Personal POS Device for Secure Card Present E-Commerce

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current e-commerce transactions are primarily 'card not present,' leading to increased fraud risks and higher interchange rates due to exposed payment card industry data, necessitating the development of 'card present' e-commerce solutions.

Innovation Solution

A personal Point of Sale (pPOS) device that combines EMV level 1 and level 2 payment components with a virtual merchant, enabling 'card present' transactions through secure microcontroller functions, payment kernels, secure elements, and sensor switches, supporting both contact and contactless payments, and incorporating biometrics and encryption for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If card not present e-commerce transactions are used, then convenience for customers is improved, but fraud risk increases and interchange rates become higher

Engineering Contradiction:
Improvecustomer convenienceVSAvoidfraud risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a personal Point of Sale (pPOS) device as an intermediary between the customer's payment card and the merchant's e-commerce system. This portable EMV terminal allows customers to physically present their cards for authentication, creating a secure bridge that eliminates direct exposure of card data on merchant websites while maintaining transaction convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the payment authentication process by separating the EMV card reading function (performed by the portable pPOS device) from the e-commerce transaction processing (performed by the merchant system). This segmentation allows the secure element in the pPOS device to handle sensitive card data locally, preventing its exposure to the merchant's web environment.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If card data is stored and processed on merchant systems, then transaction processing is simplified, but PCI data exposure increases

Engineering Contradiction:
Improvetransaction processing complexityVSAvoidPCI data exposure
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive PCI data processing function from the merchant's e-commerce system and relocates it to the customer's portable pPOS device. The secure element within the pPOS device performs local encryption and tokenization, extracting only non-sensitive transaction tokens to be transmitted to the merchant, thereby eliminating PCI data exposure risks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements preliminary encryption and authentication actions within the pPOS device before data leaves the customer's control. The secure element performs advance cryptographic operations and generates transaction tokens in advance, ensuring that no raw PCI data is ever transmitted to or stored on the merchant's systems.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If EMV level 1 and level 2 components are combined in a portable device, then card present transaction security is achieved, but device complexity increases

Engineering Contradiction:
Improvetransaction securityVSAvoiddevice structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges EMV level 1 (contactless reader) and level 2 (contact reader with secure element) payment terminal capabilities into a single portable pPOS device. This consolidation integrates multiple payment processing functions into one unified device, achieving card present security requirements while maintaining portability and ease of use.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10679201B2Personal point of sale (pPOS) device that provides for card present E-commerce transaction
Publication Date: 2020.06.09 NXP BV
  • US10679201B2 patent drawing
  • US10679201B2 patent drawing
  • US10679201B2 patent drawing

AI summary

Within the EMV payment specification, the use of an unattended terminal to accept a payment is allowed. Creating a device that has both the EMV level 1 (L1) and level 2 (L2) payment components combined with a virtual merchant creates a “card present” transaction for an on-line or e-commerce merchant. This device can be called a personal Point of Sale (pPOS). This specification discloses personal Point of Sale (pPOS) devices and methods that can provide for card present e-commerce transactions. In some embodiments, a pPOS device can include only a secure microcontroller function (MCF), a payment kernel, a secure element, and an interface to an external system with an EMV level 3 (L3) payment application. In some embodiments, a pPOS device can further include a reader. In some embodiments, a pPOS device can still further include a sensor switch and/or a user interface function.