Token Service Provider for Secure Mobile Commerce Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic commerce systems face challenges in securely and efficiently verifying transactions, particularly in environments where users are hesitant to share personal and financial information, and there is a need for a solution that leverages social media data to enhance user identification and fraud prevention.

Innovation Solution

A system and method utilizing a common identifier (ID) linked to a user's social media profiles to verify transactions, which constructs a social graph to assess risk and issues tokens with specific scopes based on user consent, preferences, and regulatory needs, enabling secure and seamless transactions across various platforms and environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users are required to share personal and financial information for transaction verification, then transaction security can be improved, but user privacy concerns and hesitation increase

Engineering Contradiction:
Improvetransaction securityVSAvoiduser privacy concerns
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a token service provider as an intermediary that issues tokens representing financial instruments. These tokens serve as mediators between users and merchants, enabling transaction verification without exposing sensitive personal or financial information. The token contains encrypted references to funding sources and user identities, allowing secure authentication while preserving privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates token copies that represent actual financial instruments without duplicating sensitive data. Each token is a cryptographic representation that can be used for transaction purposes but cannot be reverse-engineered to reveal underlying account information. This copying mechanism allows verification while protecting original sensitive data.

Inventive Principle:
Principle #26Copying

2Ease of operation

If traditional authentication methods using login IDs and passwords are used, then user identification can be achieved, but fraud prevention capabilities are limited

Engineering Contradiction:
Improveuser identificationVSAvoidfraud prevention
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication process into multiple independent components: token issuance, token validation, and transaction verification. Each component operates independently with specific security functions. The token itself is segmented into multiple cryptographic elements that work together to provide both ease of use and strong fraud prevention.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic token validation where tokens have embedded expiration times, scope limitations, and conditional validity rules. Tokens can be dynamically activated or deactivated based on transaction context. This dynamic approach enhances fraud prevention while maintaining ease of operation through automated validation.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If tokens with broad scopes are issued for transaction verification, then transaction flexibility is improved, but security risks increase

Engineering Contradiction:
Improvetransaction flexibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements local quality by embedding different security parameters and validation rules into different portions of the token structure. Each token can have specific scopes, amounts, merchants, or time periods encoded with varying security requirements. This allows highly flexible transaction authorization while maintaining targeted security controls for each specific use case.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11308483B2Token service provider for electronic/mobile commerce transactions
Publication Date: 2022.04.19 PAYPAL INC
  • US11308483B2 patent drawing
  • US11308483B2 patent drawing
  • US11308483B2 patent drawing

AI summary

In some embodiments, a verification system includes a memory storing a common identifier that identifies a user. The system may also include one or more hardware processors coupled to the memory and configured to read instructions from the memory to perform the steps of: receiving a token associated with a request to complete a transaction with an environment; determining the common identifier associated with the token, the common identifier being associated with an identifier of the merchant, an identifier of the user requesting the transaction, and a funding instrument associated with the user; and determining, based on information associated with the common identifier, whether to approve the transaction.