Account transaction fraud detection
Abstract
A merchant conducting a transaction on an account forms transaction data with a sensitive data field. To obscure the account prior to transmitting information about the transaction, for each character in the sensitive data field, a combined character is formed with a character of a generated pad. A replacement character is formed by a modulus operation on the combined character and is stored in the corresponding position in the sensitive data field. A transmission containing the sensitive data field with replacement characters is delivered to the merchant's acquirer. Subsequently, a first transmission is received for another transaction from a merchant that contains transaction data upon an account and a sensitive data field. Using the sensitive data field, an attempt is made to retrieve a transaction data record that contains data from a previous transaction that includes the account upon which the previous transaction was conducted. The sensitive data field, which is encrypted as the corresponding account upon which the previous transaction was conducted, was encrypted by a character-by-character modulo operation using a generated pad. If the transaction data record is retrieved, a second transmission is sent that contains a fraud notification of the attempt to conduct a transaction upon the encrypted account in the sensitive data field. If there is no retrieval of the transaction data record, a third transmission containing a no-fraud notification is sent.
Claims
exact text as granted — not AI-modified1 - 27 . (canceled)
28 . A computer comprising:
a processor; and a non-transitory computer-readable medium comprising code executable by the processor for implementing a method comprising:
retrieving a sensitive data field having a plurality of characters of a predetermined character set;
determining a generated pad, wherein the generated pad is a set of characters that is used to encrypt and decrypt the sensitive data field;
for each character in the sensitive data field on a character by character basis:
forming a combined value from the character of the sensitive data field, taken alone, and a character of the generated pad;
forming a replacement character by performing a modulus operation on the combined value; and
storing the replacement character in a position of a corresponding character in the sensitive data field; and
transmitting a transmission comprising the replacement characters.
29 . The computer of claim 28 , wherein each of the replacement characters is a character selected from the predetermined character set, and wherein each character of the generated pad is a character selected from the predetermined character set.
30 . The computer of claim 28 , wherein forming the combined value comprises adding a numeric value of the character of the sensitive data field to a numeric value of the character of the generated pad.
31 . The computer of claim 28 , wherein the modulus operation performed on the combined value uses a value equal to the number of characters in the predetermined character set.
32 . The computer of claim 28 , wherein the generated pad is determined using a key known by the computer and a decrypting computer.
33 . The computer of claim 32 , wherein the generated pad is further determined using a date or time.
34 . The computer of claim 28 , wherein a value of zero for a character in the generated pad causes a replacement character formed using the character in the generated pad to be the same as the corresponding character in the sensitive data field.
35 . The computer of claim 34 , wherein the sensitive data field comprises transaction data for a transaction, and wherein the generated pad has a value of zero at one or more character positions in order to accommodate a requirement associated with the transaction data.
36 . A system comprising:
the computer of claim 28 ; and a decrypting computer configured to:
receive the transmission comprising the replacement characters from the computer;
generate a second generated pad; and
determine a second sensitive data field using the replacement characters and the second generated pad, wherein the second sensitive data field and the sensitive data field are the same.
37 . A computer-implemented method comprising:
retrieving, by a computer, a sensitive data field having a plurality of characters of a predetermined character set; determining, by the computer, a generated pad, wherein the generated pad is a set of characters that is used to encrypt and decrypt the sensitive data field; for each character in the sensitive data field on a character by character basis:
forming, by the computer, a combined value from the character of the sensitive data field, taken alone, and a character of the generated pad;
forming, by the computer, a replacement character by performing a modulus operation on the combined value; and
storing, by the computer, the replacement character in a position of a corresponding character in the sensitive data field; and
transmitting, by the computer, a transmission comprising the replacement characters.
38 . The computer-implemented method of claim 37 , wherein forming the combined value comprises adding a numeric value of the character of the sensitive data field to a numeric value of the character of the generated pad.
39 . The computer-implemented method of claim 37 , wherein a value of zero for a character in the generated pad causes a replacement character formed using the character in the generated pad to be the same as the corresponding character in the sensitive data field.
40 . The computer-implemented method of claim 39 , wherein the sensitive data field comprises transaction data for a transaction, and wherein the generated pad has a value of zero at one or more character positions in order to accommodate a requirement associated with the transaction data.
41 . A computer-implemented method comprising:
receiving, by a computer, encrypted data comprising a plurality of characters of a predetermined character set; determining, by the computer, a generated pad, wherein the generated pad is a set of characters that is used to encrypt and decrypt a sensitive data field; for each character in the encrypted data on a character by character basis:
forming, by the computer, a combined value from the character of the encrypted data, taken alone, and a character of the generated pad;
forming, by the computer, a replacement character by performing a modulus operation on the combined value; and
determining, by the computer, a character of the sensitive data field using the replacement character, wherein the position of the character in the sensitive data field is the position of the character in the encrypted data.
42 . The computer-implemented method of claim 41 , wherein each character in the generated pad is a character selected from the predetermined character set, and wherein each character in the sensitive data field is selected from the predetermined character set.
43 . The computer-implemented method of claim 41 , wherein forming the combined value comprises subtracting a numeric value of the character of the generated pad from a numeric value of the character of the encrypted data.
44 . The computer-implemented method of claim 41 , wherein the modulus operation performed on the combined value uses a value equal to the number of characters in the predetermined character set.
45 . The computer-implemented method of claim 41 , wherein the generated pad is determined using a key known by the computer and an encrypting computer, and wherein the generated pad is further determined using a date or time.
46 . The computer-implemented method of claim 41 , wherein a value of zero for a character in the generated pad causes a replacement character formed using the character in the generated pad to be the same as the corresponding character in the encrypted data.
47 . The computer-implemented method of claim 46 , wherein the sensitive data field comprises transaction data for a transaction, and wherein the generated pad has a value of zero at one or more character positions in order to accommodate a requirement associated with the transaction data.Join the waitlist — get patent alerts
Track US2015254670A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.