Proxy Payment Card Data for Online Transaction Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online payment transactions expose sensitive payment card information to potential misappropriation due to varying levels of data security among merchants, making consumers' information vulnerable to unauthorized acquisition by hackers or fraudulent entities.

Innovation Solution

A technique where a user device requests and receives temporary proxy payment card information from a third-party payment processing service, which is then populated into the merchant's transaction interface, ensuring the real payment card information remains secure and is only accessed by the payment processing service for authorization, thereby protecting the consumer's data from exposure to merchants or unauthorized parties.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If consumers directly provide real payment card information to merchants for online transactions, then transaction processing is simple and direct, but payment card information becomes vulnerable to misappropriation and unauthorized acquisition by hackers

Engineering Contradiction:
Improvepayment card information securityVSAvoidtransaction processing system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a payment processing service as an intermediary between consumers and merchants. This service generates temporary proxy payment card information that is provided to merchants instead of real card information. The intermediary maintains the association between proxy and real card information, enabling transaction authorization while keeping real card data hidden from merchants and potential hackers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If merchants store consumers' real payment card information for future transactions, then convenience for repeat purchases is improved, but the risk of data breaches and unauthorized acquisition by hackers increases

Engineering Contradiction:
Improverepeat transaction convenienceVSAvoidvulnerability to data breaches
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent employs temporary proxy payment card information that is generated for each transaction or session and then discarded. These proxy card details have limited validity and cannot be reused after expiration, eliminating the long-term storage risk associated with real card information while maintaining convenience for repeat transactions through automatic regeneration of new proxy credentials.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If a third-party payment processing service is introduced to protect payment card information, then data security is improved, but the transaction system becomes more complex

Engineering Contradiction:
Improvepayment card information protectionVSAvoidtransaction authorization system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates proxy copies of payment card information that replicate the essential functionality needed for transaction processing without containing the sensitive real card data. These proxy copies include necessary elements like card numbers, expiration dates, and security codes that mirror the structure of real card information, allowing merchants to process transactions using the same systems without direct exposure to real card data.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20220292503A1Data security enhancement for online transactions involving payment card accounts
Publication Date: 2022.09.15 BLOCK INC
  • US20220292503A1 patent drawing
  • US20220292503A1 patent drawing
  • US20220292503A1 patent drawing

AI summary

Payment card information of a consumer is protected during online payment card based transactions by equipping a user device of the consumer with a control that, when activated by the consumer during an online shopping session, causes the user device automatically to request and receive, from a third-party payment processing service (PPS), temporary proxy payment card information, and to populate that information into an online transaction web interface of the merchant. The temporary proxy payment card information is associated in the third-party PPS with a real payment card account of the consumer. When the PPS receives a transaction authorization request from a merchant via a payment card network, the PPS uses the consumer's real payment card information to authorize the transaction. The consumer's real payment card information is never exposed to the merchant.