US2015120556A1PendingUtilityA1

Securing payment transactions with rotating application transaction counters

Assignee: GOOGLE INCPriority: Oct 30, 2013Filed: Aug 26, 2014Published: Apr 30, 2015
Est. expiryOct 30, 2033(~7.3 yrs left)· nominal 20-yr term from priority
G06Q 20/40G06Q 20/385G06Q 40/00G06F 21/45G06Q 20/3227G06Q 20/3278H04L 63/123G06Q 20/326G06Q 20/382
66
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An account management system creates a bundle of private application transaction counters (ATCs) and a bundle of corresponding public ATCs, and transmits them to a user device. The device receives a request for payment information from a merchant and processes the request without accessing a secure element processor on the device. The device calculates a security code using one of the bundle of private ATCs and a transaction number received from the merchant. The device transmits proxy account information, the calculated security code, and the corresponding public ATCs to the merchant. The merchant transmits a payment request to the account management system as the issuer of the proxy account information. The account management system retrieves the private ATC using the public ATC, and determines the validity of the security code by recomputing it. The account management system retrieves the financial account information and requests authorization from the issuer.

Claims

exact text as granted — not AI-modified
1 . A computer-implemented method to process financial transactions, comprising:
 receiving, by a computing device associated with a user, a request for payment information from a merchant computing system to process a payment transaction, the request for payment information comprising a request for payment account information and a merchant computing m transaction code;   processing, by the computing device associated with the user, the request for payment information without accessing a secure element of the computing device associated with the user;   generating, by the computing device associated with the user without accessing the secure element, a security code using the merchant computing system transaction code and a private application transaction counter;   transmitting, by the computing device associated with the user and to the merchant computing system, a response to the request for payment information, wherein information in the response comprises payment account information, a public application transaction counter corresponding to the private application transaction counter, and the generated security code, and wherein the information is transmitted by the merchant computing system to an account management system for payment approval in a payment processing request; and   receiving, by the computing device associated with the user, a notification of an approved payment transaction, the notification of the approved payment transaction indicating that the account management system confirmed the validity of the generated security code received in the payment processing request from the merchant computing system.   
     
     
         2 . The computer-implemented method of  claim 1 , wherein the public application transaction counter expires after a pre-defined period of time. 
     
     
         3 . The computer-implemented method of  claim 1 , wherein the public application transaction counter is valid for a single payment transaction. 
     
     
         4 . The computer-implemented method of  claim 1 , further comprising receiving, by the computing device associated with the user, a bundle of public application transaction counters and a bundle of corresponding private application transaction counters from the account management system. 
     
     
         5 . The computer-implemented method of  claim 4 , wherein the bundle of public application transaction counters comprises a set of randomly generated values that are limited in time and number. 
     
     
         6 . The computer-implemented method of  claim 1 , further comprising receiving, by the computing device associated with the user, proxy account information, wherein the payment account information comprises the proxy account information. 
     
     
         7 . The computer-implemented method of  claim 1 , wherein the security code comprises a dynamic card verification number. 
     
     
         8 . The computer-implemented method of  claim 1 , further comprising determining, by the computing device associated with the user, that the public application transaction counter and the corresponding private application transaction counter are available and not expired. 
     
     
         9 . The computer-implemented method of  claim 1 , further comprising confirming, by the account management system, the validity of the public application transaction counter by determining that the public application transaction counter is not expired and not previously used. 
     
     
         10 . The computer-implemented method of  claim 1 , wherein the account management system uses the public application transaction counter received in the payment processing request to retrieve the corresponding private application transaction counter, and wherein the retrieved private application transaction counter is used to recompute the generated security code. 
     
     
         11 . The computer-implemented method of  claim 10 , wherein the account management system confirms the validity of the generated security code by confirming the recomputed security code matches the generated security code received in the payment processing request. 
     
     
         12 . A computer program product, comprising:
 a non-transitory computer-readable medium having computer-readable program instructions embodied thereon that when executed by a computer cause the computer to process financial transactions, the computer-readable program instructions comprising:
 computer-readable program instructions for receiving a request for payment information from a merchant computing system to process a payment transaction, the request for payment information comprising a request for payment account information and a merchant computing m transaction code; 
 computer-readable program instructions for processing the request for payment information without accessing a secure element of the computer; 
 computer-readable program instructions for generating a security code using the merchant computing system transaction code and a private application transaction counter; 
 computer-readable program instructions for transmitting to the merchant computing m a response to the request for payment information, wherein information in the response comprises payment account information, a public application transaction counter corresponding to the private application transaction counter, and the generated security code, wherein the information is transmitted by the merchant computing system to an account management system for payment approval in a payment processing request; and 
 computer-readable program instructions for receiving a notification of an approved payment transaction, the notification of the approved payment transaction indicating that the account management system confirmed the validity of the generated security code received in the payment processing request from the merchant computing. 
   
     
     
         13 . The computer program product of  claim 12 , further comprising computer-readable program instructions for receiving a bundle of public application transaction counters from the account management system, wherein the bundle of public application transaction counters comprises a set of randomly generated values that are limited in time and number. 
     
     
         14 . The computer program product of  claim 12 , wherein the account management system uses the public application transaction counter received in the payment processing request to retrieve the corresponding private application transaction counter, and wherein the retrieved corresponding private application transaction counter is used to recompute the generated security code. 
     
     
         15 . The computer program product of  claim 14 , wherein the account management system confirms the validity of the generated security code by confirming the recomputed security code matches the generated security code received in the payment processing request. 
     
     
         16 . A system for processing financial transactions, comprising:
 a user computing device,
 wherein the user computing device comprises a storage device and a processor communicatively coupled to the storage device, and wherein the processor executes application code instructions that are stored in the storage device without accessing a secure element to cause the system to:
 receive, from a merchant computing m a request for payment information from a merchant computing system to process a payment transaction, the request for payment information comprising a request for payment account information and a merchant computing m transaction code; 
 process the request for payment information without accessing the secure element; 
 generate a security code using the merchant computing m transaction code and a private application transaction counter; and 
 transmit, to the merchant computing m a response to the request for payment information, wherein information in the response comprises the payment account information, the generated security code, and a public application transaction counter corresponding to the private application transaction counter; and 
 
   an account management computing system,
 wherein the account management computing system comprises one or more processors communicatively coupled to one or more storage devices, and wherein the one or more processors execute application code instructions that are stored in the one or more storage devices to cause the system to:
 receive a payment processing request from the merchant computing system, the payment processing request comprising the payment account information, the public application transaction counter, and the generated security code; 
 confirm the validity of the public application transaction counter; 
 confirm the validity of the generated security code; and 
 transmit notification of an approved payment transaction to the merchant computing system. 
 
   
     
     
         17 . The system of  claim 16 , wherein the processor executes application code instructions that are stored in the storage device without accessing a secure element to cause the system receive a bundle of public application transaction counters from the account management system, wherein the bundle of public application transaction counters comprises a set of randomly generated values that are limited in time and number. 
     
     
         18 . The system of  claim 16 , wherein account management computing system uses the public application transaction counter received in the payment processing request to retrieve the corresponding private application transaction counter, and wherein the retrieved corresponding private application transaction counter is used to recompute the generated security code. 
     
     
         19 . The system of  claim 18 , wherein the account management computing system confirms the validity of the generated security code by confirming the recomputed security code matches the generated security code received in the payment processing request. 
     
     
         20 . The system of  claim 16 , wherein confirming that the validity of the public application transaction counter comprises determining that the public application transaction counter is not expired and not previously used.

Join the waitlist — get patent alerts

Track US2015120556A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.