Merchant Token Verification for Alternate Payment Processor Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In payment environments where multiple payment processors are involved, alternate payment processors cannot enforce domain restrictions for merchant provisioned tokens since they lack access to the domain index where the necessary information is stored, compromising security and fraud protection.

Innovation Solution

An alternate payment processor verifies merchant provisioned token information by comparing it with token reference information received from the token service provider, indicating any mismatches to the issuer and merchant, ensuring domain restrictions are enforced without direct access to the domain index.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the token service provider does not enforce domain control restrictions, then payment processing flexibility is improved, but security and fraud protection deteriorate

Engineering Contradiction:
Improvepayment processing flexibilityVSAvoidsecurity and fraud protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary verification mechanism where the token service provider acts as a mediator between the payment processor and the domain restriction enforcement. The token service provider receives verification requests from payment processors, checks domain restrictions internally using its domain index, and returns verification results without requiring direct access to the domain index by the payment processor. This intermediary role enables security enforcement while maintaining payment processing flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the alternate payment processor does not have access to the domain index, then system architecture flexibility is improved, but domain restriction enforcement capability deteriorates

Engineering Contradiction:
Improvesystem architecture flexibilityVSAvoiddomain restriction enforcement capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The token service provider serves as an intermediary that bridges the gap between the payment processor and the domain index. The payment processor sends verification requests containing token information to the token service provider, which then performs the actual domain restriction checking against its domain index and returns the verification result. This architecture allows the payment processor to enforce domain restrictions without direct access to the domain index.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a verification copy mechanism where the token service provider maintains a copy of the domain restriction information in its domain index, and uses this copy to verify token domain restrictions on behalf of payment processors. This allows domain restriction enforcement to be replicated across multiple payment processors without each having direct access to the original domain index.

Inventive Principle:
Principle #26Copying

3Reliability

If the token service provider enforces domain control restrictions, then security is improved, but payment processor interoperability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidpayment processor interoperability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The token service provider implements a universal verification interface that can serve multiple payment processors simultaneously. The verification mechanism is designed to be agnostic to the specific payment processor, allowing any payment processor to request domain restriction verification through the same interface. This multi-functional design enables both security enforcement and broad payment processor interoperability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The token service provider acts as a universal intermediary between domain restriction enforcement and multiple payment processors. By centralizing the verification logic and domain index access in the token service provider, the system enables secure domain restriction enforcement while allowing multiple payment processors to interoperate through the standardized verification interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20260017648A1Transaction security for nonenforced domain control restrictions by a payment processor
Publication Date: 2026.01.15 ITS
  • US20260017648A1 patent drawing
  • US20260017648A1 patent drawing
  • US20260017648A1 patent drawing

AI summary

A merchant provisions a merchant provisioned token from a token service provider. The merchant sends a transaction authorization request, including the merchant provisioned token received from the token service provider to an alternate payment processor. The token service provider does not enforce the domain control restriction by indicating the merchant domain for which the merchant provisioned token was provisioned. The alternate payment processor validates a first set of token information received in the transaction authorization request with token reference information received form the token service provider. The alternate payment processor then indicates whether the token information on the transaction matches the token reference information. The card issuer and merchant may use this information to assist in their decisions to proceed with the transaction or decline the transaction.