Flexible token exchange before initiation of an interaction
Patent Information
- Application Number
- PCT/US2026/017109
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-02-27
- Filing Date
- 2026-02-27
- Publication Date
- 2026-09-03
Smart Images

Figure US2026017109_03092026_PF_FP_ABST
Abstract
Description
PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001FLEXIBLE TOKEN EXCHANGE BEFORE INITIATION OF AN INTERACTION CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application is a non-provisional application of and claims the benefit of U.S. Provisional Patent Application No. 63 / 764,236, filed on February 27, 2025, which is herein incorporated by reference in its entirety.BACKGROUND
[0002] User devices with interaction capabilities can allow a user to store various credentials on the user device and conduct an interaction by transmitting one of the credentials to another device. While this can be more convenient for a user than carrying multiple physical devices, an application on the user device can also become visually cluttered as more credentials are stored.
[0003] Additionally, credentials stored on a user device may be obscured or modified. While this can protect sensitive data, it can also create technical complications for authorizing entities. When a credential is transmitted for an interaction, it may be provided to an authorizing entity so that the authorizing entity can authorize the interaction. During transmission to an authorizing entity computer via a network of intermediary computers, the modified or obscured credential may be restored to its base state that is recognized by the authorizing entity. As a result, the authorizing entity can recognize the credential upon receipt. However, the authorizing entity may not be aware of the data that was initially provided by the user device when the interaction was initiated. If a cryptogram was generated based on the original data, the authorizing entity may not be technically capable of verifying the cryptogram without access to the original information. As a result, the authorizing entity may not receive or have access to the data needed to verify the authenticity of the interaction.
[0004] Embodiments of the disclosure address these and other problems individually and collectively.PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001SUMMARY
[0005] One embodiment is related to a method comprising: transmitting, by a user device to a token service computer, a token request message including a flexible credential, wherein the flexible credential is associated with a plurality of real credentials, and each of the plurality of real credentials is associated with a different one of a plurality of sources; receiving, by the user device from the token service computer, a flexible token associated with the flexible credential, and a plurality of real tokens each of which is associated with a corresponding one of the plurality of real credentials; receiving, by the user device from a user, a first selection of a first source from the plurality of sources; transmitting, by the user device to the token service computer, a cryptogram request message comprising a first real token of the plurality of real tokens, where the first real token is associated with the first source;receiving, by the user device from the token service computer, a cryptogram response message comprising a cryptogram associated with the first real token; receiving, by the user device from the user, a second selection of the flexible token for an interaction; in response to the second selection of the flexible token, determining, by the user device, to use the first real token for the interaction instead of the flexible token; and transmitting, by the user device to an access device or a resource provider computer for the interaction, the first real token and the cryptogram, wherein the access device or the resource provider computer processes an authorization request message comprising the first real token and the cryptogram.
[0006] Another embodiment is related to a user device comprising: a processor; and a computer-readable medium coupled to the processor, the computer-readable medium comprising code executable by the processor for implementing a method comprising: transmitting, to a token service computer, a token request message including a flexible credential, wherein the flexible credential is associated with a plurality of real credentials, and each of the plurality of real credentials is associated with a different one of a plurality of sources; receiving, from the token service computer, a flexible token associated with the flexible credential, and a plurality of real tokens each of which is associated with a corresponding one of the plurality of real credentials; receiving, from a user, a first selection of a first source from the pluralityPATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001of sources; transmitting, to the token service computer, a cryptogram request message comprising a first real token of the plurality of real tokens, where the first real token is associated with the first source; receiving, from the token service computer, a cryptogram response message comprising a cryptogram associated with the first real token; receiving, from the user, a second selection of the flexible token for an interaction; in response to the second selection of the flexible token, determining to use the first real token for the interaction instead of the flexible token; and transmitting, to an access device or a resource provider computer for the interaction, the first real token and the cryptogram, wherein the access device or the resource provider computer processes an authorization request message comprising the first real token and the cryptogram.
[0007] Another embodiment is related to a method comprising: receiving, by a token service computer from a user device, a token request message including a flexible credential, wherein the flexible credential is associated with a plurality of real credentials, and each of the plurality of real credentials is associated with a different one of a plurality of sources; in response to the token request message, providing, by the token service computer to the user device, a flexible token associated with the flexible credential, and a plurality of real tokens each of which is associated with a corresponding one of the plurality of real credentials; receiving, by the token service computer from the user device, a cryptogram request message comprising a first real token from the plurality of real tokens; and providing, by the token service computer to the user device, a cryptogram response message comprising a cryptogram associated with the first real token, wherein the user device transmits the first real token and the cryptogram to an access device or a resource provider computer for an interaction in response to receiving a selection of the flexible token for the interaction.
[0008] One embodiment is related to a method comprising: transmitting, by a user device to a token service computer, a first token request message including a flexible credential, wherein the flexible credential is associated with a plurality of real credentials, and each of the plurality of real credentials is associated with a different one of a plurality of sources; receiving, by the user device from the token service computer, a flexible token associated with the flexible credential; receiving, by the userPATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001device from a user, a first selection of a first source from the plurality of sources; transmitting, by the user device to the token service computer, a second token request message including the flexible token; receiving, by the user device from the token service computer, a first real token and a cryptogram associated with the first real token, where the first real token is associated with a first real credential of the plurality of real credentials, and the first real credential is associated with the first source; receiving, by the user device from the user, a second selection of the flexible token for an interaction; in response to the second selection of the flexible token, determining, by the user device, to use the first real token for the interaction instead of the flexible token; and transmitting, by the user device to an access device or a resource provider computer for the interaction, the first real token and the cryptogram, wherein the access device or the resource provider computer processes an authorization request message comprising the first real token and the cryptogram.
[0009] One embodiment is related to a user device comprising: a processor; and a computer-readable medium coupled to the processor, the computer-readable medium comprising code executable by the processor for implementing a method comprising: transmitting, to a token service computer, a first token request message including a flexible credential, wherein the flexible credential is associated with a plurality of real credentials, and each of the plurality of real credentials is associated with a different one of a plurality of sources; receiving, from the token service computer, a flexible token associated with the flexible credential; receiving, from a user, a first selection of a first source from the plurality of sources; transmitting, to the token service computer, a second token request message including the flexible token; receiving, from the token service computer, a first real token and a cryptogram associated with the first real token, where the first real token is associated with a first real credential of the plurality of real credentials, and the first real credential is associated with the first source; receiving, from the user, a second selection of the flexible token for an interaction; in response to the second selection of the flexible token, determining to use the first real token for the interaction instead of the flexible token; and transmitting, by the user device to an access device or a resource provider computer for the interaction, the first real token and the cryptogram, wherein thePATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001access device or the resource provider computer processes an authorization request message comprising the first real token and the cryptogram.
[0010] One embodiment is related to a method comprising: receiving, by a token service computer from a user device, a first token request message including a flexible credential, wherein the flexible credential is associated with a plurality of real credentials, and each of the plurality of real credentials is associated with a different one of a plurality of sources; in response to the first token request message, providing, by the token service computer to the user device, a flexible token associated with the flexible credential; receiving, by the token service computer from the user device, a second token request message comprising the flexible token; and providing, by the token service computer to the user device, a first real token and a cryptogram associated with the first real token, where the first real token is associated with a first real credential of the plurality of real credentials, and the first real credential is associated with a first source of the plurality of sources, wherein the user device transmits the first real token and the cryptogram to an access device or a resource provider computer for an interaction in response to receiving a selection of the flexible token for the interaction.
[0011] These and other embodiments of the invention are described in further detail below.BRIEF DESCRIPTION OF THE DRAWINGS
[0012] FIG. 1 shows a block diagram of a system and a process flow diagram, according to embodiments.
[0013] FIG. 2 shows a block diagram of an exemplary user device, according to embodiments.
[0014] FIG. 3 shows a block diagram of an exemplary token service computer, according to embodiments.
[0015] FIGS. 4A-4B show illustrations of displayed information on a user device, according to embodiments.PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001
[0016] FIG. 5 shows a block diagram of another process flow diagram, according to embodiments.
[0017] FIG. 6 shows a block diagram of another process flow diagram, according to embodiments.
[0018] FIG. 7 shows a block diagram of another process flow diagram, according to embodiments.DETAILED DESCRIPTION
[0019] Before discussing embodiments of the invention, some description of some terms may be helpful.
[0020] A “user” may include an individual. In some embodiments, a user may be associated with one or more personal accounts and / or mobile devices. The user may also be referred to as a cardholder, account holder, or consumer in some embodiments.
[0021] An “interaction” may include a reciprocal action or influence. An interaction can include a communication, contact, or exchange between parties, devices, and / or entities. Example interactions include a transaction between two parties and a data exchange between two devices. In some embodiments, an interaction can include a user requesting access to secure data, a secure webpage, a secure location, and the like. In other embodiments, an interaction can include a payment transaction in which two devices can interact to facilitate a payment.
[0022] “Interaction data” can include data related to and / or recorded during an interaction. In some embodiments, interaction data can be transaction data of the network data. Transaction data can comprise a plurality of data elements with data values.
[0023] A “source” can be a place where something is obtained. A “funding source” can include a place from which funds are obtained. A funding source can include an account, such as a user account. An account can be maintained by an issuer and authorizing entity. A funding source can be a particular type of fundingPATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001source. For example, a funding source can be a credit funding source, a debit funding source, a points funding source, an installment plan funding source, a cryptocurrency funding source, a rewards funding source, etc.
[0024] An “account issuer identification number” can include a value that represents an issuer of accounts. An account issuer identification number can include four to eight digits that can be used to identify an issuer. An account issuer identification number can be a bank identification number (BIN). An account issuer identification number can be included in a credential such as an account number. For example, an account issuer identification number can be the first N digits of an account number for an account that is issued by the issuer. An account issuer identification number can correspond to a particular type of account issuer identification number. Each type of account issuer identification number can indicate how the related account number can be utilized in an interaction. For example, an account issuer identification number can be a flexible account issuer identification number that can be utilized in flexible interactions involving user rules and resource provider rules. An account issuer identification number can be a credit account issuer identification number, a debit account issuer identification number, a cryptocurrency account issuer identification number, etc. A type of account issuer identification number can be identified using an identification table.
