US2023040368A1PendingUtilityA1

Transaction authentication systems and methods

Assignee: MASTERCARD INTERNATIONAL INCPriority: Nov 7, 2017Filed: Oct 17, 2022Published: Feb 9, 2023
Est. expiryNov 7, 2037(~11.3 yrs left)· nominal 20-yr term from priority
Inventors:Brian Piel
G06Q 20/023G06Q 20/12G06Q 40/02G06Q 20/401G06Q 20/405G06Q 20/40G06Q 40/00G06Q 20/4016G06Q 20/382
70
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An authentication computing device, including a processor in communication with a memory, for authenticating an ACH transaction processed over an ACH network is provided. The processor is programmed to register a payee with the authentication computing device, and to receive an authentication request for an electronic ACH transaction to transfer funds from a payor account to a payee account. The request is received from a first client computing device and includes an account identifier associated with the payor account. The processor is also programmed to transmit an authentication challenge to a second client computing device based on account data associated with the account identifier. The processor is further programmed to receive a response to the authentication challenge, determine whether the account data has been authenticated based on the received challenge response, and transmit an authentication response to the payee based on the determination.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . An authentication computing device for authenticating an ACH transaction processed over an ACH network, the authentication computing device including a processor in communication with a memory, said processor programmed to:
 register a payee with the authentication computing device;   receive an authentication request for an electronic ACH transaction to transfer funds from a payor account to a payee account, the request received from a first client computing device, the request including an account identifier associated with the payor account;   transmit an authentication challenge to a second client computing device based on account data associated with the account identifier, the account data being received from an issuer and stored in the memory;   receive a challenge response to the authentication challenge;   determine whether the account data has been authenticated based on the received challenge response; and   transmit an authentication response to the payee based on the determination.   
     
     
         2 . The authentication computing device of  claim 1 , wherein the account data, the authentication challenge, and the challenge response are not accessible to the payee. 
     
     
         3 . The authentication computing device of  claim 1 , wherein the first client computing device and the second client computing device are the same. 
     
     
         4 . The authentication computing device of  claim 1 , wherein the first client computing device and the second client computing device are different. 
     
     
         5 . The authentication computing device of  claim 1 , wherein the authentication request is received via a web call. 
     
     
         6 . The authentication computing device of  claim 1 , wherein said processor is further programmed to update the memory at least on a periodic basis and when the account data is changed at the issuer. 
     
     
         7 . The authentication computing device of  claim 1 , wherein said processor is further programmed to store in the memory a funds amount associated with the account identifier. 
     
     
         8 . The authentication computing device of  claim 7 , wherein said processor is further programmed to update the funds amount in the memory on a periodic basis. 
     
     
         9 . The authentication computing device of  claim 7 , wherein when the account data is determined to be authenticated and wherein the authentication request further includes a transaction amount, said processor is further programmed to embed a funds indicator within the authentication response, the funds indicator indicating whether the funds amount is less than or greater than the transaction amount. 
     
     
         10 . A method for authenticating an ACH transaction processed over an ACH network, said method performed using an authentication computing device including a processor in communication with a memory, said method comprising:
 registering a payee with the authentication computing device;   receiving an authentication request for an electronic ACH transaction to transfer funds from a payor account to a payee account, the request received from a first client computing device, the request including an account identifier associated with the payor account;   transmitting an authentication challenge to a second client computing device based on account data associated with the account identifier, the account data being received from an issuer and stored in the memory;   receiving a challenge response to the authentication challenge;   determining whether the account data has been authenticated based on the received challenge response; and   transmitting an authentication response to the payee based on the determination.   
     
     
         11 . The method of  claim 10 , wherein the account data, the authentication challenge, and the challenge response are not accessible to the payee. 
     
     
         12 . The method of  claim 10 , wherein the first client computing device and the second client computing device are the same. 
     
     
         13 . The method of  claim 10 , wherein the first client computing device and the second client computing device are different. 
     
     
         14 . The method of  claim 10 , wherein receiving the authentication request comprises receiving the authentication request via a web call. 
     
     
         15 . The method of  claim 10 , further comprising updating the memory at least on a periodic basis and when the account data is changed at the issuer. 
     
     
         16 . The method of  claim 10 , further comprising storing in the memory a funds amount associated with the account identifier. 
     
     
         17 . The method of  claim 16 , further comprising updating the funds amount in the memory on a periodic basis. 
     
     
         18 . The method of  claim 16 , wherein when the account data is determined to be authenticated and wherein the authentication request further includes a transaction amount, further comprising embedding a funds indicator within the authentication response, the funds indicator indicating whether the funds amount is less than or greater than the transaction amount. 
     
     
         19 . A non-transitory computer-readable storage medium having computer-executable instructions embodied thereon, wherein when executed by an authentication computing device including at least one processor coupled to a memory, the computer-executable instructions cause the authentication computing device to:
 register a payee with the authentication computing device;   receive an authentication request for an electronic ACH transaction to transfer funds from a payor account to a payee account, the request received from a first client computing device, the request including an account identifier associated with the payor account;   transmit an authentication challenge to a second client computing device based on account data associated with the account identifier, the account data being received from an issuer and stored in the memory;   receive a challenge response to the authentication challenge;   determine whether the account data has been authenticated based on the received challenge response; and   transmit an authentication response to the payee based on the determination.   
     
     
         20 . The non-transitory computer-readable storage media of  claim 19 , wherein the account data, the authentication challenge, and the challenge response are not accessible to the payee.

Join the waitlist — get patent alerts

Track US2023040368A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.