Contactless Payment Card Authentication via Issuer Token Disassembly

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing payment systems require a physical connection between the card and the issuer to reset risk management parameters and reload value, limiting convenience and security.

Innovation Solution

A method using an extended cardholder authentication process to send an authentication code from the issuer to the card, allowing the card to verify the issuer's authenticity and enable data parameter resets and value reloads without a physical connection, utilizing a personal card reader for contact or contactless communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a physical connection between card and issuer is required for resetting risk management parameters and reloading value, then security is maintained, but convenience and ease of operation are reduced

Engineering Contradiction:
Improveconvenience of parameter reset and value reloadVSAvoidsecurity of authentication process
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary authentication code mechanism that enables secure communication between the card and issuer without requiring direct physical connection. The authentication code acts as a mediator that verifies the card's authenticity and authorizes remote operations, resolving the contradiction between convenience and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical physical connection requirement with a cryptographic authentication system. Instead of requiring physical contact for security verification, the system uses cryptographic codes and algorithms to authenticate the card and authorize remote parameter resets and value reloads, thereby improving convenience while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If two-way authentication is implemented to verify issuer authenticity, then security is improved, but device complexity and processing requirements increase

Engineering Contradiction:
Improvesecurity through authenticationVSAvoidcomplexity of authentication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary authentication actions during the initial cardholder authentication process. The session key and authentication mechanisms are established in advance, enabling subsequent remote authentication operations without requiring complex real-time verification processes, thus reducing overall system complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication code mechanism serves multiple functions: it verifies card authenticity, authorizes remote operations, and maintains security throughout the communication process. This multi-functionality reduces the need for separate authentication mechanisms, thereby simplifying the overall system architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8746553B2Payment device updates using an authentication process
Publication Date: 2014.06.10 MASTERCARD INT INC
  • US8746553B2 patent drawing
  • US8746553B2 patent drawing
  • US8746553B2 patent drawing

AI summary

A payment device—payment device reader combination obtains issuer token data that was generated by an issuer entity from: input data, and an issuer application cryptogram based on the input data and a session key. The issuer token data is disassembled by the payment device—payment device reader combination to obtain the input data and the issuer application cryptogram, and the payment device—payment device reader combination computes a payment device application cryptogram based on the input data and the session key. This is compared, by the payment device—payment device reader combination, to the issuer application cryptogram. If the payment device application cryptogram matches the issuer application cryptogram, at least one action is allowed to take place on the payment device.