Tokenization via Authorization Rails
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mechanisms for obtaining tokens for transactions are limited, as they often require wireless communication connectivity, which can be unavailable in certain areas, leading to incomplete transactions or the use of sensitive information.
Innovation Solution
A method and system for obtaining tokens through alternative communication channels, such as authorization rails, allowing payment devices and mobile devices to request and receive payment tokens even without direct wireless communication with the tokenization computer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If wireless communication connectivity is required to obtain tokens over the air, then token security is improved, but transaction availability deteriorates in areas without wireless coverage
Solution Approach 1:
The patent introduces an access device as an intermediary between the mobile device and the tokenization computer. The access device receives token requests from mobile devices and forwards them to the tokenization computer via authorization rails, enabling token retrieval without direct wireless communication between the mobile device and tokenization computer.
Solution Approach 2:
The patent enables multiple communication pathways for token retrieval: traditional over-the-air wireless communication and alternative routing through access devices using authorization rails. This multi-functionality ensures tokens can be obtained regardless of wireless coverage availability.
2Adaptability or versatility
If tokens are obtained through alternative communication channels, then transaction availability is improved, but communication security may deteriorate
Solution Approach 1:
The access device serves as a secure intermediary that already has established communication channels with the tokenization computer through authorization rails. These channels inherit the security protocols of the existing authorization infrastructure, maintaining security while enabling alternative communication paths.
Solution Approach 2:
The patent uses the existing authorization message format and communication protocols as a template for token requests. By copying the established secure authorization channel structure, the system leverages proven security mechanisms rather than creating new vulnerable communication paths.
3Reliability
If tokens are retrieved only when needed during transactions, then security against token compromise is improved, but transaction processing time may increase
Solution Approach 1:
The system performs preliminary validation and token generation preparation through the access device before the actual transaction completes. The token is retrieved and validated in advance through the authorization rail channel, so when the transaction proceeds, the token is already ready for use, minimizing actual transaction delay.
Solution Approach 2:
The mobile device autonomously requests and retrieves tokens through the access device without requiring manual intervention or pre-provisioning. The system self-manages the token lifecycle, retrieving tokens on-demand only when transactions are initiated, balancing security with efficient processing.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the invention are directed to a method for submitting a tokenization request via an access device. Embodiments allow tokens to be retrieved for complex mobile devices as well as basic card-type devices. Token requests can be formatted as authorization request messages and transmitted along authorization communication channels.