Phishing Detection via Payment Card Network Proxy Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Phishing attacks on payment cardholders are challenging to detect, as fraudulent Websites can spoof legitimate ones, making it difficult to verify whether a merchant Website is registered with a payment card network, leading to potential security breaches.
Innovation Solution
A method and system using proxy interactions to determine if a merchant Website is registered with a payment card network by initiating a proxy transaction with fictitious payment card information, confirming receipt through an authorization system, and providing notifications to the payment cardholder about the legitimacy of the Website.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If server authentication is used to verify Website legitimacy, then authentication capability is provided, but the skill required to detect fake Websites becomes tremendous and detection reliability is insufficient
Solution Approach 1:
The patent introduces a payment card network as an intermediary entity that performs authentication on behalf of the payment cardholder. Instead of requiring the cardholder to directly assess Website legitimacy through complex server authentication, the payment card network acts as a mediator that verifies whether the Website is authorized to accept payment cards from its members, thereby simplifying the detection process and improving reliability
Solution Approach 2:
The patent creates a simplified copy of the authentication process where instead of directly verifying Website server credentials, the system uses a proxy interaction that copies the essential authentication function to a payment card network verification step. This copying approach maintains security while reducing the complexity and skill required for detection
2Object-generated harmful factors
If Website spoofing is used to create fake Websites, then phishing capability is enhanced, but the ability to verify Website registration with payment card networks remains insufficient
Solution Approach 1:
The patent performs a preliminary verification action before the actual phishing transaction can occur. By checking whether the Website is registered with the payment card network and authorized to accept payment cards, the system prevents the phishing process from completing successfully. This preliminary action stops the harmful effect before it can manifest
Solution Approach 2:
The payment card network serves as an intermediary that provides a reliable verification mechanism independent of the Website's visual appearance or server configuration. This intermediary verification process cannot be fooled by spoofing techniques, as it directly queries the payment card network's authorization records, thereby maintaining verification reliability even when Websites are heavily spoofed
3Reliability
If proxy interaction with payment card network is performed, then verification reliability is improved, but transaction time and processing complexity increase
Solution Approach 1:
The system performs the proxy interaction and verification action preliminarily, before the actual payment transaction occurs. By completing the authentication check in advance, the system ensures that when the real transaction happens, the verification is already done, which can actually reduce overall processing time by avoiding delays during the payment authorization step
Solution Approach 2:
The payment card network performs the verification function as part of its existing payment processing infrastructure, utilizing its own resources and protocols. This self-service approach means the verification is integrated into the normal payment flow rather than being a separate external process, reducing additional time and complexity
Data Source
AI summary
A system for identification by a payment cardholder of phishing and/or deceptive Websites is provided. The system includes an electronic storage device having a database of merchant or financial institution Website registration with a payment card network information stored therein. The system includes an access path for allowing access to the merchant or financial institution Website registration with a payment card network information. The system includes a processor for assembling the merchant or financial institution Website registration with a payment card network information in the database, and for communicating the assembled merchant or financial institution Website registration with a payment card network information to a payment cardholder that has been granted access to the database.


