Point-to-Point Encryption Tokenization Mobile Device
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack robust security measures for processing and storing sensitive data, such as Card Holder Data (CHD), especially in large-scale payment card environments, where data protection and access control are critical but often inadequate.
Innovation Solution
A point-to-point encryption and tokenization system using a mobile device, which encrypts data on the user's device, transmits it to a first computing system, and then to a PCI DSS-compliant environment for processing, generating a token that represents the data, ensuring secure storage and access control through segmented zones and cryptographic techniques.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If sensitive data is stored and processed in traditional computing systems, then data accessibility and processing capability are improved, but security and access control deteriorate
Solution Approach 1:
The system segments sensitive data into multiple components: encrypted data stored in databases, decryption keys held in HSMs, and token representations for access. This segmentation ensures that no single component contains both data and its key, improving security while maintaining accessibility through distributed retrieval mechanisms.
Solution Approach 2:
The patent introduces tokens as intermediary representations of sensitive data. Instead of directly accessing or storing plaintext data, the system uses tokens that reference encrypted data locations. This intermediary layer enables data accessibility through token manipulation while preventing direct access to the actual sensitive information, thereby maintaining security.
2Reliability
If data is encrypted and tokenized throughout its lifecycle, then security is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal tokenization framework that works across multiple data types and processing scenarios. The same tokenization mechanisms, HSM integrations, and encrypted storage approaches are applied consistently to Cardholder Data, Authentication Data, and other sensitive information types. This universal approach manages complexity by reusing the same security infrastructure rather than implementing separate systems for each data type.
Solution Approach 2:
The system creates token copies that represent sensitive data without duplicating the actual sensitive information. These token copies can be freely transmitted, stored, and processed in place of the original data, reducing the complexity of securing every instance of sensitive data while maintaining security through the underlying encryption and HSM protection of the original information.
3Reliability
If segmented zones and cryptographic techniques are used for access control, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent implements self-service mechanisms where the tokenization and encryption processes automatically manage access control without requiring manual security interventions. The HSMs automatically handle key management and decryption operations, while the tokenization framework automatically enforces access policies. This automation maintains strong access control while simplifying operations by eliminating the need for manual security management.
Solution Approach 2:
The system incorporates feedback mechanisms where tokens carry embedded authorization information that automatically determines access rights. When data is retrieved or processed, the system verifies token validity and authorization levels, providing immediate feedback on whether access is permitted. This automated feedback loop maintains security while simplifying operations by eliminating manual authorization checks.
Data Source
AI summary
Mechanisms for providing point to point encryption and tokenization enabling decryption, tokenization and storage of sensitive encrypted data on one system are discussed.