[0025] “Credentials” may comprise any evidence of authority, rights, or entitlement to privileges. For example, access credentials may comprise permissions to access certain tangible or intangible assets, such as a building or a file. Examples of credentials may include passwords, passcodes, or secret messages. In another example, payment credentials may include any suitable information associated with and / or identifying a source (e.g., a payment account and / or payment device associated with the account). Such information may be directly related to the source or may be derived from information related to the source. Examples of account information may include an “account identifier” such as a PAN (primary account number or “account number”), a token, a subtoken, a gift card number or code, a prepaid card number or code, a user name, an expiration date, a CW (card verification value), a dCVV (dynamic card verification value), a CW2 (card verification value 2),PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001a CVC3 card verification value, etc. An example of a PAN is a 16-digit number, such as “4147 0900 0000 1234”. In some embodiments, credentials may be considered sensitive information. A “flexible credential” may be one that is associated with multiple sources such as multiple payment account sources. A flexible credential may not directly identify a single source, but instead may be linked to a set of real credentials, each identifying a corresponding source (e.g., a real account). A “flexible credential” may be in the form of a PAN or a token. A “real credential” (also referred to as a specific credential, a targeted credential, a source credential, or an account credential) may be an account number that identifies a specific source (e.g., account). For example, a real credential can be a primary account number that is associated with a source maintained by an authorizing entity computer.
[0026] A “token” can include a substitute identifier for some information. For example, an interaction token may include an identifier for an interaction account that is a substitute for an account identifier, such as a primary account number (PAN). For instance, a token may include a series of alphanumeric characters that may be used as a substitute for an original account identifier. For example, a token “490000000000 0001” may be used in place of a PAN “414709000000 1234.” In some embodiments, a token may be “format preserving” and may have a numeric format that conforms to the account identifiers used in existing transaction processing networks (e.g., ISO 8583 financial transaction message format). In some embodiments, a token may be a random string of characters. In some embodiments, a token may be used in place of a PAN to initiate, authorize, settle or resolve a transaction. The token may also be used to represent the original credential in other systems where the original credential would typically be provided. In some embodiments, a token value may be generated such that the recovery of the original PAN or other account identifier from the token value may not be computationally derived. Further, in some embodiments, the token format may be configured to allow the entity receiving the token to identify it as a token and recognize the entity that issued the token. A “flexible token” may be a token that is a substitute identifier a flexible credential. A “real token” (also referred to as a specific token, a targeted token, a source token, or an account token) may be token that is a substitute identifier for a real credential.PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001
[0027] “Tokenization” can include a process by which data is replaced with substitute data. For example, an account identifier (e.g., a primary account number (PAN)) may be tokenized by replacing the account identifier with a substitute number (e.g., a token) that is associated with the account identifier. Further, tokenization may be applied to other information which may be replaced with a substitute value. Tokenization may be used to enhance transaction efficiency, improve transaction security, increase service transparency, or to provide a method for third-party enablement.
[0028] A “token service provider” or “token service computer” can include an entity including one or more server computers that generates, processes, and / or maintains tokens. A token service provider may include or be in communication with a token vault where the generated tokens are stored. Specifically, the token vault may maintain one-to-one mapping between a token and the data (e.g., a real account identifier) represented by the token. A token service provider may provide reports or data output to reporting tools regarding approved, pending, and / or declined token requests. The token service provider may provide data output related to token-based transactions to reporting tools and applications and present the token and / or the data substituted by the token (e.g., real account identifiers) as appropriate in the reporting output.
[0029] An “authorization request message” may be an electronic message that requests authorization for an interaction. In some embodiments, it is sent to a transaction processing computer and / or an issuer of a payment card to request authorization for a transaction. An authorization request message according to some embodiments may comply with International Organization for Standardization (ISO) 8583, which is a standard for systems that exchange electronic transaction information associated with a payment made by a user using a payment device or payment account. The authorization request message may include an issuer account identifier that may be associated with a payment device or payment account. An authorization request message may also comprise additional data elements corresponding to “identification information” including, by way of example only: a service code, a CVV (card verification value), a dCW (dynamic card verification value), a PAN (primaryPATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001account number or “account number”), a payment token, a username, an expiration date, etc. An authorization request message may also comprise “transaction information,” such as any information associated with a current transaction, such as the transaction value, merchant identifier, merchant location, acquirer bank identification number (BIN), card acceptor ID, information identifying items being purchased, etc., as well as any other information that may be utilized in determining whether to identify and / or authorize a transaction.
[0030] An “authorization response message” may be a message that responds to an authorization request. In some cases, it may be an electronic message reply to an authorization request message generated by an issuing financial institution or a transaction processing computer. The authorization response message may include, by way of example only, one or more of the following status indicators: Approval --transaction was approved; Decline - transaction was not approved; or Call Center - response pending more information, merchant must call the toll-free authorization phone number. The authorization response message may also include an authorization code, which may be a code that a credit card issuing bank returns in response to an authorization request message in an electronic message (either directly or through the transaction processing computer) to the merchant's access device (e.g., PCS equipment) that indicates approval of the transaction. The code may serve as proof of authorization.
[0031] An “access device” may be any suitable device that provides access to a remote system. An access device may also be used for communicating with a coordination computer, a communication network, or any other suitable system. An access device may generally be located in any suitable location, such as at the location of a merchant. An access device may be in any suitable form. Some examples of access devices include POS or point of sale devices (e.g., POS terminals), cellular phones, personal digital assistants (PDAs), personal computers (PCs), tablet PCs, hand-held specialized readers, set-top boxes, electronic cash registers (ECRs), vending machines, automated teller machines (ATMs), virtual cash registers (VCRs), kiosks, security systems, access systems, and the like.PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001
[0032] An access device may use any suitable contact or contactless mode of operation to send or receive data from, or associated with, a mobile communication or payment device. For example, access devices can have card readers that can include electrical contacts, radio frequency (RF) antennas, optical scanners, barcode readers, or magnetic stripe readers to interact with portable devices such as payment cards.
[0033] A “resource provider” may be an entity that can provide a resource such as goods, services, information, and / or access. Examples of resource providers includes merchants, data providers, transit agencies, governmental entities, venue and dwelling operators, etc.
[0034] An “authorizing entity” may be an entity that authorizes a request. Examples of an authorizing entity may be an issuer, a governmental agency, a document repository, an access administrator, etc. An authorizing entity may operate an authorizing entity computer. An “issuer” may referto a business entity (e.g., a bank) that issues and optionally maintains an account for a user. An issuer may also issue payment credentials stored on a user device, such as a cellular telephone, smart card, tablet, or laptop to the consumer, or in some embodiments, a portable device.
[0035] A “processor” may include a device that processes something. In some embodiments, a processor can include any suitable data computation device or devices. A processor may comprise one or more microprocessors working together to accomplish a desired function. The processor may include a CPU comprising at least one high-speed data processor adequate to execute program components for executing user and / or system-generated requests. The CPU may be a microprocessor such as AMD's Athlon, Duron and / or Opteron; IBM and / or Motorola's PowerPC; IBM's and Sony's Cell processor; Intel's Celeron, Itanium, Pentium, Xeon, and / or XScale; and / or the like processor(s).
[0036] A “memory” may be any suitable device or devices that can store electronic data. A suitable memory may comprise a non-transitory computer readable medium that stores instructions that can be executed by a processor to implement a desired method. Examples of memories may comprise one or more memory chips,PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001disk drives, etc. Such memories may operate using any suitable electrical, optical, and / or magnetic mode of operation.
[0037] A “server computer” may include a powerful computer or cluster of computers. For example, the server computer can be a large mainframe, a minicomputer cluster, or a group of servers functioning as a unit. In one example, the server computer may be a database server coupled to a Web server. The server computer may comprise one or more computational apparatuses and may use any of a variety of computing structures, arrangements, and compilations for servicing the requests from one or more client computers.
[0038] Embodiments of the invention provide systems and methods for provisioning a flexible token to a user device, and conducting an interaction based on the flexible token. A user device can obtain the flexible token and / or a plurality of real tokens associated with the flexible token. The user device can also receive a user’s first selection of a source for use with the flexible token, and then obtain a cryptogram associated with a first real token associated with the selected source. When the flexible token is selected for a subsequent interaction, the user device can provide the first real token and the cryptogram in place of the flexible token. An authorizing entity can then verify a cryptogram based on the provided first real token.
[0039] Embodiments solve technical problems related to flexible credentials. A flexible credential can allow for flexible funding sources that can be selected and changed for different interactions. Flexible credentials enable a one-to-many system (e.g., one flexible credential for multiple funding sources). Flexible credentials can advantageously reduce the number of physical cards provided to a user, thereby reducing costs (e.g., physical creation and mailing) and as well as weight and bulk. Flexible credentials can also improve data security by reducing the amount of source credentials that need to be protected (e.g., multiple credentials are more likely to be lost or stolen). However, flexible credentials can also cause technical problems related to authentication and verification within existing system architectures.
[0040] A flexible credential may be provided by a user device for an interaction. Then, during transmission of the flexible credential to an authorizing entity, the flexiblePATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001credential swapped for one of a plurality of real credentials (corresponding to a selected source for the interaction). As a result, the authorizing entity may receive the real credential, and not the flexible credential. This allows the authorizing entity to identify the source based on the real credential. However, this can affect the authorizing entity’s ability to verify a cryptogram. Cryptograms can be useful for verifying that the user device’s use of a credential is authentic and legitimate. Cryptograms may be utilized for interactions conducted using a user device (e.g., as opposed to a flexible credential physical card). Cryptograms can be provided by the user device along with the credential for the interaction. Cryptograms may typically be generated based on the credential information provided, which in this case may be a flexible credential (as opposed to the real credential). To verify the cryptogram, the authorizing entity may need to have the information used to generate the cryptogram, which in this case may be the flexible credential and not the real credential. However, if the authorizing entity does not receive the flexible credential in an authorizing request message (or otherwise able to obtain the flexible credential), the authorizing entity may not be able to verify the cryptogram, thereby reducing the authorizing entity’s ability to authenticate the authorization request message or otherwise ensure that the interaction is legitimate. Thus, if a flexible credential is used at a user device (e.g., instead of a flexible credential physical card), the authorizing entity may not be able to authenticate the interaction.
