Pseudo Account Identifier Generation for Contactless Payment Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing contactless payment systems using portable wireless devices are vulnerable to unauthorized data interception, and current encryption technologies are costly and not fully adopted by merchants, leading to limited protection against fraudulent transactions.
Innovation Solution
Implementing the use of pseudo primary account identifiers, which are generated by a remote server and used for transactions instead of real account identifiers, providing a secure and cost-effective solution that integrates with existing payment processing networks without requiring significant upgrades from merchants.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If contactless card readers use wireless transmission to retrieve payment card information, then user convenience is increased, but vulnerability to unauthorized data interception increases
Solution Approach 1:
The system generates pseudo primary account identifiers that are copies or substitutes of the real primary account identifier. These pseudo identifiers are transmitted during contactless transactions instead of the real identifier, allowing the transaction to proceed while protecting the actual account information from interception. The pseudo identifiers are indistinguishable from real identifiers but have limited value if intercepted.
Solution Approach 2:
The pseudo primary account identifier acts as an intermediary between the real account identifier and the transaction processing system. It mediates the transmission by replacing the sensitive real identifier with a less sensitive substitute that still enables transaction authorization, thereby reducing the risk associated with direct transmission of real account information.
2Reliability
If encryption technologies are implemented to protect payment data, then security against information theft is improved, but implementation cost and complexity increase
Solution Approach 1:
The system uses pseudo primary account identifiers that are inexpensive to generate and have a limited lifetime or scope of use. These pseudo identifiers can be discarded after use or after a certain period, reducing the risk associated with their potential compromise. This approach provides security without requiring expensive encryption infrastructure.
Solution Approach 2:
The system changes the parameter of the account identifier from a permanent, sensitive real identifier to a temporary, less sensitive pseudo identifier. This parameter change allows the same account to be referenced multiple times with different identifiers, reducing the risk of any single identifier compromise while avoiding the need for complex encryption systems.
3Reliability
If pseudo primary account identifiers are used instead of real identifiers, then security against fraud is improved, but transaction processing complexity increases
Solution Approach 1:
The system enables the portable wireless device to self-generate or self-select pseudo primary account identifiers from a set of available identifiers. This self-service capability reduces the need for complex server-side generation and management systems, simplifying the overall transaction processing while maintaining security benefits.
Data Source
AI summary
The present invention provides a method for conducting a transaction that includes receiving a pseudo account identifier that corresponds to a primary account identifier. The pseudo account identifier may be received at a portable wireless device and may be generated by a remote server computer. The portable wireless device can receive the pseudo account identifier over a first network and provide the pseudo account identifier to an access device. The access devices generally comprises a reader that can receive the pseudo account identifier, and thereafter send a message to request authorization of a transaction. The authorization request message may include the pseudo account identifier and is sent to a payment processing network. The authorization request message is sent to the payment processing network over a second network. The payment processing network may then process the authorization message and return a response that indicates if the transaction is authorized or not.


