Secure Detokenization System for Account Number Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for secure data protection, such as U.S. Pat. No. 7,451,481, cannot facilitate access to the original account number when needed, despite encrypting data to prevent misuse, as they lack a method to securely retrieve and display the account number in situations like charge disputes.
Innovation Solution
A system comprising a token retriever and detokenization system, which verifies authorized requests, transmits and decrypts tokens to reveal account numbers for a limited time, incorporating security measures like access device authentication, limit systems, and token validation to prevent unauthorized access and malware threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is encrypted to protect secure data from misuse, then data security is improved, but access to the original account number is prevented even when needed for legitimate purposes like charge disputes
Solution Approach 1:
The patent introduces a detokenization system as an intermediary component between the tokenized data storage and systems needing access to account numbers. This mediator verifies authorization requests, validates tokens, and selectively converts tokens back to account numbers only for authorized purposes, thus maintaining security while enabling legitimate access when needed.
Solution Approach 2:
The system changes the state of account number data by transforming it into tokenized form for storage and transmission, then selectively converting it back to the original form when authorization is verified. This parameter change (tokenized ↔ original) allows the system to maintain security during normal operations while enabling access under controlled conditions.
2Reliability
If account numbers are stored and transmitted securely, then data protection is improved, but the system becomes vulnerable to malware threats and unauthorized access
Solution Approach 1:
The patent extracts the sensitive account number data from systems that are vulnerable to malware and stores it in tokenized form in a secure detokenization system. The tokenized data can be used in transactions without exposing the actual account numbers to potentially compromised systems, thereby removing the vulnerability while maintaining functionality.
Solution Approach 2:
The system segments the account number into a token (public identifier) and secure storage (private mapping). The token can be freely transmitted and used in transactions, while the actual account number remains segmented off in secure storage, accessible only through verified authorization processes. This segmentation isolates the sensitive data from malware threats.
3Ease of operation
If tokens are converted back to account numbers for display, then usability is improved, but the risk of data exposure increases
Solution Approach 1:
The detokenization system implements periodic action by converting tokens to account numbers only when specifically requested and authorized, rather than continuously displaying or storing them. The account numbers are generated on-demand for specific authorized operations and then discarded, minimizing the time window for potential exposure while maintaining usability when needed.
Solution Approach 2:
Instead of displaying or storing the original account number, the system creates and uses a copy in the form of a token for all non-sensitive operations. The token is a functional copy that can be transmitted and processed, but it contains no sensitive information. The original account number is only reconstructed temporarily when absolutely necessary and authorized.
Data Source
AI summary
A system for accessing protected data comprising a token retriever system operating on a processor and configured to receive a token from a user and to transmit a request including the token to a detokenization system over a data communications medium. The detokenization system configured to receive the token, to verify that the request has been received from an authorized source, and to transmit a response to the request that includes an account number associated with the token. The token retriever system is configured to receive the account number and to display the account number for a predetermined period of time.
