Discretionary Data Field Authentication for Payment Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional digital wallet systems lack the ability to securely utilize discretionary data fields for transaction authentication, which can lead to increased fraud risks and inadequate security measures during transactions.
Innovation Solution
A computer-implemented method that employs a server to associate a payment account with a user computing device, generating an authentication challenge and response, and uses a discretionary data field to secure transactions by comparing the user-provided challenge response with the expected response, determining the authorization state for transaction approval.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional digital wallet systems use basic password authentication, then ease of operation is maintained, but transaction security is insufficient and fraud risks increase
Solution Approach 1:
The system performs preliminary authentication actions by generating and verifying challenge responses before the actual transaction is processed. The payment gateway generates a challenge, the payment application computes the response in advance using cryptographic algorithms, and this authentication is completed before funds are transferred, ensuring security without complicating the user experience
Solution Approach 2:
The patent introduces discretionary data fields as an intermediary mechanism between the user device and payment gateway. These fields carry challenge-response authentication data without requiring the user to directly interact with complex security protocols, thus maintaining ease of operation while enhancing security through automated cryptographic verification
2Reliability
If discretionary data fields are utilized for challenge-response authentication, then fraud prevention is enhanced, but device complexity increases
Solution Approach 1:
The discretionary data fields, originally designed for general-purpose data transmission in payment transactions, are made multi-functional by also carrying challenge-response authentication data. This allows the same infrastructure to serve both transaction information and security verification purposes, enhancing fraud prevention without adding separate complex authentication systems
Solution Approach 2:
The payment application on the user device automatically generates cryptographic challenge responses using stored cryptographic material without requiring user intervention or additional security hardware. The system serves its own authentication needs through automated cryptographic operations, reducing the complexity burden on users while maintaining strong security
Data Source
AI summary
Using discretionary data fields to secure transactions comprises a payment system employing a server configured to associate a payment account of a user with a user computing device, the payment account comprising a payment account identifier that identifies the payment account, and establish a authentication challenge and an corresponding challenge response. The payment system receives a first payment authorization request originating from a merchant computing system comprising the payment account identifier, data associated with the payment account identifier, and a request to fund a transaction using the payment account, wherein the data associated with the payment account identifier comprises a challenge response provided by the user computing device located in a discretionary data field. The payment system compares the provided challenge response with the corresponding challenge response, and approves the transaction based on whether the provided challenge response and the corresponding challenge response match.


