MULTI-LAYER 3D SECURE ONLINE PAYMENT SYSTEM AND METHOD ENHANCED WITH NFC-BASED PHYSICAL CARD AUTHENTICATION.

TR202608002A2Pending Publication Date: 2026-06-22LABORGEE ARGE LABORATUVARLARI GIDA KİMYA SANAYİ TİCARET LİMİTED ŞİRKETİ +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
TR202608002
Authority / Receiving Office
TR · TR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-05-20
Publication Date
2026-06-22

Smart Images

  • Figure 00000010_0000
    Figure 00000010_0000
  • Figure 00000015_0000
    Figure 00000015_0000
Patent Text Reader

Abstract

The invention is an NFC-based physical card authentication system and method integrated into the 3D Secure flow, developed to prevent unauthorized transactions and 3D Secure bypass attacks even if card information is compromised in online payment processes. In the system, after card information is entered on the e-commerce site (D), a transition is made to the bank application via a deep link (App-to-App) architecture. A one-time dynamic cryptographic random number (RND) generated by the bank server (C) is transmitted to the EMV chip of the physical card (B) via NFC. The EMV chip signs this RND input, generating a one-time dynamic ARQC cryptogram. The 3D Secure process is not initiated until this signature is verified on the bank server (C). Thanks to this invention, online payments cannot be completed without mathematically confirming the physical existence of the card.
Need to check novelty before this filing date? Find Prior Art

Description

1 TARIFF MULTIPLE CARD AUTHENTICATIONS ENHANCED BY NFC-BASED PHYSICAL CARD VERIFICATION. LAYERED 3D SECURE ONLINE PAYMENT SYSTEM AND METHOD Technical Area This invention is relevant to online payment systems, online card payment security, and NFC (Near 5.05) technology. Field Communication (FCC) based physical verification, EMV chip cryptography, multi-factor authentication. validation, deep-linking-based app-to-app architectures, and It is related to 3D Secure protocols. State of the Art Traditional online payment systems require a card number, expiration date, and 10... Payment is made by entering CVV (Card Verification Value) information, then a static or Dynamic one-time passwords and 3D Secure authentication are implemented. Currently... These systems in technology cannot verify the physical presence of the card. The current 3D Secure system... protocols include SIM swapping (SIM card cloning), SMS forwarding, phishing, and Malware that blocks or hijacks push notifications at the device level 15 This can be bypassed through this method. Once card information is leaked or stolen, the original card... Unauthorized payment transactions can be carried out outside of the owner's physical control. Payment The EMV chips on these cards provide high performance in physical POS (Point of Payment) transactions. Despite offering multi-level cryptographic security (ARQC / TC generation), the current infrastructure Due to their shortcomings and flow designs, these advanced cryptographic capabilities are not available online. 20 It cannot be actively used in payments. This situation affects the e-commerce ecosystem in terms of chargebacks. This leaves you vulnerable to chargeback and card fraud risks. Purpose of the Invention The primary purpose of the invention is to physically process the card at the device where the payment is made during online payments. 25 The invention aims to provide a dynamic cryptographic randomness generated by the bank server. the number (RND / Challenge) is transmitted via NFC to a physical card without an internet connection using EMV. feeding into the chip and the one-time dynamic cryptographic signature generated by the EMV chip (ARQC) is intended to be included in the online payment verification process. Thus, NFC The 3D Secure step cannot be initiated until the physical card verification based on the card is successfully completed. 30 making it possible to transfer data through an operating system-level app-to-app architecture. 2 preserving integrity; even if the card information is completely stolen, the card remains without its physical presence. preventing transactions and attacks such as SIM swapping, phishing, and 3D Secure bypass. The aim is to render it completely ineffective technically. Explanation of the Figures Figure 1: General components of a multi-layered online payment verification system and the 5 components between them. It is a block diagram showing the connections. Explanation of References in Figures The parts and modules shown in the figures are intended to facilitate understanding of the invention. They are numbered, and their reference equivalents are given below. A: User device (Smartphone / Tablet) 10 B: Physical payment card (with EMV chip and NFC antenna) C: Bank server (Cryptographic verification and 3DS engine) D: E-commerce interface (Payment form) Description of the Invention The system that is the subject of the invention and the method that runs on this system basically consist of the following 15 components. It consists of: User Device (A): Contains an NFC reader module, deep at the operating system level. The connection (Deep-Linking / Universal Links / App Links) management infrastructure belongs to the relevant bank. mobile banking / payment application, secure communication layer and cryptographic session smartphone or tablet containing the management, 20 Physical Card (B): Contains an embedded EMV standard microchip, NFC antenna, and ARQC. Bank including (Application Cryptogram Request) production module and dynamic signature generation unit. or credit card, Bank Server (C): Dynamic cryptographic random number (RND) generation service, NFC Authentication module, EMV signature / cryptogram authentication engine, 3D Secure authentication infrastructure 25 and a remote server system containing the risk analysis module, E-Commerce Interface (D): The web / mobile payment form where the user enters their card information and A platform that includes a routing layer with API integration with the bank server. 3 Process Flow of the Invention Method The invention concerns a multi-layered online payment verification method, following the steps in the process: It is accomplished by performing the following actions in sequence: 1. The user initiates the payment process by entering their card information (D) in the e-commerce interface. 2. The e-commerce interface (D) transmits the payment request to the bank server (C); bank server (C) 5 a one-off, dynamic cryptographic random number (RND / Challenge) specific to this process and It generates a unique session ID. 3. E-commerce via deep link protocols at the operating system level. from the interface (D) automatically to the bank mobile application (A) on the user device The transition (App-to-App redirection) is performed. 10 4. The bank's mobile application displays the NFC verification interface on the user device (A) screen. It activates and keeps the dynamic RND value it receives from the bank server (C) ready. amount. 5. The user touches the physical card (B) to the NFC scanning area of ​​the user device (A). 6. User device (A) transmits the physical card via NFC protocol (APDU command sets) 15 (B) Transmits the relevant dynamic RND value to the EMV chip. 7. The cryptographic processing unit within the physical card (B) processes the incoming RND value internally. By combining the card's private key and internal transaction counter (ATC), it creates a single system. It generates a dynamic ARQC cryptographic signature once and transmits this signature over NFC. Sends it back to the user device (A). 20 8. The bank application on user device (A) receives the ARQC signature and session It transmits its identity to the bank server (C). 9. The bank server (C) verifies the incoming ARQC signature with its own generated RND input and the card was physically present next to the device being processed at that moment Approves. 25 10. After the physical card's existence is confirmed, the bank server (C) performs a second security check. It initiates the 3D Secure verification process as a layer. 11. User; biometric data via SMS, push notification or on user device (A) They verify their identity using at least one of the following methods: (fingerprint / face recognition). 4 12. After the 3D Secure verification is also successfully completed, the payment process The bank server (C) approves and the user device (A) performs a deep connection. with its architecture e-commerce interface (D) automatically returns with a secure success token is directed. In another variant of the invention, 5 on online platforms that do not use the 3D Secure protocol. NFC-based physical card verification is also mandatory for payment transactions. In this variant, even if the 3D Secure flow is not triggered by the e-commerce interface (D), the bank Server (C) classifies the payment request as a “high-risk transaction” and 3D Secure For transactions that are not in use, NFC verification is implemented as a mandatory prerequisite. Thus, Even if card information is compromised, the payment process will not be completed without verifying the physical existence of the card. It cannot be accomplished. Another application of the invention is the linking of the card to online wallets (wallet / card-on-file). NFC-based physical verification is also required during the addition of a card. The user must have a card. When you want to save to an online wallet, the bank's mobile application opens automatically. and card (B) verification via NFC is required. Without this verification, the card cannot be added to the wallet for 15 days. Adding further details is not allowed. Thus, even if the card information is stolen, the attacker cannot use the card in any way. It becomes technically impossible to save it to an online wallet. In an advanced variant of the invention, every payment made with cards registered in the online wallet NFC-based physical verification is also required in this process. In this method, the card must have been previously verified. Even if added to the wallet, the card must be physically inserted into the