Universal Token Orchestration for Multi-Provider Sensitive Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data encryption techniques and security measures, such as PCI DSS, HIPAA, and ISO-27001, pose challenges for businesses in efficiently storing, processing, and transferring sensitive data while ensuring compliance, leading to rigid systems with single points of failure and lock-in to a single provider.

Innovation Solution

A transaction orchestration system that includes a storage coordinator, vault, aliased card coordinator, unified transaction orchestration library, and transaction orchestrator, which dynamically manages sensitive data storage and processing, ensuring compliance by generating aliased data and facilitating transactions across multiple providers, even in the absence of a secure connection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current data encryption techniques and security measures (PCI DSS, HIPAA, ISO-27001) are implemented, then data security is improved, but system rigidity and single point of failure increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments sensitive data into multiple components: original data is stored in a vault, while tokenized representations are distributed across multiple transaction processing systems. This segmentation allows each component to be independently managed and accessed, reducing the impact of failures in any single system while maintaining security through the vault's controlled access model.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a tokenization intermediary layer that sits between the vault and transaction processing systems. This intermediary converts sensitive data into tokens, allowing transaction systems to process data without directly accessing the original sensitive information. The intermediary enables flexible transaction processing while the vault maintains secure storage, resolving the contradiction between security rigidity and system versatility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a single provider is used for data storage and processing, then compliance with security standards is improved, but lock-in to a single provider and single point of failure occur

Engineering Contradiction:
ImprovecomplianceVSAvoidmulti-provider capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The tokenization framework provides universal functionality that works across multiple transaction processing providers and systems. The token standard is designed to be provider-agnostic, allowing the same tokenized data to be processed by different transaction systems without requiring provider-specific implementations. This universality enables organizations to work with multiple providers while maintaining a single compliant vault, eliminating lock-in while preserving compliance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent extracts the compliance-critical functions (secure storage, access control, audit logging) into a dedicated vault component that can be provided by a single compliant provider. Meanwhile, the transaction processing functions are separated and can be distributed across multiple providers. This extraction allows the system to maintain strict compliance through the vault while gaining flexibility in transaction processing through multiple providers.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If sensitive data is stored and processed in a centralized manner, then security control is improved, but latency and availability decrease

Engineering Contradiction:
Improvesecurity controlVSAvoidtransaction latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary tokenization of sensitive data before transaction processing begins. The vault pre-processes data into tokens and stores them ready for quick retrieval. During transaction processing, systems exchange tokens rather than accessing the original sensitive data, eliminating the need for real-time encryption/decryption operations. This preliminary action reduces transaction latency while maintaining security control through the vault's managed token lifecycle.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates tokenized copies of sensitive data that can be freely distributed and processed across multiple systems without compromising security. These token copies contain all necessary transaction information but cannot be reverse-engineered to reveal the original sensitive data. This copying approach allows parallel processing across multiple systems, reducing latency, while the vault maintains security control over the original data and token issuance.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20260081897A1Systems and methods for sensitive data transaction orchestration
Publication Date: 2026.03.19 BASIS THEORY INC
  • US20260081897A1 patent drawing
  • US20260081897A1 patent drawing
  • US20260081897A1 patent drawing

AI summary

Systems and methods are described for securely processing transactions including the transfer of sensitive data. In some cases, a universal token representative of sensitive data may be generated by a transaction orchestration service, where the universal token includes one or more aliased data sets and metadata corresponding to the underlying sensitive data. In some cases, the aliased data sets include representations of the sensitive data without including the sensitive data. A transaction request that invokes the universal token may be received, and response to the request, an aliased data set may be retrieved from the universal token, where the aliased data set corresponds to the sensitive data to fulfill the transaction. The aliased data set or the universal token may then be set to a processing service to complete the transaction.