Token Storage Device for Secure In-Store Payments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing payment systems face security concerns, particularly with physical credit cards, as they are vulnerable to skimming and data theft, and current tokenization methods are limited to mobile device-based transactions, not supporting in-store purchases without a mobile device.

Innovation Solution

A token management computing system that generates and provisions secure payment tokens for use at physical merchant locations, allowing users to set controls such as spend limits and expiration dates, and stores these tokens on a token storage device without a magnetic stripe, enabling secure in-store transactions using EMV chips and Near Field Communication (NFC).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If payment tokens are generated and stored on a token storage device for in-store purchases, then security against skimming and data theft is improved, but device complexity increases due to EMV chip and NFC requirements

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a token storage device as an intermediary between the user's payment credentials and the point-of-sale terminal. This device contains an EMV chip that generates and stores payment tokens, acting as a mediator that protects the user's actual payment information while enabling secure transactions through chip-based or NFC communication with merchants.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple users can provision tokens to a single token storage device, then adaptability and versatility are improved, but managing and controlling individual user tokens becomes more complex

Engineering Contradiction:
Improvemulti-user supportVSAvoidtoken management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the token management system by allowing multiple user accounts to be associated with a single token storage device. Each user can have their own payment credentials and token provisioning rights, dividing the management function into separate user-specific configurations while maintaining a unified physical device for transactions.

Inventive Principle:
Principle #1Segmentation

3Reliability

If token storage devices without magnetic stripes are used, then security against skimming is improved, but compatibility with legacy POS terminals that rely on magnetic stripe reading decreases

Engineering Contradiction:
ImprovesecurityVSAvoidcompatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces the magnetic stripe mechanical system with an EMV chip-based system. Instead of using magnetic strips that can be skimmed, the device uses embedded smart chip technology that requires physical insertion or contactless NFC communication, fundamentally changing the transaction mechanism from magnetic field reading to chip authentication and token verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20240104532A1Systems and methods for provisioning tokens for multiple users to a token storage device
Publication Date: 2024.03.28 MASTERCARD INT INC
  • US20240104532A1 patent drawing
  • US20240104532A1 patent drawing
  • US20240104532A1 patent drawing

AI summary

A token management computing system for provisioning at least one secure payment token for use in payment transactions is provided. The token management computing system includes a token storage device in communication with a plurality of user computing devices each associated with a respective user, and a token management (“TM”) server. The TM server is programmed to receive a token request for at least one token, generate, upon receiving the token request, the at least one token, wherein the at least one token includes at least one of i) a prepaid token including prepaid funds, ii) multiple tokens each associated with a different user, and iii) a budgeting token associated with a plurality of virtual budget accounts.