Mobile Transaction Security via Gateway Tokenization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile transaction systems are insecure, cumbersome, and lack integration with existing equipment, leading to issues such as data breaches, excessive registration processes, and inadequate protection of credit card information, which discourages spontaneous and secure transactions.
Innovation Solution
A system where a credit card number and user-selected key are encrypted on a gateway server, with the encrypted credit card number stored on the mobile device for subsequent orders, ensuring secure transactions without storing sensitive data on the server or point-of-sale terminal, using a user key for verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If credit card data is stored on merchant servers for convenient repeat ordering, then ease of operation is improved, but security and reliability deteriorate due to data breaches and PCI DSS compliance burden
Solution Approach 1:
The patent extracts the credit card data from the merchant's environment entirely. Instead of storing card data on merchant servers, the system uses tokenization where only a token (not the actual card data) is stored on the mobile device. The real card data remains exclusively in the payment processor's secure environment, eliminating the security vulnerability of storing sensitive data on merchant systems while still enabling convenient repeat ordering through the stored token.
Solution Approach 2:
The patent introduces a token as an intermediary between the mobile device and the payment processor. This token serves as a secure reference that allows repeat transactions without exposing actual card data. The token acts as a mediator that enables convenient ordering while maintaining security, as it cannot be used outside the specific mobile device and application context.
2Reliability
If tokenization is implemented with a centralized payment processor, then security is improved, but adaptability deteriorates because point-of-sale systems cannot accept universal tokens
Solution Approach 1:
The patent segments the payment system into distinct components: the mobile device application handles token storage and presentation, the point-of-sale terminal handles order processing, and the payment processor handles actual payment authorization. This segmentation allows each component to perform its specific function without requiring the point-of-sale system to understand or store sensitive card data, maintaining compatibility with existing equipment while improving security.
Solution Approach 2:
The patent creates a functional copy of the card data in the form of a token that can be stored on the mobile device. This token is a simplified representation that contains all necessary information for payment authorization without being the actual card data. The token can be presented to multiple different point-of-sale systems, providing universality without compromising security or requiring changes to existing equipment.
3Reliability
If registration processes are required for secure transactions, then reliability is improved, but ease of operation deteriorates due to multi-step procedures
Solution Approach 1:
The patent performs the security setup (registration and token generation) as a preliminary action during the first transaction. Once the token is established on the mobile device, subsequent transactions can proceed spontaneously without requiring repeated registration or complex authentication steps. The preliminary security setup enables fast, spontaneous repeat ordering while maintaining reliability.
Data Source
AI summary
Systems and methods for securing mobile transactions are provided. An order including a credit card number and a user is sent from the user's mobile device over a communication network to a gateway server, which may be coupled to a point-of-sale terminal. The gateway server generates an encryption key that is based on the user key and a server key stored at the server. The encryption key is used to encrypt the credit card number, and the encrypted credit card number is sent to the mobile device for use in subsequent orders.


