Secure Session Establishment Between Card Reader and Mobile Device

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile payment processing systems face security challenges as sensitive data, such as PINs and credit card information, are vulnerable to unauthorized access due to potential malware in mobile devices, necessitating a secure communication session between the card reader and mobile device.

Innovation Solution

A trusted remote validation system verifies the security information of both the card reader and the POS module in the mobile device before establishing an encrypted communication session, using public cryptographic keys and additional security data to ensure trustworthiness and prevent breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is read from the card using a mobile device, then convenience and ease of use are improved, but security is worsened due to potential malware and unauthorized access

Engineering Contradiction:
Improveconvenience of mobile paymentVSAvoidsecurity of card data
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A secure communication session is established as an intermediary layer between the card reader and the mobile device. This session uses encrypted channels to protect card data during transmission, preventing malware on the mobile device from accessing sensitive information while maintaining the convenience of mobile payments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security validation by establishing an encrypted communication session before any card data is read or transmitted. This preemptive security measure ensures that even if malware is present on the mobile device, it cannot access card data because the data remains encrypted throughout the communication process.

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If a secure communication session is established, then security is improved, but device complexity is worsened due to validation requirements

Engineering Contradiction:
Improvesecurity of communicationVSAvoidcomplexity of validation process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The card reader and mobile device perform mutual validation of their security capabilities autonomously during the session establishment process. Each device verifies the other's ability to maintain secure communications without requiring external intervention, simplifying the overall system architecture while ensuring security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10438187B2Establishment of a secure session between a card reader and a mobile device
Publication Date: 2019.10.08 BLOCK INC
  • US10438187B2 patent drawing
  • US10438187B2 patent drawing
  • US10438187B2 patent drawing

AI summary

Disclosed is a technique for establishing a secure communication session between a mobile device and a card reader. The technique can involve using a trusted, remote validation server to validate security information of both the card reader and a POS module in the mobile device prior to, and as a precondition of, the card reader and the POS module establishing a secure communication session with each other. In certain embodiments the POS module sends the security information of both the card reader and the POS module to the validation server. The security information can include cryptographic keys of the POS module and the card reader and additional security information related to the POS module and its software environment.