Payment Token Security via Disposable Image Codes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional financial transaction methods, especially in brick-and-mortar locations, often require users to share sensitive information and can be vulnerable to misuse due to the need for specialized hardware and time-consuming processes, particularly with mobile payments.
Innovation Solution
The implementation of payment tokens, which are unique one-time use identifiers linked to payment accounts, that include an expiration time and conditions of use, allowing users to securely conduct transactions by generating an image code for redemption, thereby limiting exposure of sensitive information and preventing misuse if the device is lost.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional mobile payment methods are used, then financial transactions can be conducted electronically, but sensitive payment information is exposed and vulnerable to misuse
Solution Approach 1:
The patent extracts sensitive payment information from the transaction process by introducing payment tokens as substitutes. The tokens contain no sensitive data but can be redeemed for payment, effectively separating the payment function from sensitive information exposure.
Solution Approach 2:
The patent implements single-use payment tokens that expire after one redemption or upon expiration. These disposable tokens eliminate the risk of repeated unauthorized use, as each token can only be redeemed once, making the system secure even if tokens are intercepted.
2Productivity
If payment cards or electronic transfers are used, then financial transactions can be processed, but the process becomes time-consuming and requires specialized hardware
Solution Approach 1:
The patent replaces physical payment cards and specialized payment hardware with digital tokens that can be transmitted through standard communication channels. This substitution eliminates the need for card readers, magnetic stripe readers, or other specialized payment terminals.
Solution Approach 2:
The payment tokens can be transmitted through multiple channels including SMS, email, or other electronic messaging systems, making the payment system universally compatible with existing communication infrastructure rather than requiring dedicated payment hardware.
3Ease of operation
If payment information is stored on mobile phone, then convenient access is provided, but misuse risk increases when device is lost or misplaced
Solution Approach 1:
The patent generates new payment tokens that are valid for only one transaction or a limited time period. Even if a device is lost, the attacker cannot reuse the tokens, and the user can generate new tokens immediately, maintaining accessibility while minimizing vulnerability.
Solution Approach 2:
The system allows users to pre-generate payment tokens before transactions occur. These tokens can be stored securely and used when needed, providing convenient access while the underlying sensitive information remains protected on the server side rather than on the mobile device.
Data Source
AI summary
A user may request a payment token from a host. The payment token may be a unique one-time use identifier linked to one or more payment accounts associated with the user. The payment token may be subject to conditions of use. To redeem the payment token, the user device may generate an image code to visually present the payment token for access by a recipient's camera. The recipient may then record the image code. The user may also provide a security identifier to the recipient. The recipient may then transmit the image code and the security identifier to the host as a payment request. The host may verify the payment request and verify compliance with any associated conditions. When the payment token is valid, funds are available, and the conditions are satisfied, then the host may transfer the funds to an account of the recipient.


