On-Demand Payment App for Secure Web Card Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Web-based platforms often lack the functionality to securely process customer data and requests, especially when using mobile web browsers, leading to security and risk issues.
Innovation Solution
Implementing on-demand applications that download and execute on devices to securely process payments using contactless cards, generating cryptograms for authentication and automatically filling payment information into web browsers without requiring dedicated client applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If web-based platforms are used to host web pages for different entities, then accessibility and ease of operation are improved, but security and functionality are worsened
Solution Approach 1:
The patent introduces an on-demand application as an intermediary component that bridges the web browser and the payment processing system. This application provides dedicated security functionality (cryptogram generation, secure data handling) that the web browser alone cannot provide, while maintaining the accessibility benefits of web-based platforms. The on-demand application acts as a mediator that enhances security without requiring a fully dedicated client application.
Solution Approach 2:
The system dynamically downloads and executes on-demand applications only when needed for specific payment transactions. This dynamic approach allows the system to provide enhanced security functionality temporarily when required, then terminate the application afterward. This resolves the contradiction by providing security only when and where needed, rather than requiring permanent installation of dedicated client applications.
2Reliability
If dedicated client applications are deployed for each entity, then security and functionality are improved, but device complexity and installation requirements are worsened
Solution Approach 1:
The patent implements on-demand applications that are downloaded temporarily, executed for the specific purpose of processing a payment transaction, and then terminated. These short-lived applications provide the security and functionality of dedicated client applications without the permanence and installation complexity. The applications are essentially disposable - created on-demand, used briefly, then discarded, eliminating the need for permanent installation.
Solution Approach 2:
The on-demand application serves multiple entities and purposes through a single universal implementation. Rather than requiring separate dedicated applications for each merchant or entity, the same on-demand application framework can handle payments for multiple different entities. This universality reduces device complexity while maintaining security across multiple use cases.
3Ease of operation
If mobile web browsers are used to access web pages, then accessibility is improved, but functionality and security are worsened
Solution Approach 1:
The patent segments the payment processing functionality into distinct components: the web browser handles user interaction and display, while the on-demand application handles secure payment processing operations. This segmentation allows each component to specialize in its strengths - the browser provides accessibility and the on-demand application provides functionality - without requiring either component to be overly complex.
Data Source
AI summary
Systems, methods, articles of manufacture, and computer-readable media. A web browser of a device may receive selection of a uniform resource locator (URL). An operating system may download an application from an application server based on the URL. The application may identify a plurality of applications installed on the device and select a first institution corresponding to a first application. The application may receive a cryptogram from a contactless card associated with the first institution and transmit the cryptogram to an authentication server. The application may receive an authentication result specifying the authentication server decrypted the cryptogram. The web browser may receive, based on the decryption of the cryptogram, an account number, an expiration date associated with the account number, and a card verification value (CVV) associated with the account number. The web browser may provide the account number, expiration date, and CVV to a server associated with the application.


