Secure Data Transformation Service for Payment Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

It is challenging for online merchants to efficiently and securely integrate with multiple third-party payment processors due to restrictions on computer systems in high security zones and limited personnel access, making it difficult to deploy and maintain payment processor-specific program code.

Innovation Solution

The implementation of a secure data transformation service (SDTS) that executes payment processor-specific program code outside the high security zone, populating and redacting high security data as needed, allowing for secure interaction with payment processors without direct access to sensitive information within the high security zone.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If payment processor-specific program code is deployed on server computers in high security zones, then secure access to high security data is maintained, but system complexity and deployment difficulty increase due to restricted access and limited personnel

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a message transformation service as an intermediary component that operates within the high security zone. This service receives messages from untrusted computing systems, transforms them by populating with high security data, and sends transformed messages to trusted computing systems. This intermediary approach allows payment processor-specific code to remain outside the high security zone while still enabling secure data access through controlled message transformation, thereby reducing system complexity and deployment difficulty while maintaining data security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If payment processor-specific program code is deployed outside high security zones, then deployment and maintenance become easier, but direct access to high security data is lost

Engineering Contradiction:
Improvedeployment easeVSAvoiddata access security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The message transformation service acts as a mediator that enables payment processor-specific program code deployed outside the high security zone to indirectly access high security data. The service receives untrusted messages, populates them with high security data within the secure zone, and forwards the transformed messages to the external program code. This allows easy deployment and maintenance of payment processor code while maintaining secure data access through the intermediary service.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the system into trusted computing systems, untrusted computing systems, and a message transformation service operating in the high security zone. This segmentation allows payment processor-specific code to be deployed on untrusted systems outside the high security zone for easy deployment, while the message transformation service handles secure data access within the high security zone, thereby resolving the contradiction between deployment ease and data access security.

Inventive Principle:
Principle #1Segmentation

3Productivity

If multiple payment processors are integrated with direct access to high security data, then processing efficiency improves, but the number of personnel needed for access and maintenance increases

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidpersonnel quantity
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The message transformation service provides universal functionality that serves multiple payment processors. Instead of each payment processor requiring dedicated personnel with direct access to the high security zone, the single message transformation service handles secure data transformation for all payment processors. This multi-functional approach maintains processing efficiency for multiple payment processors while significantly reducing the quantity of personnel needed, as the service operates autonomously within the high security zone.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If physical and network access control mechanisms are implemented in high security zones, then data security is enhanced, but integration efficiency with third-party payment processors decreases

Engineering Contradiction:
Improvedata securityVSAvoidintegration efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The message transformation service serves as an intermediary that reconciles the conflict between physical/network access control and integration efficiency. The service maintains the strict access control measures in the high security zone while handling all secure data transformations. Payment processor-specific code can be deployed outside the high security zone and communicate through standardized message formats, eliminating the need for frequent physical access to the secure zone and thereby improving integration efficiency while maintaining enhanced data security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10614454B1Remote population and redaction of high security data
Publication Date: 2020.04.07 AMAZON TECH INC
  • US10614454B1 patent drawing
  • US10614454B1 patent drawing
  • US10614454B1 patent drawing

AI summary

Technologies for remote population and redaction of high security data are disclosed. A system in a low security zone that does not have access to high security data, such as credit card numbers, can provide instructions to a system in a high security zone for populating an outgoing message with high security data. The system in the high security zone can utilize the instructions to populate the outgoing message with the high security information and provide the outgoing message to an external endpoint, such as a third-party payment processor. The system in the high security zone can also redact high security data contained within an incoming message received from the endpoint before the incoming message is provided to the system in the low security zone.