Non-EMV Tokenization for PCI DSS Compliant Transaction Flows
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems handling PCI DSS compliant transaction flows face risks due to the exposure of sensitive payment card information, particularly within the payment processor and issuing bank, as existing solutions like EMV tokens do not adequately secure data across the entire transaction process.
Innovation Solution
Implementing non-EMV tokens that translate payment card numbers (PAN) into secure tokens, maintaining a one-to-one correspondence while preserving bank identification number (BIN) processing, and using tokenization systems like Token Vault for secure storage and processing, ensuring only tokens flow through banking systems to reduce risk and maintain compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If EMV tokens are used for payment card transactions, then card payment security is improved, but data exposure risk remains within payment processor and issuing bank systems
Solution Approach 1:
The patent introduces a tokenization system as an intermediary between the payment processor and issuing bank. This system replaces sensitive PAN data with tokens during transmission and storage, while maintaining a secure mapping between tokens and actual card numbers. The tokenization intermediary prevents direct exposure of PAN data within banking systems, addressing the data exposure risk while preserving EMV token security benefits.
Solution Approach 2:
The patent segments the payment data flow into distinct tokenized and non-tokenized portions. Sensitive PAN data is separated from transaction processing flows and stored only in secure token vaults. Transaction systems process only tokenized representations, creating segmentation that limits the exposure surface area and contains potential security breaches to specific segments rather than entire systems.
2Ease of operation
If full PAN data is transmitted through banking systems, then complete payment information is available for processing, but PCI DSS compliance difficulty increases
Solution Approach 1:
The patent creates secure token copies of PAN data that preserve necessary payment information while removing sensitive elements. These token copies enable complete payment processing functionality without requiring systems to handle actual PAN data. The token vault maintains the master copy mapping, allowing detokenization only when absolutely necessary and under strict security controls, thereby simplifying PCI DSS compliance while maintaining operational completeness.
3Object-affected harmful factors
If tokenization is implemented across all transaction flows, then data security is enhanced, but system complexity increases
Solution Approach 1:
The patent implements a universal tokenization framework that serves multiple functions: data masking during transmission, secure storage replacement, transaction processing enablement, and compliance facilitation. This multi-functional approach consolidates what could be multiple separate security systems into a single tokenization infrastructure, reducing overall system complexity while enhancing data security across all transaction flows.
Data Source
AI summary
A payment processor or network receives an incoming PAN pursuant to a payment card transaction between a merchant and a customer and translates the PAN into a token having a token value for N digits within a middle portion of the PAN, while preserving a PAN value for M digits within a terminal portion of the PAN. Pursuant to generation of the token, the payment processor or network performs BIN substitution on the PAN to replace the BIN within the PAN with a different BIN. The payment processor or network sends the token downstream for downstream processing of the transaction. Upon completion of downstream processing, the payment processor or network translates the token back into a PAN for any further processing of the transaction upstream.


