Mobile Transaction Security via Gateway Tokenization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile transaction systems are insecure, cumbersome, and lack integration with existing equipment, leading to issues such as data breaches, excessive registration processes, and inadequate protection of credit card information, which discourages spontaneous and secure transactions.

Innovation Solution

A system where a credit card number and user-selected key are encrypted on a gateway server, with the encrypted credit card number stored on the mobile device for subsequent orders, ensuring secure transactions without storing sensitive data on the server or point-of-sale terminal, using a user key for verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If credit card data is stored on merchant servers for convenient repeat ordering, then ease of operation is improved, but security and reliability deteriorate due to data breaches and PCI DSS compliance burden

Engineering Contradiction:
Improveconvenience of repeat orderingVSAvoidsecurity of credit card data
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the credit card data from the merchant's environment entirely. Instead of storing card data on merchant servers, the system uses tokenization where only a token (not the actual card data) is stored on the mobile device. The real card data remains exclusively in the payment processor's secure environment, eliminating the security vulnerability of storing sensitive data on merchant systems while still enabling convenient repeat ordering through the stored token.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a token as an intermediary between the mobile device and the payment processor. This token serves as a secure reference that allows repeat transactions without exposing actual card data. The token acts as a mediator that enables convenient ordering while maintaining security, as it cannot be used outside the specific mobile device and application context.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If tokenization is implemented with a centralized payment processor, then security is improved, but adaptability deteriorates because point-of-sale systems cannot accept universal tokens

Engineering Contradiction:
Improvesecurity of credit card dataVSAvoidcompatibility with existing equipment
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the payment system into distinct components: the mobile device application handles token storage and presentation, the point-of-sale terminal handles order processing, and the payment processor handles actual payment authorization. This segmentation allows each component to perform its specific function without requiring the point-of-sale system to understand or store sensitive card data, maintaining compatibility with existing equipment while improving security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a functional copy of the card data in the form of a token that can be stored on the mobile device. This token is a simplified representation that contains all necessary information for payment authorization without being the actual card data. The token can be presented to multiple different point-of-sale systems, providing universality without compromising security or requiring changes to existing equipment.

Inventive Principle:
Principle #26Copying

3Reliability

If registration processes are required for secure transactions, then reliability is improved, but ease of operation deteriorates due to multi-step procedures

Engineering Contradiction:
Improvesecurity of transaction systemVSAvoidspontaneity of purchase decisions
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent performs the security setup (registration and token generation) as a preliminary action during the first transaction. Once the token is established on the mobile device, subsequent transactions can proceed spontaneously without requiring repeated registration or complex authentication steps. The preliminary security setup enables fast, spontaneous repeat ordering while maintaining reliability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10937074B2Securing mobile transactions
Publication Date: 2021.03.02 BLAZER & FLIP FLOPS INC DBA THE EXPERIENCE ENGINE
  • US10937074B2 patent drawing
  • US10937074B2 patent drawing
  • US10937074B2 patent drawing

AI summary

Systems and methods for securing mobile transactions are provided. An order including a credit card number and a user is sent from the user's mobile device over a communication network to a gateway server, which may be coupled to a point-of-sale terminal. The gateway server generates an encryption key that is based on the user key and a server key stored at the server. The encryption key is used to encrypt the credit card number, and the encrypted credit card number is sent to the mobile device for use in subsequent orders.