Risk-Based Decisioning System for Payment Fraud Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for detecting fraud in payment transactions rely heavily on device fingerprints and transaction attributes, but they can only provide a trust score for specific transactions and lack comprehensive risk assessment, especially when transactions deviate from a cardholder's usual patterns or profile.
Innovation Solution
A risk-based decisioning system that allows merchants to assess fraud risk through a separate authentication request, incorporating device IDs and PAN information, and includes a mechanism to pass merchant fraud scores and reason codes to issuers, enabling a more robust trust evaluation and authorization process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current systems use device fingerprints and transaction attributes to detect fraud, then fraud detection capability is improved, but comprehensive risk assessment is insufficient especially when transactions deviate from cardholder patterns
Solution Approach 1:
The system segments the fraud detection process into two distinct phases: authentication (separate authentication request evaluating device fingerprint, IP address, and transaction attributes) and authorization (separate authorization request evaluating cardholder credentials and account status). This segmentation allows each phase to focus on specific risk factors, improving both detection reliability and adaptability to different transaction scenarios.
Solution Approach 2:
The patent introduces an intermediary authentication service between the merchant and the authorization system. This intermediary evaluates device fingerprints, IP addresses, and transaction attributes to generate an authentication score, which then informs the authorization decision. This intermediary layer enables comprehensive risk assessment without compromising the existing authorization flow.
2Reliability
If a separate authentication request is implemented before authorization, then trust evaluation is improved, but transaction processing time increases
Solution Approach 1:
The system performs preliminary authentication actions by evaluating device fingerprint, IP address, and transaction attributes before the formal authorization request. This preliminary assessment identifies high-risk transactions that require full authentication, while low-risk transactions can proceed with standard authorization, thus improving trust evaluation without uniformly increasing processing time for all transactions.
Solution Approach 2:
The authentication process is implemented as a partial action rather than a complete separate workflow. The authentication service provides a score that may be sufficient for low-risk transactions, allowing the system to use only part of the authentication evaluation before proceeding to authorization. This approach improves trust evaluation while minimizing additional processing time by avoiding full authentication for all transactions.
3Reliability
If merchant fraud scores and reason codes are passed to issuers, then fraud prevention is improved, but system complexity increases
Solution Approach 1:
The authentication service is designed as a universal component that can be integrated into existing authorization flows without requiring separate dedicated systems. The same authentication service that evaluates device fingerprints also generates scores used in authorization decisions, and the infrastructure for passing fraud scores and reason codes leverages existing message exchange protocols between merchants and issuers, thus improving fraud prevention while minimizing system complexity.
Data Source
AI summary
A method and system for creating an assurance level based on authentication data attributes using a computer device coupled to a database are provided. The method includes receiving an authorization request associated with the financial transaction from the sender, the authorization request including a fraud risk assessment of the financial transaction determined by the sender using an authentication response received from the computer device by the sender, the authorization request including one or more reason codes associated with the sender fraud risk assessment. The method further includes transmitting the received authorization request to an issuer associated with the cardholder.