[0041] One possible technical solution is to allow an intermediary to verify the cryptogram on behalf of (OBO) the authorizing entity. For example, a processing computer (which may also swap the flexible credential for the real credential during authorization processing) may be able to verify the cryptogram. While technically possible, this may not be considered sufficiently secure. For maximum verification and data security, the authorizing entity itself may need to be the one to verify the cryptogram, such that it is not relying on any outside parties.
[0042] Another potential technical solution is for the authorizing entity to store information indicating that a given real credential is linked to a flexible credential. Then, if the authorizing entity receives the real credential, it can retrieve the flexible credential for verifying the token. However, this presents a significant processingPATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001burden to the authorizing entity. For each interaction, the authorizing entity may need to attempt verification of the cryptogram twice using the real credential and then the flexible credential, as it may be unaware as to which credential was used to generate the cryptogram. Additionally, every time a flexible credential is created (e.g., by a processing computer), the authorizing entity would need to update records across multiple systems for each associated real credential.
[0043] Another potential technical solution is to move the process of swapping a flexible credential for a real credential (e.g., during authorization processing) from an intermediary processing computer to the authorizing computer itself. However, this would require significant changes to existing architecture. Authorizing entities often have multiple computers and systems that are segregated based on the type of source or account. For example, credentials related to credit accounts may be authorized by a first computer, while credentials related to debit accounts may be authorized by a second computer. Authorization request messages for interactions are directed to the correct endpoint computer for authorization based on the source type associated with the credential in the authorization request message. Thus, it is important for the flexible credential to be swapped for the real credential before being transmitted to the authorizing entity, such that the correct authorizing entity computer endpoint can be identified (e.g., based on the real credential) for the transmission. Transaction processing networks rely on a portion of the credential known as a bank identification number (BIN) to identify authorizing entities and to route transactions to the appropriate network for processing. BINs have been categorized as binary, in that they identify a specific type of card product and funding source, such as debit, credit, prepaid, or charge cards. If swapping of the flexible credential were to happen at the authorizing entity, all of the authorizing entity computers would need to be combined into one such that there is only one endpoint. Then, the authorizing entity would be able to analyze the authorization request message, identify the flexible credential, determine the set of linked real credentials, determine which of the real credentials to use for the interaction, identify an account associated with the real credential, and then authorize the transaction based on that account. In addition to the added processingPATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001burden for the authorizing entity, such an overhaul of existing computer system architecture would require significant effort and investment.
[0044] Embodiments solve such technical problems by moving the process of swapping a flexible credential for a real credential from the processing computer to the user device (or other token requestor). Instead of a user device submitting a flexible credential for the interaction, the user device can first obtain a credential (or token) corresponding to the desired source, and then directly submit that credential (or token) instead of the flexible credential. This allows the cryptogram to be generated based on the real credential (or token) instead of the flexible credential. As a result, the authorizing entity can be enabled to verify the cryptogram based on the real credential (or token), while avoiding the undesirable options discussed above (e.g., on behalf of verification by the network processing computer, requiring the authorizing entity to store or retrieve the flexible credential, making the authorizing entity responsible for swapping the flexible credential for the flexible token, etc.).
[0045] Embodiments enable the processing for swapping the flexible credential for a real credential to the user device by allowing a user to select which source associated with the flexible credential to use for a subsequent interaction. The user device can thereby obtain the corresponding real credential (or token) as well as a corresponding cryptogram before the interaction begins. Then, when the interaction is initiated and the user selects the flexible credential (e.g., via a payment application), the user device can automatically swap the flexible credential for the real credential (or token) previously selected. Thus, the swapping occurs before the user device transmits any information for the interaction, as opposed to swapping by the processing computer during authorization processing.
[0046] Embodiments also can utilize tokens, thereby providing additional data security. For example, a flexible token associated with the flexible credential can be provided to the user device instead of the flexible credential. Also, a real token associated with a real credential can be provided to the user device instead of the real credential. Thus, flexible credentials can be used with user devices, and swapping of flexible credential for real credential can occur at the user device without exposing sensitive data (e.g., flexible credential or real credential). Real tokens associated withPATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001real credentials may be issued by authorizing entities or otherwise stored by authorizing entities, so authorizing entities can verify cryptograms generated based on real tokens, according to embodiments.
[0047] FIG. 1 shows a system 100 according to embodiments. The system 100 includes a user device 180, a token service computer 160, a flexible credential computer 170, an access device 140, a transport computer 141, a processing computer 142, and an authorizing entity system 150.
[0048] The user device 180 can be in operative communication with the access device 140. The access device 140 can be in operative communication with a resource provider computer (not shown), which can be in operative communication with the transport computer 141. The transport computer 141 can be in operative communication with the processing computer 142. The processing computer 142 can be in operative communication with the authorizing entity system 150. The flexible credential computer 170 can be in operative communication with the user device 180, the authorizing entity system 150, and / or the token service computer 160. The token service computer 160 can be in operative communication with the user device 180, the processing computer 142, and / or the authorizing entity system 150.
[0049] For simplicity of illustration, a certain number of components are shown in FIG. 1. It is understood, however, that embodiments of the invention may include more than one of each component. In addition, some embodiments of the invention may include fewer than or greater than all of the components shown in FIG. 1.
[0050] Messages between the devices in the system 100 illustrated in FIG. 1 can be transmitted using a secure communications protocols such as, but not limited to, File Transfer Protocol (FTP); HyperText Transfer Protocol (HTTP); Secure Hypertext Transfer Protocol (HTTPS), SSL, ISO (e.g., ISO 8583) and / or the like. The communications network may include any one and / or the combination of the following: a direct interconnection; the Internet; a Local Area Network (LAN); a Metropolitan Area Network (MAN); an Operating Missions as Nodes on the Internet (OMNI); a secured custom connection; a Wide Area Network (WAN); a wireless network (e.g., employing protocols such as, but not limited to a Wireless Application Protocol (WAP), l-mode,PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001and / or the like); and / or the like. The communications network can use any suitable communications protocol to generate one or more secure communication channels. A communications channel may, in some instances, comprise a secure communication channel, which may be established in any known manner, such as through the use of mutual authentication and a session key, and establishment of a Secure Socket Layer (SSL) session.
[0051] The user device 180 (also referred to as a token requestor) can include one or more computers, portable computers, laptop computers, tablet computers, mobile devices, cellular phones, wearable devices (e.g. , watches, glasses, lenses, clothing, etc.), personal digital assistants (PDAs), Internet of Things (loT) devices, and / or the like. The user device 180 can be operated by a user. The user device 180 can initiate interactions (e.g., transactions) with resource provider computers and / or access devices.
[0052] The user device can be configured for contact and / or contactless communications with an access device. The user device can store multiple credentials and / or payment applications, such as the first application 181 and the second application 182.
[0053] A block diagram illustrating an example of a user device is shown in FIG.2. The user device 200 can be a user device (e.g., mobile phone) with a computer readable medium 204. The user device 200 may include device hardware 208 coupled to a system memory 202.
[0054] Device hardware 208 may include a processor 210, input elements 212, a short range antenna 214, a user interface 216, output elements 218, and a long range antenna 220. Examples of input elements may include microphones, keypads, touchscreens, sensors, etc. Examples of output elements may include speakers, display screens, and tactile devices. The processor 210 can be implemented as one or more integrated circuits (e.g., one or more single core or multicore microprocessors and / or microcontrollers), and is used to control the operation of the user device 200. The processor 210 can execute a variety of programs in response to program code orPATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001computer-readable code stored in the system memory 202, and can maintain multiple concurrently executing programs or processes.
[0055] The long range antenna 220 may include one or more RF transceivers and / or connectors that can be used by the user device 200 to communicate with other devices and / or to connect with external networks. The input and output elements 218, 218 allow a user to interact with and invoke the functionalities of the user device 200.The short range antenna 214 may be configured to communicate with external devices through a short range communication medium (e.g., using Bluetooth, Wi-Fi, infrared, NFC, etc.). The long range antenna 220 may be configured to communicate with a remote base station and a remote cellular or data network, over the air.
[0056] The system memory 202 can be implemented using any combination of any number of non-volatile memories (e.g., flash memory) and volatile memories (e.g., DRAM, SRAM), or any other non-transitory storage medium, or a combination thereof media.
[0057] The system memory 202 can comprise a computer readable medium 204 comprise a first application 204A and a second application 202A. The first application 181 can be associated with an entity (e.g., an authorizing entity) that manages or provides one or more of the plurality of sources. For example, the first application 204A may be an authorizing entity application or any other suitable source selecting application. The first application 204A may be provided by an authorizing entity and in communication with the authorizing entity (e.g., for receiving information about sources and / or transmitting a user’s selection of a source). The second application 182 can be a wallet application and / or payment application. The second application 182 may be configured to provide interaction functionality and to provide tokens and / or credentials for an interaction. The second application 182 may store one or more tokens and / or credentials which may be associated with a variety of authorizing entities, merchants, network processors, programs, etc.
[0058] The computer readable medium 204 can comprise code, executable by the processor 210 to perform operations comprising: transmitting, to a token service computer, a token request message including a flexible credential, wherein the flexiblePATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001credential is associated with a plurality of real credentials, and each of the plurality of real credentials is associated with a different one of a plurality of sources; receiving, from the token service computer, a flexible token associated with the flexible credential, and a plurality of real tokens each of which is associated with a corresponding one of the plurality of real credentials; receiving, from a user, a first selection of a first source from the plurality of sources; transmitting, to the token service computer, a cryptogram request message comprising a first real token of the plurality of real tokens, where the first real token is associated with the first source; receiving, from the token service computer, a cryptogram response message comprising a cryptogram associated with the first real token; receiving, from the user, a second selection of the flexible token for an interaction; in response to the second selection of the flexible token, determining to use the first real token for the interaction instead of the flexible token; and transmitting, to an access device or a resource provider computer for the interaction, the first real token and the cryptogram, wherein the access device or the resource provider computer processes an authorization request message comprising the first real token and the cryptogram.
[0059] Referring back to FIG. 1, the access device 140 can include a device operated by a resource provider. The access device 140, for example, can include a mobile device, a point of sale (POS) terminal, a laptop computer, a desktop computer, etc. The access device 140 can communicate with another device (e.g., a user device 180) to perform an interaction. During the interaction, the access device 140 can receive credentials from the user device and can provide interaction data to the resource provider computer (not shown) for authorization of the interaction. In some embodiments, the access device 140 can generate an authorization request message comprising at least the interaction data. The access device 140 can provide the authorization request message to the resource provider computer.
