ANONYMISIERUNG EINER BLOCKKETTE
    2.
    发明申请

    公开(公告)号:WO2018130426A1

    公开(公告)日:2018-07-19

    申请号:PCT/EP2018/000017

    申请日:2018-01-11

    IPC分类号: G06Q20/02 G06F21/62

    摘要: Die vorliegende Erfindung ist gerichtet auf ein Verfahren zur Anonymisierung von Transaktionen einer Blockkette, welches es ermöglicht, dass beispielsweise ein Besitzer eines Gegenstands in einer Datenhistorie bzw. einer sogenannten Blockkette Information bezüglich vergangener Transaktionen bzw. Datenbeständen erhält, nicht jedoch zukünftige Besitzer. So kann beispielsweise eine Information bezüglich einer Fahrzeugwartung stets dem aktuellen Besitzer zugänglich gemacht werden, ohne dass dieser aktuelle Besitzer Information bezüglich zukünftiger Besitzer abrufen kann. Die Erfindung ist ferner gerichtet auf ein entsprechend eingerichtetes Kommunikationsprotokoll sowie auf ein Kommunikationssystem zur Anonymisierung von Transaktionen einer Blockkette. Ferner wird ein Computerprogrammprodukt vorgeschlagen, mit Steuerbefehlen, welche das vorgeschlagene Verfahren ausführen bzw. das vorgeschlagene Kommunikationssystem betreiben.

    SYSTEMS AND METHODS FOR USE IN FACILITATING APPLICATION OF SERVICES FOR PURCHASE TRANSACTIONS BASED ON TOKENS
    3.
    发明申请
    SYSTEMS AND METHODS FOR USE IN FACILITATING APPLICATION OF SERVICES FOR PURCHASE TRANSACTIONS BASED ON TOKENS 审中-公开
    适用于基于令牌的购买交易服务应用的系统和方法

    公开(公告)号:WO2018031224A1

    公开(公告)日:2018-02-15

    申请号:PCT/US2017/043460

    申请日:2017-07-24

    发明人: NIEHAUS, Bryan

    IPC分类号: G06Q20/38 G06Q20/40

    摘要: Disclosed are exemplary embodiments of systems and methods for facilitating services associated with transaction requests. In an exemplary embodiment, a method generally includes receiving, from a first entity, a transaction request for a payment account transaction. The transaction request includes a primary account number (PAN) for a payment account involved in the transaction. The exemplary method also includes overwriting the PAN in the transaction request with a non-PAN identifier (NPI), where a first segment of the PAN is identical to a first segment of the NPI and where the NPI is an invalid PAN. The exemplary method further includes routing the transaction request to a service, whereby the service is able to be implemented for the transaction request based, in part, on the first segment of the NPI while the PAN remains anonymous to the service.

    摘要翻译: 公开了用于促进与交易请求相关联的服务的系统和方法的示例性实施例。 在示例性实施例中,一种方法通常包括从第一实体接收对支付账户交易的交易请求。 交易请求包括交易涉及的支付账户的主账户号码(PAN)。 该示例性方法还包括用非PAN标识符(NPI)覆写交易请求中的PAN,其中PAN的第一段与NPI的第一段相同并且其中NPI是无效的PAN。 该示例性方法进一步包括将该交易请求路由到服务,由此该服务能够部分地基于该NPI的第一部分实现用于该交易请求,同时该PAN对该服务保持匿名。

    RESOURCE-DRIVEN DYNAMIC AUTHORIZATION FRAMEWORK
    4.
    发明申请
    RESOURCE-DRIVEN DYNAMIC AUTHORIZATION FRAMEWORK 审中-公开
    资源驱动动态授权框架

    公开(公告)号:WO2017004373A1

    公开(公告)日:2017-01-05

    申请号:PCT/US2016/040395

    申请日:2016-06-30

    IPC分类号: H04L29/06 H04W4/00

    摘要: Embodiments concern a dynamic authorization framework. Security Classification Process (SCP) is the process of classifying raw data, information extracted from raw data, content or code from security-value perspective. Security Achievability Determination Process (SADP) is a process based on a SV/SC that has been assigned, the RHE may determine the Security Requirements and how the security requirements may be achieved. During the Security Achievability Listing Process (SALP), the RHE uploads onto the Resource Listing Entity (RLE) the URI of the resource, the SAM associated with the resource and optionally a digital certificate associated with the resource. During the SAM Assessment Process (SAMAP) process, a Client evaluates the security mechanisms that must be carried out in order to meet the SAM that was provided as part of the Discovery Process (DP). Based on the SAM obtained from the RLE, the Client may initiate a Security Achievability Enabling Process (SAEP). The Client may be required to initiate an Authentication, Authorization, Payment and obtain an assertion of secure behavior from a Security -Achievability Enabler Function (SAEF), which may be a trusted third-party Function or Entity.

