Multi-Party Cryptogram Generation for Secure Digital Token Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing tokenization processes are vulnerable to computing attacks due to the single creation and transmission of cryptograms, which can compromise sensitive data during multi-party transactions.
Innovation Solution
A multi-party cryptogram generation scheme where each participant is assigned alphanumeric characters based on a risk assessment, with a transaction processor coordinating the generation and updating of the cryptogram across participants using a data table, ensuring secure communication and decentralized generation through smart contracts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single party creates and transmits the cryptogram, then the process is simple and fast, but the security is compromised and sensitive data is exposed to attacks
Solution Approach 1:
The cryptogram generation process is segmented into multiple independent contributions from different parties. Each party generates a portion of the cryptogram based on their own data, and these portions are combined to form the complete cryptogram. This segmentation distributes the security responsibility and prevents any single point of failure or compromise.
Solution Approach 2:
A transaction processor acts as an intermediary to coordinate the multi-party cryptogram generation. The processor collects contributions from various parties, combines them according to a determination scheme, and ensures proper integration. This intermediary manages the complexity while maintaining security through controlled coordination.
2Reliability
If multiple parties contribute to cryptogram generation, then security is enhanced through distribution, but the process complexity and coordination requirements increase
Solution Approach 1:
The system performs preliminary actions by establishing a cryptogram determination scheme before the actual cryptogram generation. This scheme pre-defines how contributions from multiple parties will be combined, what data each party should provide, and the integration methodology. This preparation reduces coordination overhead during the actual generation process.
Solution Approach 2:
Each party in the multi-party system independently generates their own cryptogram contribution based on their local data and the predetermined determination scheme. This self-service approach eliminates the need for complex real-time coordination and communication protocols, reducing time loss while maintaining security through distributed generation.
3Ease of manufacture
If a single entity controls cryptogram creation, then the process is straightforward to implement, but vulnerability to malicious attacks increases
Solution Approach 1:
The implementation is segmented so that no single entity has complete control over cryptogram creation. Each party implements a portion of the generation process using their own data, and the segments are combined through a predetermined scheme. This segmentation inherently reduces vulnerability to attacks targeting any single implementation point.
Solution Approach 2:
Each party contributes local quality to the cryptogram based on their specific data and security requirements. The determination scheme integrates these local qualities while maintaining overall security. This approach allows customization at each location while preserving implementation simplicity through a standardized integration framework.
Data Source
AI summary
There are provided systems and methods for shared cryptogram generation during multi-party digital token processing. A service provider, such as an electronic transaction processor for digital transactions, may require tokenized data in order to protect sensitive or secure data, such as payment card data during electronic transaction processing. In this regard, the service provider may tokenize the data, which may require a cryptogram for validation of a corresponding digital token. The cryptogram may be generated based on input from multiple participants to the transaction, where a length of the cryptogram may be determined based on a risk score for the transaction. Each transaction participant may be assigned one or more slots or values in the cryptogram to provide based on the risk score and other rules for cryptogram generation. Each participant may provide corresponding portions, where the service provider may generate and backwards update the participants of the cryptogram.


