POS Security Layer Tokenization for Payment Data Interception
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current payment systems at point-of-sale (POS) terminals are vulnerable to data theft due to insecure transmission and storage of payment data, with intermediaries intercepting sensitive information such as PANs and PINs, leading to fraud and unauthorized transactions.
Innovation Solution
Implementing a POS security layer (PSL) on the terminal and a server security application (SSA) to intercept and encrypt payment data, replacing it with false data for processing, thereby reducing the risk of data breaches and unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If payment data is transmitted and stored at POS terminals for transaction processing, then transaction functionality is enabled, but security vulnerabilities increase due to interception and theft risks
Solution Approach 1:
The patent introduces a payment token as an intermediary that replaces actual payment data during transmission and storage. The token acts as a mediator between the POS terminal and payment processing systems, allowing transactions to proceed without exposing sensitive payment information. The token can be mapped to the actual payment data only when needed for final processing, thereby eliminating the security vulnerability of storing and transmitting raw payment data while maintaining transaction functionality.
2Productivity
If actual payment data is stored at POS terminals for processing transactions, then transaction speed is improved, but the risk of data breaches and unauthorized access increases
Solution Approach 1:
The patent creates a copy of the payment data in the form of a payment token that can be stored and transmitted without containing the actual sensitive information. The token is a functional copy that enables transaction processing at the same speed as actual payment data would, but without the security risks. The mapping between the token and actual payment data is maintained securely, allowing fast processing while minimizing data breach risks.
3Ease of operation
If payment data is intercepted and stored by intermediaries in the transaction chain, then transaction processing is enabled, but fraud and unauthorized use increase
Solution Approach 1:
The patent transforms the form of payment data by changing its parameters - converting sensitive payment information into a tokenized representation. This parameter change maintains the functional properties needed for transaction processing (the token can still be used to identify and charge the correct payment method) while eliminating the harmful properties (the token cannot be used for fraud or unauthorized transactions without the secure mapping key). The transformation occurs at the point of interception, allowing intermediaries to process transactions without accessing actual payment data.
Data Source
AI summary
Payment card transactions at a point of sale (POS) are secured in certain embodiments by intercepting, with a POS security layer installed on a POS terminal, payment data from the POS terminal, transmitting the payment data from the POS security layer to a server security application installed on a POS server, and providing false payment data from the POS security layer to a POS terminal application installed on the POS terminal. The false payment data in various embodiments is processed as if it were the payment data, such that the POS terminal transmits an authorization request to the POS server using the false payment data. In addition, the authorization request may be transmitted from the POS server to a payment gateway.


