Payment Data Segmentation for Ecommerce Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current payment data security measures, such as PCI DSS compliance, are costly and burdensome for merchants, and there is a need for enhanced security solutions to protect payment data from misappropriation during online transactions.

Innovation Solution

Dividing payment data into proper subsets and distributing them among multiple data processing systems, reducing the scope of PCI DSS compliance requirements and enhancing security by minimizing the persistence of complete payment data sets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If payment data is stored in a single centralized location for easy access and processing, then transaction speed and ease of operation are improved, but security and risk of misappropriation deteriorate

Engineering Contradiction:
Improveease of payment processingVSAvoidpayment data security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides payment data into multiple separate subsets (e.g., cardholder name, billing address, card number, security code, expiration date) and stores each subset in different data processing systems. No single system contains the complete payment data, which prevents misappropriation while maintaining operational efficiency through coordinated retrieval and reassembly during transactions.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If complete payment data is stored for extended periods for convenience, then ease of operation is improved, but security risk and potential loss increase

Engineering Contradiction:
Improveconvenience of payment processingVSAvoidrisk of misappropriation
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Payment data is segmented into multiple subsets stored in different systems, and each subset is retained only as long as needed. The complete payment data exists only temporarily during transaction processing when subsets are reassembled, minimizing the window of vulnerability while maintaining convenience for recurring transactions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by securely storing only data subsets and retrieving them only when needed for transactions. This on-demand retrieval approach ensures that complete payment data does not persist longer than necessary, reducing exposure to security risks while maintaining operational convenience.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If payment data is distributed among multiple systems to enhance security, then reliability and security are improved, but device complexity and processing time increase

Engineering Contradiction:
Improvepayment data securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments payment data into logical subsets that can be stored in separate systems with standardized interfaces. This segmentation approach enhances security by distributing data while managing complexity through consistent data formats and protocols for retrieving and reassembling subsets during transactions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs an intermediary mechanism (such as a payment gateway or processing system) that coordinates the retrieval, reassembly, and processing of distributed payment data subsets. This intermediary manages the complexity of interacting with multiple systems while maintaining security and efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If PCI DSS compliance measures are fully implemented to secure payment data, then security is improved, but cost and operational burden increase

Engineering Contradiction:
Improvepayment data securityVSAvoidcompliance cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements segmentation of payment data as a fundamental architectural approach that inherently reduces PCI DSS compliance scope. By ensuring no single system stores complete payment data, the solution meets security requirements while reducing the number of systems that require full compliance, thereby lowering overall compliance costs and operational burden.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8589307B2Ecommerce system with payment data division
Publication Date: 2013.11.19 VOLUSION LLC
  • US8589307B2 patent drawing
  • US8589307B2 patent drawing
  • US8589307B2 patent drawing

AI summary

In at least one embodiment of an ecommerce system, payment data is divided into proper subsets and distributed among multiple data processing systems, and each of the data processing systems stores less than all of the subsets of the payment data after the subsets of payment data are distributed and until at least sending the payment data to a payment authorization system for processing. In at least one embodiment, distributing proper subsets of the payment data among multiple data processing systems enhances security of the payment data by limiting an amount of time and the locations in which a complete set of payment data is persisted.