Secure Checkout Initiation via Enrolled Device Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users are wary of card-not-present transactions due to high fraud risks associated with exposing sensitive payment information, especially when using untrusted devices for checkout processes.
Innovation Solution
A method and system for securely initiating a checkout using an enrolled device, which involves receiving a user identifier from an untrusted device, determining if it's associated with an enrolled device, retrieving user data, sending instructions for checkout, and initiating the process over a secure communications channel, ensuring secure transmission of payment information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users provide payment information on untrusted devices for card-not-present transactions, then transaction convenience is improved, but security risk increases due to fraud exposure
Solution Approach 1:
The patent introduces a digital wallet application as an intermediary between the user's payment information and the merchant system. The digital wallet stores payment details securely on the user's device and acts as a mediator that transmits only necessary transaction data to merchants, never exposing the actual payment card information. This resolves the contradiction by maintaining convenience (direct digital transactions) while eliminating security risks (no exposure of sensitive payment data on untrusted devices).
Solution Approach 2:
The patent creates a digital copy of the payment card information stored securely in the digital wallet application, rather than using the actual card details. This virtual copy can be transmitted electronically for transactions without exposing the real payment information. The copy enables card-not-present transactions to proceed conveniently while the original sensitive data remains protected on the user's device, resolving the security-convenience contradiction.
2Adaptability or versatility
If users shop on merchant websites requiring payment information entry, then purchasing capability is improved, but fraud risk increases due to exposure of sensitive payment information
Solution Approach 1:
The digital wallet application serves as an intermediary layer between the merchant's payment processing system and the user's actual payment information. When users shop on merchant websites, the digital wallet handles the payment information transmission securely, acting as a trusted mediator that prevents direct exposure of sensitive card details to potentially untrusted merchant systems, thereby maintaining purchasing capability while reducing fraud risk.
Solution Approach 2:
The system uses a digital copy of payment card information stored securely in the user's digital wallet rather than transmitting actual card details to merchants. This copy enables versatile online purchasing across different merchant platforms while the original sensitive payment information remains protected on the user's device, eliminating fraud risk associated with exposing real card data on various merchant websites.
3Ease of operation
If users use public kiosks or terminals for transactions, then accessibility is improved, but security risk increases due to potential exposure of PAN on untrusted devices
Solution Approach 1:
The digital wallet application acts as an intermediary that enables users to conduct transactions on public kiosks or terminals without exposing their payment information to these untrusted devices. The digital wallet securely manages the payment data and communicates only necessary transaction authorizations to the public terminals, maintaining accessibility to public transaction points while eliminating the security risk of PAN exposure on untrusted devices.
Solution Approach 2:
The system transmits a digital copy of payment information from the user's secure digital wallet to the public terminal, rather than requiring the user to manually enter or expose their actual card details on the untrusted public device. This copy enables convenient use of accessible public transaction points while the original sensitive payment information remains protected on the user's personal device, resolving the accessibility-security contradiction.
Data Source
AI summary
A method, performed by an initiator system, for securely initiating a checkout with an enrolled device includes the steps of receiving, from an untrusted device, a checkout request including a user identifier; determining whether the user identifier is associated with one of a plurality of enrolled devices in an enrolled device database; responsive to a determination that the user identifier is associated with an enrolled device, retrieving user data associated with the user identifier; sending, to the untrusted device, a request for instructions to perform a checkout with the enrolled device; receiving, from the untrusted device, instructions to perform the checkout with the enrolled device; generating a request to perform the checkout with the enrolled device; and initiating a checkout by sending, to a communication system, a request to initiate a checkout with the enrolled device over a secure communications channel.


