One-Time Token Payment Processing via Pseudo-PAN Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing payment transaction systems are vulnerable to data breaches, where sensitive payment information is exposed and can lead to fraudulent transactions and the need for consumers to have their cards reissued, causing inconvenience and financial loss.

Innovation Solution

Generating a one-time token, such as a pseudo-PAN, based on the actual PAN at the consumer's device, which is transmitted through the network instead of the actual payment information, ensuring that only the token is exposed in case of a data breach, thereby reducing the risk of fraudulent transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If actual payment information (PAN) is transmitted through payment networks, then payment transactions can be completed, but payment information is exposed to data breaches and fraudulent transactions

Engineering Contradiction:
Improvepayment transaction securityVSAvoidpayment information exposure
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a tokenization intermediary that replaces the actual PAN with a synthetic token during transmission through payment networks. This intermediary layer allows transactions to proceed while preventing direct exposure of sensitive payment information to merchants and networks, thereby resolving the contradiction between enabling transactions and protecting against data breaches

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a copy (token) of the payment information that appears identical to the original PAN but contains no actual sensitive data. This synthetic copy can be transmitted and processed without exposing the real payment information, allowing transaction completion while eliminating the risk of information exposure during transmission

Inventive Principle:
Principle #26Copying

2Productivity

If payment information is stored at multiple locations during transmission, then transaction processing can occur, but the likelihood of data breaches increases

Engineering Contradiction:
Improvetransaction processing capabilityVSAvoiddata breach vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the actual PAN from the transaction data flow and replaces it with a token at the point of entry. This extraction removes the sensitive information from multiple storage locations and transmission paths, allowing transactions to proceed while eliminating the vulnerability associated with storing and transmitting actual payment data across multiple networks and servers

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If payment information is changed and reissued after a data breach, then fraudulent transactions can be prevented, but consumers experience inconvenience and financial loss

Engineering Contradiction:
Improvefraud preventionVSAvoidcard reissue time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary tokenization of payment information before it enters the payment network. By establishing this protective layer in advance, the system prevents data breaches from occurring in the first place, eliminating the need for subsequent card reissues and the associated time loss and financial inconvenience for consumers

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12106290B2Systems and methods of processing payment transactions using one-time tokens
Publication Date: 2024.10.01 MASTERCARD INT INC
  • US12106290B2 patent drawing
  • US12106290B2 patent drawing
  • US12106290B2 patent drawing

AI summary

Disclosed are exemplary embodiments of systems and methods for processing a payment transaction using a pseudo-PAN. In an exemplary embodiment, a method generally includes periodically generating an encryption salt and receiving an authorization message for a payment transaction to a payment account, where the authorization message includes a token. The method also includes decrypting the token based on an encryption algorithm and the encryption salt most recently generated, prior to receipt of the authorization message, and searching in memory for the decrypted token. The method then includes determining that the decrypted token does not match any of a plurality of actual primary account numbers (PANs) in the memory, whereby the token is determined to not be a pseudo-PAN, and transmitting the authorization message without modification to a computing device associated with one of an acquirer and an issuer of said payment account.