Payment Token Provisioning With Variable Risk-Based Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing payment token provisioning systems lack robust risk evaluation mechanisms, leading to potential security vulnerabilities and unauthorized transactions.
Innovation Solution
Implement a system where an issuer backend evaluates the eligibility of a card for provisioning to a mobile device, generates a payment token with risk profiles, and requires additional authentication through one-time passcodes to activate the token, using device-bound or service-bound payloads for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If payment tokens are provisioned to mobile devices for convenient contactless payment, then ease of operation is improved, but security risks and potential unauthorized transactions increase
Solution Approach 1:
The system performs preliminary risk evaluation and generates risk profiles during the token provisioning phase before actual transactions occur. This includes evaluating device security, user behavior patterns, and transaction context in advance to establish baseline risk levels and preventive controls
Solution Approach 2:
The system continuously monitors transaction data, device information, and user behavior to update risk profiles dynamically. This feedback mechanism adjusts risk levels and authentication requirements in real-time based on observed patterns, enabling adaptive security that responds to emerging threats while maintaining convenient payment flow
2Ease of operation
If traditional authentication methods are used for payment token activation, then ease of operation is maintained, but reliability and fraud prevention are insufficient
Solution Approach 1:
The system implements dynamic authentication that adapts to risk levels. Low-risk transactions use simple authentication methods, while high-risk transactions trigger enhanced verification steps. This dynamic approach adjusts security measures in real-time based on the calculated risk profile, maintaining simplicity for legitimate users while strengthening security for suspicious activities
Solution Approach 2:
The system changes authentication parameters based on risk evaluation results. This includes adjusting the number of verification factors required, modifying time limits for transactions, or changing the type of authentication needed. These parameter changes are automatically applied based on the risk profile without requiring manual security configuration
3Reliability
If comprehensive risk evaluation is implemented for all transactions, then reliability and security are improved, but device complexity and processing time increase
Solution Approach 1:
The system applies different levels of risk evaluation to different transactions, devices, and users based on their specific characteristics. Instead of uniform comprehensive checks, the system tailors the depth and scope of evaluation to the local context of each transaction, applying stricter scrutiny only where needed based on the calculated risk profile
4Ease of operation
If uniform authentication requirements are applied to all payment tokens, then ease of operation is maintained, but adaptability to different risk levels is reduced
Solution Approach 1:
The system dynamically adjusts authentication requirements based on the risk profile of each token and transaction. This creates a flexible framework where authentication complexity is not fixed but adapts to the specific risk characteristics, allowing simple authentication for low-risk scenarios and enhanced verification for high-risk situations
Data Source
AI summary
Systems and methods for payment token provisioning with variable risk evaluation are disclosed. In one embodiment, a method may include: an issuer backend: (1) receiving, from an electronic wallet application, a payload comprising an identification of a card to be provisioned to the mobile electronic device; (2) determining that the card is eligible for provisioning to the mobile electronic device; (3) generating a card payload and communicating the card payload to the payment network, wherein the payment network creates a payment token for the card comprising payment token origin information; (4) receiving the payment token from the payment network and generating a risk profile for the payment token; and (5) activating the payment token in response to the validation.


