Verification Token Enrollment for Mobile Payment Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Card not present transactions using mobile devices are prone to higher fraud risks and incur higher processing fees due to the lack of physical verification of the payment card, unlike card present transactions.

Innovation Solution

A method and system that generates and stores a verification token on a mobile device after an authorization request is sent to a server, allowing subsequent transactions to be processed as card present transactions, even without the typical security attributes of a physical payment card.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If card not present transactions are conducted using mobile devices, then convenience is improved, but fraud risk increases and processing fees increase

Engineering Contradiction:
Improveconvenience of mobile paymentVSAvoidfraud risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary verification during device enrollment by requiring the mobile device to successfully communicate with an access device and generate authorization requests before issuing the verification token. This preliminary action establishes trust and security attributes upfront, allowing subsequent transactions to be processed with enhanced reliability while maintaining convenience.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The verification token acts as an intermediary that bridges the gap between mobile device transactions and card present transaction security requirements. The token encapsulates security attributes and verification data, enabling the mobile device to transact as if it were a physical card with security features, thereby reducing fraud risk without sacrificing convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If card not present transactions are conducted using mobile devices, then convenience is improved, but processing fees increase

Engineering Contradiction:
Improveconvenience of mobile paymentVSAvoidprocessing fees
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The system changes the transaction classification parameter from 'card not present' to 'card present' by issuing a verification token that enables card present processing. This parameter change allows mobile device transactions to qualify for lower interchange fees associated with card present transactions, thereby reducing processing costs while maintaining the convenience of mobile payments.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If verification token is issued to mobile device, then transaction security is improved, but device enrollment complexity increases

Engineering Contradiction:
Improvetransaction securityVSAvoidenrollment process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The mobile device autonomously generates authorization requests and communicates with access devices during the enrollment process without requiring manual configuration or complex user intervention. The device self-verify its capabilities and receives the verification token automatically, simplifying the enrollment process while ensuring security through automated verification protocols.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11880815B2Device enrollment system and method
Publication Date: 2024.01.23 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11880815B2 patent drawing
  • US11880815B2 patent drawing
  • US11880815B2 patent drawing

AI summary

Embodiments related to systems and methods comprising receiving payment data at an access device; receiving an identifier for a mobile device at the access device; and generating and sending an authorization request message to a payment processing network, wherein the payment processing network generates a verification token, which is then sent to the mobile device whereby the mobile device is thereafter used to conduct payment transactions.