Mobile POS Terminal Secure Payment Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile payment systems lack integration with traditional point of sale systems, limiting merchants' control over payment processing and user experience, and often require compliance with security standards like PCI DSS, which can be costly and burdensome.
Innovation Solution
A system that enables payment information from a card reader device to be securely communicated to a third-party service provider using payment processing mechanisms, allowing merchants to maintain control over user experience and avoid compliance costs by using encryption mechanisms like DUKPT and hosted order pages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If merchants use traditional fixed POS systems, then payment processing is secure and reliable, but mobility is lost due to dependency on supporting equipment
Solution Approach 1:
The patent extracts the essential payment processing functionality from the complex fixed POS system and concentrates it into a mobile computing device. The system separates the card reader device (which can be a simple external accessory) from the processing logic, which resides in the mobile device's processor running custom software. This allows the merchant to use a portable device while maintaining payment processing capabilities without needing the full infrastructure of a traditional POS system.
Solution Approach 2:
The mobile computing device serves multiple functions: it acts as the POS terminal, hosts the custom payment processing software, provides the user interface for transactions, and communicates with both the card reader and the merchant's commerce system. This multi-functional approach replaces the specialized fixed POS equipment with a versatile mobile device that can perform all necessary payment processing tasks.
2Ease of operation
If merchants use reader devices with custom software, then mobility is enabled, but control over user experience and payment processing functions is lost
Solution Approach 1:
The system establishes a feedback loop where the mobile computing device communicates with the merchant's commerce system. The device can send transaction data and receive responses, allowing the merchant to maintain control over payment processing logic, receipt handling, and checkout processes. The commerce system can provide feedback about transaction status, pricing, and other business rules that guide the mobile POS operations.
Solution Approach 2:
The mobile computing device acts as an intermediary between the card reader and the merchant's commerce system. Rather than the reader device directly controlling the transaction flow, the mobile device mediates by receiving data from the reader, processing it through custom software according to merchant-defined rules, and then communicating with the commerce system. This intermediary role preserves merchant control while enabling mobility.
3Adaptability or versatility
If merchants integrate reader devices with existing POS systems, then functionality is enhanced, but security compliance burden increases
Solution Approach 1:
The patent employs encryption mechanisms that generate unique, transaction-specific keys (such as DUKPT - Derived Unique Key Per Transaction). Each transaction uses a different encryption key that is discarded after use, eliminating the need for long-term secure storage of sensitive payment data on the mobile device. This approach provides strong security compliance at low cost and reduced complexity compared to systems that must store and manage persistent cryptographic credentials.
Solution Approach 2:
The system replaces physical security measures (such as secure hardware modules and tamper-resistant POS terminals) with software-based cryptographic solutions. The mobile computing device uses software encryption and secure communication protocols to protect payment data in transit and at rest, substituting mechanical/hardware security with information-theoretic security approaches that are easier to implement and maintain on mobile platforms.
Data Source
AI summary
Embodiments of the present invention are directed to methods, systems, and apparatuses for enabling payment information received via a reader device coupled to a mobile point-of-sale (POS) terminal to be communicated in a secure manner to a third party service provider for payment processing of a transaction between a merchant and a consumer. Some embodiments are directed to communication of the payment information received from a reader device using a payment processing mechanism (e.g., a hosted order page) of the merchant to process payment information via the third party service provider in a secure manner. The reader device can encrypt payment information using a third party encryption mechanism, such as derived unique key per transaction (DUKPT). The third party encryption mechanism can be used or accessed by the third party service provider to enable end-to-end security for payment processing.