    摘要翻译: 实施例涉及动态授权框架。 安全分类处理(SCP)是从原始数据,内容或代码从安全价值角度分析原始数据,信息分类的过程。 安全成就确定过程(SADP)是基于已分配的SV / SC的过程,RHE可以确定安全性要求以及如何实现安全性要求。 在安全实现性上市过程(SALP)期间,RHE将资源的URI,与资源关联的SAM以及可选的资源相关联的数字证书上传到资源列表实体(RLE)。 在SAM评估过程(SAMAP)过程中,客户端评估必须执行的安全机制,以满足作为发现过程(DP)一部分提供的SAM。 基于从RLE获得的SAM,客户端可以启动安全可实现性启用过程(SAEP)。 可能需要客户机从安全性可靠性启动器功能(SAEF)中启动认证,授权,支付和获取安全行为的声明,该功能可能是受信任的第三方功能或实体。

    TRANSACTION UTILIZING ANONYMIZED USER DATA
    5.
    发明申请
    TRANSACTION UTILIZING ANONYMIZED USER DATA 审中-公开
    交易使用匿名用户数据

    公开(公告)号:WO2016118896A1

    公开(公告)日:2016-07-28

    申请号:PCT/US2016/014583

    申请日:2016-01-22

    IPC分类号: G06Q30/06 G06Q20/38 G06Q20/40

    摘要: A user requests to utilize anonymized user data to conduct a transaction. The anonymized user data keeps the users sensitive data private, while still allowing certain entities to perform fraud analyses. The user configures a specific combination of user data elements to be anonymized prior to or at the time of the transaction. In some embodiments, the specific combination may be associated with a location or merchant type, which can also be selected by the user. The registration of a password associated with the anonymized user data may further increase security of the transaction.

    摘要翻译: 用户请求使用匿名用户数据进行交易。 匿名用户数据将用户敏感数据保密,同时允许某些实体进行欺诈分析。 用户在交易之前或交易时配置用户数据元素的特定组合以进行匿名化。 在一些实施例中,特定组合可以与也可由用户选择的位置或商家类型相关联。 与匿名用户数据相关联的密码的注册可以进一步增加交易的安全性。

    SERVER SIDE MOBILE PAYMENT PROCESSING AND AUTHENTICATION
    6.
    发明申请
    SERVER SIDE MOBILE PAYMENT PROCESSING AND AUTHENTICATION 审中-公开
    服务器端移动付款处理和认证

    公开(公告)号:WO2014120020A2

    公开(公告)日:2014-08-07

    申请号:PCT/NO2014/050017

    申请日:2014-01-31

    IPC分类号: G06Q20/12

    摘要: A web browser inserts a user-neutral identifier into its webpage requests. A proxy server creates records of the webpage requests, and further processes these records to create and update profiles for the corresponding user-neutral identifiers. Upon receiving a webpage request including payment transaction information, which is redirected from a payment provider, the proxy server determines whether payment should be processed by analyzing one or more data elements in the request in view of the corresponding profile. Upon determining that the payment should be processed, the proxy server forwards the payment transaction information to a payment provider. By indexing the profiles according to user-neutral identifiers, rather than specific user information, user privacy can be maintained while still being able to authenticate whether a payment transaction is legitimate.

    摘要翻译: Web浏览器将用户中立的标识符插入其网页请求中。 代理服务器创建网页请求的记录,并进一步处理这些记录以创建和更新相应用户中立标识符的配置文件。 代理服务器在接收到包括从支付提供商重定向的支付交易信息的网页请求时,通过分析相应配置文件中的请求中的一个或多个数据元素来确定是否应该处理支付。 在确定应该处理该付款时,代理服务器将支付交易信息转发到支付提供商。 通过根据用户中立的标识符而不是特定用户信息索引配置文件,可以维护用户隐私,同时仍能够验证支付交易是否合法。

    SYSTEMS AND METHODS FOR PROTECTING ACCOUNT IDENTIFIERS IN FINANCIAL TRANSACTIONS
    7.
    发明申请
    SYSTEMS AND METHODS FOR PROTECTING ACCOUNT IDENTIFIERS IN FINANCIAL TRANSACTIONS 审中-公开
    在金融交易中保护账户标识符的系统和方法

    公开(公告)号:WO2012171012A2

    公开(公告)日:2012-12-13

    申请号:PCT/US2012041918

    申请日:2012-06-11

    发明人: BARNETT TIMOTHY W

    IPC分类号: G06Q40/00

    CPC分类号: G06Q20/383 G06Q20/02

    摘要: In a system for protecting account identifiers in financial transactions, a consumer provides an account identifier to be used for purchasing a good or service from a merchant. However, only a portion of the account identifier is transmitted to the merchant. The remaining portion of the account identifier is transmitted to a server, referred to as a "payment facilitator," that is not controlled by the merchant. During the financial transaction, the merchant submits a request for financial payment containing a portion of the consumer's account identifier to the payment facilitator. The payment facilitator combines the account identifier portion in the request with the account identifier portion transmitted to it from the consumer in order to determine the consumer's full account identifier. The payment facilitator then submits a request for financial payment to a financial institution for approval.

