Token Authentication Cryptogram Generation for Secure Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems for online transactions are inefficient due to dependency on separate cryptogram generation systems and lack of flexibility, leading to increased transaction friction and security risks.

Innovation Solution

A method where a service provider computer generates and sends a token authentication cryptogram derived from user-exclusive data, allowing for secure and flexible authentication within the transaction process, enabling the extraction of user data for validation purposes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a separate token generation service is used to create cryptograms, then authentication security is improved, but transaction efficiency deteriorates due to system dependency and additional processing steps

Engineering Contradiction:
Improveauthentication securityVSAvoidtransaction efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines the token generation service and transaction requestor into a single system. The service provider computer both requests tokens and generates cryptograms, eliminating the need for a separate external token generation service. This integration removes system dependency and reduces processing steps, thereby improving transaction efficiency while maintaining authentication security through the same cryptographic mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If cryptogram generation is performed by an external system, then authentication verification is improved, but system complexity increases due to multiple independent components

Engineering Contradiction:
Improveauthentication verificationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the token generation service and transaction requestor into a single service provider computer system. This consolidation reduces the number of independent components from multiple external systems to one integrated system, thereby reducing system complexity while maintaining authentication verification capabilities through the unified cryptogram generation process.

Inventive Principle:
Principle #5Merging (Combining)

3Device complexity

If predefined rules are used for cryptogram generation, then system simplicity is improved, but adaptability deteriorates as the requestor has no influence over authentication parameters

Engineering Contradiction:
Improvesystem simplicityVSAvoidauthentication flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic cryptogram generation where the service provider computer can adapt authentication parameters based on specific transaction requirements. Instead of rigid predefined rules, the system dynamically determines cryptogram generation parameters, allowing the requestor to influence authentication processes while maintaining system simplicity through a unified control mechanism.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12170730B2Unique token authentication verification value
Publication Date: 2024.12.17 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US12170730B2 patent drawing
  • US12170730B2 patent drawing
  • US12170730B2 patent drawing

AI summary

Embodiments of the invention are directed to systems and methods for validating transactions using a cryptogram. One embodiment of the invention is directed to a method of processing a remote transaction initiated by a communication device provisioned with a token. The method comprises receiving, by a service provider computer, from an application on the communication device, a request for a token authentication cryptogram, wherein the token authentication cryptogram includes encrypted user exclusive data. The service provider computer may generate the token authentication cryptogram to include the user exclusive data. The service provider computer may send the token authentication cryptogram to the application, where the token authentication cryptogram can be used to validate the transaction, and the user exclusive data is extracted from the token authentication cryptogram during validation.