Cryptogram Generation in Webservice Payment Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Consumer payment information stored on computing devices is vulnerable to theft and compromise during electronic transactions, and merchants' systems are also susceptible to hacking, leading to security concerns and reduced consumer comfort with e-commerce payments.

Innovation Solution

A system and method for generating cryptograms in a webservice environment using multiple computing environments, where a consumer's payment information is securely stored and processed without being transmitted directly, using a secure communication protocol to ensure data isolation and protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If payment information is stored locally in consumer computing devices, then payment transactions can be conducted electronically, but the payment information becomes vulnerable to theft and compromise

Engineering Contradiction:
Improveelectronic payment transaction capabilityVSAvoidvulnerability to theft and compromise
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive payment information from the consumer's computing device and stores it in a separate, secure computing environment. The system retrieves only necessary authentication data (username, password) from the consumer device, while keeping payment details isolated in a secure environment, thus eliminating the vulnerability of local storage while maintaining transaction capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a secure computing environment as an intermediary between the consumer device and the merchant system. This intermediary retrieves authentication data from the consumer device, processes payment information securely, and returns transaction results, thereby protecting sensitive data from direct exposure to potentially compromised consumer or merchant systems

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If merchant systems retain consumer payment information for future use, then transaction convenience is improved, but the merchant system becomes vulnerable to hacking and data compromise

Engineering Contradiction:
Improvefuture transaction convenienceVSAvoidmerchant system vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts payment information retention functionality from the merchant system and relocates it to a secure computing environment. The merchant system only stores authentication credentials (username, password) while payment details are kept secure and isolated, allowing future transactions to reference stored authentication data without exposing sensitive payment information to merchant system vulnerabilities

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secure computing environment acts as an intermediary that handles all payment information processing. The merchant system interacts with this intermediary through authenticated sessions, allowing convenient future transactions while the intermediary maintains strict security control over payment data, preventing merchant system hacking from compromising payment information

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If payment information is transmitted from consumer computing device at transaction time, then transaction authenticity is maintained, but security comfort is reduced due to transmission vulnerability

Engineering Contradiction:
Improvetransaction authenticityVSAvoidtransmission vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive payment information from the transmission path between consumer device and merchant system. Instead of transmitting full payment details, the system transmits only authentication data to establish a secure session, then retrieves payment information from the secure computing environment during the authenticated transaction, eliminating transmission vulnerability while maintaining authenticity through cryptographic verification

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secure computing environment serves as an intermediary that establishes authenticated sessions between consumers and merchants. It verifies consumer identity through username and password, then securely manages payment information retrieval and transmission during transactions, ensuring authenticity through cryptographic protocols while protecting against transmission vulnerabilities by keeping sensitive data isolated until authenticated

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11842340B2Method and system for generating cryptograms for validation in a webservice environment
Publication Date: 2023.12.12 MASTERCARD INT INC
  • US11842340B2 patent drawing
  • US11842340B2 patent drawing
  • US11842340B2 patent drawing

AI summary

A method for generating cryptograms in a webservice environment includes: receiving, in a first environment of a computing system, a credential request transmitted by an external computing device using a secure communication protocol, the credential request including a transaction identifier and account identifier; transmitting, by the first environment, a data request to a second environment of the computing system, the data request including the account identifier; receiving, by the first environment, an account profile and session key from the second environment; transmitting, by the first environment, a cryptogram request to a third environment of the computing system, the cryptogram request including the account profile and session key; receiving, by the first environment, a cryptogram from the third environment generated using the account profile and session key; and transmitting, by the first environment, the cryptogram and transaction identifier to the external computing device via the secure communication protocol.