Trusted Tokenization Service Provider for Secure Transaction Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data security methods fail to effectively protect sensitive data elements during transactions over open telecommunications networks, as tokens used for security can be reversed back to real data through direct attacks or other means, compromising security.

Innovation Solution

A system and method where a trusted tokenization service provider generates and correlates tokens with sensitive data elements, ensuring that only tokens are used for transactions, and the real data remains secure, with strict controls to prevent unauthorized access or reversal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If tokens are used to replace sensitive data elements in transactions, then security is improved, but tokens can be reversed back to real data through direct attacks

Engineering Contradiction:
Improvedata securityVSAvoidtoken reversal attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the sensitive data protection into multiple independent components: a tokenization service provider that generates tokens, a correlation database that stores token-real data mappings, and transaction processing systems that use tokens. This segmentation ensures that no single component has access to both tokens and their corresponding real data, preventing token reversal attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trusted tokenization service provider as an intermediary between the sensitive data and the transaction processing systems. This intermediary generates tokens, manages the correlation database, and controls the decryption process. The intermediary architecture ensures that tokens cannot be directly reversed without accessing the secured correlation database through authorized channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If tokens are correlated with sensitive data elements in a centralized database, then token functionality is improved, but the centralized database becomes a single point of failure and attack target

Engineering Contradiction:
Improvetoken managementVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The correlation database is segmented into distributed storage units across multiple secure locations. Each segment contains only specific token-real data correlations, and access to any single segment is insufficient to compromise the entire system. This distributed segmentation reduces the single point of failure risk while maintaining centralized management capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different segments of the correlation database are distributed to different trusted parties or locations, each with specific access rights. This local quality assignment ensures that even if one location is compromised, other locations remain secure and can continue to function. Each local segment has the specific quality of being accessible only to authorized entities with appropriate credentials.

Inventive Principle:
Principle #3Local quality

3Productivity

If real data is decrypted from tokens during transaction processing, then transaction functionality is improved, but sensitive data exposure increases

Engineering Contradiction:
Improvetransaction processingVSAvoiddata exposure risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

Sensitive data is pre-encrypted and tokenized before being stored in the correlation database. This preliminary action ensures that the real data never exists in plaintext form during transmission or storage. When transactions require the data, the decryption process occurs only in controlled, secured environments with strict access controls, minimizing exposure time and risk.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the decryption function from the general transaction processing system and places it in a dedicated, secured decryption environment. This extraction ensures that even when real data must be accessed for transaction processing, it occurs in an isolated, monitored environment with enhanced security controls, minimizing the risk of unauthorized exposure.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11429965B2System and method for tokenization
Publication Date: 2022.08.30 CARDINALCOMMERCE CORP
  • US11429965B2 patent drawing
  • US11429965B2 patent drawing
  • US11429965B2 patent drawing

AI summary

A method for obscuring a value of a sensitive data element includes: (a) receiving the sensitive data element, the sensitive data element being received over a data communications network (110) at a hardware computing device (142) of a trusted tokenization service provider (140); (b) generating a token corresponding to the received sensitive data element; (c) storing the token and sensitive data element in a memory device (146) such that they are correlated with one another; (d) providing the generated token to a first party (130) that uses the token in place of the sensitive data element in a request for authorization to complete a transaction, the request being sent from the first party (130); (e) intercepting the request for authorization including the token; (f) using the token contained in the intercepted request to look-up and retrieve the correlated sensitive data element in the memory device (160); (g) replacing the token contained in the request with the sensitive data element retrieved from the memory device (160); and (h) forwarding the request containing the sensitive data element to a second party (160 and/or 162) which employs the sensitive data element to determine whether completion of the transaction should be authorized or declined.