Dynamic Challenge Question Authentication for Payment Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current customer authentication methods at point-of-sale (POS) devices are inadequate in preventing fraudulent transactions, as they rely on static information that can be compromised by thieves, leading to potential misuse of portable customer devices.

Innovation Solution

Implementing a dynamic customer authentication process where a payment processing service generates challenge questions based on the customer's transaction history and behavior, which are presented to the customer through the POS device, ensuring authentication is more secure and tailored to the specific transaction context.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static authentication methods (zip code, personally identifiable information) are used, then the authentication process is simple and easy to operate, but the security against fraudulent transactions is insufficient

Engineering Contradiction:
Improvesecurity against fraudulent transactionsVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms static authentication questions into dynamic ones that change based on transaction context. The system selects different authentication questions from a pool based on transaction amount, merchant type, customer history, and risk factors, making the authentication process adaptive rather than fixed. This resolves the contradiction by maintaining simplicity for low-risk transactions while enhancing security for high-risk ones.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameters of authentication questions based on transaction characteristics. Questions are selected and customized according to transaction amount thresholds, merchant category codes, customer risk profiles, and device location data. This parameter-based adaptation allows the system to scale security measures to match actual risk levels, avoiding unnecessary complexity for routine transactions.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If dynamic challenge questions based on transaction history are implemented, then the security against fraudulent transactions is significantly improved, but the processing time and system complexity increase

Engineering Contradiction:
Improveauthentication accuracyVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-selecting and caching authentication questions based on transaction characteristics before the actual authentication occurs. Transaction risk profiles are pre-calculated using historical data, and appropriate authentication questions are prepared in advance, reducing real-time processing requirements and minimizing customer wait time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses feedback from transaction outcomes to continuously refine authentication question selection. Successful and fraudulent transactions provide learning data that improves the algorithm's ability to select appropriate questions, making the system progressively more efficient at identifying high-risk transactions that require enhanced authentication while allowing low-risk transactions to proceed quickly.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10755281B1Payment transaction authentication system and method
Publication Date: 2020.08.25 BLOCK INC
  • US10755281B1 patent drawing
  • US10755281B1 patent drawing
  • US10755281B1 patent drawing

AI summary

This disclosure describes, in part, techniques for validating a payment transaction between a customer and a merchant via challenge questions. For instance, the method includes determining, by a payment processing system, a level of risk associated with a current payment transaction between the merchant and the customer; in response the level of risk being higher than a threshold, obtaining a query for the customer, wherein the query is based at least on the current payment transaction or one or more past transactions involving the customer; receiving, from a customer device associated with the customer, a response to the query; and validating the current payment transaction based on the response.