Customer-Defined Limited Use Authorization Tokens for Fraud Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current payment systems face challenges in providing real-time fraud detection and control during transactions, as they rely on reusable Primary Account Numbers (PANs), leading to increased costs and delayed fraud reporting, and existing tokens offer limited sophistication and control in spending and reconciliation.
Innovation Solution
A system that generates customer-defined limited use authorization tokens, allowing for multiple tokens per parent PAN, with customizable authorization controls such as date ranges, geographical limitations, and transaction amounts, which are managed within the issuer's network to enhance fraud control and reconciliation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If reusable Primary Account Numbers (PANs) are used for transactions, then transaction processing is simple and fast, but fraud risk increases and security control is insufficient
Solution Approach 1:
The patent segments the reusable PAN into multiple single-use tokens. Each token is generated from a parent PAN and can be used only once for a specific transaction. This segmentation maintains the speed of token-based processing while eliminating the fraud risk associated with reusable PANs, as each token is unique and cannot be reused for fraudulent transactions.
Solution Approach 2:
The patent introduces tokens as an intermediary between the customer's PAN and the transaction system. The token acts as a mediator that provides both security (unique, single-use) and efficiency (fast processing). The token includes embedded transaction details and authentication data, allowing the system to process transactions quickly without directly handling the reusable PAN, thus maintaining productivity while improving fraud detection.
2Reliability
If existing tokens are used for transactions, then some security is provided, but control and sophistication for spending and reconciliation is limited
Solution Approach 1:
The patent makes the token dynamic by embedding multiple types of controls directly into the token structure. The token can include date range restrictions, time window limitations, geographical restrictions, merchant category codes, and transaction amount limits. This dynamic approach allows the token to adapt to different spending scenarios and provides sophisticated control over when and where the token can be used, greatly enhancing both fraud control and spending flexibility.
Solution Approach 2:
The patent applies local quality by customizing specific attributes of each token based on the individual transaction requirements. Instead of a one-size-fits-all token, each token can have specific controls tailored to the intended use (e.g., a travel token with geographical restrictions, a gift card token with amount limits). This allows different parts of the system to have different levels of control and sophistication according to their specific needs.
3Reliability
If multiple safeguards are added to detect and report fraud, then fraud detection improves, but system cost and infrastructure complexity increase
Solution Approach 1:
The patent performs preliminary action by embedding fraud prevention controls directly into the token generation process. Before a transaction occurs, the system pre-configures the token with authentication data, usage limits, and control parameters. This preliminary setup eliminates the need for complex real-time fraud detection systems, as the security measures are already built into the token itself, reducing both system cost and infrastructure complexity while maintaining high fraud detection accuracy.
4Speed
If real-time fraud detection is implemented, then fraud detection speed improves, but reporting delays still occur and infrastructure costs increase
Solution Approach 1:
The patent enables the token to perform self-service by including embedded authentication data and control parameters that automatically validate during transaction processing. The token itself carries the fraud prevention information, eliminating the need for separate real-time fraud detection systems and reporting mechanisms. This self-contained approach achieves instantaneous validation (improving speed) while eliminating reporting delays, as the authentication decision is made directly during the transaction without requiring separate detection and reporting steps.
Data Source
AI summary
The present disclosure presents systems and related methods for customer defined limited use authorization. One such method comprises implementing a customer defined generation control associated with a parent transaction account; receiving a request to generate the electronic payment token from at least one of an issuer web app or an issuer native app; verifying that the generation control condition has been satisfied; generating via a tokenization engine, the electronic payment token in response to the request to generate the electronic payment token, wherein generating the electronic payment token further comprises storing an expanded set of token controls comprising customer defined authorization control as token data; and transmitting, via the tokenization engine, the electronic payment token to the customer mobile device responsive to the generation control condition being verified as being satisfied.


