Tokenized Payment Linking Across Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Online payment security risks arise from the need to enter sensitive financial information, which can be stolen and used fraudulently, and existing tokenized payment schemes may not adequately protect consumer data during transactions.
Innovation Solution
A computer-implemented method facilitates tokenized payment transactions by using a web browser on a first device to initiate a purchase and link with a second device, such as a mobile device, through a payment agent that generates a unique payment identification code, allowing the payer to authorize transactions without exposing sensitive information to the merchant, using a push payment mechanism that enhances security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a consumer enters sensitive financial information into a computer for online payments, then the transaction can be completed, but the consumer is exposed to security risks of having that information stolen and used fraudulently
Solution Approach 1:
The patent extracts the sensitive financial information from the transaction flow by introducing tokenization. The consumer's actual financial details are replaced with tokens, so the sensitive information never enters the merchant's system. This resolves the contradiction by maintaining transaction completion while removing the security risk of exposing financial information.
Solution Approach 2:
The patent introduces a payment agent as an intermediary between the consumer and merchant. The payment agent handles the sensitive financial information separately from the merchant, using tokens that the merchant cannot use fraudulently. This intermediary structure allows transaction completion while protecting the consumer from security risks.
2Object-affected harmful factors
If a tokenized payment scheme is used to protect sensitive information, then security is improved, but the system complexity increases with multiple devices and authentication steps
Solution Approach 1:
The patent merges the token storage and authentication functions into the consumer's existing mobile device and web browser. Rather than requiring separate hardware tokens or complex multi-device setups, the system uses familiar devices with integrated security features, reducing overall system complexity while maintaining strong information protection.
Solution Approach 2:
The patent performs preliminary actions by pre-configuring the mobile device with the payment agent application and pre-generating tokens before the actual transaction. This preparation work is done once, allowing subsequent transactions to proceed with simpler authentication steps, thereby reducing the perceived complexity for the user.
3Object-affected harmful factors
If the payment agent stores contact details against link tokens for secure communication, then transaction security is enhanced, but the risk of data breaches at the payment agent increases
Solution Approach 1:
The patent extracts the most sensitive information (full contact details) from the payment agent's storage by using link tokens as references instead. The payment agent stores only tokenized references that cannot be used fraudulently, while the actual contact details are stored encrypted or in a more secure location. This reduces the harm potential of any data breach at the payment agent.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention relates to linking of computer devices for performing tokenised payment transactions, for example linking a web browser operating on a first computing device such as a desktop or laptop computer with a mobile computing device such as a smartphone or tablet. This may allow for a payer to shop using a first computing device, but to arrange payment using a second computing device such as a mobile computing device like a smart phone, tablet or similar. The mobile computing device may have an app installed that is used to arrange the tokenised transaction, for example a banking app provided by a financial institution. The banking app may provide enhanced security.