Distributed Payment Verification for Tokenized Credential Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current payment processing systems using tokenized credentials are vulnerable to theft or interception of real payment credentials due to the involvement of token service providers, compromising consumer privacy and security.
Innovation Solution
A system where each entity involved in a payment transaction verifies and appends its credentials to a data set, which is then stored on a distributed ledger like a blockchain, ensuring that only the issuer knows the actual payment credentials, providing secure verification at each step without storing them elsewhere.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If payment tokens are distributed by token service providers, then payment transactions can be processed with digitized credentials, but the real payment credentials may be stolen or intercepted
Solution Approach 1:
The patent extracts the token service provider from the payment processing flow entirely. Instead of having a centralized provider that holds and manages tokens, the system uses direct peer-to-peer communication where the consumer's device directly communicates with the merchant's system, eliminating the intermediary that could compromise credentials.
Solution Approach 2:
The patent introduces a distributed ledger as an intermediary that enables verification without credential storage. The ledger provides a shared reference for verifying payment credentials and transaction history without requiring any single entity to store the actual credentials, thus maintaining security while enabling processing.
2Ease of operation
If payment tokens are stored on mobile devices, then consumer convenience is improved, but security is compromised if the device is stolen or intercepted
Solution Approach 1:
The patent uses cryptographic copies of payment credentials in the form of digital signatures and hashed values stored on the distributed ledger. These copies allow verification of credentials without storing the actual sensitive data on consumer devices or anywhere else, enabling convenience while maintaining security even if devices are stolen.
Solution Approach 2:
The patent moves the security verification from the physical device dimension to the distributed ledger dimension. Instead of relying on secure storage on the consumer's mobile device, the system uses the distributed ledger as a separate verification dimension that confirms credential validity without exposing the actual credentials.
3Device complexity
If a centralized system manages payment tokens, then processing can be simplified, but complete privacy of actual payment credentials cannot be maintained
Solution Approach 1:
The patent segments the payment processing function across multiple independent entities (consumer device, merchant system, acquirer, issuer) rather than concentrating it in a single centralized system. Each entity performs a specific function and appends its verification to the distributed ledger, maintaining simplicity through functional segmentation while preserving credential privacy through distributed verification.
Solution Approach 2:
The distributed ledger serves as an intermediary that enables all processing entities to verify payment credentials without any single entity needing to store or access the actual credential values. The ledger provides the necessary verification mechanism while maintaining complete privacy of the credentials throughout the processing flow.
Data Source
AI summary
A method for pre-authorization of a payment transaction with tokenized credentials includes: receiving a first data set signed with a first digital signature and including an acquirer identification value and a second data set; verifying the first digital signature using a first public key of a first cryptographic key pair associated with the acquirer identification value; extracting, from the first data set in response to verification of the first digital signature, the second data set including a merchant identification value and a third data set; extracting, from the second data set, the third data set including an issuer identification value and transaction data; identifying an issuing computing system based on the issuer identification value; and transmitting a fourth data set to the issuing computing system, the fourth data set including the first data set and a steward identification value.


