E-commerce Browser Redirecting Payment Data via VPN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing theft of electronic payment data in e-commerce transactions poses a significant security risk, leading to potential large monetary fines and damages for entities handling this information, as existing payment systems lack robust security measures.
Innovation Solution
A method and system utilizing a cloud computing environment and a virtual private network (VPN) to securely transmit confidential information during e-commerce sessions, where a browser redirects sensitive data directly to a transaction server within the same Internet domain, preventing exposure to the cloud computing service and ensuring compliance with industry standards like PCI DSS.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If confidential information is transmitted through the cloud computing service, then e-commerce functionality is simplified and unified, but security risk increases due to potential data breaches
Solution Approach 1:
The system segments the e-commerce platform into two distinct components: a cloud-based service for non-sensitive operations (product browsing, cart management) and a separate transaction server for confidential information handling. This segmentation allows the majority of e-commerce functionality to remain unified and accessible via the cloud while isolating security-critical operations to a dedicated secure component.
Solution Approach 2:
The patent extracts the confidential information handling functionality from the cloud computing service and places it on a separate transaction server. By taking out the sensitive payment processing operations from the cloud environment, the system eliminates the security vulnerability of transmitting confidential data through the cloud while preserving the cloud's ability to handle non-sensitive e-commerce tasks.
2Object-affected harmful factors
If a separate transaction server is used for confidential information, then security is improved, but system complexity increases
Solution Approach 1:
The patent merges the cloud computing service and transaction server under a single domain name, presenting them as a unified e-commerce platform to users. This merging of the external interface simplifies user interaction while the backend maintains the necessary separation between cloud and transaction components.
Solution Approach 2:
The system uses an intermediary mechanism (the domain name system and routing logic) that directs traffic to appropriate servers based on the nature of the request. This intermediary layer manages the complexity of having multiple servers by providing a unified access point that automatically routes confidential information to the transaction server and other requests to the cloud service.
Data Source
AI summary
A method of secure automated communication comprises communicating by a computer with a cloud computing service having an address in a first Internet domain, the communicating performed during a first electronic commerce session using an electronic commerce web page rendered by a browser executing on the computer; communicating by the computer with a transaction server having an address in the first Internet domain via a virtual private network (VPN), the communicating performed during the first electronic commerce session using the electronic commerce web page rendered by the browser; determining when the browser is accessing a product information portion of the electronic commerce web page during the first electronic commerce session; determining when the browser is providing confidential information to the electronic commerce web page during the first electronic commerce session; and directing the confidential information to the transaction server via the virtual private network during the first electronic commerce session.


