OBO Issuer Service for Card-Not-Present Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current card-not-present transactions face higher fraud risks due to limited merchant verification of cardholder identity, leading to increased disputes and chargebacks, and existing authentication protocols like 3-D Secure can be cumbersome and have lower authorization approval rates compared to card-present transactions.
Innovation Solution
Implementing a 3-D Secure on-behalf-of (OBO) issuer service that intercepts and validates the universal cardholder authentication field (UCAF) within the authorization message, ensuring its integrity and inclusion, thereby increasing transaction confidence by validating the authentication value on behalf of the issuer financial institution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If 3-D Secure authentication protocol is implemented for card-not-present transactions, then fraud risk is reduced and authentication security is improved, but transaction complexity increases and authorization approval rates decrease
Solution Approach 1:
The patent introduces an intermediary service that acts as a mediator between the authentication system and the authorization system. This service intercepts authorization requests, validates the UCAF field, and communicates with the authentication system on behalf of the issuer. By introducing this intermediary layer, the complex authentication process is decoupled from the authorization flow, reducing transaction complexity while maintaining security.
Solution Approach 2:
The patent segments the authentication and authorization processes into separate, independent operations. The authentication process (generating AAV and UCAF) is separated from the authorization process (validating UCAF and approving transactions). This segmentation allows each process to be optimized independently, reducing overall transaction complexity while maintaining security.
2Reliability
If 3-D Secure authentication protocol is implemented for card-not-present transactions, then fraud risk is reduced and authentication security is improved, but authorization approval rates decrease
Solution Approach 1:
The patent performs preliminary validation of the UCAF field during the authorization process. By validating the authentication result in advance (checking if UCAF is present and properly formatted) before final authorization decisions, the system can quickly approve legitimate transactions while maintaining security. This preliminary action prevents unnecessary rejections of valid transactions.
Solution Approach 2:
The intermediary service automatically validates the UCAF field and makes authorization decisions based on the authentication result without requiring manual intervention or complex additional verification steps. This self-service approach streamlines the authorization process, improving approval rates for legitimate transactions while maintaining security through automated UCAF validation.
3Reliability
If merchant adds authentication value to authorization message, then cardholder authentication is completed, but risk of authentication value manipulation increases
Solution Approach 1:
The patent introduces an intermediary service that acts as a trusted mediator to validate the UCAF field. Instead of relying on the merchant to correctly add and protect the authentication value, the intermediary service intercepts the authorization request, validates that UCAF is present and properly formatted, and communicates with the authentication system. This intermediary layer eliminates the risk of merchant manipulation while ensuring authentication is properly completed.
Data Source
AI summary
Methods and systems for providing cardholder authentication services on-behalf-of (OBO) issuers utilizing a payment card authorization network to bridge cardholder authentication and transaction authorization processes. In some embodiments, the process includes an OBO issuer service computer receiving an authentication message, storing the authentication message in a transaction database and then receiving a purchase transaction authorization request message from a payment network. The OBO issuer service computer then determines that an authentication value of the received purchase transaction authorization request message matches the authentication value of the stored authentication message, stores a record of the match, and transmits the purchase transaction authorization request to the payment network for purchase authorization processing.


