Unique Handle Payment System for Secure E-Commerce Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing e-commerce systems pose security risks as customers need to provide personally identifiable login information and payment details to merchant websites for transactions, which can lead to data exposure and security breaches.

Innovation Solution

A system and method for processing payments using an electronic wallet application on a mobile device, where a unique handle is used instead of payment information, with the payment server associating the user account with the handle, verifying the account, and transmitting a payment security token to the merchant server over a secured channel, ensuring secure transactions without exposing sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If customers provide personally identifiable login information and payment details to merchant websites for transactions, then payment processing can be completed, but security risks and data exposure increase

Engineering Contradiction:
Improvetransaction securityVSAvoiddata exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive payment information from the transaction flow by introducing a separate authentication channel. Instead of transmitting payment details through the merchant website, the system pulls authentication data directly from the customer's mobile device via a dedicated payment server, removing the harmful element of data exposure while preserving transaction functionality

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a payment server as an intermediary between the customer's mobile device and the merchant website. This mediator handles authentication and token generation, preventing direct exposure of sensitive information to the merchant while enabling secure transaction processing. The intermediary architecture isolates sensitive data from potential breaches at the merchant level

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a unique handle is used instead of payment information for transactions, then security is enhanced and data breach risk is reduced, but system complexity increases

Engineering Contradiction:
Improvepayment securityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a simplified representation (copy) of the payment system through the unique handle mechanism. Instead of managing complex payment card data, the system uses a simple tokenized handle that references the actual payment information stored securely on the mobile device. This copying approach reduces system complexity at the merchant level while maintaining security through the underlying secure storage architecture

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent transforms the payment authentication process by changing the parameter from sensitive payment card data to a simple unique handle. This parameter transformation simplifies the transaction interface while the underlying system maintains security through biometric authentication and secure enclave storage, effectively decoupling interface simplicity from security complexity

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20180150830A1System, process and device for e-commerce transactions
Publication Date: 2018.05.31 ROYAL BANK OF CANADA
  • US20180150830A1 patent drawing
  • US20180150830A1 patent drawing
  • US20180150830A1 patent drawing

AI summary

Systems, devices and processes for electronic commerce payment processing using a handle and a mobile device with a mobile wallet application installed thereon. The handle may be used at a merchant website to process the electronic commerce payment for instead of providing payment information and/or personally identifiable information. That is, the handle may not include payment information and/or personally identifiable information.