ELECTRONIC PAYMENT DEVICE TRANSACTIONS
20180181950 ยท 2018-06-28
Inventors
- Axel Emile Jean Charles Cateland (Scarsdale, NY, US)
- Patrik Smets (Nijlen, BE)
- Luis Filipe de Almeida Ferreira Da Silva (Brussels, BE)
Cpc classification
G06Q20/202
PHYSICS
G06Q20/4018
PHYSICS
G06Q20/38215
PHYSICS
International classification
G06Q20/34
PHYSICS
G06Q20/40
PHYSICS
Abstract
Performance and processing of a contactless transaction at an electronic payment device with a terminal of a transaction system is described. In the device, an account data set is prepared for use in contactless transactions. This account data set comprises user account details to identify a user account with an issuer for the user account and an indicator indicating that the contactless transaction is a customer not present (CNP) transaction. A contactless transaction is performed with the terminal using the contactless transaction account data set. In processing, transaction details of a contactless transaction are received and reviewed to determine whether the contactless transaction is indicated to be a customer present or a customer not present transaction. If the contactless transaction is indicated to be a customer present transaction, an issuing bank for the electronic payment device is notified. If the contactless transaction is indicated to be a customer not present transaction, the contactless transaction is processed as a customer not present transaction. Suitable apparatus is also described.
Claims
1. A method of performing a contactless transaction at an electronic payment device with a terminal of a transaction system, the method comprising: preparing an account data set for use in contactless transactions, wherein the account data set comprises user account details to associate a user account with an issuer of the user account and an indicator indicating that the contactless transaction is a card not present (CNP) transaction; performing the contactless transaction with the terminal using the contactless transaction account data set.
2. The method as claimed in claim 1, wherein the electronic payment device is adapted to perform a contactless transaction according to EMV protocols, and wherein the indicator is comprised in the application interchange profile.
3. The method as claimed in claim 1, wherein the contactless transaction account data set comprises one or more of the following: an account number, a card number, an expiry date, a valid from date, an issue number, a card type and a card verification value (CVV).
4. The method as claimed in claim 1, wherein the contactless transaction account data set excludes cryptographic information shared between the electronic payment device and the issuer to establish a trust relationship between them.
5. The method as claimed in claim 1 wherein the electronic payment device is a computing device.
6. The method as claimed in claim 1 wherein the electronic payment device is a physical token.
7. The method as claimed in claim 6, wherein the physical token is a payment card.
8. The method of processing a contactless transaction made between an electronic payment device and a terminal of a transaction system, the method comprising: receiving transaction details of a contactless transaction for processing; reviewing the transaction details to determine whether the contactless transaction is indicated to be a card present or a card not present transaction; and if the contactless transaction is indicated to be a card present transaction, notifying an issuing bank for the electronic payment device; and if the contactless transaction is indicated to be a card not present transaction, processing the contactless transaction as a card not present transaction.
9. The method as claimed in claim 8, wherein the contactless transaction is performed according to EMV protocols, and wherein the indicator is comprised in the application interchange profile.
10. An electronic payment device adapted to perform a contactless transaction with a terminal of a transaction system by preparing an account data set for use in contactless transactions, wherein the account data set comprises user account details to associate a user account with an issuer of the user account and an indicator indicating that the contactless transaction is a card not present (CNP) transaction, and by performing the contactless transaction with the terminal using the contactless transaction account data set, the electronic payment device comprising a memory containing the account data set and the indicator, and circuitry to establish a local wireless connection to a terminal of a transaction system.
11. The electronic payment device of claim 10 wherein the electronic payment device is a computing device.
12. The electronic payment device of claim 10 wherein the electronic payment device is a cellular telecommunications system handset.
13. The electronic payment device of claim 10 wherein the electronic payment device is a physical token.
14. The electronic payment device of claim 13, wherein the physical token is a payment card.
15. The electronic payment device of claim 13, wherein the physical token is a key fob.
16. The method as claimed in claim 8, wherein the contactless transaction account data set comprises one or more of the following: an account number, a card number, an expiry date, a valid from date, an issue number, a card type and a card verification value (CVV).
