Cloud-Based Virtual Wallet NFC Transaction Bounding Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current electronic purchase transaction systems face challenges in securing transactions, particularly in remote settings where physical contact with a merchant's point-of-sale device is not feasible, leading to vulnerabilities in payment security and consumer confidence.
Innovation Solution
The implementation of a Cloud-Based Virtual Wallet NFC system that generates and manages transaction bounding tokens, allowing secure transactions without physical contact, using secure elements on payment cards and mobile devices, and issuing certificates to merchants for remote transactions, ensuring token-based payments that are time-limited, session-specific, and merchant-specific.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If physical card presence is required at point-of-sale terminal, then transaction security is maintained through direct contact, but consumer convenience and remote transaction capability are reduced
Solution Approach 1:
A cloud-based virtual wallet system acts as an intermediary between the consumer's payment card and the merchant's point-of-sale terminal. The system generates time-limited transaction bounding tokens that mediate the authentication process, allowing remote transactions while maintaining security through server-side validation and token management.
Solution Approach 2:
The system creates a virtual copy of the payment card functionality in the cloud, where the virtual wallet stores and manages payment information. This digital representation enables transactions without requiring the physical card to be present at the point-of-sale terminal, while maintaining security through encrypted storage and controlled access.
2Adaptability or versatility
If physical contact with point-of-sale device is required, then transaction authorization is secure, but remote commerce capability is limited
Solution Approach 1:
The system implements dynamic token generation where each transaction bounding token is time-limited and session-specific. The tokens have varying validity periods and scopes, adapting to different transaction scenarios. This dynamic approach enables remote transactions while maintaining security through constantly changing authentication credentials.
Solution Approach 2:
The system changes the parameters of transaction authentication by using time-limited tokens with specific validity windows, merchant-specific scopes, and amount constraints. These parameter changes enable flexible remote commerce while maintaining security through multi-factor validation including time, merchant identity, and transaction amount.
3Productivity
If traditional payment processing is used, then transaction completion is straightforward, but consumer data vulnerability increases
Solution Approach 1:
The system extracts sensitive payment data from the traditional transaction flow and stores it securely in the cloud-based virtual wallet. The virtual card numbers and payment information are separated from the point-of-sale processing, with only non-sensitive transaction bounding tokens being transmitted during transactions. This extraction reduces consumer data vulnerability while maintaining processing efficiency.
Solution Approach 2:
The system uses disposable, single-use transaction bounding tokens that are generated for each transaction and become invalid after use or expiration. These short-lived tokens replace traditional reusable payment card numbers in transaction communications, minimizing the exposure window for consumer data and reducing vulnerability to data breaches while maintaining straightforward transaction processing.
Data Source
AI summary
The CLOUD-BASED VIRTUAL WALLET NFC APPARATUSES, METHODS AND SYSTEMS (“EAE”) transform user enhanced security transaction initiation requests using EAE components into time-limited, session-specific transaction bounding tokens. In some implementations, the disclosure provides a processor-implemented method of transforming a transaction bounding token request into transaction bounded tokens and purchase authorizations.


