Dynamic Risk-Based Payment Token Verification System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Remote payment transactions, such as those over the internet, are at a higher risk of fraud due to the inability of merchants to verify the identity of the token holder, and existing solutions like SECURECODE require registration and additional verification steps that may not be justified for all transactions.
Innovation Solution
A system that performs a risk analysis based on transaction data and requires the use of a secure payment token if the risk level is deemed unacceptable, allowing either the merchant or customer to conduct transactions securely using a smart card or dynamic data tokens.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a static PIN or password verification system is used for all online transactions, then fraud risk is reduced, but transaction complexity and customer burden increase
Solution Approach 1:
The patent implements dynamic verification by transitioning from static PIN/password systems to a dynamic verification value system where the authentication requirement changes based on real-time risk assessment of each transaction, allowing the system to adapt security measures to actual risk levels rather than applying uniform verification
Solution Approach 2:
The system changes the verification parameter from always requiring static credentials to conditionally requiring dynamic verification values based on risk factors such as transaction amount, location, and customer history, thereby adjusting security intensity to match actual risk levels
2Reliability
If mandatory registration with SECURECODE is required for all cardholders, then authentication security is improved, but device complexity and enrollment burden increase
Solution Approach 1:
The patent segments cardholders into different groups based on risk profiles and transaction patterns, applying different verification requirements to different segments rather than uniformly requiring all cardholders to register with SECURECODE, thereby reducing overall system complexity while maintaining security for high-risk cases
Solution Approach 2:
The system introduces an intermediary risk assessment mechanism that determines whether dynamic verification is needed, acting as a mediator between static card data and full SECURECODE authentication, allowing most transactions to proceed without mandatory registration while still providing security when needed
3Reliability
If dynamic verification values are used for high-risk transactions, then fraud detection capability is improved, but transaction processing time increases
Solution Approach 1:
The system performs preliminary risk assessment using pre-collected customer data and transaction context before determining whether dynamic verification is needed, allowing low-risk transactions to proceed quickly without verification while pre-identifying high-risk cases that require additional authentication
Solution Approach 2:
The system uses feedback from risk assessment results to dynamically adjust verification requirements, providing immediate feedback on whether a transaction requires enhanced authentication, thereby minimizing processing time for most transactions while maintaining strong fraud detection for suspicious cases
Data Source
AI summary
Example embodiments of the presently described subject matter are described that require a customer to use a secure payment token if, during a payment transaction, it is determined that the payment transaction poses a risk. A risk analysis may be performed based at least in part on data related to the payment transaction, such as data related to the customer, the transaction itself, the merchant, etc. If the results of the risk analysis indicate that an unacceptable amount of risk exists, the merchant or any interested party may require the customer to use a secure payment token, for example, a smart card, to conduct the transaction. Otherwise, the customer may proceed by using a static payment token, for example a credit card or PIN/password-based payment token.


