Secured Intermediate Server Payment Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online payment systems face challenges in ensuring secure authentication and reducing fraud, leading to potential losses for merchants due to the complexity of existing solutions like 3D-Secure, which complicates the purchasing process and increases the risk of transaction repudiation.

Innovation Solution

A method involving a secured intermediate server and payment module that establishes a point-to-point secured link using encryption keys and microcircuit card data to process transactions, ensuring authentication and preventing repudiation, while keeping sensitive information away from merchants.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If 3D-Secure protocol is implemented for authentication, then payment security is improved, but user operation complexity increases and sales are reduced

Engineering Contradiction:
Improvepayment securityVSAvoiduser operation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a payment module as an intermediary component that mediates between the user terminal and the payment network. This module handles the complex authentication processes in the background, presenting a simplified interface to users while maintaining strong security protocols. The payment module acts as a buffer that translates complex security requirements into simple user actions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the complex authentication logic from the main payment flow and isolates it within the payment module. By separating the authentication function into a dedicated component, the system maintains security while preventing authentication complexity from blocking the overall payment process. The extracted authentication logic can be executed independently without impeding user experience.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If 3D-Secure protocol is implemented for authentication, then payment security is improved, but transaction repudiation risk increases

Engineering Contradiction:
Improvepayment securityVSAvoidtransaction repudiation risk
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent implements preliminary authentication actions through the payment module before the actual transaction occurs. The module performs pre-authentication checks, validates user identity in advance, and establishes binding agreements that prevent later repudiation. By completing authentication preliminarily, the system creates an uncontestable record of authorized transactions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms where the payment module continuously monitors and reports on the authentication status and transaction validity. This feedback loop ensures that any attempts at repudiation are detected and prevented, as the system maintains ongoing verification of the transaction's authenticity and authorization.

Inventive Principle:
Principle #23Feedback

3Device complexity

If merchant collects sensitive payment data, then payment processing is simplified, but security risk increases

Engineering Contradiction:
Improvepayment processing complexityVSAvoidsecurity risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive payment data collection and processing functions from the merchant system and relocates them to the dedicated payment module. This separation ensures that merchants never handle or store sensitive payment information, eliminating their security liability while maintaining streamlined payment processing through the specialized module that is designed specifically for secure data handling.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10832240B2Methods for processing transactional data, and corresponding devices and programs
Publication Date: 2020.11.10 BANKS & ACQUIRERS INT HLDG SAS
  • US10832240B2 patent drawing
  • US10832240B2 patent drawing
  • US10832240B2 patent drawing

AI summary

The invention relates to a method for processing transactional data, implemented within a secured intermediate server, connected to a communications network. Such a method comprises:reception, by the secured intermediate server, of a request for payment comprising a piece of data representing an identification of a communications terminal used by a user to carry out a purchase operation with a merchant server connected to said communications network;setting up a secured point-to-point link with a payment module of the communications terminal;transmission, to said payment module, of a request for execution of payment;reception, by the payment module, of a piece of information on payment;transmission of a message of information to the merchant server.