    摘要翻译: 在用于在金融交易中保护帐户标识符的系统中,消费者提供用于从商家购买商品或服务的帐户标识符。 然而,只有一部分帐户标识符被传送给商家。 帐户标识符的剩余部分被发送到不被商家控制的称为“支付促进者”的服务器。 在金融交易期间,商家向付款协调人提交包含消费者帐户标识符的一部分的财务付款请求。 支付促进者将请求中的帐户标识符部分与从消费者发送给它的帐户标识符部分相结合,以便确定消费者的完整帐户标识符。 然后,付款协调人向金融机构提交财务付款请求批准。

    SYSTEM AND METHODS FOR TRANSFERRING MONEY
    8.
    发明申请
    SYSTEM AND METHODS FOR TRANSFERRING MONEY 审中-公开
    用于转移货币的系统和方法

    公开(公告)号:WO2012012545A1

    公开(公告)日:2012-01-26

    申请号:PCT/US2011/044700

    申请日:2011-07-20

    IPC分类号: G06Q20/00

    摘要: Aspects of the present invention relate to systems and methods for increasing security and privacy of financial transactions. More specifically, certain aspects of the invention provide consumers, financial institutions, and/or merchants with increased protection of sensitive information associated with financial accounts and transactions. Herein disclosed are methods and systems for allowing a consumer to pay a merchant without the consumer needing to disclose confidential information to the merchant.

    摘要翻译: 本发明的方面涉及用于增加金融交易的安全性和隐私的系统和方法。 更具体地,本发明的某些方面为消费者,金融机构和/或商家提供与金融账户和交易相关联的敏感信息的更多保护。 这里公开的方法和系统允许消费者在没有消费者需要向商家披露机密信息的情况下支付商家。

    METHOD AND SYSTEM FOR PROCESSING PIN DEBIT TRANSACTIONS
    9.
    发明申请
    METHOD AND SYSTEM FOR PROCESSING PIN DEBIT TRANSACTIONS 审中-公开
    用于处理PIN码交易的方法和系统

    公开(公告)号:WO2011127029A1

    公开(公告)日:2011-10-13

    申请号:PCT/US2011/031210

    申请日:2011-04-05

    IPC分类号: G06Q20/00

    摘要: A system for processing a debit transaction between a merchant and a consumer. The system includes one or more processors programmed to receive payment information for the consumer, collect authentication data for the debit card from the consumer, transmit an alias account number unique to the debit transaction to the merchant, receive a credit authorization message including the alias account number from the merchant, translate the credit authorization message to a debit authorization message using the authentication data, and transmit the debit authorization message to a payment processor.

    摘要翻译: 一种用于处理商家和消费者之间借方交易的系统。 该系统包括被编程为接收消费者的支付信息的一个或多个处理器,从消费者收集借记卡的认证数据,将对借方交易唯一的别名帐号发送给商家,接收包括别名帐户的信用授权消息 使用认证数据将信用授权消息转换为借记授权消息,并将付款授权消息发送到支付处理器。

    ENCRYPTION SWITCH PROCESSING
    10.
    发明申请
    ENCRYPTION SWITCH PROCESSING 审中-公开
    加密开关处理

    公开(公告)号:WO2011057092A2

    公开(公告)日:2011-05-12

    申请号:PCT/US2010/055652

    申请日:2010-11-05

    IPC分类号: G06Q20/00

    摘要: Techniques for eliminating the need for merchants and acquirers to conduct Payment Card Industry ("PCI") security audit procedures are provided. Merchants and acquirers can eliminate the operating expenses associated with conducting audits to ensure compliance with PCI Data Security Standards ("DSS"), while at the same time ensuring that cardholders' data remains secure, thus protecting the cardholders from fraudulent transactions. System security is further enhanced through the use of per transaction audits, with the scope of the audit being directly between the Point of Sale (POS) terminal and the payment processing network. PCI DSS compliance can thus be assured on a per transaction basis, as opposed to only ensuring compliance generally for a merchant or acquirer on a periodic basis. Per transaction PCI DSS compliance is assured, while at the same time eliminating the need for merchants or acquirers to conduct compliance audits.

    摘要翻译: 提供消除商户和收单机构进行支付卡行业(“PCI”)安全审计程序的需要的技术。 商家和收单机构可以消除与执行审计相关的运营费用以确保符合PCI数据安全标准(“DSS”),同时确保持卡人的数据保持安全,从而保护持卡人免受欺诈性交易。 通过使用每笔交易审计,系统安全性得到进一步增强,审计范围直接位于销售点(POS)终端和支付处理网络之间。 PCI DSS合规性因此可以在每次交易的基础上得到保证,而不是仅仅确保商家或收购方定期遵守。 每次交易PCI DSS合规性得到保证,同时无需商家或收单机构进行合规性审计。