Secure Detokenization System for Account Number Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for secure data protection, such as U.S. Pat. No. 7,451,481, cannot facilitate access to the original account number when needed, despite encrypting data to prevent misuse, as they lack a method to securely retrieve and display the account number in situations like charge disputes.

Innovation Solution

A system comprising a token retriever and detokenization system, which verifies authorized requests, transmits and decrypts tokens to reveal account numbers for a limited time, incorporating security measures like access device authentication, limit systems, and token validation to prevent unauthorized access and malware threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is encrypted to protect secure data from misuse, then data security is improved, but access to the original account number is prevented even when needed for legitimate purposes like charge disputes

Engineering Contradiction:
Improvedata securityVSAvoidaccess to account number
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a detokenization system as an intermediary component between the tokenized data storage and systems needing access to account numbers. This mediator verifies authorization requests, validates tokens, and selectively converts tokens back to account numbers only for authorized purposes, thus maintaining security while enabling legitimate access when needed.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the state of account number data by transforming it into tokenized form for storage and transmission, then selectively converting it back to the original form when authorization is verified. This parameter change (tokenized ↔ original) allows the system to maintain security during normal operations while enabling access under controlled conditions.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If account numbers are stored and transmitted securely, then data protection is improved, but the system becomes vulnerable to malware threats and unauthorized access

Engineering Contradiction:
Improvedata protectionVSAvoidmalware threats
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive account number data from systems that are vulnerable to malware and stores it in tokenized form in a secure detokenization system. The tokenized data can be used in transactions without exposing the actual account numbers to potentially compromised systems, thereby removing the vulnerability while maintaining functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments the account number into a token (public identifier) and secure storage (private mapping). The token can be freely transmitted and used in transactions, while the actual account number remains segmented off in secure storage, accessible only through verified authorization processes. This segmentation isolates the sensitive data from malware threats.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If tokens are converted back to account numbers for display, then usability is improved, but the risk of data exposure increases

Engineering Contradiction:
ImproveusabilityVSAvoiddata exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The detokenization system implements periodic action by converting tokens to account numbers only when specifically requested and authorized, rather than continuously displaying or storing them. The account numbers are generated on-demand for specific authorized operations and then discarded, minimizing the time window for potential exposure while maintaining usability when needed.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

Instead of displaying or storing the original account number, the system creates and uses a copy in the form of a token for all non-sensitive operations. The token is a functional copy that can be transmitted and processed, but it contains no sensitive information. The original account number is only reconstructed temporarily when absolutely necessary and authorized.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20240152895A1System and method for secure detokenization
Publication Date: 2024.05.09 MERCHANT LINK LLC
  • US20240152895A1 patent drawing

AI summary

A system for accessing protected data comprising a token retriever system operating on a processor and configured to receive a token from a user and to transmit a request including the token to a detokenization system over a data communications medium. The detokenization system configured to receive the token, to verify that the request has been received from an authorized source, and to transmit a response to the request that includes an account number associated with the token. The token retriever system is configured to receive the account number and to display the account number for a predetermined period of time.