Token Enrollment System with Dynamic Parameter Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional electronic payment systems do not allow token requesting parties to customize or control the token generation process, limiting their participation in token services due to exposure of account numbers during transaction lifecycles, which increases the risk of fraudulent activity.

Innovation Solution

A token requesting party can specify parameters for token generation, including account selection, encryption keys, and notification thresholds, using a token service provider's online portal and modules like key management, provisioning, and risk management, enabling control over the token generation and storage process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a token service provider generates and manages tokens unilaterally, then token generation efficiency is improved, but token requesting parties cannot customize or control the token generation process

Engineering Contradiction:
Improvetoken generation efficiencyVSAvoidcustomization capability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic control of the token generation process by allowing token requesting parties to configure various parameters including encryption key selection, token format specifications, and generation thresholds. The system transitions from a static, provider-controlled process to a dynamic, participant-configurable process where each party can customize token generation according to their specific requirements while maintaining system efficiency.

Inventive Principle:
Principle #15Dynamics

2Ease of manufacture

If account numbers are exposed at various points in the transaction lifecycle, then transaction processing is simplified, but the risk of fraudulent activity increases

Engineering Contradiction:
Improvetransaction processing simplicityVSAvoidfraud risk
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent creates cryptographic copies (tokens) of account numbers that can be used in transactions without exposing the actual account number. These token copies maintain the functional equivalence of account numbers for transaction processing while eliminating the security vulnerability of exposing real account numbers at multiple stages. The token serves as a surrogate that preserves transaction simplicity while mitigating fraud risk.

Inventive Principle:
Principle #26Copying

3Reliability

If token requesting parties can control the token generation process, then security and customization are improved, but system complexity increases

Engineering Contradiction:
Improvesecurity levelVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a token service provider as an intermediary platform that manages the complexity of token generation while enabling customization for requesting parties. This intermediary layer abstracts the complex cryptographic operations and token management functions, allowing participants to configure tokens through simplified interfaces without directly managing the underlying system complexity. The intermediary handles key management, token generation, and coordination between multiple parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10412060B2Token enrollment system and method
Publication Date: 2019.09.10 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US10412060B2 patent drawing
  • US10412060B2 patent drawing
  • US10412060B2 patent drawing

AI summary

Embodiments of the invention are directed to methods, apparatuses, computer readable media and systems for providing a token service environment that allows a token requesting party (e.g. token requestor) to specify parameters for token generation for controlling and customizing the token generation process. For example, the token requesting party may specify (e.g. select from a list or provide a list of) the accounts for tokenization. The accounts may be identified by account identifiers (e.g. account numbers) or bank identification numbers (BINs). The token requesting party may also specify encryption keys for the tokens to be generated. The token requesting party may also specify additional parameters such as notification thresholds indicating when notifications associated with the tokens are to be generated.