Secure Mobile Transaction Tokenization via Issuer-Acquirer Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile transaction systems expose customers' payment information to merchants, increasing the risk of data breaches and burdening merchants with payment card industry (PCI) compliance requirements, while lacking robust authentication and validation mechanisms.

Innovation Solution

A secure mobile transaction system involving an acquirer and issuer portion, both associated with or under the control of a financial institution, uses a mobile electronic device to authenticate customers, generate a transaction session identifier, and validate location information, ensuring that payment device information is not shared with merchants, thereby maintaining data security and reducing PCI burdens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If customer payment information is shared with merchants for transaction processing, then transaction functionality is enabled, but data security risk increases and PCI compliance burden increases

Engineering Contradiction:
Improvetransaction functionalityVSAvoiddata security risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a tokenization intermediary that replaces sensitive payment information with non-sensitive tokens. The tokenization service acts as a mediator between the customer's payment data and the merchant's processing systems, allowing transactions to proceed while preventing exposure of actual payment information. This resolves the contradiction by enabling transaction functionality through tokens while eliminating data security risks associated with sharing real payment data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts sensitive payment information from the transaction flow by separating it into a dedicated tokenization process. The actual payment data is extracted and stored securely in a token vault, while only token representations are included in merchant transactions. This extraction eliminates the security risk of sharing payment information while preserving transaction functionality through the token mechanism.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If customer payment information is shared with merchants for transaction processing, then transaction functionality is enabled, but PCI compliance burden increases

Engineering Contradiction:
Improvetransaction functionalityVSAvoidPCI compliance burden
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts payment information handling from the merchant's scope by implementing tokenization. The merchant no longer touches or processes actual payment data, extracting the compliance burden from their system. Only non-sensitive tokens are handled by the merchant, eliminating PCI DSS compliance requirements while maintaining full transaction functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The tokenization service serves as an intermediary that absorbs the PCI compliance complexity. By placing the tokenization layer between the customer's payment data and the merchant's systems, the patent transfers the compliance burden to the tokenization provider rather than the merchant, simplifying the merchant's compliance requirements while preserving transaction capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication and location validation mechanisms are implemented, then transaction security is improved, but system complexity increases

Engineering Contradiction:
Improvetransaction securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary authentication and location validation before the actual transaction occurs. The system pre-verifies the customer's identity and device location, establishing security credentials in advance. This preliminary action ensures transaction security is built-in from the start rather than added as a complex post-processing layer, reducing overall system complexity while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables the mobile device to self-verify its location and authentication status using built-in sensors and stored credentials. The device autonomously performs location validation and authentication checks without requiring complex external verification systems. This self-service approach enhances transaction security while minimizing system complexity by leveraging the device's own capabilities.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10970721B2Systems and methods for secure mobile transactions
Publication Date: 2021.04.06 JPMORGAN CHASE BANK NA
  • US10970721B2 patent drawing
  • US10970721B2 patent drawing
  • US10970721B2 patent drawing

AI summary

Systems and methods for secure mobile transactions are disclosed. A method for conducting a transaction may include an issuer receiving, over a first network and from a customer mobile device, authentication information and mobile device location information; the issuer authenticating the customer, generating a transaction session identifier, and communicating the transaction session identifier to the mobile device over the first network; the issuer communicating, over a second network, the transaction session identifier and payment device information to an acquirer; the acquirer receiving, from the merchant, the transaction session identifier from the computer application, location information a merchant point of transaction, and transaction information; the acquirer generating a transaction authorization request including payment device information and the transaction information and communicating the request to the issuer portion over the second network; and the issuer authorizing the transaction authorization request. The issuer and acquirer may be under common control.