Mobile Transaction Token Generation via Intermediary Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The proliferation of mobile devices and applications has increased opportunities for unauthorized access and misuse of sensitive information during transactions, as less scrupulous resource providers may lack the capability to secure transactions, leading to risks for users and entities involved.

Innovation Solution

A system and method that enables users to remotely generate a token for transactions using a mobile device identifier, where the token is used to authenticate and complete transactions anonymously, without sharing sensitive information with resource providers, ensuring secure and liability-limited transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users provide sensitive information (e.g., credit card numbers) directly to resource providers for transactions, then transaction completeness is improved, but security and risk of unauthorized access deteriorate

Engineering Contradiction:
Improvetransaction completenessVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a service provider as an intermediary between the user and resource provider. The service provider receives the mobile device identifier from the resource provider, generates a message to the user's mobile device, and obtains a token that is then used to complete the transaction. This intermediary system prevents direct exposure of sensitive information while enabling transaction completion.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses a token as a copy or substitute for sensitive information. Instead of transmitting actual credit card numbers or other sensitive data, the system generates a token that represents the user's authorization. This token can be used to complete transactions without exposing the underlying sensitive information to resource providers or potential attackers.

Inventive Principle:
Principle #26Copying

2Object-affected harmful factors

If users transact anonymously without providing sensitive information, then security is improved, but transaction authorization and verification deteriorate

Engineering Contradiction:
Improvedata securityVSAvoidtransaction authorization
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent replaces traditional mechanical authentication methods (direct provision of credit card numbers, IDs, or other sensitive information) with an electronic token-based system. The token is generated through a secure process involving the service provider and the user's mobile device, and it can be electronically transmitted and verified without physical exposure of sensitive data.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If resource providers have access to sensitive user information, then transaction processing is simplified, but opportunities for misuse and unauthorized access increase

Engineering Contradiction:
Improvetransaction processing efficiencyVSAvoidmisuse risk
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The patent extracts sensitive information from the transaction flow. Instead of resource providers having direct access to sensitive user data, the system extracts this information and replaces it with a token. The resource provider only receives and processes the token, not the underlying sensitive information, thereby maintaining transaction processing efficiency while eliminating misuse risks.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20240362630A1Secure remote transaction system using mobile devices
Publication Date: 2024.10.31 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US20240362630A1 patent drawing
  • US20240362630A1 patent drawing
  • US20240362630A1 patent drawing

AI summary

Described herein is a secure system and methods for enabling a user to remotely generate a token to be used in a transaction. In the disclosure, the user may provide a mobile device identifier to a resource provider to complete a transaction. A service provider, upon receiving the mobile device identifier, may generate a message to be transmitted to a mobile device associated with that mobile device identifier that includes details of the transaction to be complete. Upon receiving the message, the user may be asked to elect a token service installed on the mobile device with which the transaction should be completed. This token service may be used to authenticate the user and subsequently generate or provide the requested token. The service provider computer may then use the generated token to complete the transaction.