Subtoken Routing for Secure One-Time Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing token systems face limitations in securely conducting transactions due to the constraints of one-dimensional bar codes, which cannot include all necessary information, and the limited availability of tokens, making it difficult to manage multiple transactions securely.

Innovation Solution

A subtoken system is introduced, where a first server generates a subtoken with an obfuscated portion that routes to a second server, which retrieves the associated credential to authorize transactions, allowing for secure and efficient use of tokens even in data-constrained environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a token and token validation cryptogram are used in a traditional token system, then credential security is improved, but the system cannot accommodate data-constrained environments like one-dimensional bar codes

Engineering Contradiction:
Improvecredential securityVSAvoidcompatibility with data-constrained environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the traditional token system into two distinct components: a subtoken (which can be embedded in data-constrained formats like bar codes) and a primary token (which maintains full security functionality). The subtoken contains a header and obfuscated portion that route to the primary token stored securely, allowing the system to work within space constraints while preserving security through the two-token architecture.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple tokens are generated for a single credential, then transaction versatility is improved, but token availability and manageability deteriorate

Engineering Contradiction:
Improvetransaction versatilityVSAvoidtoken management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the security-critical functions from the subtoken and concentrates them in the primary token. The subtoken contains only routing information (header and obfuscated portion), while the primary token holds the actual credential mapping and security validation logic. This extraction allows multiple subtokens to be generated easily without duplicating complex security management, as all subtokens reference the same primary token.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of manufacture

If traditional tokens are used with fixed headers and check digits, then processing compatibility is improved, but the number of available unique tokens is limited

Engineering Contradiction:
Improveprocessing compatibilityVSAvoidnumber of available tokens
Core Design Contradiction:
Ease of manufactureVSQuantity of substance

Solution Approach 1:

The patent applies local quality by making different parts of the token serve different purposes. The header portion maintains fixed formatting for routing compatibility, while the obfuscated portion uses dynamic generation with multiple possible formats and encodings. This allows the system to maintain processing compatibility where needed while generating vast numbers of unique subtokens through the flexible obfuscated portion.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11995649B2Systems and methods for creating subtokens using primary tokens
Publication Date: 2024.05.28 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11995649B2 patent drawing
  • US11995649B2 patent drawing
  • US11995649B2 patent drawing

AI summary

According to one embodiment of the invention, a subtoken corresponding to a primary token is generated. The primary token corresponds to a credential. The credential may be, for example, a primary account number (PAN) corresponding to a payment account. The subtoken may be a temporary, one-time use subtoken based on a primary token associated with the credential that allows a user to conduct a transaction from his or her account, while still providing security for the user's sensitive data. The subtoken may contain a header and an obfuscated portion. The header of the subtoken routes the subtoken to the entity issuing the subtoken for translation into the primary token. The obfuscated portion acts as a pointer to the primary token and data associated with the primary token. A same check digit may be included in the subtoken, the primary token, and the credential, in order to ensure that the transaction is not improperly denied.