Browser Extension Payment Data Capture via Proxy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional solutions for Hosted Payment Pages (HPPs) in contact centers are inconvenient and fragile, requiring site-specific modifications and certificates, which can conflict with business requirements and break integration due to the need for a modifying proxy to decrypt and modify payment page traffic.

Innovation Solution

A system that uses browser extensions to inject code and data into web pages, allowing agents to choose input elements for data capture, redirecting requests to a payment proxy for data modification, and utilizing dynamic tokens or placeholders to handle payment page submissions without requiring extensive proxy configuration or site-specific modifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a modifying proxy is used to intercept and modify payment page traffic, then secure data capture is achieved, but the system becomes complex and fragile requiring site-specific modifications and certificates

Engineering Contradiction:
Improvesecure data captureVSAvoidproxy configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a modifying proxy as an intermediary component that sits between the agent's browser and the payment page server. This proxy intercepts HTTP requests, modifies them by injecting captured payment data, and forwards them to the destination. The proxy acts as a mediator that enables secure data capture without requiring changes to the merchant's payment system, thus resolving the contradiction by accepting the complexity of proxy configuration as the trade-off for achieving reliable secure data capture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-configuring the modifying proxy with payment data capture capabilities before actual payment transactions occur. The proxy is set up in advance to intercept and capture payment information from voice communications, store it securely, and have it ready for injection when payment pages are accessed. This preliminary preparation enables reliable secure data capture while managing complexity through advance setup rather than ad-hoc configuration.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a modifying proxy is deployed to capture payment data, then data security is improved, but the system becomes fragile and may break integration due to site-specific modifications

Engineering Contradiction:
Improvedata securityVSAvoidintegration compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the payment data capture process into distinct functional components: the modifying proxy handles data injection, the payment data capture facility captures voice-based payment information, and the agent's browser handles user interaction. This segmentation allows each component to operate independently with well-defined interfaces, improving data security while reducing fragility. The proxy only needs to understand the general structure of payment forms, not specific site implementations, thereby maintaining integration compatibility across different merchants.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The modifying proxy is designed with universal functionality to handle multiple different payment page formats and protocols. Rather than requiring site-specific configuration for each merchant, the proxy uses general patterns to identify and modify payment forms across different websites. This multi-functionality approach maintains data security through centralized control while improving adaptability to various payment scenarios without breaking integrations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If certificates are added to the agent's PC trust store for proxy decryption, then secure communication is achieved, but ease of operation deteriorates due to certificate management requirements

Engineering Contradiction:
Improvesecure communicationVSAvoidcertificate management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the certificate management function into the modifying proxy itself rather than requiring separate certificate installation on each agent's PC. The proxy handles SSL/TLS decryption and certificate validation centrally, combining multiple security functions into a single component. This approach maintains secure communication through proper certificate handling while eliminating the operational burden of distributing and managing certificates across multiple client machines.

Inventive Principle:
Principle #5Merging (Combining)

4Ease of manufacture

If site-specific modifications are made to payment page code, then data capture functionality is achieved, but the system becomes fragile and time-consuming to maintain

Engineering Contradiction:
Improvedata capture functionalityVSAvoidcode modification complexity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The modifying proxy serves as an intermediary that eliminates the need for site-specific code modifications to payment pages. Instead of altering merchant code, the proxy intercepts and modifies HTTP traffic at the network level, injecting captured payment data into forms automatically. This approach achieves data capture functionality while avoiding the complexity and fragility of modifying payment page code for each site, as the proxy handles adaptations centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240232397A9Secure data capture systems and methods
Publication Date: 2024.07.11 SYNTEC HLDG
  • US20240232397A9 patent drawing
  • US20240232397A9 patent drawing
  • US20240232397A9 patent drawing

AI summary

Methods comprising steps for processing data for a customer-agent interaction are disclosed, as well as systems configured to perform such steps. These steps may comprise retrieving a web form comprising one or more elements, from a web server, using a first device; displaying the web form to the agent via a browser running on the first device; detecting, by the first device, an interaction of the agent with a first element in the web form; modifying the web form using a program running in the browser; generating a submission from the web form; and transmitting the submission to a service provider.