Enriched Authentication Messages for Authorization Bridge

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current consumer authentication systems in credit card transactions are isolated from authorization systems, limiting the information that can be shared between them, which can lead to false positives and negatives, and there is a lack of a suitable method to bridge this gap effectively.

Innovation Solution

A system and method for securely communicating enriched messages between authentication and authorization systems using existing protocols, employing Format Preserving Encryption (FPE) and Decryption (FPD) to create and decode a Pre-Authentication Transaction Number (Pre-ATN) and Special Encode Value (SEV), allowing additional data to be passed and used for enhanced decision-making during transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If authentication and authorization systems communicate only via predefined messages, then system compatibility and ease of operation are maintained, but information sharing is limited leading to false positives and negatives

Engineering Contradiction:
Improveinformation sharing between authentication and authorizationVSAvoidcommunication protocol compatibility
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent embeds additional authentication information within the structure of existing predefined authentication messages. The enriched message contains both the original authentication data and supplementary risk-based authentication results, allowing information nesting within the conventional message framework without breaking protocol compatibility

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent modifies message parameters by adding new data fields to the authentication message structure. These parameter changes include incorporating risk scores, authentication method details, and device information while maintaining the core message format to ensure backward compatibility with existing authorization systems

Inventive Principle:
Principle #35Parameter changes

2Reliability

If risk-based authentication is used with additional information, then authorization decision accuracy is improved, but the complexity of the communication protocol increases

Engineering Contradiction:
Improveauthorization decision accuracyVSAvoidcommunication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs risk-based authentication and information enrichment during the authentication phase before the authorization decision is made. This preliminary action prepares enriched authentication results that can be directly consumed by the authorization system, improving decision accuracy without adding complexity to the authorization protocol itself

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The enriched authentication message serves multiple functions: it provides the standard authentication result required by existing protocols, includes risk-based authentication outcomes for improved decision-making, and carries additional contextual information. This multi-functionality allows a single message structure to satisfy both compatibility requirements and enhanced authorization needs

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11741462B2Authentication to authorization bridge using enriched messages
Publication Date: 2023.08.29 CARDINALCOMMERCE CORP
  • US11741462B2 patent drawing
  • US11741462B2 patent drawing
  • US11741462B2 patent drawing

AI summary

A system of electronic communication is disclosed. The system may: create a Pre-Authentication Transaction Number (Pre-ATN) by combining a number with a Special Encode Value (SEV), wherein the SEV is a single digit integer value; encrypt the Pre-ATN using a Format Preserving Encryption (FPE) to generate an encrypted Authentication Transaction Number (ATN); and send the encrypted ATN to an access control server (ACS) to use the encrypted ATN to generate a cardholder Authentication Verification Value (CAVV) or an Accountholder Authentication Value (AAV).