pPOS Device Mirroring PCI Data for Secure Merchant Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current e-commerce transactions, both 'card present' and 'card not present,' require merchants to store customer PCI data, leading to increased costs and risks due to potential fraud and compliance burdens, especially for 'card not present' transactions where data is exposed.

Innovation Solution

A personal Point of Sale (pPOS) device that creates a 'card present' transaction by filtering and encoding payment and customer identification data elements, generating a merchant mirror transaction that does not contain actual PCI data, thereby reducing the merchant's risk and cost by allowing access to customer data for authentication and management without storing sensitive payment information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If merchants store customer PCI data in their system for authentication and customer relationship management, then they have access to customer information for business operations, but they incur extra costs and increased security risks

Engineering Contradiction:
Improveaccess to customer PCI dataVSAvoidsecurity risk and compliance cost
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent segments PCI data into two categories: authentication data (PAN, name, address) that can be stored for future transactions, and sensitive payment data (CVC/CVC2, expiration date) that should not be stored. This segmentation allows merchants to retain necessary customer information while eliminating security risks associated with storing complete PCI data sets.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts and removes the most sensitive PCI data elements (CVC/CVC2 and expiration date) from the transaction data that merchants receive and store. By taking out only the critical authentication fields and eliminating the highly sensitive payment verification fields, the system maintains customer relationship management capabilities while significantly reducing security exposure.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If merchants use card not present transactions for e-commerce, then transaction convenience is improved, but fraud risk and data exposure increase

Engineering Contradiction:
Improvetransaction convenienceVSAvoidfraud risk and data exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent creates a simplified copy of the card present transaction process for e-commerce environments. Instead of requiring physical card insertion, the system captures card data through alternative methods (mobile device cameras, manual entry) and processes it as if it were a card present transaction, thereby maintaining security protocols while enabling remote commerce convenience.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a mobile device as an intermediary between the customer's physical card and the merchant's processing system. The mobile device captures card data through camera or NFC, transmits it securely, and facilitates the transaction without the card physically present at the merchant terminal, thus enabling convenient e-commerce while maintaining security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If merchants use card present transactions for e-commerce, then fraud risk is reduced, but PCI data storage requirements and costs increase

Engineering Contradiction:
Improvefraud reductionVSAvoidPCI data storage volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by treating different data elements with different storage policies based on their sensitivity and necessity. Authentication data (PAN, name, address) is stored locally at the merchant for customer relationship management and fraud prevention, while sensitive payment data (CVC/CVC2, expiration date) is never stored locally, being transmitted only for immediate transaction processing and then discarded.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11620623B2Merchant transaction mirroring for personal point of sale (pPOS) for card present e-commerce and in vehicle transaction
Publication Date: 2023.04.04 NXP BV
  • US11620623B2 patent drawing
  • US11620623B2 patent drawing
  • US11620623B2 patent drawing

AI summary

It is desirable for a merchant to not store customer PCI (Payment Card Industry) data in the merchant's system, because this would reduce cost and risk to the merchant. But the merchant still wants access to the customer primary account number (PAN) and other PCI data elements for customer authentication, customer relationship management, etc. Therefore, this specification discloses systems and methods that allow a pPOS (personal Point of Sale) device to create a mirror of the original transaction and provide that to the merchant. Then the merchant would still have access to the customer PAN and other PCI data elements, but there are no PCI or payment data in the mirror transaction, so cost and risk are reduced for the merchant.