A pragmatic approach to temporary payment card numbers

  • Authors:
  • David J. Boyd

  • Affiliations:
  • Information Security Group, Royal Holloway, University of London, Egham, Surrey TW20 0EX, UK

  • Venue:
  • International Journal of Electronic Security and Digital Forensics
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

With the push towards electronic payments that use a smart card and authenticate the cardholder by his or her personal identification number, much fraud has switched to the residual payment methods that just rely on knowing the card number: card-not-present transactions. There are various countermeasures; notably some issuers allocate temporary card numbers (TCNs). The snag is that this is an online solution that requires the cardholder to be identified and authenticated over a separate and direct link between the cardholder and card issuer each time a number is allocated. Some off-line mechanisms have been proposed but those TCNs do not act as the cardholder's identifier. This paper examines a sample of online and off-line TCN mechanisms and then proposes an off-line mechanism that gives a comparable service to the online mechanisms. The cardholder's privacy is protected whilst still allowing proof of payment.