Personal Point of Sale Device for Secure Card Present E-Commerce

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

E-commerce transactions are typically processed as 'card not present,' leading to higher fraud risks and increased interchange rates for merchants due to exposed payment card industry (PCI) data, necessitating a solution for 'card present' transactions that secure customer data and reduce fraud.

Innovation Solution

A personal Point of Sale (pPOS) device with a secure microcontroller and secure element, capable of processing payments locally or remotely, using EMV level 1 and level 2 components, supports Point to Point encryption (P2PE) and End to End encryption (E2EE), allowing customers to authenticate transactions without exposing their credit or debit account numbers, and enabling both contact and contactless payments through various communication protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If e-commerce transactions are processed as 'card not present' with customer entering card data on merchant website, then transaction convenience is improved, but fraud risk increases and interchange rates increase due to exposed PCI data

Engineering Contradiction:
Improvetransaction convenienceVSAvoidfraud risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a personal Point of Sale (pPOS) device as an intermediary between the customer and the merchant's e-commerce website. The pPOS device contains a payment kernel that securely stores and processes payment card data, acting as a mediator that eliminates the need for customers to manually enter sensitive card information on potentially insecure merchant websites. This intermediary approach maintains transaction convenience while significantly reducing fraud risk by preventing PCI data exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the payment processing system into distinct components: the pPOS device (containing secure payment kernel and secure element), the merchant's e-commerce website, and the payment network. By separating the sensitive payment data storage and processing functions into the dedicated pPOS device, the system achieves both convenience and security - customers can transact online without exposing PCI data to the merchant's website environment.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If e-commerce transactions are processed as 'card not present' with customer entering card data on merchant website, then transaction convenience is improved, but interchange rates increase due to higher fraud risk

Engineering Contradiction:
Improvetransaction convenienceVSAvoidinterchange rates
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The pPOS device serves as an intermediary that enables 'card present' transaction treatment for e-commerce purchases. By using the pPOS device with its secure payment kernel, customers can authenticate payments without manually entering card data online, allowing merchants to process transactions at lower interchange rates applicable to card-present transactions while maintaining the convenience of online shopping.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the transaction parameter from 'card not present' to 'card present' by introducing the pPOS device. This parameter change fundamentally alters the interchange rate structure, enabling merchants to access lower interchange rates typically associated with in-person transactions while maintaining e-commerce convenience. The secure element and payment kernel in the pPOS device enable this parameter transformation.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If customers enter their card account number on merchant's e-commerce web site, then transaction processing is simplified, but PCI data exposure increases creating security vulnerabilities

Engineering Contradiction:
Improvetransaction processing complexityVSAvoidPCI data exposure
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive PCI data storage and processing functions from the merchant's e-commerce website environment and places them into the customer's personal Point of Sale device. The secure element and payment kernel in the pPOS device hold the payment card information, eliminating the need for customers to manually input card data on merchant websites. This extraction removes PCI data exposure risks from the online transaction environment while maintaining simplified transaction processing.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If a personal Point of Sale device with local and/or remote payment kernel is used, then PCI data security is improved and fraud is reduced, but device complexity increases

Engineering Contradiction:
ImprovePCI data securityVSAvoidpPOS device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs the personal Point of Sale device with multi-functional capabilities that justify the increased complexity. The pPOS device not only stores payment card data securely in its secure element but also processes payments, authenticates transactions, and can function with both local and remote payment kernels. This universal device serves multiple functions (secure storage, processing, authentication) that collectively enhance PCI data security while the integrated design manages the complexity burden.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11514418B2Personal point of sale (pPOS) device with a local and/or remote payment kernel that provides for card present e-commerce transaction
Publication Date: 2022.11.29 NXP BV
  • US11514418B2 patent drawing
  • US11514418B2 patent drawing
  • US11514418B2 patent drawing

AI summary

Within EMV payment specification, use of an unattended terminal to accept a payment is allowed. Creating a device that has both EMV level 1 (L1) and level 2 (L2) payment components combined with a virtual merchant creates a “card present” transaction for an on-line or e-commerce merchant. This device can be called a personal Point of Sale (pPOS). This specification discloses pPOS devices and methods that can provide for card present e-commerce transactions with a payment kernel that is local and/or remote to a pPOS device. In some embodiments, a pPOS device can include only a secure microcontroller function (MCF) and a secure element, wherein a payment kernel configured to process payment is local, remote, or split between local and remote to the device. In some embodiments, a pPOS device can further include a reader, a sensor switch, and/or a user interface function.