Method for securely updating payment method tokens

BR112025020731A2Pending Publication Date: 2026-08-25
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
BR112025020731
Authority / Receiving Office
BR · BR
Patent Type
Applications
Publication Date
2026-08-25

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

1 / 12 METHOD FOR SECURELY UPDATING PAYMENT METHOD TOKENS DESCRIPTION OBJECT OF THE INVENTION

[001] The present invention relates to a method for securely updating payment tokens. Specifically, the present invention aims to update a user's payment tokens across all involved parties (users, payment issuers, merchants) while maintaining the security of the payment tokens.

[002] The invention is particularly applicable in the field of telecommunications techniques, virtual security, authentication, and privacy and anonymity protection. BACKGROUND OF THE INVENTION AND TECHNICAL PROBLEM TO BE SOLVED

[003] In the current state of the art, the token (defined in the next paragraph) has become the basic element for account access and, therefore, for payments to be made by a merchant to a client holding the account. Therefore, it is essential for the merchant, because if they do not have this information correctly, they will not be able to make payments to their client, which will reduce their business and may even lead them to incur penalties. Furthermore, it is important for the client, because if this information is not updated, they may be left without the good or service they wished to obtain from their merchant. Since their emergence as a technology, tokens have been generated and maintained as a proprietary element of the merchant or acquirer, allowing them to have a barrier that allows the merchant to abandon their service, while maintaining little transparency about the viability of the import and export processes of proprietary tokens.Recently, credit card brands led by Visa have taken a step forward and started managing branded tokens on both the issuing and acquiring sides. What is relevant in the context of the present invention is that... Petition 870250087430, dated 09 / 26 / 2025, page 36 / 52 2 / 12 Merchants now have the opportunity to have a branded token with which they can offer new payment operations to their customers, while maintaining the level of security. The essential point of the service for merchants is to guarantee the automated lifecycle of the branded token, as this way they can optimize their operations and offer the best possible experience to their customers. The present invention, therefore, focuses on maintaining this automated lifecycle even in the event of account replacement by the customer.

[004] In the state of the art, a “token” is known as a digital representation of data existing in the real world that allows it to be masked using various mechanisms that ultimately prevent the real data from being compromised. Therefore, the “tokenization” of information can reduce the risk of fraud because, unlike real information, a “token” is a perishable element that can be replaced periodically or at any sign of compromise to its security. Although tokens minimize risks, an attacker can capture a token and attempt to reuse it fraudulently.

[005] In the state of the art, the “brand token” is known as the digital representation generated by a payment card issuer (“brand”) (Visa, MasterCard, etc.) based on the PAN (“Personal Account Number”) of the actual plastic payment card. The generation and management of the “Brand token” is the sole responsibility of the payment card brand itself.

[006] In the state of the art, and for the current technical sector, the “MainID” is known as the token of a static information element of a natural and / or legal person that does not change over time. In this sense, a personal identification number (“ID”), passport, driver's license number, social security number, etc. can function as a “MainID”.

[007] “Tokens”, as elements of digital information, can be and are widely used to protect sensitive personal information related to payment methods and any other type of personal information. Petition 870250087430, dated 09 / 26 / 2025, page 37 / 52 3 / 12 that can be replaced by tokens in the digital world.

[008] Currently, each user / customer possesses a set of personal data such as name, ID, passport, CPF, etc., or address number, telephone, email, etc., which are tokenized in each commercial establishment along with information about their preferred payment method, for which they have a "proprietary token" or "branded token" that can be used to easily and automatically make future purchases and payments for this user, as well as recurring payments initiated without the user's presence and in a secure manner. This data set has time-invariant data and time-variant or time-replaceable data. The common practice in tokenizing payment method data (bank card) by service providers to merchants (non-branded token) is usually limited to card data, not including other data of the payment method holder (bank card).

[009] Due to the tokenization of payment methods to maintain their security, the process of updating payment methods in the state of the art is controlled exclusively by the payment method issuer as the only entity capable of generating and managing the brand token.

[0010] The problem arises when the user, along with their payment method, which is registered at multiple establishments, updates the payment method. In particular, if the token in question is the token of the payment method that the user registered with the merchant, this will be the brand token for that user and at that merchant. When the payment method is updated, the problem for the set of merchants that stored the user's brand token information for each of the merchants to which they are related is the loss of connection with that customer and, ultimately, the loss of business that this may entail, or the loss of usability and availability for the user. This occurs because the brand token is encrypted information that represents the payment method. Petition 870250087430, dated 09 / 26 / 2025, page 38 / 52 4 / 12 of the user, the user and the merchant.

