Mobile POS Authentication Using Dynamic Hashed Security Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of mobile POS terminals for contactless transactions has led to a rise in fraudulent activities, as cardholders cannot verify the legitimacy of the POS terminal and payment processors are unable to detect compromised devices capturing payment card details, leading to disputes and reduced transaction confidence.

Innovation Solution

A secure merchant authentication system (SMA) generates dynamic hashed security tokens and monitors application activity using an offline smart token to authenticate the POS terminal, ensuring that only registered applications can access transaction data, and blocks unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If mobile POS terminals are used for contactless transactions, then transaction convenience is improved, but fraud risk increases

Engineering Contradiction:
Improvetransaction convenienceVSAvoidfraud risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication of the POS terminal before allowing transactions to proceed. The secure merchant authentication system validates the terminal's legitimacy in advance, ensuring that only authenticated terminals can process transactions, thereby preventing fraud while maintaining convenience

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication layer between the cardholder and the POS terminal. The secure merchant authentication system acts as a mediator that verifies the terminal's credentials, providing an additional security checkpoint that doesn't complicate the user experience

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cardholders can verify POS terminal legitimacy, then transaction security is improved, but system complexity increases

Engineering Contradiction:
Improvetransaction securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The POS terminal automatically performs authentication with the secure merchant authentication system without requiring cardholder intervention. The terminal self-verifies its legitimacy by presenting credentials to the authentication system, eliminating the need for complex user-facing verification mechanisms

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The secure merchant authentication system serves as an intermediary that handles the complex verification processes behind the scenes. Cardholders interact only with the familiar POS interface while the intermediary system manages security protocols in the background

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If payment processors monitor application activity, then fraud detection is improved, but processing time increases

Engineering Contradiction:
Improvefraud detectionVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs fraud detection checks in advance by authenticating the POS terminal before transactions occur. By pre-validating terminal credentials and monitoring application activity beforehand, the system establishes a security baseline that enables faster real-time transaction processing without repeated verification delays

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12548023B2Methods and systems for blocking multi-rail contactless fraud
Publication Date: 2026.02.10 MASTERCARD INT INC
  • US12548023B2 patent drawing
  • US12548023B2 patent drawing
  • US12548023B2 patent drawing

AI summary

A system and method for performing a transaction at a software-based POS system of a merchant includes receiving, from the software-based POS system, a payment authorization request message. A processor is programmed to extract a dynamic hashed security token from the payment authorization request message. In addition, the processor is programmed to validate the dynamic hashed security token and, upon validating the dynamic hashed security token, determine that the software-based POS system that transmitted the payment authorization request message is running a mobile POS software application. Furthermore, the processor is programed to extract the hardware identifier and the application identifier from the transaction data and compare them to account registration information stored with a merchant account. The processor then determines that the hardware identifier and the application identifier match with the account registration information and transmits the payment authorization request message to an issuer associated with the transaction card details.