Mobile Browser Checkout with Contactless Card Cryptogram Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in accurately entering long account identifiers for payment cards, which are prone to errors and security risks, and online transactions are often treated as 'card not present' transactions, incurring higher fees and fraud risks.

Innovation Solution

A method using a mobile web browser to authenticate and process transactions with a contactless card by generating a URI that launches a registered application, authenticating the user, receiving a cryptogram from the card, verifying it with a server, and populating payment information into web form fields, enabling secure, automated checkout.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual entry of account identifiers is used, then users can input payment information, but errors and security risks increase

Engineering Contradiction:
Improveease of payment information entryVSAvoidaccuracy of account identifier entry
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces manual mechanical entry of account identifiers with automated optical recognition using a camera to capture and read the card number, thereby eliminating entry errors while maintaining ease of operation

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service by allowing the payment card itself to provide its identification information through visual capture, eliminating the need for manual typing and reducing errors

Inventive Principle:
Principle #25Self-service

2Productivity

If account identifiers are entered in plain text, then payment processing can proceed, but security risks increase due to camera capture and identification

Engineering Contradiction:
Improvetransaction processing speedVSAvoidsecurity risks from camera capture
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent creates a visual copy of the account identifier through camera capture and processes this copy through recognition algorithms, allowing the system to read the information without exposing plain text that could be captured by malicious entities

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces an intermediary recognition system that translates visual card information into processed data, preventing direct exposure of raw account identifiers and reducing security risks from camera capture

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If online transactions are processed as card not present transactions, then remote purchasing is enabled, but processing fees and fraud risks increase

Engineering Contradiction:
Improveremote transaction capabilityVSAvoidfraud risk and processing fees
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent replaces traditional card-not-present processing with a visual recognition system that captures and verifies card information through camera imaging, enabling remote transactions to be processed with higher security and lower fees typically associated with card-present transactions

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12354077B2Mobile web browser authentication and checkout using a contactless card
Publication Date: 2025.07.08 CAPITAL ONE SERVICES LLC
  • US12354077B2 patent drawing
  • US12354077B2 patent drawing
  • US12354077B2 patent drawing

AI summary

A merchant page in a browser may receive selection of a first financial institution. The merchant page may generate a uniform resource identifier (URI) directed to an application. At least a portion of the URI may be registered with the application and the first financial institution in a mobile operating system. Responsive to receiving selection of the URI, the mobile OS may launch the application, which may authenticate credentials for an account. The application may associate the user ID parameter and the session ID parameter with the account and receive a cryptogram from a contactless card. The application may receive, from a server, an indication specifying the server verified the cryptogram. The OS may launch the browser, which may refresh the page. The refreshed page may include a virtual card number (VCN) in a first form field. A transaction may be processed based on the VCN.