Tokenization Service for Secure PII Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Individuals face a challenge in transmitting personally identifiable information (PII) while protecting it from unauthorized access, as existing encryption methods do not adequately safeguard the information throughout the entire transmission process, including input and storage on personal devices.

Innovation Solution

A system and method using tokenization, where a user's financial institution maps a primary account number to a digital token, which is used to convey encrypted PII, ensuring that only the financial institution possesses the PII until it is authorized for access by a third party, thereby preventing open transmission and unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption keys are provided to users to encrypt their PII, then protection against interception is improved, but the user's device and input process remain vulnerable to unauthorized access

Engineering Contradiction:
Improveprotection against interceptionVSAvoidvulnerability of user device and input process
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a tokenization service as an intermediary between the user and the PII transmission process. The service replaces the traditional encryption key distribution model with a token-based system where the user receives a token that can be exchanged for encrypted PII only when needed, eliminating the need to provide encryption keys to the user's device while maintaining security throughout the entire transmission process

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If users directly input and store PII on their personal devices, then ease of operation is improved, but security and protection from unauthorized access deteriorate

Engineering Contradiction:
Improveease of PII input and storageVSAvoidunauthorized access and data theft
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the PII storage function from the user's personal device and relocates it to a secure tokenization service. Users no longer store PII locally but instead receive encrypted PII only when needed through the token exchange mechanism, eliminating the security risks associated with storing sensitive information on personal devices while maintaining operational convenience

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If PII is transmitted in clear text for business purposes, then ease of operation and data accessibility are improved, but security and protection from interception deteriorate

Engineering Contradiction:
Improvedata accessibility for businessVSAvoidinterception and unauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary tokenization before any PII transmission occurs. The tokenization service pre-processes the PII by replacing it with tokens that can be exchanged for encrypted data only when authorized, ensuring that PII is never transmitted in clear text while maintaining business accessibility through the token exchange mechanism

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10839385B2Method and system for personally identifiable information
Publication Date: 2020.11.17 MASTERCARD INT INC
  • US10839385B2 patent drawing
  • US10839385B2 patent drawing
  • US10839385B2 patent drawing

AI summary

A method for subverting open transmission of personally identifiable information through the use of tokenization includes: receiving a token request from an issuing financial institution; identifying a digital token; mapping the identified digital token to a primary account number; transmitting the identified digital token to the issuing financial institution; receiving a data request from a third party, wherein the data request includes the identified digital token; replacing the identified digital token in the data request with the mapped primary account number; transmitting the data request including the mapped primary account number to the issuing financial institution; receiving a data package including one or more items of personally identifiable information; and forwarding the data package.