Tokenized Transactional Identity Framework for PII Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional transactional models are vulnerable to malicious attacks, exposing critical personal information due to their attack surfaces and reliance on symmetric or asymmetric cryptography, which fails to adequately secure electronic transactions.
Innovation Solution
A novel transaction identity framework that generates and utilizes tokenized identifiers, leveraging existing credit bureau infrastructure, to provide an additional security layer for transactional operations, ensuring secure processing and storage of personally identifiable information (PII) while facilitating electronic transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If symmetric or asymmetric cryptography is applied to protect user information, then data confidentiality is improved, but vulnerability to malicious attacks worsens due to exposed keys
Solution Approach 1:
The patent extracts and removes personally identifiable information (PII) from the transactional model by replacing it with tokenized identifiers. This extraction eliminates the exposure of sensitive data while maintaining the ability to process transactions, directly addressing the vulnerability caused by relying on cryptographic keys that must be exposed for transactions to occur.
Solution Approach 2:
The patent introduces tokenized identifiers as an intermediary between the user's actual PII and the transactional system. These tokens act as mediators that enable transaction processing without requiring the exposure of sensitive information or cryptographic keys, thereby resolving the contradiction between data protection and transactional functionality.
2Reliability
If tokenized identifiers are implemented to eliminate PII exposure, then security against malicious attacks is improved, but system complexity worsens due to additional security layers
Solution Approach 1:
The patent creates a universal tokenization framework that can be applied across multiple transaction types and systems. The tokenized identifier system serves multiple functions including authentication, authorization, and data protection, thereby reducing overall system complexity despite the introduction of new security mechanisms.
Solution Approach 2:
The patent performs preliminary tokenization of identifiers before transactions occur. By pre-replacing PII with tokens and establishing the mapping relationships in advance, the system eliminates the need for complex real-time cryptographic operations during transactions, thereby reducing operational complexity while maintaining security.
3Object-affected harmful factors
If PII is eliminated from transactional models, then vulnerability to attacks is reduced, but ability to process identity-related transactions worsens
Solution Approach 1:
The patent creates cryptographic copies of PII in the form of tokenized identifiers that preserve the essential functionality needed for identity-related transactions. These tokens contain sufficient information to enable authentication and authorization operations without exposing the actual PII, thereby maintaining transactional capability while eliminating vulnerability.
Solution Approach 2:
The patent transforms the parameter representation from raw PII to tokenized identifiers through a mathematical transformation process. This parameter change maintains the functional properties needed for transactions (such as uniqueness and verifiability) while eliminating the security risks associated with exposing actual personal information.
Data Source
AI summary
Disclosed are systems, servers and methods for a novel, multifactor-token based framework for securely executing electronic transactions while protecting user and transactional data related to and/or communicated during the transactions. The disclosed systems and methods enable an on-demand multifactor token to be generated for electronic transactions, whereby the tokens can be specific to a type of transaction, a type of entity and/or other party involved, and the like. The disclosed tokens can be relayed between users and the parties they are interacting with rather than personally identifiable information, which ensures a user's data is securely maintained and prevented from undesired exposure on a network.


