Token Storage Device Provisioning for Contactless Payments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cardholders face security concerns when using physical credit cards or mobile devices for in-store payments due to the risk of data theft from evolving credit card skimmers and data breaches, and existing solutions like encryption do not adequately protect payment credentials during in-store transactions.
Innovation Solution
A token management computing system that generates and provisions secure payment tokens for use on a token storage device, allowing users to set custom controls such as spend limits and expiration dates, and enables contactless payments via EMV chips without magnetic stripes, thereby enhancing security and fraud prevention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If payment tokens are used for in-store transactions via mobile device, then security against data theft is improved, but the ability to use tokens without mobile device is limited
Solution Approach 1:
The system separates the token storage function from the mobile device by introducing a dedicated token storage device (token box) that can hold multiple payment tokens. This segmentation allows tokens to be stored and used independently of any single mobile device, resolving the contradiction between security and versatility.
Solution Approach 2:
The patent introduces an intermediary token storage device that acts as a mediator between the token management system and the point-of-sale terminal. This intermediary enables token usage without requiring the original mobile device, while maintaining security through controlled token provisioning and revocation capabilities.
2Reliability
If encryption is used to protect cardholder data, then data security is improved, but tokenization is cheaper and easier to use
Solution Approach 1:
The system uses tokenization to create simplified copies (tokens) of sensitive cardholder data that can be transmitted and stored without exposing the actual account information. This copying approach provides strong security while being more cost-effective and easier to implement than comprehensive encryption schemes.
Solution Approach 2:
The patent transforms the security approach by changing the parameter from encryption (complex mathematical transformations) to tokenization (substitution with simplified placeholders). This parameter change maintains security effectiveness while reducing implementation complexity and cost.
3Ease of operation
If physical payment cards with magnetic stripes are used, then ease of use is improved, but vulnerability to skimming and data theft increases
Solution Approach 1:
The system employs disposable, single-use payment tokens that can be provisioned on demand and invalidated after use or upon detection of compromise. These short-living tokens replace traditional reusable payment cards, providing ease of use while eliminating the vulnerability to skimming since each token is temporary and can be revoked.
Solution Approach 2:
The patent introduces dynamic token provisioning where payment tokens can be created, updated, and revoked in real-time based on security conditions. This dynamic approach maintains the ease of using physical payment methods while adapting security measures to counter evolving skimming threats.
Data Source
AI summary
A token management computing system for provisioning a payment token to a token storage device for a payment transaction is provided. The token management computing system includes a user computing device in communication with the token storage device and a token management server that includes at least one processor communicatively coupled to a memory device. The at least one processor is programmed to (i) receive, from the user computing device, a token request for a payment token, the request including a payment account number (PAN) selected from a digital wallet stored on the user computing device, and at least one token control, (ii) store token information including the PAN and the at least one token control, (iii) generate a single-use payment token, (iv) transmit the token to the user computing device, and (v) instruct the user computing device to transfer the token to the token storage device.


