Point-to-Point Encryption Tokenization Mobile Device

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack robust security measures for processing and storing sensitive data, such as Card Holder Data (CHD), especially in large-scale payment card environments, where data protection and access control are critical but often inadequate.

Innovation Solution

A point-to-point encryption and tokenization system using a mobile device, which encrypts data on the user's device, transmits it to a first computing system, and then to a PCI DSS-compliant environment for processing, generating a token that represents the data, ensuring secure storage and access control through segmented zones and cryptographic techniques.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If sensitive data is stored and processed in traditional computing systems, then data accessibility and processing capability are improved, but security and access control deteriorate

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments sensitive data into multiple components: encrypted data stored in databases, decryption keys held in HSMs, and token representations for access. This segmentation ensures that no single component contains both data and its key, improving security while maintaining accessibility through distributed retrieval mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces tokens as intermediary representations of sensitive data. Instead of directly accessing or storing plaintext data, the system uses tokens that reference encrypted data locations. This intermediary layer enables data accessibility through token manipulation while preventing direct access to the actual sensitive information, thereby maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is encrypted and tokenized throughout its lifecycle, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal tokenization framework that works across multiple data types and processing scenarios. The same tokenization mechanisms, HSM integrations, and encrypted storage approaches are applied consistently to Cardholder Data, Authentication Data, and other sensitive information types. This universal approach manages complexity by reusing the same security infrastructure rather than implementing separate systems for each data type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system creates token copies that represent sensitive data without duplicating the actual sensitive information. These token copies can be freely transmitted, stored, and processed in place of the original data, reducing the complexity of securing every instance of sensitive data while maintaining security through the underlying encryption and HSM protection of the original information.

Inventive Principle:
Principle #26Copying

3Reliability

If segmented zones and cryptographic techniques are used for access control, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveaccess controlVSAvoiddata processing simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service mechanisms where the tokenization and encryption processes automatically manage access control without requiring manual security interventions. The HSMs automatically handle key management and decryption operations, while the tokenization framework automatically enforces access policies. This automation maintains strong access control while simplifying operations by eliminating the need for manual security management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback mechanisms where tokens carry embedded authorization information that automatically determines access rights. When data is retrieved or processed, the system verifies token validity and authorization levels, providing immediate feedback on whether access is permitted. This automated feedback loop maintains security while simplifying operations by eliminating manual authorization checks.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11361312B2System and methods for point to point encryption and tokenization using a mobile device
Publication Date: 2022.06.14 WALMART APOLLO LLC
  • US11361312B2 patent drawing
  • US11361312B2 patent drawing
  • US11361312B2 patent drawing

AI summary

Mechanisms for providing point to point encryption and tokenization enabling decryption, tokenization and storage of sensitive encrypted data on one system are discussed.