MOTO Transaction Authentication via Dynamic Issuer Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mail order and telephone order (MOTO) transactions face security challenges due to the use of static passcodes, which can be intercepted and reused, and existing dynamic authentication technologies do not adequately address the infrastructure needs for secure cardholder authentication in these environments, leading to frequent fraudulent activities.

Innovation Solution

A method and system for authenticating MOTO transactions that involves receiving and validating authentication information from cardholders, using dynamic or static passcodes, biometrics, and issuer-specific data, with a focus on preventing unauthorized access by ensuring that sensitive information is not transmitted to merchants, and utilizing a plug-in software module and authentication service to verify cardholder identity and authorize transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If static passcodes are used for MOTO transactions, then ease of operation is improved, but security deteriorates due to interception and reuse risks

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic authentication values that change for each transaction, replacing static passcodes with time-sensitive or transaction-specific codes. This dynamic approach maintains ease of use while significantly improving security by preventing interception and reuse attacks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the authentication parameter from a fixed static passcode to a variable dynamic value that is generated fresh for each transaction. This parameter change ensures that even if one authentication value is compromised, it cannot be used for subsequent transactions.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If dynamic authentication technologies are implemented, then security is improved, but device complexity increases due to infrastructure requirements

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication service as an intermediary component that mediates between the merchant system and the cardholder. This service handles the complexity of generating and verifying dynamic authentication values, allowing the merchant system to remain relatively simple while still achieving enhanced security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into separate functional components: the authentication service that generates dynamic values, the merchant system that collects and transmits them, and the cardholder interface. This segmentation allows each component to be optimized independently, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

3Reliability

If cardholder authentication is implemented, then reliability is improved by preventing fraud, but loss of information increases as sensitive data must be handled securely

Engineering Contradiction:
ImprovesecurityVSAvoidloss of information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts the sensitive authentication data handling from the merchant system and places it in the secure authentication service. The merchant system only handles non-sensitive transaction data, while the authentication service securely manages the dynamic authentication values, minimizing the risk of information loss.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system uses disposable dynamic authentication values that are generated for each transaction and then discarded. These short-lived credentials reduce the risk of information loss because they cannot be reused even if intercepted, and their brief existence minimizes the window for potential compromise.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS9569775B2Methods and systems for performing authentication in consumer transactions
Publication Date: 2017.02.14 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US9569775B2 patent drawing
  • US9569775B2 patent drawing
  • US9569775B2 patent drawing

AI summary

The method for authenticating a mail order or telephone order transaction according to the present invention includes receiving authentication information from a cardholder, providing authentication information to an issuer, and determining whether the authentication information is valid. If the authentication information is valid, the issuer informs the merchant that the transaction is valid. In an embodiment, the issuer may not supply a personal assurance message and/or other confidential cardholder information previously supplied by the cardholder in response to the authentication information.