Remote POS Cryptogram Generation for Secure Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure payment systems, particularly 'Card-Not-Present' transactions, are less secure and prone to fraud compared to 'Card-Present' transactions, and are limited in their ability to conduct transactions with networked devices like smart appliances due to the requirement of a physical point-of-sale (POS) system.

Innovation Solution

A computer-implemented method and system that enables secure payment transactions using a client device with an account identifier and issuer key to generate a cryptogram for a remote POS system, allowing 'Card-Present' transactions without a physical POS, by receiving product identifiers, detecting checkout actions, and transmitting cryptograms to a remote POS system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a physical POS system is used for Card-Present transactions, then transaction security is improved, but device complexity and infrastructure requirements increase

Engineering Contradiction:
Improvetransaction securityVSAvoidPOS system infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The invention extracts the critical security function (cryptogram generation using issuer keys) from the physical POS system and places it in the client device. This allows the security verification capability to be portable and eliminates the need for merchants to maintain complex physical POS infrastructure, while still enabling Card-Present level security for Card-Not-Present transactions

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The invention creates a virtual copy of the card presentment experience by generating cryptograms in the client device that mimic the security tokens produced by physical POS systems. This virtual cryptogram serves as a digital equivalent to the physical card verification, enabling secure transactions without physical card insertion or magnetic stripe swiping

Inventive Principle:
Principle #26Copying

2Reliability

If a physical POS system is required for secure transactions, then transaction security is improved, but ease of operation and accessibility for networked devices deteriorate

Engineering Contradiction:
Improvetransaction securityVSAvoidtransaction accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The invention makes the client device universal by enabling it to perform multiple functions: store issuer keys securely, generate cryptograms for various transaction types, and interface with different merchants and payment networks. This single device replaces the need for specialized physical POS systems at every transaction point, making secure transactions accessible to smartphones, tablets, and other networked devices

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The client device performs self-service by autonomously generating the cryptogram using its own stored issuer keys and the transaction details provided by the merchant. The device independently completes the security verification process without requiring external POS hardware, enabling users to conduct secure transactions directly from their personal devices

Inventive Principle:
Principle #25Self-service

3Ease of operation

If Card-Not-Present authentication methods are used, then ease of operation is improved, but transaction security and fraud resistance deteriorate

Engineering Contradiction:
Improvetransaction convenienceVSAvoidfraud resistance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The invention changes the security parameter from static credentials (passwords, CVV codes) to dynamic cryptograms that are generated fresh for each transaction. These cryptograms incorporate transaction-specific details such as amount, merchant ID, and timestamp, making them unique to each transaction and resistant to fraud. This maintains the convenience of Card-Not-Present transactions while dramatically improving security

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11875331B2System, method, and apparatus for conducting a secure transaction using a remote point-of-sale system
Publication Date: 2024.01.16 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11875331B2 patent drawing
  • US11875331B2 patent drawing
  • US11875331B2 patent drawing

AI summary

Provided is a computer-implemented method for conducting a secure payment transaction for a purchase at a merchant using a client device and a remote point-of-sale (POS) system associated with the merchant. The method includes receiving, with a client device, at least one identifier for at least one product to be purchased, the at least one product associated with a transaction value, and detecting a checkout action with the client device. In response to detecting the checkout action, the method includes generating at least one transaction message based on the transaction value of the at least one item to be purchased and at least one account identifier, generating a cryptogram based at least partially on the at least one transaction message and the at least one issuer key, and transmitting the cryptogram to the remote POS system associated with the merchant. A system and computer program product are also disclosed.