Transaction Privacy Control via Mask Labels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing payment networks lack effective mechanisms for cardholders to control the privacy of their transaction data, leading to potential misuse by service providers.

Innovation Solution

A computer-implemented method and system that allows cardholders to assign privacy labels to payment transactions, enabling them to mask specific data fields and control the disclosure of transaction data to third parties.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If service providers access transaction data through open banking APIs, then they can provide valuable financial services and insights, but cardholder privacy is compromised and transaction data can be misused

Engineering Contradiction:
Improveservice provision capabilityVSAvoidprivacy violation
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments transaction data into different types (e.g., merchant category, amount, location, time) and applies different privacy protection levels to each segment. This allows service providers to access necessary data for providing services while protecting sensitive information, resolving the contradiction between service capability and privacy protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements differential privacy protection for different cardholders and different data fields based on their privacy preferences and sensitivity. Each cardholder can specify which data fields should be protected and to what extent, allowing personalized privacy control while enabling service provision where appropriate.

Inventive Principle:
Principle #3Local quality

2Loss of information

If comprehensive transaction data is shared with service providers, then better financial insights and services can be provided, but the risk of data misuse and advertising abuse increases

Engineering Contradiction:
Improveinformation utilityVSAvoiddata misuse risk
Core Design Contradiction:
Loss of informationVSObject-generated harmful factors

Solution Approach 1:

The patent extracts and removes sensitive information from transaction data before sharing it with service providers. By taking out personally identifiable information and sensitive details while retaining transaction patterns and categories, the system maintains information utility for financial insights while eliminating the basis for data misuse and targeted advertising abuse.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a privacy-preserving intermediary layer between the cardholder's transaction data and service providers. This intermediary processes and anonymizes data according to privacy policies, allowing service providers to receive useful transaction insights without accessing raw sensitive data, thus preventing misuse while maintaining service quality.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If consent mechanisms are implemented through term and service agreements, then legal compliance is achieved, but cardholders cannot provide granular control over their transaction data

Engineering Contradiction:
Improvelegal complianceVSAvoiduser control capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent transforms static consent agreements into dynamic, real-time privacy controls. Cardholders can adjust their privacy preferences for each transaction or data type on-demand, allowing granular control over which data is shared and with whom, while the system automatically ensures compliance with selected preferences, combining legal reliability with operational ease.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent empowers cardholders to self-manage their own privacy settings and data sharing preferences without requiring legal intermediaries or complex agreement negotiations. Users can directly control which transaction data fields are shared, with whom, and under what conditions, making privacy management simple and intuitive while maintaining compliance.

Inventive Principle:
Principle #25Self-service

4Productivity

If all transaction data is collected at once by service providers, then comprehensive analysis is possible, but cardholders lose the ability to control data disclosure at individual transaction levels

Engineering Contradiction:
Improvedata analysis efficiencyVSAvoidgranular privacy control
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent applies privacy masking and anonymization to transaction data at the point of transaction occurrence, before the data is collected or aggregated by service providers. This preliminary privacy protection ensures that even comprehensive data collection cannot violate privacy, as sensitive information has already been protected at the source, enabling both efficient analysis and granular control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments transaction data collection and processing into discrete, controllable units at the transaction level. Each transaction can be independently evaluated against privacy policies, allowing cardholders to grant or deny access on a per-transaction basis while service providers can still aggregate and analyze the data efficiently for comprehensive insights.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250053971A1Methods and systems for transaction level privacy control
Publication Date: 2025.02.13 MASTERCARD INT INC
  • US20250053971A1 patent drawing
  • US20250053971A1 patent drawing
  • US20250053971A1 patent drawing

AI summary

Embodiments provide methods and systems for assigning privacy labels to payment transactions. The method performed by a system includes receiving user input for masking a subset of data fields of a plurality of data fields in transaction data of the payment transaction performed within a pre-defined time period of occurrence of the payment transaction. The method includes assigning a mask label to the subset of data fields in the transaction data. Upon receiving a transaction insight request for the payment transaction from a third party server, the method includes determining whether the mask label is assigned to the subset of data fields. The method includes generating masked transaction data for the payment transaction based, at least in part, on masking the subset of data fields associated with the payment transaction in the transaction data. The method includes facilitating the transfer of the masked transaction data to the third party server.