Tokenized Payment System via VPN Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic payment systems are vulnerable to payer account theft as they transmit sensitive information like account numbers and card details along the transaction chain.
Innovation Solution
A distributed payer-controlled payment system architecture that uses a VPN to encrypt transaction information, eliminating the need to transmit payer account data to the merchant, and instead uses a payer token for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If payer account data is transmitted to merchant for electronic transactions, then transaction processing is enabled, but payer account theft vulnerability increases
Solution Approach 1:
The patent extracts sensitive payer account data from the transaction flow. Instead of transmitting account numbers and card details to the merchant, the system uses tokenization where sensitive data is replaced with non-sensitive tokens. The merchant receives only the token and transaction information, never the actual account data, thereby eliminating the vulnerability to account theft while maintaining transaction processing capability.
Solution Approach 2:
The patent introduces an intermediary tokenization layer between the payer and merchant. A token service acts as the intermediary that converts sensitive account information into tokens. The merchant communicates only with the token, not the actual account data. This intermediary mechanism enables transaction processing while preventing direct exposure of sensitive information to the merchant.
2Productivity
If sensitive payer data is stored and transmitted in transaction chain, then payment authorization is completed, but compliance burden on merchant increases
Solution Approach 1:
The patent extracts sensitive payer data from the merchant's environment entirely. By using tokens instead of actual account information, the merchant no longer needs to store, process, or transmit sensitive data. This extraction eliminates PCI-DSS compliance requirements for the merchant while maintaining full payment authorization functionality through the token-based system.
Solution Approach 2:
The patent uses tokens as disposable substitutes for sensitive data. Tokens are non-sensitive, can be freely transmitted and stored without compliance concerns, and can be revoked or replaced if needed. This approach replaces the need for complex security infrastructure and compliance programs with simple, low-cost token handling.
Data Source
AI summary
Herein disclosed are secure digital transaction systems and methods wherein in response to a merchant device receiving a transaction initiation indication comprising a purchase request referencing a payer device, sending an encrypted transaction information message to the payer device from the merchant device using at least a VPN. The encrypted transaction information message may comprise a merchant ID, a security key and transaction information referencing the purchase request, permitting one-touch control of the secured transaction by the payer and eliminating payer account theft along the merchant transaction chain. The payer may subscribe to a service configured to permit the merchant to autonomously push a transaction information message to the payer device. An implementation may advantageously remove sensitive payer data such as account information and/or card numbers from the electronic transaction chain with the merchant, eliminating payer account number theft because there is no payer account data available to be stolen.


