminal comprises a tap-to-phone device.
14. The system of Claim 11 , further comprising:a payment authorization module configured to authorize the payment transaction based on the payment credential; anda tokenization module configured to generate the tokenized credential corresponding to the payment credential using a certified payment network tokenization, wherein the contactless payment terminal is configured to concurrently engage the payment authorization module to authorize the payment transaction and the tokenization module to generate the tokenized credential.
15. The system of Claim 14, further comprising a credential storage module configured to store the tokenized credential in a credential-on-file database for the future instances of payment with the payment instrument.29322566466.1Attorney Docket No. 240027PCT-9327W00116. The system of Claim 15, wherein the credential storage module is configured to encrypt the tokenized credential before storage in the credential-on-file database.
17. A computer-implemented method, comprising:obtaining, by an issuer system, first request data from a payment network to process a payment using a payment credential obtained during a single instance of contactless payment by a payment instrument associated with the payment credential;authorizing, by the issuer system, the payment based on the first request data;obtaining, by the issuer system, second request data from a tokenization service to tokenize the payment credential obtained during the single instance of contactless payment; andauthorizing, by the issuer system, the tokenization service to tokenize the payment credential for future instances of payment involving the payment credential.
18. The computer-implemented method of Claim 17, wherein obtaining, by the issuer system, the first request data is in a payment flow, wherein obtaining, by the issuer system, the second request data is in a provisioning flow, and wherein the payment flow and the provisioning flow are based on the single instance of contactless payment.
19. The computer-implemented method of Claim 18, wherein the payment flow is separate from the provisioning flow.
20. The computer-implemented method of Claim 17, wherein authorizing, by the issuer system, the tokenization service to tokenize the payment credential is further based on the first request data.30322566466.1