Dynamic Security Code Assembly for EMV Fraud Adaptation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

EMV smart cards and electronic devices face evolving security threats, with existing security mechanisms failing to adapt effectively to new fraud schemes and lacking flexibility in security check operations during transactions.

Innovation Solution

A method that allows for personalized security behavior by forming a code from prerecorded instructions to configure and execute dynamic security checks, enabling adaptation of security check operations and parameters in response to new threats, without compromising certification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If fixed security mechanisms are used in EMV smart cards, then certification is maintained, but the ability to adapt to new fraud schemes is lost

Engineering Contradiction:
Improveadaptability to new fraud schemesVSAvoidsecurity certification
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The security check is divided into multiple independent operations that can be selectively executed. Each operation corresponds to a specific security check type (e.g., verifying transaction amount, verifying merchant category code), and the system can dynamically select which operations to perform based on detected fraud patterns without changing the overall certified security framework.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts security check operations by modifying the set of instructions to be executed during a transaction based on detected fraud patterns. The terminal or card can add, remove, or modify security operations in real-time, allowing adaptation to new threats while maintaining the underlying certified security architecture.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If security check operations are fixed, then certification is maintained, but flexibility in security parameters is reduced

Engineering Contradiction:
Improveflexibility in security parametersVSAvoidsecurity check structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system changes parameters of existing security operations (such as thresholds, validation rules, or check criteria) based on detected fraud patterns. For example, it can adjust the transaction amount threshold or modify the strictness of merchant category code verification without changing the fundamental security check structure, thereby adapting to new threats while maintaining certification.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If dynamic security adaptation is implemented, then response to new threats improves, but system complexity increases

Engineering Contradiction:
Improvethreat response capabilityVSAvoidsecurity configuration
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system pre-configures multiple security check operations and stores them in a database or memory. When a fraud pattern is detected, the system quickly assembles the appropriate pre-prepared operations rather than creating them on-the-fly. This reduces the computational complexity and processing time required for dynamic adaptation while maintaining the ability to respond to new threats.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11200571B2Method of controlling an electronic device and corresponding electronic device
Publication Date: 2021.12.14 IDEMIA FRANCE SAS
  • US11200571B2 patent drawing
  • US11200571B2 patent drawing
  • US11200571B2 patent drawing

AI summary

Method of controlling an electronic device and corresponding electronic device. The method may be performed by an electronic device (20) and includes steps such as receiving an instruction command (CMD) that includes identifiers (ID) of instructions (IS) that are prerecorded in a memory (30) of the electronic device; using the identifiers to form a code (RC) defining a set of instructions, where the set of instructions combines prerecorded instructions (IS) to execute a security check; and storing the code (RC) in a memory (28) of the electronic device in order to configure the electronic device (20) to execute the security check.