Anonymized Transaction Data Sharing via Payment Processor Tokenization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for providing transaction data to third-parties pose security and privacy risks, as they often fail to comply with Payment Card Industry (PCI) standards, leading to potential breaches of cardholder information.
Innovation Solution
A computer-implemented method and system where a payment processor authorizes access to anonymized transaction data by requesting and authenticating cardholder account information, generating a secure identifier, and using a secure authentication mechanism to transmit data to third-party systems without exposing sensitive cardholder information, thus ensuring PCI compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If transaction data is provided to third-parties using known methods, then third-parties can provide value-added services, but security and privacy risks increase due to non-PCI compliance
Solution Approach 1:
The patent introduces an intermediary system that sits between the transaction data source and third-party recipients. This intermediary anonymizes transaction data by removing or masking PCI-sensitive information (such as primary account numbers) before transmitting to third-parties, thereby enabling their service capabilities while ensuring PCI compliance is maintained through the use of tokenized or hashed data representations
2Reliability
If anonymized transaction data is shared with third-parties, then privacy and security risks are mitigated, but the utility of transaction data for third-party services is reduced
Solution Approach 1:
The patent applies local quality by differentiating the level of data detail provided to different third-parties based on their specific needs and compliance requirements. Rather than uniformly anonymizing all data, the system selectively masks or tokenizes only the PCI-sensitive portions while preserving other transaction attributes (such as merchant category, transaction amount ranges, or time patterns) that maintain analytical utility for third-party services
Data Source
AI summary
A computer-implemented method for authorizing access to transaction data to a third-party computer system is implemented by a payment processor computer system coupled to a memory. The method includes receiving a request for access to transaction data associated with a cardholder account, requesting a set of authentication information associated with the cardholder account, authenticating the set of authentication information upon receiving the set of authentication information, and authorizing the third-party computer system to receive transaction data associated with the cardholder account. Upon validation, the payment processor computer system generates an authorization token and provides the authorization token to the third-party computer system. The third-party computer system uses the authorization token and a secure identifier to retrieve transaction data associated with the cardholder account.


