Merchant Token Sharing for Cardholder Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Tokenization systems limit merchants' ability to share cardholder data (CHD) with other merchants, hindering services like booking reservations or charging cancellation fees, and restrict access to payment processors not supported by the tokenization gateway.

Innovation Solution

A system and process for sharing CHD between merchants using a tokenization provider system, allowing a first merchant to associate and share tokens with a second merchant, enabling the second merchant to access the CHD while maintaining security through authorization factors, preventing automated access and ensuring two levels of obscurity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If tokenization is implemented to secure cardholder data, then security is improved, but merchants lose the ability to share CHD with other merchants

Engineering Contradiction:
ImprovesecurityVSAvoidability to share CHD
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the cardholder data access by creating separate authorization pathways: tokens for automated processing and authorized CHD sharing for merchant-initiated transactions. This allows both security (through tokenization) and flexibility (through controlled CHD sharing) to coexist by dividing the access control mechanism into distinct segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary authorization process where the first merchant acts as a mediator to grant controlled access to the second merchant. The authorization factor serves as an intermediary credential that enables the second merchant to access CHD without direct exposure, maintaining security while enabling necessary data sharing for customer service continuity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If CHD is shared with second merchant, then service continuity is improved, but security risk increases

Engineering Contradiction:
Improveservice continuityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authorization by requiring the first merchant to pre-approve and share authorization factors with the second merchant before any CHD access occurs. This preliminary action establishes security controls in advance, allowing service continuity while pre-vetting the second merchant's access rights and minimizing security risks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the access parameter from direct CHD exposure to authorized access via authentication. The second merchant's access rights are dynamically controlled through authentication factors and authorization levels, transforming the security model from static data protection to dynamic access control that enables service continuity with managed risk.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If authorization factors are implemented, then automated access is prevented, but system complexity increases

Engineering Contradiction:
Improveautomated access preventionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system extracts the authentication capability from the transaction processing flow by implementing separate authorization factor verification. This extraction prevents automated brute-force attacks on transaction systems while isolating the complexity of authentication into a dedicated component, reducing overall system complexity despite enhanced security.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9818111B2Merchant-based token sharing
Publication Date: 2017.11.14 SHIFT4 CORP
  • US9818111B2 patent drawing
  • US9818111B2 patent drawing
  • US9818111B2 patent drawing

AI summary

One embodiment of the present disclosure provides a system and associated processes for sharing cardholder data (CHD) between a merchant that utilizes tokenization and a second merchant that may or may not utilize tokenization. In one embodiment, the merchant, or an employee of the merchant, can use the system and associated processes to reacquire CHD from a tokenization provider system. In one embodiment, the merchant identifies to the tokenization provider system a desire to share CHD, which is associated with a token, with a second merchant. The merchant and/or the tokenization provider system can then invite the second merchant to register with the tokenization provider system. Once registered with the tokenization provider system, the second merchant can access any CHD that the merchant associated with the second merchant.