Token-Based Transaction Authentication in Untrusted Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current transaction security methods are inadequate for untrusted environments, such as e-commerce and non-traditional devices, as they rely on trusted networks and are vulnerable to skimming attacks, especially with the rise of remote networking technologies, leading to increased fraud risks.
Innovation Solution
A token-based system that provides authentication through a unique identifier and public-key signature, allowing information requestors to verify transactions securely even in untrusted environments by deriving the appropriate information provider and obtaining authorization from the issuer, ensuring the integrity of transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If transactions are conducted over public networks like the Internet, then convenience and accessibility are improved, but security and vulnerability to fraud worsen
Solution Approach 1:
The patent introduces a token as an intermediary device between the cardholder and the transaction network. The token receives authentication requests, generates dynamic verification values, and communicates with the authorization system, thereby mediating the interaction and enabling secure transactions over public networks without requiring direct trusted connections between all parties
Solution Approach 2:
The patent transforms static card data into dynamic verification values that change with each transaction. The token generates unique authentication data for each transaction based on the requestor's identity and other parameters, making each transaction credential unique and preventing reuse of captured data from previous transactions
2Reliability
If dynamic verification values are used, then security against skimming attacks is improved, but device complexity worsens
Solution Approach 1:
The patent extracts the complex cryptographic verification logic from the cardholder's device and places it within the token device. The token contains the authentication application and generates verification values, while the cardholder's device only needs to present the token and receive authorization decisions, thereby reducing the complexity burden on the cardholder's system
Solution Approach 2:
The token autonomously generates dynamic verification values and manages authentication without requiring complex user input or management from the cardholder. The token self-manages the authentication process by receiving requests, generating appropriate verification data, and communicating with the authorization system, making the complex security mechanism transparent to the user
Data Source
AI summary
To secure communications in an untrusted environment for a commercial transaction on an account between the account's holder and a merchant, an identifier and a signature can be derived from a token. The identifier is associated by use of a directory with an application context that identifies the account's issuer. The merchant will provide the signature to the account's issuer, or agent thereof, to be verified. In practice, a merchant to the identified issuer of an account an authorization request message for a transaction that includes a signature and an identifier for the account upon which the transaction is to be conducted. The account's issuer responds with an authorization response message that includes an indicator that the signature has been verified. After notice of the signature's verification, the transaction on the account is deemed authorized and the merchant can proceed.


