Contactless Card Cryptograms for Secure Merchant Messaging Payments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing payment systems face challenges in providing secure and fast payment channels that do not degrade the customer experience, particularly in online transactions, as they are vulnerable to hacking and require inconvenient authentication methods.
Innovation Solution
A system and method utilizing a contactless card as one authentication factor, where a cryptogram from the card is validated to extract a unique customer identifier, verified, and used to retrieve account information for secure payment processing via application programming interfaces (APIs).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If email or SMS is used for authentication, then customer verification can be performed, but the system becomes vulnerable to hacking and unauthorized access
Solution Approach 1:
The patent introduces a contactless card as an intermediary authentication device between the customer and the payment system. The card contains a cryptogram that serves as a secure mediator, transferring authentication credentials without exposing sensitive data. This intermediary layer prevents direct exposure of authentication vulnerabilities that exist in email/SMS-based systems.
Solution Approach 2:
The patent replaces the mechanical/vulnerable systems of email and SMS authentication with a contactless cryptographic system. Instead of relying on text-based communication channels that can be intercepted, the system uses contactless card technology with embedded cryptograms, substituting the authentication mechanism entirely to eliminate the vulnerability to hacking.
2Reliability
If photo ID is used as authentication factor, then identity verification is improved, but it does not work for online or non-face-to-face transactions
Solution Approach 1:
The patent creates a digital copy of identity verification capabilities within the contactless card. Instead of requiring physical photo ID presentation, the system embeds cryptographic credentials in the contactless card that replicate the identity verification function. This digital copy enables the same level of identity assurance to work seamlessly in online and remote transactions where physical ID cannot be presented.
Solution Approach 2:
The contactless card serves multiple functions: it acts as both an identity verification tool and a payment authentication device. This multi-functional card replaces the need for separate photo ID and payment methods, providing universal authentication that works across both in-person and online transaction contexts.
3Reliability
If traditional payment authentication methods are used, then security can be maintained, but the payment process becomes slow and customer experience degrades
Solution Approach 1:
The contactless card contains pre-computed cryptograms and authentication credentials that are prepared in advance. When a transaction occurs, the card can immediately provide these pre-prepared credentials without requiring real-time computation or additional verification steps. This preliminary preparation of authentication data enables fast processing while maintaining security.
Solution Approach 2:
The patent enables the authentication process to skip multiple traditional verification steps by using the contactless card's embedded cryptogram. Instead of proceeding through lengthy authentication sequences, the system can rapidly verify the cryptogram and complete authentication in a single step, rushing through the security verification process efficiently.
Data Source
AI summary
A method is provided including receiving, by a server from a user device, a cryptogram of a contactless card, wherein the user device receives a payment request message from a merchant device, and the user device receives the cryptogram from a contactless card upon tapping the contactless card to the user device. The method further includes validating and decrypting, by the server, the cryptogram, extracting, by the server, from the decrypted cryptogram a unique customer identifier associated with the user, and verifying, by the server, the unique customer identifier. The method further includes retrieving, by the server from a database, account information of the user, calling, by the server, one or more application programming interfaces (APIs) of the merchant device to make a payment in response to the payment request message, and provisioning, by the server, the account information to the merchant device via the APIs.


