Payment Network Referents for PCI-Compliant Sensitive Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Financial technology companies face the challenge of achieving Payment Card Industry Data Security Standard (PCI DSS) compliance by obfuscating sensitive information such as Primary Account Information (PAI) and Personally Identifiable Information (PII) before use or storage, which is complex and costly to develop in-house.
Innovation Solution
A solution that obfuscates PAI and PII at the payment network level, generating non-payment referents like PAN references, ensuring compliance without requiring issuers to develop their own complex solutions, thereby reducing fraud risk.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If financial technology companies develop in-house solutions to obfuscate sensitive data before use or storage, then PCI DSS compliance can be achieved, but the complexity and cost of development increase significantly
Solution Approach 1:
The patent introduces a payment network as an intermediary between the issuer and the system requiring payment data. The payment network receives sensitive payment data from the issuer, obfuscates it by generating non-payment referents (such as PAN references), and forwards only the obfuscated data to the acquirer. This intermediary approach eliminates the need for the acquirer or merchant to implement complex obfuscation solutions in-house, as the payment network centralizes the compliance functionality.
2Object-affected harmful factors
If financial technology companies implement comprehensive data obfuscation systems, then security against fraudulent transactions is enhanced, but the cost of implementation increases
Solution Approach 1:
The payment network serves as a mediator that centralizes the obfuscation functionality, allowing acquirers and merchants to benefit from enhanced security without bearing the full implementation cost. The payment network infrastructure is already in place and can be leveraged to provide obfuscation services to multiple participants simultaneously, distributing the cost across the entire payment ecosystem rather than requiring each entity to independently implement expensive security solutions.
Solution Approach 2:
The payment network implements a universal obfuscation mechanism that serves multiple functions: it obfuscates Primary Account Information (PAI), protects Personally Identifiable Information (PII), enables PCI DSS compliance, and reduces fraud risk. This single multi-functional solution replaces what would otherwise require separate systems for each security and compliance requirement, reducing overall implementation cost.
3Ease of operation
If sensitive payment data is transmitted in plain form for authorization, then transaction processing is simplified, but exposure to fraud and data breaches increases
Solution Approach 1:
The payment network acts as an intermediary that transparently handles the obfuscation process. The acquirer sends authorization requests with obfuscated data (non-payment referents) without needing to implement complex obfuscation logic, while the payment network automatically resolves these referents to the original payment data for authorization processing. This maintains operational simplicity for the acquirer while ensuring data protection during transmission.
Solution Approach 2:
The system creates non-payment referents (such as PAN references) that are copies or representations of the actual payment data. These referents contain sufficient information to identify and process the transaction but do not reveal the sensitive original data. The payment network maintains the ability to resolve these copies back to the original data when necessary for authorization, balancing security with processing efficiency.
Data Source
AI summary
A computer-implemented method for generating a non-payment referent associated with payment data related to a payment account is disclosed. The computer-implemented method includes receiving, by a payment network, a message from an issuer, wherein the message includes payment data relating to a payment account, wherein the payment data is used as a payment instrument; generating, by the payment network, a non-payment referent associated with the payment data based on the payment network receiving the payment data for a first time, wherein the non-payment referent is not a payment instrument; and sending, by the payment network, a correlation message to the issuer, wherein the correlation message includes the payment data and the non-payment referent, and wherein the correlation message is configured to inform the issuer that the non-payment referent is associated with the payment data.


