Payer-Controlled Payment Processing via VPN Tokenization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic payment systems are vulnerable to data theft as they transmit sensitive account information during transactions, leading to security risks and compliance issues for merchants.
Innovation Solution
A distributed payer-controlled payment architecture that uses a payer device, a merchant device, and an authorization server to process transactions without transmitting any account data to the merchant, instead relying on encrypted merchant identification, kiosk identification, and a security key validated through an authorization database, ensuring secure communication via a virtual private network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If sensitive account information is transmitted during transactions, then payment processing can be completed, but security risks and data theft vulnerabilities increase
Solution Approach 1:
The patent extracts and removes sensitive account information from the transaction flow entirely. Instead of transmitting account data between merchant and payer systems, the invention uses tokenization where sensitive information is replaced with non-sensitive tokens that cannot be used for fraud. This extraction principle directly resolves the contradiction by eliminating the harmful transmission of sensitive data while maintaining transaction functionality.
Solution Approach 2:
The patent introduces an intermediary authorization server that acts as a mediator between the merchant system and payer system. This server receives transaction requests, validates tokens, and processes authorizations without exposing sensitive account information to either party. The intermediary principle resolves the contradiction by creating a secure middle ground where transactions can be processed without direct exposure of sensitive data.
2Productivity
If account data is transmitted for transaction processing, then payments can be authorized, but compliance burdens and security vulnerabilities increase for merchants
Solution Approach 1:
The patent extracts sensitive account data from the merchant's transaction processing environment. By using tokenized representations instead of actual account information, merchants can process transactions efficiently without handling sensitive data, thereby reducing compliance burdens while maintaining productivity.
Solution Approach 2:
The patent implements a self-service authorization model where the authorization server automatically validates tokens and processes transactions without requiring merchants to implement complex security measures or compliance frameworks. This reduces the complexity of merchant systems while maintaining efficient transaction processing.
3Productivity
If traditional payment systems transmit sensitive information, then transactions can be completed, but fraud prevention capabilities are reduced
Solution Approach 1:
The patent extracts sensitive account information from the transaction flow and replaces it with tokens. This extraction enables fraud prevention because tokens cannot be stolen or misused in the same way account information can, while transaction completion remains efficient through automated token validation.
Solution Approach 2:
The authorization server intermediary enhances fraud prevention by centrally managing token validation and authorization logic. It can detect suspicious patterns, enforce security policies, and prevent fraud without interfering with the speed of transaction completion at the merchant and payer endpoints.
Data Source
AI summary
An apparatus comprising an authorization server, merchant device and payer device, including a virtual private network (VPN) communicatively coupled with the merchant device processor and the payer device processor, wherein the VPN tunnels through a communication network, the payer device is configured to receive a first encrypted message from the merchant using at least one of: the VPN, an image-capturing interface, or a near-field communication interface, depending on the type of the transaction initiated by the payer. In response to receiving a purchase request from the payer using the payer device: the merchant device sends on the VPN to the payer device, the first encrypted message comprising the security key and transaction information referencing the purchase request. An implementation can conduct a secure transaction using a VPN connection between the payer device and the merchant device, improving electronic transaction security, preventing replay attacks and data capture by an adversary.


