Merchant Payment Tokenization Without Sensitive Card Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing tokenization methods in credit card and financial transactions have limitations in functionality, leading to high compliance costs and security risks for merchants due to the need for PCI DSS compliance and potential data breaches.
Innovation Solution
A system where sensitive financial account information is stored on a secure server, with a token generated for the merchant to process payments, reducing the need for merchants to handle or store the actual data, thus minimizing compliance costs and security risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If merchants store and process credit card data directly, then payment processing functionality is complete, but security risks and compliance costs increase significantly
Solution Approach 1:
The patent extracts sensitive credit card data from the merchant's environment and stores it in a separate, PCI-compliant data store. The merchant system only retains token references, not actual card data. This extraction resolves the contradiction by removing the security burden from merchants while preserving payment processing functionality.
Solution Approach 2:
The patent introduces a tokenization intermediary layer that mediates between the merchant system and the payment card industry data security standard requirements. Tokens act as intermediaries that reference actual card data stored securely elsewhere, allowing merchants to process payments without directly handling sensitive data, thus reducing compliance complexity.
2Reliability
If merchants implement full PCI DSS compliance measures, then security is improved, but operational costs and time investment increase substantially
Solution Approach 1:
By extracting sensitive data storage from the merchant's responsibility scope and placing it in a PCI-compliant environment, the patent eliminates the need for merchants to undergo expensive and time-consuming PCI DSS compliance audits while maintaining equivalent security standards.
Solution Approach 2:
The patent creates token copies that reference actual card data. These tokens can be stored and processed by merchants without requiring them to implement full PCI compliance, as the tokens themselves are not sensitive data. This copying mechanism preserves security while reducing compliance burden and time investment.
3Ease of manufacture
If tokenization is implemented to reduce compliance burden, then compliance costs decrease, but functionality is limited
Solution Approach 1:
The patent implements a universal tokenization framework that works across multiple payment scenarios including online transactions, mobile payments, and recurring billing. The token system is designed to be versatile and adaptable to different payment processing needs while maintaining reduced compliance requirements, thus resolving the functionality limitation.
Solution Approach 2:
The patent creates a dynamic tokenization system where tokens can be generated, updated, and revoked as needed. The system adapts to different functional requirements while maintaining the core benefit of reduced compliance burden, allowing merchants to implement tokenization easily without sacrificing payment processing versatility.
Data Source
AI summary
Processing a payment transaction from a payer (operating a payer computing system) to a payee (operating a merchant computing system) by a secure computing system. The secure computing system outputs a financial account registration request form to the payer computing system (e.g., within a window or frame that is displayed within an ecommerce webpage provided by the merchant computing system) for the payer to provide sensitive financial account information, securely stores the sensitive financial account information, maintains compliance with an information security standard (e.g., a Payment Card Industry Data Security Standard), and provides a non-sensitive electronic data token representing the sensitive financial account information to the merchant computing system. The merchant computing system can then process the payment transaction using the sensitive financial account information represented by the non-sensitive electronic data token without actually receiving—and, therefore, having to secure—the underlying sensitive financial account information.


