Cryptographic Transaction Tokens for Secure Recurring Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face security risks when resubmitting or recurring transactions without full authentication data, as merchants are not permitted to store transaction authentication data, leading to increased spoofing vulnerabilities.

Innovation Solution

A cryptographically signed and/or encrypted token is generated based on transaction characteristics and transmitted to the merchant, allowing secure authentication of subsequent transactions by verifying this token to establish an authenticated association with an initial transaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If merchants are not permitted to store authentication data for security reasons, then security risk is reduced, but the ability to authenticate subsequent transactions is compromised

Engineering Contradiction:
Improvetransaction authentication securityVSAvoidspoofing vulnerability
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent introduces a token as an intermediary element that mediates between the authentication data and the transaction processing system. The token contains embedded authentication information and can be verified without storing the actual authentication data, thus resolving the contradiction by providing a secure verification mechanism that doesn't require storing sensitive authentication data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a cryptographic copy of the authentication data in the form of a token. This token is a verified representation of the original authentication that can be stored and reused for subsequent transactions without compromising the security of the original authentication data, allowing authentication without storing sensitive information.

Inventive Principle:
Principle #26Copying

2Reliability

If transaction authentication data is not stored, then security is improved, but transaction resubmission and recurring transactions cannot be authenticated

Engineering Contradiction:
Improveauthentication securityVSAvoidtransaction resubmission capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent performs preliminary authentication and creates a token containing the authentication verification before the actual transaction is completed or before recurring transactions occur. This token is then stored and can be used to authenticate future transactions without needing to重新 perform full authentication or store sensitive authentication data, enabling both security and resubmission capability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If full authentication data is required for each transaction, then authentication security is maintained, but transaction processing complexity and time increase

Engineering Contradiction:
Improveauthentication integrityVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs authentication preliminarily and stores the verification result in a token. Subsequent transactions can be authenticated by verifying the token rather than repeating the full authentication process, significantly reducing processing time while maintaining authentication integrity through cryptographic verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a verified copy of the authentication result in the token format. This copy can be quickly verified without repeating the time-consuming authentication process, thus maintaining security through cryptographic verification while dramatically reducing transaction processing time for recurring and resubmitted transactions.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12393934B2Method of retaining transaction context
Publication Date: 2025.08.19 VISA EUROPE
  • US12393934B2 patent drawing
  • US12393934B2 patent drawing
  • US12393934B2 patent drawing

AI summary

Methods of transaction authentication are provided. In one such method, at least one first transaction has been conducted, the or each first transaction generating data including first data comprising authentication data and second data identifying the or each first transaction, wherein a given first transaction is between a merchant and a card holder. A cryptographically signed and/or encrypted token corresponding to the given first transaction and comprising a characteristic of the first transaction has been generated using at least said second data. The cryptographically signed and/or encrypted token has been transmitted to the merchant. The method comprises receiving, from the merchant, data corresponding to a second transaction and in the event that the data corresponding to the second transaction includes the cryptographically signed and/or encrypted token, responsively authenticating the cryptographically signed and/or encrypted token, whereby to determine an authenticated association between the second transaction and a given first transaction.