17. The method as claimed in claim 8, wherein the contactless transaction account data set excludes cryptographic information shared between the electronic payment device and the issuer to establish a trust relationship between them.
18. The method as claimed in claim 2, wherein the contactless transaction account data set comprises one or more of the following: an account number, a card number, an expiry date, a valid from date, an issue number, a card type and a card verification value (CVV).
19. The method as claimed in claim 2, wherein the contactless transaction account data set excludes cryptographic information shared between the electronic payment device and the issuer to establish a trust relationship between them.
20. The method as claimed in claim 3, wherein the contactless transaction account data set excludes cryptographic information shared between the electronic payment device and the issuer to establish a trust relationship between them.
Description
BRIEF DESCRIPTION OF THE FIGURES
[0018] Embodiments of the disclosure will now be described, by way of example, with reference to the accompanying Figures in which;
[0019]
[0020]
[0021]
[0022]
[0023]
[0024]
[0025]
[0026]
DETAILED DESCRIPTION
[0027] With reference to
[0028] With reference to
[0029] With the E-wallet on the smartphone 114, the smartphone 114 thus has a data storage module 32. The touchscreen is directly connected to the data storage module 32. The data storage module 32 includes an account data store 34 and an identifier 36. The account data store comprises data entered into the E-wallet. The account data store 32 allows for account information to be stored as electronic data on the memory component of the smartphone 114. This account information forms an account data set. Various account data items can be input to the account data store by the touchscreen 130. With brief reference to
[0030] For a conventional contactless transaction, information is present in both the account data store 34 and the issuer to support a trust relationship between the E-wallet and the issuerthis typically requires user involvement in the set up of the E-wallet to establish the trust relationship and share information such that the issuer can verify that a transaction is received from a trusted E-wallet by decryption of data encrypted by the E-wallet. As discussed below, embodiments of the present disclosure allow effective use of an E-wallet on the smartphone 114 even when there has not been issuer involvement in set-up.
[0031] The identifier is in the form of electronic data. The identifier is a transaction type identifier. The identifier 36 is coded in accordance with conventional EMV data formats. In particular, the identifier is coded in one embodiment using the application interchange profile (AIP) defined in EMV standards. EMV stands for Europay (RTM) Mastercard (RTM) and Visa (RTM), and EMV provides a global standard for transaction infrastructure operations. The AIP is provided in tag 82 defined by EMV protocols, and is used to indicate the capabilities of a payment device to support specific functions in the application. Data in tag 82 is passed from the payment device to the point of sale device, and then information in this AIP Tag 82 EMV can be passed onwards from the point of sale device for processing elsewhere in the transaction infrastructure. As such, coding the identifier using AIP TAG 82 EMV means that existing points of sale are not affected by implementation of the present disclosure.
[0032] The smartphone 114 also includes an antenna 152 for near field wireless communication, for example using NFC protocols to implement the ISO/IEC 14443 standard for contactless payment. In this way, the electronic payment device 14 includes a communication module 52. The NFC antenna may alternatively be replaced by any suitable near field wireless or RF communication antenna (for example, BluetoothRFID may also be used though generally in passive devices rather than a smartphone, which will typically be used as an active device as it has an internal battery). A processor of the smartphone 114 is connected to the memory component and the NFC antenna 152. The processor is arranged to configure the data storage module 32 to generate a transaction demand 54 based on the identifier 36 and the account data set stored at the account data store. The processor is also arranged to configure the NFC antenna 152 to transmit the transaction demand 54 to the point of sale terminal 16. The processor is thus a control module 35.
[0033] The point of sale terminal 16 includes a NFC aerial and a display for displaying information (not shown). This NFC aerial is part of a transceiver 56 being able to send and receive data. In this case, the transceiver is a NFC transceiver 156. By virtue of the NFC antenna 152 of the electronic payment device 14 and the NFC transceiver of the point of sale terminal 16, the electronic payment device 14 is arranged to communicate with the point of sale terminal 16.
