Mobile Transaction Token Generation via Intermediary Service
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The proliferation of mobile devices and applications has increased opportunities for unauthorized access and misuse of sensitive information during transactions, as less scrupulous resource providers may lack the capability to secure transactions, leading to risks for users and entities involved.
Innovation Solution
A system and method that enables users to remotely generate a token for transactions using a mobile device identifier, where the token is used to authenticate and complete transactions anonymously, without sharing sensitive information with resource providers, ensuring secure and liability-limited transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users provide sensitive information (e.g., credit card numbers) directly to resource providers for transactions, then transaction completeness is improved, but security and risk of unauthorized access deteriorate
Solution Approach 1:
The patent introduces a service provider as an intermediary between the user and resource provider. The service provider receives the mobile device identifier from the resource provider, generates a message to the user's mobile device, and obtains a token that is then used to complete the transaction. This intermediary system prevents direct exposure of sensitive information while enabling transaction completion.
Solution Approach 2:
The patent uses a token as a copy or substitute for sensitive information. Instead of transmitting actual credit card numbers or other sensitive data, the system generates a token that represents the user's authorization. This token can be used to complete transactions without exposing the underlying sensitive information to resource providers or potential attackers.
2Object-affected harmful factors
If users transact anonymously without providing sensitive information, then security is improved, but transaction authorization and verification deteriorate
Solution Approach 1:
The patent replaces traditional mechanical authentication methods (direct provision of credit card numbers, IDs, or other sensitive information) with an electronic token-based system. The token is generated through a secure process involving the service provider and the user's mobile device, and it can be electronically transmitted and verified without physical exposure of sensitive data.
3Productivity
If resource providers have access to sensitive user information, then transaction processing is simplified, but opportunities for misuse and unauthorized access increase
Solution Approach 1:
The patent extracts sensitive information from the transaction flow. Instead of resource providers having direct access to sensitive user data, the system extracts this information and replaces it with a token. The resource provider only receives and processes the token, not the underlying sensitive information, thereby maintaining transaction processing efficiency while eliminating misuse risks.
Data Source
AI summary
Described herein is a secure system and methods for enabling a user to remotely generate a token to be used in a transaction. In the disclosure, the user may provide a mobile device identifier to a resource provider to complete a transaction. A service provider, upon receiving the mobile device identifier, may generate a message to be transmitted to a mobile device associated with that mobile device identifier that includes details of the transaction to be complete. Upon receiving the message, the user may be asked to elect a token service installed on the mobile device with which the transaction should be completed. This token service may be used to authenticate the user and subsequently generate or provide the requested token. The service provider computer may then use the generated token to complete the transaction.


