Tokenized Payment Transaction Verification System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securing digital transactions between consumers and organizations are vulnerable to fraud, as they require cardholders to share personal data with merchants, making them susceptible to unauthorized access and theft.

Innovation Solution

A computer-implemented method generates a unique identifier derived from a user's device and payment card, which is recorded on a database, allowing for customer-initiated transactions without sharing personal data with sellers, and uses preprogrammed logic to verify and authorize requests, eliminating the need for third-party input during authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the merchant receives all information from the cardholder, then the transaction can be completed, but the cardholder is vulnerable to fraud and data theft

Engineering Contradiction:
Improvetransaction completionVSAvoidfraud and data theft risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the cardholder's personal information out of the transaction flow. Instead of the merchant receiving cardholder data, the system uses a tokenization approach where only a unique transaction identifier is transmitted to the merchant. The cardholder's sensitive information remains exclusively in the cardholder's possession, eliminating the security vulnerability while maintaining transaction functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary tokenization system that mediates between the cardholder and merchant. The unique identifier generated by the cardholder's device acts as an intermediary element that enables transaction verification without exposing personal data. This intermediary mechanism allows the merchant to verify transaction authenticity without directly handling sensitive cardholder information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a new authentication system is implemented, then security is improved, but the system complexity increases

Engineering Contradiction:
Improvetransaction securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service authentication system where the cardholder's mobile device automatically generates and manages the unique identifier without requiring complex third-party authentication protocols. The device uses its existing secure elements and cryptographic capabilities to autonomously create and protect the transaction token, eliminating the need for additional authentication infrastructure while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent inverts the traditional authentication model by having the cardholder generate and control the verification identifier rather than the merchant or bank generating it. This inversion shifts the security burden to the cardholder's device, which already has robust security measures in place, thereby simplifying the overall system architecture while enhancing security.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS20240127242A1Methods and systems for processing customer-initiated payment transactions
Publication Date: 2024.04.18 HERNANDEZ FR
  • US20240127242A1 patent drawing
  • US20240127242A1 patent drawing
  • US20240127242A1 patent drawing

AI summary

A computer implemented method for processing customer-initiated payment transactions is disclosed. The computer implemented method is to be executed on at least one processor of a first computing device. The computer implemented method includes generating a unique identifier, derived from a second computing device's unique identifier which is associated with a first user and a first user's payment card unique identifier. Said payment card can only be associated with one computing device at a time. The method further includes recording the unique identifier on a connected database having a record keeping system. Once recorded, the method continues with the first computing device, normally in the form of an application, receiving a message to authorize a request. Lastly, the first computing device will utilize its preprogrammed logic to verify the unique identifier and authorize the request. The disclosed method eliminates personal data being shared with sellers during transactions.