Personal Point of Sale Device for Secure Card Present E-Commerce
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
E-commerce transactions are typically processed as 'card not present,' leading to higher fraud risks and increased interchange rates for merchants due to exposed payment card industry (PCI) data, necessitating a solution for 'card present' transactions that secure customer data and reduce fraud.
Innovation Solution
A personal Point of Sale (pPOS) device with a secure microcontroller and secure element, capable of processing payments locally or remotely, using EMV level 1 and level 2 components, supports Point to Point encryption (P2PE) and End to End encryption (E2EE), allowing customers to authenticate transactions without exposing their credit or debit account numbers, and enabling both contact and contactless payments through various communication protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If e-commerce transactions are processed as 'card not present' with customer entering card data on merchant website, then transaction convenience is improved, but fraud risk increases and interchange rates increase due to exposed PCI data
Solution Approach 1:
The patent introduces a personal Point of Sale (pPOS) device as an intermediary between the customer and the merchant's e-commerce website. The pPOS device contains a payment kernel that securely stores and processes payment card data, acting as a mediator that eliminates the need for customers to manually enter sensitive card information on potentially insecure merchant websites. This intermediary approach maintains transaction convenience while significantly reducing fraud risk by preventing PCI data exposure.
Solution Approach 2:
The patent segments the payment processing system into distinct components: the pPOS device (containing secure payment kernel and secure element), the merchant's e-commerce website, and the payment network. By separating the sensitive payment data storage and processing functions into the dedicated pPOS device, the system achieves both convenience and security - customers can transact online without exposing PCI data to the merchant's website environment.
2Ease of operation
If e-commerce transactions are processed as 'card not present' with customer entering card data on merchant website, then transaction convenience is improved, but interchange rates increase due to higher fraud risk
Solution Approach 1:
The pPOS device serves as an intermediary that enables 'card present' transaction treatment for e-commerce purchases. By using the pPOS device with its secure payment kernel, customers can authenticate payments without manually entering card data online, allowing merchants to process transactions at lower interchange rates applicable to card-present transactions while maintaining the convenience of online shopping.
Solution Approach 2:
The patent changes the transaction parameter from 'card not present' to 'card present' by introducing the pPOS device. This parameter change fundamentally alters the interchange rate structure, enabling merchants to access lower interchange rates typically associated with in-person transactions while maintaining e-commerce convenience. The secure element and payment kernel in the pPOS device enable this parameter transformation.
3Device complexity
If customers enter their card account number on merchant's e-commerce web site, then transaction processing is simplified, but PCI data exposure increases creating security vulnerabilities
Solution Approach 1:
The patent extracts the sensitive PCI data storage and processing functions from the merchant's e-commerce website environment and places them into the customer's personal Point of Sale device. The secure element and payment kernel in the pPOS device hold the payment card information, eliminating the need for customers to manually input card data on merchant websites. This extraction removes PCI data exposure risks from the online transaction environment while maintaining simplified transaction processing.
4Reliability
If a personal Point of Sale device with local and/or remote payment kernel is used, then PCI data security is improved and fraud is reduced, but device complexity increases
Solution Approach 1:
The patent designs the personal Point of Sale device with multi-functional capabilities that justify the increased complexity. The pPOS device not only stores payment card data securely in its secure element but also processes payments, authenticates transactions, and can function with both local and remote payment kernels. This universal device serves multiple functions (secure storage, processing, authentication) that collectively enhance PCI data security while the integrated design manages the complexity burden.
Data Source
AI summary
Within EMV payment specification, use of an unattended terminal to accept a payment is allowed. Creating a device that has both EMV level 1 (L1) and level 2 (L2) payment components combined with a virtual merchant creates a “card present” transaction for an on-line or e-commerce merchant. This device can be called a personal Point of Sale (pPOS). This specification discloses pPOS devices and methods that can provide for card present e-commerce transactions with a payment kernel that is local and/or remote to a pPOS device. In some embodiments, a pPOS device can include only a secure microcontroller function (MCF) and a secure element, wherein a payment kernel configured to process payment is local, remote, or split between local and remote to the device. In some embodiments, a pPOS device can further include a reader, a sensor switch, and/or a user interface function.


