Token-Based Mobile Payment Data Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices pose a risk in resource access transactions as sensitive user data, such as passwords or account numbers, can be compromised if the device is lost or hacked, as the data is typically stored in an unencrypted format, making it vulnerable to unauthorized access.

Innovation Solution

Implementing a system where sensitive user data is never stored on the mobile device in an unencrypted format; instead, a token server generates and manages tokens that represent the user data, which are then stored on the device, minimizing the impact of device theft or compromise, as tokens can be easily replaced or updated periodically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If sensitive user data is stored on mobile device in unencrypted format, then ease of access and operation is improved, but security and vulnerability to unauthorized access deteriorates

Engineering Contradiction:
Improveease of accessVSAvoidvulnerability to unauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive user data from the mobile device by implementing a tokenization system where only token representations are stored on the device, while the actual sensitive data remains secured on remote servers. This extraction eliminates the security vulnerability of storing unencrypted sensitive data on mobile devices while maintaining operational convenience through token-based access.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces tokens as intermediary representations that mediate between the mobile device and sensitive user data. These tokens serve as secure placeholders that enable device operations without exposing actual sensitive information, thus resolving the contradiction between ease of access and security vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If tokens are used to represent sensitive user data instead of storing actual data, then security against device theft is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity against device theftVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The tokenization system operates with a high degree of automation where tokens are automatically generated, stored, and managed without requiring complex user configuration or intervention. The system self-manages the token lifecycle including creation from sensitive data, storage on the device, and automatic replacement if compromised, thereby reducing the perceived complexity for users while maintaining strong security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates simplified token copies that represent the essential functionality of sensitive user data without containing the actual sensitive information. These token copies enable all necessary device operations while being much simpler and more secure than storing actual sensitive data, thus improving security against device theft without proportionally increasing system complexity.

Inventive Principle:
Principle #26Copying

3Reliability

If tokens are easily replaceable and updated periodically, then security resilience to compromise is improved, but operational overhead and time consumption increases

Engineering Contradiction:
Improvesecurity resilienceVSAvoidtime for token replacement
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements automatic periodic token refreshment where tokens are systematically updated at predetermined intervals without requiring user intervention. This periodic action maintains security resilience by ensuring tokens remain current and can be replaced if compromised, while the automated nature of the process minimizes time loss and operational overhead.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The tokenization system incorporates feedback mechanisms that automatically detect when tokens may be compromised or expired and trigger replacement processes. This feedback-driven approach ensures security resilience by responding to potential threats while optimizing the timing of token replacements to minimize operational disruption and time consumption.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3518567B1Remote server encrypted data provisioning system and methods
Publication Date: 2020.09.09 VISA INTERNATIONAL SERVICE ASSOCIATION
  • EP3518567B1 patent drawingFigure 1
  • EP3518567B1 patent drawingFigure 2
  • EP3518567B1 patent drawingFigure 3

AI summary

Embodiments of the invention are directed to methods, systems and devices for providing sensitive user data to a mobile device using an encryption key. For example, a mobile application on a mobile device may receive encrypted sensitive user data from a mobile application server, where the user sensitive data is encrypted with a key from a token server computer. The mobile application may then request that the encrypted payment information be sent to the token server. The mobile device may then receive a payment token associated with the payment information from the token server.