Anonymized Transaction Data Sharing via Payment Processor Tokenization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for providing transaction data to third-parties pose security and privacy risks, as they often fail to comply with Payment Card Industry (PCI) standards, leading to potential breaches of cardholder information.

Innovation Solution

A computer-implemented method and system where a payment processor authorizes access to anonymized transaction data by requesting and authenticating cardholder account information, generating a secure identifier, and using a secure authentication mechanism to transmit data to third-party systems without exposing sensitive cardholder information, thus ensuring PCI compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If transaction data is provided to third-parties using known methods, then third-parties can provide value-added services, but security and privacy risks increase due to non-PCI compliance

Engineering Contradiction:
Improvethird-party service capabilityVSAvoidPCI compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary system that sits between the transaction data source and third-party recipients. This intermediary anonymizes transaction data by removing or masking PCI-sensitive information (such as primary account numbers) before transmitting to third-parties, thereby enabling their service capabilities while ensuring PCI compliance is maintained through the use of tokenized or hashed data representations

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If anonymized transaction data is shared with third-parties, then privacy and security risks are mitigated, but the utility of transaction data for third-party services is reduced

Engineering Contradiction:
Improveprivacy and security protectionVSAvoidtransaction data utility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies local quality by differentiating the level of data detail provided to different third-parties based on their specific needs and compliance requirements. Rather than uniformly anonymizing all data, the system selectively masks or tokenizes only the PCI-sensitive portions while preserving other transaction attributes (such as merchant category, transaction amount ranges, or time patterns) that maintain analytical utility for third-party services

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20210295316A1Systems and methods for providing anonymized transaction data to third-parties
Publication Date: 2021.09.23 MASTERCARD INT INC
  • US20210295316A1 patent drawing
  • US20210295316A1 patent drawing
  • US20210295316A1 patent drawing

AI summary

A computer-implemented method for authorizing access to transaction data to a third-party computer system is implemented by a payment processor computer system coupled to a memory. The method includes receiving a request for access to transaction data associated with a cardholder account, requesting a set of authentication information associated with the cardholder account, authenticating the set of authentication information upon receiving the set of authentication information, and authorizing the third-party computer system to receive transaction data associated with the cardholder account. Upon validation, the payment processor computer system generates an authorization token and provides the authorization token to the third-party computer system. The third-party computer system uses the authorization token and a secure identifier to retrieve transaction data associated with the cardholder account.