One-time Transaction Token Payment Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing payment transaction systems are vulnerable to security breaches due to the need to transfer sensitive primary account number (PAN) data across multiple networks and systems, which increases the risk of man-in-the-middle attacks and data breaches.
Innovation Solution
A method for securely processing payment transactions by generating a one-time transaction token within the payment provider system, eliminating the need to transmit PAN data externally, and using a defined validation computation policy to ensure only authorized parties can retrieve and validate the token, thereby minimizing data exposure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PAN data is transferred across multiple networks and systems for tokenisation and transaction processing, then the tokenisation function can be performed, but the security risk increases due to potential man-in-the-middle attacks and data breaches
Solution Approach 1:
The patent extracts the PAN data from the transmission path by performing tokenisation locally within the payment provider system. The PAN is never transmitted across networks - only the generated token is shared with external systems, effectively removing the vulnerable data element from the communication chain.
Solution Approach 2:
The patent introduces a token as an intermediary element that replaces the PAN in all external communications. The token acts as a mediator that preserves the functionality of payment processing while eliminating the need to expose sensitive PAN data across networks and systems.
2Ease of operation
If PAN data is transmitted to external tokenisation services for provisioning tokens, then tokens can be generated and stored in a registry, but the exposure of PAN data increases vulnerability to interception
Solution Approach 1:
The patent merges the tokenisation function into the payment provider system itself, combining the PAN storage, token generation, and token management capabilities into a single secure system. This eliminates the need for external tokenisation services and the associated PAN data transmission.
Solution Approach 2:
The patent extracts the PAN data transmission step from the token provisioning process. By generating tokens internally without external service involvement, the system removes the vulnerable transmission环节 while maintaining complete token provisioning functionality.
3Productivity
If multiple systems (user device, tokenisation service, acquirer bank, issuer bank) have access to PAN data for transaction processing, then the transaction can be completed, but the number of access points increases security vulnerabilities
Solution Approach 1:
The patent extracts PAN data from the transaction processing flow by replacing it with tokens at all external access points. The PAN remains confined to the secure payment provider system, while tokens enable all necessary transaction operations without exposing the sensitive data.
Solution Approach 2:
The patent creates a functional copy of the PAN in the form of a token that can be used for all transaction purposes. This token copy enables transaction processing across multiple systems while the original PAN remains protected and inaccessible to external parties.
Data Source
AI summary
A one-time transaction token is requested by a user from a payment provider system for a payment transaction initiated by the user. The one-time transaction token is stored by the payment provider system. The one-time transaction token is provided to the user, and the user provides the one-time transaction token to a transaction processing system and from there to an acquirer processing system. Based on the one-time transaction token received, the acquirer processing system identifies the payment provider system which generated the one-time transaction token and transmits it to the identified payment provider system. Upon receipt of the one-time transaction token, the identified payment provider system validates the received one-time transaction token with the one-time transaction token previously generated by the identified payment provider system. If validated, the identified payment provider system generates transaction payment data for the user and transmits it to the acquirer processing system to complete the payment transaction.


