| CPC H04W 12/08 (2013.01) [H04L 9/3271 (2013.01); H04L 63/0838 (2013.01); H04W 12/06 (2013.01); H04W 12/068 (2021.01)] | 20 Claims |

|
1. A method comprising:
receiving, by an access device, a credential or a token from a portable device associated with a user in an interaction;
responsive to receiving the credential or the token from the portable device, transmitting, by the access device, a first authentication request message comprising the credential or the token to an access control server via a directory server, wherein the access control server transmits a one-time password to a user device associated with the user;
receiving, by the access device, the one-time password from the user;
transmitting, by the access device, a second authentication request message comprising the credential or the token, and the one-time password to the directory server, which then transmits the second authentication request message to the access control server via the directory server, wherein the access control server generates an authentication response message comprising an authentication indicator after validating the one-time password;
receiving, by the access device from the access control server, the authentication response message comprising the authentication indicator from the access control server via the directory server; and
transmitting, by the access device, an authorization request message comprising the authentication indicator, and the credential or the token to a processing network computer.
|