Encrypted Account Number Segmentation for Payment Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current payment systems lack adequate security measures to protect account information such as expiration dates and verification values, making them vulnerable to unauthorized use in transactions.

Innovation Solution

Encrypting a portion of the account number to generate new expiration dates and verification values, which are used instead of the real information for transactions, with a server computer determining the real account information for authorization purposes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real account information is transmitted during payment transactions, then transaction authorization can be processed, but account information becomes vulnerable to unauthorized interception and use

Engineering Contradiction:
Improvedata securityVSAvoidunauthorized access to account information
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The account number is divided into multiple segments, with the middle segment being encrypted. This segmentation allows the system to transmit account information in a protected form while still enabling authorization processing through selective encryption of sensitive portions only.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An encrypted middle segment acts as an intermediary that replaces the transmission of clear-text account information. This intermediary element maintains the ability to authorize transactions while preventing unauthorized parties from obtaining usable account data through interception.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption is applied to account information, then data security is improved, but the complexity of the transaction processing system increases

Engineering Contradiction:
Improvedata securityVSAvoidtransaction processing system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

By encrypting only the middle segment of the account number rather than the entire account information, the system achieves enhanced security with minimal additional complexity. This selective approach avoids the overhead of encrypting and processing complete account details while still protecting the most sensitive portions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different segments of the account number receive different levels of protection - the middle segment is encrypted while other segments remain in clear text. This local quality approach applies encryption only where most needed, reducing overall system complexity compared to universal encryption while maintaining adequate security.

Inventive Principle:
Principle #3Local quality

3Reliability

If new account information is generated from encrypted data, then fraudulent transaction prevention is enhanced, but the ease of operation for merchants and users decreases

Engineering Contradiction:
Improvefraud preventionVSAvoidtransaction operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system creates a modified copy of the account information where only the middle segment is encrypted. This copy maintains the functional properties needed for transaction authorization while incorporating security protections, allowing users and merchants to operate with familiar account information formats without additional complexity.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The encryption of the middle segment transforms the account number into a different form that still functions for authorization purposes. This parameter change protects against fraud by making intercepted data unusable while maintaining operational simplicity through automated processing of the encrypted format.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11941591B2Device including encrypted data for expiration date and verification value creation
Publication Date: 2024.03.26 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11941591B2 patent drawing
  • US11941591B2 patent drawing
  • US11941591B2 patent drawing

AI summary

In order to make it more difficult to obtain numbers that can be used to conduct fraudulent transactions, a portion of a real account number is encrypted. The encrypted portion of the account number is used to generate a new account number, a new expiration date, and a new verification value. This information can be determined using processor that may reside in a point of sale terminal, a smart card, or a computer operated by a user. The new account number, the new expiration date, and the new verification value can be used in a payment transaction. A server computer in a central payment processing network may determine that the new account information is not the real account information, and may subsequently generate a modified authorization request message using the real account information and may send it to an issuer for approval. The transmission of data is more secure, since real account information is not sent from the merchant to the payment processing network.