Web Payment Authentication via Segmented Credit Card Value Encoding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing online payment systems lack a standard for secure non-face-to-face transactions, relying on individual authentication methods like credit card numbers and virtual cards, which are not secure against forgery and require manual input of payment information, hindering global compatibility and convenience.

Innovation Solution

An apparatus and method for authentication and payment on a web platform that divides credit card authentication values into multiple information blocks, using one block for decoding and another for transmission, with encoding and decoding processes secured by Hardware Security Module (HSM) and Advanced Encryption Standard (AES), ensuring secure transactions and forgery detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If credit card authentication value is transmitted in full to enable payment, then payment functionality is achieved, but security against forgery deteriorates

Engineering Contradiction:
Improvepayment securityVSAvoidpayment convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The credit card authentication value is divided into multiple information blocks (first information block and second information block). The first block is transmitted to the user authentication device for encoding with PIN, while the second block remains in the credit card permission request device. This segmentation ensures that neither block alone can be used for forgery, resolving the contradiction between security and convenience.

Inventive Principle:
Principle #1Segmentation

2Reliability

If payment information is manually input to maintain security, then security against infringement is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvepayment securityVSAvoidpayment convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically performs encoding of the first information block using the user's PIN stored in the user authentication device. This self-service mechanism eliminates manual input requirements while maintaining security through cryptographic encoding, resolving the contradiction between security and ease of operation.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If credit card information is stored centrally to simplify payment, then ease of operation is improved, but security against forgery deteriorates

Engineering Contradiction:
Improvepayment convenienceVSAvoidpayment security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Instead of storing complete credit card information centrally, the system segments the authentication value into multiple blocks distributed across different devices. The first block is encoded with PIN in the user authentication device, while the second block remains in the credit card permission request device, preventing centralized storage vulnerabilities while maintaining convenience.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The user authentication device acts as an intermediary that encodes the first information block with the user's PIN before transmission. This intermediary layer adds security without requiring manual user input during transactions, resolving the contradiction between centralized convenience and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If encoding with PIN is performed to prevent forgery, then security against infringement is improved, but device complexity increases

Engineering Contradiction:
Improvepayment securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The user authentication device performs multiple functions: storing PIN information, encoding the first information block with PIN, and managing the encoded data. This multi-functionality consolidates security operations into a single device, reducing overall system complexity while maintaining strong security against forgery.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11200579B2Apparatus for authentication and payment based on web, method for authentication and payment based on web, system for authentication and payment based on web and non-transitory computer readable storage medium having computer program recorded thereon
Publication Date: 2021.12.14 ELEVEN STREET CO LTD
  • US11200579B2 patent drawing
  • US11200579B2 patent drawing
  • US11200579B2 patent drawing

AI summary

The present invention provides that a credit card authentication value is divided into meaningless information block 1 and information block 2, the information block 1 can be transmitted to a user authentication device that is physically insulated, and the user authentication device that encodes the information block 1 on the basis of payment PIN information received from user equipment and keeps the encoded information block 1, and decodes the encoded information block 1 on the basis of the payment PIN information and transmits the information block 1 to the credit card permission request device, when there is a request from the credit card permission request device, thereby determining whether there is forgery in payment on a web. Accordingly, security in payment can be improved.