Secure Payment Authentication via Intermediary Gateway
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for securing Internet transactions lack effective authentication of user identities, leading to high levels of chargebacks and consumer distrust due to the risk of fraud and theft of payment card details, which discourages both customers and merchants from participating in online commerce.
Innovation Solution
A system comprising a secure data entry device connected to a public network and a gateway device that transmits identifying information securely to the card-issuing financial institution for verification, using ISO 8583 message formats and encryption to authenticate the user and generate a replacement card number for secure transactions, ensuring that actual card details are never transmitted insecurely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If customer card details are transmitted over public networks for Internet transactions, then payment convenience is improved, but security and fraud risk worsen
Solution Approach 1:
The patent introduces an intermediary authentication system between the customer and merchant that verifies cardholder presence without exposing card details. The system uses an authentication server that receives transaction requests, verifies the cardholder's presence through secure channels, and returns authentication results without transmitting actual card numbers over public networks.
Solution Approach 2:
The patent extracts the authentication function from the traditional card detail transmission process. Instead of transmitting card details and relying on merchants to verify them, the system separates the authentication step into a dedicated secure verification process that occurs before the actual transaction, removing card details from the public network transmission path.
2Productivity
If merchants store customer card details for repeat purchases, then transaction speed is improved, but risk of theft and fraud worsens
Solution Approach 1:
The patent creates a secure copy mechanism where authentication results are cached for repeat transactions. Instead of storing actual card details, the system stores authenticated session tokens or references that can be quickly verified without exposing sensitive information. This allows fast repeat transactions while maintaining security through the use of cryptographic tokens rather than actual card data.
3Device complexity
If traditional authentication methods are used without verification of cardholder presence, then system simplicity is maintained, but chargeback rates increase
Solution Approach 1:
The patent implements preliminary authentication before the actual transaction occurs. The system performs cardholder presence verification as a pre-requisite step, obtaining authentication confirmation from the cardholder's financial institution before authorizing the transaction. This preliminary action prevents chargebacks by ensuring the cardholder was present and authorized the transaction before funds are transferred.
Data Source
AI summary
A system for the authentication by a card-issuing financial institution of identifying information of a card-holding user of a public data network. The system includes a secure data entry device connected to the public data network and a gateway device connected to the public data network and to a private data network used for transmitting messages between financial institutions. The secure data entry device enables the user to enter identifying information of a card issued by the card-issuing financial institution, and transmits the identifying information in a secure manner over the public data network to the gateway device. The gateway device transmits the identifying information to the card-issuing financial institution and receives an approval response from the card-issuing financial institution over the private data network. The approval response provides authentication of the identifying information by the card-issuing financial institution.


