Token-Based Transaction Security via Mobile Device Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional transaction technologies at point of sale (POS) devices are vulnerable to security breaches as they transmit sensitive electronic card information over networks, exposing users' personal information to unauthorized access.

Innovation Solution

A token-based system where a mobile device generates a token with a transaction identifier, total cost, and payment method identifier, which is used to authorize transactions without sharing sensitive card information, utilizing an identity verification server and payment blockchain to ensure secure transactions without exposing personal data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional POS devices transmit sensitive electronic card information over networks, then transaction authorization can be completed, but security vulnerabilities arise exposing users' personal information to unauthorized access

Engineering Contradiction:
Improvetransaction securityVSAvoiddata breach risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive card information from the transaction process by using tokenization. The mobile device generates a token that represents the card information without containing the actual sensitive data. This token is then transmitted instead of the real card information, effectively removing the harmful element (sensitive data) from the transaction flow while maintaining the essential function of payment authorization.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary token as a mediator between the card information and the transaction system. This token acts as a safe intermediary that carries the necessary transaction information without exposing the underlying sensitive card data. The tokenization system and mobile device work together to create and manage this intermediary representation, protecting the original sensitive information from exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If mobile devices generate and transmit tokens instead of card information, then security is enhanced by preventing transmission of sensitive information, but system complexity increases due to token generation and verification processes

Engineering Contradiction:
Improvedata protectionVSAvoidtoken-based system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The mobile device performs self-service by autonomously generating the token using its own processing capabilities and stored card information. The device creates the token representation without requiring external tokenization infrastructure during the transaction moment. This self-service approach shifts the complexity to the mobile device while simplifying the POS and network infrastructure, as they only need to handle the generated tokens without complex decryption or verification systems.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11893570B1Token based demand and remand system
Publication Date: 2024.02.06 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US11893570B1 patent drawing
  • US11893570B1 patent drawing
  • US11893570B1 patent drawing

AI summary

A system is described to authorize a transaction using blockchain technology. For example, a transaction authorization system comprises a point of sale (POS) device, a mobile device, and a payment blockchain. The POS device can initiate a transaction by scanning one or more items to be purchased and generating a code comprising a transaction identifier and a total cost of the one or more items. The mobile device can receive the code and can generate a token comprising the transaction identifier, total cost, a selected payment method identifier, and a value that can identify an account of a person associated with the mobile device. The token is sent to a payment blockchain to authorize the transaction.