Secure Mobile Payment Tokenization via Intermediary Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of credit and gift cards for payments has led to rampant fraud, especially in self-service terminals and online transactions, where there is no validation of the cardholder's presence, making it easier for individuals to guess card numbers without physical verification.

Innovation Solution

A method for secure mobile payment that involves acquiring payment card information, processing an added security check, and using a token for transactions, which can be supplied via a mobile device, allowing for secure payments without storing the card information on the device and providing additional security without modifying existing payment services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If payment card information is used for transactions at self-service terminals or online, then convenience for customers is improved, but fraud risk increases due to lack of physical verification

Engineering Contradiction:
Improveconvenience of paymentVSAvoidfraud risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a token as an intermediary element that replaces direct use of payment card information. The token is generated by a trusted service provider and contains encrypted references to the actual card details. This intermediary layer allows automated transactions to proceed conveniently while preventing fraud, as the token cannot be reverse-engineered to reveal the original card information and can only be used with proper authorization verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a cryptographic copy (token) of the payment card information that functions similarly to the original card but cannot be used to reconstruct the original. The token is a simplified representation that contains only the necessary information for transaction processing, stripped of sensitive details that could be exploited for fraud. This copying approach maintains convenience while eliminating the security vulnerability of storing or transmitting actual card numbers.

Inventive Principle:
Principle #26Copying

2Ease of operation

If card numbers are made accessible for guessing or visual inspection, then ease of use is improved, but security against fraud deteriorates

Engineering Contradiction:
Improveease of card useVSAvoidsecurity validation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the essential functional elements of card information needed for transactions while removing the vulnerable components (actual card numbers, CVV codes). The token contains only the minimum necessary data for authorization, separated from the sensitive information that could be guessed or visually inspected. This extraction creates a system that maintains ease of use through simple token presentation while eliminating the security weaknesses of exposing complete card details.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If security checks are added to payment processing, then fraud prevention is improved, but transaction complexity increases

Engineering Contradiction:
Improvefraud preventionVSAvoidpayment processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs security verification in advance during the token generation process. The trusted service provider validates the payment card information and creates the authorized token before the actual transaction occurs. This preliminary security check ensures that only properly authenticated cards can generate valid tokens, preventing fraud before transactions happen. The actual transaction then becomes simple token presentation, reducing complexity at the point of sale while maintaining strong security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11030627B2Techniques for secure mobile payment
Publication Date: 2021.06.08 NCR VOYIX CORP
  • US11030627B2 patent drawing
  • US11030627B2 patent drawing
  • US11030627B2 patent drawing

AI summary

Techniques for secure mobile payment are provided. A credit or gift card is registered for additional security, such that a secure identifier or personal identification number (PIN) is required for use of the credit or gift card. Registration is not required or even known by the third-party payment service associated with the card. Subsequently, when a consumer attempts to use the card and before payment instructions are sent to the corresponding third-party payment service, the secure identifier or PIN is requested and verified. If properly verified, the payment instructions are forwarded for processing by the third-party payment service.