Payment Data Segmentation for Ecommerce Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current payment data security measures, such as PCI DSS compliance, are costly and burdensome for merchants, and there is a need for enhanced security solutions to protect payment data from misappropriation during online transactions.
Innovation Solution
Dividing payment data into proper subsets and distributing them among multiple data processing systems, reducing the scope of PCI DSS compliance requirements and enhancing security by minimizing the persistence of complete payment data sets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If payment data is stored in a single centralized location for easy access and processing, then transaction speed and ease of operation are improved, but security and risk of misappropriation deteriorate
Solution Approach 1:
The patent divides payment data into multiple separate subsets (e.g., cardholder name, billing address, card number, security code, expiration date) and stores each subset in different data processing systems. No single system contains the complete payment data, which prevents misappropriation while maintaining operational efficiency through coordinated retrieval and reassembly during transactions.
2Ease of operation
If complete payment data is stored for extended periods for convenience, then ease of operation is improved, but security risk and potential loss increase
Solution Approach 1:
Payment data is segmented into multiple subsets stored in different systems, and each subset is retained only as long as needed. The complete payment data exists only temporarily during transaction processing when subsets are reassembled, minimizing the window of vulnerability while maintaining convenience for recurring transactions.
Solution Approach 2:
The system performs preliminary actions by securely storing only data subsets and retrieving them only when needed for transactions. This on-demand retrieval approach ensures that complete payment data does not persist longer than necessary, reducing exposure to security risks while maintaining operational convenience.
3Reliability
If payment data is distributed among multiple systems to enhance security, then reliability and security are improved, but device complexity and processing time increase
Solution Approach 1:
The patent segments payment data into logical subsets that can be stored in separate systems with standardized interfaces. This segmentation approach enhances security by distributing data while managing complexity through consistent data formats and protocols for retrieving and reassembling subsets during transactions.
Solution Approach 2:
The system employs an intermediary mechanism (such as a payment gateway or processing system) that coordinates the retrieval, reassembly, and processing of distributed payment data subsets. This intermediary manages the complexity of interacting with multiple systems while maintaining security and efficiency.
4Reliability
If PCI DSS compliance measures are fully implemented to secure payment data, then security is improved, but cost and operational burden increase
Solution Approach 1:
The patent implements segmentation of payment data as a fundamental architectural approach that inherently reduces PCI DSS compliance scope. By ensuring no single system stores complete payment data, the solution meets security requirements while reducing the number of systems that require full compliance, thereby lowering overall compliance costs and operational burden.
Data Source
AI summary
In at least one embodiment of an ecommerce system, payment data is divided into proper subsets and distributed among multiple data processing systems, and each of the data processing systems stores less than all of the subsets of the payment data after the subsets of payment data are distributed and until at least sending the payment data to a payment authorization system for processing. In at least one embodiment, distributing proper subsets of the payment data among multiple data processing systems enhances security of the payment data by limiting an amount of time and the locations in which a complete set of payment data is persisted.


