Payment Authentication Routing for Card-Funding Account Mismatches
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods in e-commerce transactions fail to reliably authenticate consumers when the payment card details entered do not match the payment account used for funding, complicating compliance with regulations like PSD2 and introducing security vulnerabilities.
Innovation Solution
A method involving a payment network server that routes authentication requests from a first ACS to a second ACS associated with the preferred payment card, ensuring Strong Customer Authentication (SCA) is performed correctly, even when the payment card details do not match the funding account, by using a directory server or incorporating directory server functionality within the first ACS to reduce latency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the payment card details entered by the consumer do not match the payment account used for funding, then flexibility in payment account usage is improved, but authentication reliability deteriorates
Solution Approach 1:
The payment network server acts as an intermediary between the first ACS (associated with the entered card) and the second ACS (associated with the funding account). It receives the authentication request from the first ACS, identifies that the card and funding account belong to the same consumer, and routes the request to the second ACS for proper authentication. This mediator approach enables flexible payment account usage while maintaining authentication reliability.
2Reliability
If authentication requests are routed through multiple ACSs to handle card-funding account mismatches, then authentication security is improved, but transaction latency increases
Solution Approach 1:
The payment network server performs preliminary identification of the funding account associated with the entered card before routing the authentication request. By pre-identifying that both cards belong to the same consumer and determining the correct second ACS in advance, the server optimizes the routing path and reduces unnecessary delays in the authentication process.
Solution Approach 2:
The payment network server as an intermediary optimizes the routing of authentication requests between ACSs. It intelligently determines the most efficient path by identifying the relationship between the entered card and funding account, thereby minimizing transaction latency while ensuring proper authentication security through appropriate ACS routing.
3Adaptability or versatility
If a complex routing system is implemented to handle preferred payment card identification, then adaptability to different payment scenarios is improved, but device complexity increases
Solution Approach 1:
The payment network server serves as a centralized intermediary that handles all the complex routing logic for identifying preferred payment cards and routing authentication requests to the appropriate ACSs. This concentrates the complexity in a single component rather than distributing it across multiple devices, thereby improving adaptability to different payment scenarios while managing system complexity in a controlled manner.
Solution Approach 2:
The payment network server performs multiple functions: it acts as an intermediary for authentication requests, identifies preferred payment cards, determines the correct ACS for routing, and manages the relationship between entered cards and funding accounts. This multi-functionality improves adaptability to various payment scenarios while consolidating complexity in a single universal component.
Data Source
AI summary
The present invention provides a technical solution by which a consumer can be successfully authenticated in the scenario where the payment card or payment token provided by the consumer in an e-commerce/card not present transaction does not correspond to the payment account that is to provide the funds for effecting payment. This technical solution advantageously ensures that authentication security is not compromised whilst also enabling the consumer to enjoy the increased flexibility that comes with funding a transaction using a payment account that is not associated with the payment card/token provided by the consumer. Additionally, the present invention requires relatively little change to the configuration of the computing devices that collectively function to enable the transaction to take place (e.g. payment network computing devices, merchant computing devices, access control servers (ACS)).


