Multi-Party Cryptogram Generation for Secure Digital Token Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing tokenization processes are vulnerable to computing attacks due to the single creation and transmission of cryptograms, which can compromise sensitive data during multi-party transactions.

Innovation Solution

A multi-party cryptogram generation scheme where each participant is assigned alphanumeric characters based on a risk assessment, with a transaction processor coordinating the generation and updating of the cryptogram across participants using a data table, ensuring secure communication and decentralized generation through smart contracts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single party creates and transmits the cryptogram, then the process is simple and fast, but the security is compromised and sensitive data is exposed to attacks

Engineering Contradiction:
Improvecryptogram securityVSAvoidcryptogram generation process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cryptogram generation process is segmented into multiple independent contributions from different parties. Each party generates a portion of the cryptogram based on their own data, and these portions are combined to form the complete cryptogram. This segmentation distributes the security responsibility and prevents any single point of failure or compromise.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A transaction processor acts as an intermediary to coordinate the multi-party cryptogram generation. The processor collects contributions from various parties, combines them according to a determination scheme, and ensures proper integration. This intermediary manages the complexity while maintaining security through controlled coordination.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple parties contribute to cryptogram generation, then security is enhanced through distribution, but the process complexity and coordination requirements increase

Engineering Contradiction:
Improvedata securityVSAvoidcryptogram generation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by establishing a cryptogram determination scheme before the actual cryptogram generation. This scheme pre-defines how contributions from multiple parties will be combined, what data each party should provide, and the integration methodology. This preparation reduces coordination overhead during the actual generation process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Each party in the multi-party system independently generates their own cryptogram contribution based on their local data and the predetermined determination scheme. This self-service approach eliminates the need for complex real-time coordination and communication protocols, reducing time loss while maintaining security through distributed generation.

Inventive Principle:
Principle #25Self-service

3Ease of manufacture

If a single entity controls cryptogram creation, then the process is straightforward to implement, but vulnerability to malicious attacks increases

Engineering Contradiction:
Improveimplementation simplicityVSAvoidcomputing attacks
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The implementation is segmented so that no single entity has complete control over cryptogram creation. Each party implements a portion of the generation process using their own data, and the segments are combined through a predetermined scheme. This segmentation inherently reduces vulnerability to attacks targeting any single implementation point.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each party contributes local quality to the cryptogram based on their specific data and security requirements. The determination scheme integrates these local qualities while maintaining overall security. This approach allows customization at each location while preserving implementation simplicity through a standardized integration framework.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11799638B2Shared cryptogram generation during multi-party digital token processing
Publication Date: 2023.10.24 PAYPAL INC
  • US11799638B2 patent drawing
  • US11799638B2 patent drawing
  • US11799638B2 patent drawing

AI summary

There are provided systems and methods for shared cryptogram generation during multi-party digital token processing. A service provider, such as an electronic transaction processor for digital transactions, may require tokenized data in order to protect sensitive or secure data, such as payment card data during electronic transaction processing. In this regard, the service provider may tokenize the data, which may require a cryptogram for validation of a corresponding digital token. The cryptogram may be generated based on input from multiple participants to the transaction, where a length of the cryptogram may be determined based on a risk score for the transaction. Each transaction participant may be assigned one or more slots or values in the cryptogram to provide based on the risk score and other rules for cryptogram generation. Each participant may provide corresponding portions, where the service provider may generate and backwards update the participants of the cryptogram.