Low-Value Token System for Secure Third-Party Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the context of secure network transactions, merchants face challenges in accessing sensitive data for third-party services while maintaining security and cost-effectiveness, as existing tokenization methods may dilute the risk reduction and value proposition when involving third-party services that require sensitive data access.

Innovation Solution

The implementation of a low-value token system, where a low-value token is generated and used to obtain sensitive data from a transaction processor, allowing third-party services to access only the necessary data for specific transactions, with controls in place to restrict usage and ensure security, such as dynamic token generation and time-limited validity, and authentication processes for authorized third-party access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If merchants store sensitive data locally for third-party service access, then service functionality is improved, but security and risk reduction are worsened

Engineering Contradiction:
Improvethird-party service accessVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments sensitive data access by creating two types of tokens: high-value tokens for transaction processing and low-value tokens for third-party service access. This segmentation allows third parties to access only the minimum necessary data (low-value tokens) rather than full sensitive data, thereby enabling service functionality while maintaining security and reducing risk exposure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces low-value tokens as intermediaries between merchants and third-party services. These tokens act as mediators that enable third-party access to necessary data without exposing actual sensitive information. The tokens are de-tokenized by the transaction processor only when needed for specific services, providing controlled access while maintaining security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If merchants use traditional tokenization without third-party access, then security is improved, but service functionality and interoperability are worsened

Engineering Contradiction:
Improvedata securityVSAvoidthird-party service interoperability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic token management where low-value tokens can be generated, revoked, and controlled based on service requirements. The system dynamically adjusts token validity periods, access permissions, and de-tokenization policies to balance security with third-party service interoperability needs, allowing merchants to engage multiple third parties with different access levels.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of tokenization by creating tokens with different value levels and access permissions. Low-value tokens have restricted parameters that allow only specific data access for defined purposes and time periods, enabling third-party service interoperability while maintaining security controls through parameter-based access management.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If merchants store sensitive data for future transactions, then transaction convenience is improved, but security risk and compliance burden are worsened

Engineering Contradiction:
Improvetransaction convenienceVSAvoiddata breach risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive data from merchant systems and stores it only in the encrypted token vault at the transaction processor. Merchants keep only token references locally, which are useless without the corresponding de-tokenization keys held by the transaction processor. This extraction eliminates the security risk of storing sensitive data at merchants while maintaining transaction convenience through token-based processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent employs short-lived low-value tokens that are generated for specific transactions or service sessions and then invalidated. These disposable tokens minimize the window of opportunity for data breaches, as even if compromised, they have limited validity periods and restricted access permissions, reducing the overall data breach risk while maintaining operational convenience.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS20240348616A1Systems and methods for third-party interoperability in secure network transactions using tokenized data
Publication Date: 2024.10.17 WORLDPAY LLC
  • US20240348616A1 patent drawing
  • US20240348616A1 patent drawing
  • US20240348616A1 patent drawing

AI summary

Embodiments include methods and systems for enabling third-party data service interoperability, comprising receiving, from an electronic data server, a request for a low-value token, the low-value token being associated with a subset of sensitive data associated with a user; providing the low-value token to the electronic data server; receiving a request for the subset of sensitive data, from a third-party data service server, the request comprising the low-value token; de-tokenizing the low-value token to obtain the subset of sensitive data; providing the subset of sensitive data to the third-party data service server; receiving, from an electronic data server, the low-value token and a transaction authorization request; determining, based on the low-value token and authorization request, an authorization response; and providing the authorization response to the electronic data server.