Secure Guest Checkout via Device Pairing Codes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current online transaction environments lack standardization, leading to complexity and susceptibility to fraud, especially in voice user interface (VUI) devices which do not enable secure guest checkout due to inconsistent device identification.

Innovation Solution

A system comprising an application server and an untrusted user interaction device with a unique device identifier, registered with the application server, that receives input data, generates a pairing code, and wirelessly broadcasts identifier data for verification, enabling secure remote commerce (SRC) checkout processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If VUI devices are used for checkout without consistent device identification, then user convenience is improved, but security and reliability deteriorate due to fraud susceptibility

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary device identification and pairing code generation before the actual checkout transaction. The untrusted user interaction device communicates its unique device identifier to the application server in advance, and the server generates a pairing code that binds the device to the user's account. This preliminary setup enables secure guest checkout without requiring the user to manually enter payment information during the transaction.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The application server acts as an intermediary between the untrusted user interaction device and the payment processing system. It verifies the device identifier, generates the pairing code, and facilitates the secure exchange of information. This intermediary role allows the system to trust an untrusted device by mediating the authentication process through verified device identification and coded verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If device identifiers are not consistently registered, then device versatility is improved, but measurement precision deteriorates leading to inability to verify device identity

Engineering Contradiction:
Improvedevice compatibilityVSAvoiddevice identification accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The system performs preliminary device identification and pairing code generation before the actual checkout transaction. The untrusted user interaction device communicates its unique device identifier to the application server in advance, and the server generates a pairing code that binds the device to the user's account. This preliminary setup enables secure guest checkout without requiring the user to manually enter payment information during the transaction.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback mechanism where the application server verifies the device identifier and responds with a pairing code. The untrusted user interaction device uses this pairing code to verify its identity during checkout. This closed-loop feedback ensures that only properly identified and authorized devices can complete transactions, maintaining measurement precision in device identification.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If manual entry of payment data is required at multiple places, then adaptability is improved, but loss of information increases due to data compromise risk

Engineering Contradiction:
Improvecheckout flexibilityVSAvoiddata compromise risk
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The system extracts the sensitive payment information entry step from the checkout process. Instead of requiring users to manually enter payment data at multiple points, the system uses the pre-registered device identifier and generated pairing code to automatically retrieve and verify payment information. This extraction eliminates the need for repeated manual data entry while maintaining checkout flexibility through the device-based authentication mechanism.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12093917B2System and application server for secure guest checkout
Publication Date: 2024.09.17 MASTERCARD ASIAPACIFIC PTE LTD
  • US12093917B2 patent drawing
  • US12093917B2 patent drawing
  • US12093917B2 patent drawing

AI summary

A system for initiating secure guest checkout includes an application server; and an untrusted user interaction device that is in communication with the application server. The untrusted user interaction device has a unique device identifier that is registered with the application server. The untrusted user interaction device is configured to: receive input data relating to a selection of one or more items; transmit, to the application server, the selection of one or more items and the unique device identifier, for creation of a cart at the application server; communicate a pairing code received from the application server, the pairing code being associated with the cart; and wirelessly broadcast identifier data including, and/or derived from, the unique device identifier; such that a computing device that receives the identifier data and the pairing code can verify the unique device identifier and retrieve the cart from the application server for initiation of a secure remote commerce (SRC) checkout process at an SRC initiator.