Mobile Payment Pass Virtual Container API Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile payment applications do not seamlessly integrate with other mobile applications, leading to an undesired user experience, and the passes stored by these applications are not secure, exposing users to potential data breaches.
Innovation Solution
A method for integrating a mobile payment application with other mobile applications by generating a view of application programming interfaces exposed to leverage created passes, allowing seamless integration while creating a virtual container to control and limit data exposure, ensuring enhanced security through encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If passes are treated as a separate entity hosted by the mobile payment application, then security is maintained within the payment application, but seamless integration with other mobile applications is prevented
Solution Approach 1:
The patent introduces an intermediary layer (application programming interfaces and virtual container) that enables communication between the mobile payment application and other mobile applications without exposing the underlying secure pass data. This mediator allows seamless integration while maintaining security boundaries.
Solution Approach 2:
The patent segments the system into distinct layers: the secure pass storage layer within the mobile payment application, and the integration layer with controlled APIs. This segmentation allows different parts of the system to have different security requirements, enabling both security and integration.
2Ease of operation
If passes are integrated with other mobile applications, then seamless user experience is achieved, but security exposures increase
Solution Approach 1:
The virtual container acts as a mediator that allows other applications to access and interact with pass features seamlessly while preventing direct access to the underlying sensitive data. This intermediary layer blocks security exposures while maintaining ease of operation.
Solution Approach 2:
The patent applies different security qualities to different parts of the system. The pass data itself remains highly secure within the mobile payment application, while the integrated features exposed through APIs have controlled, appropriate security levels for their specific functions.
3Ease of operation
If bar codes or Quick Response codes are used to represent gift card numbers, then ease of use is improved, but security is compromised
Solution Approach 1:
The patent extracts the sensitive gift card number from direct exposure and replaces it with a surrogate representation (bar code or Quick Response code) that can be easily scanned but does not reveal the actual card number. This removes the harmful exposure while maintaining ease of use.
Solution Approach 2:
Instead of displaying the actual sensitive data, the patent uses a copy or representation (visual code) that serves the same functional purpose for scanning and identification but does not expose the underlying sensitive information.
Data Source
AI summary
A method, system and computer program product for integrating a mobile payment application with other mobile applications while preventing security exposures. A set of application programming interfaces of mobile applications that may possibly be utilized by a pass created by a mobile payment application is generated in response to receiving an indication that the pass was created. A “pass,” as used herein, refers to a form of mobile payment, such as a gift card. A selection of these application programming interfaces may then be received to interact with the created pass. In this manner, the existing mobile applications are seamlessly integrated with the features of passes. Furthermore, a virtual container is created for the created pass and the selected application programming interfaces to interface with the created pass. By creating such a container, the data to be exposed to the application layer can be controlled.


