Secure Voice Payment System Using IVA Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for secure voice payments during call-based transactions face challenges in ensuring compliance with the Payment Card Industry Data Security Standard (PCI DSS) while maintaining cost-effectiveness and simplicity.
Innovation Solution
The proposed solution involves a secure voice payment system that uses a call manager and a secure gateway to establish a secure communication channel between the user and a secure agent, preventing sensitive information from reaching the agent or seller, thus ensuring PCI DSS compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If credit card information is collected through voice calls with human agents, then customer service quality improves, but fraud risk and security compliance complexity increase
Solution Approach 1:
The system segments the call flow into distinct phases: initial customer service interaction, secure payment collection phase with IVA, and post-payment support. During payment collection, the system automatically transfers callers to an Intelligent Virtual Agent that collects payment information without human agent involvement, thereby maintaining security while preserving customer service quality across different transaction phases
Solution Approach 2:
The Intelligent Virtual Agent acts as an intermediary between the customer and the payment processing system. The IVA automatically collects payment information through voice interaction, eliminating the need for human agents to handle sensitive card details while maintaining natural conversation flow and customer service quality
2Reliability
If digital payment solutions are implemented to eliminate human involvement, then fraud risk decreases, but customer service preference and user experience worsen
Solution Approach 1:
The system dynamically adapts its interaction mode based on the transaction phase. During payment collection, it operates in automated mode with IVA for security. For other customer service needs, it seamlessly transitions to human agent mode, providing the flexibility to deliver both security and preferred customer service experience
3Reliability
If PCI DSS compliance is enforced for all voice-based payment systems, then security improves, but system complexity and deployment cost increase
Solution Approach 1:
The system extracts the PCI DSS compliance requirement from the human agent environment and applies it only to the automated IVA payment collection phase. By removing human involvement from the payment data handling process entirely, the system achieves compliance without requiring complex security infrastructure across the entire call center environment
Solution Approach 2:
The IVA implements temporary, session-based payment collection where sensitive information is processed in-memory and immediately discarded after transaction completion. This approach achieves security compliance without requiring persistent secure storage infrastructure, reducing system complexity and deployment costs
Data Source
AI summary
The techniques herein are directed generally to improving voice and digital payment systems for secure payments, and, more particularly, to securing voice payments for transactions taking place over a phone call. That is, the techniques herein facilitate secured payments over voice channels for transactions between a caller (or a callee) and an agent of the selling organization, such as a call center agent. The techniques herein specifically ensure compliance with the Payment Card Industry Data Security Standard (PCI DSS) while reducing the complexity and cost of deploying PCI-compliant payment systems.