user's device (A) 20 during each payment. Contact must be made. This approach involves handling card information or wallet accounts. Even if it were to pass through, it completely prevents unauthorized payments. In a variant of the invention relating to virtual cards, the virtual cards replace a physical card. Since it is not present, the main physical card (B) to which the virtual card is linked must be connected via NFC once. Verification is required. When a user creates a new virtual card, the bank application requires verification on 25... The virtual card requires the physical card to be verified via NFC. This verification... The virtual card will not be activated until this process is complete. Therefore, even if the virtual card information is compromised... Transactions cannot be processed without physical card verification. Another variant of the invention regarding security settings involves NFC-based physical verification. This feature can only be disabled by the user in the bank's mobile application 30. This can be done via biometric authentication and multi-factor authentication. This process requires both biometric authentication. Both fingerprint / face recognition and reading of the physical card (B) via NFC are required. In contrast, reactivating the NFC verification feature is only possible with the bank. This can be done in a single step via the application. Security settings, push notifications, It cannot be changed via SMS or third-party applications. This approach is security 5. This makes it technically impossible for malware to disable this feature. In another future-oriented variant of the invention, payment transactions would be handled exclusively by smartphones. not through the skin; smartwatches, smart rings, smart bracelets, augmented reality glasses, subcutaneous implant chips, biometric wearable devices, and IoT-based portable payment terminals In cases where it can also be initiated via wearable or body-integrated technologies, the word 10 The devices in question have the authority to trigger payments only if the physical card (B) is via NFC. It can be activated upon verification. This approach will enable mobile payment transactions in the future. Even if the shift from devices to wearable technologies occurs, the physical presence of the card will remain. This makes mathematical verification mandatory and ensures the security of all new generation devices. It enables them to make payments in this way. 15 How the invention can be applied to industry. The invention concerns a multi-layered online payment verification system and method, for the financial industry. fully integrated into banking infrastructures, e-commerce ecosystems, and mobile software / hardware sectors. It is feasible. The invention requires the production of hardware from scratch in order to bring it to life. not required, existing and widely used industrial standards and technological 20 It is possible to implement these systems in industry by integrating them with the infrastructure. Hardware and Infrastructure Compatibility: Modern smartphones and tablets (User) The device - A) has a very large section embedded with an NFC (Near Field Communication) reader. It has modules. Similarly, bank and credit cards (Physical Card - B) on the market. Almost entirely microchips compliant with EMV standards and built-in NFC 25 enabling contactless payments. It houses the antenna. The invention uses this existing equipment line without incurring an additional cost. It can be applied directly in industry without requiring any intervention. Software Integration and Standards: Validation on the Bank Server (C) side Its mechanisms are fully compliant with global EMVCo standards and 3D Secure (3DS) protocols. It can be installed via software algorithms (API, SDK). 30 at the operating system level. Application transitions are made via "Android App Links" on the Android operating system and on the iOS operating system. 6 standard software development using "Universal Links" protocols in the system It is integrated with the processes. Global Scalability: The method integrates with existing e-commerce sites. with a small API / routing layer to be added to payment forms (D) worldwide Easily accessible to all digital shopping platforms and payment gateways. It is scalable and can be integrated in series. 5 Based on these characteristics, the invention has applications in the financial technology (FinTech) industry and banking. immediate, repeatable and commercial in digital security processes and the cybersecurity sector It has a viable quality. 