Token-Based Transaction Authentication via Intermediary Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online and mobile payments face increased risks due to the lack of physical card presentation and fragmented authentication processes, which can lead to injection attacks and data security disruptions across multiple entities involved in transactions.

Innovation Solution

A token-based transaction authentication system that generates unique tokens by the payment processing network, merchant, and issuer to authenticate sending entities and verify messages, using payment reference identifiers (PRIDs) and consumer payment nicknames (CPNs) to identify authentication threads and defend against injection attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If fragmented authentication process with multiple redirections is used between merchant, issuer, and payment processing network, then sending entity authentication can be achieved, but the system becomes vulnerable to injection attacks and data security compromises

Engineering Contradiction:
Improveauthentication securityVSAvoidinjection attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a payment processing network as an intermediary that receives authentication requests from merchants, generates unique tokens, and manages the authentication flow between merchants and issuers. This centralized intermediary eliminates direct redirections between merchants and issuers, preventing injection attacks while maintaining authentication reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by generating unique tokens and authentication identifiers before the actual authentication transaction occurs. These pre-generated tokens are used to securely identify authentication threads and prevent injection attacks during the authentication process.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If multiple entities (merchant, issuer, payment processing network) process transactions simultaneously, then transaction throughput is improved, but message identification and entity identification become complex

Engineering Contradiction:
Improvetransaction throughputVSAvoidmessage identification complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into distinct, independently identifiable transactions using unique tokens and authentication identifiers. Each transaction is assigned a unique identifier that allows the payment processing network to track and manage multiple simultaneous authentication requests without confusion, simplifying message identification while maintaining high throughput.

Inventive Principle:
Principle #1Segmentation

3Reliability

If redirections between merchant and issuer are implemented for authentication, then sending entity verification is achieved, but loss of time occurs due to multiple redirections

Engineering Contradiction:
Improvesending entity verificationVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The payment processing network acts as a mediator that consolidates authentication logic, allowing verification to occur in a single redirected flow rather than multiple sequential redirections between merchant and issuer. This reduces authentication time while maintaining verification reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2526517B1Token based transaction authentication
Publication Date: 2018.08.08 VISA INTERNATIONAL SERVICE ASSOCIATION
  • EP2526517B1 patent drawingFigure 1
  • EP2526517B1 patent drawingFigure 2
  • EP2526517B1 patent drawingFigure 3

AI summary

A token based transaction authentication system is disclosed. Issuer, merchants, and a payment processing network generate unique tokens or keys to authenticate messages between themselves and to authenticate a sending entity or consumer as they are redirected between entities. The tokens are also used to identify the particular authentication thread a message or sending entity is associated with. The sending entity authentication occurs over a web-based channel or a mobile based channel.