Triple-Blind Payment System Using Segmented Data Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile payment systems face security concerns due to the centralization of customer data, making them vulnerable to unauthorized access and identity theft, which limits adoption and convenience.
Innovation Solution
A 'triple-blind' payment system is implemented where customer identity and payment instrument data are distributed among multiple unrelated parties, with none possessing both identity and payment information, using a server-based method that generates and transmits a code readable by a merchant device, facilitating secure transactions without storing sensitive data centrally.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If customer data is stored centrally in existing mobile payment systems, then transaction processing is simplified, but security is compromised due to vulnerability to unauthorized access and identity theft
Solution Approach 1:
The patent segments customer data into two distinct parts: identity information stored by the identity manager and payment instrument information stored by the payment processor. This segmentation ensures that no single entity possesses both identity and payment information, preventing spoofing and identity theft while maintaining transaction processing capability through the coordinated interaction of these segmented data stores.
2Reliability
If customer identity and payment information are distributed among multiple unrelated parties, then security is enhanced, but system complexity increases
Solution Approach 1:
The patent introduces a token as an intermediary element that bridges the segmented data stores. The token, generated by the payment processor and associated with the customer's identity, enables transaction processing without requiring any single party to possess both identity and payment information. This intermediary mechanism simplifies the interaction between distributed data stores while maintaining security.
3Productivity
If a central store of sensitive data is maintained, then transaction authorization is streamlined, but vulnerability to hacking and data theft increases
Solution Approach 1:
The patent divides the centralized data store into separate identity information stored by the identity manager and payment instrument information stored by the payment processor. This segmentation eliminates the single point of failure that exists in centralized storage, as hackers would need to compromise multiple independent entities simultaneously to obtain both identity and payment information.
Solution Approach 2:
The patent extracts payment instrument information from the identity management system and places it in a separate payment processor system. This extraction removes the vulnerable centralized data store containing both identity and payment information, while maintaining transaction authorization efficiency through the token-based verification process that queries both segmented stores.
Data Source
AI summary
Representative embodiments of a server-based method of facilitating payment by a user registered with the server include, at the server, generating and storing, for the user, a code readable by a merchant device, transmitting the code to a mobile device of the user, facilitating provision of information characterizing a payment instrument from the user to a payment-processing entity without storing the data at the server, receiving, from the payment-processing entity, a token indicative of the payment instrument but not encoding data that would enable use of the instrument, associating the token with the user, receiving, from a merchant, the code and a payment amount, matching the received code to the user and retrieving the token associated with the user, and providing the token and the payment amount to the payment-processing entity to facilitate completion of a transaction between the user and the merchant.


