Smart Card Secure Transaction Gateway Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Online transactions pose a risk of exposing sensitive information due to substandard security in third-party systems and rogue systems that mimic legitimate ones, and even digital wallets do not fully address these security challenges, increasing the risk of data exposure.
Innovation Solution
A smart card with embedded integrated circuitry that allows users to enter unique codes generated by vendors directly into the card, establishing a secure communication channel with a secure transaction gateway without exposing sensitive information to third-party systems, using a keypad, microprocessor, and wireless interface to encrypt and process transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users enter sensitive transaction information into third-party systems (web browsers, mobile applications), then online transactions can be completed, but the security of sensitive information is compromised due to substandard security or compromised third-party systems
Solution Approach 1:
The patent extracts sensitive transaction information from the third-party system environment and processes it locally within a secure element on the user's device. The secure element generates authentication credentials independently, removing the need to transmit sensitive data through potentially compromised third-party systems, thereby maintaining transaction functionality while eliminating security risks.
Solution Approach 2:
The patent introduces a secure element as an intermediary between the user's device and third-party systems. This secure element acts as a trusted mediator that handles sensitive information locally and communicates only authenticated credentials to external systems, preventing direct exposure of sensitive data to untrusted third-party environments.
2Ease of operation
If digital wallets are used to store sensitive transaction information, then transaction convenience is improved, but the risk of data exposure increases due to additional third-party applications that can track and capture sensitive information
Solution Approach 1:
The patent segments the transaction system into distinct functional components: a secure element that stores and processes sensitive information, and external applications that interact only with authenticated credentials. This segmentation isolates sensitive data within the secure element, preventing external applications from accessing or tracking it, while still enabling convenient transactions through the external interface.
Solution Approach 2:
The patent implements local quality by creating a specialized secure environment within the user's device that has different security properties than the rest of the system. The secure element maintains local control over sensitive information with restricted access permissions, allowing convenient external interaction while preserving local security autonomy that prevents tracking by third-party applications.
3Productivity
If users provide sensitive transaction information to vendors or third-party systems, then purchases can be completed, but the information may be inadvertently disclosed or misused
Solution Approach 1:
The patent extracts the sensitive information handling function from the vendor's third-party system and relocates it to the user's secure element. The secure element performs authentication and generates credentials locally, extracting the need to transmit sensitive data to the vendor system. This maintains transaction completion capability while eliminating the information exposure risk associated with providing sensitive data to external vendors.
Data Source
AI summary
Typically, online transactions, such as online purchases of products or services require entering sensitive transaction information into a third-party web browser or application. This may expose sensitive transaction information to an increased risk of inadvertent disclosure. Apparatus and methods are provided for a smart card which enables users to securely complete online transactions without entering any sensitive transaction information into a third-party system. Vendor websites may be configured to generate a unique code identifying the vendor offering the product/service, the product/service and price of the product/service. The smart card includes a keypad for entering the unique code and completing payment for the desired product/service. The smart card will include a microprocessor and wireless interface. The wireless interface provides wireless communication capabilities and the ability to initiate online payments based on information captured by the keypad.


