MOTO Transaction Authentication via Dynamic Issuer Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mail order and telephone order (MOTO) transactions face security challenges due to the use of static passcodes, which can be intercepted and reused, and existing dynamic authentication technologies do not adequately address the infrastructure needs for secure cardholder authentication in these environments, leading to frequent fraudulent activities.
Innovation Solution
A method and system for authenticating MOTO transactions that involves receiving and validating authentication information from cardholders, using dynamic or static passcodes, biometrics, and issuer-specific data, with a focus on preventing unauthorized access by ensuring that sensitive information is not transmitted to merchants, and utilizing a plug-in software module and authentication service to verify cardholder identity and authorize transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If static passcodes are used for MOTO transactions, then ease of operation is improved, but security deteriorates due to interception and reuse risks
Solution Approach 1:
The patent implements dynamic authentication values that change for each transaction, replacing static passcodes with time-sensitive or transaction-specific codes. This dynamic approach maintains ease of use while significantly improving security by preventing interception and reuse attacks.
Solution Approach 2:
The system changes the authentication parameter from a fixed static passcode to a variable dynamic value that is generated fresh for each transaction. This parameter change ensures that even if one authentication value is compromised, it cannot be used for subsequent transactions.
2Reliability
If dynamic authentication technologies are implemented, then security is improved, but device complexity increases due to infrastructure requirements
Solution Approach 1:
The patent introduces an authentication service as an intermediary component that mediates between the merchant system and the cardholder. This service handles the complexity of generating and verifying dynamic authentication values, allowing the merchant system to remain relatively simple while still achieving enhanced security.
Solution Approach 2:
The authentication system is segmented into separate functional components: the authentication service that generates dynamic values, the merchant system that collects and transmits them, and the cardholder interface. This segmentation allows each component to be optimized independently, reducing overall system complexity.
3Reliability
If cardholder authentication is implemented, then reliability is improved by preventing fraud, but loss of information increases as sensitive data must be handled securely
Solution Approach 1:
The patent extracts the sensitive authentication data handling from the merchant system and places it in the secure authentication service. The merchant system only handles non-sensitive transaction data, while the authentication service securely manages the dynamic authentication values, minimizing the risk of information loss.
Solution Approach 2:
The system uses disposable dynamic authentication values that are generated for each transaction and then discarded. These short-lived credentials reduce the risk of information loss because they cannot be reused even if intercepted, and their brief existence minimizes the window for potential compromise.
Data Source
AI summary
The method for authenticating a mail order or telephone order transaction according to the present invention includes receiving authentication information from a cardholder, providing authentication information to an issuer, and determining whether the authentication information is valid. If the authentication information is valid, the issuer informs the merchant that the transaction is valid. In an embodiment, the issuer may not supply a personal assurance message and/or other confidential cardholder information previously supplied by the cardholder in response to the authentication information.


