Secure Intermediary for Payment Data Substitution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure communication protocols, such as SSL, do not adequately address the issues of security and trust in online transactions, particularly with credit card numbers, as they do not prevent misuse by honest retailers or ensure secure storage of card information, and require active user intervention for limited-use account numbers, hindering streamlined commerce.
Innovation Solution
A secure intermediary system is positioned between client and server nodes to establish dual secure sessions, intercepting and modifying credit card numbers to limited-use account numbers, ensuring secure communication and reducing fraudulent charges by using limited-use payment numbers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SSL secure sessions are used to encrypt credit card numbers, then security against eavesdropping is improved, but trust issues remain as retailers can still misuse stored card information
Solution Approach 1:
The patent introduces a payment intermediary that acts as a mediator between the client and server. The intermediary receives the credit card number, replaces it with a limited-use account number, and forwards the transaction. This intermediary structure prevents the server from storing or misusing the actual card information while maintaining transaction functionality.
Solution Approach 2:
The patent extracts the sensitive card information from the transaction flow by having the intermediary capture and replace the card number before it reaches the server. The actual card information is taken out of the communication path and stored only by the trusted intermediary, not by the potentially untrustworthy server.
2Reliability
If limited-use account numbers are used to prevent fraud, then security against fraudulent charges is improved, but active user intervention is required which hinders streamlined commerce
Solution Approach 1:
The system implements self-service by automatically generating and managing limited-use account numbers through the intermediary without requiring user action. The intermediary autonomously intercepts card numbers, generates replacements, and manages the entire process in the background, making the security enhancement transparent to the user.
Solution Approach 2:
The intermediary performs preliminary actions by pre-generating limited-use account numbers and setting up the replacement mechanism before transactions occur. This preparation work is done automatically in advance, so when a transaction happens, the replacement has already been arranged and requires no user intervention.
3Ease of operation
If card information is stored for future transactions, then convenience of repeat purchases is improved, but risk of misuse and fraud increases
Solution Approach 1:
The intermediary serves as a trusted mediator that stores card information securely on behalf of both client and server. The server never receives or stores actual card numbers, eliminating its ability to misuse them. The intermediary can still enable convenient repeat transactions by managing limited-use account numbers that reference the stored card information without exposing it.
Data Source
AI summary
In an intermediation system, an intermediary is positioned along a communications path between a client and a server. The client sends a payment message over the communications path to consummate a payment. The intermediary receives the payment message and detects whether the message includes an account number, such as a credit card number. The intermediary replaces the account number with a limited-use payment number, such as a one-time-use credit card number. The intermediary may request the limited-use payment number from a credit card issuer. The intermediary may send a verification message to the client to verify that the client approves of the replacement of the account number with a limited-use payment number.


