Cash Register Cloud Server Secure Payment Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional electronic payment transactions using mobile merchant devices are vulnerable to fraud due to the potential security weaknesses in cash register applications, which may send incorrect information, as they are not as well-protected as payment control applications.
Innovation Solution
A cash register cloud server is introduced to support secure electronic payment transactions by implementing multiple cash register applications, receiving electronic payment data via a secure channel, generating authentication requests with cryptographic keys, and transmitting these requests securely to mobile merchant and payment cloud servers, using TLS tunnels and digital signatures for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cash register applications are implemented on mobile merchant devices to process payments, then payment processing functionality is improved, but security vulnerability increases due to potential fraud from unprotected applications
Solution Approach 1:
The patent introduces a payment server as an intermediary between the mobile merchant device and the payment network. The payment server validates authentication requests, verifies transaction data integrity, and mediates the authorization process, thereby protecting against fraudulent transactions while enabling payment processing functionality.
Solution Approach 2:
The patent implements preliminary authentication and validation actions before processing payments. The mobile merchant device performs authentication requests with the payment server before completing transactions, and the payment server validates device integrity and application authenticity in advance, preventing fraudulent transactions before they occur.
2Adaptability or versatility
If multiple cash register applications are implemented on a mobile device, then payment processing capability is improved, but security attack surface increases due to multiple potential weak points
Solution Approach 1:
The patent merges the authentication and validation functions of multiple cash register applications into a single centralized payment server. Instead of each application independently handling security, all authentication requests are consolidated and processed by the payment server, which maintains a single security model and reduces the attack surface despite supporting multiple applications.
Solution Approach 2:
The payment server acts as an intermediary that mediates between multiple cash register applications and the payment network. It validates each application's authenticity and ensures proper authentication, thereby managing security across multiple applications without requiring each to be independently secure.
3Reliability
If conventional payment control applications with high protection standards are used, then transaction security is improved, but system complexity increases due to integration with multiple vendor applications
Solution Approach 1:
The patent creates a universal payment server that performs multiple functions: authentication validation, device integrity verification, transaction authorization, and communication with various cash register applications. This single multi-functional component maintains high security standards while simplifying the overall system architecture by providing a common interface for all applications.
Solution Approach 2:
The payment server serves as a universal intermediary that standardizes security protocols and authentication mechanisms. It provides a common security layer that works with multiple vendor applications, reducing integration complexity while maintaining high protection standards through centralized control.
Data Source
Figure 1
Figure 2
Figure 3a
AI summary
A cash register cloud server (150) for supporting an electronic payment based on an interaction between a mobile merchant communication device (120) and a customer payment device (110) is disclosed. The cash register cloud server (150) comprises a processing circuitry (151) configured to implement a plurality of cash register applications (151a). Moreover, the cash register cloud server (150) comprises a communication interface (153) configured to receive electronic payment data based on an user input from the mobile merchant communication device (120) via a secure channel. The processing circuitry (151) is further configured to assign the electronic payment data to one of the plurality of cash register applications (151a) and to generate an authentication request for requesting further processing of the electronic payment, wherein the authentication request comprises authentication information based on a cryptographic key of the one of the plurality of cash register applications (151a). The communication interface (153) is further configured to transmit the authentication request to the mobile merchant communication device (120) and/or a payment cloud server (140) via a further secure channel.