Cryptogram Generation in Webservice Payment Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Consumer payment information stored on computing devices is vulnerable to theft and compromise during electronic transactions, and merchants' systems are also susceptible to hacking, leading to security concerns and reduced consumer comfort with e-commerce payments.
Innovation Solution
A system and method for generating cryptograms in a webservice environment using multiple computing environments, where a consumer's payment information is securely stored and processed without being transmitted directly, using a secure communication protocol to ensure data isolation and protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If payment information is stored locally in consumer computing devices, then payment transactions can be conducted electronically, but the payment information becomes vulnerable to theft and compromise
Solution Approach 1:
The patent extracts sensitive payment information from the consumer's computing device and stores it in a separate, secure computing environment. The system retrieves only necessary authentication data (username, password) from the consumer device, while keeping payment details isolated in a secure environment, thus eliminating the vulnerability of local storage while maintaining transaction capability
Solution Approach 2:
The patent introduces a secure computing environment as an intermediary between the consumer device and the merchant system. This intermediary retrieves authentication data from the consumer device, processes payment information securely, and returns transaction results, thereby protecting sensitive data from direct exposure to potentially compromised consumer or merchant systems
2Ease of operation
If merchant systems retain consumer payment information for future use, then transaction convenience is improved, but the merchant system becomes vulnerable to hacking and data compromise
Solution Approach 1:
The patent extracts payment information retention functionality from the merchant system and relocates it to a secure computing environment. The merchant system only stores authentication credentials (username, password) while payment details are kept secure and isolated, allowing future transactions to reference stored authentication data without exposing sensitive payment information to merchant system vulnerabilities
Solution Approach 2:
The secure computing environment acts as an intermediary that handles all payment information processing. The merchant system interacts with this intermediary through authenticated sessions, allowing convenient future transactions while the intermediary maintains strict security control over payment data, preventing merchant system hacking from compromising payment information
3Reliability
If payment information is transmitted from consumer computing device at transaction time, then transaction authenticity is maintained, but security comfort is reduced due to transmission vulnerability
Solution Approach 1:
The patent extracts sensitive payment information from the transmission path between consumer device and merchant system. Instead of transmitting full payment details, the system transmits only authentication data to establish a secure session, then retrieves payment information from the secure computing environment during the authenticated transaction, eliminating transmission vulnerability while maintaining authenticity through cryptographic verification
Solution Approach 2:
The secure computing environment serves as an intermediary that establishes authenticated sessions between consumers and merchants. It verifies consumer identity through username and password, then securely manages payment information retrieval and transmission during transactions, ensuring authenticity through cryptographic protocols while protecting against transmission vulnerabilities by keeping sensitive data isolated until authenticated
Data Source
AI summary
A method for generating cryptograms in a webservice environment includes: receiving, in a first environment of a computing system, a credential request transmitted by an external computing device using a secure communication protocol, the credential request including a transaction identifier and account identifier; transmitting, by the first environment, a data request to a second environment of the computing system, the data request including the account identifier; receiving, by the first environment, an account profile and session key from the second environment; transmitting, by the first environment, a cryptogram request to a third environment of the computing system, the cryptogram request including the account profile and session key; receiving, by the first environment, a cryptogram from the third environment generated using the account profile and session key; and transmitting, by the first environment, the cryptogram and transaction identifier to the external computing device via the secure communication protocol.


