Backend System for Secure Mobile Payment Enrollment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic payment systems using mobile merchant communication devices lack secure methods to authenticate and authorize transactions, risking the integrity of security-relevant data processing.
Innovation Solution
A backend system generates and manages electronic secrets for mobile merchant communication devices, employing a challenge-response procedure to attest their integrity and enable secure payment transactions by transmitting personalization data, including cryptographic keys, to ensure secure interactions with payment servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a mobile merchant communication device is used to replace traditional POS terminals for payment transactions, then the ease of operation and accessibility are improved, but the security risk and reliability of processing security-relevant data deteriorate
Solution Approach 1:
The patent introduces a backend system as an intermediary between the mobile merchant device and the payment network. This backend system acts as a trusted mediator that performs challenge-response authentication and verifies the integrity of security-relevant data, thereby maintaining reliability while enabling mobile operation. The backend system mediates the security concerns by centrally managing authentication without preventing mobile accessibility.
Solution Approach 2:
The patent replaces traditional mechanical security verification methods (physical POS terminals with hardware security modules) with electronic/challenge-response based verification. Instead of relying on physical device integrity, the system uses cryptographic challenge-response procedures to verify the mobile device's authenticity, substituting mechanical security with electronic authentication mechanisms.
2Reliability
If security verification procedures are implemented for mobile merchant devices, then the reliability and security are improved, but the device complexity and processing time increase
Solution Approach 1:
The patent extracts the complex security verification logic from the mobile merchant device and relocates it to the backend system. The mobile device only needs to implement simple challenge-response authentication, while the complex integrity verification and security management are performed externally by the backend system. This reduces device complexity while maintaining reliability.
Solution Approach 2:
The patent implements preliminary registration and provisioning of mobile merchant devices with security credentials before they engage in payment transactions. The backend system pre-configures devices with necessary security parameters and establishes trust relationships in advance, so that during actual transactions, only lightweight challenge-response verification is needed rather than complex real-time security analysis.
3Reliability
If challenge-response procedures are used to attest device integrity, then the security and control are improved, but the loss of time for enrollment and verification increases
Solution Approach 1:
The patent performs the time-consuming challenge-response authentication and device integrity verification during the initial enrollment phase, before the device begins processing payments. Once enrolled and verified, the device maintains its authenticated state for subsequent transactions, eliminating the need for repeated time-consuming verification procedures during each payment transaction.
Solution Approach 2:
The patent implements periodic or intermittent re-verification of device integrity rather than continuous verification. The backend system can periodically challenge enrolled devices to reaffirm their integrity, balancing security requirements with time efficiency by not requiring constant verification while still maintaining security oversight.
Data Source
Figure 1
Figure 2a
Figure 2b
AI summary
A backend system (160) configured to enroll a mobile merchant communication device (120) for performing a payment transaction with a mobile consumer communication device (110) is disclosed. The backend system (160) comprises a processing circuitry (141; 151) configured to generate a first electronic secret for the mobile merchant communication device (120). Moreover, backend system (160) comprises a communication interface (143; 153) configured to receive an enrollment request from the mobile merchant communication device (120), wherein the enrollment request comprises the first electronic secret for authorizing the enrollment request and a second electronic secret generated by the mobile merchant communication device (120). The processing circuitry (141) is further configured, if the enrollment request is successful, to generate personalization data for the mobile merchant communication device (120). The communication interface (143) is further configured to transmit the personalization data to the mobile merchant communication device (120) for enabling the mobile merchant communication device (120) to perform the payment transaction with the mobile consumer communication device (110) The communication interface (143; 153) is further configured to attest the integrity of the mobile merchant communication device (120) based on the second electronic secret using a challenge response procedure.