Customer-Generated Network Page Portions for PCI DSS Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Online merchants using third-party hosted electronic commerce platforms face challenges in customizing their network sites due to security concerns and compliance with Payment Card Industry Data Security Standards (PCI DSS), limiting their flexibility and control over stylistic and content aspects.
Innovation Solution
Implementing a system that allows merchants to upload and execute page generation code server-side, with data aggregation services isolating customer-supplied code from direct data sources, and enabling customers to self-generate network page portions while ensuring compliance through restricted API calls and validation services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If merchants use third-party hosted electronic commerce platforms, then PCI DSS compliance and security are ensured, but flexibility and control over site customization are lost
Solution Approach 1:
The system segments the page generation functionality into customer-supplied code portions and hosting provider infrastructure. Customers can upload and execute their own page generation code on the hosted platform, allowing customization while maintaining security compliance through the provider's infrastructure.
Solution Approach 2:
The hosting provider acts as an intermediary between the customer's customization needs and the PCI DSS compliance requirements. The provider's platform mediates by allowing customer code execution while maintaining security controls, data protection, and compliance monitoring.
2Adaptability or versatility
If merchants use self-managed electronic commerce solutions, then flexibility and control over site customization are maintained, but PCI DSS compliance and security management become challenging
Solution Approach 1:
The solution separates customization responsibilities (customer-supplied code) from compliance responsibilities (hosting provider infrastructure). This segmentation allows merchants to maintain flexibility through custom code while the provider ensures compliance through managed security infrastructure.
Solution Approach 2:
Customers can self-serve by uploading and executing their own page generation code, maintaining control over customization. Meanwhile, the hosting provider automatically manages compliance requirements, reducing the burden on merchants.
Data Source
AI summary
Disclosed are various embodiments for generating network pages for customers that include customer-generated page portions. A request for a network page is obtained from a client. The network page is associated with a network site hosted on behalf of a first party by a second party. A portion of the network page is obtained from a service operated by the party in response to the request. The network page, which includes the portion, is generated in response to the request. The generated network page is sent to the client in response to the request.


