Hosted Sensitive Data Form Fields for PCI DSS Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for accepting sensitive data, such as credit card information, over the Internet face challenges in compliance with security standards like PCI DSS, particularly due to the need for extensive investments in computing equipment and the difficulty in maintaining consistent appearance and customization, especially when outsourcing payment functions to third-party processors.

Innovation Solution

A method where a third-party payment processor provides hosted sensitive data form fields as inline frames within a web page, allowing merchants to customize their appearance using style sheet languages and minimizing the need for merchants to store or maintain sensitive data, thus offloading compliance with security standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If merchants outsource payment functions to third-party processors, then PCI DSS compliance burden is reduced, but the appearance and behavior of payment forms become inconsistent with the merchant's website

Engineering Contradiction:
ImprovePCI DSS compliance burdenVSAvoidappearance consistency
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent uses an intermediary approach by having the third-party payment processor's form fields embedded within the merchant's own web page template. The payment form is rendered as part of the merchant's page hierarchy, allowing the merchant to apply their own CSS styles and design elements while the third party handles the actual payment processing and compliance responsibilities. This mediator solution resolves the contradiction by maintaining both compliance ease and appearance consistency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If merchants implement their own secure data storage systems, then compliance control is improved, but extensive investment in computing equipment and security measures is required

Engineering Contradiction:
Improvecompliance controlVSAvoidcomputing equipment investment
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the sensitive data storage and security management functions from the merchant's system and places them entirely within the third-party payment processor's infrastructure. The merchant's web page only collects payment information temporarily and immediately transmits it to the third party, who then handles all storage, encryption, and compliance-related security measures. This extraction eliminates the need for merchants to invest in complex secure computing equipment while maintaining compliance control through the third party's expertise.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If third-party payment forms are used, then security compliance is simplified, but customization options are limited

Engineering Contradiction:
Improvesecurity complianceVSAvoidcustomization options
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic solution where the payment form fields are rendered within the merchant's own web page template structure. This allows the form to inherit and respond to the merchant's CSS styles, JavaScript behaviors, and overall page design dynamically. The third-party payment processor provides the functional core while the merchant's template provides the visual and behavioral customization, creating a flexible hybrid that satisfies both ease of compliance and customization requirements.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11301219B2Hosted sensitive data form fields for compliance with security standards
Publication Date: 2022.04.12 PAYPAL INC
  • US11301219B2 patent drawing
  • US11301219B2 patent drawing
  • US11301219B2 patent drawing

AI summary

Systems and methods providing, by a third party, input form fields for sensitive data on a web page provided by an organization. A user may request a web page from an organization, such as a merchant's checkout web page, that requires entry of sensitive data. The merchant's checkout web page may include reference to a script file that provides hosted sensitive data form fields. In response to rendering the merchant web page in a web browser of the user, a request to provide sensitive data form fields on the merchant web page may be received. The request may include a call to a function in a scripting file provided by the third party, and the provided file may cause one or more inline frames to be rendered in the web browser, each inline frame including a sensitive data form field. Data entered by the user in the sensitive data form fields may be received by a third party payment processor device.