Token Transfer Device Security via Tokenization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile electronic transaction systems face significant security challenges due to the distribution, storage, and usage of actual account data, particularly in mobile device payments, which are not adequately addressed by traditional magnetic stripe card technologies and early mobile payment solutions.

Innovation Solution

A method for processing transactions using a token transfer device, such as a smartphone, where transaction tokens with specified resource values and validation parameters are stored and managed, enabling secure online or offline mobile device payments through a network-accessible transaction resource, utilizing a token state manager to determine events and issue transaction modification calls based on connectivity and condition register data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional magnetic stripe card technologies are used for mobile electronic transactions, then the system is simple and easy to implement, but security is insufficient and account data is vulnerable to data breaches

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses tokenization to create a copy of the account data (token) that is stored on the mobile device instead of the actual sensitive account information. The token is a placeholder that maps to the real account data through a secure vault, allowing transactions to proceed without exposing the actual account data, thus improving security while maintaining system functionality.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a token as an intermediary between the mobile device and the actual account data. The token serves as a mediator that enables transactions to occur without directly exposing the sensitive account information. The token is validated and processed by the system, and only if valid does it reveal the actual account data to be charged, thus protecting security while enabling transaction functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If actual account data is stored and transferred in mobile payment systems, then transaction processing is straightforward, but security risks increase due to data distribution and storage vulnerabilities

Engineering Contradiction:
Improvetransaction processing efficiencyVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the transfer of actual account data with the transfer of tokens. The token is a simplified copy that contains only the necessary transaction information and validates against stored parameters, enabling efficient transaction processing without the security risks associated with transferring and storing sensitive account data across multiple systems.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent extracts the sensitive account data from the transaction flow and stores it securely in a vault, separate from the transaction processing. Only the token, which is a non-sensitive reference to the account data, is used during transactions. This extraction removes the harmful factor of exposed account data while maintaining the ability to process transactions efficiently.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If validation parameters are stored with tokens in mobile devices, then transaction security is improved, but device memory requirements and data management complexity increase

Engineering Contradiction:
Improvetransaction securityVSAvoiddata management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the validation parameters into distinct fields within the token structure, separating the token identifier, the validation parameters (such as expiration dates, usage limits), and the mapping to actual account data. This segmentation allows for organized storage and efficient retrieval of validation information without requiring complex data management structures, thus improving security while controlling data management complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11042875B2Client-side security for tokenized transactions
Publication Date: 2021.06.22 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11042875B2 patent drawing
  • US11042875B2 patent drawing
  • US11042875B2 patent drawing

AI summary

Embodiments include a method for configuring a token transfer device for electronic transactions. The method can include requesting, by a token transfer device, one or more tokens having specified transaction exchange value; receiving, over a network, the one or more tokens; assigning, by the token transfer device, validation parameters indicating conditions under which the one or more tokens will be accepted in a transaction; determining, by the token transfer device, that one or more of the conditions have been met based on data provided by electronic components of the token transfer device; and initiating the transaction with a point of sale system.