Token Access Granting System for Secure Cardholder Data Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Tokenization systems in credit and debit card processing limit merchants' ability to share cardholder data, hindering services like reservation confirmations and fee charging, as merchants cannot access or reacquire cardholder data stored as tokens.
Innovation Solution
A system and method for sharing cardholder data between merchants by allowing the reacquisition of tokens associated with cardholder data from a tokenization provider system, enabling secure access and use by second merchants without storing the actual cardholder data, using authorization factors for secure transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If merchants store tokens instead of cardholder data for security, then security is improved, but the ability to share cardholder data with other merchants deteriorates
Solution Approach 1:
The patent introduces a token access granting system that acts as an intermediary between merchants and the tokenization provider. This system receives requests from merchants to access tokens, verifies authorization through authorization factors, and grants controlled access to token information without exposing actual cardholder data. The intermediary enables secure data sharing by mediating the access request process while maintaining security constraints.
Solution Approach 2:
The patent segments the token access process into distinct components: token storage at the tokenization provider, merchant requests for token access, authorization factor verification, and controlled token disclosure. By dividing the system into these separate functional segments, the patent enables selective access to token information while maintaining overall security architecture.
2Reliability
If merchants cannot access cardholder data stored as tokens, then security is maintained, but service capabilities like reservation confirmations and fee charging deteriorate
Solution Approach 1:
The token access granting system serves as an intermediary that enables service capabilities by allowing merchants to request and receive token information when authorized. The system mediates between security constraints and service needs by verifying authorization factors and granting controlled access to necessary token data for operations like reservation confirmations and fee charging.
Solution Approach 2:
The patent implements dynamic access control where merchants can obtain token information on-demand based on authorization factors. The system transitions from static token storage to dynamic token disclosure, allowing merchants to access token data when needed for specific services while maintaining security when access is not authorized or required.
3Reliability
If tokenization is implemented to prevent CHD theft, then security against theft is improved, but the ability to reacquire cardholder data for additional transactions deteriorates
Solution Approach 1:
The token access granting system acts as an intermediary that enables data reacquisition by receiving requests from merchants to access previously tokenized cardholder data. The system verifies authorization factors and grants controlled access to the original CHD or token information, allowing merchants to reacquire data for additional transactions while maintaining security through the intermediary layer.
Solution Approach 2:
The patent implements preliminary authorization where merchants must provide authorization factors before accessing reacquired cardholder data. The system performs preliminary verification of the merchant's right to access the data before disclosing it, enabling secure reacquisition for additional transactions while preventing unauthorized access.
Data Source
AI summary
One embodiment of the present disclosure provides a system and associated processes for sharing cardholder data (CHD) between a merchant that utilizes tokenization and a second merchant that may or may not utilize tokenization. In one embodiment, the merchant, or an employee of the merchant, can use the system and associated processes to reacquire CHD from a tokenization provider system. In one embodiment, the merchant identifies to the tokenization provider system a desire to share CHD, which is associated with a token, with a second merchant. The merchant and/or the tokenization provider system can then invite the second merchant to register with the tokenization provider system. Once registered with the tokenization provider system, the second merchant can access any CHD that the merchant associated with the second merchant.


