On-Demand Web Payment Apps Using Contactless Card Cryptograms
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Web-based platforms often lack the functionality to securely process customer data and requests, especially when using mobile web browsers, leading to security and risk issues.
Innovation Solution
Implementing on-demand applications that download and execute on devices to securely process payments using contactless cards, generating cryptograms for authentication and automatically filling payment information into web browsers without requiring dedicated client applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If web-based platforms are used to host web pages for different entities, then accessibility and ease of operation are improved, but security and functionality are worsened
Solution Approach 1:
The patent introduces a server as an intermediary between the web browser and the application store. The server receives the URL from the web page, downloads the application, and transmits it to the device. This intermediary architecture allows the system to maintain web-based accessibility while incorporating secure application store functionality, as the server mediates the secure transmission and installation of authenticated applications.
2Reliability
If dedicated application store applications are used for each entity, then security and functionality are improved, but device complexity and installation requirements are worsened
Solution Approach 1:
The patent implements a dynamic system where the application is not statically installed on the device but is instead downloaded on-demand from the application store through the server. The application is temporarily installed, executed to perform the specific function (such as processing a payment), and then removed. This dynamic approach provides secure dedicated application functionality without permanently increasing device complexity or requiring manual installation by the user.
Solution Approach 2:
The patent creates a universal system where a single web page can trigger the download and execution of different applications based on the URL provided. Instead of requiring each entity to have its own permanently installed application, the system uses a universal mechanism where the server receives URLs, downloads appropriate applications from the application store, and transmits them to the device. This multi-functional approach allows one web infrastructure to support multiple entities securely without requiring separate dedicated installations for each.
3Ease of operation
If mobile web browsers are used to access web pages, then accessibility is improved, but functionality and security are worsened
Solution Approach 1:
The patent segments the functionality by separating the web browser's role (providing accessibility and URL input) from the application's role (providing specialized functionality). The web browser remains a simple interface for entering URLs, while the downloaded application handles complex tasks such as secure payment processing. This segmentation allows the system to maintain web-based accessibility while incorporating full application-level functionality for specific tasks.
Data Source
AI summary
Systems, methods, articles of manufacture, and computer-readable media. A web browser of a device may receive selection of a uniform resource locator (URL). An operating system may download an application from an application server based on the URL. The application may identify a plurality of applications installed on the device and select a first institution corresponding to a first application. The application may receive a cryptogram from a contactless card associated with the first institution and transmit the cryptogram to an authentication server. The application may receive an authentication result specifying the authentication server decrypted the cryptogram. The web browser may receive, based on the decryption of the cryptogram, an account number, an expiration date associated with the account number, and a card verification value (CVV) associated with the account number. The web browser may provide the account number, expiration date, and CVV to a server associated with the application.


