Risk-Based Authentication Platform for Payment Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication systems for online transactions, particularly in electronic payment networks, face challenges such as high costs, limited data access, and lack of sophisticated authentication capabilities in Access Control Servers (ACS), leading to increased fraud and user friction, especially in card-not-present transactions.
Innovation Solution
An authentication platform that performs risk-based authentication (RBA) on behalf of ACSs, using a directory server and RBA engine to generate risk scores and reason codes, allowing for more accurate and timely authentication decisions, even when ACSs are unavailable, by leveraging a comprehensive data set including historical transaction data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Access Control Servers (ACS) are used for authentication services, then authentication capability is provided, but the system becomes dependent on ACS availability and sophistication
Solution Approach 1:
The payment processing network acts as an intermediary between merchants/issuers and ACS providers. It receives authentication requests, determines whether an ACS is available and capable, and routes requests accordingly. This intermediary role allows the system to maintain reliability through ACS when available while adapting to its unavailability or insufficient capability by using alternative authentication methods.
Solution Approach 2:
The authentication system dynamically adjusts its behavior based on ACS availability and capability. The payment processing network continuously assesses whether an ACS is available and sophisticated enough to handle the authentication request, and switches between ACS-based authentication and alternative methods accordingly. This dynamic adaptation resolves the contradiction between relying on ACS for reliability and needing flexibility when ACS is unavailable or insufficient.
2Reliability
If different issuers contract with different ACSs, then authentication services are provided, but data availability for authentication is limited
Solution Approach 1:
The payment processing network merges authentication requests from multiple issuers contracting with different ACSs into a centralized processing flow. By consolidating the authentication request routing and data collection at the payment processing network level, the system aggregates data from multiple sources that would otherwise remain siloed across different ACS contracts, thereby improving data availability while maintaining the reliability of individual ACS services.
3Reliability
If SCA methods such as passwords are used, then consumer authentication is strengthened, but user friction increases and transactions are abandoned
Solution Approach 1:
Instead of universally applying strong consumer authentication (SCA) methods like passwords to all transactions, the system applies authentication selectively based on risk assessment. The payment processing network evaluates each transaction and applies SCA only when necessary, using partial action rather than excessive action. This approach maintains authentication reliability for high-risk transactions while preserving ease of operation for low-risk transactions, reducing unnecessary user friction and abandonment.
4Measurement precision
If ACS performs sophisticated authentication procedures, then authentication accuracy improves, but system complexity and cost increase
Solution Approach 1:
The authentication system is segmented into multiple layers: the payment processing network handles request routing and basic coordination, while specialized ACS providers handle sophisticated authentication procedures when needed. This segmentation allows individual components to focus on specific functions, reducing overall system complexity while maintaining high authentication accuracy through specialized services. Rather than one system trying to do everything, the segmentation enables distributed sophistication.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An authentication platform for authenticating an online user is provided. The authentication platform includes a memory device including an authentication profile and at least one processor coupled to the memory device. The at least one processor is programmed to receive an authentication request message for a transaction. The authentication request message includes authentication data. The at least one processor is also programmed to extract the authentication data from the authentication request message and determine if the ACS is available to process the transaction. If the ACS is unavailable, the at least one processor is further programmed to generate, based at least in part on the extracted authentication data, risk-based authentication (RBA) result data including a risk score and transmit an authentication response message based on the RBA result data.