Secure Mobile Transaction Tokenization via Issuer-Acquirer Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile transaction systems expose customers' payment information to merchants, increasing the risk of data breaches and burdening merchants with payment card industry (PCI) compliance requirements, while lacking robust authentication and validation mechanisms.
Innovation Solution
A secure mobile transaction system involving an acquirer and issuer portion, both associated with or under the control of a financial institution, uses a mobile electronic device to authenticate customers, generate a transaction session identifier, and validate location information, ensuring that payment device information is not shared with merchants, thereby maintaining data security and reducing PCI burdens.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If customer payment information is shared with merchants for transaction processing, then transaction functionality is enabled, but data security risk increases and PCI compliance burden increases
Solution Approach 1:
The patent introduces a tokenization intermediary that replaces sensitive payment information with non-sensitive tokens. The tokenization service acts as a mediator between the customer's payment data and the merchant's processing systems, allowing transactions to proceed while preventing exposure of actual payment information. This resolves the contradiction by enabling transaction functionality through tokens while eliminating data security risks associated with sharing real payment data.
Solution Approach 2:
The patent extracts sensitive payment information from the transaction flow by separating it into a dedicated tokenization process. The actual payment data is extracted and stored securely in a token vault, while only token representations are included in merchant transactions. This extraction eliminates the security risk of sharing payment information while preserving transaction functionality through the token mechanism.
2Ease of operation
If customer payment information is shared with merchants for transaction processing, then transaction functionality is enabled, but PCI compliance burden increases
Solution Approach 1:
The patent extracts payment information handling from the merchant's scope by implementing tokenization. The merchant no longer touches or processes actual payment data, extracting the compliance burden from their system. Only non-sensitive tokens are handled by the merchant, eliminating PCI DSS compliance requirements while maintaining full transaction functionality.
Solution Approach 2:
The tokenization service serves as an intermediary that absorbs the PCI compliance complexity. By placing the tokenization layer between the customer's payment data and the merchant's systems, the patent transfers the compliance burden to the tokenization provider rather than the merchant, simplifying the merchant's compliance requirements while preserving transaction capabilities.
3Reliability
If authentication and location validation mechanisms are implemented, then transaction security is improved, but system complexity increases
Solution Approach 1:
The patent implements preliminary authentication and location validation before the actual transaction occurs. The system pre-verifies the customer's identity and device location, establishing security credentials in advance. This preliminary action ensures transaction security is built-in from the start rather than added as a complex post-processing layer, reducing overall system complexity while maintaining high security standards.
Solution Approach 2:
The patent enables the mobile device to self-verify its location and authentication status using built-in sensors and stored credentials. The device autonomously performs location validation and authentication checks without requiring complex external verification systems. This self-service approach enhances transaction security while minimizing system complexity by leveraging the device's own capabilities.
Data Source
AI summary
Systems and methods for secure mobile transactions are disclosed. A method for conducting a transaction may include an issuer receiving, over a first network and from a customer mobile device, authentication information and mobile device location information; the issuer authenticating the customer, generating a transaction session identifier, and communicating the transaction session identifier to the mobile device over the first network; the issuer communicating, over a second network, the transaction session identifier and payment device information to an acquirer; the acquirer receiving, from the merchant, the transaction session identifier from the computer application, location information a merchant point of transaction, and transaction information; the acquirer generating a transaction authorization request including payment device information and the transaction information and communicating the request to the issuer portion over the second network; and the issuer authorizing the transaction authorization request. The issuer and acquirer may be under common control.


