Ledger Server Security for Electronic Payment Settlement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The security of electronic payment processes is limited by the strength of security measures implemented at point-of-sale terminals and computer networks, as consumer and merchant account information are transmitted over the same network, making the process vulnerable to breaches.

Innovation Solution

A ledger server system that receives service option initiation and authorization messages from distinct computer servers, validating these messages and facilitating transfers between institution ledgers, thereby improving security by separating the transmission of account information and authorization processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If consumer and merchant account information are transmitted over the same computer network from the same point-of-sale terminal and acquirer server, then the electronic payment process can be completed, but the security of the payment process is limited by the strength of security measures at the point-of-sale terminal and computer network

Engineering Contradiction:
Improvesecurity of electronic payment processVSAvoidcomplexity of separate server architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the payment processing architecture into separate servers: the point-of-sale terminal server handles transaction initiation and consumer account information, while the acquirer server handles authorization and merchant account information. This segmentation ensures that even if one server is compromised, the other remains secure, thereby improving overall payment process security without requiring complete restructuring of the payment ecosystem.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention introduces a ledger server as an intermediary that receives service option initiation messages from the point-of-sale terminal server and service option authorization messages from the acquirer server. This intermediary validates messages and effects transfers between institution ledgers, creating an additional layer of security that isolates the transmission of sensitive account information from the authorization process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate and distinct computer servers are used for service option initiation and authorization messages, then security is improved by separating transmission of account information and authorization processes, but the system complexity increases

Engineering Contradiction:
Improvesecurity through separated transmissionVSAvoidnumber of distinct computer servers
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The payment system is segmented into distinct functional servers: point-of-sale terminal server for initiating transactions and transmitting consumer account information, acquirer server for authorizing transactions and transmitting merchant account information, and ledger server for validating messages and processing transfers. This segmentation improves security by ensuring that compromise of one server does not necessarily compromise others, while the ledger server coordinates between them to manage the increased system complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11687933B2Electronic account settlement via distinct computer servers
Publication Date: 2023.06.27 THE TORONTO DOMINION BANK
  • US11687933B2 patent drawing
  • US11687933B2 patent drawing
  • US11687933B2 patent drawing

AI summary

A server includes a processor that receives, from a first device, initiation message(s) each including a service identifier and a service value and, for each initiation message, saves in a database a record comprising the service identifier in association with the service value. The processor receives, from a second device, authorization message(s) each including one of the service identifiers and an authorization value, and for each authorization message, validates one of the initiation messages by (i) locating in the database the record comprising the one service identifier, and (ii) confirming that the service value in the located database record matches the authorization value. The processor updates a journal with an entry identifying a transfer between a first ledger and a second ledger in an amount equal to a sum of the service values of the validated initiation messages, and provides the first device with a message confirming the transfer.