Single-Use Token and Cryptogram for Secure Transaction Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current token-based systems face challenges in ensuring transaction security, as tokens can be compromised, and devices provisioned with tokens can be stolen for fraudulent use, while merchants may inadvertently process incorrect transaction amounts.

Innovation Solution

A cloud-based single-use token processing system that generates and verifies tokens and cryptograms using access device and communication device data, ensuring secure transactions by limiting the transaction to specific parameters and verifying the device's proximity and transaction authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If tokens are used to replace personal information, then the risk of data breach is reduced, but tokens can still be captured and reused by fraudsters

Engineering Contradiction:
Improvedata breach riskVSAvoidtoken capture and reuse
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by making the token single-use and time-bound. Each token is generated with a specific expiration time and cannot be reused. The system dynamically generates new tokens for each transaction, ensuring that a captured token becomes invalid after use. This transforms the static token into a dynamic, self-destructing credential that eliminates reuse possibilities.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary actions by embedding expiration timestamps and usage counts into tokens before they are issued. The token generation process预先 sets limitations on token usage, and the verification process checks these parameters before accepting the token. This preliminary conditioning prevents fraudsters from capturing and reusing tokens, as the token's validity is already constrained by its embedded parameters.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If devices are provisioned with tokens, then transactions can be performed, but stolen devices can be used for fraudulent transactions

Engineering Contradiction:
Improvetransaction capabilityVSAvoiddevice theft and fraud
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system makes tokens dynamic by binding them to specific devices through device identifiers and setting expiration times. Each token includes a timestamp that limits its validity period. Even if a device is stolen, the token cannot be used after its expiration time, and the system can detect and prevent usage from unauthorized devices through device authentication protocols.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The verification process provides feedback by checking multiple parameters including device identifier, timestamp, and usage count before accepting a token. The system continuously monitors token usage and can reject tokens from stolen or unauthorized devices based on feedback from device authentication mechanisms. This feedback loop prevents fraudulent transactions from stolen devices.

Inventive Principle:
Principle #23Feedback

3Productivity

If merchants process transactions, then sales are completed, but incorrect transaction amounts may be processed inadvertently

Engineering Contradiction:
Improvetransaction processingVSAvoidtransaction amount accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system performs preliminary verification by embedding the exact transaction amount into the token before issuance. The token includes a predefined amount field that specifies the exact value for the transaction. Before processing, the system verifies that the token's embedded amount matches the transaction amount, preventing merchants from inadvertently processing incorrect amounts. This preliminary encoding of the correct amount ensures accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The verification process provides feedback by comparing the token's embedded transaction amount with the amount being processed. The system checks for consistency between the token's predefined amount and the transaction amount, and only accepts the transaction if they match. This feedback mechanism prevents merchants from processing incorrect amounts, as the system actively verifies and rejects mismatches.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11943231B2Token and cryptogram using transaction specific information
Publication Date: 2024.03.26 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11943231B2 patent drawing
  • US11943231B2 patent drawing
  • US11943231B2 patent drawing

AI summary

Systems and methods for token processing are disclosed. An access device can provide access device data to a mobile communication device. The communication device generates a token request including the access device data and communication device data and sends the token request to a server computer. The server computer returns a token and a token cryptogram to the mobile communication device. The token and the cryptogram may be used in a transaction.