Secure Data Transformation Service for Payment Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
It is challenging for online merchants to efficiently and securely integrate with multiple third-party payment processors due to restrictions on computer systems in high security zones and limited personnel access, making it difficult to deploy and maintain payment processor-specific program code.
Innovation Solution
The implementation of a secure data transformation service (SDTS) that executes payment processor-specific program code outside the high security zone, populating and redacting high security data as needed, allowing for secure interaction with payment processors without direct access to sensitive information within the high security zone.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If payment processor-specific program code is deployed on server computers in high security zones, then secure access to high security data is maintained, but system complexity and deployment difficulty increase due to restricted access and limited personnel
Solution Approach 1:
The patent introduces a message transformation service as an intermediary component that operates within the high security zone. This service receives messages from untrusted computing systems, transforms them by populating with high security data, and sends transformed messages to trusted computing systems. This intermediary approach allows payment processor-specific code to remain outside the high security zone while still enabling secure data access through controlled message transformation, thereby reducing system complexity and deployment difficulty while maintaining data security.
2Ease of operation
If payment processor-specific program code is deployed outside high security zones, then deployment and maintenance become easier, but direct access to high security data is lost
Solution Approach 1:
The message transformation service acts as a mediator that enables payment processor-specific program code deployed outside the high security zone to indirectly access high security data. The service receives untrusted messages, populates them with high security data within the secure zone, and forwards the transformed messages to the external program code. This allows easy deployment and maintenance of payment processor code while maintaining secure data access through the intermediary service.
Solution Approach 2:
The patent segments the system into trusted computing systems, untrusted computing systems, and a message transformation service operating in the high security zone. This segmentation allows payment processor-specific code to be deployed on untrusted systems outside the high security zone for easy deployment, while the message transformation service handles secure data access within the high security zone, thereby resolving the contradiction between deployment ease and data access security.
3Productivity
If multiple payment processors are integrated with direct access to high security data, then processing efficiency improves, but the number of personnel needed for access and maintenance increases
Solution Approach 1:
The message transformation service provides universal functionality that serves multiple payment processors. Instead of each payment processor requiring dedicated personnel with direct access to the high security zone, the single message transformation service handles secure data transformation for all payment processors. This multi-functional approach maintains processing efficiency for multiple payment processors while significantly reducing the quantity of personnel needed, as the service operates autonomously within the high security zone.
4Reliability
If physical and network access control mechanisms are implemented in high security zones, then data security is enhanced, but integration efficiency with third-party payment processors decreases
Solution Approach 1:
The message transformation service serves as an intermediary that reconciles the conflict between physical/network access control and integration efficiency. The service maintains the strict access control measures in the high security zone while handling all secure data transformations. Payment processor-specific code can be deployed outside the high security zone and communicate through standardized message formats, eliminating the need for frequent physical access to the secure zone and thereby improving integration efficiency while maintaining enhanced data security.
Data Source
AI summary
Technologies for remote population and redaction of high security data are disclosed. A system in a low security zone that does not have access to high security data, such as credit card numbers, can provide instructions to a system in a high security zone for populating an outgoing message with high security data. The system in the high security zone can utilize the instructions to populate the outgoing message with the high security information and provide the outgoing message to an external endpoint, such as a third-party payment processor. The system in the high security zone can also redact high security data contained within an incoming message received from the endpoint before the incoming message is provided to the system in the low security zone.


