Verification Token for Portable Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The credit card industry faces challenges in preventing fraud, particularly with skimming in static magnetic stripe-based transactions, which becomes more prevalent in wireless environments where counterfeit cards can be created without physical possession of the card, and existing solutions like dynamic card verification values (dCVV) may inconvenience users, reducing transaction frequency.

Innovation Solution

A verification token system that reads identification information from portable consumer devices, securely transmits it to a validation entity, and receives a device verification value, ensuring authentication through mutual authentication processes and secure encryption, thereby reducing fraud without significantly impacting the user experience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dynamic card verification values (dCVV) are used to prevent skimming fraud, then fraud prevention capability is improved, but user convenience deteriorates due to additional steps required to receive and use the dCVV

Engineering Contradiction:
Improvefraud prevention capabilityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically performs the dCVV generation and delivery process without requiring manual user intervention. The verification token reads device identification information, communicates with the validation entity, and obtains the dCVV automatically, making the system self-serving and eliminating the need for users to manually receive or enter verification values.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A verification token is introduced as an intermediary device between the user's portable consumer device and the validation entity. This token handles the complex authentication process by reading device information, communicating with validation entities, and obtaining dCVV values, thereby shielding the user from the complexity of the fraud prevention mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If verification processes are made more secure through mutual authentication and encryption, then transaction security is improved, but system complexity increases

Engineering Contradiction:
Improvetransaction securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification token serves as an intermediary that encapsulates the complex authentication and encryption logic. It handles mutual authentication with validation entities and secure transmission of device identification information, thereby isolating the complexity from the user and portable consumer devices while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The verification system is segmented into distinct functional components: the verification token that handles device authentication, the validation entity that performs security validation, and the portable consumer device that provides identification information. This segmentation allows each component to be optimized independently and simplifies the overall system architecture.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9904919B2Verification of portable consumer devices
Publication Date: 2018.02.27 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US9904919B2 patent drawing
  • US9904919B2 patent drawing
  • US9904919B2 patent drawing

AI summary

Apparatuses, methods, and systems pertaining to the verification of portable consumer devices are disclosed. In one implementation, a verification token is coupled to a computer by a USB connection so as to use the computer's networking facilities. The verification token reads identification information from a user's portable consumer device (e.g., credit card) and sends the information to a validation entry over a communications network using the computer's networking facilities. The validation entity applies one or more validation tests to the information that it receives from the verification token. If a selected number of tests are passed, the validation entity sends a device verification value to the verification token, and optionally to a payment processing network. The verification token may enter the device verification value into a CVV field of a web page appearing on the computer's display, or may display the value to the user using the computer's display.