Electronic Data Protection Device for Secure Transaction Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for protecting sensitive data during computer interactions are limited in their ability to prevent unauthorized access, particularly in scenarios where users are subjected to phishing or 'man-in-the-middle' attacks, and where data is compromised during transmission.

Innovation Solution

The implementation of an Electronic Data Protection (EDP) computing device that receives interaction data from a business entity computing device, generates a token request message to establish a secure communication channel with a user application, and retrieves protected data objects associated with user accounts selected by the user, thereby completing computer interactions without exposing sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users transmit protected data directly during computer interactions, then data can be accessed and processed by business entities, but data security is compromised due to phishing and man-in-the-middle attacks

Engineering Contradiction:
Improvedata securityVSAvoiddata transmission process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an electronic data protection (EDP) computing device as an intermediary between the user and the business entity. The EDP device receives interaction data from the business entity, retrieves protected data from secure storage, and transmits it to complete the interaction. This mediator architecture ensures that users never directly transmit protected data over networks, eliminating exposure to phishing and man-in-the-middle attacks while maintaining the ability to process protected data when needed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If username and password systems are used to protect data access, then authentication is provided, but the system remains vulnerable to phishing and credential theft attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the protected data from the user's device and stores it securely in the EDP computing device. Instead of requiring users to transmit credentials or protected data, the system uses the user's identifier to authenticate and then retrieves the protected data from the EDP device's secure storage. This extraction removes the vulnerability point where credentials would be transmitted or stored on user devices.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If protected data is transmitted during online transactions, then transactions can be completed, but network traffic can be intercepted through packet-sniffing attacks

Engineering Contradiction:
Improvetransaction completionVSAvoidnetwork interception vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The EDP computing device serves as a mediator that handles protected data transmission. The device receives interaction data from the business entity, retrieves the appropriate protected data from secure storage using the user identifier, and transmits it to complete the transaction. This intermediary approach allows transactions to be completed efficiently while the protected data never traverses the user's network connection, eliminating packet-sniffing vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If users enter protected data into unprotected computer devices, then data input is enabled, but the data is exposed during transmission between computing devices

Engineering Contradiction:
Improvedata input capabilityVSAvoiddata transmission security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts protected data from the user's unprotected device and stores it in the secure environment of the EDP computing device. During interactions, the system uses the user identifier to retrieve the protected data from the EDP device rather than transmitting it from the user's device. This extraction eliminates the security vulnerability of transmitting data from unprotected devices while maintaining the ability to input and use protected data through the secure intermediary.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250193184A1Systems and methods for improved electronic data security
Publication Date: 2025.06.12 MASTERCARD INT INC
  • US20250193184A1 patent drawing
  • US20250193184A1 patent drawing
  • US20250193184A1 patent drawing

AI summary

An electronic data protection (EDP) computing device for protecting sensitive data of a user during a computer interaction between the user and a business entity computing device associated with a business entity is provided. The EDP computing device is configured to receive interaction data for the computer interaction from the business entity computing device. The interaction data includes an interaction identifier, a business entity identifier, and a user identifier in lieu of a protected data object. The EDP computing device generates a token request message using the interaction data and a request token and transmits the token request message to the user computing device, prompting the user to pick a user account. The EDP computing device receives a response token identifying an account selected to complete the computer interaction, retrieves the protected data object, and completes the computer interaction using the protected data object.