Card Reader Session Validation Against Mobile POS Malware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile payment systems face security challenges in protecting customer PINs and credit card data from unauthorized access, particularly due to the vulnerability of mobile devices to malware and the need for secure communication sessions between card readers and mobile devices.

Innovation Solution

A trusted remote validation system validates the security of both the card reader and the POS module in the mobile device before establishing an encrypted communication session, using cryptographic keys and additional security information to ensure trustworthiness, and generates a shared secure session key for encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a mobile device is used to process credit card transactions with a card reader, then convenience and ease of use are improved, but security risks increase due to potential malware and unauthorized access to PIN and card data

Engineering Contradiction:
Improveconvenience of mobile paymentVSAvoidsecurity risks from malware
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a secure element as an intermediary component between the card reader and the mobile device's main processor. This secure element acts as a trusted mediator that handles sensitive cryptographic operations and data storage, isolating them from the potentially compromised mobile device environment. The secure element mediates the authentication process by verifying the card reader's trustworthiness and managing the establishment of secure communication channels, thereby protecting against malware while maintaining mobile payment convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the mobile payment system into distinct security zones: a secure element (isolated trusted environment), a POS module (application layer), and the mobile device operating system. This segmentation allows sensitive cryptographic functions and card data to be isolated in the secure element, separate from the general-purpose mobile device components that may be vulnerable to malware. The card reader authentication process is specifically isolated within this segmented architecture, protecting critical security functions while maintaining overall system functionality.

Inventive Principle:
Principle #1Segmentation

2Reliability

If cryptographic keys and security validation are implemented to protect data, then security is improved, but device complexity increases

Engineering Contradiction:
Improvedata protection securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex cryptographic key management and security validation functions from the main mobile device system and relocates them to a dedicated secure element. This extraction removes the burden of implementing robust cryptographic protocols, key storage, and validation logic from the general-purpose mobile device, thereby reducing its complexity. The secure element, being a specialized component, is better suited to handle these complex security requirements in a streamlined manner.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secure element performs self-service by autonomously managing its own cryptographic keys, validating the card reader's trustworthiness, and establishing secure communication channels without requiring complex intervention from the mobile device's main processor or user configuration. The POS module simply initiates the authentication process, while the secure element independently handles the complex cryptographic operations, key exchange, and validation procedures, thereby simplifying the overall system architecture.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3866092B1Establishment of a secure session between a card reader and a mobile device
Publication Date: 2025.12.31 BLOCK INC
  • EP3866092B1 patent drawingFigure 1
  • EP3866092B1 patent drawingFigure 2
  • EP3866092B1 patent drawingFigure 3

AI summary

Disclosed is a technique for establishing a secure communication session between a mobile device and a card reader. The technique can involve using a trusted, remote validation server to validate security information of both the card reader and a POS module in the mobile device prior to, and as a precondition of, the card reader and the POS module establishing a secure communication session with each other. In certain embodiments the POS module sends the security information of both the card reader and the POS module to the validation server. The security information can include cryptographic keys of the POS module and the card reader and additional security information related to the POS module and its software environment.