Wireless Device Tokenized Transaction Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile electronic transaction systems face significant security challenges due to the distribution and usage of sensitive account data during near-field transactions, particularly in tokenized transactions between wireless devices and point-of-sale systems.

Innovation Solution

A method is introduced where a wireless device receives a resource account system ID from a near-field transaction terminal, selects a locally stored resource account, and sends a corresponding application ID to the terminal. The device then receives a token ID, which is sent to an account management system to generate a transaction token, minimizing the transfer of sensitive account information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If sensitive account data is transferred during near-field transactions, then transaction authorization can be obtained, but security risks increase due to potential data breaches

Engineering Contradiction:
Improvetransaction securityVSAvoiddata breach risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive account data from the transaction flow by replacing it with a token (token ID). The actual account information remains securely stored in the account management system, while only the token is transmitted during near-field transactions. This extraction eliminates the security risk of transmitting sensitive data while maintaining transaction functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a token as an intermediary between the account data and the transaction terminal. The token acts as a mediator that carries the necessary authorization information without exposing the underlying sensitive account data. This intermediary layer protects the original data from potential breaches during transmission and storage at the terminal.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If tokenized transaction protocols are implemented, then security is enhanced, but system complexity increases due to additional communication interfaces and protocols

Engineering Contradiction:
Improvetransaction securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the transaction system into distinct functional components: the wireless device with its first communication interface for near-field communication, the account management system with its second communication interface for token processing, and the terminal system. This segmentation allows each component to handle specific tasks independently, making the overall complex system more manageable and maintainable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal token-based protocol that can be applied across different transaction types and systems. The token ID serves as a multi-functional identifier that works with various account types and transaction scenarios, reducing the need for system-specific implementations and simplifying the overall architecture despite the added security layer.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10423954B2Resource account application management
Publication Date: 2019.09.24 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10423954B2 patent drawing
  • US10423954B2 patent drawing
  • US10423954B2 patent drawing

AI summary

A program product and device for processing a resource account transaction within a wireless electronic device, such as a smartphone or other portable electronic device. During or at the initiation of a resource transaction with a near-field transaction terminal, the device receives from the terminal via a first communication interface, a resource account system ID. A locally stored resource account is selectively identified based on the received resource account system ID. The device sends a resource account application ID corresponding to the selected resource account to the near-field transaction terminal via the first communication interface. From the near-field transaction terminal, the device receives a token ID that is associated with the selected resource account, and sends, the token ID to an account management system via a second communication interface. The device receives from the account management system a transaction token comprising the token ID associated with a specified transaction resource value.