Third-Party Token Processor for Secure Payment Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In online transactions, users' sensitive payment information is transmitted in plain text, posing security risks as eCommerce sites store this information for future use, exposing users and providers to potential breaches.

Innovation Solution

A secure token specific to an online service provider is generated by a third-party processor, which receives user account information, establishes a secure channel for exchange information, verifies the user, and creates a unique token mapped to the provider, allowing secure transactions without exposing sensitive information to the provider.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If payment information is stored by eCommerce sites for future processing, then payment convenience is improved, but security risk increases due to potential breaches

Engineering Contradiction:
Improvepayment convenienceVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive payment information from the eCommerce site's storage system by introducing a third-party token processor. The actual payment data is stored at the token processor, not at the eCommerce site, thereby removing the harmful factor (security risk) while preserving the useful function (payment convenience through stored payment methods).

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The token processor acts as an intermediary between the user and the eCommerce site. Instead of the eCommerce site directly storing and accessing payment information, the intermediary token processor handles the sensitive data, enabling convenient payments while mitigating security risks through centralized secure storage and token-based communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If payment information is transmitted in plain text, then transmission simplicity is improved, but security is worsened due to exposure to breaches

Engineering Contradiction:
Improvetransmission simplicityVSAvoidsecurity exposure
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent creates a copy of the payment information in the form of a token that is transmitted instead of the actual sensitive data. The token is a simplified representation that conveys payment intent without exposing the underlying credit card numbers or other sensitive information, thus maintaining transmission simplicity while eliminating security exposure.

Inventive Principle:
Principle #26Copying

3Object-affected harmful factors

If a secure token system is implemented, then security is improved, but system complexity increases due to third-party processor involvement

Engineering Contradiction:
Improvesecurity enhancementVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The token processor serves multiple functions: it stores payment information securely, generates tokens for eCommerce sites, validates payment requests, and manages the communication between users and merchants. By consolidating these multiple functions into a single intermediary system, the patent achieves enhanced security without proportionally increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10057238B2System and method for generating a service provider based secure token
Publication Date: 2018.08.21 AT&T INTELLECTUAL PROPERTY I L P
  • US10057238B2 patent drawing
  • US10057238B2 patent drawing
  • US10057238B2 patent drawing

AI summary

Devices, systems, and methods for generating a secure token specific to an online service provider are provided. User account information of a user is transmitted to a token processor from an online service provider requesting a secure token generation. The token processor also receives, from the online service provider, exchange information for an exchange between the user and the online service provider. The token processor generates, based on the exchange information and the user account information, a secure token to be used for the exchange. The generated secure token is mapped to the online service provider and transmitted to the online service provider. The exchange information is deleted from the online service provider. The stored secure token is usable only at the mapped online service provider.