Encryption Switch Processing for PCI Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Payment Card Industry (PCI) security audit procedures are inadequate as they are conducted at discrete points in time, leaving merchants and acquirers vulnerable to data breaches and imposing significant costs for ongoing compliance, while consumers' account information remains at risk due to exposure through merchant or acquirer systems.

Innovation Solution

Implementing a system that eliminates the need for PCI compliance audits by using tokens derived from keys associated with POS terminals, ensuring per-transaction audits between the Point of Sale (POS) terminal and the payment processing network, thus ensuring PCI Data Security Standards (DSS) compliance without exposing actual account identifiers, reducing fraud risks and operational costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PCI security audits are conducted periodically, then merchants can maintain compliance with PCI DSS standards, but security vulnerabilities exist between audits and operational costs are significant

Engineering Contradiction:
Improvesecurity complianceVSAvoidaudit frequency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent transforms periodic security audits into continuous per-transaction audits. Instead of conducting audits at discrete intervals (quarterly or annually), the system performs security verification with every transaction processing event, eliminating the security gap between audits while maintaining PCI DSS compliance.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system performs security verification in advance by validating the security envelope and token integrity before processing each transaction. This preliminary security check ensures that compliance requirements are met prior to any potential data exposure, rather than discovering vulnerabilities after a breach occurs.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If account identifiers are stored and processed in merchant systems, then transaction processing can be performed, but data breaches and fraud risks increase

Engineering Contradiction:
Improvetransaction processingVSAvoiddata breach risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the actual account identifier from the transaction data stream and replaces it with a token. The account identifier is removed from merchant systems entirely, with only the tokenized version being processed. This extraction eliminates the security vulnerability while preserving transaction processing functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system introduces a security envelope and token as an intermediary between the account identifier and the transaction processing system. The envelope contains the actual account identifier in encrypted form, while the token serves as a safe placeholder that can be processed without exposing sensitive data. This intermediary layer protects against data breaches while enabling normal transaction flow.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If encryption and decryption processes are implemented at Host Security Modules, then data security is enhanced, but operational complexity and costs increase

Engineering Contradiction:
Improvedata securityVSAvoidsecurity infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a cryptographic copy of the account identifier in the form of a token. Instead of repeatedly encrypting and decrypting the actual account identifier at various security modules, the system uses the token as a functional copy that can be processed throughout the transaction chain without requiring decryption. This eliminates the need for multiple HSMs while maintaining security.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system segments the security requirements by separating the handling of account identifiers from transaction processing. The account identifier is encrypted once in the security envelope at the point of capture, then the tokenized version is used for all subsequent processing steps. This segmentation allows transaction systems to operate without complex encryption/decryption infrastructure while maintaining security through the envelope mechanism.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9633351B2Encryption switch processing
Publication Date: 2017.04.25 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US9633351B2 patent drawing
  • US9633351B2 patent drawing
  • US9633351B2 patent drawing

AI summary

Techniques for eliminating the need for merchants and acquirers to conduct Payment Card Industry (“PCI”) security audit procedures are provided. Merchants and acquirers can eliminate the operating expenses associated with conducting audits to ensure compliance with PCI Data Security Standards (“DSS”), while at the same time ensuring that cardholders' data remains secure, thus protecting the cardholders from fraudulent transactions. System security is further enhanced through the use of per transaction audits, with the scope of the audit being directly between the Point of Sale (POS) terminal and the payment processing network. PCI DSS compliance can thus be assured on a per transaction basis, as opposed to only ensuring compliance generally for a merchant or acquirer on a periodic basis. Per transaction PCI DSS compliance is assured, while at the same time eliminating the need for merchants or acquirers to conduct compliance audits.