Risk-Based Authentication Platform for Payment Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems for online transactions, particularly in electronic payment networks, face challenges such as high costs, limited data access, and lack of sophisticated authentication capabilities in Access Control Servers (ACS), leading to increased fraud and user friction, especially in card-not-present transactions.

Innovation Solution

An authentication platform that performs risk-based authentication (RBA) on behalf of ACSs, using a directory server and RBA engine to generate risk scores and reason codes, allowing for more accurate and timely authentication decisions, even when ACSs are unavailable, by leveraging a comprehensive data set including historical transaction data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Access Control Servers (ACS) are used for authentication services, then authentication capability is provided, but the system becomes dependent on ACS availability and sophistication

Engineering Contradiction:
Improveauthentication service availabilityVSAvoidauthentication capability flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The payment processing network acts as an intermediary between merchants/issuers and ACS providers. It receives authentication requests, determines whether an ACS is available and capable, and routes requests accordingly. This intermediary role allows the system to maintain reliability through ACS when available while adapting to its unavailability or insufficient capability by using alternative authentication methods.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system dynamically adjusts its behavior based on ACS availability and capability. The payment processing network continuously assesses whether an ACS is available and sophisticated enough to handle the authentication request, and switches between ACS-based authentication and alternative methods accordingly. This dynamic adaptation resolves the contradiction between relying on ACS for reliability and needing flexibility when ACS is unavailable or insufficient.

Inventive Principle:
Principle #15Dynamics

2Reliability

If different issuers contract with different ACSs, then authentication services are provided, but data availability for authentication is limited

Engineering Contradiction:
Improveauthentication service provisionVSAvoidauthentication data availability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The payment processing network merges authentication requests from multiple issuers contracting with different ACSs into a centralized processing flow. By consolidating the authentication request routing and data collection at the payment processing network level, the system aggregates data from multiple sources that would otherwise remain siloed across different ACS contracts, thereby improving data availability while maintaining the reliability of individual ACS services.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If SCA methods such as passwords are used, then consumer authentication is strengthened, but user friction increases and transactions are abandoned

Engineering Contradiction:
Improveconsumer authentication verificationVSAvoidtransaction completion ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Instead of universally applying strong consumer authentication (SCA) methods like passwords to all transactions, the system applies authentication selectively based on risk assessment. The payment processing network evaluates each transaction and applies SCA only when necessary, using partial action rather than excessive action. This approach maintains authentication reliability for high-risk transactions while preserving ease of operation for low-risk transactions, reducing unnecessary user friction and abandonment.

Inventive Principle:
Principle #16Partial or excessive action

4Measurement precision

If ACS performs sophisticated authentication procedures, then authentication accuracy improves, but system complexity and cost increase

Engineering Contradiction:
Improveauthentication accuracyVSAvoidauthentication system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The authentication system is segmented into multiple layers: the payment processing network handles request routing and basic coordination, while specialized ACS providers handle sophisticated authentication procedures when needed. This segmentation allows individual components to focus on specific functions, reducing overall system complexity while maintaining high authentication accuracy through specialized services. Rather than one system trying to do everything, the segmentation enables distributed sophistication.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3588422A1Systems and methods for authenticating online users
Publication Date: 2020.01.01 MASTERCARD INT INC
  • EP3588422A1 patent drawingFigure 1
  • EP3588422A1 patent drawingFigure 2
  • EP3588422A1 patent drawingFigure 3

AI summary

An authentication platform for authenticating an online user is provided. The authentication platform includes a memory device including an authentication profile and at least one processor coupled to the memory device. The at least one processor is programmed to receive an authentication request message for a transaction. The authentication request message includes authentication data. The at least one processor is also programmed to extract the authentication data from the authentication request message and determine if the ACS is available to process the transaction. If the ACS is unavailable, the at least one processor is further programmed to generate, based at least in part on the extracted authentication data, risk-based authentication (RBA) result data including a risk score and transmit an authentication response message based on the RBA result data.