Transaction Identifier Credential Exchange for Reduced Data Exposure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic transaction systems expose account credentials to multiple entities, posing security risks and requiring complex secure data management across various systems.
Innovation Solution
A method where a user device transmits a transaction identifier to a server, which generates and transmits account credentials directly to a resource provider, bypassing exposure to the user device, using separate communication channels for account selection and credential transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If account credentials are transmitted through multiple entities (user device, application, routing computers) to enable transaction processing, then transaction functionality is achieved, but security is compromised and data exposure increases
Solution Approach 1:
The patent introduces a transaction identifier as an intermediary element that replaces direct transmission of account credentials. The transaction identifier acts as a mediator between the user device and the resource provider, allowing transaction processing without exposing sensitive account information to intermediate entities or storage in vulnerable locations.
2Adaptability or versatility
If account credentials are stored and handled by multiple entities to facilitate transaction processing, then transaction capability is enabled, but the complexity of secure data management increases
Solution Approach 1:
The patent extracts the sensitive account credential information from the transaction flow and replaces it with a non-sensitive transaction identifier. This removes the burden of secure credential management from multiple entities while maintaining transaction processing capability, as the transaction identifier can be handled without special security measures.
3Ease of operation
If account credentials are transmitted through user device and application to resource provider, then transaction is enabled, but vulnerability to theft and loss increases
Solution Approach 1:
The patent employs a disposable transaction identifier that is generated for each transaction and then discarded. This temporary identifier serves the single purpose of enabling the specific transaction without the long-term security risks associated with storing and reusing account credentials. The transaction identifier is used once and then destroyed, eliminating ongoing vulnerability.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the invention are directed to systems and methods of securely transmitting account credentials, such as a token. A user device and application can initially select an account, and then obtain a transaction identifier associated with the account. The user device can provide the transaction identifier to a resource provider, which can then directly exchange the transaction identifier for the account credentials.