[0060] A resource provider computer (not shown) can include any suitable computational apparatus operated by a resource provider (e.g., a merchant). In some embodiments, the resource provider computer may include one or more server computers that may host one or more websites associated with the resource provider (e.g., a merchant). In some embodiments, the resource provider computer may bePATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001configured to send data to the processing computer 142 via the transport computer 141 as part of a payment verification and / or authentication process for a transaction between the user (e.g., consumer) and the resource provider. The resource provider computer may also be configured to generate authorization request messages for interactions between a resource provider and a user and route the authorization request messages to the authorizing entity system 150 for interaction processing.
[0061] The transport computer 141 can include a server computer. The transport computer 141 may be associated with an acquirer, which may be an entity (e.g., a commercial bank) that has a business relationship with a particular merchant or other entity. Some entities can perform both issuer and acquirer functions. Some embodiments may encompass such single entity issuer-acquirers.
[0062] The processing computer 142 can include processing computers, which may be server computers. A processing computer in the processing computer 142 may be disposed between the transport computer 141 and the authorizing entity system 150, as well as a number of other transport computers and authorizing entity computers (not shown). The processing computer may include data processing subsystems, networks, and operations used to support and deliver authorization services, exception file services, and clearing and settlement services. For example, the processing computer may comprise a server coupled to a network interface (e.g., by an external communication interface), and databases of information. The processing computer may be representative of a transaction processing network. An exemplary transaction processing network may include VisaNet™. Transaction processing networks such as VisaNet™ are able to process credit card transactions, debit card transactions, and other types of commercial transactions. VisaNet™, in particular, includes a VIP system (Visa Integrated Payments system) which processes authorization requests and a Base II system which performs clearing and settlement services. The processing computer may use any suitable wired or wireless network, including the Internet.
[0063] The authorizing entity system 150 can include one or more server computers operated by an authorizing entity. For example, as shown, the authorizing entity system 150 can include a first authorizing computer 151, a second authorizingPATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001computer 152, a third authorizing computer 153, and / or any other suitable authorizing computers. The authorizing entity system 150 may be associated with an authorizing entity, which may be an entity that authorizes a request. An example of an authorizing entity may be an issuer, which may typically refer to a business entity (e.g., a bank) that maintains a source (e.g., an account) for a user. An issuer may also issue and manage a source associated with the user device 180.
[0064] In some embodiments, each of the authorizing computers can authorizing interactions for, provide, manage, or otherwise be associated with a predefined source type or source types. For example, the first authorizing computer 151 may be associated with a credit source type, the second authorizing computer 152 may be associated with a debit source type, and the third authorizing computer 153 may be associated with a points source type.
[0065] In some embodiments, a credential and / or token can comprise an account issuer identification number (e.g., a BIN) for the authorizing entity. The BIN can be associated with a source type and / or a specific one of the authorizing computers. Accordingly, a BIN within a credential or token can serve as an indication as to which authorizing computer should be contacted for authorizing an interaction based on that credential. In some embodiments, the account issuer identification number of a flexible credential or flexible token can be a flexible account issuer identification number (e.g., a flexible BIN). A flexible account issuer identification number can indicate that the flexible credential is associated with one or more funding sources (e.g., associated with a first debit account, a second debit account, a first credit account, second credit account, a loyalty points account, etc.). The flexible account issuer identification number can be a portion of an account number such as a primary account number (PAN) included in the flexible credential. For example, the flexible account issuer identification number can include a first 4, 5, 6, 7, 8, 10, 14, etc. numbers of an account number.
[0066] The flexible credential computer 170 (also referred to as an account coordination computer) may be configured to maintain records of groups of sources that are associated and / or configured for interchangeable usage during a transaction. The flexible credential computer 170 may also be configured to provide a flexiblePATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001credential associated with the group of accounts. For example, a flexible credential can be associated with a plurality of real credentials, where each of the plurality of real credentials represent a corresponding one of a plurality of sources. The flexible credential computer 170 may store information about a plurality of flexible credentials and their associations. The flexible credential computer 170 may receive information from the authorizing entity system 150 about real credentials and sources associated with flexible credentials, as well as information about selections of sources or real credentials to be utilized when the flexible credential is utilized for an interaction, etc.
[0067] The token service computer 160 may be configured provide tokens that are associated with credentials. The token service computer 160 may provide tokens for each of the credentials stored by the flexible credential computer 170. The token service computer 160 may be configured to receive flexible credentials, real credentials, source information, and / or any other suitable information from the authorizing entity system 150 and / or the flexible credential computer 170.
[0068] A block diagram illustrating an example of a token service computer is shown in FIG. 3, according to embodiments. The exemplary token service computer 160 may comprise a processor 304, which may be coupled to a memory 302, a network interface 306, and a computer readable medium 308.
[0069] The memory 302 can be used to store data and code. For example, the memory 302 can store interaction data, routing tables, user rules, resource provider rules, etc. The memory 302 may be coupled to the processor 304 internally or externally (e.g., cloud based data storage), and may comprise any combination of volatile and / or non-volatile memory, such as RAM, DRAM, ROM, flash, or any other suitable memory device.
[0070] The network interface 306 may include an interface that can allow the token service computer 160 to communicate with external computers. Some examples of the network interface 306 may include a modem, a physical network interface (such as an Ethernet card or other Network Interface Card (NIC)), a virtual network interface, a communications port, a Personal Computer Memory Card International Association (PCMCIA) slot and card, or the like.PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001
[0071] The computer readable medium may comprise code, executable by the processor 304, for performing a method comprising: receiving, from a user device, a token request message including a flexible credential, wherein the flexible credential is associated with a plurality of real credentials, and each of the plurality of real credentials is associated with a different one of a plurality of sources; in response to the token request message, providing, to the user device, a flexible token associated with the flexible credential, and a plurality of real tokens each of which is associated with a corresponding one of the plurality of real credentials; receiving, from the user device, a cryptogram request message comprising a first real token from the plurality of real tokens; and providing, to the user device, a cryptogram response message comprising a cryptogram associated with the first real token, wherein the user device transmits the first real token and the cryptogram to an access device or a resource provider computer for an interaction in response to receiving a selection of the flexible token for the interaction.
[0072] The computer readable medium 308 may comprise a number of software modules including a tokenization module 308A, a cryptogram module 308B, and a detokenization module 504C.
[0073] The tokenization module 308A can, in conjunction with the processor 304, perform token generation, determine whether a credential is a flexible credential or a real credential, determine whether to provide one token or multiple tokens, etc.
[0074] The cryptogram module 308B can, in conjunction with the processor 304, perform cryptogram generation. For example, generating a cryptogram based on a token and / or any other suitable inputs.
[0075] The detokenization module 308C can, in conjunction with the processor 304, perform de-tokenization. For example, receiving a detokenization request with a token, obtaining a credential associated with the token, and providing the credential.
[0076] Referring back to FIG. 1, some embodiments, the token service computer 160 and the flexible credential computer 170 may be combined into a single computer or system, or otherwise managed by a single entity. Embodiments allowPATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001details and processes discussed with respect to the token service computer 160 to apply to the flexible credential computer 170, and vice versa.
[0077] FIG. 1 also includes a flow diagram for provisioning a flexible token and / or executing an interaction based on a flexible token, according to embodiments.
[0078] The method illustrated in FIG. 1 will be described in the context of a user, operating the user device 180, performing an interaction with a resource provider that operates the access device 140 and / or a resource provider computer. The interaction can be a transaction for the user to obtain a particular resource from the resource provider. However, it is understood that other types of interactions can be processed by the system. For example, the interaction can include a request to access a secure webpage, a request to access and transfer data, a request to access a secure location, etc. Additionally, embodiments allow other entities besides the user device 180 to act as token requestors that request tokens and / or transmit tokens for an interaction, such as a resource provider computer. A user device is one example of a token requestor.
[0079] A user may desire to use a flexible credential via a user device with interaction capabilities. For example, the user may wish to add the flexible credential to a second application (e.g., a mobile wallet) of the user device. The user may activate the second application and / or initiate a process for providing the flexible credential to the second application. The user may present to the user device a payment device (e.g., card) with wireless communications that includes the flexible credential, and the payment device may transmit the flexible credential to the user device. Alternatively, the user device can manually input the flexible credential via a user interface of the user device.
[0080] The flexible credential may be associated with a plurality of real credentials. Each of the plurality of real credentials may be associated with a different one of a plurality of sources. In some embodiments, each of the sources may be a different source type. For example, a first real credential may represent a first source being a credit line or credit account. A second real credential may represent a second source being a debit account. A third real credential may represent a third source being a cryptocurrency account. In some embodiments, each of the sources may bePATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001provided and / or managed by the same authorizing entity. Further, in some embodiments, the authorizing entity may operate multiple authorizing computers, each of which may be dedicated to different types of sources (e.g., a first authorizing computer for credit, a second authorizing computer for debit, a third authorizing computer for points, etc.).
[0081] At step 401, the user device can (e.g., via the second application) transmit a token request message to a token service computer. The token request message can include the flexible credential. The token request message may not include the plurality of real credentials (e.g., as the user may only have provided the flexible credential to the user device).
[0082] At step 402, the token service computer can determine a type of credential included in the token request message. For example, the token service computer can determine that the credential is a flexible credential (e.g., as opposed to a real credential). A flexible credential may be identified to be a flexible credential based on a portion of the credential (e.g., a BIN), based on stored information associated with the credential (e.g., a database indicating credential types associated with various credentials), and / or based on communications with the flexible server computer or the authorizing entity system. By determining that the credential is a flexible credential, the token service computer can thereby determine that the flexible credential is associated with a plurality of real credentials (which can be associated with a plurality of real sources). The token service computer may also lookup or otherwise obtain the plurality of real credentials (e.g., via a local database or the flexible credential computer).
