Dual Cryptogram Transmission for Payment Terminal Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current payment systems using magnetic stripe authorizations for credit or debit applications face security limitations due to the embedding of only a subset of cryptogram bits, resulting in reduced security for card authentication.
Innovation Solution
The method involves transmitting and verifying two 2-byte cryptograms (CVC3 Track 1 and CVC3 Track 2) along with additional data, such as an unpredictable number and transaction counter, to enhance security, allowing the issuer to authenticate the card with a 4-byte MAC equivalent, thereby increasing the security level comparable to EMV chip-and-PIN transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If only a subset of cryptogram bits is embedded in magnetic stripe authorization, then compatibility with existing payment networks is maintained, but security level is reduced
Solution Approach 1:
The cryptogram is divided into multiple segments (first cryptogram and second cryptogram) that are transmitted separately through different channels (contactless and contact portions). This segmentation allows the system to maintain compatibility with existing single-cryptogram networks while actually transmitting more security data through the combination of multiple cryptogram segments.
Solution Approach 2:
The patent transitions from a single-dimension cryptogram transmission (one cryptogram through one channel) to a multi-dimensional approach by transmitting multiple cryptograms through different communication portions (contactless RF portion and contact magnetic stripe portion). This dimensional expansion increases security without sacrificing network compatibility.
2Reliability
If two cryptograms are transmitted instead of one, then security is enhanced, but message complexity increases
Solution Approach 1:
The terminal component is designed with multi-functionality to handle both single-cryptogram and dual-cryptogram transmission modes. It can operate with existing single-cryptogram networks while also supporting the enhanced security mode with multiple cryptograms, making the system universally compatible across different network configurations.
Solution Approach 2:
The terminal component acts as an intermediary that combines multiple cryptograms into a unified authentication message. It receives the first cryptogram from the contactless portion and the second cryptogram from the contact portion, then transmits them together through the payment network, simplifying the complexity management at the network level.
3Measurement precision
If multiple cryptograms are verified by the issuer, then authentication accuracy improves, but processing requirements increase
Solution Approach 1:
The terminal component performs preliminary combination and validation of multiple cryptograms before transmission to the issuer. It aggregates the first and second cryptograms into a unified message structure, reducing the processing burden on the issuer by pre-organizing the data in a format ready for verification.
Data Source
AI summary
At least a first cryptogram and a second cryptogram are transmitted from a payment device reader component to a terminal component. A message including at least the first cryptogram and the second cryptogram is transmitted from the terminal component to an issuer of a payment device presented to the reader component, through a payment network. A message is obtained from the issuer, corresponding to authentication, by the issuer, of the payment device (and optionally the owner of the payment device) presented to the reader component, based at least on the first cryptogram and the second cryptogram. The payment network is configured in accordance with at least one of (i) a standard, and (ii) a specification, which normally employs only a single cryptogram for the message and the authentication. Apparatuses and computer program products are also disclosed.


