Transaction Identifier Credential Exchange for Reduced Data Exposure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic transaction systems expose account credentials to multiple entities, posing security risks and requiring complex secure data management across various systems.

Innovation Solution

A method where a user device transmits a transaction identifier to a server, which generates and transmits account credentials directly to a resource provider, bypassing exposure to the user device, using separate communication channels for account selection and credential transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If account credentials are transmitted through multiple entities (user device, application, routing computers) to enable transaction processing, then transaction functionality is achieved, but security is compromised and data exposure increases

Engineering Contradiction:
Improvetransaction securityVSAvoiddata exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a transaction identifier as an intermediary element that replaces direct transmission of account credentials. The transaction identifier acts as a mediator between the user device and the resource provider, allowing transaction processing without exposing sensitive account information to intermediate entities or storage in vulnerable locations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If account credentials are stored and handled by multiple entities to facilitate transaction processing, then transaction capability is enabled, but the complexity of secure data management increases

Engineering Contradiction:
Improvetransaction processing capabilityVSAvoidsecure data management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the sensitive account credential information from the transaction flow and replaces it with a non-sensitive transaction identifier. This removes the burden of secure credential management from multiple entities while maintaining transaction processing capability, as the transaction identifier can be handled without special security measures.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If account credentials are transmitted through user device and application to resource provider, then transaction is enabled, but vulnerability to theft and loss increases

Engineering Contradiction:
Improvetransaction convenienceVSAvoidtheft and loss risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent employs a disposable transaction identifier that is generated for each transaction and then discarded. This temporary identifier serves the single purpose of enabling the specific transaction without the long-term security risks associated with storing and reusing account credentials. The transaction identifier is used once and then destroyed, eliminating ongoing vulnerability.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentEP3652694B1Systems and methods for using a transaction identifier to protect sensitive credentials
Publication Date: 2025.09.10 VISA INTERNATIONAL SERVICE ASSOCIATION
  • EP3652694B1 patent drawingFigure 1
  • EP3652694B1 patent drawingFigure 2
  • EP3652694B1 patent drawingFigure 3

AI summary

Embodiments of the invention are directed to systems and methods of securely transmitting account credentials, such as a token. A user device and application can initially select an account, and then obtain a transaction identifier associated with the account. The user device can provide the transaction identifier to a resource provider, which can then directly exchange the transaction identifier for the account credentials.