[0011] In the state of the art, registering the payment method a user wishes to use involves a series of steps that are exchanged in an interconnected environment composed of the user, an establishment, a cloud system, and a payment method issuer (“brand”), such that: • The merchant captures the payment method (bank card) data that the merchant's customer wishes to associate with their payments; • The merchant uses their own interface with the cloud system to request a card branding token. This request includes only information about the payment method (bank card); • The system requests a token for the card brand and forwards it to the merchant.

[0012] And when should an update be performed: • The payment method issuer informs the cloud system about changes to the expiration date or the deletion of a token; • The cloud system notifies the merchant about changes to the expiration date or the deletion of a token.

[0013] In other words, due to the cryptography (tokenization) required for payment methods, payment methods can only be updated when the “new” payment method belongs to the same provider as the “old” payment method to be updated and only for a single merchant, since each generated token includes only one merchant per user.

[0014] Therefore, there is a need in the state of the art to be able to update an encrypted (tokenized) payment method across all participants in the environment when one of the participants wishes to update the payment method, without compromising the security of the encrypted payment method. DESCRIPTION OF THE INVENTION Petition 870250087430, dated 09 / 26 / 2025, page 39 / 52 5 / 12

[0015] The present invention fits into an environment with the following actors: • The merchant's customer who holds a payment account, whether in the form of a card or any other method; • A merchant, central to the benefit of the present invention, and which is equipped with an automated method for maintaining brand tokens to optimize its operations; • Account / card issuers, such as payment account providers to customers so they can manage their payments at merchants; • The brand, as the provider of the brand token to the merchant-owner; • The present invention acts as an intermediary between merchants and brands, but additionally, both account / card issuers and the customers themselves can connect directly or indirectly to maintain automated management of the lifecycle of their brand token at their merchants, thus avoiding any type of interruption in the supply of the good or service provided by the merchant.

[0016] This specification refers to the “brand token,” in which one of the invariant data (Name, ID, Passport, etc.) that the “brand token” has encrypted is the user’s “MainID” on the different websites where they register variable personal information. The brand token is designed so that, in the world of tokens created by merchant payment issuers, events that would require a replacement due to card expiration, theft, loss, damage, etc., do not require replacement (they change the card data but not the underlying account), since brand tokens have the ability to represent both the old and new card precisely to avoid the need for replacement. This MainID is normally shared by the set of websites (merchants) associated with the system and is the point of convergence of the additional set of data that each website (merchant) may collect according to its specific business or activity. This implies that a Petition 870250087430, dated 09 / 26 / 2025, pages 40 / 52 6 / 12 A single customer may have “n” pieces of information, typically represented as tokens, across the “n” merchants with whom he or she normally interacts, and the information stored in them accurately reflects the reality at the time the information was recorded.

[0017] Therefore, the present invention allows for the updating of a “brand token”, and its transparent replacement and substitution across the “n” sites (merchants) associated with the system.

[0018] In a first aspect of the invention, a system for the secure updating of payment tokens is disclosed. The system of the present invention comprises a merchant, a cloud system, and a payment issuer. The cloud system has at least one database that stores the associated MainID, the brand token, the payment method (card), and the merchant(s). The system of the present invention may also comprise an interface through which the user and / or the merchant(s) communicate with the cloud system. The interface, the cloud system, and the payment issuer may be interconnected by means of cryptographic protocols. The cryptographic protocol may be selected between TLS1.2 and TLS1.3.

[0019] In a second aspect of the invention, a method for securely updating payment tokens is disclosed. The method for securely updating payment tokens comprises the following steps: • capturing data from a payment method and a payment method holder; • Send a request for a brand token for the payment method to a cloud system via an interface connected to the cloud system, where the request includes at least one identifying information of the payment method holder (“MainID”); • verify if the payment method holder's identification information (“MainID”) exists in a database contained within the system in Petition 870250087430, dated 09 / 26 / 2025, pages 41 / 52 7 / 12 cloud; • If the payment method holder's identification information (“MainlD”) exists in the database, then: ◦ Search the database for associations that include brand tokens, merchants, payment methods, and payment method holder identification information (“MainID”); • To provide, through the interface, the associations along with a list of update options calculated based on predefined management criteria and the associations found.

[0020] In any case, whether or not the payment method holder's identification data is available: • Request a new brand token for each of the associations from a payment processing issuer via the cloud system; • Sending the new brand token to the respective merchants via cloud system and to each of the associations (to be used in subsequent purchases - the brand token is new if it is the first time; updated if it already existed previously).

