Verification Token for Secure Payment Data Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The persistence of fraud and counterfeiting in financial transactions, particularly with magnetic stripe-based transactions, due to the passive nature of magnetic stripes which can be easily copied, and the increased risk in wireless environments where skimming can occur without physical possession of the card.

Innovation Solution

A verification token that reads identification information from portable consumer devices and securely transmits it to a validation entity, which validates the information before sending it to merchants, using encryption and dynamic verification values to enhance security and prevent fraud.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If magnetic stripe-based transactions are used, then ease of operation is improved, but reliability deteriorates due to easy copying and fraud

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transforms the static magnetic stripe data into dynamic verification tokens that change with each transaction. The verification token includes a dynamic verification value that is regenerated for each transaction attempt, making each transaction unique and preventing replay attacks. This dynamic approach maintains ease of operation while significantly improving reliability by preventing fraud through copying.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the fundamental parameter of data stability by introducing ephemeral verification tokens that expire after use. Instead of relying on static magnetic stripe data that can be copied indefinitely, the system uses tokens with limited validity periods and changing verification values, thereby improving reliability without compromising the ease of operation.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If wireless transaction environment is used, then ease of operation is improved, but object-affected harmful factors increase due to interception risks

Engineering Contradiction:
Improveease of operationVSAvoidinterception risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by pre-authenticating the verification token before wireless transmission. The token is validated by the payment processing system before being sent wirelessly to the merchant, establishing authenticity in advance. This preliminary validation prevents interception attacks because even if the token is captured during wireless transmission, it has already been authenticated and includes dynamic verification values that prevent reuse.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent introduces the verification token as an intermediary between the consumer's portable device and the merchant's payment system. This intermediary layer secures the wireless communication by encapsulating sensitive payment information within the token structure, which includes encryption and validation mechanisms that protect against interception while maintaining ease of wireless operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If dynamic verification values are implemented, then reliability is improved, but device complexity increases

Engineering Contradiction:
ImprovereliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex dynamic verification logic from the consumer's portable device and places it in the payment processing system. The portable device only needs to store and transmit the verification token, while the complex generation and validation of dynamic verification values occurs server-side. This extraction maintains reliability through dynamic verification while minimizing the complexity burden on the consumer device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The verification token is designed to be self-validating, containing within its structure the necessary information for authentication. The token includes embedded verification data that allows the payment processing system to validate it without requiring complex client-side verification logic. This self-service approach improves reliability through dynamic verification while keeping the device implementation simple.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10049360B2Secure communication of payment information to merchants using a verification token
Publication Date: 2018.08.14 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US10049360B2 patent drawing
  • US10049360B2 patent drawing
  • US10049360B2 patent drawing

AI summary

Disclosed are apparatuses, systems, and methods pertaining to the secure communication of payment information from portable consumer devices, such as credit cards, to online merchants using verification tokens.