15 25 7 FIGURE 1 EU CD 15 8 REQUESTS Claim 1. An authentication method that provides multi-layered security for online payments. feature; Entering card information into the e-commerce interface (D) via the user device (A) and making the payment triggering, 5 When the payment is triggered, the bank server (C) processes a dynamic cryptographic random number specific to the transaction. Generating a native number (RND) and a session ID, User device (A) e- via deep link protocols at the operating system level Automatic app-to-app transfer from the trading interface (D) to the bank mobile application. Switching to (App) 10 The dynamic RND that the bank mobile application receives from the bank server (C) transmitting its value to the EMV chip of the physical card (B) via the NFC protocol, The physical card (B) processes this RND value via its internal cryptographic processing unit. It processes and generates a one-time dynamic ARQC cryptographic signature via NFC. the user must return the device (A), 15 The ARQC signature in question is transmitted to the bank server (C) for verification and this NFC 3D Secure authentication cannot be performed until the physical card verification step based on the card verification process is successfully completed. It includes steps to prevent the process from being initiated. Claim 2. A verification method compliant with Claim 1, characterized by its NFC-based physical card. If the verification fails or the card is not touched, the bank will charge 20 The server (C) automatically cancels the 3D Secure flow, does not generate the payment token, and It is the rejection of the transaction. Claim 3 is a verification method compliant with Claim 1, and its characteristic is that it is used during NFC verification. By scanning the unique chip ID of the physical card (B), the card is determined to be copied or counterfeit. Whether or not it exists is determined on the bank server (C) side. 25 Claim 4 is a verification method compliant with Claim 1, and its features include SIM swap and SMS. To prevent redirection attacks, NFC-based physical authentication is being used in conjunction with SMS. or as a mandatory prerequisite step before push notification-based 3D Secure steps It is the execution of. 9 Claim 5. A verification method compliant with Claim 1, characterized by its compatibility with the NFC verification process. geographic location data received from the user device (A) in a timely manner and the device The attributes are processed by a risk analysis module on the bank server (C) and the transaction is It is the determination of the risk score. Claim 6. This is a verification method compliant with Claim 1, and its feature is; NFC verification with user 5 data received from the built-in biometric authentication hardware on device (A) The goal is to create a multi-factor authentication matrix by combining these factors. Claim 7. This is a verification method that conforms to Claim 1, and its characteristic feature is the verification protocol. In this context, the card's security on physical POS devices is reduced due to magnetic strip fallback. (fallback) operations are completely disabled on the server (C) side of the online channel 10 It is to be abandoned. Claim 8. Configured to execute the method specified in Claim 1; it incorporates an NFC. a user device (A) containing reader module and deep link management infrastructure, A physical card (B) containing an embedded EMV chip and NFC antenna, dynamic cryptographic A 15 with a random number (RND) generation service and an EMV cryptogram verification engine a multi-layered system containing a bank server (C) and an e-commerce interface (D) with a payment form It is an online payment verification system. Claim 9 is an authentication method compliant with Claim 1, and its characteristic feature is the 3D Secure protocol. In online payment transactions that do not use the bank server (C), the transaction in question is high. Classified as risky, even if the 3D Secure flow is not triggered, the NFC-based physical card 20 It is the application of verification as a mandatory prerequisite. Claim 10. A verification method that complies with Claim 1 and features; online wallets (wallet / card-on-file) card adding process via bank mobile application (B) NFC The goal is to prevent the item from being added to the wallet without physical verification through the system. Claim 11. A verification method compliant with Claim 1, characterized by having 25 registered in the online wallet. In every payment transaction made with cards, the card (B) makes contact with the user device (A) via NFC. It is mandatory to have it done. Claim 12. A verification method that complies with Claim 1 and features the activation of virtual cards. before they are brought in, the main physical card (B) to which they are linked must be verified via NFC It is mandatory. 30 Claim 13. A verification method compliant with Claim 1, characterized by its ability to process online payment transactions. In all cases, regardless of the type of transaction, the card (B) is sent to the user device (A) for each transaction. It is mandatory to make physical contact via NFC. Claim 14. A verification method compliant with Claim 1, characterized by its NFC-based physical nature. Disabling the verification feature is only possible via the bank's mobile application, 5 biometric authentication and reading of the physical card (B) via NFC is possible It is the fact that. Claim 15. A verification method compliant with Claim 14, characterized by its NFC verification capability. Push notifications cannot be changed via SMS messages or third-party applications. And it can only be changed within the bank application. 