Transaction Authentication Platform Using Token-Based Multifactor Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multifactor authentication methods for payment cards, such as 3-D Secure, are inconvenient for users, leading to high opt-out rates and dissatisfaction, particularly in card-not-present transactions.
Innovation Solution
A method and system that associates a payment card with a personal computing device using a device activation code, generating tokens without storing the Primary Account Number (PAN), leveraging the device as a first factor in multifactor authentication, and utilizing additional hardware features for further authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If 3-D Secure authentication protocol is implemented with enrolment-based system, then security protection for card-not-present transactions is improved, but user convenience deteriorates leading to high opt-out rates
Solution Approach 1:
The patent performs ID&V and token issuance in advance before the actual transaction occurs. The cardholder's identity is verified and a payment token is issued during the enrolment phase, so that during the transaction the cardholder simply presents the token without undergoing additional authentication steps. This preliminary action eliminates the need for repeated authentication during transactions.
Solution Approach 2:
The patent creates a payment token that serves as a surrogate copy of the cardholder's identity and account information. Instead of requiring the cardholder to repeatedly present their actual card or undergo authentication, the system uses this token copy which can be easily transmitted electronically for transactions, thereby improving convenience while maintaining security.
2Reliability
If multifactor authentication with multiple verification steps is implemented, then fraud protection is improved, but transaction processing time increases
Solution Approach 1:
The patent performs the complex multifactor authentication and ID&V process in advance during the token issuance phase. Once the token is issued, subsequent transactions simply require presenting this pre-validated token, eliminating the need to repeat the time-consuming authentication steps for each transaction while maintaining the same level of fraud protection.
3Reliability
If cardholder enrolment process is made mandatory, then authentication security is improved, but user satisfaction deteriorates leading to abandonment of purchases
Solution Approach 1:
The patent enables cardholders to enrol and receive their payment tokens through an automated self-service process. The system guides cardholders through the ID&V and token issuance steps without requiring extensive manual intervention or complex interactions with customer service representatives, thereby improving user satisfaction while maintaining security standards.
Solution Approach 2:
The patent performs the enrolment and token issuance as a preliminary one-time action that enables all future transactions. Once the cardholder completes the enrolment process and receives their token, they can make purchases without repeatedly going through the enrolment steps, significantly improving user satisfaction and reducing purchase abandonment.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method and system are disclosed in an electronic payment network, for associating a payment card of a cardholder with a personal computing device of the cardholder, then authenticating the payment card in electronic transactions processed in the network. The card and a device activation code are input to the cardholder device by the cardholder, then communicated sent to a remote server for obtaining a card token. The server generates a device token and an authorisation token, stores the generated tokens together with the card token, and sends the card and device tokens to the cardholder device for storage. Whenever a transaction is processed in the network, the payment card is authenticated by inputting authenticating data to the cardholder device for generating an authorisation token, which is sent to the server with the stored card and device tokens, for a matching operation against the card, device and authorisation tokens at the server.