Tokenized Card Information Generation and Transmission
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing tokenization process for cards is insecure as it requires sharing sensitive card details with token requestors, exposing users to security risks.
Innovation Solution
A computer-implemented method and system that generates and transmits tokenized card information securely by using a tokenization server to create a token key based on location information within files on a user device, which is then encrypted and shared with the token requestor.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If sensitive card details are shared with token requestors to enable tokenization, then the tokenization process can be completed, but security risks increase due to exposure of sensitive information
Solution Approach 1:
The patent extracts the sensitive card details from the tokenization process by storing them locally in the tokenization module within the user device. Only non-sensitive tokenized representations are transmitted to token requestors, eliminating the need to share actual card information while maintaining tokenization functionality.
Solution Approach 2:
The patent introduces a tokenization module as an intermediary component that resides locally on the user device. This module acts as a mediator between the payment card information and external token requestors, transforming sensitive data into secure tokens without requiring exposure of the original card details to external parties.
2Device complexity
If tokenized card information is stored at the token requestor's end, then transaction processing is simplified, but the risk of data breaches and unauthorized access increases
Solution Approach 1:
The patent inverts the conventional storage model by placing the tokenization module and sensitive card information storage on the user device rather than at the token requestor's end. This reversal ensures that even if token requestors are compromised, the sensitive card details remain protected locally on user devices.
Solution Approach 2:
The patent implements self-service tokenization where each user device maintains its own tokenization module and locally manages the transformation of card details into tokens. This self-contained approach eliminates reliance on external token requestors for secure storage, reducing the attack surface for data breaches.
3Reliability
If authentication pin is used to encrypt token key, then security is enhanced, but the complexity of token retrieval increases
Solution Approach 1:
The patent applies preliminary action by pre-establishing the authentication pin as a security measure during the tokenization setup phase. The pin is used to encrypt the token key in advance, so that during token retrieval, the system only needs to perform decryption rather than complex authentication protocols, balancing security with retrieval simplicity.
Data Source
AI summary
The present disclosure relates to a method and a tokenization server for generating and transmitting tokenized card information to a token requestor. In some non-limiting embodiments or aspects, the method includes receiving, from the token requestor, a request for a token corresponding to a payment card. The token may include a plurality of characters. Further, the method includes generating a token key corresponding to the token based on location information associated with a plurality of files stored in a user device. Subsequently, the method includes transmitting the token key, including location information within the plurality of files in the user device, to the token requestor. Here, the location information may include a location embedded with a character of the plurality of characters of the token. Thus, the present disclosure provides a secure method of generating, storing, and transmitting the tokenized card information.


