Securing payment transactions with rotating application transaction counters
Abstract
An account management system creates a bundle of private application transaction counters (ATCs) and a bundle of corresponding public ATCs, and transmits them to a user device. The device receives a request for payment information from a merchant and processes the request without accessing a secure element processor on the device. The device calculates a security code using one of the bundle of private ATCs and a transaction number received from the merchant. The device transmits proxy account information, the calculated security code, and the corresponding public ATCs to the merchant. The merchant transmits a payment request to the account management system as the issuer of the proxy account information. The account management system retrieves the private ATC using the public ATC, and determines the validity of the security code by recomputing it. The account management system retrieves the financial account information and requests authorization from the issuer.
Claims
exact text as granted — not AI-modified1 . A computer-implemented method to process financial transactions, comprising:
receiving, by a computing device associated with a user, a request for payment information from a merchant computing system to process a payment transaction, the request for payment information comprising a request for payment account information and a merchant computing m transaction code; processing, by the computing device associated with the user, the request for payment information without accessing a secure element of the computing device associated with the user; generating, by the computing device associated with the user without accessing the secure element, a security code using the merchant computing system transaction code and a private application transaction counter; transmitting, by the computing device associated with the user and to the merchant computing system, a response to the request for payment information, wherein information in the response comprises payment account information, a public application transaction counter corresponding to the private application transaction counter, and the generated security code, and wherein the information is transmitted by the merchant computing system to an account management system for payment approval in a payment processing request; and receiving, by the computing device associated with the user, a notification of an approved payment transaction, the notification of the approved payment transaction indicating that the account management system confirmed the validity of the generated security code received in the payment processing request from the merchant computing system.
2 . The computer-implemented method of claim 1 , wherein the public application transaction counter expires after a pre-defined period of time.
3 . The computer-implemented method of claim 1 , wherein the public application transaction counter is valid for a single payment transaction.
4 . The computer-implemented method of claim 1 , further comprising receiving, by the computing device associated with the user, a bundle of public application transaction counters and a bundle of corresponding private application transaction counters from the account management system.
5 . The computer-implemented method of claim 4 , wherein the bundle of public application transaction counters comprises a set of randomly generated values that are limited in time and number.
6 . The computer-implemented method of claim 1 , further comprising receiving, by the computing device associated with the user, proxy account information, wherein the payment account information comprises the proxy account information.
7 . The computer-implemented method of claim 1 , wherein the security code comprises a dynamic card verification number.
8 . The computer-implemented method of claim 1 , further comprising determining, by the computing device associated with the user, that the public application transaction counter and the corresponding private application transaction counter are available and not expired.
9 . The computer-implemented method of claim 1 , further comprising confirming, by the account management system, the validity of the public application transaction counter by determining that the public application transaction counter is not expired and not previously used.
10 . The computer-implemented method of claim 1 , wherein the account management system uses the public application transaction counter received in the payment processing request to retrieve the corresponding private application transaction counter, and wherein the retrieved private application transaction counter is used to recompute the generated security code.
11 . The computer-implemented method of claim 10 , wherein the account management system confirms the validity of the generated security code by confirming the recomputed security code matches the generated security code received in the payment processing request.
12 . A computer program product, comprising:
a non-transitory computer-readable medium having computer-readable program instructions embodied thereon that when executed by a computer cause the computer to process financial transactions, the computer-readable program instructions comprising:
computer-readable program instructions for receiving a request for payment information from a merchant computing system to process a payment transaction, the request for payment information comprising a request for payment account information and a merchant computing m transaction code;
computer-readable program instructions for processing the request for payment information without accessing a secure element of the computer;
computer-readable program instructions for generating a security code using the merchant computing system transaction code and a private application transaction counter;
computer-readable program instructions for transmitting to the merchant computing m a response to the request for payment information, wherein information in the response comprises payment account information, a public application transaction counter corresponding to the private application transaction counter, and the generated security code, wherein the information is transmitted by the merchant computing system to an account management system for payment approval in a payment processing request; and
computer-readable program instructions for receiving a notification of an approved payment transaction, the notification of the approved payment transaction indicating that the account management system confirmed the validity of the generated security code received in the payment processing request from the merchant computing.
13 . The computer program product of claim 12 , further comprising computer-readable program instructions for receiving a bundle of public application transaction counters from the account management system, wherein the bundle of public application transaction counters comprises a set of randomly generated values that are limited in time and number.
14 . The computer program product of claim 12 , wherein the account management system uses the public application transaction counter received in the payment processing request to retrieve the corresponding private application transaction counter, and wherein the retrieved corresponding private application transaction counter is used to recompute the generated security code.
15 . The computer program product of claim 14 , wherein the account management system confirms the validity of the generated security code by confirming the recomputed security code matches the generated security code received in the payment processing request.
16 . A system for processing financial transactions, comprising:
a user computing device,
wherein the user computing device comprises a storage device and a processor communicatively coupled to the storage device, and wherein the processor executes application code instructions that are stored in the storage device without accessing a secure element to cause the system to:
receive, from a merchant computing m a request for payment information from a merchant computing system to process a payment transaction, the request for payment information comprising a request for payment account information and a merchant computing m transaction code;
process the request for payment information without accessing the secure element;
generate a security code using the merchant computing m transaction code and a private application transaction counter; and
transmit, to the merchant computing m a response to the request for payment information, wherein information in the response comprises the payment account information, the generated security code, and a public application transaction counter corresponding to the private application transaction counter; and
an account management computing system,
wherein the account management computing system comprises one or more processors communicatively coupled to one or more storage devices, and wherein the one or more processors execute application code instructions that are stored in the one or more storage devices to cause the system to:
receive a payment processing request from the merchant computing system, the payment processing request comprising the payment account information, the public application transaction counter, and the generated security code;
confirm the validity of the public application transaction counter;
confirm the validity of the generated security code; and
transmit notification of an approved payment transaction to the merchant computing system.
17 . The system of claim 16 , wherein the processor executes application code instructions that are stored in the storage device without accessing a secure element to cause the system receive a bundle of public application transaction counters from the account management system, wherein the bundle of public application transaction counters comprises a set of randomly generated values that are limited in time and number.
18 . The system of claim 16 , wherein account management computing system uses the public application transaction counter received in the payment processing request to retrieve the corresponding private application transaction counter, and wherein the retrieved corresponding private application transaction counter is used to recompute the generated security code.
19 . The system of claim 18 , wherein the account management computing system confirms the validity of the generated security code by confirming the recomputed security code matches the generated security code received in the payment processing request.
20 . The system of claim 16 , wherein confirming that the validity of the public application transaction counter comprises determining that the public application transaction counter is not expired and not previously used.Join the waitlist — get patent alerts
Track US2015120556A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.