Secure In-Line Payments via RIA Runtime Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for secure financial transactions through rich Internet applications (RIAs) on mobile devices lack secure in-line payment capabilities, as they redirect users to external service providers for authentication, exposing them to phishing and man-in-the-middle attacks without standard validation mechanisms for app legitimacy.

Innovation Solution

Implementing a payment library on the user's device that communicates with the RIA runtime to authenticate the application and user, using oblivious hashing and out-of-band confirmations to ensure app validity and prevent attacks, while providing secure in-line payment functionalities within the RIA framework.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users are redirected to external service providers for authentication, then payment processing can be performed, but users are exposed to phishing and man-in-the-middle attacks without standard validation mechanisms

Engineering Contradiction:
Improvetransaction securityVSAvoidphishing and man-in-the-middle attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary validation mechanism where the RIA runtime acts as a mediator between the user and the payment transaction. The runtime validates the legitimacy of the RIA and the transaction before allowing payment processing, creating a secure intermediary layer that prevents direct exposure to phishing and man-in-the-middle attacks while still enabling payment processing to occur.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If standard validation mechanisms are implemented for app legitimacy, then security against attacks is improved, but the complexity of the payment system increases

Engineering Contradiction:
Improveapp validity validationVSAvoidpayment system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the validation functionality directly into the RIA runtime framework itself, combining the security validation mechanisms with the existing runtime infrastructure. This integration approach allows validation of app legitimacy to be performed as an inherent part of the runtime operation, reducing the need for separate complex validation systems while maintaining strong security against phishing and man-in-the-middle attacks.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If in-line payment capabilities are provided within RIA framework, then user experience is improved, but secure authentication becomes more difficult to implement

Engineering Contradiction:
Improvein-line payment capabilityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary authentication and validation actions performed by the RIA runtime before the in-line payment process begins. The runtime预先 validates the legitimacy of the RIA and establishes secure authentication credentials in advance, enabling smooth in-line payment capabilities while maintaining strong authentication security through these preliminary security measures.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250104066A1Secure in-line payments
Publication Date: 2025.03.27 PAYPAL INC
  • US20250104066A1 patent drawing
  • US20250104066A1 patent drawing
  • US20250104066A1 patent drawing

AI summary

Methods and systems are provided for making secure financial transactions, such as purchase payments, using rich Internet applications (RIA) running an RIA runtime (also referred to as a platform or framework) on the user's smart phone or other mobile device. Embodiments differ from the usual way of re-directing a user from a third-party application and authenticating the user by providing secure in-line payments from a rich Internet application running on an RIA runtime. A system includes: a mobile device executing a rich Internet application running on an RIA runtime; a payment library communicating with the RIA runtime and a service provider, for which the payment library communicates with the service provider to authenticate the rich Internet application; and in response to authentication by the service provider, facilitates secure financial transactions via the rich Internet application.