Cash Register Cloud Server Secure Payment Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional electronic payment transactions using mobile merchant devices are vulnerable to fraud due to the potential security weaknesses in cash register applications, which may send incorrect information, as they are not as well-protected as payment control applications.

Innovation Solution

A cash register cloud server is introduced to support secure electronic payment transactions by implementing multiple cash register applications, receiving electronic payment data via a secure channel, generating authentication requests with cryptographic keys, and transmitting these requests securely to mobile merchant and payment cloud servers, using TLS tunnels and digital signatures for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cash register applications are implemented on mobile merchant devices to process payments, then payment processing functionality is improved, but security vulnerability increases due to potential fraud from unprotected applications

Engineering Contradiction:
Improvepayment processing functionalityVSAvoidtransaction security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a payment server as an intermediary between the mobile merchant device and the payment network. The payment server validates authentication requests, verifies transaction data integrity, and mediates the authorization process, thereby protecting against fraudulent transactions while enabling payment processing functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication and validation actions before processing payments. The mobile merchant device performs authentication requests with the payment server before completing transactions, and the payment server validates device integrity and application authenticity in advance, preventing fraudulent transactions before they occur.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If multiple cash register applications are implemented on a mobile device, then payment processing capability is improved, but security attack surface increases due to multiple potential weak points

Engineering Contradiction:
Improvepayment processing capabilityVSAvoidsecurity attack surface
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges the authentication and validation functions of multiple cash register applications into a single centralized payment server. Instead of each application independently handling security, all authentication requests are consolidated and processed by the payment server, which maintains a single security model and reduces the attack surface despite supporting multiple applications.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The payment server acts as an intermediary that mediates between multiple cash register applications and the payment network. It validates each application's authenticity and ensures proper authentication, thereby managing security across multiple applications without requiring each to be independently secure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If conventional payment control applications with high protection standards are used, then transaction security is improved, but system complexity increases due to integration with multiple vendor applications

Engineering Contradiction:
Improvetransaction securityVSAvoidsystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal payment server that performs multiple functions: authentication validation, device integrity verification, transaction authorization, and communication with various cash register applications. This single multi-functional component maintains high security standards while simplifying the overall system architecture by providing a common interface for all applications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The payment server serves as a universal intermediary that standardizes security protocols and authentication mechanisms. It provides a common security layer that works with multiple vendor applications, reducing integration complexity while maintaining high protection standards through centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4191495A1Devices, methods and a system for secure electronic payment transactions
Publication Date: 2023.06.07 RUBEAN AG
  • EP4191495A1 patent drawingFigure 1
  • EP4191495A1 patent drawingFigure 2
  • EP4191495A1 patent drawingFigure 3a

AI summary

A cash register cloud server (150) for supporting an electronic payment based on an interaction between a mobile merchant communication device (120) and a customer payment device (110) is disclosed. The cash register cloud server (150) comprises a processing circuitry (151) configured to implement a plurality of cash register applications (151a). Moreover, the cash register cloud server (150) comprises a communication interface (153) configured to receive electronic payment data based on an user input from the mobile merchant communication device (120) via a secure channel. The processing circuitry (151) is further configured to assign the electronic payment data to one of the plurality of cash register applications (151a) and to generate an authentication request for requesting further processing of the electronic payment, wherein the authentication request comprises authentication information based on a cryptographic key of the one of the plurality of cash register applications (151a). The communication interface (153) is further configured to transmit the authentication request to the mobile merchant communication device (120) and/or a payment cloud server (140) via a further secure channel.