[0034] The point of sale terminal 16 also includes a processor 60, a communication port 62 and a memory component 64. The memory component is similar to that of the electronic payment device 14. A query 66 in the form of electronic data is stored on the memory component 64 of the point of sale terminal 16. The processor 60 is arranged to send the query 66 to the smart phone 114 device via the transceiver 56. The processor constantly sends the query 66 so that any electronic payment devices within range of the NFC transceiver 156 receive the query 66.
[0035] A transaction module 68 in the form of electronic data is also stored on the memory component 64 of the point of sale terminal 16. When the processor 60 executes the transaction module 68, the point of sale terminal 16 reads the transaction demand 54 and processes the transaction accordingly.
[0036] When the transaction is processed by the point of sale terminal 16, transaction details are passed to the acquirer 18. Transaction details may be passed through a transaction infrastructure (not explicitly shown for this step) or through a dedicated path.
[0037] The acquirer 18 infrastructure includes a computer having a processor and a memory component. The memory component is a non-volatile component such as a read only memory component (ROM), by way of example, but could also be a re-writable memory component. The merchant's account details are stored as electronic data on the memory component. The point of sale terminal is connected to the computer at the acquirer 18 over a communication medium. Although the communication medium between the acquirer and the point of sale terminal may be a direct connection, it is envisaged that an internet based communication medium governed by established communication protocols is more suitable. The internet based communication medium may include a local area network (LAN) or a wide area network (WAN), and may also be a dial up connection, cable modem or a high speed ISDN line.
[0038] The transaction infrastructure 20 connects the computer at the acquirer 18 to a computer at the issuer 22. The network 20 comprises an internet based communication medium but also comprises switches for routing transaction information appropriately and computing resources for processing transaction information. This transaction infrastructure may be the same as that connecting the point of sale terminal 16 to the acquirer 18.
[0039] The computer at the issuer 22 is similar in construction to the computer at the acquirer 18. The computer at the issuer 22 has one or more account data sets 24 stored as electronic data on the memory component. The issuer 22 thus has the account data set 24 stored thereon which is associated with the electronic payment device 14. This specific account data set is known as the card holder's account 24. Each transaction relating to a cardholder account stored on the issuers' computer may be processed as either a card present (CP) transaction or a card not present (CNP) transaction. The memory component of the issuers' computer has a transaction program stored thereon which is executed by the computer's processor in order to process the transaction as a card present or card not present transaction. Different rules may be applied for the authorisation of CP and CNP transactionsCP transactions will typically be regarded as more secure as additional user authorisation information may be used in transactions as cryptographic information is included evidencing a trust relationship between the payment device and the issuer, though this approach has hitherto required registration of the user authorisation information with the issuer. CNP transactions may require additional authorisation steps for issuer approval to take place.
[0040] With reference to
[0041] When the account holder wishes to pay for an item at the merchant, the account holder approaches the point of sale terminal 16 with the smart phone 114. The point of sale terminal, once the necessary steps have been taken to establish that there is a transaction to be carried out, is constantly emitting the query to any devices in the immediate proximity of the POS terminal as per step 504. The smartphone 114 receives the query 66 and upon reading the query 66 at step 506, configures the data storage module to generate a transaction demand 54 based on the account and identifier as per step 508the specifics of this approach depend on the protocol used, but according to EMV payment protocols there will first be an interaction to determine a working combination of application at the payment device and processing kernel at the point of sale device, followed by provision of data from the payment device to the point of sale device to provide necessary account information to complete the transaction (here termed a transaction demand). The smartphone 114 sends the transaction demand to the point of sale terminal 16 as step 510. The point of sale terminal 16 processes the transaction demand 54 by reading the received data as per step 512.
[0042] The point of sale terminal 16 processes the transaction as a normal contactless payment. The transaction details however contain the identifier to indicate that the transaction is a CNP transaction. The point of sale terminal 16 able to process the transaction demand as a conventional contactless transaction, even though this is conventionally always a CP transaction, as the presence of the identifier will allow different processing options to be taken in the processing infrastructure. While it is possible to take these different processing options (as discussed below) in the point of sale device, it will typically be more advantageous for point of sale device design to be unchanged and for the differences in processing to be handled in the transaction infrastructure.