10 Claim 16 is a verification method compliant with Claim 1, characterized by the fact that additional cardholders can verify their own identity. They can make payments by verifying their cards via NFC on their own user devices (A) and The purpose is to prevent unauthorized third parties from using the cardholder's card. Claim 17 is a verification method compliant with Claim 10, and its characteristic is that it uses the API of wallet services. NFC verification is also mandatory for card addition attempts via the system. 15 Claim 18 is a verification method compliant with Claim 12, and its characteristic feature is that every transaction made with a virtual card... In the transaction, the physical card (B) to which the virtual card is linked must have been previously verified via NFC. This is checked by the bank server (C). Claim 19 is a verification method compliant with Claim 11, and its feature is that if the wallet account is compromised... Payment is not allowed unless the physical existence of the card (B) is verified via NFC. It is to prevent. Claim 20. A verification method compliant with Claim 1, and its feature is; smartwatch, smart ring, smart Wristbands, augmented reality glasses, subcutaneous implant chips, biometric wearable devices and in payment transactions initiated via other IoT-based portable payment devices, the word The devices in question have payment triggering authorization only if the physical card (B) is connected to the user device (A) 25 It can be activated by verification through contact via NFC. 11 SUMMARY MULTIPLE CARD AUTHENTICATIONS ENHANCED BY NFC-BASED PHYSICAL CARD VERIFICATION. LAYERED 3D SECURE ONLINE PAYMENT SYSTEM AND METHOD The invention prevents unauthorized transactions and 3D Secured Data protection, even if card information is compromised during online payment processes. A 5-bit system integrated into the 3D Secure flow, developed to prevent secure bypass attacks. It is an NFC-based physical card verification system and method. In the system, on the e-commerce site (D) After entering card information, it is transferred to the bank application via a deep link (App-to-App) architecture. A one-time dynamic cryptographic is generated by the bank server (C). A random number (RND) is transmitted via NFC to the EMV chip of the physical card (B). The EMV chip then transmits this RND generates a one-time dynamic ARQC cryptogram by signing its input. This signature is issued by the bank in 10 steps. The 3D Secure process cannot be initiated without verification on server (C). Thanks to this invention, the card... Online payments cannot be completed without mathematical confirmation of the physical existence of the payment method.

Claims

1 REQUESTS Claim 1. An authentication method that provides multi-layered security for online payments. feature; Entering card information into the e-commerce interface (D) via the user device (A) and making the payment triggering, 5 When the payment is triggered, the bank server (C) processes a dynamic cryptographic random number specific to the transaction. Generating a native number (RND) and a session ID, User device (A) e- via deep link protocols at the operating system level Automatic app-to-app transfer from the trading interface (D) to the bank mobile application. Switching to (App) 10 The dynamic RND that the bank mobile application receives from the bank server (C) transmitting its value to the EMV chip of the physical card (B) via the NFC protocol, The physical card (B) processes this RND value via its internal cryptographic processing unit. It processes and generates a one-time dynamic ARQC cryptographic signature via NFC. the user must return the device (A), 15 The ARQC signature in question is transmitted to the bank server (C) for verification and this NFC 3D Secure authentication cannot be performed until the physical card verification step based on the card verification process is successfully completed. It includes steps to prevent the process from being initiated. Claim 2. A verification method compliant with Claim 1, characterized by its NFC-based physical card. If the verification fails or the card is not touched, the bank will charge 20 The server (C) automatically cancels the 3D Secure flow, does not generate the payment token, and It is the rejection of the transaction. Claim 3 is a verification method compliant with Claim 1, and its characteristic is that it is used during NFC verification. By scanning the unique chip ID of the physical card (B), the card is determined to be copied or counterfeit. Whether or not it exists is determined on the bank server (C) side. 25 Claim 4 is a verification method compliant with Claim 1, and its features include SIM swap and SMS. To prevent redirection attacks, NFC-based physical authentication is being used in conjunction with SMS. or as a mandatory prerequisite step before push