Mobile Device Verification for Secure Payment Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing payment transaction systems, especially in card-present environments, face challenges in ensuring security against fraud and counterfeiting, particularly since merchants do not typically verify portable consumer devices, which can lead to fraudulent transactions even when the payment device is stolen or copied.
Innovation Solution
The system employs a mobile device to interact with a portable consumer device and an access device, using short-range wireless communication to obtain and validate a device verification value, which is then used to authenticate the transaction, thereby enhancing security without burdening the merchant or consumer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If merchants do not verify portable consumer devices in card-present transactions, then transaction speed and ease of operation are maintained, but security and reliability deteriorate due to fraud and counterfeiting
Solution Approach 1:
The mobile device performs self-verification by automatically generating and transmitting a device verification value to the access device without requiring merchant intervention. The mobile device's processor independently validates the portable consumer device and generates cryptographic proof, eliminating the need for merchants to manually verify device authenticity while maintaining high security standards
Solution Approach 2:
A device verification value acts as an intermediary element between the mobile device and the transaction system. This cryptographic token mediates the verification process by providing machine-readable proof of device authenticity that the access device can automatically validate, bridging the gap between security requirements and operational simplicity
2Reliability
If device verification is implemented in card-present transactions, then security against fraud is improved, but device complexity and system infrastructure requirements increase
Solution Approach 1:
The mobile device leverages its existing multi-functional capabilities (processor, memory, communication interfaces) to perform verification functions. The same hardware components used for general mobile operations are utilized for cryptographic operations and device verification, avoiding the need for dedicated verification hardware and reducing overall system complexity
Solution Approach 2:
The system transforms complex security verification into a simplified parameter exchange process. By converting device authenticity into a discrete device verification value (cryptographic token), the system changes the verification parameter from complex multi-factor authentication to simple token validation, reducing computational and infrastructural requirements
3Ease of operation
If mobile devices are used as payment devices, then transaction convenience is improved, but security vulnerabilities increase due to potential device compromise or theft
Solution Approach 1:
The system applies preliminary anti-action by proactively verifying device authenticity before allowing transaction execution. The mobile device's processor performs pre-transaction validation of the portable consumer device and generates a device verification value that proves the device's legitimate status, preventing unauthorized devices from initiating transactions even if physically obtained through theft
Data Source
AI summary
In some embodiments, a first server computer may be provided. The first server computer may comprise a processor and a computer readable medium coupled to the processor. The computer readable medium may include code executable by the processor for implementing a method. The method may include the step of electronically receiving an authorization request message that includes a first device verification value from a merchant for a first transaction, where the first device verification value may have been received by the merchant from a mobile device based on an interaction between the mobile device and an access device. In some embodiments, the mobile device may have received the first verification value based on a first request. The method may further include the step of determining by a data processor if the first device verification value corresponds to a stored device verification value.


