Offline Credit Payment Terminal Using Virtual Card Numbers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional magnetic stripe credit cards are vulnerable to skimming fraud, identity theft, and financial losses due to high payment limits that require adjustment at issuers, and they often necessitate real-time network-based transactions, which can be inefficient and insecure.
Innovation Solution
A data interaction method and offline credit payment system that involves collecting and recording authorization data from a remote server, allowing for offline transactions using intelligent terminals and fee deduction terminals, which can process payments without real-time network access, enhancing security and efficiency by using temporary authorization data and secure communication protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If magnetic stripe credit cards are used for payment, then payment functionality is provided, but security is compromised due to skimming fraud and identity theft risks
Solution Approach 1:
The patent uses a virtual card number generated by a random number generator as a copy of the physical card information. This virtual number is stored in the terminal and used for transactions, replacing the magnetic stripe data. The virtual card number can be regenerated if compromised, preventing the harmful effects of skimming and identity theft while maintaining payment functionality.
2Adaptability or versatility
If high payment limits are set on credit cards, then purchasing power is enhanced, but user convenience deteriorates due to the need to visit issuers to adjust limits
Solution Approach 1:
The system enables users to self-manage payment limits through the terminal's local storage and processing capabilities. The terminal stores user credit information and can autonomously process transactions within predefined limits without requiring users to visit issuers. Users can adjust limits through the terminal interface, making the system self-serving and eliminating the need for physical visits to adjust payment limits.
3Reliability
If real-time network-based payment processing is used, then transaction authorization is ensured, but payment efficiency deteriorates due to network dependency and processing delays
Solution Approach 1:
The terminal performs preliminary actions by storing credit card information, virtual card numbers, and authorization data locally before transactions occur. This pre-stored data enables the terminal to process transactions offline without real-time network connectivity. The system maintains transaction authorization reliability through local validation mechanisms while dramatically improving processing efficiency by eliminating network dependency for each transaction.
4Ease of operation
If magnetic stripe information is stored on cards, then payment functionality is enabled, but data security deteriorates due to duplication and loss risks
Solution Approach 1:
The system generates disposable virtual card numbers that are single-use or limited-use. Each virtual card number is created for a specific transaction or time period and can be regenerated if compromised. This disposable approach eliminates the risk of long-term data storage and duplication associated with magnetic stripe cards. The virtual numbers are stored temporarily in the terminal and automatically invalidated after use, preventing information loss and card cloning.
Data Source
AI summary
Implementations of the present application provide data interaction methods and devices. In one example implementation, authorization data for a current interaction are received from a remote server, wherein the authorization data comprises signature information, time information of current authorization, a random number of the current authorization, and a threshold. The authorization data are verified by performing at least one of: comparing the time information comprised in the authorization data with a current time; determining whether the random number comprises in the authorization data exists in a previous data interaction; or determining whether the data of the current interaction exceeds the threshold comprised in the authorization data. Whether to cancel the current interaction is determined based on the verification of the authorization data.