[0083] At step 403, the token service computer can determine to provide a plurality of real tokens corresponding to the plurality of real credentials in addition to a flexible token corresponding to the flexible credential. For example, in response to determining that the credential received in the credential request is a flexible credential, the token service computer can begin a process for providing additional tokens for additional credentials (e.g., the plurality of real credentials) in addition to a token for the received credential (e.g., the flexible credential).PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001
[0084] At step 404, the token service computer can obtain a flexible token associated with the flexible credential. The token service computer can also obtain a plurality of real tokens, each of which can be associated with a corresponding one of the plurality of real credentials. Embodiments allow the token service computer to generate one or more of the flexible token and the plurality of tokens, or to retrieve the flexible token and the plurality of tokens from a database.
[0085] At step 405, in response to the token request message, the token service computer can provide the flexible token to the user device (e.g., via the second application). The token service computer can also provide the plurality of real tokens to the user device. For example, the token service computer can generate and transmit a token response message including the flexible token and the plurality of real tokens to the user device. In some embodiments, the flexible token and the plurality of real tokens can be provided separately. For example, one token per token response message, or a first token response message with the flexible token and a second token response message with the plurality of real tokens. Additionally, the user device may receive additional information associated with each token, such as a source type (e.g., credit, debit) and / or a portion of a real credential corresponding to the token. As a result, the user device can receive multiple tokens in response to a single token response message (e.g., for a single token corresponding to the flexible credential).
[0086] At step 406, the token service computer can also provide the plurality of real tokens to an authorizing entity system. The authorizing entity system may store one or more records indicating which of the plurality of real tokens correspond to which of the plurality of real credentials. As a result, the authorizing entity system can be enabled to recognize and / or verify each of the plurality of real tokens if later received in authorization requests for an interaction. In some embodiments, the authorizing entity system can include a plurality of authorizing computers, each of which may be associated with different type of source. The token service computer may provide each of the plurality of real tokens to an authorizing computer associated with a source type corresponding to that real token. For example, the token service computer may provide a first real token (e.g., associated with a credit source of the user) of the plurality of real tokens to a first authorizing computer (e.g., associated with creditPATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001sources), the token service computer may provide a second real token (e.g., associated with a debit source of the user) of the plurality of real tokens to a second authorizing computer (e.g., associated with debit sources), and / or the token service computer may provide a third real token (e.g., associated with a points source of the user) of the plurality of real tokens to a third authorizing computer (e.g., associated with points sources).
[0087] In addition to preparing the user device with the flexible token, in some embodiments, the user may also select a source for the flexible credential via the user device. For example, the user may activate a first application (e.g., an authorizing entity application) through which a source can be selected for a next interaction involving the flexible credential. This process is described below with respect to steps 407-414. While the steps for selecting the source discussed below are numbered after steps 401-406, selecting the source may occur at any suitable time, including before steps 401 -406.
[0088] At step 407, the user device can (e.g., via the first application) display information associated with each of the plurality of sources. The information associated with each of the plurality of sources can include, for each of the plurality of sources, a source type (e.g., credit, debit, etc.), a name, a portion (e.g., 4 digits) or all of a corresponding one of the plurality of real credentials, an image, an icon, a logo, and / or any other suitable information. The displayed information can include separate information for each of the sources, such that a user can visually distinguish each source and thereby identify a set of selectable options. The user device can also display information associated with the flexible credential and / or an indication that each of the plurality of sources are associated with the flexible credential.
[0089] An example of a user device displaying information associated with each of the plurality of sources is illustrated in FIG. 4A. As illustrated, in some embodiments, the information associated with each of the plurality of sources can include source types for each of three sources. In this example, the source types can be credit, debit, and points. The user may be able to choose a source by selecting (e.g., tap or click) an icon or display area representing a desired source. The user may be able to toggle between different sources via additional selections.PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001
[0090] Referring back to FIG. 1 , at step 408, the user device may receive (e.g., via the first application) a first selection of a first source of the plurality of sources. For example, the user may tap a touchscreen or otherwise indicate a selection of displayed information (e.g., a subset of the total displayed information) corresponding to the first source. The first application may thereby determine a first source and / or a first real credential corresponding to the first source that is selected by the user for use in a subsequent interaction associated with the flexible credential.
[0091] At step 409, the user device can transmit (e.g., via the first application) information about the first selection to an authorizing entity system. The information about the first selection can include any suitable information associated with the first source, such as a source type, a name, and / or a portion (e.g., 4 digits) or all of a first real credential that identifies the first source. The information about the first selection can also include the flexible credential and / or an indication that the first source is selected for use in a subsequent interaction involving the flexible credential. The authorizing entity system can manage or otherwise be associated with the first source and / or the others of the plurality of sources.
[0092] At step 410, in some embodiments, the authorizing entity system may then provide the information about the first selection to a flexible credential computer. The flexible credential computer may then store information about the first selection. For example, the flexible credential computer can store an indication about which of the plurality of sources (e.g., the first source) has been selected for usage in a subsequent interaction involving the flexible credential.
[0093] At step 411, the user device may (e.g., via the second application) transmit a request for the information about the first selection to the flexible credential computer. For example, the second application may not communicate directly with the first application, and thereby may not be able to access information about the first selection. Instead, in some embodiments, the second application may be able to communicate with the flexible credential computer, and may thereby be able to obtain information about which of the plurality of sources associated with the flexible credential has been selected for use the next time the flexible credential is utilized for an interaction.PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001
[0094] At step 412, the user device (e.g., via the second application) may receive information about the first selection from the flexible credential computer. The second application may receive any suitable information associated with the selected first source, such as the source type, a name, and / or a portion or all of the first real credential. The second application can also receive an indication of the flexible credential associated with the first selection. As a result, in some embodiments, information about the first selection received by the first application from the user can be indirectly shared with the second application.
[0095] At step 413, the second application can determine a first real token of the plurality of real tokens based on the first selection. For example, the second application can look up the first real token in a local database based on a source type and / or a portion of a real credential as indicated by the flexible credential computer. The second application can thereby determine which of the plurality of tokens is selected for use in a future interaction.
[0096] At step 414, the user device (e.g., via the second application) may store the information about the first selection. For example, the second application may store an indication that the first real token is selected for use in a future interaction (e.g., in the case that the flexible credential is chosen forthat transaction). The second application may also store an indication about the selected first source, such as the source type and / or a portion or all of the first real credential.
[0097] At step 415, the user device (e.g., via the second application) can transmit a cryptogram request message to the token service computer. The cryptogram request message can comprise the first real token. The cryptogram request message can be sent in response to determining the first real token based on the first selection.
[0098] At step 416, the token service computer can generate a cryptogram. The cryptogram can be associated with the first real token. For example, the token service computer can generate the cryptogram based on the first real token and / or for usage with the first real token.PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001
[0099] At step 417, the token service computer can provide the cryptogram to the user device. For example, the token service computer can generate and send a cryptogram response message comprising a cryptogram to the user device.
[0100] After receiving the plurality or real tokens, the first selection of the first source, and the cryptogram response message with the cryptogram generated for the first real token corresponding to the first source, the user device (e.g., via the second application) may be prepared for conducting an interaction. An interaction may be initiated at any suitable time. In some embodiments, an interaction may be initiated when the user activates an interaction functionality of the user device, and / or when the user presents the user device to an access device, and / or when the user device transmits the first real token and the cryptogram to the access device.
[0101] At step 418, the user device can receive from the user an indication to activate an interaction functionality of the user device. For example, the user can provide input (e.g., taps on a touchscreen) for opening the second application and / or activating an interaction functionality (e.g., mobile payment communications) of the user device and / or first application. The user can thereby initiate an interaction.
[0102] At step 419, the user device can activate the interaction functionality of the user device. In some embodiments, activating the interaction functionality can include presenting credential options (also referred to as payment devices or provisioned tokens) for the user to select. In some embodiments, the user device can (e.g., via the second application) display a set of options (e.g., a plurality of credentials, tokens, and / or other source information) for use in the interaction. One of the available options can be the flexible token. The user device can display information associated with the flexible token, such as a portion (e.g., 4 digits) of the flexible token, a portion (e.g., 4 digits) of the flexible credential, a card image, a logo, a name or other description, and / or any other suitable information that allows the user to identify the flexible token and / or flexible credential.
[0103] An example of a user device displaying information associated with each of the plurality of credential options is illustrated in FIG. 4B. As illustrated, in some embodiments, the information associated with each of the plurality of credentialPATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001options can include card images with merchant names, issuer names, network processor names, brand names, program names, logos, balances, colors, and / or any other suitable information for identifying a type of credential or an associated entity (e.g., merchant, issuer, network, program, etc.). In this example, the flexible token can be represented by a card image with the word “flex”. The user may be able to choose one of the options by selecting (e.g., tap or click) an icon or display area representing a desired option. The user may be able to toggle between different options (e.g., credentials and / or tokens) via additional selections.
[0104] In some embodiments, the user device (e.g., via the second application) may not display information representing the plurality of real tokens or the plurality of real credentials. The user device may solely display information (e.g., text and / or images) representing the flexible credential and / or flexible token, such that the user may be able to select the flexible credential and / or flexible token for an interaction but not directly view or select (at this point) among the plurality of real tokens (or associated credentials or sources) for the interaction. Selection of a source may not be necessary at this point, as the user may have already selected a source via the first selection. For example, as shown in FIG. 4B, the flexible token may be represented by the “flex” card image, and the plurality of sources may not be shown or represented within the card image or otherwise.
[0105] Referring back to FIG. 1, at step 420, the user device can (e.g., via the second application) receive from the user a second selection of the flexible token for an interaction. For example, the user may tap a touchscreen or otherwise indicate a second selection of displayed information associated with the flexible token.
[0106] At step 421, the user device can (e.g., via the second application) determine to use the first real token for the interaction instead of the flexible token. For example, in response to the second selection of the flexible token, the user device can determine that the flexible token is a flexible type of token (e.g., based on a BIN, token formatting, a flag associated with the flexible token in a local database, or any other suitable indicator) that is intended to be replaced with a real token for an interaction. The user device can then identify the first real token associated with the flexible token. For example, the user device can lookup the plurality of real tokensPATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001associated with the flexible token (e.g., in a local database), check stored information about the first selection of the first real token (e.g., from among the plurality of real tokens), or otherwise determine that the first real token is intended to be submitted for an interaction in place of the flexible token (e.g., based on information about the first selection stored by the second application).
