Constrained Interaction Token for Fraud Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Interaction tokens, used to reduce fraud risk in the payments industry, still pose risks as they can be stolen and used for illegitimate purchases, necessitating additional security measures to protect both users and merchants.

Innovation Solution

A method and system for provisioning interaction tokens with constraints, including a defined resource, value, and time period, where a communication device generates and transmits an interaction token to a token provider computer, which processes the transaction, ensuring the token's value and validity, thereby limiting its misuse.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If interaction tokens are used to substitute for primary account numbers, then fraud risk is reduced and user confidence is improved, but new fraud risks emerge as stolen tokens can still be used for illegitimate purchases

Engineering Contradiction:
Improvefraud risk reductionVSAvoidtoken theft risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies parameter changes by transforming the interaction token from a static substitution value into a dynamic credential with multiple controllable parameters including time validity period, geographic location restrictions, merchant category codes, and spending limits. These parameter changes ensure that even if a token is stolen, its usefulness is severely limited by the constrained parameters, thereby reducing the harmful effects of token theft while maintaining the fraud risk reduction benefits

Inventive Principle:
Principle #35Parameter changes

2Reliability

If interaction tokens are made more restrictive with constraints on resource, value, and time, then security is enhanced and fraud risk is reduced, but the complexity of token provisioning and management increases

Engineering Contradiction:
ImprovesecurityVSAvoidtoken provisioning complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring all security constraints (time periods, resource identifiers, interaction values, geographic locations) during the token provisioning phase rather than enforcing them during transaction processing. The token is generated with embedded constraints that automatically validate themselves during use, eliminating the need for complex real-time verification systems while maintaining high security standards

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If automated resource transfer initiation is implemented, then user convenience is improved and time required for resource acquisition is reduced, but the system complexity and potential for automated fraud increase

Engineering Contradiction:
Improveuser convenienceVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling the interaction token system to automatically initiate and complete resource transfers without requiring additional user intervention or complex system coordination. The token itself contains all necessary instructions and constraints, allowing it to self-validate and self-execute the transfer process, thereby improving convenience while minimizing the added system complexity

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11449862B2System and method using interaction token
Publication Date: 2022.09.20 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11449862B2 patent drawing
  • US11449862B2 patent drawing
  • US11449862B2 patent drawing

AI summary

A communication device may receive input from a user and initiate generation of an interaction token in response. This interaction token can be used by the communication device in order search for a specific resource provider computer from among one or more resource provider computers, and to initiate a resource transfer between the user and a specific resource provider, mediated by a token provider computer.