Token-Based Identity Verification for Online Payment Fraud
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Online fraud, particularly involving unauthorized use of bank account and credit/debit card numbers, poses significant losses for online merchants due to the theft of private information and the use of account number generators, which existing technologies have not adequately addressed.
Innovation Solution
A system and method utilizing tokens generated by depository financial institution servers, associated with account holders, to facilitate online transactions, where these tokens are verified through a network involving depository financial institution servers, merchant/merchant aggregator servers, and financial network servers, using hash algorithms, digital signatures, and time-based rolling encryption to ensure secure authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If account holder information is shared during online transactions, then transaction convenience is improved, but security and fraud risk worsen
Solution Approach 1:
The patent extracts the essential authentication function from the account holder's actual account information (card numbers, bank account details) and creates a separate token that represents the account holder's identity and authorization. This token can be shared during transactions without exposing the actual sensitive account information, thus maintaining transaction convenience while eliminating fraud risk from information exposure.
Solution Approach 2:
The patent introduces a token as an intermediary element between the account holder and the transaction system. Instead of directly sharing account information, the token serves as a mediator that carries the necessary authentication data. The token can be verified by merchants and payment processors without revealing the underlying account details, resolving the contradiction between convenience and security.
2Ease of operation
If traditional authentication methods are used, then ease of use is maintained, but fraud vulnerability increases
Solution Approach 1:
The patent creates a digital copy or representation of the account holder's authentication credentials in the form of a token. This token copy contains the necessary information to verify identity and authorize transactions but is not the actual sensitive data. The copy can be freely transmitted and verified without compromising the security of the original account information, thus maintaining ease of use while improving fraud protection.
3Productivity
If sensitive account information is transmitted, then transaction processing is simplified, but security risks worsen
Solution Approach 1:
The patent extracts only the essential authentication elements from the full account information and embeds them in a token. This allows transaction processing to proceed efficiently with the token instead of requiring transmission of complete account details, thereby maintaining productivity while reducing the attack surface for information theft.
Solution Approach 2:
The token can be designed as a single-use or time-limited authentication credential that becomes invalid after verification or after a specific time period. This disposable nature means that even if intercepted, the token cannot be reused for fraud, thus maintaining transaction efficiency while eliminating the long-term security risks associated with reusable sensitive information.
Data Source
AI summary
In some example embodiments, a system and method is shown that includes receiving a purchase request through an Electronic Payment Financial Network (EPFN), the purchase request including a token to identify a merchant server. The system and method further includes comparing the token against a merchant identifier value to determine that that token is assigned to the merchant server. Additionally, the system and method includes transmitting a purchase request authorization authorizing an online transaction, where the token and merchant identifier value are equivalent.


