Tokenization Payment System Bypasses PCI DSS Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Merchants face significant administrative and compliance costs due to restrictions like PCI DSS, which require them to securely manage and store sensitive payment data, increasing the complexity and expense of payment processing transactions.

Innovation Solution

A secure payment system acts as an intermediary between merchants and payment gateways, allowing merchants to process payments without storing sensitive data by using unique identifiers instead of credit card numbers, thus reducing compliance costs and risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If merchants store sensitive payment data to perform payment processing transactions, then payment processing capability is improved, but compliance costs and security restrictions increase

Engineering Contradiction:
Improvepayment processing capabilityVSAvoidcompliance complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent extracts sensitive payment data (credit card numbers, CVV, expiration dates) from the merchant's system entirely. Instead of storing this data, the system uses tokenization to replace sensitive information with non-sensitive unique identifiers that cannot be reverse-engineered to reveal the original payment data, thereby eliminating PCI DSS compliance requirements while maintaining payment processing capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a payment gateway as an intermediary between the merchant and the payment network. The gateway handles all sensitive data transmission and storage, acting as a mediator that allows the merchant to process payments without directly handling or storing sensitive payment information, thus resolving the contradiction between payment processing capability and compliance complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If merchants implement PCI DSS compliance measures to secure payment data, then data security is improved, but administrative costs and infrastructure expenses increase

Engineering Contradiction:
Improvedata securityVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent employs disposable, single-use tokens that are generated for each payment transaction. These tokens are designed to be used once and then discarded, replacing the need for expensive, long-term security infrastructure required by PCI DSS compliance. The tokens cannot be reverse-engineered and provide equivalent security at a fraction of the cost

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent creates functional copies of payment data in the form of tokens that replicate the ability to process payments without containing the actual sensitive information. These token copies enable payment processing while eliminating the need for expensive security measures, as the tokens themselves are inherently secure by design

Inventive Principle:
Principle #26Copying

3Object-affected harmful factors

If merchants encrypt payment device data to protect from fraudulent activity, then security protection is improved, but administrative overhead and auditing costs increase

Engineering Contradiction:
Improvefraud protectionVSAvoidadministrative time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent extracts the encryption function entirely from the merchant's responsibility. Instead of requiring merchants to implement and manage encryption protocols, the system uses tokenization where sensitive data is replaced with tokens that are inherently secure. This eliminates the need for encryption management, key rotation, and related administrative overhead while maintaining equivalent fraud protection

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9805368B2End-to end secure payment processes
Publication Date: 2017.10.31 PROPAY INC
  • US9805368B2 patent drawing
  • US9805368B2 patent drawing
  • US9805368B2 patent drawing

AI summary

Systems and method for performing secure electronic payment transactions to allow merchants to perform payment processing such that the merchant payment system is not required to store data specific to a particular payment device.