Secure Session Establishment Between Card Reader and Mobile Device
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile payment processing systems face security challenges as sensitive data, such as PINs and credit card information, are vulnerable to unauthorized access due to potential malware in mobile devices, necessitating a secure communication session between the card reader and mobile device.
Innovation Solution
A trusted remote validation system verifies the security information of both the card reader and the POS module in the mobile device before establishing an encrypted communication session, using public cryptographic keys and additional security data to ensure trustworthiness and prevent breaches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is read from the card using a mobile device, then convenience and ease of use are improved, but security is worsened due to potential malware and unauthorized access
Solution Approach 1:
A secure communication session is established as an intermediary layer between the card reader and the mobile device. This session uses encrypted channels to protect card data during transmission, preventing malware on the mobile device from accessing sensitive information while maintaining the convenience of mobile payments.
Solution Approach 2:
The system performs preliminary security validation by establishing an encrypted communication session before any card data is read or transmitted. This preemptive security measure ensures that even if malware is present on the mobile device, it cannot access card data because the data remains encrypted throughout the communication process.
2Reliability
If a secure communication session is established, then security is improved, but device complexity is worsened due to validation requirements
Solution Approach 1:
The card reader and mobile device perform mutual validation of their security capabilities autonomously during the session establishment process. Each device verifies the other's ability to maintain secure communications without requiring external intervention, simplifying the overall system architecture while ensuring security.
Data Source
AI summary
Disclosed is a technique for establishing a secure communication session between a mobile device and a card reader. The technique can involve using a trusted, remote validation server to validate security information of both the card reader and a POS module in the mobile device prior to, and as a precondition of, the card reader and the POS module establishing a secure communication session with each other. In certain embodiments the POS module sends the security information of both the card reader and the POS module to the validation server. The security information can include cryptographic keys of the POS module and the card reader and additional security information related to the POS module and its software environment.


