Secure CNP Transactions Using Card Location Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Card not present (CNP) transactions are vulnerable to fraud, with users often unaware when their credit or debit cards are stolen or misplaced, leading to potential identity theft and significant financial losses, as existing systems lack effective mechanisms to verify the physical location of the card during online transactions.
Innovation Solution
Implementing a system where a user's computing device tracks the geographical location of their chip-enabled card and sends datasets to a server, alerting the user if the card is not within range and verifying the card's location during transactions to prevent unauthorized use, by comparing the card's location with the purchaser's location to authenticate and approve or deny transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If location tracking and verification systems are implemented to prevent fraud, then transaction security is improved, but device complexity increases
Solution Approach 1:
The patent introduces an authentication server as an intermediary component that mediates between the purchaser computing device and the card processing system. This server receives location information from the purchaser device, compares it with card location data, and makes authorization decisions. By centralizing the location verification logic in a dedicated intermediary server, the complexity is isolated from both the purchaser device and the card system, allowing them to remain relatively simple while achieving enhanced security through the mediating authentication layer.
2Reliability
If continuous location tracking is performed to detect card theft, then fraud detection capability is improved, but energy consumption increases
Solution Approach 1:
The patent implements periodic location tracking where the purchaser computing device determines its location at scheduled intervals or at specific transaction events rather than continuously. The device sends location information to the authentication server periodically, which then compares this periodic location data with card location information. This periodic action approach provides sufficient fraud detection capability while significantly reducing energy consumption compared to continuous tracking, as the device only activates its location services and communication modules at discrete time points.
3Reliability
If location verification is required for all transactions, then fraud prevention is improved, but transaction processing time increases
Solution Approach 1:
The patent performs location verification as a preliminary step before final transaction authorization. The authentication server receives and validates location information from the purchaser device along with the transaction request, comparing it against card location data stored in the system. By conducting this verification early in the transaction flow, the system can quickly reject obviously fraudulent transactions (where locations don't match) and proceed with standard processing for legitimate ones, preventing time loss from later detection and enabling faster overall processing through early filtering.
Data Source
AI summary
Techniques are described for performing secure card not present (CNP) transactions using integrated circuit chip-enabled cards. The techniques include continually or periodically tracking a location of a user's card by a user computing device, e.g., a “smart” phone, and storing a log of datasets relating to the location of the user's card at a server device. Based on the tracking, the user computing device may alert the user via a push notification or other message when the user's card is not within a preset range of the user computing device. In addition, an authentication server determines a location of a purchaser computing device attempting to perform a CNP transaction using the user's card information, and compares the location of the purchaser computing device with a most recent location of the user's card retrieved from the log of datasets to determine whether to approve the CNP transaction.


