Hosted Sensitive Data Form Fields for PCI DSS Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for accepting sensitive data, such as credit card information, over the Internet face challenges in compliance with security standards like PCI DSS, particularly due to the need for extensive investments in computing equipment and the difficulty in maintaining consistent appearance and customization, especially when outsourcing payment functions to third-party processors.
Innovation Solution
A method where a third-party payment processor provides hosted sensitive data form fields as inline frames within a web page, allowing merchants to customize their appearance using style sheet languages and minimizing the need for merchants to store or maintain sensitive data, thus offloading compliance with security standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If merchants outsource payment functions to third-party processors, then PCI DSS compliance burden is reduced, but the appearance and behavior of payment forms become inconsistent with the merchant's website
Solution Approach 1:
The patent uses an intermediary approach by having the third-party payment processor's form fields embedded within the merchant's own web page template. The payment form is rendered as part of the merchant's page hierarchy, allowing the merchant to apply their own CSS styles and design elements while the third party handles the actual payment processing and compliance responsibilities. This mediator solution resolves the contradiction by maintaining both compliance ease and appearance consistency.
2Reliability
If merchants implement their own secure data storage systems, then compliance control is improved, but extensive investment in computing equipment and security measures is required
Solution Approach 1:
The patent extracts the sensitive data storage and security management functions from the merchant's system and places them entirely within the third-party payment processor's infrastructure. The merchant's web page only collects payment information temporarily and immediately transmits it to the third party, who then handles all storage, encryption, and compliance-related security measures. This extraction eliminates the need for merchants to invest in complex secure computing equipment while maintaining compliance control through the third party's expertise.
3Ease of operation
If third-party payment forms are used, then security compliance is simplified, but customization options are limited
Solution Approach 1:
The patent implements a dynamic solution where the payment form fields are rendered within the merchant's own web page template structure. This allows the form to inherit and respond to the merchant's CSS styles, JavaScript behaviors, and overall page design dynamically. The third-party payment processor provides the functional core while the merchant's template provides the visual and behavioral customization, creating a flexible hybrid that satisfies both ease of compliance and customization requirements.
Data Source
AI summary
Systems and methods providing, by a third party, input form fields for sensitive data on a web page provided by an organization. A user may request a web page from an organization, such as a merchant's checkout web page, that requires entry of sensitive data. The merchant's checkout web page may include reference to a script file that provides hosted sensitive data form fields. In response to rendering the merchant web page in a web browser of the user, a request to provide sensitive data form fields on the merchant web page may be received. The request may include a call to a function in a scripting file provided by the third party, and the provided file may cause one or more inline frames to be rendered in the web browser, each inline frame including a sensitive data form field. Data entered by the user in the sensitive data form fields may be received by a third party payment processor device.


