Secure Enclave for Pre-funded Payment Token Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for electronic payment transactions lack secure and efficient methods for generating, transferring, and processing pre-funded payment tokens, which are essential for pre-paid and pre-authorized transactions.

Innovation Solution

The development of systems, methods, and machine-interpretable programming for generating, transferring, and processing secure data sets representing pre-funded payment tokens, allowing for secure creation, administration, manipulation, processing, and storage of electronic data for pre-funded payment transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure data sets representing pre-funded payment tokens are generated and transferred between network communication devices, then the security and reliability of electronic payment transactions is improved, but the device complexity and system architecture requirements increase

Engineering Contradiction:
Improvesecurity of electronic payment transactionsVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces secure enclaves as intermediary secure processing environments within network communication devices. These enclaves act as mediators that handle sensitive payment token operations isolated from the main device processor, providing enhanced security without requiring complete system redesign. The enclave serves as a trusted intermediary that manages cryptographic operations and token validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments payment processing functions by separating secure token operations from general device operations. The secure enclave is partitioned as a distinct secure processing unit within the device, allowing payment-related cryptographic operations to be isolated from other device functions. This segmentation enables targeted security enhancements without affecting overall device architecture.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple funding sources are integrated into the payment token system, then the versatility and adaptability of the payment system is improved, but the processing complexity and adjudication requirements increase

Engineering Contradiction:
Improveuse of multiple funding sourcesVSAvoidprocessing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The payment token system is designed with universal adjudication capabilities that can handle multiple funding source types through a unified processing framework. The system can accommodate diverse funding sources (credit, debit, pre-paid, rewards accounts) using the same core token generation and validation mechanisms, enabling multi-functionality without requiring separate processing paths for each funding type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system manages complexity by changing parameters rather than structure - using configurable token parameters to represent different funding source characteristics. The adjudication process adjusts token validation parameters based on the specific funding source type, allowing flexible handling of multiple funding sources through parameter variation rather than structural complexity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If secure enclaves are implemented within network communication devices for token processing, then the security of token storage and processing is improved, but the manufacturing complexity and cost increase

Engineering Contradiction:
Improvesecurity of token storage and processingVSAvoiddevice manufacturing
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The secure enclave is implemented as a nested structure within the network communication device, with the enclave containing its own isolated processing environment. This nesting approach allows the secure processing unit to be integrated within the existing device form factor, embedding security functionality without requiring completely separate hardware components. The enclave can be implemented as a secured region within the device's memory or processing unit.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentEP4102434B1Systems, methods, and devices for secure generation and processing of data sets representing pre-funded payments
Publication Date: 2025.05.28 ROYAL BANK OF CANADA
  • EP4102434B1 patent drawingFigure 1
  • EP4102434B1 patent drawingFigure 2
  • EP4102434B1 patent drawingFigure 3

AI summary

Systems (10), devices (106), methods, and non-transient machine-interpretable programming and/or other instruction products for the generation, transfer, storage, and other processing of secure data sets (11) used in electronic payment transactions, including particularly the secure creation, administration, manipulation, processing, and storage of electronic data useful in processing of pre-funded, pre-paid, and/or otherwise pre-authorized payment transactions. Devices (106, 100, 101) and methods in accordance with the disclosure can be used to create pre-funded payment token data sets (11), the token data sets comprising secure data items or records representing negotiable monetary or other economic value, and to share them between network communication devices (106) such as smart phones, home or business desktop computers, etc., for use in purchases and other transactions.