Dynamic Authentication Token Generation for E-commerce Fraud Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for online transactions using credit or debit cards lack robustness, relying on static passwords or PINs, which are vulnerable to fraud and do not effectively verify the presence of both the card and cardholder at the point of interaction, especially in e-commerce environments.

Innovation Solution

The Chip Authentication Program (CAP) integrates EMV and 3-D Secure technologies to provide stronger authentication by using an Access Control Server and Authentication Request Server, generating a dynamic authentication token based on encrypted customer and transaction information, which is evaluated to ensure card and cardholder presence, eliminating the need for merchant-specific software downloads.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static passwords or PINs are used for authentication, then the authentication process is simple and easy to operate, but the security is weak and vulnerable to fraud

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent transforms static authentication credentials (passwords/PINs) into dynamic authentication tokens that change with each transaction. The EMV chip generates unique cryptograms based on transaction-specific data, making each authentication credential valid only for that specific transaction, thereby enhancing security while maintaining operational simplicity through automated token generation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication mechanism changes from using fixed parameters (static passwords) to variable parameters (dynamic cryptograms). The EMV chip modifies authentication credentials based on transaction data, timestamp, and other variable inputs, ensuring that each authentication attempt uses unique parameters that cannot be reused or predicted.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If EMV chip authentication is implemented, then security is enhanced by verifying card and cardholder presence, but the device complexity increases

Engineering Contradiction:
Improvefraud preventionVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The EMV chip acts as an intermediary authentication device between the cardholder and the remote server. It performs complex cryptographic operations locally within the chip, generating authentication tokens without requiring the merchant's system to handle complex security protocols, thereby distributing complexity to specialized components.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The EMV chip performs self-contained authentication operations including key generation, cryptogram creation, and transaction verification. The chip independently manages its own security credentials and performs cryptographic operations without requiring external assistance, reducing the burden on the overall system architecture.

Inventive Principle:
Principle #25Self-service

3Reliability

If traditional authentication methods are used, then compatibility with existing systems is maintained, but fraud risks increase

Engineering Contradiction:
Improvetransaction securityVSAvoidimplementation difficulty
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The EMV authentication system is designed to work across multiple platforms and transaction types. The same EMV chip and protocol can be used for in-person transactions, remote transactions, and various card types, providing a universal authentication mechanism that enhances security without requiring separate implementations for different scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9514458B2Customer authentication in E-commerce transactions
Publication Date: 2016.12.06 MASTERCARD INT INC
  • US9514458B2 patent drawing
  • US9514458B2 patent drawing
  • US9514458B2 patent drawing

AI summary

A Chip Authentication Program based on 3-D Secure protocols is provided for authenticating customers' on-line transactions. An issuer, who may be a payment card issuer, operates Access Control and Authentication Request Servers for authenticating transactions by individual customers who are identified by their personal EMV-complaint smart cards. An authentication token is generated at the point of interaction (POI) for each transaction based on information from the customer's smart card and transaction specific information sent directly by the issuer to populate a web page at the POI. Authentication tokens generated at the POI are evaluated by the Authentication Request Server to authenticate individual customer and/or card presence at the transaction POI. Authentication values are transported on-line in designated Universal Cardholder Authentication Fields consistent with 3-D Secure protocols.