Personal POS Device for Secure Card Present E-Commerce
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current e-commerce transactions are primarily 'card not present,' leading to increased fraud risks and higher interchange rates due to exposed payment card industry data, necessitating the development of 'card present' e-commerce solutions.
Innovation Solution
A personal Point of Sale (pPOS) device that combines EMV level 1 and level 2 payment components with a virtual merchant, enabling 'card present' transactions through secure microcontroller functions, payment kernels, secure elements, and sensor switches, supporting both contact and contactless payments, and incorporating biometrics and encryption for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If card not present e-commerce transactions are used, then convenience for customers is improved, but fraud risk increases and interchange rates become higher
Solution Approach 1:
The patent introduces a personal Point of Sale (pPOS) device as an intermediary between the customer's payment card and the merchant's e-commerce system. This portable EMV terminal allows customers to physically present their cards for authentication, creating a secure bridge that eliminates direct exposure of card data on merchant websites while maintaining transaction convenience.
Solution Approach 2:
The patent segments the payment authentication process by separating the EMV card reading function (performed by the portable pPOS device) from the e-commerce transaction processing (performed by the merchant system). This segmentation allows the secure element in the pPOS device to handle sensitive card data locally, preventing its exposure to the merchant's web environment.
2Device complexity
If card data is stored and processed on merchant systems, then transaction processing is simplified, but PCI data exposure increases
Solution Approach 1:
The patent extracts the sensitive PCI data processing function from the merchant's e-commerce system and relocates it to the customer's portable pPOS device. The secure element within the pPOS device performs local encryption and tokenization, extracting only non-sensitive transaction tokens to be transmitted to the merchant, thereby eliminating PCI data exposure risks.
Solution Approach 2:
The patent implements preliminary encryption and authentication actions within the pPOS device before data leaves the customer's control. The secure element performs advance cryptographic operations and generates transaction tokens in advance, ensuring that no raw PCI data is ever transmitted to or stored on the merchant's systems.
3Reliability
If EMV level 1 and level 2 components are combined in a portable device, then card present transaction security is achieved, but device complexity increases
Solution Approach 1:
The patent merges EMV level 1 (contactless reader) and level 2 (contact reader with secure element) payment terminal capabilities into a single portable pPOS device. This consolidation integrates multiple payment processing functions into one unified device, achieving card present security requirements while maintaining portability and ease of use.
Data Source
AI summary
Within the EMV payment specification, the use of an unattended terminal to accept a payment is allowed. Creating a device that has both the EMV level 1 (L1) and level 2 (L2) payment components combined with a virtual merchant creates a “card present” transaction for an on-line or e-commerce merchant. This device can be called a personal Point of Sale (pPOS). This specification discloses personal Point of Sale (pPOS) devices and methods that can provide for card present e-commerce transactions. In some embodiments, a pPOS device can include only a secure microcontroller function (MCF), a payment kernel, a secure element, and an interface to an external system with an EMV level 3 (L3) payment application. In some embodiments, a pPOS device can further include a reader. In some embodiments, a pPOS device can still further include a sensor switch and/or a user interface function.


