Secure Guest Checkout via Device Pairing Codes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current online transaction environments lack standardization, leading to complexity and susceptibility to fraud, especially in voice user interface (VUI) devices which do not enable secure guest checkout due to inconsistent device identification.
Innovation Solution
A system comprising an application server and an untrusted user interaction device with a unique device identifier, registered with the application server, that receives input data, generates a pairing code, and wirelessly broadcasts identifier data for verification, enabling secure remote commerce (SRC) checkout processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If VUI devices are used for checkout without consistent device identification, then user convenience is improved, but security and reliability deteriorate due to fraud susceptibility
Solution Approach 1:
The system performs preliminary device identification and pairing code generation before the actual checkout transaction. The untrusted user interaction device communicates its unique device identifier to the application server in advance, and the server generates a pairing code that binds the device to the user's account. This preliminary setup enables secure guest checkout without requiring the user to manually enter payment information during the transaction.
Solution Approach 2:
The application server acts as an intermediary between the untrusted user interaction device and the payment processing system. It verifies the device identifier, generates the pairing code, and facilitates the secure exchange of information. This intermediary role allows the system to trust an untrusted device by mediating the authentication process through verified device identification and coded verification.
2Adaptability or versatility
If device identifiers are not consistently registered, then device versatility is improved, but measurement precision deteriorates leading to inability to verify device identity
Solution Approach 1:
The system performs preliminary device identification and pairing code generation before the actual checkout transaction. The untrusted user interaction device communicates its unique device identifier to the application server in advance, and the server generates a pairing code that binds the device to the user's account. This preliminary setup enables secure guest checkout without requiring the user to manually enter payment information during the transaction.
Solution Approach 2:
The system implements a feedback mechanism where the application server verifies the device identifier and responds with a pairing code. The untrusted user interaction device uses this pairing code to verify its identity during checkout. This closed-loop feedback ensures that only properly identified and authorized devices can complete transactions, maintaining measurement precision in device identification.
3Adaptability or versatility
If manual entry of payment data is required at multiple places, then adaptability is improved, but loss of information increases due to data compromise risk
Solution Approach 1:
The system extracts the sensitive payment information entry step from the checkout process. Instead of requiring users to manually enter payment data at multiple points, the system uses the pre-registered device identifier and generated pairing code to automatically retrieve and verify payment information. This extraction eliminates the need for repeated manual data entry while maintaining checkout flexibility through the device-based authentication mechanism.
Data Source
AI summary
A system for initiating secure guest checkout includes an application server; and an untrusted user interaction device that is in communication with the application server. The untrusted user interaction device has a unique device identifier that is registered with the application server. The untrusted user interaction device is configured to: receive input data relating to a selection of one or more items; transmit, to the application server, the selection of one or more items and the unique device identifier, for creation of a cart at the application server; communicate a pairing code received from the application server, the pairing code being associated with the cart; and wirelessly broadcast identifier data including, and/or derived from, the unique device identifier; such that a computing device that receives the identifier data and the pairing code can verify the unique device identifier and retrieve the cart from the application server for initiation of a secure remote commerce (SRC) checkout process at an SRC initiator.