[0021] In one embodiment of the invention, the method of the present invention further comprises updating the associations with the new brand token(s) in the database.

[0022] In one embodiment of the invention, the list of upgrade options comprises: • Updating all branded tokens with payment methods; • updating the brand tokens selected by the payment method holder; • Do not update any brand tokens.

[0023] In one embodiment of the invention, the payment method holder’s identification information is the “MainID”.

[0024] In one embodiment of the invention, the method of the present Petition 870250087430, dated 09 / 26 / 2025, pages 42 / 52 8 / 12 The invention also includes enabling the payment method holder to use the interface via a personal blockchain ID.

[0025] In one embodiment of the invention, the method of the present invention further comprises enabling the merchant to use the interface by means of encrypted authentication.

[0026] In one embodiment of the invention, the method of the present invention further comprises enabling an external data source communicating with the cloud system to use the interface by means of encrypted authentication. BRIEF DESCRIPTION OF THE FIGURES

[0027] To complete the description of the invention and to help make its features more easily understandable, according to a preferred exemplary embodiment thereof, a set of drawings is attached, where, for illustrative and non-limiting purposes, the following figures are represented:

[0028] Figure 1 presents a diagram that demonstrates the interactions between different entities to perform the registration and updating of a payment method according to the state of the art.

[0029] Figure 2 illustrates a diagram showing the interactions between different entities to perform the secure token update method for payment methods according to the present invention.

[0030] Below is a list of the references used in the figures: 1. Cloud system; 2. User / holder of the payment method; 3. Merchant; 3': merchants; 4. Issuer of the payment method; 5. Cloud-based system database; 5': associations; 6. External data source; 7. Payment methods - Bank card; Petition 870250087430, dated 09 / 26 / 2025, pages 43 / 52 9 / 12 8. Interface; 9. Brand token; 15: steps of the method for updating payment methods according to the state of the art; 22: steps of the method for updating the means of payment of the present invention. DESCRIPTION OF A PREFERRED EMBODIMENT OF THE INVENTION

[0031] Figure 1 presents a diagram that demonstrates the interactions between different entities to register a payment method according to the state of the art. The registration of the payment method that the user wishes to perform involves a series of steps that are exchanged in an interconnected environment composed of the user, an establishment, a cloud system, and a payment method issuer in such a way that: • The merchant captures the payment method 7 (bank card) data that merchant 3's customer 2 wishes to associate with their payments; merchant 3 uses their own interface with cloud system 1 to request a payment method 7 brand token. This request includes only information about the payment method (bank card); • Cloud system 1 requests a brand token for card 7 from the payment method issuer 4, the payment method issuer 4 sends the brand token to the cloud system, and the said cloud system forwards the brand token to the merchant 3.

[0032] And when an update should be performed according to the state of the art: • the payment method issuer 4 informs the cloud system 1 about changes to the expiration date or the deletion of a brand token; and, • the cloud system 1 notifies the merchant 3 about the change to the expiration date or the deletion of a brand token 9. [ 0033] In addition, Fig. 2 illustrates a diagram showing the Petition 870250087430, dated 09 / 26 / 2025, pages 44 / 52 10 / 12 interactions between different entities to perform the secure registration and updating of payment tokens according to the method of the present invention. Therefore, Fig. 2 shows the system of the present invention composed of the interface 8, the cloud system 1, and the payment issuer 4. The cloud system 1 has the database 5 that stores the data associations 5'. Each association 5' is composed of the brand tokens 9, the merchants 3, the payment methods 7, and the user's MainID 2. In other words, the database 5 stores all the brand tokens 9, the merchants 3, and the payment methods 7 that correspond to the same user / holder of the payment method 2 identified by the corresponding MainID. Optionally, the system of the present invention may additionally comprise the external data source 6.Cloud system 1, interface 8 (used by the merchant or user), payment method issuer 4, and external data source 6 possess the MainID of the user / payment method holder, which allows the registration and updating of brand tokens regardless of whether there is one or more payment method issuer(s), or whether the update of brand tokens is initiated by user 2, merchant 3, payment method issuer(s) 4, or external data source 6, if any.

