E-commerce Protocol Using Encrypted Tokens for Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

E-commerce systems face vulnerabilities such as credit card fraud and unauthorized access to user information, leading to security concerns for companies and costly security measures.

Innovation Solution

An E-commerce protocol that encrypts user data and allows only manipulated versions to be stored, giving users control over their information, using symmetric encryption and mathematical methods to secure transactions, ensuring data security without requiring companies to handle sensitive information directly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If E-commerce companies store user data (credit card information, personal information) in their databases, then they can provide convenient payment and shopping services, but they become vulnerable to security breaches, fraud, and data theft

Engineering Contradiction:
Improveconvenience of payment serviceVSAvoidsecurity of user data
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts sensitive user data (credit card information, personal information) from the E-commerce company's database and stores it only in the user's personal database. The E-commerce company retains only encrypted tokens that cannot be reversed to obtain original data, thereby eliminating the security vulnerability while preserving payment functionality

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary encryption mechanism where user data is transformed into encrypted tokens through a cryptographic process. This intermediary representation allows the E-commerce company to verify and process payments without ever possessing or storing the actual sensitive information, thus resolving the contradiction between service convenience and data security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If E-commerce companies implement strong security measures to protect user data, then data security is improved, but the cost of security investments and system complexity increases

Engineering Contradiction:
Improvesecurity of user dataVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

By extracting sensitive data from the E-commerce company's system and storing it exclusively in the user's personal database, the patent eliminates the need for complex security infrastructure at the company level. The security burden is shifted to the user's device, which the user controls and protects

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements a self-service security model where users manage their own sensitive data and encryption keys in their personal databases. This distributes the security responsibility to individual users, reducing the centralized security burden and complexity that would otherwise require significant corporate investment

Inventive Principle:
Principle #25Self-service

3Reliability

If E-commerce companies store manipulated versions of user data, then security is improved, but the ability to access and verify original information is reduced

Engineering Contradiction:
Improvesecurity of stored dataVSAvoidaccessibility of user information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent uses cryptographic tokens as intermediaries that preserve the essential verification functionality while eliminating the need to store or access original sensitive data. The tokens contain sufficient information for payment verification through cryptographic proof, maintaining information accessibility for legitimate purposes while preventing unauthorized access to actual user data

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11663597B2Secure e-commerce protocol
Publication Date: 2023.05.30 ISTANBUL TEKNIK UNIVSI
  • US11663597B2 patent drawing
  • US11663597B2 patent drawing

AI summary

An E-commerce protocol is provided. The E-commerce protocol has been developed as a solution to malicious attacks such as credit card fraud and stealing of various financial data, wherein the malicious attacks appeared particularly in a cyber world. With the help of the E-commerce protocol, a manipulated version of user information in an E-commerce database removes security risks of compromising on E-commerce systems. Even though a user does not have to share personal information of the user with E-commerce companies, an application also eliminates a necessity of entering the user information for each online transaction.