Web Payment Authentication via Segmented Credit Card Value Encoding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing online payment systems lack a standard for secure non-face-to-face transactions, relying on individual authentication methods like credit card numbers and virtual cards, which are not secure against forgery and require manual input of payment information, hindering global compatibility and convenience.
Innovation Solution
An apparatus and method for authentication and payment on a web platform that divides credit card authentication values into multiple information blocks, using one block for decoding and another for transmission, with encoding and decoding processes secured by Hardware Security Module (HSM) and Advanced Encryption Standard (AES), ensuring secure transactions and forgery detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If credit card authentication value is transmitted in full to enable payment, then payment functionality is achieved, but security against forgery deteriorates
Solution Approach 1:
The credit card authentication value is divided into multiple information blocks (first information block and second information block). The first block is transmitted to the user authentication device for encoding with PIN, while the second block remains in the credit card permission request device. This segmentation ensures that neither block alone can be used for forgery, resolving the contradiction between security and convenience.
2Reliability
If payment information is manually input to maintain security, then security against infringement is improved, but ease of operation deteriorates
Solution Approach 1:
The system automatically performs encoding of the first information block using the user's PIN stored in the user authentication device. This self-service mechanism eliminates manual input requirements while maintaining security through cryptographic encoding, resolving the contradiction between security and ease of operation.
3Ease of operation
If credit card information is stored centrally to simplify payment, then ease of operation is improved, but security against forgery deteriorates
Solution Approach 1:
Instead of storing complete credit card information centrally, the system segments the authentication value into multiple blocks distributed across different devices. The first block is encoded with PIN in the user authentication device, while the second block remains in the credit card permission request device, preventing centralized storage vulnerabilities while maintaining convenience.
Solution Approach 2:
The user authentication device acts as an intermediary that encodes the first information block with the user's PIN before transmission. This intermediary layer adds security without requiring manual user input during transactions, resolving the contradiction between centralized convenience and security.
4Reliability
If encoding with PIN is performed to prevent forgery, then security against infringement is improved, but device complexity increases
Solution Approach 1:
The user authentication device performs multiple functions: storing PIN information, encoding the first information block with PIN, and managing the encoded data. This multi-functionality consolidates security operations into a single device, reducing overall system complexity while maintaining strong security against forgery.
Data Source
AI summary
The present invention provides that a credit card authentication value is divided into meaningless information block 1 and information block 2, the information block 1 can be transmitted to a user authentication device that is physically insulated, and the user authentication device that encodes the information block 1 on the basis of payment PIN information received from user equipment and keeps the encoded information block 1, and decodes the encoded information block 1 on the basis of the payment PIN information and transmits the information block 1 to the credit card permission request device, when there is a request from the credit card permission request device, thereby determining whether there is forgery in payment on a web. Accordingly, security in payment can be improved.


