Hybrid Dynamic Wallet Token Morphing for Cross-Channel Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The payment industry faces challenges in securely representing user digital identity and preventing card/funding source data sharing across payment systems, especially with the rise of cross-channel commerce and Internet of Things (IoT) use cases, where secure transaction methods are needed to ensure data integrity and privacy.
Innovation Solution
The implementation of hybrid dynamic wallet tokens that can morph with additional transaction-related information, using discretionary fields in track 1 and 2 data, and ISO 8583 Bitmap 2 or 3, to transmit metadata such as user identity, preferences, and loyalty information, allowing secure offline caching and online transactions, even in environments with limited connectivity, through a wallet token service provider like PayPal.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If card/funding source data is shared across payment systems to enable cross-channel commerce, then transaction convenience is improved, but security and data privacy are worsened
Solution Approach 1:
The patent introduces tokenization as an intermediary mechanism that replaces sensitive card/funding source data with tokens. These tokens serve as mediators between the payment system and the user's financial information, allowing transactions to proceed without exposing actual card data. The token acts as a secure bridge that enables cross-channel commerce while preventing direct access to sensitive funding source information.
Solution Approach 2:
The patent creates token copies that represent the original card/funding source data without containing the actual sensitive information. These token copies enable transaction processing across multiple channels while the original sensitive data remains protected. The token is a functional copy that allows payment operations without replicating the harmful exposure of actual card numbers.
2Reliability
If user digital identity is represented securely to prevent data sharing, then security is improved, but transaction functionality across channels is worsened
Solution Approach 1:
The patent makes the token universal across multiple payment channels and transaction types. A single tokenized representation of user identity and funding source can be used online, offline, through mobile devices, and across different merchants. This multi-functional token enables cross-channel commerce while maintaining consistent security standards, as the same tokenization mechanism protects user data regardless of the transaction channel.
Solution Approach 2:
The patent implements dynamic tokenization where tokens can be generated, updated, and invalidated based on transaction context. Tokens can be channel-specific or merchant-specific, allowing the system to adapt security parameters dynamically. This dynamic approach enables secure functionality across diverse channels by adjusting token properties to match specific transaction requirements while maintaining overall security integrity.
3Productivity
If actual card data is transmitted for transactions, then transaction processing is simplified, but data privacy and security are worsened
Solution Approach 1:
The token serves as an intermediary that replaces actual card data in transmission. Instead of sending sensitive card numbers across networks and between systems, the token is transmitted as the intermediary representation. This maintains transaction processing efficiency because the token can be processed through existing payment infrastructure, while simultaneously protecting data privacy by eliminating the transmission of actual sensitive card information.
4Adaptability or versatility
If sensitive payment information is stored and shared across systems, then service functionality is improved, but security risks are worsened
Solution Approach 1:
The patent extracts the sensitive information from the token, storing only the non-sensitive token representation in payment systems. The actual sensitive payment information remains extracted and protected, stored only in secure tokenization vaults with strict access controls. This allows service functionality to operate with the token while the harmful exposure of sensitive data is prevented by taking it out of the transaction flow entirely.
Data Source
AI summary
A system or method may be provided to implement dynamic hybrid wallet tokens. The method can includes determining to generate a hybrid wallet token based on a user request for a transaction at a user device. The method includes determining, based on a transaction type of the transaction, non-payment information of a user associated with the user device. The method includes generating a hybrid wallet token for use with a payment account associated with the user, where the generating is based on the authorization token and on the transaction type, the hybrid wallet token comprising information indicating a funding instrument associated with the user, the hybrid wallet token further comprising the non-payment information. The method also includes providing the wallet token to the user device for implementing the transaction.


