POS App Deployment via Pre-Validation and Tokenization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current payment processing systems using mobile devices as point-of-sale terminals face challenges in ensuring the security and compliance of POS applications, particularly in handling sensitive payment card data, which can lead to vulnerabilities and non-compliance with PCI requirements.

Innovation Solution

The deployment of POS applications on payment terminals involves scanning for security and compliance, cryptographic signing, and verification to ensure integrity, followed by controlled deployment using a deployment plan, which includes tokenization of payment data to prevent exposure to merchant systems and maintain PCI compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If POS applications are deployed directly to mobile payment terminals without scanning and verification, then deployment speed and ease of operation are improved, but security and compliance reliability deteriorate

Engineering Contradiction:
Improvedeployment speedVSAvoidsecurity and compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary scanning, security verification, and cryptographic signing of POS applications before deployment to mobile payment terminals. This advance preparation ensures that only secure and compliant applications are deployed, resolving the contradiction by maintaining high deployment speed while ensuring security and compliance reliability through pre-validation mechanisms

Inventive Principle:
Principle #10Preliminary action

2Reliability

If POS applications are scanned and cryptographically signed before deployment, then security and compliance are improved, but device complexity and processing time increase

Engineering Contradiction:
Improvesecurity and complianceVSAvoiddeployment process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary server that centralizes the scanning, security verification, and cryptographic signing processes for POS applications. This intermediary handles the complex security operations remotely, reducing the complexity burden on mobile payment terminals while maintaining high security and compliance standards through centralized control

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If payment card data is processed directly through merchant systems, then processing efficiency is improved, but PCI compliance and security are worsened due to data exposure

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidPCI compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system extracts sensitive payment card data from merchant systems and routes it through a dedicated payment processing application that communicates directly with the payment gateway. This extraction removes sensitive data exposure from merchant systems, maintaining PCI compliance while preserving processing efficiency through direct payment gateway communication

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20240152394A1Deploying applications to a payment terminal
Publication Date: 2024.05.09 STRIPE LLC
  • US20240152394A1 patent drawing
  • US20240152394A1 patent drawing
  • US20240152394A1 patent drawing

AI summary

The present disclosure is directed to deployment of applications to mobile devices such as, for example, payment terminals. In some embodiments, a method includes uploading a mobile application that is for execution on a group of mobile devices; preparing the mobile application for deployment; receiving a first request with a deploy plan that specifies parameters and a subset of mobile devices for deploying the mobile application; and deploying the mobile application to the subset of mobile devices according to the deploy plan.