Transaction Token Encryption for Payment Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Entities handling electronic transactions face increased regulatory burdens due to multiple systems processing and storing sensitive information, such as credit card numbers, leading to repetitive compliance issues and high audit costs.

Innovation Solution

A system and method where a first server receives a security token from a client, authenticates the second server, and requests a transaction token from a service provider, encrypting it with the second server's public key, allowing the client to send a request to the second server with an encrypted URL, thereby minimizing the need for sensitive information to be stored or processed by the first server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple systems are deployed for electronic commerce transactions, then service coverage and functionality are improved, but regulatory compliance burden and audit costs increase

Engineering Contradiction:
Improveservice coverageVSAvoidregulatory compliance burden
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts sensitive information handling from multiple commerce applications and centralizes it in a single payment processing server. This allows multiple service deployments without multiplying compliance burdens, as only the centralized server requires full PCI DSS compliance while client systems can operate with reduced compliance requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a centralized payment processing server as an intermediary between clients and service providers. This intermediary handles all sensitive information processing, allowing multiple service systems to coexist while consolidating regulatory compliance responsibilities to a single controlled entity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If sensitive information is processed and stored locally in multiple systems, then transaction processing capability is improved, but security risk and regulatory audit scope increase

Engineering Contradiction:
Improvetransaction processing capabilityVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive information processing from client systems and relocates it to a centralized payment processing server. Clients can maintain full transaction processing functionality while the actual handling of sensitive data occurs only on the secure centralized server, reducing both security risks and audit scope.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses tokenization where sensitive information is replaced with non-sensitive tokens in client systems. These tokens can be processed locally without compromising security, as they cannot be used to access actual sensitive data which remains stored only on the centralized secure server.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If each system stores sensitive information independently, then system autonomy and functionality are improved, but compliance cost and regulatory burden multiply

Engineering Contradiction:
Improvesystem autonomyVSAvoidcompliance cost
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent merges sensitive information storage and processing across multiple autonomous systems into a single centralized location. Each system maintains its operational autonomy and functionality, but the compliance burden is consolidated to one system rather than multiplying across all systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized payment processing server provides universal payment processing functionality that serves multiple client systems. This single multi-functional system handles compliance requirements for all connected services, eliminating the need for each system to independently implement full compliance measures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9577991B2System and method for processing transactions
Publication Date: 2017.02.21 CANON USA INC
  • US9577991B2 patent drawing
  • US9577991B2 patent drawing
  • US9577991B2 patent drawing

AI summary

Embodiments of the invention include methods, systems, and computer-readable media for processing transactions involving sensitive information, such as a credit card number. Embodiments include a first server authenticating a second server based on a security token and determining whether the security token is expired. Based on the results, the first server may request a transaction token associated with sensitive information. The first server may encrypt the transaction token using a public key of the second server. The first server may send the encrypted transaction token as a parameter to a URL, wherein the URL is configured to cause a browser on a client to send, to the second server, a request for the page and the encrypted transaction token.