Token-Based Mobile Payment Data Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices pose a risk in resource access transactions as sensitive user data, such as passwords or account numbers, can be compromised if the device is lost or hacked, as the data is typically stored in an unencrypted format, making it vulnerable to unauthorized access.
Innovation Solution
Implementing a system where sensitive user data is never stored on the mobile device in an unencrypted format; instead, a token server generates and manages tokens that represent the user data, which are then stored on the device, minimizing the impact of device theft or compromise, as tokens can be easily replaced or updated periodically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If sensitive user data is stored on mobile device in unencrypted format, then ease of access and operation is improved, but security and vulnerability to unauthorized access deteriorates
Solution Approach 1:
The patent extracts the sensitive user data from the mobile device by implementing a tokenization system where only token representations are stored on the device, while the actual sensitive data remains secured on remote servers. This extraction eliminates the security vulnerability of storing unencrypted sensitive data on mobile devices while maintaining operational convenience through token-based access.
Solution Approach 2:
The patent introduces tokens as intermediary representations that mediate between the mobile device and sensitive user data. These tokens serve as secure placeholders that enable device operations without exposing actual sensitive information, thus resolving the contradiction between ease of access and security vulnerability.
2Object-affected harmful factors
If tokens are used to represent sensitive user data instead of storing actual data, then security against device theft is improved, but system complexity increases
Solution Approach 1:
The tokenization system operates with a high degree of automation where tokens are automatically generated, stored, and managed without requiring complex user configuration or intervention. The system self-manages the token lifecycle including creation from sensitive data, storage on the device, and automatic replacement if compromised, thereby reducing the perceived complexity for users while maintaining strong security.
Solution Approach 2:
The patent creates simplified token copies that represent the essential functionality of sensitive user data without containing the actual sensitive information. These token copies enable all necessary device operations while being much simpler and more secure than storing actual sensitive data, thus improving security against device theft without proportionally increasing system complexity.
3Reliability
If tokens are easily replaceable and updated periodically, then security resilience to compromise is improved, but operational overhead and time consumption increases
Solution Approach 1:
The patent implements automatic periodic token refreshment where tokens are systematically updated at predetermined intervals without requiring user intervention. This periodic action maintains security resilience by ensuring tokens remain current and can be replaced if compromised, while the automated nature of the process minimizes time loss and operational overhead.
Solution Approach 2:
The tokenization system incorporates feedback mechanisms that automatically detect when tokens may be compromised or expired and trigger replacement processes. This feedback-driven approach ensures security resilience by responding to potential threats while optimizing the timing of token replacements to minimize operational disruption and time consumption.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the invention are directed to methods, systems and devices for providing sensitive user data to a mobile device using an encryption key. For example, a mobile application on a mobile device may receive encrypted sensitive user data from a mobile application server, where the user sensitive data is encrypted with a key from a token server computer. The mobile application may then request that the encrypted payment information be sent to the token server. The mobile device may then receive a payment token associated with the payment information from the token server.