Intermediary Gateway Tokenization for PCI DSS Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for handling sensitive information, such as credit card data, in call center operations face challenges in complying with PCI DSS requirements and protecting data from unauthorized access, especially when processing and transmitting cardholder data across various system components.

Innovation Solution

Implementing an intermediary computing device that converts protected information into an unprotected format for secure transmission, while ensuring only authorized devices receive the sensitive information, using techniques like encryption, tokenization, and obscuration, and employing a proxy server to reroute communications and modify data entry formats to prevent plain-text storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If call centre operations directly access and process cardholder data to provide services, then service functionality is improved, but PCI DSS compliance burden and security risk increase

Engineering Contradiction:
Improveservice functionalityVSAvoidPCI DSS compliance burden
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the call centre operations and the cardholder data environment. The gateway receives cardholder data from the call centre, converts it to tokenized form, and forwards tokens to authorized systems. This intermediary architecture allows call centre operations to maintain service functionality while the gateway itself becomes the primary PCI DSS compliance target, reducing the compliance burden on individual call centre systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the cardholder data environment into distinct functional zones: the call centre operation zone that handles service requests, the gateway zone that performs tokenization, and the authorized system zone that processes tokens. This segmentation isolates the PCI DSS compliance requirements to specific components rather than requiring all systems to be fully compliant, thereby reducing overall compliance complexity.

Inventive Principle:
Principle #1Segmentation

2Productivity

If sensitive information is transmitted in plain text for processing, then processing efficiency is improved, but security risk from unauthorized access increases

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the format parameter of sensitive information from plain text to tokenized form during transmission and storage. The tokenization process transforms cardholder data into non-sensitive tokens that maintain the structural properties needed for processing (such as length and format) while eliminating the security risks associated with storing and transmitting actual card numbers. This parameter change allows systems to process data efficiently without exposing sensitive information.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If all system components connected to cardholder data environment must comply with PCI DSS, then security coverage is improved, but operational complexity and audit costs increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway acts as a centralized intermediary that consolidates PCI DSS compliance requirements. By positioning the gateway as the primary point of contact for cardholder data and implementing robust tokenization and logging at this single point, the system achieves comprehensive security coverage while reducing operational complexity. The gateway's centralized security controls replace the need for distributed compliance measures across all connected systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the compliance burden from individual call centre systems and centralized it in the gateway device. The gateway extracts and processes cardholder data through secure tokenization before any data enters the broader system environment. This extraction approach ensures that security controls are applied at the critical entry point rather than requiring every downstream system to implement full PCI DSS compliance, thereby reducing operational complexity while maintaining security coverage.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2795556B1Method and apparatus for mediating communications
Publication Date: 2019.06.19 ECKOH UK
  • EP2795556B1 patent drawingFigure 1
  • EP2795556B1 patent drawingFigure 2a~2d
  • EP2795556B1 patent drawingFigure 3a~3b

AI summary

A method of mediating communications between a first computing device and a second computing device, by an intermediary computing device, comprising establishing a communications link to each of the first and second computing devices, receiving a first message from the first computing device, the content of the first message comprising information in a protected format, converting at least part of the information in the protected format to an unprotected format, and transmitting a second message to the second computing device, the content of the second message comprising at least part of the information in the unprotected format.