Appliance Token Provisioning for Secure Shared Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current smart appliance transaction systems require users to provision their personal account numbers, exposing financial information and being unsuitable for shared or rental appliances, as they rely on user-specific financial instruments for transactions.
Innovation Solution
A system and method where an original account identifier is registered to an appliance, not associated with any user, and a device token is stored, allowing user account identifiers to be associated for transaction authorization and processing without exposing personal financial information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a user provisions their personal account number to a smart appliance for transactions, then the appliance can conduct transactions with merchants, but the user's financial information is exposed and potentially disseminated widely
Solution Approach 1:
The patent introduces a token as an intermediary that sits between the user's personal account number and the appliance. The token enables transaction functionality while preventing direct exposure of the user's financial information. The token can be provisioned to the appliance without revealing the underlying PAN, thus resolving the contradiction between enabling transactions and protecting financial information.
Solution Approach 2:
The patent creates a token copy that represents the user's account for transaction purposes. Instead of using the actual personal account number in the appliance, a token copy is used that contains sufficient information to authorize transactions while masking the real financial data. This copying approach allows transaction capability while eliminating information exposure.
2Ease of operation
If a user's personal account number is provisioned to an appliance, then transactions can be processed, but the model is unsuitable for shared or rental appliances where a single owner does not continuously use one appliance
Solution Approach 1:
The patent makes the token provisioning system universal by allowing multiple users to provision tokens to the same appliance over time. The appliance does not need to be permanently associated with a single user's account number. Instead, any authorized user can provision a token for transactions, making the system adaptable to shared ownership, rental, and multi-user scenarios while maintaining transaction processing capability.
3Object-affected harmful factors
If an appliance is issued its own financial instrument that can be tokenized, then transactions can be conducted without exposing the owner's financial information, but the system complexity increases
Solution Approach 1:
The patent uses a token as an intermediary layer that simplifies the system architecture despite introducing new components. The token acts as a standard interface between the appliance and the payment network, following existing tokenization frameworks. This intermediary approach protects financial information while maintaining compatibility with current payment infrastructure, thus managing system complexity through standardized mediation rather than radical architectural changes.
Data Source
AI summary
Provided herein is a computer-implemented method for provisioning a token to an appliance. The method includes registering an original account identifier to an appliance, wherein the original account identifier is not associated with any user, associating a device token to the original account identifier, wherein the device token is stored by the appliance, associating a user account identifier for a user to at least one of the device token and the original account identifier, receiving, from the appliance, a transaction request for a transaction, the transaction request including the device token, identifying the user account identifier based on the device token, determining that the transaction is authorized based at least partially on the user account identifier and the original account identifier registered to the at least one appliance, and in response to determining that the transaction is authorized, processing the transaction. A system and appliance are also disclosed.


