Token Authentication Cryptogram Generation for Secure Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication systems for online transactions are inefficient due to dependency on separate cryptogram generation systems and lack of flexibility, leading to increased transaction friction and security risks.
Innovation Solution
A method where a service provider computer generates and sends a token authentication cryptogram derived from user-exclusive data, allowing for secure and flexible authentication within the transaction process, enabling the extraction of user data for validation purposes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a separate token generation service is used to create cryptograms, then authentication security is improved, but transaction efficiency deteriorates due to system dependency and additional processing steps
Solution Approach 1:
The patent combines the token generation service and transaction requestor into a single system. The service provider computer both requests tokens and generates cryptograms, eliminating the need for a separate external token generation service. This integration removes system dependency and reduces processing steps, thereby improving transaction efficiency while maintaining authentication security through the same cryptographic mechanisms.
2Reliability
If cryptogram generation is performed by an external system, then authentication verification is improved, but system complexity increases due to multiple independent components
Solution Approach 1:
The patent merges the token generation service and transaction requestor into a single service provider computer system. This consolidation reduces the number of independent components from multiple external systems to one integrated system, thereby reducing system complexity while maintaining authentication verification capabilities through the unified cryptogram generation process.
3Device complexity
If predefined rules are used for cryptogram generation, then system simplicity is improved, but adaptability deteriorates as the requestor has no influence over authentication parameters
Solution Approach 1:
The patent implements dynamic cryptogram generation where the service provider computer can adapt authentication parameters based on specific transaction requirements. Instead of rigid predefined rules, the system dynamically determines cryptogram generation parameters, allowing the requestor to influence authentication processes while maintaining system simplicity through a unified control mechanism.
Data Source
AI summary
Embodiments of the invention are directed to systems and methods for validating transactions using a cryptogram. One embodiment of the invention is directed to a method of processing a remote transaction initiated by a communication device provisioned with a token. The method comprises receiving, by a service provider computer, from an application on the communication device, a request for a token authentication cryptogram, wherein the token authentication cryptogram includes encrypted user exclusive data. The service provider computer may generate the token authentication cryptogram to include the user exclusive data. The service provider computer may send the token authentication cryptogram to the application, where the token authentication cryptogram can be used to validate the transaction, and the user exclusive data is extracted from the token authentication cryptogram during validation.


