Secure Payment Transaction via Isolated Cardholder Data Entry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Consumers are hesitant to enter their credit card information on merchant mobile devices due to security concerns and data breaches, making it challenging to facilitate secure and seamless payment transactions.

Innovation Solution

A method involving a payment solution provider that generates a unique resource locator (URL) for the cardholder device to input payment information independently of the merchant device, ensuring secure authentication and authorization without exposing cardholder data on the merchant device, using QR codes or SMS for communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cardholders enter credit card information on merchant mobile devices, then payment transactions can be completed, but security risks and fraud exposure increase

Engineering Contradiction:
Improvetransaction completionVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive cardholder data entry function from the merchant device and relocates it to a secure server environment. Cardholders enter their payment information on a web interface hosted by the merchant's server, not on the merchant's mobile device. The merchant device only receives authorization tokens, never the actual card data, thereby eliminating the security vulnerability while maintaining transaction functionality

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a secure server as an intermediary between the cardholder and the merchant device. The server acts as a trusted mediator that collects, validates, and processes cardholder information securely, then communicates only authorization results back to the merchant device. This intermediary layer protects cardholders from direct exposure to potentially insecure merchant devices while enabling transaction completion

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If cardholders are required to enter payment information on merchant devices, then transactions can be processed, but consumer trust and convenience decrease

Engineering Contradiction:
Improvetransaction processingVSAvoidconsumer convenience
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent enables cardholders to service their own payment information entry through a secure web interface on their personal devices. Cardholders can enter and manage their payment details in a controlled, familiar environment (their own smartphone or computer browser) rather than being forced to use the merchant's device. This self-service approach maintains transaction processing while significantly improving consumer convenience and trust

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent shifts the payment information entry from the physical dimension (merchant's physical device) to the digital dimension (secure web interface accessible from any device). By moving the data entry to a different dimensional space (online web form versus offline device keyboard), the system maintains transaction capability while dramatically improving ease of operation and consumer comfort

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20240386411A1System and method for facilitating frictionless payment transactions field
Publication Date: 2024.11.21 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US20240386411A1 patent drawing
  • US20240386411A1 patent drawing
  • US20240386411A1 patent drawing

AI summary

A method, for conducting a secure and frictionless payment transaction involving a merchant device and a cardholder device, includes receiving, by a payment solution provider, transaction details from the merchant device, storing, by the payment solution provider, the transaction details, generating, by the payment solution provider, based on the transaction details, a unique resource locator (URL) for a communication to the cardholder device, wherein the URL is configured to permit the cardholder device to provide payment information for the payment transaction independent of the merchant device, capturing, by the payment solution provider, the payment information communicated by the cardholder device independently of the merchant device, matching, by the payment solution provider, the payment information with the transaction details, and initiating, by the payment solution provider, a transaction authorization request based on the matching of the payment information with the transaction details being successful.