Payment Instrument Provisioning Authentication With Secure Data Entry
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing payment instrument provisioning methods are vulnerable to unauthorized users provisioning payment instruments without the knowledge or consent of the authorized user, particularly through social engineering techniques, leading to potential fraud.
Innovation Solution
A method and system for authenticating payment instrument provisioning that involves secure data entry devices, electronic devices, and servers to verify the authenticity of the user by matching secure data, generating authorization messages, and approving or declining the provisioning request based on validation success.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual entry of payment instrument information is allowed during provisioning, then ease of operation is improved, but security deteriorates due to vulnerability to unauthorized provisioning
Solution Approach 1:
A secure data entry device is introduced as an intermediary between the user and the provisioning system. This device captures payment instrument information through its interface (card reader, camera, or manual entry) and securely transmits it to the server, eliminating the need for users to manually enter sensitive information on their electronic devices. The intermediary device provides a secure environment for data capture and transmission, resolving the contradiction between ease of operation and security.
2Reliability
If identity verification is implemented during provisioning, then security is improved, but device complexity increases
Solution Approach 1:
The secure data entry device serves as an intermediary that handles all identity verification and validation processes. The device captures secure data, validates it against stored information, and only transmits authenticated information to the server. This concentrates the complexity in a dedicated security device rather than distributing it throughout the entire provisioning system, achieving security enhancement while managing complexity through specialized hardware.
3Object-affected harmful factors
If secure data verification is performed during provisioning, then fraud prevention is improved, but provisioning time increases
Solution Approach 1:
The secure data entry device performs verification of payment instrument information and user identity before the provisioning process is initiated. By conducting security checks in advance and only transmitting verified information to the server, the system prevents fraudulent provisioning attempts early in the process. This preliminary validation approach reduces the overall time required compared to performing multiple verification steps during and after provisioning.
Data Source
AI summary
The invention relates generally to the provisioning of payment instruments onto electronic devices such as a mobile telephone, tablet, laptop or wearable, and in particular to securely provisioning payment instrument for which authorisation for the provisioning must be provided by a payment instrument issuer. A first embodiment is provided in which data that is generated during module a transaction is received by an electronic device and transmitted controller from the electronic device to a server associated with an acquirer. The data received from the electronic device is compared to the data generated during the transaction and, if these match, provisioning is authorised. A second embodiment is provided in which a server associated with an acquirer generates an identification message that is separate from but based on a response message associated with a transaction, and provisioning is authorised or declined based on the identification message.


