Merchant-Issuer Dynamic Passcode Exchange for Frictionless Payment MFA

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-factor authentication (MFA) methods for electronic payments increase the number of steps and communications required for transactions, leading to friction and inefficiency.

Innovation Solution

A system and method for dynamic passcode communication between a merchant and issuer application on a user device, where the merchant application determines the presence of the issuer application, requests a dynamic passcode, and sends an authorization request with the passcode to the issuer system, reducing the number of steps and communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-factor authentication is implemented for electronic payments, then security is improved, but the number of steps and communications required increases

Engineering Contradiction:
ImprovesecurityVSAvoidnumber of steps and communications
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the authentication factors by having the issuer application generate a dynamic passcode that is automatically transmitted to the merchant application through a unified communication channel. This merging of passcode generation and transmission into a single integrated process reduces the number of separate steps and communications required while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The communication between the issuer application and merchant application serves as an intermediary mechanism that automatically handles the dynamic passcode exchange. This intermediary process eliminates the need for manual authentication steps and reduces direct communications between the user and multiple systems, thereby simplifying the overall authentication flow.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dynamic passcode is transmitted between applications on user device, then authentication security is improved, but application complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidapplication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The issuer application automatically generates and transmits the dynamic passcode without requiring user intervention. The system performs self-service authentication by having the issuer application directly communicate the passcode to the merchant application, thereby improving security while avoiding the complexity that would arise from manual user actions.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The dynamic passcode is generated in advance by the issuer application before the actual transaction authorization is needed. This preliminary generation of the authentication credential allows the system to have the security measure ready beforehand, simplifying the real-time authentication process and reducing the complexity of on-the-fly passcode generation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12393937B2System, method, and computer program product for dynamic passcode communication
Publication Date: 2025.08.19 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US12393937B2 patent drawing
  • US12393937B2 patent drawing
  • US12393937B2 patent drawing

AI summary

Systems, methods, and computer program products for dynamic passcode communication use a merchant application installed on a user device that receives transaction data associated with a transaction at a merchant system. The transaction data may include an account identifier associated with an account at an issuer system. The merchant application determines, based on the account identifier, whether an issuer application associated with the issuer system is installed on the user device. In response to determining that the issuer application is installed on the user device, the merchant application transmits, to the issuer application, a request for a dynamic passcode. The merchant application receives, from the issuer application, the dynamic passcode and transmits, to the issuer system, an authorization request including the account identifier and the dynamic passcode. The merchant application receives, from the issuer system, an authorization response authorizing or denying the transaction.