Dynamic Button Object for Secure Payment Device Enrollment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current payment device systems face security and privacy risks when linking marketing documents to a payment device, as third parties must collect and manage Primary Account Numbers (PANs), exposing both the PAN owner and the financial institution to potential risks.

Innovation Solution

A computer-implemented system and method that uses a dynamic graphic object managed by the issuing financial institution, allowing users to link their payment device to marketing documents without exposing sensitive information, by utilizing an alias instead of the PAN, which is created and managed by a payment processing server and linked to the user's account data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If third parties collect and manage PANs to link marketing documents to payment devices, then the linking process can be completed, but security and privacy risks increase

Engineering Contradiction:
Improvelinking processVSAvoidsecurity and privacy risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a payment processing server as an intermediary between the third party and the PAN. The server receives the PAN from the third party, stores it securely, and returns a token instead of the actual PAN. This mediator approach allows the linking process to proceed while preventing the third party from directly accessing or storing sensitive PAN data, thereby resolving the contradiction between operational ease and security risk

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a token that serves as a copy or representation of the PAN. This token contains sufficient information to link marketing documents to the payment device but does not expose the actual PAN. The token acts as a safe substitute that maintains functionality while eliminating security risks associated with sharing real account numbers

Inventive Principle:
Principle #26Copying

2Reliability

If the PAN is shared with third parties for marketing document linking, then the linking can be established, but exposure of sensitive data occurs

Engineering Contradiction:
Improvelinking establishmentVSAvoidexposure of sensitive data
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The payment processing server acts as a trusted intermediary that receives the PAN, processes the linking request, and communicates only non-sensitive token information to the third party. This ensures reliable linking establishment while preventing loss of sensitive information through controlled data disclosure

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system extracts only the necessary identifying information from the PAN to create a token, separating the essential linking functionality from the sensitive account details. This extraction approach maintains linking reliability while removing the exposure of sensitive data that would occur with full PAN sharing

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11100537B2Payment device enrollment in linked offers
Publication Date: 2021.08.24 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11100537B2 patent drawing
  • US11100537B2 patent drawing
  • US11100537B2 patent drawing

AI summary

A dynamic button object managed by a financial institution that issues a payment device prevents third-party access to sensitive account data when linking the payment device to marketing documents provided by the third party. A payment processing server uses an alias for the sensitive data and configures a dynamic button object with the alias. The object may also include instructions to link the sensitive data to the alias and allow the payment processing server to monitor transactions with the third party. The payment processing server may then mediate communication between the consumer and the third party without exposing sensitive data.