PAN Length Issuer Identifier for Payment Tokenization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing payment systems face limitations in generating a large number of tokens and ensuring enhanced security for payment account numbers, particularly in digital wallet transactions, while also lacking effective reporting and tracking capabilities for account holders.
Innovation Solution
Implementing a system where a PAN-length issuer identifier is used in place of account information, dynamically derived and encrypted, allowing for sub-account selection and enhanced security through tokenization, with the payment-enabled mobile device processing transaction data to create a modified transaction authorization request message that includes an encrypted, transformed token and device identifier.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional payment account numbers (PANs) are used in digital wallet transactions, then transaction processing is straightforward, but security is compromised and the number of generatable tokens is limited
Solution Approach 1:
The payment account number is segmented into two parts: a PAN-length issuer identifier (containing only issuer information) and a separate account identifier. This segmentation allows the issuer identifier to be used for routing and identification while the account identifier handles specific account transactions, thereby enhancing security by not exposing the full PAN in digital wallets while maintaining straightforward processing through the issuer identifier.
Solution Approach 2:
The account-identifying information is extracted from the traditional PAN structure, leaving only the issuer identifier in the PAN-length format. This extraction removes sensitive account-specific data from the tokenized credential while retaining the necessary issuer identification for transaction routing, thus improving security without significantly increasing processing complexity.
2Reliability
If payment tokens are substituted for PANs in digital wallets, then security is enhanced, but the number of tokens that can be generated is constrained
Solution Approach 1:
The PAN-length issuer identifier serves multiple functions: it identifies the account issuer for routing purposes, maintains the expected format for system compatibility, and enables the generation of multiple account-specific identifiers. This multi-functionality allows numerous tokens to be generated under a single issuer identifier, removing the constraint on token quantity while maintaining security enhancements.
Solution Approach 2:
The system transitions from a single-dimension token structure (where each token must be a complete PAN) to a two-dimension structure separating issuer identification from account identification. This dimensional change allows multiple account identifiers to be generated under one issuer identifier, effectively increasing the number of usable tokens without compromising security.
3Loss of information
If full payment account numbers are transmitted in transactions, then complete account information is available for reporting, but security exposure increases
Solution Approach 1:
Account-identifying information is extracted from the full PAN and placed in a separate data field, while only the PAN-length issuer identifier (containing no account-specific information) is transmitted in the account number data field. This extraction maintains transaction reporting capability through the separate account identifier while eliminating security exposure by not transmitting the full PAN.
Solution Approach 2:
The system introduces an intermediary mechanism where the account identifier serves as a mediator between the need for reporting complete account information and the need for security. The account identifier provides full reporting capability to authorized parties while the issuer identifier provides security by not exposing account-specific data in transmission.
Data Source
AI summary
Transaction data is obtained relating to a current purchase transaction. An account indicator is retrieved. The transaction data is used to transform the account indicator. The transformed account indicator is encrypted to generate an encrypted account indicator.


