US 11,973,871 B2
Domain validations using verification values
Sheldon Banow, Castro Valley, CA (US); Eduardo Lopez, Menlo Park, CA (US); and Sayeed Mohammed, Foster City, CA (US)
Assigned to Visa International Service Association, San Francisco, CA (US)
Filed by Visa International Service Association, San Francisco, CA (US)
Filed on Jan. 20, 2022, as Appl. No. 17/580,563.
Prior Publication US 2023/0231717 A1, Jul. 20, 2023
Int. Cl. H04L 9/32 (2006.01)
CPC H04L 9/3213 (2013.01) 19 Claims
OG exemplary drawing
 
1. A method comprising:
receiving, at a processing system comprising a token service computer from a token requestor, a token data request message comprising an initial resource provider identifier associated with a resource provider operating a resource provider computer;
determining, by the processing system, a permanent resource provider identifier using the initial resource provider identifier;
responsive to determining the permanent resource provider identifier, determining, by the processing system, a verification value;
associating, by the processing system, the permanent resource provider identifier with a token, the verification value, and domain controls associated with the token;
providing, by the processing system, a token data response message comprising the verification value to the token requestor;
receiving, by the processing system, an authorization request message for a transaction, the authorization request message comprising the token, the verification value, and one or more data elements in a plurality of data fields;
determining, by the processing system, the permanent resource provider identifier using the one or more data elements in the plurality of data fields;
determining, by the processing system, that the verification value in the authorization request message matches the verification value that was provided to the token requestor, and that the transaction satisfies the domain controls; and
transmitting, by the processing system, an authorization response message to the resource provider computer, and wherein the method further comprises:
before the authorization request message is received by the processing system, temporarily linking, by the processing system, the permanent resource provider identifier, the initial resource provider identifier, and the token; and
after the authorization response message is transmitted, permanently linking, by the processing system, the permanent resource provider identifier, the initial resource provider identifier, and the token.