[0107] At step 422, the user device can (e.g., via the second application) transmit to the first real token and the cryptogram for the interaction. The user device can transmit the information to an access device (e.g., for an in-person interaction) operated by a resource provider or to a resource provider computer (e.g., via a webpage for an internet-based interaction) operated by a resource provider. The user and / or user device can indicate a particular resource to obtain from the resource provider for the interaction.
[0108] According to embodiments, the user device may not provide the flexible token for the interaction. Even though the flexible token was selected for the interaction (e.g., via the second selection), the user device may provide the first real token instead of the flexible token. Additionally, the cryptogram may be generated based on the first real token and / or otherwise correspond to the first real token and not the flexible token. The user device may not possess or provide a second cryptogram generated based on or otherwise corresponding to the flexible token. As a result, from this point forward, the interaction can proceed using the first real token and not the flexible token, according to embodiments.
[0109] The interaction may be a financial transaction between the user operating the user device and a resource provider associated with the access device and / or the resource provider computer. The access device or the resource provider computer can then process an authorization request message comprising the first real token, the cryptogram, an amount for the interaction, and / or any other suitable information. For example, at step 423, the access device can generate and transmit an authorization request message to a transport computer. In some embodiments, the access device can forward the first real token and the cryptogram to a resource provider computer, and the resource provider computer can then generate and transmit the authorization request message to the transport computer.PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001
[0110] At step 424, the transport computer can forward the authorization request message to the processing computer. As a result, the access device can forward the authorization request message to the processing computer via the transport computer.
[0111] At step 425, the processing computer can send a detokenization request to the token service computer including the first real token (e.g., extracting from the authorization request message). At step 426, the token service computer can identify the first real credential associated with the first real token (e.g., via a local database). At step 427, the token service computer can provide the first real credential to the processing computer.
[0112] At step 428, the processing computer can update the authorization request message to include a first real credential. The updated authorization request may include both the first real token and the first real credential, according to embodiments. At step 429, the processing computer can forward the updated authorization request message to an authorizing entity system. Specifically, the processing computer can identify a first authorizing computer from among a plurality of authorizing computers within the authorizing entity system, where the first authorizing computer is associated with the first source. For example, the first source may have a certain source type (e.g. credit), and the first authorizing computer may be configured to authorize interactions involving that same source type (e.g., credit). The processing computer may identify the source type and / or corresponding authorizing computer based on a portion of (e.g., the first four digits) of the first real token, a BIN of the first real token, formatting of the first real token, and / or local records associated with the first real token.
[0113] At step 430, the authorizing entity system (e.g., via the first authorizing computer) can identify a first source of the plurality of sources based on the first real credential. The authorizing entity system can then authorize the interaction based on the first source. Additionally, the authorizing entity system can verify the cryptogram. For example, the authorizing entity system can verify the cryptogram based on the first real token.PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001
[0114] At step 431, the authorizing entity system (e.g., via the first authorizing computer) can generate and send an authorization response message to the processing computer indicating that the interaction has been authorized. At step 432, the processing computer can update the authorization response message. For example, by removing the first real credential and / or inserting the first real token. By doing so, the system can solve a technical problem of real credential security, by switching the first real credential with the first real token when communicating with the transport computer 141 and the resource provider computer. The processing computer can then forward the authorization response message to the transport computer. At step 433, the transport computer can forward the authorization response message to the resource provider computer and / or access device (e.g., via the resource provider computer). The resource provider computer can determine that the interaction is authorized, and then in response provide goods and / or services to the user.
[0115] As a result, embodiments allow an interaction to be initiated at a user device by a user selecting a flexible credential (e.g., the flexible token). By enabling the user device to swap the flexible token for the first real token and obtaining a cryptogram for the first real token before the interaction begins, embodiments allow the authorizing entity system (e.g., via the first authorizing computer) to receive and verify a cryptogram that is generated based on credential information included in the authorization request message (e.g., the first real token instead of the flexible token). Additionally, by providing the first real token instead of the flexible token, the authorizing request message can be routed to a first authorizing computer (e.g., from among a plurality of authorizing computers) that is associated with the selected first source.
[0116] Referring back to step 420, in some embodiments, the user device may receive the second selection in real time when an interaction is being conducted. For example, as discussed above, the interaction functionality of the user device can be activated for an interaction, and the user may select the flexible token at that time. Alternatively, in other embodiments, the user device may receive the second selection at an earlier time. For example, at an earlier time, the user may configure the second application to use the flexible token as a default payment method whenever thePATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001interaction functionality is activated, or to otherwise use the flexible token for the next interaction. Then, when the interaction functionality is activated, the user device can automatically utilize the flexible token for the interaction according to a second selection of the flexible token that was received at an earlier time. Further, in some embodiments, the second selection of the flexible token according to step 420 may occur at an earlier time than the first selection of the first source according to step 408.Accordingly, the first selection and second selection can be received in any suitable order and at any suitable times.
[0117] Referring back to step 402, in some embodiments, the token service computer may determine that the credential received in the token request message is a flexible credential via communications with the flexible credential server. For example, the token service computer may send an eligibility request including the credential to the flexible credential computer. The flexible credential computer may then provide a response to the token service computer indicating whether the credential is a flexible credential (e.g., after checking local records associated with the credential). In some embodiments, the flexible credential computer may also provide the plurality of real credentials to the tokens service computer.
[0118] Referring back to step 403, in some embodiments, determining to provide the plurality of real tokens can include additional communications with the user device. For example, the tokens service computer may send a message to the user device informing the user device that the credential provided in the token request message is a flexible credential. In some embodiments, this can be a first token response message including the flexible token and further including an indication that the token is a flexible token. In response, the user device (e.g., via the second application) may send one or more additional token request messages requesting additional tokens corresponding to the plurality of real credentials. The token service computer can then determine to provide the plurality of real tokens in response to the additional token request messages.
[0119] Referring back to step 411 and step 412, as discussed above, the user device may (e.g., via the second application) obtain the information about the first selection via communications with the flexible credential computer. However, in somePATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001embodiments, the user device may instead obtain the information about the first selection via communications with the token service computer. The token service computer may have previously received the information about the first selection from the flexible credential computer or from the authorizing entity system. For example, at step 410, the authorizing entity system may provide the information about the first selection to the token service computer instead of the flexible credential computer.
[0120] Referring back to step 401, in some embodiments, the first token request message can include a first real credential of the plurality of real credentials instead of the flexible credential. For example, the user may present to the user device a payment card associated with the first real credential instead of the flexible credential. Then, at step 402, the token service computer can determine that the first real credential is associated with the flexible credential and / or plurality of real credentials. The remaining steps can occur in the same or similar manner. Thereby, the user device can transmit a token request message with a single real credential for a single real token, and then receive a plurality of real tokens and / or a flexible token.
[0121] FIG. 5 shows another flow diagram for provisioning a flexible token and / or executing an interaction based on a flexible token, according to embodiments. The process illustrated in FIG. 5 can be similar to orthe same as the process illustrated in FIG. 1 in many respects. However, while FIG. 1 illustrates steps for a source being selected via the first application and then communicated to the second application via the authorizing entity system, the flexible credential computer, and the token service computer, the process in FIG. 5 allows the user to instead select the source via the second application. Accordingly, the first selection and the second selection can both received by the same application (e.g., the second application) of the user device.
[0122] Steps 501-506 can be the same as or similar to steps 401-406, and they will not be repeated here.
[0123] Step 507 can be similar to step 407, except displaying the information associated with each of the plurality of sources can be performed via the second application instead of the first application. The second application may display the plurality of sources along with the flexible token and / or flexible credential. The pluralityPATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001of sources may be displayed in a manner indicating that they are associated with the flexible token. For example, as selectable options within a larger representation of the flexible token. The flexible token can also be displayed along with other selected credential options, similar to step 419.
[0124] Step 508 can be similar to step 408, except receiving the first selection of a first source of the plurality of sources can be performed via the second application instead of the first application. Further, in some embodiments, the user can provide the first selection of the first source and the second selection of the flexible token at a same or similar time. For example, within the second application, the user’s selection of the first source may serve as a selection of both the first source and the flexible token (e.g., from among other credential options) for the next interaction. In such a manner, steps 508 and 520 can be combined.
[0125] Steps 409-412 can be omitted in FIG. 5, as the second application can instead receive information about the first selection more directly via step 508, and the method can proceed directly to step 513. Steps 513-533 can be the same as or similar to steps 413-433, and they will not be repeated here.
[0126] Embodiments allow the processes of FIG. 1 and FIG. 5 to be combined. For example, a user may initially provide the first selection via the first application, as discussed with respect to FIG. 1. Subsequently, the user may be able to update or modify the first selection via the second application as discussed above with respect to FIG. 5. In other words, the user may be able to choose the source via either or both of the first application and the second application.
[0127] FIG. 6 shows another flow diagram for provisioning a flexible token and / or executing an interaction based on a flexible token, according to embodiments. The process illustrated in FIG. 6 can be similar to orthe same as the process illustrated in FIG. 1 in many respects. However, while FIG. 1 includes steps for provisioning the plurality of real tokens along with the flexible token to the user device, the process in FIG. 6 initially provisions just the flexible token, and then the first real token can be obtained later on along with the cryptogram.PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001
[0128] Steps 601-602 can be the same as or similar to steps 401-402, and they will not be repeated here.
[0129] Step 603 can be similar to step 403, except the token service computer can determine to provide information corresponding to the plurality of sources instead of providing the plurality of real tokens.
[0130] Step 604 can be similar to step 404, except the token service computer can obtain information about the plurality of sources corresponding to the plurality of real credentials. The token service computer may still obtain the plurality of real tokens, but may store them locally instead of providing them to the user device. Alternatively, the tokens service computer may generate or obtain a real token later on at the same time as generating the cryptogram.
[0131] Step 605 can be similar to step 405, except the token service computer can, instead of providing the plurality of real tokens, provide information about the plurality of sources corresponding to the plurality of real credentials to the user device. The information about the plurality of sources can, for each source, a source type (e.g., credit, debit, etc.), a portion (e.g., 4 digits) or a corresponding one of the plurality of real credentials, an image, an icon, a logo, and / or any other suitable information. The token service computer can still provide the flexible token. As a result, the user device can receive the flexible token along with information about the types of sources that can be used via the flexible token.
