Merchant Token Verification for Alternate Payment Processor Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In payment environments where multiple payment processors are involved, alternate payment processors cannot enforce domain restrictions for merchant provisioned tokens since they lack access to the domain index where the necessary information is stored, compromising security and fraud protection.
Innovation Solution
An alternate payment processor verifies merchant provisioned token information by comparing it with token reference information received from the token service provider, indicating any mismatches to the issuer and merchant, ensuring domain restrictions are enforced without direct access to the domain index.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the token service provider does not enforce domain control restrictions, then payment processing flexibility is improved, but security and fraud protection deteriorate
Solution Approach 1:
The patent introduces an intermediary verification mechanism where the token service provider acts as a mediator between the payment processor and the domain restriction enforcement. The token service provider receives verification requests from payment processors, checks domain restrictions internally using its domain index, and returns verification results without requiring direct access to the domain index by the payment processor. This intermediary role enables security enforcement while maintaining payment processing flexibility.
2Adaptability or versatility
If the alternate payment processor does not have access to the domain index, then system architecture flexibility is improved, but domain restriction enforcement capability deteriorates
Solution Approach 1:
The token service provider serves as an intermediary that bridges the gap between the payment processor and the domain index. The payment processor sends verification requests containing token information to the token service provider, which then performs the actual domain restriction checking against its domain index and returns the verification result. This architecture allows the payment processor to enforce domain restrictions without direct access to the domain index.
Solution Approach 2:
The system creates a verification copy mechanism where the token service provider maintains a copy of the domain restriction information in its domain index, and uses this copy to verify token domain restrictions on behalf of payment processors. This allows domain restriction enforcement to be replicated across multiple payment processors without each having direct access to the original domain index.
3Reliability
If the token service provider enforces domain control restrictions, then security is improved, but payment processor interoperability deteriorates
Solution Approach 1:
The token service provider implements a universal verification interface that can serve multiple payment processors simultaneously. The verification mechanism is designed to be agnostic to the specific payment processor, allowing any payment processor to request domain restriction verification through the same interface. This multi-functional design enables both security enforcement and broad payment processor interoperability.
Solution Approach 2:
The token service provider acts as a universal intermediary between domain restriction enforcement and multiple payment processors. By centralizing the verification logic and domain index access in the token service provider, the system enables secure domain restriction enforcement while allowing multiple payment processors to interoperate through the standardized verification interface.
Data Source
AI summary
A merchant provisions a merchant provisioned token from a token service provider. The merchant sends a transaction authorization request, including the merchant provisioned token received from the token service provider to an alternate payment processor. The token service provider does not enforce the domain control restriction by indicating the merchant domain for which the merchant provisioned token was provisioned. The alternate payment processor validates a first set of token information received in the transaction authorization request with token reference information received form the token service provider. The alternate payment processor then indicates whether the token information on the transaction matches the token reference information. The card issuer and merchant may use this information to assist in their decisions to proceed with the transaction or decline the transaction.


