Contactless Card Preauthorization for Fraud Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional contactless card systems lack adequate security mechanisms to ensure that physical cards and virtual card numbers are used in accordance with defined restrictions, exposing them to security risks.

Innovation Solution

Implementing a system where contactless cards communicate with mobile devices and servers to enforce geographic, amount, and time restrictions through cryptographic algorithms and preauthorization processes, ensuring transactions are authorized only within permitted parameters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If contactless cards are shared with trusted individuals, then accessibility and ease of use are improved, but security risks increase

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments card functionality by creating separate virtual card numbers for different users (cardholders and trusted individuals). Each user has their own virtual card number that can be independently managed and restricted, allowing safe sharing while maintaining security through isolation of financial data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces a server as an intermediary between the physical contactless card and the payment processing system. This server validates transactions by checking location data, amount restrictions, and time constraints before authorizing payments, adding a security layer that mediates between accessibility and security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If geographic restrictions are enforced, then security is improved, but transaction processing complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidtransaction processing complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system performs preliminary action by pre-authorizing transactions before they occur. The server checks location data, amount restrictions, and time constraints in advance and issues preauthorization codes that are stored on the contactless card. This advance validation simplifies the actual transaction processing at the point of sale, as the card only needs to present the preauthorization code.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the server continuously monitors transaction parameters (location, amount, time) and provides feedback in the form of preauthorization codes. This feedback loop allows the system to enforce security restrictions while maintaining simple transaction processing, as the feedback code guides the entire transaction flow.

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple validation checks are performed, then reliability is improved, but processing time increases

Engineering Contradiction:
Improvetransaction authorization reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs all necessary validation checks (location, amount, time constraints) in advance before the actual transaction occurs. The server issues preauthorization codes after validating all parameters, and these codes are stored on the contactless card. During transaction processing, the system only needs to verify the preauthorization code, dramatically reducing processing time while maintaining high reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The preauthorization code creates a continuous validation state that persists from the time of preauthorization through the actual transaction. This continuous validation mechanism ensures that all security checks remain effective without requiring repeated validation at each step, maintaining both reliability and efficiency throughout the transaction process.

Inventive Principle:
Principle #20Continuity of useful action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enhances security by reducing fraud and ensuring authorized use, thereby preserving the security of associated accounts and devices.

Implementation Method 1

verification of encrypted data, the encrypted data generated by the contactless card using a cryptographic algorithm and a private key stored in the memory of the contactless card

Methodology Applied
Scientific EffectCryptographic algorithm:

Data Source

PatentUS11694187B2Constraining transactional capabilities for contactless cards
Publication Date: 2023.07.04 CAPITAL ONE SERVICES LLC
  • US11694187B2 patent drawing
  • US11694187B2 patent drawing
  • US11694187B2 patent drawing

AI summary

Systems, methods, articles of manufacture, and computer-readable media. A communications interface may receive an indication that a server preauthorized a transaction. The communications interface may receive, from a point of sale device, an indication to pay for the transaction. The contactless card may determine, based on rules stored in the memory, that the location of the mobile device is within one or more locations the contactless card is permitted for use. The contactless card may generate transaction data comprising: indications of an account number and an expiration date of the contactless card, and the indication of the preauthorization. The contactless card may transmit the transaction data to the POS device as payment for the transaction. The server may authorize payment for the transaction using at least a portion of the transaction data based at least in part on identifying the indication of the preauthorization in the transaction data.