[0132] Steps 606-612 can be the same as or similar to steps 406-412, and they will not be repeated here. Step 413 can be omitted, as the user device may not yet be in possession of the first real token. Step 614 can be the same as or similar to step 414, and it will not be repeated here.
[0133] Step 615 can be similar to step 415, except the cryptogram request message may instead take the form of a token request message. The token request message may include the flexible token and an indication of the selected first source (e.g., a source type, a BIN, a portion of the first real credential, etc.). The token request message can be sent in response to receiving the information about the first selection at step 612. Thus, a second token request message including can be sent in order toPATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001obtain a second token. The token request message of step 601 can be a first token request message.
[0134] Step 616 can be similar to step 416, except the token service computer can obtain (e.g., generate or look up) a first real token corresponding to the first real credential. This can be in addition to generating a cryptogram based on the first real token.
[0135] Step 617 can be similar to step 417, except the token service computer can provide the first real token to the user device along with the cryptogram. For example, the token service computer can generate and send a token response message comprising the first real token and the cryptogram to the user device. Accordingly, in some embodiments, the user device may receive a single real token of the plurality of real tokens instead of all of the plurality of real tokens. The token response message can be a second token response message, where the flexible token was provided in a first token response message.
[0136] Steps 618-633 can be the same as or similar to steps 418-433, and they will not be repeated here.
[0137] In some embodiments, after the first real token is transmitted for an interaction or otherwise utilized, the user device may obtain another real token. Each real token may be a single use token. To obtain a new real token, the user device may send another token request message (e.g., a third token request message) to request a real token from the plurality of real tokens that corresponds to a currently selected source, which may be the same first source or a different one of the plurality of sources. The user may update the selected source (e.g., provide a new first selection) at any suitable time.
[0138] It can be advantageous to provide a single real token to the user device instead of a plurality of real tokens, as this can reduce computing needs utilizing by provisioning tokens to the user device, and this can increase data security by limiting the transmission of sensitive data. Additionally, this can enable a more simple and frequent process for providing updated real tokens (including the cycling of real tokensPATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001corresponding to the same source), as a new token can be provided for each interaction.
[0139] FIG. 7 shows another flow diagram for provisioning a flexible token and / or executing an interaction based on a flexible token, according to embodiments. The process illustrated in FIG.7 can be similar to orthe same as the process illustrated in FIG. 6 in many respects. However, while FIG. 6 illustrates steps for a source being selected via the first application and then communicated to the second application via the authorizing entity system, the flexible credential computer, and the token service computer, the process in FIG. 7 allows the user to instead select the source via the second application. Accordingly, the first selection and the second selection can both be received by the same application (e.g., the second application) of the user device. In other words, the process of FIG. 7 can be modified relative to the process FIG. 6 similar to how the process of FIG. 5 is modified relative to the process of FIG. 1.
[0140] Steps 701-706 can be the same as or similar to steps 601-606, and they will not be repeated here.
[0141] Step 707 can be similar to step 607, except displaying the information associated with each of the plurality of sources can be performed via the second application instead of the first application. The second application may display the plurality of sources along with the flexible token and / or flexible credential. The plurality of sources may be displayed in a manner indicating that they are associated with the flexible token. For example, as selectable options within a larger representation of the flexible token. The flexible token can also be displayed along with other selected credential options, similar to step 619.
[0142] Step 708 can be similar to step 608, except receiving the first selection of a first source of the plurality of sources can be performed via the second application instead of the first application. Further, in some embodiments, the user can provide the first selection of the first source and the second selection of the flexible token at a same or similar time. For example, within the second application, the user’s selection of the first source may serve as a selection of both the first source and the flexiblePATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001token (e.g., from among other credential options) for the next interaction. In such a manner, steps 708 and 720 can be combined.
[0143] Steps 609-612 can be omitted in FIG. 7, as the second application can instead receive information about the first selection more directly via step 708, and the method can proceed directly to step 714 (e.g., where there is no step 613 or step 713).Steps 714-733 can be the same as or similar to steps 614-633, and they will not be repeated here.
[0144] Embodiments allow the processes of FIG. 6 and FIG. 7 to be combined. For example, a user may initially provide the first selection via the first application, as discussed with respect to FIG. 6. Subsequently, the user may be able to update or modify the first selection via the second application as discussed above with respect to FIG.7. In otherwords, the user may be able to choose one of the plurality of sources via either or both of the first application and the second application.
[0145] Embodiments of the invention have a number of advantages. For example, embodiments allow for flexible credentials to be utilized with user devices, thereby allowing payment applications and mobile wallets to be decluttered, simplified, and easier to operate, as a single flexible credential (or associated visual display) can replace multiple real credentials within an application. The advantages of flexible payment cards can be realized within user device applications. Further, this functionality can be achieved without compromising an authorizing entity’s ability to verify a cryptogram, as the flexible credential (or token) can be swapped for a preselected real credential (or token) before an interaction begins, thereby allowing the cryptogram to be generated based on information that the authorizing entity can recognize or otherwise process.
[0146] Embodiments of the invention also advantageously allow multiple tokens for different sources to be provisioned in response to a token request with a single credential (e.g., the flexible credential). This reduces the overall number of messages, reduces the latency of the computers, and reduces the total computational requirements of the system. This also reduced the burden on the user, as the user can present a single card or credential instead of multiple.PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001
[0147] Further embodiments of the invention relate to a method comprising: transmitting, by a user device to a token service computer, a first token request message including a flexible credential, wherein the flexible credential is associated with a plurality of real credentials, and each of the plurality of real credentials is associated with a different one of a plurality of sources; receiving, by the user device from the token service computer, a flexible token associated with the flexible credential; receiving, by the user device from a user, a first selection of a first source from the plurality of sources; transmitting, by the user device to the token service computer, a second token request message including the flexible token; receiving, by the user device from the token service computer, a first real token and a cryptogram associated with the first real token, where the first real token is associated with a first real credential of the plurality of real credentials, and the first real credential is associated with the first source; receiving, by the user device from the user, a second selection of the flexible token for an interaction; in response to the second selection of the flexible token, determining, by the user device, to use the first real token for the interaction instead of the flexible token; and transmitting, by the user device to an access device or a resource provider computer for the interaction, the first real token and the cryptogram, wherein the access device or the resource provider computer processes an authorization request message comprising the first real token and the cryptogram.
[0148] According to further embodiments, the first selection is received by a first application of the user device, the second selection is received by a second application of the user device, and further comprising: transmitting, by the first application to an authorizing entity computer, information about the first selection, wherein the authorizing entity computer provides the information about the first selection to a flexible credential computer; and receiving, by the second application from the flexible credential computer, the information about the first selection; and storing, by the second application, the information about the first selection, wherein determining to use the first real token for the interaction in response to the second selection of the flexible token is performed by the second application and based on the information about the first selection stored by the second application.PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001
[0149] According to further embodiments, the method further comprises transmitting, by the second application to the flexible credential computer, a request for the information about the first selection.
[0150] According to further embodiments, the method further comprises displaying, by the user device via the first application, information associated with each of the plurality of sources, wherein receiving the first selection of the first source from the plurality of sources includes receiving a selection of displayed information associated with the first source; and displaying, by the user device via the second application, information associated with the flexible token, wherein receiving the second selection of the flexible token includes receiving a selection of displayed information associated with the flexible token.
[0151] According to further embodiments, the second application does not display the information associated with each of the plurality of sources.
[0152] According to further embodiments, the information associated with each of the plurality of sources includes, for each of the plurality of sources, a source type or a portion of a corresponding one of the plurality of real credentials.
[0153] According to further embodiments, the first selection and the second selection are both received by the same application of the user device, and further comprising: receiving, by the user device from the token service computer, in response to the first token request message, information associated with each of the plurality of sources including, for each of the plurality of sources, a source type or a portion of a corresponding one of the plurality of real credentials; displaying, by the user device, the information associated with each of the plurality of sources, wherein receiving the first selection of the first source from the plurality of sources includes receiving a selection of displayed information associated with the first source; and storing, by the user device, information about the first selection, and wherein determining to use the first real token for the interaction in response to the second selection of the flexible token is based on the information about the first selection stored by the user device.
[0154] According to further embodiments, the second token request message further includes an indication of the first source based on the first selection.PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001
[0155] According to further embodiments, the indication of the first source includes a source type or a portion of the first real credential.
[0156] According to further embodiments, the method further comprises, after the interaction, receiving, by the user device from the token service computer, a second real token for a subsequent interaction, where the second real token is associated with the first real credential of the plurality of real credentials, and where the second real token is different than the first real token.
[0157] According to further embodiments the first real token is one of a plurality of real tokens stored by the token service computer, wherein each of the plurality of real tokens is associated with a corresponding one of the plurality of real credentials.
[0158] According to further embodiments, the method further, after receiving the first selection and after receiving the first real token, receiving, by the user device from the user, an indication to activate an interaction functionality of the user device; and activating the interaction functionality of the user device.
[0159] According to further embodiments the interaction is between the user and a resource provider associated with the access device or the resource provider computer, the authorization request message further includes an amount for the interaction.
[0160] According to further embodiments the access device or the resource provider computer processes the authorization request message by forwarding the authorization request message to a processing computer, the processing computer modifies the authorization request message to include the first real credential associated with the first real token, the processing computerforwards the authorization request message to an authorizing entity computer, the authorizing entity computer authorizes the interaction based on the first source as identified by the first real credential, and the authorizing entity computer verifies the cryptogram based on the first real token.
[0161] One embodiment is related to a user device comprising: a processor; and a computer-readable medium coupled to the processor, the computer-readable medium comprising code executable by the processor for implementing a methodPATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001comprising: transmitting, to a token service computer, a first token request message including a flexible credential, wherein the flexible credential is associated with a plurality of real credentials, and each of the plurality of real credentials is associated with a different one of a plurality of sources; receiving, from the token service computer, a flexible token associated with the flexible credential; receiving, from a user, a first selection of a first source from the plurality of sources; transmitting, to the token service computer, a second token request message including the flexible token; receiving, from the token service computer, a first real token and a cryptogram associated with the first real token, where the first real token is associated with a first real credential of the plurality of real credentials, and the first real credential is associated with the first source; receiving, from the user, a second selection of the flexible token for an interaction; in response to the second selection of the flexible token, determining to use the first real token for the interaction instead of the flexible token; and transmitting, by the user device to an access device or a resource provider computer for the interaction, the first real token and the cryptogram, wherein the access device or the resource provider computer processes an authorization request message comprising the first real token and the cryptogram.
