Single-Use Token and Cryptogram for Secure Transaction Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current token-based systems face challenges in ensuring transaction security, as tokens can be compromised, and devices provisioned with tokens can be stolen for fraudulent use, while merchants may inadvertently process incorrect transaction amounts.
Innovation Solution
A cloud-based single-use token processing system that generates and verifies tokens and cryptograms using access device and communication device data, ensuring secure transactions by limiting the transaction to specific parameters and verifying the device's proximity and transaction authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If tokens are used to replace personal information, then the risk of data breach is reduced, but tokens can still be captured and reused by fraudsters
Solution Approach 1:
The patent applies dynamics by making the token single-use and time-bound. Each token is generated with a specific expiration time and cannot be reused. The system dynamically generates new tokens for each transaction, ensuring that a captured token becomes invalid after use. This transforms the static token into a dynamic, self-destructing credential that eliminates reuse possibilities.
Solution Approach 2:
The system performs preliminary actions by embedding expiration timestamps and usage counts into tokens before they are issued. The token generation process预先 sets limitations on token usage, and the verification process checks these parameters before accepting the token. This preliminary conditioning prevents fraudsters from capturing and reusing tokens, as the token's validity is already constrained by its embedded parameters.
2Ease of operation
If devices are provisioned with tokens, then transactions can be performed, but stolen devices can be used for fraudulent transactions
Solution Approach 1:
The system makes tokens dynamic by binding them to specific devices through device identifiers and setting expiration times. Each token includes a timestamp that limits its validity period. Even if a device is stolen, the token cannot be used after its expiration time, and the system can detect and prevent usage from unauthorized devices through device authentication protocols.
Solution Approach 2:
The verification process provides feedback by checking multiple parameters including device identifier, timestamp, and usage count before accepting a token. The system continuously monitors token usage and can reject tokens from stolen or unauthorized devices based on feedback from device authentication mechanisms. This feedback loop prevents fraudulent transactions from stolen devices.
3Productivity
If merchants process transactions, then sales are completed, but incorrect transaction amounts may be processed inadvertently
Solution Approach 1:
The system performs preliminary verification by embedding the exact transaction amount into the token before issuance. The token includes a predefined amount field that specifies the exact value for the transaction. Before processing, the system verifies that the token's embedded amount matches the transaction amount, preventing merchants from inadvertently processing incorrect amounts. This preliminary encoding of the correct amount ensures accuracy.
Solution Approach 2:
The verification process provides feedback by comparing the token's embedded transaction amount with the amount being processed. The system checks for consistency between the token's predefined amount and the transaction amount, and only accepts the transaction if they match. This feedback mechanism prevents merchants from processing incorrect amounts, as the system actively verifies and rejects mismatches.
Data Source
AI summary
Systems and methods for token processing are disclosed. An access device can provide access device data to a mobile communication device. The communication device generates a token request including the access device data and communication device data and sends the token request to a server computer. The server computer returns a token and a token cryptogram to the mobile communication device. The token and the cryptogram may be used in a transaction.


