Adaptable Messaging for Mobile Payment Fraud Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Remote purchase transactions using mobile devices pose challenges for financial institutions due to authentication and fraud issues, particularly since not all online or remote merchant systems support EMV Standards, leading to a need for systems and methods that provide a good user experience while reducing fraud.
Innovation Solution
The system allows transactions between mobile devices and merchant servers by determining whether the server supports a first data format or an alternative format, generating remote payment data accordingly, and using Digital Secure Remote Payment (DSRP) protocol for improved fraud prevention, enabling transactions with both EMV and non-EMV compliant merchant servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If EMV Standards are used for remote transactions, then authentication security and fraud prevention are improved, but compatibility with merchant systems is worsened since not all online or remote merchant systems support these standards
Solution Approach 1:
The patent changes the data format parameter based on merchant server capability. The mobile device determines whether the merchant server supports EMV data format or alternative format, then transmits payment data in the appropriate format. This allows the system to maintain high security where EMV is supported while ensuring broad compatibility where it is not.
Solution Approach 2:
The system dynamically adapts its operation based on the merchant server's capabilities. The mobile device queries the merchant server to determine supported data formats and adjusts the transmission format accordingly. This dynamic adaptation resolves the contradiction by allowing the system to optimize for security when possible and prioritize compatibility when necessary.
2Adaptability or versatility
If alternative data format is used for transactions, then merchant system compatibility is improved, but authentication security and fraud prevention are worsened compared to EMV format
Solution Approach 1:
The patent introduces an intermediary determination step where the mobile device queries the merchant server to identify the appropriate data format capability. This intermediary process allows the system to select the most secure format available while ensuring compatibility, rather than defaulting to a single format that would compromise either security or compatibility.
Solution Approach 2:
The system changes the data format parameter based on the merchant's capabilities. When EMV format is supported, it uses that for enhanced security. When only alternative formats are supported, it uses those while maintaining fraud protection through available mechanisms. This parameter adaptation resolves the contradiction by optimizing security within the constraints of merchant capability.
3Device complexity
If a single data format is used for all transactions, then system complexity is reduced, but adaptability to different merchant systems is worsened
Solution Approach 1:
The system implements dynamic format selection based on merchant server responses. The mobile device determines the merchant's supported formats and adjusts accordingly, avoiding the need to hardcode support for multiple formats in advance. This dynamic approach maintains relatively simple device logic while achieving broad compatibility.
Solution Approach 2:
The patent makes the mobile payment system universal by enabling it to operate with both EMV-compliant and non-EMV merchant systems. Through automatic format detection and adaptation, a single mobile device can serve multiple merchant types without requiring separate implementations, achieving multi-functionality while keeping device complexity manageable.
Data Source
AI summary
Methods, apparatus and systems for operating a payment-enabled mobile device to facilitate a payment transaction with a merchant server. In an embodiment, a mobile device processor of the payment-enabled mobile device receives a payment transaction request from a user, transmits a payment transaction initiation message directly to a merchant server of the merchant, and receives a request message from the merchant server that includes one of a request to provide an Authorization Request Cryptogram (ARQC) or a request to provide user consent information. The user consent information may include cardholder verification results or a request to provide an ARQC. Based on the received request message, the mobile device processor selects a particular mobile payment cardlet to use from a plurality of mobile payment cardlets running in a secure element, generates remote payment data using the particular mobile payment cardlet, and transmits the remote payment data to the merchant server to process the payment transaction.


