Overlaid Input Fields for Secure Remote Payment Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices face challenges in complying with the Payment Application Data Security Standard (PA DSS) due to limited computing resources and security features, making it difficult to securely process and store payment information, especially for transactions requiring user signatures which often necessitate physical documentation.

Innovation Solution

Implementing overlaid input fields in user interfaces that allow sensitive payment information to be securely input and processed on a remote server, eliminating the need for local storage and compliance with PA DSS on mobile devices, while enabling remote user signatures through network requests and secure data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If payment information is processed and stored locally on mobile devices to enable transactions, then transaction functionality is improved, but security compliance with PA DSS becomes difficult and computing resources are overwhelmed

Engineering Contradiction:
Improvetransaction functionalityVSAvoidPA DSS compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the sensitive payment data processing function from the mobile device and relocates it to a remote server. The mobile device only handles user interaction and displays tokenized information, while all PA DSS-compliant processing occurs remotely, thus resolving the compliance issue while maintaining transaction functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a tokenization intermediary system that replaces sensitive payment data with tokens. The token acts as a mediator between the user interface and the payment processing system, allowing the mobile device to handle transactions without directly processing or storing sensitive cardholder data, thereby achieving PA DSS compliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cardholder data is encrypted before transmission to mobile devices, then security is improved, but the requirement for separate card readers and physical scanning is added

Engineering Contradiction:
Improvedata securityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical card scanning system with a digital token-based system. Instead of requiring physical card readers and optical scanning mechanisms, the system uses electronic tokens that can be displayed on the mobile device screen, eliminating the need for additional hardware while maintaining security through cryptographic protection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If remote transactions are enabled without signature requirements, then user convenience is improved, but authorization security is compromised

Engineering Contradiction:
Improveremote transaction convenienceVSAvoidauthorization security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent creates a digital copy of the signature process through token-based authorization. The token serves as a digital representation of user authorization, allowing remote transactions to be authenticated without requiring physical signature collection, thus maintaining security while improving convenience.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10235672B2Securely receiving from a remote user sensitive information and authorization to perform a transaction using the sensitive information
Publication Date: 2019.03.19 ZUKUNFTWARE LLC
  • US10235672B2 patent drawing
  • US10235672B2 patent drawing
  • US10235672B2 patent drawing

AI summary

Payment information and user input to serve as authorization to perform a transaction using the payment information can be obtained from a remote user having a client computing device. A merchant can send a request for payment information and authorization over a network to any device having a browser and touch screen or other means for receiving user input. A user interface having overlaid fields can be used to receive the payment information in a secure manner that prevents the payment information from being stored on the client computing device. An input area can also be displayed within the browser on the user's device. When the user inputs a signature (or other authorization information) into the input area, the signature can be routed over a network back to the merchant to provide authorization for a transaction.