Mobile Payment Tokenization via Intermediary Layer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data protection methods in mobile and payment environments are inadequate in preventing unauthorized access to sensitive data, as encryption can be overcome by hacking methods and storage security measures do not protect data after being bypassed.

Innovation Solution

Tokenization of sensitive data in mobile and payment environments using tokenization parameters, where data is replaced with tokens stored in token tables, and additional security measures like initialization vectors are used to enhance security, allowing for secure transmission and storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is used to protect sensitive data during transmission and storage, then data security is improved, but encryption can be overcome by hacking methods and is subject to resource-intensive audit requirements

Engineering Contradiction:
Improvedata securityVSAvoidaudit requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a tokenization intermediary layer that replaces sensitive data with tokens before transmission and storage. This intermediary mechanism (tokenization service) converts actual sensitive data into token representations, which cannot be reverse-engineered even if intercepted. The tokenization process eliminates the need for traditional encryption/decryption cycles and associated audit requirements, while maintaining data security through unbreakable token mappings stored securely in token vaults.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If storage security measures are implemented to protect sensitive data at authorized entities, then protection against intrusion is improved, but such measures do not protect data after unauthorized entities bypass the security measures

Engineering Contradiction:
Improvestorage securityVSAvoiddata exposure after breach
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive data from the storage environment entirely by replacing it with tokens at the point of capture. Instead of securing sensitive data in storage systems with complex security measures, the actual sensitive data is removed from the storage ecosystem and replaced with inert tokens. Even if unauthorized entities bypass storage security measures, they only obtain tokens that cannot be converted back to sensitive data without access to the tokenization service's secure token vaults.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If sensitive data is transmitted wirelessly between multiple authorized entities, then data processing capability is improved, but vulnerability to interception at multiple points increases

Engineering Contradiction:
Improvedata processing capabilityVSAvoidinterception vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by performing tokenization at the very first point where sensitive data is captured (e.g., at the mobile device or point-of-sale terminal) before any wireless transmission occurs. This preliminary transformation converts sensitive data into tokens upfront, so that all subsequent wireless transmissions between authorized entities involve only tokens rather than actual sensitive data. This eliminates interception vulnerability across the entire transmission chain while maintaining processing capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9904923B2Tokenization in mobile environments
Publication Date: 2018.02.27 PROTEGRITY US HLDG LLC
  • US9904923B2 patent drawing
  • US9904923B2 patent drawing
  • US9904923B2 patent drawing

AI summary

Data can be protected in mobile and payment environments through various tokenization operations. A mobile device can tokenize communication data based on device information and session information associated with the mobile device. A payment terminal can tokenize payment information received at the payment terminal during a transaction based on transaction information associated with the transaction. Payment data tokenized first a first set of token tables and according to a first set of tokenization parameters by a first payment entity can be detokenized or re-tokenized with a second set of token tables and according to a second set of tokenization parameters. Payment information can be tokenized and sent to a mobile device as a token card based on one or more selected use rules, and a user can request a transaction based on the token card. The transaction can be authorized if the transaction satisfies the selected use rules.