Token Enrollment System with Dynamic Parameter Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional electronic payment systems do not allow token requesting parties to customize or control the token generation process, limiting their participation in token services due to exposure of account numbers during transaction lifecycles, which increases the risk of fraudulent activity.
Innovation Solution
A token requesting party can specify parameters for token generation, including account selection, encryption keys, and notification thresholds, using a token service provider's online portal and modules like key management, provisioning, and risk management, enabling control over the token generation and storage process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a token service provider generates and manages tokens unilaterally, then token generation efficiency is improved, but token requesting parties cannot customize or control the token generation process
Solution Approach 1:
The patent implements dynamic control of the token generation process by allowing token requesting parties to configure various parameters including encryption key selection, token format specifications, and generation thresholds. The system transitions from a static, provider-controlled process to a dynamic, participant-configurable process where each party can customize token generation according to their specific requirements while maintaining system efficiency.
2Ease of manufacture
If account numbers are exposed at various points in the transaction lifecycle, then transaction processing is simplified, but the risk of fraudulent activity increases
Solution Approach 1:
The patent creates cryptographic copies (tokens) of account numbers that can be used in transactions without exposing the actual account number. These token copies maintain the functional equivalence of account numbers for transaction processing while eliminating the security vulnerability of exposing real account numbers at multiple stages. The token serves as a surrogate that preserves transaction simplicity while mitigating fraud risk.
3Reliability
If token requesting parties can control the token generation process, then security and customization are improved, but system complexity increases
Solution Approach 1:
The patent introduces a token service provider as an intermediary platform that manages the complexity of token generation while enabling customization for requesting parties. This intermediary layer abstracts the complex cryptographic operations and token management functions, allowing participants to configure tokens through simplified interfaces without directly managing the underlying system complexity. The intermediary handles key management, token generation, and coordination between multiple parties.
Data Source
AI summary
Embodiments of the invention are directed to methods, apparatuses, computer readable media and systems for providing a token service environment that allows a token requesting party (e.g. token requestor) to specify parameters for token generation for controlling and customizing the token generation process. For example, the token requesting party may specify (e.g. select from a list or provide a list of) the accounts for tokenization. The accounts may be identified by account identifiers (e.g. account numbers) or bank identification numbers (BINs). The token requesting party may also specify encryption keys for the tokens to be generated. The token requesting party may also specify additional parameters such as notification thresholds indicating when notifications associated with the tokens are to be generated.


