Vault Server Tokenization for Secure Payments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current electronic payment systems are vulnerable to unauthorized use and fraud, as they rely on static information that can be easily stolen or compromised, leading to significant financial losses for both consumers and merchants, with existing security measures being inadequate in preventing fraudulent transactions, especially in "card not present" scenarios.
Innovation Solution
A computerized payment verification system utilizing a tokenization process where a consumer's credit card information is stored on a vault server, generating a token for authentication, allowing transactions without the need for the physical card, shifting liability from the credit card entity to the issuing bank, and enabling secure "card not present" transactions through a subscription service and authentication notification server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional electronic payment systems use static credit card information, then transactions are convenient and widely used, but the system becomes vulnerable to unauthorized use and fraud
Solution Approach 1:
The system performs preliminary authentication and token generation before the actual transaction. The vault server pre-generates tokens that represent credit card information, and these tokens are stored securely. During transactions, the pre-generated tokens are used instead of actual card information, preventing fraud while maintaining convenience.
Solution Approach 2:
The patent introduces a vault server as an intermediary between the payment system and credit card information. The vault server generates and manages tokens that mediate the transaction process, allowing payments without exposing actual card details. This intermediary layer protects against fraud while enabling convenient transactions.
2Productivity
If credit card information is stored on merchant servers, then transactions can be processed efficiently, but the risk of data theft and unauthorized copying increases
Solution Approach 1:
The system creates a token copy of the credit card information that functions identically to the original card data but cannot be reverse-engineered. The vault server generates tokens that replicate the necessary payment functionality without containing actual card details, allowing efficient processing while eliminating data theft risk.
Solution Approach 2:
The vault server acts as an intermediary that manages token generation and storage. Instead of merchants storing sensitive card information, the vault server holds the tokens and manages their distribution. This intermediary approach maintains transaction efficiency while removing the vulnerability of storing actual card data on merchant servers.
3Ease of operation
If physical credit cards are required for transactions, then authentication is straightforward, but the system remains vulnerable to card theft and unauthorized use
Solution Approach 1:
The patent replaces the mechanical physical card system with an electronic token system. Instead of requiring physical card presence, the system uses digitally generated tokens that provide the same authentication function. This substitution eliminates card theft risks while maintaining simple authentication through the token verification process.
Data Source
AI summary
A novel method of allowing secure payments from a purchaser to a seller through the utilization of a combined server platform/vault server system. Such a system entails the generation of a subscription service that allows for authentication of a consumer's credit card in terms of pre-approved identification for future transactions. Such a system initiates a tokenization procedure through transfer of credit card information to the server platform through the vault program and to issuing banks/card providers. Upon acceptance thereof, the vault server generates a token that correlates to a specific credit card of a specific user that is then stored on the server platform. Upon request from a subscribing merchant for acceptance of a tokenized card for payments, the user merely needs to provide an identifying code to access the card for such a purpose.