[0162] One embodiment is related to a method comprising: receiving, by a token service computer from a user device, a first token request message including a flexible credential, wherein the flexible credential is associated with a plurality of real credentials, and each of the plurality of real credentials is associated with a different one of a plurality of sources; in response to the first token request message, providing, by the token service computer to the user device, a flexible token associated with the flexible credential; receiving, by the token service computer from the user device, a second token request message comprising the flexible token; and providing, by the token service computer to the user device, a first real token and a cryptogram associated with the first real token, where the first real token is associated with a first real credential of the plurality of real credentials, and the first real credential is associated with a first source of the plurality of sources, wherein the user device transmits the first real token and the cryptogram to an access device or a resourcePATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001provider computer for an interaction in response to receiving a selection of the flexible token for the interaction.
[0163] According to further embodiments the second token request message further comprises an indication of the first source based on a user selection of the first source.
[0164] According to further embodiments the method further includes determining, by the token service computer, that the flexible credential is associated with the plurality of real credentials, wherein the first token request message does not include the plurality of real credentials.
[0165] According to further embodiments the access device or the resource provider computer transmits an authorization request message comprising the first real token and the cryptogram to processing computer, and further comprising: receiving, by the token service computer from the processing computer, a detokenization request including the first real token; identifying, by the token service computer, the first real credential of the plurality of real credentials associated with the first real token; and providing, by the token service computer to the processing computer, the first real credential associated with the first real token.
[0166] According to further embodiments, the processing computer modifies the authorization request message to include the first real credential associated with the first real token, the processing computer forwards the authorization request message to an authorizing entity computer, the authorizing entity computer authorizes the interaction based on the first source as identified by the first real credential, and the authorizing entity computer verifies the cryptogram based on the first real token.
[0167] Although the steps in the flowcharts and process flows described above are illustrated or described in a specific order, it is understood that embodiments of the invention may include methods that have the steps in different orders. In addition, steps may be omitted or added and may still be within embodiments of the invention.
[0168] Any of the software components or functions described in this application, may be implemented as software code to be executed by a processor using any suitable computer language such as, for example, Java, C++, or Perl using,PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001for example, conventional or object-oriented techniques. The software code may be stored as a series of instructions, or commands on a computer readable medium, such as a random access memory (RAM), a read only memory (ROM), a magnetic medium such as a hard-drive or a floppy disk, or an optical medium such as a CD-ROM. Any such computer readable medium may reside on or within a single computational apparatus, and may be presenton or within different computational apparatuses within a system or network.
[0169] The above description is illustrative and is not restrictive. Many variations of the invention may become apparent to those skilled in the art upon review of the disclosure. The scope of the invention can, therefore, be determined not with reference to the above description, but instead can be determined with reference to the pending claims along with their full scope or equivalents.
[0170] One or more features from any embodiment may be combined with one or more features of any other embodiment without departing from the scope of the invention.
[0171] A recitation of “a”, “an” or “the” is intended to mean “one or more” unless specifically indicated to the contrary.
[0172] All patents, patent applications, publications, and descriptions mentioned above are herein incorporated by reference in their entirety for all purposes. None is admitted to be prior art.
Claims
PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001WHAT IS CLAIMED IS:
1. A method comprising:transmitting, by a user device to a token service computer, a token request message including a flexible credential, wherein the flexible credential is associated with a plurality of real credentials, and each of the plurality of real credentials is associated with a different one of a plurality of sources;receiving, by the user device from the token service computer, a flexible token associated with the flexible credential, and a plurality of real tokens each of which is associated with a corresponding one of the plurality of real credentials;receiving, by the user device from a user, a first selection of a first source from the plurality of sources;transmitting, by the user device to the token service computer, a cryptogram request message comprising a first real token of the plurality of real tokens, where the first real token is associated with the first source;receiving, by the user device from the token service computer, a cryptogram response message comprising a cryptogram associated with the first real token; receiving, by the user device from the user, a second selection of the flexible token for an interaction;in response to the second selection of the flexible token, determining, by the user device, to use the first real token for the interaction instead of the flexible token; andtransmitting, by the user device to an access device or a resource provider computer for the interaction, the first real token and the cryptogram, wherein the access device or the resource provider computer processes an authorization request message comprising the first real token and the cryptogram.
2. The method of claim 1 , wherein the first selection is received by a first application of the user device, the second selection is received by a second application of the user device, and further comprising:PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001transmitting, by the first application to an authorizing entity computer, information about the first selection, wherein the authorizing entity computer provides the information about the first selection to a flexible credential computer; and receiving, by the second application from the flexible credential computer, the information about the first selection; andstoring, by the second application, the information about the first selection, wherein determining to use the first real token for the interaction in response to the second selection of the flexible token is performed by the second application and based on the information about the first selection stored by the second application.
3. The method of claim 2, further comprising:transmitting, by the second application to the flexible credential computer, a request for the information about the first selection.
4. The method of claim 2, further comprising:displaying, by the user device via the first application, information associated with each of the plurality of sources, wherein receiving the first selection of the first source from the plurality of sources includes receiving a selection of displayed information associated with the first source; anddisplaying, by the user device via the second application, information associated with the flexible token, wherein receiving the second selection of the flexible token includes receiving a selection of displayed information associated with the flexible token.
5. The method of claim 4, wherein the second application does not display the information representing each of the plurality of real tokens.
6. The method of claim 4, wherein the information associated with each of the plurality of sources includes, for each of the plurality of sources, a source type or a portion of a corresponding one of the plurality of real credentials.PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W0017. The method of claim 1 , wherein the first selection and the second selection are both received by the same application of the user device, and further comprising:storing, by the user device, information about the first selection, and wherein determining to use the first real token for the interaction in response to the second selection of the flexible token is based on the information about the first selection stored by the user device.
8. The method of claim 1 , wherein each of the plurality of sources has a different source type, and wherein each of the plurality of sources are provided by the same authorizing entity.
9. The method of claim 1 , wherein receiving the first selection, receiving the plurality of real tokens, and receiving the cryptogram response message all occur before the interaction is initiated.
10. The method of claim 7, wherein the interaction is initiated when the user presents the user device to the access device for transmitting the first real token and the cryptogram.
11. The method of claim 1 , wherein the user device does not provide the flexible token to the access device for the interaction even though the flexible token was selected for the interaction, and the user device does not receive or provide a second cryptogram generated based on the flexible token.
12. The method of claim 1 , further comprising:after receiving the first selection and after receiving the cryptogram response message, receiving, by the user device from the user, an indication to activate an interaction functionality of the user device; andactivating the interaction functionality of the user device.PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W00113. The method of claim 1 , wherein the interaction is between the user and a resource provider associated with the access device or the resource provider computer, the authorization request message further includes an amount for the interaction.
14. The method of claim 1 , wherein the access device or the resource provider computer processes the authorization request message by forwarding the authorization request message to a processing computer, the processing computer modifies the authorization request message to include a real credential associated with the first real token, the processing computer forwards the authorization request message to an authorizing entity computer, the authorizing entity computer authorizes the interaction based on a source of the plurality of sources that is identified by the real credential, and the authorizing entity computer verifies the cryptogram based on the first real token.
15. A user device comprising:a processor; anda computer-readable medium coupled to the processor, the computer-readable medium comprising code executable by the processor for implementing a method comprising:transmitting, to a token service computer, a token request message including a flexible credential, wherein the flexible credential is associated with a plurality of real credentials, and each of the plurality of real credentials is associated with a different one of a plurality of sources;receiving, from the token service computer, a flexible token associated with the flexible credential, and a plurality of real tokens each of which is associated with a corresponding one of the plurality of real credentials;receiving, from a user, a first selection of a first source from the plurality of sources;transmitting, to the token service computer, a cryptogram request message comprising a first real token of the plurality of real tokens, where the first real token is associated with the first source;PATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001receiving, from the token service computer, a cryptogram response message comprising a cryptogram associated with the first real token;receiving, from the user, a second selection of the flexible token for an interaction;in response to the second selection of the flexible token, determining to use the first real token for the interaction instead of the flexible token; and transmitting, to an access device or a resource provider computer for the interaction, the first real token and the cryptogram, wherein the access device or the resource provider computer processes an authorization request message comprising the first real token and the cryptogram.
16. A method comprising:receiving, by a token service computer from a user device, a token request message including a flexible credential, wherein the flexible credential is associated with a plurality of real credentials, and each of the plurality of real credentials is associated with a different one of a plurality of sources;in response to the token request message, providing, by the token service computer to the user device, a flexible token associated with the flexible credential, and a plurality of real tokens each of which is associated with a corresponding one of the plurality of real credentials;receiving, by the token service computer from the user device, a cryptogram request message comprising a first real token from the plurality of real tokens; and providing, by the token service computer to the user device, a cryptogram response message comprising a cryptogram associated with the first real token, wherein the user device transmits the first real token and the cryptogram to an access device or a resource provider computer for an interaction in response to receiving a selection of the flexible token for the interaction.
17. The method of claim 16, further comprising:generating, by the token service computer, the flexible token and the plurality of real tokens; andPATENT Attorney Docket No. 079900-1539554 Client Ref. No.: 10148W001generating, by the token service computer, the cryptogram based on the first real token.
18. The method of claim 16, further comprising:determining, by the token service computer, that the flexible credential is associated with the plurality of real credentials, wherein the token request message does not include the plurality of real credentials; anddetermining, by the token service computer, to provide the plurality of real tokens in addition to the flexible token.
19. The method of claim 16, wherein the access device or the resource provider computer transmits an authorization request message comprising the first real token and the cryptogram to processing computer, and further comprising:receiving, by the token service computer from the processing computer, a detokenization request including the first real token;identifying, by the token service computer, a first real credential of the plurality of real credentials associated with the first real token; andproviding, by the token service computer to the processing computer, the first real credential associated with the first real token.
20. The method of claim 19, wherein the processing computer modifies the authorization request message to include the first real credential associated with the first real token, the processing computer forwards the authorization request message to an authorizing entity computer, the authorizing entity computer authorizes the interaction based on a source of the plurality of sources that is identified by the first real credential, and the authorizing entity computer verifies the cryptogram based on the first real token.