Token-Based Identity Verification for Online Payment Fraud

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online fraud, particularly involving unauthorized use of bank account and credit/debit card numbers, poses significant losses for online merchants due to the theft of private information and the use of account number generators, which existing technologies have not adequately addressed.

Innovation Solution

A system and method utilizing tokens generated by depository financial institution servers, associated with account holders, to facilitate online transactions, where these tokens are verified through a network involving depository financial institution servers, merchant/merchant aggregator servers, and financial network servers, using hash algorithms, digital signatures, and time-based rolling encryption to ensure secure authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If account holder information is shared during online transactions, then transaction convenience is improved, but security and fraud risk worsen

Engineering Contradiction:
Improvetransaction convenienceVSAvoidfraud risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the essential authentication function from the account holder's actual account information (card numbers, bank account details) and creates a separate token that represents the account holder's identity and authorization. This token can be shared during transactions without exposing the actual sensitive account information, thus maintaining transaction convenience while eliminating fraud risk from information exposure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a token as an intermediary element between the account holder and the transaction system. Instead of directly sharing account information, the token serves as a mediator that carries the necessary authentication data. The token can be verified by merchants and payment processors without revealing the underlying account details, resolving the contradiction between convenience and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional authentication methods are used, then ease of use is maintained, but fraud vulnerability increases

Engineering Contradiction:
Improveease of useVSAvoidfraud protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent creates a digital copy or representation of the account holder's authentication credentials in the form of a token. This token copy contains the necessary information to verify identity and authorize transactions but is not the actual sensitive data. The copy can be freely transmitted and verified without compromising the security of the original account information, thus maintaining ease of use while improving fraud protection.

Inventive Principle:
Principle #26Copying

3Productivity

If sensitive account information is transmitted, then transaction processing is simplified, but security risks worsen

Engineering Contradiction:
Improvetransaction processing efficiencyVSAvoidinformation theft risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the essential authentication elements from the full account information and embeds them in a token. This allows transaction processing to proceed efficiently with the token instead of requiring transmission of complete account details, thereby maintaining productivity while reducing the attack surface for information theft.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The token can be designed as a single-use or time-limited authentication credential that becomes invalid after verification or after a specific time period. This disposable nature means that even if intercepted, the token cannot be reused for fraud, thus maintaining transaction efficiency while eliminating the long-term security risks associated with reusable sensitive information.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS8838503B2Unified identity verification
Publication Date: 2014.09.16 PAYPAL INC
  • US8838503B2 patent drawing
  • US8838503B2 patent drawing
  • US8838503B2 patent drawing

AI summary

In some example embodiments, a system and method is shown that includes receiving a purchase request through an Electronic Payment Financial Network (EPFN), the purchase request including a token to identify a merchant server. The system and method further includes comparing the token against a merchant identifier value to determine that that token is assigned to the merchant server. Additionally, the system and method includes transmitting a purchase request authorization authorizing an online transaction, where the token and merchant identifier value are equivalent.