Remote POS Cryptogram Generation for Secure Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure payment systems, particularly 'Card-Not-Present' transactions, are less secure and prone to fraud compared to 'Card-Present' transactions, and are limited in their ability to conduct transactions with networked devices like smart appliances due to the requirement of a physical point-of-sale (POS) system.
Innovation Solution
A computer-implemented method and system that enables secure payment transactions using a client device with an account identifier and issuer key to generate a cryptogram for a remote POS system, allowing 'Card-Present' transactions without a physical POS, by receiving product identifiers, detecting checkout actions, and transmitting cryptograms to a remote POS system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a physical POS system is used for Card-Present transactions, then transaction security is improved, but device complexity and infrastructure requirements increase
Solution Approach 1:
The invention extracts the critical security function (cryptogram generation using issuer keys) from the physical POS system and places it in the client device. This allows the security verification capability to be portable and eliminates the need for merchants to maintain complex physical POS infrastructure, while still enabling Card-Present level security for Card-Not-Present transactions
Solution Approach 2:
The invention creates a virtual copy of the card presentment experience by generating cryptograms in the client device that mimic the security tokens produced by physical POS systems. This virtual cryptogram serves as a digital equivalent to the physical card verification, enabling secure transactions without physical card insertion or magnetic stripe swiping
2Reliability
If a physical POS system is required for secure transactions, then transaction security is improved, but ease of operation and accessibility for networked devices deteriorate
Solution Approach 1:
The invention makes the client device universal by enabling it to perform multiple functions: store issuer keys securely, generate cryptograms for various transaction types, and interface with different merchants and payment networks. This single device replaces the need for specialized physical POS systems at every transaction point, making secure transactions accessible to smartphones, tablets, and other networked devices
Solution Approach 2:
The client device performs self-service by autonomously generating the cryptogram using its own stored issuer keys and the transaction details provided by the merchant. The device independently completes the security verification process without requiring external POS hardware, enabling users to conduct secure transactions directly from their personal devices
3Ease of operation
If Card-Not-Present authentication methods are used, then ease of operation is improved, but transaction security and fraud resistance deteriorate
Solution Approach 1:
The invention changes the security parameter from static credentials (passwords, CVV codes) to dynamic cryptograms that are generated fresh for each transaction. These cryptograms incorporate transaction-specific details such as amount, merchant ID, and timestamp, making them unique to each transaction and resistant to fraud. This maintains the convenience of Card-Not-Present transactions while dramatically improving security
Data Source
AI summary
Provided is a computer-implemented method for conducting a secure payment transaction for a purchase at a merchant using a client device and a remote point-of-sale (POS) system associated with the merchant. The method includes receiving, with a client device, at least one identifier for at least one product to be purchased, the at least one product associated with a transaction value, and detecting a checkout action with the client device. In response to detecting the checkout action, the method includes generating at least one transaction message based on the transaction value of the at least one item to be purchased and at least one account identifier, generating a cryptogram based at least partially on the at least one transaction message and the at least one issuer key, and transmitting the cryptogram to the remote POS system associated with the merchant. A system and computer program product are also disclosed.


