Payment Gateway Tokenization for Secure Transaction Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Credit card information is vulnerable to compromise during electronic transactions, as it is transmitted and handled by merchants, leading to security risks.

Innovation Solution

A payment gateway generates a unique token-ID for each transaction, allowing credit card information to be processed without being transmitted to or through the merchant, ensuring secure handling and storage by using a processor gateway that encrypts and stores sensitive information, enabling secure transactions without exposing cardholder data to merchants.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If credit card information is transmitted through the merchant during electronic transactions, then transaction processing can be completed, but security risks increase and credit card information may be compromised

Engineering Contradiction:
Improvesecurity of credit card informationVSAvoidrisk of data breach
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a payment gateway as an intermediary component that sits between the merchant and the payment processor. The gateway receives credit card information directly from the customer, processes it securely, and communicates only transaction status back to the merchant. This intermediary structure eliminates the need for merchants to handle sensitive credit card data, thereby resolving the security contradiction by maintaining transaction functionality while removing the security vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If merchants handle and store credit card information, then transactions can be processed, but the complexity of security management increases

Engineering Contradiction:
Improvetransaction processing simplicityVSAvoidsecurity management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the security management burden from the merchant system by removing the requirement for merchants to store or process sensitive credit card information. The payment gateway assumes responsibility for secure handling, encryption, and processing of card data. This extraction allows merchants to focus on their core business operations without the complexity of implementing and maintaining security infrastructure, thus resolving the contradiction between operational simplicity and security management complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If credit card information is transmitted to the payment processor through the merchant, then authorization can be obtained, but vulnerability to intentional or unintentional compromise increases

Engineering Contradiction:
Improvetransaction authorizationVSAvoidinformation compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The payment gateway serves as a secure intermediary that establishes direct communication channels between the customer and payment processor, bypassing the merchant's systems for sensitive data transmission. The gateway receives authorization requests with encrypted card information, processes them securely, and returns authorization status to the merchant without exposing card data. This intermediary approach maintains the essential authorization function while eliminating the vulnerability to information compromise during transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8595098B2Transmission of sensitive customer information during electronic-based transactions
Publication Date: 2013.11.26 NETWORK MERCHANTS LLC
  • US8595098B2 patent drawing
  • US8595098B2 patent drawing
  • US8595098B2 patent drawing

AI summary

An exemplary method is implemented by a payment gateway for processing electronic transactions. A token-ID that is unique to each transaction is generated, and on receiving a request to initiate an electronic transaction from a merchant server, a first message is transmitted to the merchant server that includes a first token-ID. A communication is received from an electronic device of a cardholder that contains information about the cardholder's credit card account and the first token-ID. A record is stored that includes the first token-ID and information enabling the credit card account of the cardholder to be identified. On receiving a second request, that includes the first token-ID, from the merchant server for payment of a specified amount, the credit card account of the cardholder to be debited for the requested payment is identified based on the token-ID. A determination is made if the cardholder's credit card account was successfully debited for the requested payment, and a second message is transmitted to the merchant server that specifies if the requested payment transaction was successfully completed.