Payment Card Authentication Using Manual Code Against Skimming
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Point-of-sale systems are susceptible to skimming devices that capture payment information, enabling unauthorized transactions.
Innovation Solution
A physical payment card with embedded and non-embedded data, where the non-embedded data includes a multi-character code, requiring manual input at the point-of-sale system, and a card payment network verifies the authenticity of the payment using both embedded data and the multi-character code.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If payment information is stored on the card in embedded form for easy processing, then transaction speed is improved, but the card becomes vulnerable to skimming devices that can capture the embedded data
Solution Approach 1:
The payment authentication process is segmented into two distinct parts: embedded data stored on the card for machine reading, and a separate multi-character code that requires manual entry. This segmentation ensures that even if the embedded data is captured by skimming devices, the embedded data alone is insufficient for fraudulent transactions without the manually entered code.
Solution Approach 2:
The multi-character code acts as an intermediary element between the cardholder and the payment system. It serves as an additional layer of authentication that bridges the gap between machine-readable embedded data and secure transaction authorization, preventing unauthorized use of captured embedded data.
2Reliability
If a multi-character code with special characters is required for payment processing, then fraud prevention is improved, but the ease of operation deteriorates due to manual input requirements
Solution Approach 1:
The multi-character code is pre-configured and associated with the card account before the transaction occurs. This preliminary setup allows the code to be readily available for manual entry during the transaction, reducing the operational burden on the cardholder while maintaining strong fraud prevention capabilities.
Solution Approach 2:
The system accepts the multi-character code as a manual input copy of the authentication element, rather than requiring direct machine reading. This approach balances security with usability by allowing flexible manual entry while still verifying the code against the pre-configured authentication data.
3Productivity
If embedded data is made machine-readable for efficient processing, then productivity is improved, but the loss of information increases when skimming devices intercept the data
Solution Approach 1:
The authentication information is divided into embedded machine-readable data and a separate manually entered multi-character code. This segmentation ensures that even if the embedded data is intercepted and copied by skimming devices, the intercepted data remains incomplete without the manually entered code, preventing fraudulent transactions.
Solution Approach 2:
The system preemptively counteracts the potential loss from data interception by requiring a second authentication element (the multi-character code) that cannot be easily captured by skimming devices. This preliminary anti-action neutralizes the security risk before it can be exploited.
Data Source
AI summary
A system can include a physical payment card, a point-of-sale card payment device for processing a payment using the physical payment card, and a card payment network in communication with the point-of-sale card payment device. The physical payment card includes embedded data and non-embedded data. Embedded data may include payment information required for processing a payment using the physical payment card, where at least a portion of the payment information is not printed visibly on the physical payment card. Non-embedded data may include a multi-character code may include at least one special character, where the multi-character code is required for processing a payment using the physical payment card.


