Contactless Card Preauthorization for Fraud Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional contactless card systems lack adequate security mechanisms to ensure that physical cards and virtual card numbers are used in accordance with defined restrictions, exposing them to security risks.
Innovation Solution
Implementing a system where contactless cards communicate with mobile devices and servers to enforce geographic, amount, and time restrictions through cryptographic algorithms and preauthorization processes, ensuring transactions are authorized only within permitted parameters.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If contactless cards are shared with trusted individuals, then accessibility and ease of use are improved, but security risks increase
Solution Approach 1:
The system segments card functionality by creating separate virtual card numbers for different users (cardholders and trusted individuals). Each user has their own virtual card number that can be independently managed and restricted, allowing safe sharing while maintaining security through isolation of financial data.
Solution Approach 2:
The system introduces a server as an intermediary between the physical contactless card and the payment processing system. This server validates transactions by checking location data, amount restrictions, and time constraints before authorizing payments, adding a security layer that mediates between accessibility and security requirements.
2Object-affected harmful factors
If geographic restrictions are enforced, then security is improved, but transaction processing complexity increases
Solution Approach 1:
The system performs preliminary action by pre-authorizing transactions before they occur. The server checks location data, amount restrictions, and time constraints in advance and issues preauthorization codes that are stored on the contactless card. This advance validation simplifies the actual transaction processing at the point of sale, as the card only needs to present the preauthorization code.
Solution Approach 2:
The system implements feedback mechanisms where the server continuously monitors transaction parameters (location, amount, time) and provides feedback in the form of preauthorization codes. This feedback loop allows the system to enforce security restrictions while maintaining simple transaction processing, as the feedback code guides the entire transaction flow.
3Reliability
If multiple validation checks are performed, then reliability is improved, but processing time increases
Solution Approach 1:
The system performs all necessary validation checks (location, amount, time constraints) in advance before the actual transaction occurs. The server issues preauthorization codes after validating all parameters, and these codes are stored on the contactless card. During transaction processing, the system only needs to verify the preauthorization code, dramatically reducing processing time while maintaining high reliability.
Solution Approach 2:
The preauthorization code creates a continuous validation state that persists from the time of preauthorization through the actual transaction. This continuous validation mechanism ensures that all security checks remain effective without requiring repeated validation at each step, maintaining both reliability and efficiency throughout the transaction process.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enhances security by reducing fraud and ensuring authorized use, thereby preserving the security of associated accounts and devices.
Implementation Method 1
verification of encrypted data, the encrypted data generated by the contactless card using a cryptographic algorithm and a private key stored in the memory of the contactless card
Data Source
AI summary
Systems, methods, articles of manufacture, and computer-readable media. A communications interface may receive an indication that a server preauthorized a transaction. The communications interface may receive, from a point of sale device, an indication to pay for the transaction. The contactless card may determine, based on rules stored in the memory, that the location of the mobile device is within one or more locations the contactless card is permitted for use. The contactless card may generate transaction data comprising: indications of an account number and an expiration date of the contactless card, and the indication of the preauthorization. The contactless card may transmit the transaction data to the POS device as payment for the transaction. The server may authorize payment for the transaction using at least a portion of the transaction data based at least in part on identifying the indication of the preauthorization in the transaction data.


