Applet Authorization for Wireless Transaction Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless transaction systems do not adequately protect non-transaction enabling data, such as transaction history and personal identification information, from unauthorized release during wireless transactions, posing security and privacy concerns for users.
Innovation Solution
An electronic device with a wireless communication interface, memory, and processor is configured to store transaction enabling data and non-transaction enabling data, where an applet determines whether to release non-transaction enabling data based on authorization, distinguishing between open-access and controlled-access data elements and requesting user consent for controlled-access data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If non-transaction enabling data is stored on the electronic device for wireless transactions, then transaction functionality is improved, but data security and user privacy deteriorate due to unauthorized release risks
Solution Approach 1:
The patent segments non-transaction enabling data into two distinct categories: open-access data elements and controlled-access data elements. This segmentation allows the system to apply different access control mechanisms to different data types, enabling transaction functionality while protecting sensitive user privacy information through selective authorization requirements.
Solution Approach 2:
The patent introduces an intermediary mechanism (the applet with authorization determination logic) that mediates between the transaction terminal's data requests and the protected non-transaction enabling data. This intermediary evaluates each request and determines whether to release data based on user authorization, thus preventing unauthorized access while maintaining necessary transaction functionality.
2Object-affected harmful factors
If controlled-access data elements are protected with authorization requirements, then user privacy is improved, but device complexity increases due to additional authorization mechanisms
Solution Approach 1:
By segmenting data into open-access and controlled-access categories, the system applies authorization mechanisms only where necessary, rather than implementing complex protection across all data. This selective approach reduces overall system complexity while maintaining strong privacy protection for sensitive information.
Solution Approach 2:
The patent implements self-service through automatic authorization determination by the applet. When a data request arrives, the system automatically determines whether the data corresponds to open-access or controlled-access elements and handles authorization accordingly, reducing the need for complex user interaction and manual control mechanisms.
3Ease of operation
If all non-transaction enabling data is made accessible during transactions, then ease of operation is improved, but data security deteriorates due to unauthorized release
Solution Approach 1:
The patent segments data accessibility into two paths: open-access data elements that are automatically released for ease of operation, and controlled-access data elements that require authorization for security. This segmentation allows the system to maintain both ease of operation for necessary data and security for sensitive information simultaneously.
Solution Approach 2:
The patent applies local quality by differentiating access control based on the specific characteristics of each data element. Rather than applying uniform access control to all non-transaction enabling data, the system tailors access rights to each data element's sensitivity level, allowing broad accessibility where safe and restricted access where necessary.
Data Source
AI summary
The present disclosure includes an electronic device for processing a wireless transaction. The electronic device includes a wireless communication interface, a memory, and a processor configured to execute an applet. The wireless communication interface is configured to communicate with a transaction terminal. The memory is configured to store a first set of data for enabling a transaction between the electronic device and the transaction terminal, and a second set of data different from the first set of data. The applet is configured to receive a first request for conducting the transaction. The applet is configured to transmit a first message including or based on the first set of data. The applet is configured to receive a second request for retrieving at least part of the second set of data. The applet is configured to determine whether release of at least part of the second set of data has been authorized.


