Encrypted Token Payment System for Secure Mobile Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic payment systems lack secure methods for processing transactions, particularly in mobile commerce, where sensitive financial information is vulnerable to interception and storage, leading to security concerns and liability issues for merchants.
Innovation Solution
A secure transaction environment using encrypted tokens and a payment processing server that stores and manages purchaser information, allowing transactions to be processed without exposing actual payment details to merchants, using mobile devices or point-of-sale terminals, and enabling secure storage, transmission, and management of payment information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If payment information is stored and processed by merchants directly, then transaction processing is simple and direct, but security is compromised and financial data is vulnerable to interception
Solution Approach 1:
The patent introduces a payment processing server as an intermediary between the mobile device and the merchant. This server securely stores payment information and handles transaction processing, while the merchant only receives encrypted tokens. The intermediary protects sensitive financial data from direct exposure to merchants, resolving the contradiction between processing simplicity and security reliability.
Solution Approach 2:
The patent uses encrypted tokens as copies of payment information. Instead of storing actual payment details at the merchant, the system stores encrypted versions (tokens) that can be processed without exposing the real financial data. This copying approach maintains processing functionality while eliminating direct exposure of sensitive information.
2Ease of operation
If actual payment details are stored at merchant locations, then transaction processing is straightforward, but liability and security risks increase for merchants
Solution Approach 1:
The payment processing server acts as a mediator that handles all payment information storage and processing. Merchants interact with this intermediary through standardized interfaces, maintaining ease of operation while the intermediary assumes security responsibilities, thereby eliminating direct merchant liability for data breaches.
Solution Approach 2:
The patent extracts sensitive payment information storage from the merchant environment and relocates it to a secure, centralized payment processing server. This extraction removes the harmful factor (security vulnerability) from the merchant's system while maintaining the merchant's ability to process transactions through the intermediary.
3Productivity
If payment information is transmitted over networks, then electronic commerce is enabled and efficiency is improved, but data is vulnerable to interception
Solution Approach 1:
The patent transmits encrypted tokens instead of actual payment information over networks. These tokens are encrypted copies that appear as random data to interceptors but can be decrypted and processed by the payment system. This enables efficient network-based commerce while eliminating the risk of intercepted readable financial data.
Solution Approach 2:
The patent changes the state of payment information from plaintext to encrypted form during transmission. By transforming the data parameter from readable to unreadable (encrypted) state, the system maintains transmission efficiency while preventing interception, as the encrypted data appears meaningless to unauthorized parties.
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
A method for facilitating secure payment for a transaction comprises generating, at a customer device, an encrypted token for presentation to a merchant device as an optically scannable indicia for use in authenticating a transaction without exposing customer payment information to a merchant, at a payment processing server, storing payment information of a customer in a secure customer database, receiving, at said payment processing server, signals representing transaction information from a merchant device, the transaction information comprising purchase information and scanned indicia data representative of the encrypted token and omitting the payment information of the customer, retrieving said payment information from said secure customer database based on the scanned indicia data representative of the encrypted token, sending, by said payment processing server to an account processing resource, signals representing an authorization request, the authorization request including data corresponding to at least a portion of the transaction information and the payment information of the customer, receiving, at the payment processing server, signals representing an authorization response indicating whether the authorization request has been approved, and sending signals corresponding to the authorization response to at least one of the merchant device and the customer device, wherein at least a portion of the transaction information is received from the customer device via the merchant device, or from the merchant device via the customer device using a scanner, Bluetooth, NFC, Wi-Fi, or IR.