Encryption Module for Secure Online Transaction Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online transactions face security concerns due to the risk of tampering and interception, particularly with the transmission of sensitive credit card information, as identity theft and fraud increase with the growth of e-commerce.

Innovation Solution

Implementing encryption techniques within online transaction systems, including the use of encryption modules in data capture devices and secure transaction modules throughout the transaction network to secure and decrypt credit card information, ensuring protection from tampering and interception.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption techniques are implemented to secure credit card information during online transactions, then security against tampering and interception is improved, but device complexity and system complexity increase due to the need for encryption modules in data capture devices and secure transaction modules throughout the transaction network

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption system is divided into separate functional modules: an encryption module within the data capture device that encrypts credit card information at the point of capture, and secure transaction modules positioned throughout the transaction network that decrypt information at appropriate points. This segmentation allows security functions to be distributed across multiple components rather than centralized in one complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The encryption module acts as an intermediary between the data capture device and the transaction network, transforming sensitive credit card information into encrypted form before transmission. Secure transaction modules serve as intermediaries at various network points, decrypting information only when necessary and appropriate, thereby mediating between security requirements and transaction processing needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption is applied to all credit card data during transmission, then security is improved, but loss of time occurs due to the computational overhead of encrypting and decrypting data at multiple points in the transaction network

Engineering Contradiction:
ImprovesecurityVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Encryption of credit card information is performed preliminarily at the data capture device before the data enters the transaction network. This preliminary encryption action ensures that sensitive information is protected during transmission without requiring repeated encryption operations at intermediate network points, thereby reducing computational overhead and processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Rather than encrypting and decrypting data at every possible point in the transaction network, the system applies encryption selectively at the capture point and decrypts only at appropriate intermediate points where security requirements dictate. This partial application of encryption minimizes computational overhead while maintaining adequate security protections.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9679290B2Personal token read system and method
Publication Date: 2017.06.13 VERIFONE INC
  • US9679290B2 patent drawing
  • US9679290B2 patent drawing
  • US9679290B2 patent drawing

AI summary

A system for facilitating secure transactions between a purchaser and a vendor is provided. The system might include a purchaser token data capture device for reading token data into the system, an encryption module for encrypting the token data and a network based vendor input form for communicating the encrypted token data to the vendor. The system might further include a purchaser terminal for routing the encrypted token data to a transaction processing network or a vendor for providing payment and confirmation to the vendor of an authorized token.