Secure Payment Data Access via Unique URL and Step-Up Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing systems for secure payment device data storage and access involve multiple entities, increasing the risk of insecurity and the need for additional resources to comply with standards like PCI DSS, necessitating a solution that reduces the number of entities handling sensitive information while ensuring security.

Innovation Solution

A method and system that generates a unique URL for payment device data, allowing secure access through a separate communication channel, with step-up authentication and tokenization to minimize exposure and resource requirements, using a remote access system for consolidated storage and encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple entities store and communicate payment device data, then data accessibility and functionality are improved, but security risk and compliance burden increase

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts sensitive payment device data from multiple communicating entities and stores it in a single secure remote location. Only tokenized references remain at the application provider, eliminating the need for multiple entities to possess actual card data while maintaining data accessibility through secure remote retrieval.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a remote access system as an intermediary that hosts the secure data storage environment. This mediator allows the application provider to access payment device data without directly storing or handling sensitive information, thereby maintaining functionality while reducing security risk at the application provider level.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple entities handle payment device data, then system functionality is improved, but resource requirements for security compliance increase

Engineering Contradiction:
Improvesystem functionalityVSAvoidresource requirements
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent removes the burden of PCI DSS compliance resources from the application provider by extracting actual payment device data storage away from the application provider's environment. The application provider only handles tokenized data, significantly reducing their security resource requirements while maintaining system functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The remote access system acts as a mediator that assumes the security compliance burden, allowing the application provider to maintain full functionality without investing heavily in security infrastructure. The intermediary handles the resource-intensive security requirements centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If payment device data is stored locally at the application provider, then data access speed is improved, but security exposure and compliance burden increase

Engineering Contradiction:
Improvedata access speedVSAvoidsecurity exposure
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent extracts payment device data from local application provider storage and relocates it to a secure remote environment. Access speed is maintained through optimized remote retrieval mechanisms, while security exposure is dramatically reduced by eliminating local storage of sensitive data at the application provider.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11922407B2System, method, and computer program product for secure payment device data storage and access
Publication Date: 2024.03.05 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11922407B2 patent drawing
  • US11922407B2 patent drawing
  • US11922407B2 patent drawing

AI summary

Provided are a system, method, and computer program product for secure payment device data storage and access. The method includes storing payment device data associated with a payment device of a user and generating a unique uniform resource locator (URL) associated with the payment device. The method also includes transmitting the unique URL to an application provider system through a first communication channel and receiving a data access request from the client device via the unique URL through a second communication channel separate from the first communication channel. The method further includes, in response to receiving the data access request, verifying an identity of the user by executing a step-up authentication protocol. The method further includes, in response to verifying the identity of the user, transmitting a data access response including the payment device data to the client device through the second communication channel.