Mobile Device Verification for Secure Payment Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing payment transaction systems, especially in card-present environments, face challenges in ensuring security against fraud and counterfeiting, particularly since merchants do not typically verify portable consumer devices, which can lead to fraudulent transactions even when the payment device is stolen or copied.

Innovation Solution

The system employs a mobile device to interact with a portable consumer device and an access device, using short-range wireless communication to obtain and validate a device verification value, which is then used to authenticate the transaction, thereby enhancing security without burdening the merchant or consumer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If merchants do not verify portable consumer devices in card-present transactions, then transaction speed and ease of operation are maintained, but security and reliability deteriorate due to fraud and counterfeiting

Engineering Contradiction:
Improvetransaction securityVSAvoidmerchant verification burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mobile device performs self-verification by automatically generating and transmitting a device verification value to the access device without requiring merchant intervention. The mobile device's processor independently validates the portable consumer device and generates cryptographic proof, eliminating the need for merchants to manually verify device authenticity while maintaining high security standards

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A device verification value acts as an intermediary element between the mobile device and the transaction system. This cryptographic token mediates the verification process by providing machine-readable proof of device authenticity that the access device can automatically validate, bridging the gap between security requirements and operational simplicity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If device verification is implemented in card-present transactions, then security against fraud is improved, but device complexity and system infrastructure requirements increase

Engineering Contradiction:
Improvefraud preventionVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The mobile device leverages its existing multi-functional capabilities (processor, memory, communication interfaces) to perform verification functions. The same hardware components used for general mobile operations are utilized for cryptographic operations and device verification, avoiding the need for dedicated verification hardware and reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system transforms complex security verification into a simplified parameter exchange process. By converting device authenticity into a discrete device verification value (cryptographic token), the system changes the verification parameter from complex multi-factor authentication to simple token validation, reducing computational and infrastructural requirements

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If mobile devices are used as payment devices, then transaction convenience is improved, but security vulnerabilities increase due to potential device compromise or theft

Engineering Contradiction:
Improvepayment convenienceVSAvoiddevice theft vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by proactively verifying device authenticity before allowing transaction execution. The mobile device's processor performs pre-transaction validation of the portable consumer device and generates a device verification value that proves the device's legitimate status, preventing unauthorized devices from initiating transactions even if physically obtained through theft

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS20240273506A1Security system incorporating mobile device
Publication Date: 2024.08.15 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US20240273506A1 patent drawing
  • US20240273506A1 patent drawing
  • US20240273506A1 patent drawing

AI summary

In some embodiments, a first server computer may be provided. The first server computer may comprise a processor and a computer readable medium coupled to the processor. The computer readable medium may include code executable by the processor for implementing a method. The method may include the step of electronically receiving an authorization request message that includes a first device verification value from a merchant for a first transaction, where the first device verification value may have been received by the merchant from a mobile device based on an interaction between the mobile device and an access device. In some embodiments, the mobile device may have received the first verification value based on a first request. The method may further include the step of determining by a data processor if the first device verification value corresponds to a stored device verification value.