Temporary Encrypted Payment Storage for Secondary Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing payment systems require users to repeatedly enter sensitive information for secondary transactions, introducing friction and potential security vulnerabilities, especially with the rise of e-commerce.
Innovation Solution
A system that temporarily stores encrypted payment information in a web browser for subsequent use in secondary transactions, eliminating the need for re-entry by using a temporary storage location and public key encryption, ensuring secure and efficient data transfer between affiliated websites.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If payment information is stored long-term for autofill, then user convenience is improved, but security risks and data exposure increase
Solution Approach 1:
The system performs preliminary encryption of payment information using the secondary website's public key before storage. This advance preparation ensures that even if data is accessed, it remains protected and can only be decrypted by the intended recipient, thus maintaining security while enabling convenient reuse.
Solution Approach 2:
The patent employs temporary storage of encrypted payment information that is automatically deleted after a single use or after a short time period. This disposable approach allows the data to be available for convenient reuse immediately, but eliminates long-term security risks by ensuring the data cannot be retained or misused after its intended purpose is fulfilled.
2Productivity
If payment information is reused across multiple transactions, then transaction efficiency is improved, but the risk of data breach and unauthorized access increases
Solution Approach 1:
The system introduces encrypted payment information as an intermediary between the user and the secondary website. Instead of directly sharing or storing sensitive data in plain form, the encrypted version serves as a secure mediator that can be transmitted and stored without exposing the underlying payment information, thus enabling efficient reuse while maintaining security.
Solution Approach 2:
The patent transforms the payment information from its original plaintext state to an encrypted state using cryptographic parameters (public key encryption). This parameter change fundamentally alters the data's properties, making it unusable for unauthorized access while preserving its functional utility for the intended recipient who possesses the corresponding private key.
3Loss of time
If sensitive data is stored in browser for reuse, then redundant data entry is eliminated, but compliance with data protection regulations becomes difficult
Solution Approach 1:
The system stores encrypted payment information temporarily in the browser with automatic deletion after use or after a predetermined time period. This short-living storage approach eliminates redundant data entry for immediate reuse while naturally complying with data protection regulations by ensuring data is not retained longer than necessary for its intended purpose.
4Reliability
If encrypted payment information is temporarily stored, then security is improved, but storage capacity and accessibility may be reduced
Solution Approach 1:
Instead of storing multiple copies of sensitive payment information in different formats or locations, the system creates a single encrypted copy using cryptographic transformations. This copying approach maintains security while being space-efficient, as the encrypted data can be compactly stored and retrieved as needed without requiring additional storage infrastructure.
Data Source
AI summary
A payment system includes a first set of servers for a first website configured to provide a payment information form page, process payment information to determine a primary transaction status, and provide a confirmation page. The payment information form page configures a client device to accept payment information from a user, convey the payment information to the first set of servers, and store the payment information in a temporary storage location. The confirmation page, or a subsequent page reachable via the confirmation page, configures the client device to obtain a user decision regarding a secondary transaction, send the payment information to a second set of servers for a second website without requiring completion of another payment information form if the user decision is affirmative, and delete the payment information from the temporary storage location before, or upon, closure of the confirmation page or the subsequent page.


