E-Commerce Payment Authentication Using Token and Cryptogram Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication and validation techniques for payment account transactions are primarily designed for card-present transactions and are not effectively utilized for e-commerce transactions, which are more commonly card-not-present, leading to vulnerabilities in preventing fraudulent and unauthorized transactions.
Innovation Solution
A system and method that incorporates a directory server, digital service server, access control server, and other entities to generate and validate authentication values for e-commerce transactions, using tokenization and cryptograms to enhance security, including a process that involves generating a DSRP cryptogram, mapping tokens to primary account numbers, and creating a full accountholder authentication value (AAV) for transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If EMV technology and 3-D Secure protocol are used for card-present transactions, then authentication security is improved, but these techniques are not effectively applicable to card-not-present e-commerce transactions, leaving them vulnerable to fraud
Solution Approach 1:
The patent introduces an intermediary authentication system that bridges card-present and card-not-present transaction environments. The system uses tokenization to create digital representations of card data that can be securely transmitted online, and employs challenge-response authentication mechanisms that adapt EMV-style security to e-commerce contexts where the physical card is not present.
Solution Approach 2:
The patent creates a cryptographic copy or token of the actual card data that can be used in place of the physical card in online transactions. This token contains authenticated information that replicates the security functions of EMV authentication without requiring the physical card to be present, thereby adapting card-present security techniques to card-not-present environments.
2Reliability
If tokenization and cryptogram validation are implemented for e-commerce transactions, then fraud prevention is improved, but system complexity increases due to multiple servers and validation steps
Solution Approach 1:
The patent combines multiple authentication functions into an integrated system where tokenization, cryptogram generation, and validation occur within a unified architecture. The directory server, digital service server, and access control server work as coordinated components of a single authentication ecosystem, reducing operational complexity despite the multiple elements involved.
Solution Approach 2:
The patent performs authentication and tokenization actions in advance of the actual transaction. The directory server pre-validates card data and generates tokens before the e-commerce transaction occurs, and the access control server pre-establishes authentication credentials. This preliminary authentication reduces the complexity during the actual transaction processing.
Data Source
AI summary
Systems and methods are provided for authenticating users. An exemplary method includes receiving, by a directory server (DS), an authentication request for a transaction to an account where the request includes a token and a cryptogram, and transmitting the token and cryptogram to a digital service server (DSS). The method also includes mapping, by the DSS, the token to an account number for the account, validating the cryptogram, generating a directory server nonce (DSN) for the request, and transmitting the DSN and the account number to the DS. The method further includes transmitting, by the DS, the DSN and the account number to an access control server (ACS) associated with an issuer of the account and, in response to an issuer authentication value (IAV), compiling an accountholder authentication value (AAV) including the IAV, the DSN and an amount of the transaction and transmitting the AAV to a merchant or server.


