摘要:
A transaction security process includes authentication and identification parts for pushing an encrypted colorgram for user authentication and persona descriptors for user identification from a transaction server to a first personal trusted device. A decryption of the colorgram is displayed on the first personal trusted device. An image is captured by a second personal trusted device. An encryption of the image captured from the second personal trusted device is uploaded to the transaction server. The persona descriptors are used to build a composite rendering for identification of the first user to the second user. The second user clicks “OK” if they recognize the composite drawing as a reasonable persona of the first user.
摘要:
A thin-client access card has a card body with partial or fully emissive magnetic data tracks. An emissive element is disposed in the card body under the location of the legacy magnetic data tracks. An electronic signal conditioner converts audio signals from a mobile device into magnetic data applied to the emissive element. A swipe sensor detects when the thin-client access card is being swiped by a legacy card reader, and triggers an output of magnetic data from the emissive element while proximal to the POS reader head. A cable attaches the thin-client access card as a peripheral to the mobile device with an audio output jack.
摘要:
A method for securing financial transactions involving payment cards includes associating a sixteen-digit personal account number (PAN) with a particular payment card and user, wherein are included fields for a system number, a bank/product number, a user account number, and a check digit. A four-digit expiration date (MMYY) associated with the PAN. A magnetic stripe on the payment card is encoded with the PAN for periodic reading by a magnetic card reader during a financial transaction. A table of cryptographic values associated with the PAN and the MMYY is stored on each user's payment card during personalization by an issuing bank. A next financial transaction being commenced with the payment card is sensed. A cryptographic value from the table of cryptographic values is selected for inclusion as a dynamic portion of the user account number with the PAN when a next financial transaction is sensed. Any cryptographic value from the table of cryptographic values will not be used again in another financial transaction after being used once. The issuing bank authorizes the next financial transaction only if the PAN includes a correct cryptographic value in the user account number field.
摘要:
A financial transaction payment processor includes an account access request processor for receiving dynamic swipe data from a payment card through a merchant infrastructure. A fraud detection processor is connected to analyze a dynamic data obtained by the account access request processor that should agree with values pre-loaded in a Crypto-Table by a card manufacturer. A payment authorization processor is connected to receive a message from the fraud detection processor and to then forward a response to the merchant infrastructure.
摘要:
A method for validating a payment card financial transaction includes receiving a financial transaction approval request message derived from a payment card that is able to change its magnetic card data as elicited by a card reader. Out-of-sequence transactions encoded in a dynamic number included in said magnetic card data are detected. The dynamic number is compared with a last valid number that was previously stored in a database. An approval message is issued to enable the completion of a financial transaction with the payment card.
摘要:
An adaptor allows a magnetic stripe card reader to receive information from other media such as wireless proximity chip cards while maintaining the ability to receive a magnetic stripe card. In accordance with one embodiment, the adaptor includes a simulacrum structure of sufficiently narrow width to fit substantially permanently within the slot of the magnetic stripe reading device, while providing sufficient room for a magnetic stripe card to also be concurrently accommodated within the slot and read by the reader head. The simulacrum structure may be in electronic communication with one or more transceivers of wireless communications such as RF and IR.
摘要:
Data and financial transactions are secured on a mobile electronics device, with three downloadable modules. A first module provides for the mobile electronics device and a network server to interactively register a cryptographic abstract of an object usually carried by the user. These objects represent physical passwords from which processing can derive characterizing information. A second module is invoked by a transaction and signals the mobile electronics device to collect a new sample of the physical password. A cryptographic abstract of it is distilled and compared to preregistered cryptographic abstracts. A third module is a key recovery process for use when the preregistered physical password sound or object is no longer available to the user.
摘要:
A method for validating a payment card financial transaction includes receiving a financial transaction approval request message derived from a payment card that is able to change its magnetic card data as elicited by a card reader. Out-of-sequence transactions encoded in a dynamic number included in said magnetic card data are detected. The dynamic number is compared with a last valid number that was previously stored in a database. An approval message is issued to enable the completion of a financial transaction with the payment card.
摘要:
A payment card comprises a plastic card and operates with three different legacy payment systems. A magnetic stripe with user account data allows card use in traditional point-of-sale magnetic card readers. A dual-input crypto-processor embedded in the card provides for contact/contactless smart card operation. A user input provides for user authentication by the crypto-processor. Internal to the plastic card, and behind the magnetic stripe, a magnetic array includes a number of fixed-position magnetic write heads that allow the user account data to be automatically modified by the crypto-processor.
摘要:
A payment card comprises a display to support card-not-present transactions where no card reader is available to automate the transaction, and an account number retrieval method for dynamic, one-time use virtual account numbers whose use can assist authorities in rapid fraud and location detection. The account number generator is able to produce a sequence of virtual account numbers over its life that are predictable by the issuing bank and useful in authenticating transactions. A server for the issuing bank logs the merchant locations associated with each use or attempted use, and provides real-time detection of fraudulent attempts to use a virtual account number outside the predicted set. Fraud identification efforts can then be directed in a timely and useful way.