Payment Tokenization for Secure Transaction Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securing payment card data, such as PCI DSS compliance, are resource-intensive and fail to adequately protect sensitive information from theft, with key management being a significant oversight in encryption solutions, leading to ongoing costs and breaches despite efforts.

Innovation Solution

Implementing tokenization processes where payment processors encrypt and replace sensitive payment card data with tokens, which are stored securely, eliminating the need for merchants to maintain sensitive financial data and reducing the risk of data compromise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If merchants implement PCI DSS compliance and encryption solutions to protect cardholder data, then data security is improved, but resource costs and operational complexity increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts sensitive cardholder data from the merchant's environment entirely. By using tokenization, the actual card data is removed and replaced with non-sensitive tokens, eliminating the need for merchants to maintain encryption systems and key management infrastructure while preserving security functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a payment processor as an intermediary between the merchant and cardholder data. The processor handles all encryption, decryption, and key management operations, allowing the merchant to interact only with tokens rather than sensitive data, thus reducing the merchant's security burden.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If merchants store encrypted card data locally for transaction processing, then transaction speed is improved, but the risk of key compromise and data breach increases

Engineering Contradiction:
Improvetransaction processing speedVSAvoiddata breach risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent uses tokens as disposable substitutes for sensitive card data. These tokens are non-sensitive, can be freely stored locally by merchants, and have no value if compromised since they cannot be used for fraudulent transactions. The actual card data never resides in the merchant's environment.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If merchants maintain encryption keys and secure storage infrastructure, then data protection capability is improved, but ongoing operational costs and compliance burden increase

Engineering Contradiction:
Improvedata protection capabilityVSAvoidoperational costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent enables the payment processor to self-manage all encryption and key management operations without requiring merchant involvement. The processor automatically handles key generation, storage, rotation, and compromise response, eliminating the need for merchants to invest in ongoing security operations and compliance maintenance.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8788429B2Secure transaction management
Publication Date: 2014.07.22 FIRST DATA CORP
  • US8788429B2 patent drawing
  • US8788429B2 patent drawing
  • US8788429B2 patent drawing

AI summary

Methods, systems, and devices for secure transaction management are provided. Embodiments include a method for providing secure transactions that include receiving an identifier of a financial account at a payment processor system. A token may be generated that is linked with the identifier of the financial account at the payment processor system. The identifier of the financial account and the token may be stored securely at the payment processor system. The token may be transmitted without the identifier of the financial account to at least a recipient system or a recipient device where the token replaces the identifier of the financial account.