Smart Payment Intermediary for Skimming Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The rise of e-commerce has shifted fraudulent activities from brick-and-mortar stores to card-not-present transactions, with a significant portion of credit card information theft occurring in restaurants, where consumers are vulnerable during payment processing, and current solutions are either expensive or require behavioral changes.

Innovation Solution

A method utilizing a smart device that receives transaction data from an access device, suspends the transaction, communicates with a portable device to obtain a cryptogram, and resumes the transaction with the access device, ensuring secure payment processing without direct communication between the access device and portable device, thereby preventing skimming and relay attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If consumers place their payment card in a folder for processing, then the transaction can be completed, but the card becomes vulnerable to skimming and relay attacks by malicious waitstaff

Engineering Contradiction:
Improvepayment convenienceVSAvoidcredential theft risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The smart folder acts as an intermediary device between the portable device and the access device. It receives transaction data from the access device, securely stores it temporarily, then retrieves and forwards the necessary data (cryptogram) to complete the transaction. This intermediary role prevents direct exposure of the portable device to the access device, eliminating skimming and relay attack vectors while maintaining payment convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a smart folder is implemented to secure transactions, then security is enhanced, but device complexity increases

Engineering Contradiction:
Improvetransaction securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The smart folder is designed as a multi-functional device that combines secure data storage, temporary data handling, and communication capabilities. It can store multiple types of data (transaction data, cryptograms), interface with different devices (access device, portable device), and perform various operations (receive, store, retrieve, forward). This universal design consolidates security functions into a single device rather than requiring multiple separate systems, thereby enhancing security while managing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the smart folder stores and forwards transaction data, then direct communication between access device and portable device is prevented, but communication overhead increases

Engineering Contradiction:
Improvesecurity against skimmingVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The smart folder performs preliminary actions by temporarily storing transaction data received from the access device before the portable device is ready. This pre-staging of data allows the subsequent data retrieval and forwarding operations to proceed quickly once the portable device is available, minimizing actual communication delays while maintaining security through the intermediary storage step.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230410108A1Smart device system and method of use
Publication Date: 2023.12.21 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US20230410108A1 patent drawing
  • US20230410108A1 patent drawing
  • US20230410108A1 patent drawing

AI summary

A smart device is provided between a transaction terminal (e.g. an access device, a point of sale terminal) and a payment card to facilitate a secure transaction. The smart device receives transaction details from the transaction terminal. The transaction terminal suspends the transaction. The smart device is brought in communication with a payment device in control of the user (e.g. the user of the payment device does not hand over the payment device to a merchant, clerk, waitstaff). The smart device receives a cryptogram identifying an account from the payment device and transmits the cryptogram to the transaction terminal. The transaction terminal resumes the transaction, generates a transaction authorization request message including the cryptogram, and transmits the transaction authorization request message to an issuer of the account. The transaction terminal receives an authorization response message from the issuer, and notifies the smart device of the transaction being approved or declined.