Contactless Payment Card Security at Unattended Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Contactless payment cards are vulnerable to misuse and unauthorized transactions at unattended terminal devices with near field communication capabilities, as these devices can initiate transactions without the cardholder's consent by being brought within NFC range.

Innovation Solution

A system that includes a cloud POS server receiving unique identifiers from a communication device and a contactless payment card, implementing either a first or second payment authorization communication flow based on whether the identifier combination has been previously recorded, with the second flow requiring additional authentication if not recorded, to ensure authorized transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If contactless payment cards are used at unattended terminal devices with NFC capabilities, then payment convenience and transaction speed are improved, but vulnerability to misuse and unauthorized transactions increases

Engineering Contradiction:
Improvepayment convenienceVSAvoidunauthorized transactions
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by recording the combination of payment card identifier and communication device identifier before the actual payment transaction. This pre-registration of device-card pairs ensures that only authorized combinations can complete transactions, preventing unauthorized use while maintaining contactless convenience

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by checking whether the combination of payment card identifier and communication device identifier has been previously recorded. Based on this feedback, the system either permits the transaction (if recorded) or blocks it (if not recorded), creating a closed-loop security mechanism that maintains both convenience and security

Inventive Principle:
Principle #23Feedback

2Reliability

If authentication is required for contactless payment transactions, then transaction security is improved, but transaction processing time increases

Engineering Contradiction:
Improvetransaction securityVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication is performed in advance during the setup phase where the communication device identifier and payment card identifier are recorded together. This preliminary authentication eliminates the need for time-consuming verification during actual transactions, as the system only needs to check whether the pre-recorded combination matches

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies partial authentication by only verifying the combination of device identifier and card identifier, rather than requiring full user verification for every transaction. This partial check is sufficient for security purposes while being rapid enough to maintain transaction speed

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240054498A1Systems, Methods and Computer Program Products for Contactless Payment Card Security at Unattended Type Terminals
Publication Date: 2024.02.15 MASTERCARD INT INC
  • US20240054498A1 patent drawing
  • US20240054498A1 patent drawing
  • US20240054498A1 patent drawing

AI summary

The invention secures contactless payment cards against misuse at ‘unattended type’ terminal devices having near field communication capabilities. The invention involves receiving from a communication device a first unique identifier associated with a contactless payment card, and a second unique identifier associated with the communication device. Transmission of the first unique identifier and the second unique identifier from the communication device is implemented in response to the communication device detecting a contactless card tap event, and the communication device retrieving the first unique identifier from the contactless payment card. The invention involves selectively implementing one of a first payment authorization communication flow and a second payment authorization communication flow. The selective implementation is based on whether the first and second unique identifiers have been recorded within a database that stores combinations of payment card identifiers and communication device identifiers for payment transactions that have been previously successfully authorized.