Tokenized Payment System via VPN Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic payment systems are vulnerable to payer account theft as they transmit sensitive information like account numbers and card details along the transaction chain.

Innovation Solution

A distributed payer-controlled payment system architecture that uses a VPN to encrypt transaction information, eliminating the need to transmit payer account data to the merchant, and instead uses a payer token for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If payer account data is transmitted to merchant for electronic transactions, then transaction processing is enabled, but payer account theft vulnerability increases

Engineering Contradiction:
Improvetransaction processingVSAvoidpayer account theft vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive payer account data from the transaction flow. Instead of transmitting account numbers and card details to the merchant, the system uses tokenization where sensitive data is replaced with non-sensitive tokens. The merchant receives only the token and transaction information, never the actual account data, thereby eliminating the vulnerability to account theft while maintaining transaction processing capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary tokenization layer between the payer and merchant. A token service acts as the intermediary that converts sensitive account information into tokens. The merchant communicates only with the token, not the actual account data. This intermediary mechanism enables transaction processing while preventing direct exposure of sensitive information to the merchant.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If sensitive payer data is stored and transmitted in transaction chain, then payment authorization is completed, but compliance burden on merchant increases

Engineering Contradiction:
Improvepayment authorizationVSAvoidcompliance burden
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent extracts sensitive payer data from the merchant's environment entirely. By using tokens instead of actual account information, the merchant no longer needs to store, process, or transmit sensitive data. This extraction eliminates PCI-DSS compliance requirements for the merchant while maintaining full payment authorization functionality through the token-based system.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses tokens as disposable substitutes for sensitive data. Tokens are non-sensitive, can be freely transmitted and stored without compliance concerns, and can be revoked or replaced if needed. This approach replaces the need for complex security infrastructure and compliance programs with simple, low-cost token handling.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS12211044B2Secure one-touch transaction system and method
Publication Date: 2025.01.28 KUBERA LLC
  • US12211044B2 patent drawing
  • US12211044B2 patent drawing
  • US12211044B2 patent drawing

AI summary

Herein disclosed are secure digital transaction systems and methods wherein in response to a merchant device receiving a transaction initiation indication comprising a purchase request referencing a payer device, sending an encrypted transaction information message to the payer device from the merchant device using at least a VPN. The encrypted transaction information message may comprise a merchant ID, a security key and transaction information referencing the purchase request, permitting one-touch control of the secured transaction by the payer and eliminating payer account theft along the merchant transaction chain. The payer may subscribe to a service configured to permit the merchant to autonomously push a transaction information message to the payer device. An implementation may advantageously remove sensitive payer data such as account information and/or card numbers from the electronic transaction chain with the merchant, eliminating payer account number theft because there is no payer account data available to be stolen.