[0043] At step 514, the transaction infrastructure checks to see whether the CNP indicator is present. This enables it to determine whether the transaction should be processed as a conventional CP transaction or as a CNP transaction.
[0044] If the indicator is present, the transaction infrastructure processes the transaction as a CNP transaction 516 and routes the transaction to the issuer (or to whichever party handles CNP transactions for the issuer) to approve or decline the transaction 518.
[0045] This may require the customer to make an additional authentication step 519 of the kind customarily required for CNP transactions (for example Verified by Visa or MasterCard SecureCode for conventional online transactions). With reference again to
[0046] In the case where the account data set matches that of the cardholder's account 24 the transaction is approved by the issuer as per step 522. With further reference to
[0047] In the case where the account data set does not match that associated with the card holder's account 24, the transaction is declined by the issuer at step 524 on
[0048] If the transaction is identified as a conventional CP contactless transaction, the transaction infrastructure determines 526 that the transaction should be processed as a CP transaction and the steps that follow are conventional. The transaction request is forwarded 528 to the issuer to be accepted or declined, the issuer uses 530 its decryption key to authenticate the encrypted authentication data provided in the transaction information, and the transaction is approved or rejected as before depending on the assessment 532 of the validity of the account information.
[0049] Various alternatives to the electronic payment apparatus or the process to proceed with the transaction are envisaged without falling outside the scope of the claims. In particular, the payment device need not be a computing device such as a smart phone (or tablet computer)it could be a physical token such as a payment card or even a key fob.
[0050] With reference to
[0051] Providing the electronic payment device 14 in the form a payment card 214 or a key fob 414 may be particularly advantageous in certain situations, particularly for performing transactions with a particular retailer. Store cardsand proxies for store cardsmay provide significant additional benefits for retailers and customers in that they allow the retailer to track customer behaviour, in return for which loyalty discounts and special offers are provided to the customer. It is desirable for the retailer to control issuance of these devices, as this makes it easier for the retailer to control secure interactions with the device (so that the retailer can confirm that the device is a valid registered device) and for the retailer to ensure that transactions between the customer and the retailer will be made with that payment device. It is difficult for a conventional payment device to act both as a store card and a contactless payment device, as this currently requires both issuer and retailer involvement in device set up.
[0052] In embodiments of the disclosure it may be desired to establish a store card as a contactless electronic payment device. The store may wish to link the store card to the user's account with an issuer directly without preloading the store card with credit or providing a special overdraft facility. In this way, the store can issue the store card to the user without having to request authentication from the account issuer thus saving time and maintaining flexibility and control.
[0053] A process of setting up a payment device according to an embodiment of the disclosure will now be described with reference to
[0054] These steps are described above in the context of a physical device. However, they may also be employed in customisation of an application to be downloaded to a user device such as a smart phone such as in the
[0055] An approach is then needed to enable 808 customer account information to be written to the payment device. Where the payment device is a smart phone equipped with a suitable payment application, this may simply be through use of the smart phone user interface to write data into fields of the payment application. In the case of a payment card, this may require customer account information to be written into the device using a system that is in contact with the processing environment on the card through a contact or contactless interfacethis may be the retailer (who will then needed to be provided with user account information, for example by a dummy transaction with the customer's payment card to read account information into a retailer terminal) or it may be the customer if provided with an interface to do so (for example, an interface into the retailer system where the retailer has control of the card, or by means of an application on a user device or a website which the customer can access). The customer account information is then written 810 into the payment devicethis account information is typically that available visibly on a payment card (account number, sort code, CVV code etc.) but does not include any cryptographic material used to establish a trust relationship between a payment device and the issuer.
[0056] Further embodiments of this disclosure may be provided by the person skilled in the art according to the spirit and scope of the claims without limitation to the embodiments described above.