Offline Payment Fraud Prevention via Monotonic Counters
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing NFC-enabled smart card systems face challenges in preventing fraud during offline transactions, as they lack secure verification mechanisms and are vulnerable to balance rollback attacks and unauthorized use due to the limitations of traditional card verification methods.
Innovation Solution
A method that involves encoding smart cards with randomly generated card verification numbers, establishing secure communication channels between smart cards and contactless devices, and using session access keys to authenticate and authorize transactions, ensuring that every deposit and withdrawal is signed and verified by a remote system for integrity and balance management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional card verification methods (CCV) are used, then ease of operation is improved, but security is worsened due to limited combinations and vulnerability to fraud
Solution Approach 1:
The patent changes the verification parameter from a static 3-4 digit CCV to a dynamic verification process using monotonic counters and session access keys. The counter value changes with each transaction, providing unique verification data that cannot be reused, thus improving security while maintaining ease of operation through automatic device-based verification.
Solution Approach 2:
The patent introduces an intermediary verification mechanism between the card and merchant device. Instead of direct CCV entry, the system uses a trusted intermediary (the contactless device) that automatically verifies transaction integrity by comparing monotonic counter values, eliminating the need for users to manually enter verification codes.
2Productivity
If offline transaction processing is enabled, then productivity is improved by enabling transactions without network access, but security is worsened due to lack of real-time verification
Solution Approach 1:
The patent performs preliminary actions by pre-configuring the contactless device with session access keys and initializing monotonic counters before offline transactions occur. This allows the device to independently verify transaction integrity without real-time network access, maintaining security while enabling offline productivity.
Solution Approach 2:
The patent implements a feedback mechanism where the monotonic counter on the contactless device provides continuous feedback on transaction state. Each transaction increments the counter, and this feedback is used to verify that transactions are processed in the correct sequence and cannot be rolled back, ensuring security in offline mode.
3Reliability
If monotonic counters are implemented, then security is improved by preventing balance rollback attacks, but device complexity is worsened
Solution Approach 1:
The patent implements self-service by making the contactless device itself maintain and verify the monotonic counter. The device automatically manages counter initialization, incrementing, and verification without requiring external intervention or complex backend systems, improving security while keeping the implementation relatively simple.
4Reliability
If session access keys are used for authentication, then security is improved by ensuring authorized transactions, but ease of operation is worsened due to additional authentication steps
Solution Approach 1:
The contactless device performs self-service by automatically managing session access keys. The device independently verifies transaction authenticity using the access key without requiring users to manually input authentication credentials, thus improving security while maintaining ease of operation through automated background verification.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach enhances the security and integrity of offline transactions by preventing fraud through secure authentication and balance management, ensuring that only authorized transactions are processed and reducing the risk of balance rollback attacks.
Implementation Method 1
Near Field Communication (NFC) is a proximity communication technology that can enable contactless device payment technologies
Implementation Method 2
Radio frequency identification (RFID) is another wireless communication technology that can be adapted to enable NFC smart card payment technology
Data Source
AI summary
Preventing fraud during an offline transaction by encoding a randomly-generated card verification code onto a smart card. The verification code is transmitted to a contactless device during each transaction, wherein it is cross-referenced with the account number to ensure presence of the card. Also, every transaction record is signed by an access key resident on the contactless device and certified by a signing key resident on a remote system. Funds may be deposited onto the card when the contactless device creates a deposit request, signs the request using an access key and transmits it to the remote system, which in turn processes the request and certifies it with a signing key. Funds may be withdrawn when the contactless device creates a withdrawal record and signs it using an access key. The remote system verifies the signatures and certifies the records using a signing key when the records are later transmitted.


