Browser Payment Credential Overlay With Dynamic Verification Fields
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing graphical user interfaces for secure transactions, such as those using static information from physical plastic cards, are vulnerable to theft and cybersecurity risks, including photographic extraction of credit card details, leading to significant transactional vulnerabilities.
Innovation Solution
A hybrid graphical user interface overlay system that operates with a backend server, utilizing a browser extension to transform static fields into dynamic fields through encryption and biometric verification, enhancing security without requiring extensive website modifications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If static information from physical plastic cards is used for transactions, then user convenience is improved, but cybersecurity vulnerability increases due to photographic extraction and interception risks
Solution Approach 1:
The patent transforms static card verification values into dynamic values that change with each transaction. The system generates time-sensitive or transaction-specific verification values that are valid only for a single use or limited time period, making photographic extraction and replay attacks ineffective.
Solution Approach 2:
The system changes the parameter of the verification value from static to dynamic by incorporating temporal or transactional variables. Each verification value is generated with unique parameters such as timestamp, transaction ID, or random nonce, ensuring that even if one value is captured, it cannot be reused.
2Reliability
If additional secure processing screens are inserted into graphical user interface flows, then security is improved, but interface complexity and user experience deteriorate
Solution Approach 1:
The patent introduces a backend security system that acts as an intermediary between the user interface and transaction processing. The secure verification values are generated and validated server-side without requiring users to interact with complex security screens, maintaining a clean interface while enhancing security.
Solution Approach 2:
The complex security processing logic is extracted from the graphical user interface and moved to the backend server. This separation allows the interface to remain simple and user-friendly while the backend handles the computationally intensive security validations and dynamic value generation.
3Reliability
If dynamic verification values are generated and entered in real-time, then transactional security is improved, but processing time and computational cost increase
Solution Approach 1:
The system performs preliminary generation and caching of verification values before they are needed for transactions. By pre-computing and storing valid verification values with their validity periods, the system reduces real-time computational overhead while maintaining security.
Solution Approach 2:
The patent replaces complex real-time cryptographic computations with pre-computed verification values that can be quickly validated. The heavy computational work is done in advance during value generation, while the validation process uses simpler comparison operations that execute rapidly.
Data Source
AI summary
A computer system and method for populating electronic payment credentials is provided. The system comprises at least one processor and a memory storing instructions which when executed by the processor configure the processor to perform the method. The method comprises receiving a browser extension activation input, sending a payment details request message to a financial institution system, receiving payment details from the financial institution system following authentication at a mobile device, and populating a payment form on the browser using the payment details. Dynamic credentials are provided by the financial institution system and combined with pre-populated tokenized credentials during automatic entry into the payment form.