[0034] The registration or updating of brand tokens initiated by user 2 can be carried out through an application (interface 8) from a smartphone belonging to the user through secure authentication. In this case, the user, in direct communication with the cloud system 1, updates the payment method to be replaced. The cloud system 1 evaluates the update and proceeds to determine the merchants with whom the brand token 9 should be updated and how this should be done. For this purpose, the cloud system 1 prepares dialogues with the payment method issuers 4 and dialogues with the merchants for secure, confidential and transparent distribution to the relevant merchants according to the update options desired by user 2. Petition 870250087430, dated 09 / 26 / 2025, pages 45 / 52 11 / 12

[0035] Regarding the secure token update method for payment methods of the present invention, Fig. 2 shows that merchant 3 captures 16 the data of the payment method (bank card) and the user / holder 2 of the payment method, or user 2 himself modifies / includes 16' the same data by accessing merchant 3. Merchant 3 sends 17 a request for a token 9 for the payment method 7 to the cloud system 1 through the interface 8 connected to the cloud system 1. The request includes at least the MainID that identifies the holder of the payment method 7. The cloud system 1 checks 18 if the MainID of user 2 exists in the database 5 contained in the cloud system 1. If the MainID of user 2 exists in the database 5, then: ◦ For user 2's MainID, cloud system 1 searches the database for all its associations 5', which are composed of brand tokens, merchants, and payment methods for user 2's MainID; ◦ Cloud system 1 sends 19 associations to merchant 3 so that they can be provided to merchant 3 or user 2, through interface 8, along with a list of update options calculated based on standard management criteria and the associations 5' found; user 2 or merchant 3 will respond by choosing the desired options.

[0036] Regardless of whether the MainID exists in database 5 or not, for each update of an association 5' or for the creation of a new association 5', cloud system 1 requests 20 a new mark token from the payment method issuer 4, said token being sent 20 from the payment method issuer 4 to cloud system 1. Cloud system 1 updates the association with the new mark token 9 associated with changes in payment methods (new bank card, change of expiry date, etc.). Finally, cloud system 1 sends 21 the new mark token 9 to all listed merchants (to be used in subsequent purchases). Petition 870250087430, dated 09 / 26 / 2025, pages 46 / 52 12 / 12 in associations 5'. In other words, cloud system 1 sends 21 new brand tokens representing the updated payment method to all establishments (3,3') where the user has their payment method registered.

[0037] The entire update process described above is equally fulfilled when, instead of being initiated by merchant 3 or user 2, said update is initiated 22 by external source 6, which may be a bank, official bodies, trusted websites, etc. Petition 870250087430, dated 09 / 26 / 2025, pages 47 / 52

Claims

1 / 2 CLAIMS 1. A method for securely updating payment tokens, characterized by comprising: • capturing (16) data from a payment method (7) and a payment token holder (2); • sending (17) a request for a brand token (9) for the payment method (7) to a cloud system (1) via an interface (8) connected to the cloud system (1), wherein the request includes at least one identifying information of the payment token holder (2); • checking (18) whether the identifying data of the payment token holder (2) exists in a database (5) contained in the cloud system (1); • if the identifying information of the payment token holder exists in the database (5), then: ◦ searching the database for associations (5') that include brand tokens, merchants, payment methods and identifying information of the payment token holder;• provide (19), through the interface, the associations (5') together with a list of update options calculated based on standard management criteria and the associations (5') found; • request (20) a new brand token (9) for each of the associations (5') from a payment means issuer (4) through the cloud system; • send (21,22) the new brand token to the respective merchants (3,3') via the cloud system and for each of the associations.; 2. Method, according to claim 1, characterized by further comprising updating the associations with the new brand token in the database.

3. Method, according to claim 1, characterized in that the list of update options comprises: Petition 870250087430, dated 09 / 26 / 2025, page 48 / 52 2 / 2 • updating all brand tokens with the payment methods; • updating the brand tokens selected by the payment method holder; • not updating any brand tokens.

4. Method, according to claim 1, characterized in that the identification information of the payment method holder is the MainID.

5. Method, according to claim 1, characterized by comprising enabling the holder of the means of payment to use the interface by means of a personal blockchain ID.

6. Method, according to claim 1, characterized by comprising enabling the merchant to use the interface by means of encrypted authentication.

7. A method according to claim 1, characterized by comprising enabling an external data source communicating with the cloud system to use the interface through encrypted authentication.

8. System for secure updating of payment tokens, characterized by comprising at least one interface (8), a cloud system (1) and a payment issuer (4), wherein the cloud system (1) comprises at least one database (5) that stores associations (5') comprising brand tokens (9), merchants (3,3') and identification information of payment holders (2).

9. System according to claim 8, characterized in that the interface, the cloud system and the payment medium issuer are interconnected by means of cryptographic protocols.

10. System, according to claim 9, characterized in that the encryption protocol is selected between TLS1.2 and TLS1.

3. Petition 870250087430, dated 09 / 26 / 2025, pp. 49 / 52