Terminal Data Exchange Using User-Side Tokenized Provider Accounts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data exchange mechanisms between user devices and terminal devices require complex integration of third party service provider information at the terminal devices, leading to computational complexity and data security vulnerabilities, especially when non-currency payment options are involved.
Innovation Solution
The user device communicates with a server device to obtain and confirm data exchange options with third party service providers, transmitting tokenized data to the terminal device, thereby avoiding direct integration of sensitive information at the terminal device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If terminal devices integrate third party service provider information directly, then data exchange functionality is improved, but device complexity and data security vulnerabilities increase
Solution Approach 1:
The patent extracts third party service provider information from the terminal device and relocates it to the user device. The user device stores and manages third party service provider data, while the terminal device only receives tokenized information. This extraction eliminates the need for terminal devices to maintain complex integration with multiple third party service providers, thereby reducing terminal device complexity while preserving data exchange functionality.
Solution Approach 2:
The patent introduces a tokenization mechanism as an intermediary between the user device and terminal device. Third party service provider information is tokenized and stored at the user device, with only the tokens transmitted to the terminal device during data exchange. This intermediary layer allows the terminal device to access third party functionality without directly integrating with the service providers, thus reducing complexity.
2Adaptability or versatility
If terminal devices integrate third party service provider information directly, then data exchange functionality is improved, but data security vulnerabilities increase
Solution Approach 1:
The patent extracts sensitive third party service provider information from terminal devices and relocates it to user devices. By storing third party data at the user device level rather than at the terminal device, the system reduces the attack surface at terminal devices and eliminates the need for terminal devices to maintain secure storage and processing of sensitive third party information, thereby reducing data security vulnerabilities.
Solution Approach 2:
The patent uses tokenization as an intermediary mechanism that masks third party service provider information. Only tokenized versions of the data are transmitted to terminal devices, preventing direct exposure of sensitive information. This intermediary layer protects against data security vulnerabilities by ensuring that even if terminal devices are compromised, the actual third party service provider information remains protected at the user device.
3Loss of information
If user device obtains data exchange options from server device, then user privacy is improved, but communication time increases
Solution Approach 1:
The patent implements preliminary action by having the user device obtain and cache third party service provider information and data exchange options in advance, before the actual data exchange session. The user device stores tokenized information and pre-configures exchange parameters, so that during the actual data exchange with the terminal device, the system can proceed more quickly without needing to perform complex queries in real-time. This preliminary preparation maintains user privacy while reducing communication time during active data exchange.
Data Source
AI summary
Techniques are disclosed for implementing a data exchange account at a user device. An application executing on a user device can initiate a data exchange session with a terminal device and determine that a data exchange account is not associated with the user device. The application can then obtain, from a server device, a list comprising a plurality of third party service providers and present the list at a display of the user device. The application can then receive an indication that a third party service provider of the plurality of third party service providers has been selected. In response, the application can transmit a request to associate the data exchange account with the user device. The application can receive data exchange account information comprising a token and transmit a data cryptogram generated by the application using the token.


