Payment Token Provisioning With Variable Risk-Based Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing payment token provisioning systems lack robust risk evaluation mechanisms, leading to potential security vulnerabilities and unauthorized transactions.

Innovation Solution

Implement a system where an issuer backend evaluates the eligibility of a card for provisioning to a mobile device, generates a payment token with risk profiles, and requires additional authentication through one-time passcodes to activate the token, using device-bound or service-bound payloads for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If payment tokens are provisioned to mobile devices for convenient contactless payment, then ease of operation is improved, but security risks and potential unauthorized transactions increase

Engineering Contradiction:
Improvepayment convenienceVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary risk evaluation and generates risk profiles during the token provisioning phase before actual transactions occur. This includes evaluating device security, user behavior patterns, and transaction context in advance to establish baseline risk levels and preventive controls

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors transaction data, device information, and user behavior to update risk profiles dynamically. This feedback mechanism adjusts risk levels and authentication requirements in real-time based on observed patterns, enabling adaptive security that responds to emerging threats while maintaining convenient payment flow

Inventive Principle:
Principle #23Feedback

2Ease of operation

If traditional authentication methods are used for payment token activation, then ease of operation is maintained, but reliability and fraud prevention are insufficient

Engineering Contradiction:
Improveauthentication simplicityVSAvoidfraud prevention
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements dynamic authentication that adapts to risk levels. Low-risk transactions use simple authentication methods, while high-risk transactions trigger enhanced verification steps. This dynamic approach adjusts security measures in real-time based on the calculated risk profile, maintaining simplicity for legitimate users while strengthening security for suspicious activities

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters based on risk evaluation results. This includes adjusting the number of verification factors required, modifying time limits for transactions, or changing the type of authentication needed. These parameter changes are automatically applied based on the risk profile without requiring manual security configuration

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive risk evaluation is implemented for all transactions, then reliability and security are improved, but device complexity and processing time increase

Engineering Contradiction:
Improvetransaction securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies different levels of risk evaluation to different transactions, devices, and users based on their specific characteristics. Instead of uniform comprehensive checks, the system tailors the depth and scope of evaluation to the local context of each transaction, applying stricter scrutiny only where needed based on the calculated risk profile

Inventive Principle:
Principle #3Local quality

4Ease of operation

If uniform authentication requirements are applied to all payment tokens, then ease of operation is maintained, but adaptability to different risk levels is reduced

Engineering Contradiction:
Improveauthentication consistencyVSAvoidrisk-based flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system dynamically adjusts authentication requirements based on the risk profile of each token and transaction. This creates a flexible framework where authentication complexity is not fixed but adapts to the specific risk characteristics, allowing simple authentication for low-risk scenarios and enhanced verification for high-risk situations

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250259163A1Systems and methods for payment token provisioning with variable risk evaluation
Publication Date: 2025.08.14 JPMORGAN CHASE BANK NA
  • US20250259163A1 patent drawing
  • US20250259163A1 patent drawing
  • US20250259163A1 patent drawing

AI summary

Systems and methods for payment token provisioning with variable risk evaluation are disclosed. In one embodiment, a method may include: an issuer backend: (1) receiving, from an electronic wallet application, a payload comprising an identification of a card to be provisioned to the mobile electronic device; (2) determining that the card is eligible for provisioning to the mobile electronic device; (3) generating a card payload and communicating the card payload to the payment network, wherein the payment network creates a payment token for the card comprising payment token origin information; (4) receiving the payment token from the payment network and generating a risk profile for the payment token; and (5) activating the payment token in response to the validation.