Contactless Payment Authorization via Server-Side Verification Status
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing payment transaction methods, particularly contactless transactions, lack sufficient security and convenience as they often require user verification for higher-value transactions, imposing limitations on transaction values or requiring alternative methods like 'Chip & PIN', which reduces the convenience of contactless payments.
Innovation Solution
A method and system that authorize payment transactions based on a user's verification status stored in a server system, allowing contactless payments without immediate user verification by determining authorization based on pre-set conditions such as time, transaction number, or value thresholds, ensuring security even when the payment device lacks input means.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If contactless payment transactions are allowed without user verification, then convenience and transaction speed are improved, but security and fraud prevention deteriorate
Solution Approach 1:
The system performs user verification in advance of the contactless transaction by sending verification codes to the user's device and requiring confirmation. This preliminary verification establishes user authorization before the actual payment occurs, allowing contactless transactions to proceed without real-time verification while maintaining security through pre-authorized status tracking.
Solution Approach 2:
The system introduces an intermediary verification mechanism that acts as a mediator between the user and the contactless payment device. Verification codes sent to the user's device serve as an intermediary layer that confirms user intent without requiring direct interaction with the payment terminal during the actual transaction, thus maintaining both convenience and security.
2Reliability
If transaction value limits are imposed on contactless payments, then security is improved, but convenience and user flexibility deteriorate
Solution Approach 1:
The system dynamically adjusts verification requirements based on transaction characteristics such as value, frequency, and user behavior patterns. Rather than imposing fixed value limits, the system adapts its verification intensity to match the risk level of each transaction, allowing high-value transactions to require verification while enabling frictionless low-value transactions, thus providing both security and flexibility.
Solution Approach 2:
The system changes verification parameters (such as requiring verification code confirmation) based on transaction parameters like value thresholds and transaction count. This allows the system to maintain security for high-risk transactions while preserving convenience for low-risk transactions, effectively replacing static value limits with dynamic parameter-based verification decisions.
3Reliability
If verification processes are required for each transaction, then security is improved, but transaction speed and convenience deteriorate
Solution Approach 1:
The system performs verification in advance by sending confirmation codes to the user's device before the contactless transaction occurs. Once verified, the user's device stores verification status that can be rapidly checked during subsequent transactions. This separates the time-consuming verification step from the actual payment execution, maintaining security while enabling fast contactless transactions.
Solution Approach 2:
The system maintains continuous verification status between transactions by storing verified state information on the user's device. Once a user is verified, this status persists across multiple transactions, eliminating the need to repeat the full verification process for each transaction. This continuous verification state enables rapid successive transactions while maintaining security oversight.
Data Source
AI summary
Methods, apparatus and computer programs for authorizing transactions are described. A server system receives, from a first computing device, verification information relating to a verification process for verifying a user associated with the first computing device. A verification status associated with the user is set in a memory of the server system, based on the verification information. The server system receives an authorization request for a payment transaction from a payment terminal, the request including an identifier associated with the user, and having been provided to the payment terminal by a payment device different from the first computing device. Responsive to receipt of the authorization request, the verification status associated with the user is identified, and a determination as to whether to authorize the payment transaction is made at least partly on the basis of the identified verification status.


