Tokenization via Authorization Rails

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mechanisms for obtaining tokens for transactions are limited, as they often require wireless communication connectivity, which can be unavailable in certain areas, leading to incomplete transactions or the use of sensitive information.

Innovation Solution

A method and system for obtaining tokens through alternative communication channels, such as authorization rails, allowing payment devices and mobile devices to request and receive payment tokens even without direct wireless communication with the tokenization computer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If wireless communication connectivity is required to obtain tokens over the air, then token security is improved, but transaction availability deteriorates in areas without wireless coverage

Engineering Contradiction:
Improvetoken securityVSAvoidtransaction availability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an access device as an intermediary between the mobile device and the tokenization computer. The access device receives token requests from mobile devices and forwards them to the tokenization computer via authorization rails, enabling token retrieval without direct wireless communication between the mobile device and tokenization computer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent enables multiple communication pathways for token retrieval: traditional over-the-air wireless communication and alternative routing through access devices using authorization rails. This multi-functionality ensures tokens can be obtained regardless of wireless coverage availability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If tokens are obtained through alternative communication channels, then transaction availability is improved, but communication security may deteriorate

Engineering Contradiction:
Improvetransaction availabilityVSAvoidcommunication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The access device serves as a secure intermediary that already has established communication channels with the tokenization computer through authorization rails. These channels inherit the security protocols of the existing authorization infrastructure, maintaining security while enabling alternative communication paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses the existing authorization message format and communication protocols as a template for token requests. By copying the established secure authorization channel structure, the system leverages proven security mechanisms rather than creating new vulnerable communication paths.

Inventive Principle:
Principle #26Copying

3Reliability

If tokens are retrieved only when needed during transactions, then security against token compromise is improved, but transaction processing time may increase

Engineering Contradiction:
Improvesecurity against token compromiseVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary validation and token generation preparation through the access device before the actual transaction completes. The token is retrieved and validated in advance through the authorization rail channel, so when the transaction proceeds, the token is already ready for use, minimizing actual transaction delay.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mobile device autonomously requests and retrieves tokens through the access device without requiring manual intervention or pre-provisioning. The system self-manages the token lifecycle, retrieving tokens on-demand only when transactions are initiated, balancing security with efficient processing.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3224784B1Tokenization request via access device
Publication Date: 2025.02.19 VISA INTERNATIONAL SERVICE ASSOCIATION
  • EP3224784B1 patent drawingFigure 1
  • EP3224784B1 patent drawingFigure 2
  • EP3224784B1 patent drawingFigure 3

AI summary

Embodiments of the invention are directed to a method for submitting a tokenization request via an access device. Embodiments allow tokens to be retrieved for complex mobile devices as well as basic card-type devices. Token requests can be formatted as authorization request messages and transmitted along authorization communication channels.