Secure Mobile Device Credential Provisioning Using Risk Decision Non-Overrides
    1.
    发明申请
    Secure Mobile Device Credential Provisioning Using Risk Decision Non-Overrides 审中-公开
    使用风险决策非覆盖的安全移动设备凭证配置

    公开(公告)号:US20160086184A1

    公开(公告)日:2016-03-24

    申请号:US14861916

    申请日:2015-09-22

    IPC分类号: G06Q20/40 G06Q20/38 G06Q20/32

    摘要: Embodiments are directed to optimizing the secure provisioning of credentials to mobile devices through use of risk decision non-overrides. In some embodiments, a service provider receives a request from a wallet provider to provision a credential associated with an account to a mobile device. The request includes a first risk level associated with the provisioning. The service provider receives a second risk level associated with the provisioning request from an issuer of the account. Based upon determining that a non-override condition exists, the service provider uses the first risk level from the wallet provider and accordingly causes a user authentication to occur. A non-override condition may be determined based upon scenario indicators received within the provisioning request. In some embodiments, the non-override condition may be ignored when the first risk level indicates medium risk and the second risk level indicates high risk.

    摘要翻译: 实施例旨在通过使用风险决策非覆盖来优化对移动设备的凭证的安全提供。 在一些实施例中,服务提供者接收来自钱包提供者的请求以向移动设备提供与帐户相关联的证书。 请求包括与供应相关联的第一风险级别。 服务提供商从帐户的发行者接收与供应请求相关联的第二风险级别。 基于确定存在非覆盖条件,服务提供商使用来自钱包提供商的第一风险级别,并因此导致用户认证发生。 可以基于在供应请求内接收到的情景指示来确定非覆盖条件。 在一些实施例中,当第一风险水平指示中等风险并且第二风险水平指示高风险时,可以忽略非重写条件。

    NETWORK TOKEN SYSTEM
    2.
    发明申请
    NETWORK TOKEN SYSTEM 审中-公开
    网络系统

    公开(公告)号:US20150127547A1

    公开(公告)日:2015-05-07

    申请号:US14514290

    申请日:2014-10-14

    IPC分类号: G06Q20/38 G06Q20/40

    摘要: Embodiments of the invention are directed to methods, apparatuses, computer readable media and systems for providing, along with a token, a token assurance level and data used to generate the token assurance level. At the time a token is issued, one or more Identification and Verification (ID&V) methods may be performed to ensure that the token is replacing a PAN that was legitimately used by a token requestor. A token assurance level may be assigned to a given token in light of the type of ID&V that is performed and the entity performing the ID&V. Different ID&Vs may result in different token assurance levels. An issuer may wish to know the level of assurance and the data used in generating the level of assurance associated with a token prior to authorizing a payment transaction that uses the token.

    摘要翻译: 本发明的实施例涉及用于向令牌提供令牌保证级别和用于生成令牌保证级别的数据的方法,装置,计算机可读介质和系统。 在发出令牌时,可以执行一个或多个识别和验证(ID&V)方法以确保令牌正在替换令牌请求者合法使用的PAN。 根据执行的ID&V的类型和执行ID&V的实体,可以将令牌保证级别分配给给定的令牌。 不同的ID和Vs可能会导致不同的令牌保证级别。 在授权使用令牌的支付交易之前,发行人可能希望知道用于生成与令牌相关联的保证级别的保证级别和数据。

    MESSAGING INCLUDING VALUE ACCOUNT CONVERSION
    3.
    发明申请
    MESSAGING INCLUDING VALUE ACCOUNT CONVERSION 审中-公开
    包括价值账户转换的消息

    公开(公告)号:US20110225058A1

    公开(公告)日:2011-09-15

    申请号:US13038637

    申请日:2011-03-02

    IPC分类号: G06Q20/00 G06Q40/00

    摘要: A system, method, and computer-readable storage medium configured to facilitate, for example, point-of-sale check approval in real-time. The system converts a demand type payment transaction into a payment card transaction. A cardholder database contains a cardholder record. The cardholder record includes a demand account and payment card information of a cardholder. A network interface receives point-of-service transaction data. A transaction processor correlates the user with the cardholder record, and generates an authorization request message which is sent to an issuer for approval.

    摘要翻译: 被配置为实时地促进例如销售点检查批准的系统,方法和计算机可读存储介质。 系统将需求类型支付交易转换成支付卡交易。 持卡人数据库包含持卡人记录。 持卡人记录包括持卡人的需求账户和支付卡信息。 网络接口接收服务点交易数据。 交易处理器将用户与持卡人记录相关联,并且生成授权请求消息,该消息被发送给发行者以供批准。

    Automated Account Provisioning
    4.
    发明申请
    Automated Account Provisioning 有权
    自动帐户配置

    公开(公告)号:US20150140960A1

    公开(公告)日:2015-05-21

    申请号:US14546955

    申请日:2014-11-18

    IPC分类号: H04W4/24 H04W12/06 H04W4/12

    摘要: Embodiments of the present invention are directed to systems, methods, and apparatus for allowing an issuer to initiate account provisioning on a mobile device without interacting with an accountholder. The issuer may initiate the process by sending a provisioning information request message to a mobile device with a secure element. The mobile device may recognize the provisioning request message and gather the requisite provisioning information without requiring user input. The provisioning information may include information associated with the secure element of the mobile device. The mobile device may then send a provisioning request message to a provisioning system. The provisioning request message may include the requisite provisioning information to allow the provisioning system to provision the financial account on the secure element of the mobile device.

    摘要翻译: 本发明的实施例涉及用于允许发行者在移动设备上发起账户配置而不与账户持有者交互的系统,方法和装置。 发行者可以通过向具有安全元素的移动设备发送供应信息请求消息来发起该过程。 移动设备可以识别供应请求消息并且收集必需的供应信息而不需要用户输入。 配置信息可以包括与移动设备的安全元件相关联的信息。 然后,移动设备可以向供应系统发送供应请求消息。 供应请求消息可以包括必要的供应信息,以允许供应系统在移动设备的安全元件上配置金融帐户。

    SECURE MOBILE DEVICE CREDENTIAL PROVISIONING USING RISK DECISION NON-OVERRIDES

    公开(公告)号:US20190057389A1

    公开(公告)日:2019-02-21

    申请号:US16168829

    申请日:2018-10-24

    IPC分类号: G06Q20/40 G06Q20/32 G06Q20/38

    摘要: Embodiments are directed to optimizing the secure provisioning of credentials to mobile devices through use of risk decision non-overrides. In some embodiments, a service provider receives a request from a wallet provider to provision a credential associated with an account to a mobile device. The request includes a first risk level associated with the provisioning. The service provider receives a second risk level associated with the provisioning request from an issuer of the account. Based upon determining that a non-override condition exists, the service provider uses the first risk level from the wallet provider and accordingly causes a user authentication to occur. A non-override condition may be determined based upon scenario indicators received within the provisioning request. In some embodiments, the non-override condition may be ignored when the first risk level indicates medium risk and the second risk level indicates high risk.

    VALIDATION CRYPTOGRAM FOR TRANSACTION
    6.
    发明申请

    公开(公告)号:US20170272253A1

    公开(公告)日:2017-09-21

    申请号:US15456288

    申请日:2017-03-10

    摘要: A method for validating an interaction is disclosed. A first interaction cryptogram can be generated by a first device using information about a first party to the interaction and a second party to the interaction. A second interaction cryptogram can be generated by a second device also using information about the first party to the interaction and the second party to the interaction. Verifying each cryptogram can validate that the interaction details have not been changed, and that both the first party and second party legitimately authorized the interaction.