pPOS Device Mirroring PCI Data for Secure Merchant Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current e-commerce transactions, both 'card present' and 'card not present,' require merchants to store customer PCI data, leading to increased costs and risks due to potential fraud and compliance burdens, especially for 'card not present' transactions where data is exposed.
Innovation Solution
A personal Point of Sale (pPOS) device that creates a 'card present' transaction by filtering and encoding payment and customer identification data elements, generating a merchant mirror transaction that does not contain actual PCI data, thereby reducing the merchant's risk and cost by allowing access to customer data for authentication and management without storing sensitive payment information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If merchants store customer PCI data in their system for authentication and customer relationship management, then they have access to customer information for business operations, but they incur extra costs and increased security risks
Solution Approach 1:
The patent segments PCI data into two categories: authentication data (PAN, name, address) that can be stored for future transactions, and sensitive payment data (CVC/CVC2, expiration date) that should not be stored. This segmentation allows merchants to retain necessary customer information while eliminating security risks associated with storing complete PCI data sets.
Solution Approach 2:
The patent extracts and removes the most sensitive PCI data elements (CVC/CVC2 and expiration date) from the transaction data that merchants receive and store. By taking out only the critical authentication fields and eliminating the highly sensitive payment verification fields, the system maintains customer relationship management capabilities while significantly reducing security exposure.
2Ease of operation
If merchants use card not present transactions for e-commerce, then transaction convenience is improved, but fraud risk and data exposure increase
Solution Approach 1:
The patent creates a simplified copy of the card present transaction process for e-commerce environments. Instead of requiring physical card insertion, the system captures card data through alternative methods (mobile device cameras, manual entry) and processes it as if it were a card present transaction, thereby maintaining security protocols while enabling remote commerce convenience.
Solution Approach 2:
The patent introduces a mobile device as an intermediary between the customer's physical card and the merchant's processing system. The mobile device captures card data through camera or NFC, transmits it securely, and facilitates the transaction without the card physically present at the merchant terminal, thus enabling convenient e-commerce while maintaining security controls.
3Reliability
If merchants use card present transactions for e-commerce, then fraud risk is reduced, but PCI data storage requirements and costs increase
Solution Approach 1:
The patent applies local quality by treating different data elements with different storage policies based on their sensitivity and necessity. Authentication data (PAN, name, address) is stored locally at the merchant for customer relationship management and fraud prevention, while sensitive payment data (CVC/CVC2, expiration date) is never stored locally, being transmitted only for immediate transaction processing and then discarded.
Data Source
AI summary
It is desirable for a merchant to not store customer PCI (Payment Card Industry) data in the merchant's system, because this would reduce cost and risk to the merchant. But the merchant still wants access to the customer primary account number (PAN) and other PCI data elements for customer authentication, customer relationship management, etc. Therefore, this specification discloses systems and methods that allow a pPOS (personal Point of Sale) device to create a mirror of the original transaction and provide that to the merchant. Then the merchant would still have access to the customer PAN and other PCI data elements, but there are no PCI or payment data in the mirror transaction, so cost and risk are reduced for the merchant.


