Contactless Payment Card Provisioning via NFC Tokenization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing provisioning processes for wallet applications are vulnerable to fraud and do not adequately verify that the user possesses the physical payment card, failing to meet regulatory requirements for a possession factor in payment card transactions.
Innovation Solution
A contactless provisioning process that securely transmits payment card information from a physical payment card to a mobile device using near-field communication, eliminating manual data entry and ensuring the cardholder's possession through tokenization and cardholder verification, while adhering to regulatory requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual entry or image capture methods are used for provisioning, then the provisioning process can be completed, but the system becomes vulnerable to fraud and cannot verify physical card possession
Solution Approach 1:
The patent introduces an intermediary verification process where the system communicates with the payment card issuer to validate whether the card is in its active state and can be provisioned. This intermediary check acts as a mediator between the user's claim of card possession and the system's acceptance, preventing fraud while maintaining a user-friendly process. The issuer's confirmation serves as trusted third-party verification that the card is genuine and active.
Solution Approach 2:
The system implements feedback mechanisms where the issuer is notified of the provisioning attempt and can respond with approval or rejection based on their policies. This feedback loop ensures that only legitimate card provisioning requests are fulfilled, adding a layer of security without requiring complex user verification steps. The feedback from the issuer about card status and provisioning eligibility enables fraud prevention while keeping the process simple for users.
2Reliability
If traditional provisioning methods are used, then the process is simple, but regulatory requirements for possession factor verification are not met
Solution Approach 1:
The system enables self-service provisioning where the user can add their card to the digital wallet through a simple process, while the backend automatically handles the complex verification with the issuer. The user experiences a simple, card-present process, while the system autonomously manages the regulatory compliance requirements by communicating with the issuer to verify card status and obtain provisioning authorization. This self-service approach meets possession verification requirements without adding complexity to the user-facing process.
Solution Approach 2:
The issuer acts as an intermediary that handles the complex verification logic on behalf of the wallet system. Rather than implementing complex possession verification mechanisms directly, the wallet system leverages the issuer's authority and existing card validation capabilities. The issuer's response to provisioning requests provides the necessary possession factor verification in a way that is transparent to the user and does not complicate the wallet system's architecture.
3Reliability
If contactless transmission is implemented, then security is enhanced through tokenization, but the provisioning process becomes more complex
Solution Approach 1:
The system performs preliminary actions by establishing security tokens and encryption protocols before the actual provisioning transaction occurs. The tokenization framework is pre-configured, and security parameters are set in advance, allowing the contactless provisioning to proceed smoothly without requiring complex real-time security negotiations. This preliminary setup enhances security while keeping the user-facing process simple, as the complexity is handled beforehand in the backend.
Solution Approach 2:
The system creates a tokenized copy of the payment card information that can be transmitted securely through contactless communication. Instead of transmitting actual card data, a virtual representation (token) is used that maintains security while enabling the provisioning function. This copying approach enhances security by preventing exposure of sensitive card information, while the tokenization process is managed automatically by the system without requiring user involvement in the complexity of security protocols.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach enhances security and fraud prevention by ensuring the cardholder's possession of the payment card, simplifies the provisioning flow, and complies with regulatory standards, providing a more secure and user-friendly experience for cardholders and issuers.
Implementation Method 1
A mobile device may receive payment card information from a payment card using contactless communication
Data Source
AI summary
Systems, methods, and computer program code are provided to contactlessly provision payment card information into a mobile wallet application of a mobile device are provided.


