Encryption Switch Processing for PCI Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing Payment Card Industry (PCI) security audit procedures are inadequate as they are conducted at discrete points in time, leaving merchants and acquirers vulnerable to data breaches and imposing significant costs for ongoing compliance, while consumers' account information remains at risk due to exposure through merchant or acquirer systems.
Innovation Solution
Implementing a system that eliminates the need for PCI compliance audits by using tokens derived from keys associated with POS terminals, ensuring per-transaction audits between the Point of Sale (POS) terminal and the payment processing network, thus ensuring PCI Data Security Standards (DSS) compliance without exposing actual account identifiers, reducing fraud risks and operational costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PCI security audits are conducted periodically, then merchants can maintain compliance with PCI DSS standards, but security vulnerabilities exist between audits and operational costs are significant
Solution Approach 1:
The patent transforms periodic security audits into continuous per-transaction audits. Instead of conducting audits at discrete intervals (quarterly or annually), the system performs security verification with every transaction processing event, eliminating the security gap between audits while maintaining PCI DSS compliance.
Solution Approach 2:
The system performs security verification in advance by validating the security envelope and token integrity before processing each transaction. This preliminary security check ensures that compliance requirements are met prior to any potential data exposure, rather than discovering vulnerabilities after a breach occurs.
2Productivity
If account identifiers are stored and processed in merchant systems, then transaction processing can be performed, but data breaches and fraud risks increase
Solution Approach 1:
The patent extracts the actual account identifier from the transaction data stream and replaces it with a token. The account identifier is removed from merchant systems entirely, with only the tokenized version being processed. This extraction eliminates the security vulnerability while preserving transaction processing functionality.
Solution Approach 2:
The system introduces a security envelope and token as an intermediary between the account identifier and the transaction processing system. The envelope contains the actual account identifier in encrypted form, while the token serves as a safe placeholder that can be processed without exposing sensitive data. This intermediary layer protects against data breaches while enabling normal transaction flow.
3Reliability
If encryption and decryption processes are implemented at Host Security Modules, then data security is enhanced, but operational complexity and costs increase
Solution Approach 1:
The patent creates a cryptographic copy of the account identifier in the form of a token. Instead of repeatedly encrypting and decrypting the actual account identifier at various security modules, the system uses the token as a functional copy that can be processed throughout the transaction chain without requiring decryption. This eliminates the need for multiple HSMs while maintaining security.
Solution Approach 2:
The system segments the security requirements by separating the handling of account identifiers from transaction processing. The account identifier is encrypted once in the security envelope at the point of capture, then the tokenized version is used for all subsequent processing steps. This segmentation allows transaction systems to operate without complex encryption/decryption infrastructure while maintaining security through the envelope mechanism.
Data Source
AI summary
Techniques for eliminating the need for merchants and acquirers to conduct Payment Card Industry (“PCI”) security audit procedures are provided. Merchants and acquirers can eliminate the operating expenses associated with conducting audits to ensure compliance with PCI Data Security Standards (“DSS”), while at the same time ensuring that cardholders' data remains secure, thus protecting the cardholders from fraudulent transactions. System security is further enhanced through the use of per transaction audits, with the scope of the audit being directly between the Point of Sale (POS) terminal and the payment processing network. PCI DSS compliance can thus be assured on a per transaction basis, as opposed to only ensuring compliance generally for a merchant or acquirer on a periodic basis. Per transaction PCI DSS compliance is assured, while at the same time eliminating the need for merchants or acquirers to conduct compliance audits.


