Authorization Server Cryptogram Routing for Multi-Issuer Payments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing payment systems face challenges in verifying the integrity and origin of electronic communication messages, particularly in transactions involving multiple issuers, as cryptograms generated by integrated circuit cards (ICCs) are specific to a given issuer and cannot be validated by other issuers, limiting the use of a single payment device for transactions across different accounts.

Innovation Solution

A computer-implemented method that involves receiving an authorization request from a payment device, determining a secondary issuer, generating an updated authorization request with a secondary cryptogram associated with the secondary issuer, and sending it to the secondary issuer's server, allowing a single payment device to initiate transactions across multiple issuer accounts by using a secondary cryptogram that can be verified by the secondary issuer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single payment device uses issuer-specific cryptograms for transactions, then cryptographic verification security is improved, but device versatility across multiple issuers deteriorates

Engineering Contradiction:
Improvecryptographic verification securityVSAvoiddevice versatility across multiple issuers
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the cryptographic verification process by separating the initiation of authorization requests (performed by the payment device with main issuer cryptogram) from the validation process (performed by the secondary issuer). This allows the payment device to maintain a single cryptographic tool while enabling verification by multiple issuers through the authorization processing system's routing capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authorization processing system acts as an intermediary between the payment device and multiple issuers. It receives authorization requests with main issuer cryptograms, determines appropriate secondary issuers, and routes requests to the correct issuer for validation. This intermediary enables the payment device to interact with multiple issuers without requiring multiple cryptographic tools.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If cryptograms are generated using issuer-specific cryptographic materials, then origin verification accuracy is improved, but system adaptability to multiple issuers deteriorates

Engineering Contradiction:
Improveorigin verification accuracyVSAvoidsystem adaptability to multiple issuers
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The authorization processing system provides universal functionality by handling authorization requests from a single payment device and routing them to multiple different issuers. The system can process main issuer cryptograms from one issuer while validating against secondary issuers, making the overall system adaptable to multiple issuers without requiring the payment device to have multiple cryptographic tools.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically determines which secondary issuer to use based on the transaction context and routing rules. The authorization processing system can adaptively select appropriate secondary issuers for different transactions, maintaining origin verification accuracy through issuer-specific cryptogram validation while providing system-wide adaptability to multiple issuers through dynamic routing decisions.

Inventive Principle:
Principle #15Dynamics

3Reliability

If a payment device is linked to a particular issuer for cryptogram generation, then transaction security is improved, but user flexibility for multiple accounts deteriorates

Engineering Contradiction:
Improvetransaction securityVSAvoiduser flexibility for multiple accounts
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system extracts the multi-issuer functionality from the payment device itself and places it in the authorization processing system. The payment device maintains its simple, secure role of generating cryptograms with a single issuer, while the authorization processing system handles the complexity of routing to multiple issuers. This extraction preserves transaction security at the device level while enabling user flexibility at the system level.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authorization processing system automatically determines and routes to appropriate secondary issuers without requiring user intervention. The system self-manages the complexity of multi-issuer transactions by automatically selecting the appropriate secondary issuer based on routing rules and transaction context, thereby providing user flexibility without compromising transaction security or requiring users to manage multiple cryptographic credentials.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3933731A1Authorization data processing for multiple issuers
Publication Date: 2022.01.05 MASTERCARD INT INC
  • EP3933731A1 patent drawingFigure 1
  • EP3933731A1 patent drawingFigure 2
  • EP3933731A1 patent drawingFigure 3

AI summary

The invention provides systems and methods capable of effecting payment with a payment account that is different to the payment account associated with a payment device that initiated a payment transaction. An authorisation request message is modified by the invention to replace a cryptogram associated with the payment device with a cryptogram associated with the payment account that payment is to be taken from. A user may use a mobile communication device to communicate with a server storing associations between payment devices, such that the server can be consulted by a payment network server to determine which cryptogram to generate when modifying the authorisation request.