Payment Token Verification via Graphical Codes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure payment systems rely on merchant devices for transaction verification, which can be compromised, and require network connectivity, making them costly, cumbersome, and insecure for customers.
Innovation Solution
A method where a merchant device generates a graphically encoded representation of billing information and an encryption key, allowing customers to scan and decode this information using their own device to initiate payments, thereby reducing reliance on merchant devices and ensuring secure transaction verification without network connectivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional secure payment systems use merchant card reader devices with network connectivity, then transaction verification can be performed, but security is degraded when connection is inactive and customers must trust merchant devices
Solution Approach 1:
The patent inverts the traditional payment verification model by having the customer's device (scanner) verify the merchant's payment token instead of the merchant's device verifying the customer's card. The scanner device generates a payment token that the merchant's authentication device verifies, reversing the trust relationship and eliminating the need for customers to trust merchant devices with their sensitive information
Solution Approach 2:
The patent introduces a payment token as an intermediary element that carries billing information and encryption key information between the customer's scanner device and the merchant's authentication device. This token serves as a secure mediator that eliminates the need for direct trust between customer and merchant devices, allowing verification without network connectivity
2Reliability
If traditional payment verification uses text messages or dedicated hardware devices, then transaction success can be communicated, but the system becomes costly and cumbersome to implement
Solution Approach 1:
The patent replaces complex verification infrastructure with a simple graphical code representation (QR code or barcode) that can be scanned by any smartphone camera or barcode scanner. Instead of requiring dedicated hardware devices or text message systems, the solution uses a universal visual code that can be captured and processed by common consumer devices
Solution Approach 2:
The patent replaces mechanical and network-based verification systems (text messages, dedicated hardware devices requiring network connectivity) with an optical system using graphical codes that can be scanned and processed offline. This substitution eliminates the need for network infrastructure and specialized hardware
3Ease of operation
If merchant devices store complete access to customer payment card information, then transactions can be processed, but security risk increases if devices are hacked or compromised
Solution Approach 1:
The patent segments the sensitive payment information into two separate components: billing information and encryption key information. These segmented components are embedded within a payment token that is generated by the customer's device and verified by the merchant's authentication device, eliminating the need for merchant devices to store complete access to customer payment information
Solution Approach 2:
The patent extracts sensitive customer payment information from the merchant's card reader device and places it within a payment token generated and controlled by the customer's own device. This extraction removes the security vulnerability of having merchant devices store complete access to customer payment card information
Data Source
AI summary
Disclosed herein are methods and apparatus related to making payments in response to payment requests. For example, a customer device can receive a payment request including billing information and information related to an encryption key. The customer device can obtain the billing information and the information related to the encryption key from the payment request. The customer device can receive an input related to initiating payment of the payment request. After receiving the input related to initiating payment, the customer device can generate a request to initiate payment that includes the information related to the encryption key. The customer device can send the request to initiate payment.


