Transaction Token Encryption for Payment Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Entities handling electronic transactions face increased regulatory burdens due to multiple systems processing and storing sensitive information, such as credit card numbers, leading to repetitive compliance issues and high audit costs.
Innovation Solution
A system and method where a first server receives a security token from a client, authenticates the second server, and requests a transaction token from a service provider, encrypting it with the second server's public key, allowing the client to send a request to the second server with an encrypted URL, thereby minimizing the need for sensitive information to be stored or processed by the first server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple systems are deployed for electronic commerce transactions, then service coverage and functionality are improved, but regulatory compliance burden and audit costs increase
Solution Approach 1:
The patent extracts sensitive information handling from multiple commerce applications and centralizes it in a single payment processing server. This allows multiple service deployments without multiplying compliance burdens, as only the centralized server requires full PCI DSS compliance while client systems can operate with reduced compliance requirements.
Solution Approach 2:
The patent introduces a centralized payment processing server as an intermediary between clients and service providers. This intermediary handles all sensitive information processing, allowing multiple service systems to coexist while consolidating regulatory compliance responsibilities to a single controlled entity.
2Productivity
If sensitive information is processed and stored locally in multiple systems, then transaction processing capability is improved, but security risk and regulatory audit scope increase
Solution Approach 1:
The patent extracts sensitive information processing from client systems and relocates it to a centralized payment processing server. Clients can maintain full transaction processing functionality while the actual handling of sensitive data occurs only on the secure centralized server, reducing both security risks and audit scope.
Solution Approach 2:
The patent uses tokenization where sensitive information is replaced with non-sensitive tokens in client systems. These tokens can be processed locally without compromising security, as they cannot be used to access actual sensitive data which remains stored only on the centralized secure server.
3Adaptability or versatility
If each system stores sensitive information independently, then system autonomy and functionality are improved, but compliance cost and regulatory burden multiply
Solution Approach 1:
The patent merges sensitive information storage and processing across multiple autonomous systems into a single centralized location. Each system maintains its operational autonomy and functionality, but the compliance burden is consolidated to one system rather than multiplying across all systems.
Solution Approach 2:
The centralized payment processing server provides universal payment processing functionality that serves multiple client systems. This single multi-functional system handles compliance requirements for all connected services, eliminating the need for each system to independently implement full compliance measures.
Data Source
AI summary
Embodiments of the invention include methods, systems, and computer-readable media for processing transactions involving sensitive information, such as a credit card number. Embodiments include a first server authenticating a second server based on a security token and determining whether the security token is expired. Based on the results, the first server may request a transaction token associated with sensitive information. The first server may encrypt the transaction token using a public key of the second server. The first server may send the encrypted transaction token as a parameter to a URL, wherein the URL is configured to cause a browser on a client to send, to the second server, a request for the page and the encrypted transaction token.


