Payment Card Security Scoring via API Tokenization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current payment card electronic funds transfer (EFT) systems lack the ability to provide security scores for cardholders and do not inform them about insecure transactions, leading to uncertainty about secure methods of payment, which can result in unauthorized use and fraud.
Innovation Solution
A system and method that generate security scores for cardholders and provide real-time notifications about insecure transactions, using an Application Programming Interface (API) to inform cardholders and issuing bank computer systems, promoting the use of more secure transaction methods and fraud alerts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If clear transmission of card data or magnetic stripe swiping is used for payment card EFT transactions, then transaction processing is simple and fast, but security is compromised and unauthorized use occurs
Solution Approach 1:
The patent introduces an intermediary system (tokenization system and security scoring system) that sits between the cardholder and the transaction processing system. Instead of directly transmitting sensitive card data, the system uses tokens as intermediaries and security scores as mediators to evaluate transaction risk, thereby maintaining security without significantly complicating the user experience
Solution Approach 2:
The patent implements feedback mechanisms where security scores are calculated based on transaction patterns and provided back to cardholders and issuing banks. This feedback loop allows the system to dynamically adjust security measures based on observed behavior, improving security while maintaining simplicity through automated decision-making
2Reliability
If tokenization is used to substitute sensitive card data, then security is improved, but cardholders are unsure which methods are most secure and may not use tokenization
Solution Approach 1:
The patent uses visual indicators (color-coded security scores) to communicate transaction security levels to cardholders. By translating complex security metrics into simple, intuitive visual feedback, the system makes security information accessible and actionable for users without requiring them to understand the underlying technical mechanisms
Solution Approach 2:
The system automatically calculates and communicates security scores to cardholders, enabling them to make informed decisions about their transactions without requiring expert knowledge of security protocols. The system serves itself by automatically evaluating and reporting security levels
3Reliability
If security scores and real-time notifications are implemented, then fraud detection is improved, but system complexity and processing time increase
Solution Approach 1:
The patent calculates security scores in advance based on historical transaction patterns and cardholder behavior, so that when a transaction occurs, the evaluation is already complete or can be rapidly finalized. This preliminary preparation minimizes the time added to actual transaction processing while maintaining comprehensive fraud detection capabilities
Solution Approach 2:
The system applies security scoring selectively based on risk factors, focusing computational resources on transactions that require detailed analysis. By not applying full security scrutiny to every low-risk transaction, the system maintains fraud detection capability while minimizing processing time for routine transactions
Data Source
AI summary
A computer system is configured to provide a payment card security application programming interface (API) for providing a payment card security score to a partner entity computer system. Responsive to receipt of user identification data for a card holder from the partner entity computer system via the API, the computer system retrieves payment card electronic funds transfer (EFT) transaction data records corresponding to the card holder, and determines a transaction type and security level associated for the user's transactions. The computer system generates, based on the determined security level for each of the transactions, a security score for the card holder. The partner entity computer system provides the user identification data for the card holder to the payment card security API responsive to receipt of an authorization request for a new transaction. The partner entity computer system may determine whether to approve or deny the new payment card EFT transaction based upon the security score.