notification-based 3D Secure steps It is the execution of. 2 Claim 5. A verification method compliant with Claim 1, characterized by its compatibility with the NFC verification process. geographic location data received from the user device (A) in a timely manner and the device The attributes are processed by a risk analysis module on the bank server (C) and the transaction is It is the determination of the risk score. Claim 6. This is a verification method compliant with Claim 1, and its feature is; NFC verification with user 5 data received from the built-in biometric authentication hardware on device (A) The goal is to create a multi-factor authentication matrix by combining these factors. Claim 7. This is a verification method that conforms to Claim 1, and its characteristic feature is the verification protocol. In this context, the card's security on physical POS devices is reduced due to magnetic strip fallback. (fallback) operations are completely disabled on the server (C) side of the online channel 10 It is to be abandoned. Claim 8. Configured to execute the method specified in Claim 1; it incorporates an NFC. a user device (A) containing reader module and deep link management infrastructure, A physical card (B) containing an embedded EMV chip and NFC antenna, dynamic cryptographic A 15 with a random number (RND) generation service and an EMV cryptogram verification engine a multi-layered system containing a bank server (C) and an e-commerce interface (D) with a payment form It is an online payment verification system. Claim 9 is an authentication method compliant with Claim 1, and its characteristic feature is the 3D Secure protocol. In online payment transactions that do not use the bank server (C), the transaction in question is high. Classified as risky, even if the 3D Secure flow is not triggered, the NFC-based physical card 20 It is the application of verification as a mandatory prerequisite. Claim 10. A verification method that complies with Claim 1 and features; online wallets (wallet / card-on-file) card adding process via bank mobile application (B) NFC The goal is to prevent the item from being added to the wallet without physical verification through the system. Claim 11. A verification method compliant with Claim 1, characterized by having 25 registered in the online wallet. In every payment transaction made with cards, the card (B) makes contact with the user device (A) via NFC. It is mandatory to have it done. Claim 12. A verification method that complies with Claim 1 and features the activation of virtual cards. before they are brought in, the main physical card (B) to which they are linked must be verified via NFC It is mandatory. 30 3 Claim 13. A verification method compliant with Claim 1, characterized by its ability to process online payment transactions. In all cases, regardless of the type of transaction, the card (B) is sent to the user device (A) for each transaction. It is mandatory to make physical contact via NFC. Claim 14. A verification method compliant with Claim 1, characterized by its NFC-based physical nature. Disabling the verification feature is only possible via the bank's mobile application, 5 biometric authentication and reading of the physical card (B) via NFC is possible It is the fact that. Claim 15. A verification method compliant with Claim 14, characterized by its NFC verification capability. Push notifications cannot be changed via SMS messages or third-party applications. And it can only be changed within the bank application. 10 Claim 16 is a verification method compliant with Claim 1, characterized by the fact that additional cardholders can verify their own identity. They can make payments by verifying their cards via NFC on their own user devices (A) and The purpose is to prevent unauthorized third parties from using the cardholder's card. Claim 17 is a verification method compliant with Claim 10, and its characteristic is that it uses the API of wallet services. NFC verification is also mandatory for card addition attempts via the system. 15 Claim 18 is a verification method compliant with Claim 12, and its characteristic feature is that every transaction made with a virtual card... In the transaction, the physical card (B) to which the virtual card is linked must have been previously verified via NFC. This is checked by the bank server (C). Claim 19 is a verification method compliant with Claim 11, and its feature is that if the wallet account is compromised... Payment is not allowed unless the physical existence of the card (B) is verified via NFC. It is to prevent. Claim 20. A verification method compliant with Claim 1, and its feature is; smartwatch, smart ring, smart Wristbands, augmented reality glasses, subcutaneous implant chips, biometric wearable devices and in payment transactions initiated via other IoT-based portable payment devices, the word The devices in question have payment triggering authorization only if the physical card (B) is connected to the user device (A) 25 It can be activated by verification through contact via NFC.