Transaction Security Testing for Fraudulent Authorization Flows

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing payment transaction systems, particularly those following the four-party model, are vulnerable to security vulnerabilities such as configuration issues, incomplete system implementation, and software coding errors, which can lead to fraudulent transactions.

Innovation Solution

A computer security device that analyzes configuration data of the transaction processing system, generates fraudulent transaction emulating messages, and analyzes response messages to identify and address security vulnerabilities, including configuration issues and software coding errors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the transaction processing system processes transactions without comprehensive security checks, then the processing speed and productivity are improved, but the system becomes vulnerable to fraudulent transactions and security breaches

Engineering Contradiction:
Improvetransaction processing speedVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary security assessments by analyzing configuration data before processing transactions to identify potential vulnerabilities. This proactive approach allows the system to detect and address security issues in advance, maintaining both high processing speed and security reliability without requiring comprehensive checks on every transaction.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary security assessment layer that analyzes configuration data and generates vulnerability reports separately from the main transaction processing flow. This intermediary component enables the system to maintain high transaction processing speed while simultaneously ensuring security reliability through independent vulnerability detection and remediation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system implements comprehensive security vulnerability detection and analysis, then the security reliability is improved, but the device complexity and operational overhead increase

Engineering Contradiction:
Improvesecurity vulnerability detectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts the security vulnerability detection function as a separate, dedicated component that analyzes configuration data independently from the main transaction processing system. This extraction reduces the complexity of the overall system by isolating the security assessment functionality, making it easier to implement and maintain comprehensive security checks without overwhelming the core transaction processing infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If the system analyzes configuration data to identify security vulnerabilities, then the security reliability is improved, but the processing time and operational duration increase

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidconfiguration analysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs configuration data analysis as a preliminary action before transaction processing begins. By conducting security vulnerability assessments in advance and maintaining updated vulnerability reports, the system avoids time-consuming analysis during active transaction processing, thus improving security reliability without significantly increasing operational delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements periodic security assessments by analyzing configuration data at scheduled intervals and maintaining current vulnerability reports. This periodic approach ensures continuous security reliability through regular updates while minimizing the time impact on transaction processing, as the analysis is performed periodically rather than continuously during operations.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP3671614B1Computer security device
Publication Date: 2026.03.25 MASTERCARD INT INC
  • EP3671614B1 patent drawingFigure 1
  • EP3671614B1 patent drawingFigure 2~3
  • EP3671614B1 patent drawingFigure 4

AI summary

A computer security device (254) for detecting security vulnerabilities in a transaction processing system (130), the device comprising: an input (257) arranged to receive configuration data relating to the transaction processing system; a communications interface (259) arranged to output transaction authorisation request messages for processing by the transaction processing system and to receive authorisation response messages from the transaction processing system; a processor (255) arranged to: analyse (308) the received configuration data relating to the transaction processing system and to determine one or more fraudulent transaction types that the transaction processing system is potentially vulnerable to; generate (310) one or more transaction authorisation request messages emulating the determined one or more fraudulent transaction types; output (312) the one or more generated transaction authorisation request messages via the communications interface to the transaction processing system; analyse (330) any authorisation response messages from the transaction processing system received via the communications interface to identify the presence of security vulnerability issues in the transaction processing system.