Contactless Card Cryptogram Verification for Digital Transaction Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital transaction systems lack adequate security measures to prevent fraud, especially for transactions that satisfy predetermined risk factors such as high value or suspicious origins.
Innovation Solution
A method that solicits communication between a contactless card and a mobile device when a digital transaction satisfies certain risk factors, involving the receipt and verification of a cryptogram to authenticate the user account and confirm the contactless card association, as well as verifying the phone number associated with the mobile device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security measures (user names and passwords) are used for digital transactions, then ease of operation is maintained, but security against fraud is insufficient for high-risk transactions
Solution Approach 1:
The system applies different authentication methods based on the risk level of the transaction. Low-risk transactions use simple password authentication, while high-risk transactions trigger additional verification steps including contactless card authentication and biometric verification. This localized application of security measures ensures strong protection where needed without unnecessarily complicating routine transactions.
Solution Approach 2:
The system performs risk assessment before authorizing the transaction to determine the appropriate authentication level. By evaluating transaction characteristics (amount, location, device, IP address) in advance, the system can prepare and request the necessary verification steps beforehand, preventing fraud while maintaining smooth processing for legitimate transactions.
2Reliability
If additional verification steps are added for high-risk transactions, then security is improved, but transaction processing time increases
Solution Approach 1:
The system evaluates risk factors and determines the need for enhanced authentication before the transaction is fully processed. By identifying high-risk transactions early in the process, the system can prompt users to complete verification steps (contactless card tap, biometric scan) before authorization, rather than adding delays after the transaction is initiated. This allows legitimate users to complete verification quickly while preventing fraudulent transactions.
Solution Approach 2:
The system replaces traditional manual verification methods with contactless card authentication and biometric verification. These automated verification methods are processed rapidly by the mobile device and server, reducing the time required for enhanced authentication compared to manual identity verification or multiple password confirmations.
3Measurement precision
If contactless card authentication is implemented, then user identification accuracy is improved, but device complexity increases
Solution Approach 1:
The mobile device serves as an intermediary that manages the contactless card authentication process. The mobile device contains the short-range communication antenna for receiving cryptograms from the contactless card and the processor for verifying authentication. This distributes the complexity across multiple components rather than requiring a single complex system, making the overall solution more manageable and scalable.
Solution Approach 2:
The system replaces physical card insertion or manual data entry with contactless card authentication using short-range communication. The contactless card transmits a cryptogram that is rapidly verified by the mobile device processor, providing accurate user identification through automated cryptographic verification rather than manual processes.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enhances security for digital transactions by ensuring that only authorized users can execute high-risk or suspicious transactions, thereby reducing the risk of fraud.
Implementation Method 1
receiving, by a short-range communication antenna of the mobile device, a cryptogram from the contactless card
Data Source
AI summary
Systems and methods disclosed herein can determine when a digital transaction initiated in connection with a user account satisfies at least one predetermined risk factor. Responsive thereto, systems and methods disclosed herein can increase security to verify that the digital transaction is likely being initiated by an authorized user of the user account prior to executing the digital transaction in connection with the user account. To do so, a mobile device can communicate with a contactless card to receive a cryptogram therefrom, verify the cryptogram to identify the user account and to confirm that the contactless card is associated with the user account, and verify that a phone number of the mobile device is also associated with the user account.


