Smart Card Secure Transaction Gateway Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online transactions pose a risk of exposing sensitive information due to substandard security in third-party systems and rogue systems that mimic legitimate ones, and even digital wallets do not fully address these security challenges, increasing the risk of data exposure.

Innovation Solution

A smart card with embedded integrated circuitry that allows users to enter unique codes generated by vendors directly into the card, establishing a secure communication channel with a secure transaction gateway without exposing sensitive information to third-party systems, using a keypad, microprocessor, and wireless interface to encrypt and process transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users enter sensitive transaction information into third-party systems (web browsers, mobile applications), then online transactions can be completed, but the security of sensitive information is compromised due to substandard security or compromised third-party systems

Engineering Contradiction:
Improveonline transaction completionVSAvoidsecurity of sensitive information
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts sensitive transaction information from the third-party system environment and processes it locally within a secure element on the user's device. The secure element generates authentication credentials independently, removing the need to transmit sensitive data through potentially compromised third-party systems, thereby maintaining transaction functionality while eliminating security risks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a secure element as an intermediary between the user's device and third-party systems. This secure element acts as a trusted mediator that handles sensitive information locally and communicates only authenticated credentials to external systems, preventing direct exposure of sensitive data to untrusted third-party environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If digital wallets are used to store sensitive transaction information, then transaction convenience is improved, but the risk of data exposure increases due to additional third-party applications that can track and capture sensitive information

Engineering Contradiction:
Improvetransaction convenienceVSAvoidrisk of data exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the transaction system into distinct functional components: a secure element that stores and processes sensitive information, and external applications that interact only with authenticated credentials. This segmentation isolates sensitive data within the secure element, preventing external applications from accessing or tracking it, while still enabling convenient transactions through the external interface.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by creating a specialized secure environment within the user's device that has different security properties than the rest of the system. The secure element maintains local control over sensitive information with restricted access permissions, allowing convenient external interaction while preserving local security autonomy that prevents tracking by third-party applications.

Inventive Principle:
Principle #3Local quality

3Productivity

If users provide sensitive transaction information to vendors or third-party systems, then purchases can be completed, but the information may be inadvertently disclosed or misused

Engineering Contradiction:
Improvetransaction completionVSAvoidexposure of sensitive information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent extracts the sensitive information handling function from the vendor's third-party system and relocates it to the user's secure element. The secure element performs authentication and generates credentials locally, extracting the need to transmit sensitive data to the vendor system. This maintains transaction completion capability while eliminating the information exposure risk associated with providing sensitive data to external vendors.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11397942B2Online interaction security technology
Publication Date: 2022.07.26 BANK OF AMERICA CORP
  • US11397942B2 patent drawing
  • US11397942B2 patent drawing
  • US11397942B2 patent drawing

AI summary

Typically, online transactions, such as online purchases of products or services require entering sensitive transaction information into a third-party web browser or application. This may expose sensitive transaction information to an increased risk of inadvertent disclosure. Apparatus and methods are provided for a smart card which enables users to securely complete online transactions without entering any sensitive transaction information into a third-party system. Vendor websites may be configured to generate a unique code identifying the vendor offering the product/service, the product/service and price of the product/service. The smart card includes a keypad for entering the unique code and completing payment for the desired product/service. The smart card will include a microprocessor and wireless interface. The wireless interface provides wireless communication capabilities and the ability to initiate online payments based on information captured by the keypad.