Structure-Preserving Encryption for Payment Token Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Securing sensitive tokens in online transactions is challenging, especially in environments with multiple merchants or sub-entities, leading to potential security vulnerabilities.

Innovation Solution

The use of structure-preserving encryption algorithms to encrypt tokens with a cryptographic key shared between the payment card processor and merchant, embedding a processor identifier in the encrypted token to ensure secure transmission and decryption for settlement requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If tokens are encrypted using traditional encryption methods, then security is improved, but the ability to embed processor identifier and maintain token structure is lost

Engineering Contradiction:
Improvetoken securityVSAvoidprocessor identifier embedding
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies parameter changes by modifying the encryption approach from traditional encryption that completely obscures data to structure-preserving encryption that maintains specific structural properties. The encryption algorithm preserves the format and embeddability of the token while still providing security, allowing processor identifiers to be embedded without compromising either security or operational capability

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The structure-preserving encryption algorithm serves multiple functions simultaneously: it provides security encryption, maintains token structure for compatibility, and enables embedding of processor identifiers. This multi-functionality resolves the contradiction by making a single encryption method that accomplishes what previously required separate mechanisms

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If tokens are securely encrypted, then unauthorized access is prevented, but routing information may be lost

Engineering Contradiction:
Improvetoken protectionVSAvoidprocessor identifier
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements nesting by embedding the processor identifier within the encrypted token structure itself. The identifier is nested inside the encrypted data in a way that allows extraction without decryption of the entire token, enabling routing information to be recovered while maintaining security of the actual token data

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The processor identifier is embedded into the token structure during the encryption process itself, before the token needs to be transmitted or used. This preliminary embedding ensures that routing information is already in place and will not be lost during subsequent processing or transmission steps

Inventive Principle:
Principle #10Preliminary action

3Reliability

If traditional encryption is used, then security is enhanced, but token format compatibility is compromised

Engineering Contradiction:
ImprovesecurityVSAvoidtoken format compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The encryption method changes the parameter of format preservation from false (traditional encryption) to true (structure-preserving encryption). This allows the encrypted token to maintain its original format characteristics, ensuring compatibility with existing systems while still providing security protection

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10318932B2Payment card processing system with structure preserving encryption
Publication Date: 2019.06.11 MICRO FOCUS LLC
  • US10318932B2 patent drawing
  • US10318932B2 patent drawing
  • US10318932B2 patent drawing

AI summary

A customer may provide a merchant with primary account number information in connection with a purchase transaction. The merchant may send an associated authorization request to a payment card processor. A tokenization server at the payment card processor may generate a token corresponding to the primary account number. To secure the token, the token may be encrypted at the payment card processor using a cryptographic key shared with the merchant. A structure preserving encryption algorithm may be used in encrypting the token. A processor identifier may be embedded in the encrypted version of the token during the structure preserving encryption operation. The merchant can use the shared key to decrypt the token and extract the processor identifier. A settlement request may be directed to the processor from the merchant to settle the transaction using the processor identifier.