Dynamic Button Object for Secure Payment Device Enrollment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current payment device systems face security and privacy risks when linking marketing documents to a payment device, as third parties must collect and manage Primary Account Numbers (PANs), exposing both the PAN owner and the financial institution to potential risks.
Innovation Solution
A computer-implemented system and method that uses a dynamic graphic object managed by the issuing financial institution, allowing users to link their payment device to marketing documents without exposing sensitive information, by utilizing an alias instead of the PAN, which is created and managed by a payment processing server and linked to the user's account data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If third parties collect and manage PANs to link marketing documents to payment devices, then the linking process can be completed, but security and privacy risks increase
Solution Approach 1:
The patent introduces a payment processing server as an intermediary between the third party and the PAN. The server receives the PAN from the third party, stores it securely, and returns a token instead of the actual PAN. This mediator approach allows the linking process to proceed while preventing the third party from directly accessing or storing sensitive PAN data, thereby resolving the contradiction between operational ease and security risk
Solution Approach 2:
The system creates a token that serves as a copy or representation of the PAN. This token contains sufficient information to link marketing documents to the payment device but does not expose the actual PAN. The token acts as a safe substitute that maintains functionality while eliminating security risks associated with sharing real account numbers
2Reliability
If the PAN is shared with third parties for marketing document linking, then the linking can be established, but exposure of sensitive data occurs
Solution Approach 1:
The payment processing server acts as a trusted intermediary that receives the PAN, processes the linking request, and communicates only non-sensitive token information to the third party. This ensures reliable linking establishment while preventing loss of sensitive information through controlled data disclosure
Solution Approach 2:
The system extracts only the necessary identifying information from the PAN to create a token, separating the essential linking functionality from the sensitive account details. This extraction approach maintains linking reliability while removing the exposure of sensitive data that would occur with full PAN sharing
Data Source
AI summary
A dynamic button object managed by a financial institution that issues a payment device prevents third-party access to sensitive account data when linking the payment device to marketing documents provided by the third party. A payment processing server uses an alias for the sensitive data and configures a dynamic button object with the alias. The object may also include instructions to link the sensitive data to the alias and allow the payment processing server to monitor transactions with the third party. The payment processing server may then mediate communication between the consumer and the third party without exposing sensitive data.


