Dual Cryptogram Transmission for Payment Terminal Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current payment systems using magnetic stripe authorizations for credit or debit applications face security limitations due to the embedding of only a subset of cryptogram bits, resulting in reduced security for card authentication.

Innovation Solution

The method involves transmitting and verifying two 2-byte cryptograms (CVC3 Track 1 and CVC3 Track 2) along with additional data, such as an unpredictable number and transaction counter, to enhance security, allowing the issuer to authenticate the card with a 4-byte MAC equivalent, thereby increasing the security level comparable to EMV chip-and-PIN transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If only a subset of cryptogram bits is embedded in magnetic stripe authorization, then compatibility with existing payment networks is maintained, but security level is reduced

Engineering Contradiction:
Improvecompatibility with existing payment networksVSAvoidsecurity level
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The cryptogram is divided into multiple segments (first cryptogram and second cryptogram) that are transmitted separately through different channels (contactless and contact portions). This segmentation allows the system to maintain compatibility with existing single-cryptogram networks while actually transmitting more security data through the combination of multiple cryptogram segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single-dimension cryptogram transmission (one cryptogram through one channel) to a multi-dimensional approach by transmitting multiple cryptograms through different communication portions (contactless RF portion and contact magnetic stripe portion). This dimensional expansion increases security without sacrificing network compatibility.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If two cryptograms are transmitted instead of one, then security is enhanced, but message complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidmessage complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The terminal component is designed with multi-functionality to handle both single-cryptogram and dual-cryptogram transmission modes. It can operate with existing single-cryptogram networks while also supporting the enhanced security mode with multiple cryptograms, making the system universally compatible across different network configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The terminal component acts as an intermediary that combines multiple cryptograms into a unified authentication message. It receives the first cryptogram from the contactless portion and the second cryptogram from the contact portion, then transmits them together through the payment network, simplifying the complexity management at the network level.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If multiple cryptograms are verified by the issuer, then authentication accuracy improves, but processing requirements increase

Engineering Contradiction:
Improveauthentication accuracyVSAvoidprocessing requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The terminal component performs preliminary combination and validation of multiple cryptograms before transmission to the issuer. It aggregates the first and second cryptograms into a unified message structure, reducing the processing burden on the issuer by pre-organizing the data in a format ready for verification.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10217109B2Apparatus and method for combining cryptograms for card payments
Publication Date: 2019.02.26 MASTERCARD INT INC
  • US10217109B2 patent drawing
  • US10217109B2 patent drawing
  • US10217109B2 patent drawing

AI summary

At least a first cryptogram and a second cryptogram are transmitted from a payment device reader component to a terminal component. A message including at least the first cryptogram and the second cryptogram is transmitted from the terminal component to an issuer of a payment device presented to the reader component, through a payment network. A message is obtained from the issuer, corresponding to authentication, by the issuer, of the payment device (and optionally the owner of the payment device) presented to the reader component, based at least on the first cryptogram and the second cryptogram. The payment network is configured in accordance with at least one of (i) a standard, and (ii) a specification, which normally employs only a single cryptogram for the message and the authentication. Apparatuses and computer program products are also disclosed.