Phishing Detection via Payment Card Network Proxy Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Phishing attacks on payment cardholders are challenging to detect, as fraudulent Websites can spoof legitimate ones, making it difficult to verify whether a merchant Website is registered with a payment card network, leading to potential security breaches.

Innovation Solution

A method and system using proxy interactions to determine if a merchant Website is registered with a payment card network by initiating a proxy transaction with fictitious payment card information, confirming receipt through an authorization system, and providing notifications to the payment cardholder about the legitimacy of the Website.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If server authentication is used to verify Website legitimacy, then authentication capability is provided, but the skill required to detect fake Websites becomes tremendous and detection reliability is insufficient

Engineering Contradiction:
Improvedetection reliabilityVSAvoidskill required to detect
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a payment card network as an intermediary entity that performs authentication on behalf of the payment cardholder. Instead of requiring the cardholder to directly assess Website legitimacy through complex server authentication, the payment card network acts as a mediator that verifies whether the Website is authorized to accept payment cards from its members, thereby simplifying the detection process and improving reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a simplified copy of the authentication process where instead of directly verifying Website server credentials, the system uses a proxy interaction that copies the essential authentication function to a payment card network verification step. This copying approach maintains security while reducing the complexity and skill required for detection

Inventive Principle:
Principle #26Copying

2Object-generated harmful factors

If Website spoofing is used to create fake Websites, then phishing capability is enhanced, but the ability to verify Website registration with payment card networks remains insufficient

Engineering Contradiction:
Improvephishing capabilityVSAvoidverification reliability
Core Design Contradiction:
Object-generated harmful factorsVSReliability

Solution Approach 1:

The patent performs a preliminary verification action before the actual phishing transaction can occur. By checking whether the Website is registered with the payment card network and authorized to accept payment cards, the system prevents the phishing process from completing successfully. This preliminary action stops the harmful effect before it can manifest

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The payment card network serves as an intermediary that provides a reliable verification mechanism independent of the Website's visual appearance or server configuration. This intermediary verification process cannot be fooled by spoofing techniques, as it directly queries the payment card network's authorization records, thereby maintaining verification reliability even when Websites are heavily spoofed

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If proxy interaction with payment card network is performed, then verification reliability is improved, but transaction time and processing complexity increase

Engineering Contradiction:
Improveverification reliabilityVSAvoidtransaction time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs the proxy interaction and verification action preliminarily, before the actual payment transaction occurs. By completing the authentication check in advance, the system ensures that when the real transaction happens, the verification is already done, which can actually reduce overall processing time by avoiding delays during the payment authorization step

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The payment card network performs the verification function as part of its existing payment processing infrastructure, utilizing its own resources and protocols. This self-service approach means the verification is integrated into the normal payment flow rather than being a separate external process, reducing additional time and complexity

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9972013B2Internet site authentication with payments authorization data
Publication Date: 2018.05.15 MASTERCARD INT INC
  • US9972013B2 patent drawing
  • US9972013B2 patent drawing
  • US9972013B2 patent drawing

AI summary

A system for identification by a payment cardholder of phishing and/or deceptive Websites is provided. The system includes an electronic storage device having a database of merchant or financial institution Website registration with a payment card network information stored therein. The system includes an access path for allowing access to the merchant or financial institution Website registration with a payment card network information. The system includes a processor for assembling the merchant or financial institution Website registration with a payment card network information in the database, and for communicating the assembled merchant or financial institution Website registration with a payment card network information to a payment cardholder that has been granted access to the database.