Intelligent Cipher Token for Mutual Authentication in Mobile Payments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile payment systems face security challenges in ensuring the integrity and confidentiality of data interactions, particularly in preventing phishing, tampering, and man-in-the-middle attacks during transactions.

Innovation Solution

A secure data interactive method and system that employs intelligent cipher tokens for mutual authentication between terminals, background system servers, and intelligent cipher tokens, using cryptographic techniques to establish secure channels and manage user information, thereby preventing unauthorized access and ensuring transaction security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional mobile payment data interaction is used, then operation simplicity is maintained, but security against phishing, tampering, and man-in-the-middle attacks deteriorates

Engineering Contradiction:
Improvetransaction securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intelligent cipher token as an intermediary authentication device between the terminal and the background system server. This token contains cryptographic elements and enables mutual authentication, thereby enhancing transaction security without requiring complex security protocols to be implemented directly in the terminal or server infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into distinct functional components: the terminal, the intelligent cipher token, and the background system server. Each component has specific authentication responsibilities, with the cipher token serving as a portable security module that can be independently managed and replaced, simplifying the overall system architecture while maintaining high security standards.

Inventive Principle:
Principle #1Segmentation

2Reliability

If mutual authentication protocols are implemented, then data integrity is improved, but processing time increases

Engineering Contradiction:
Improvedata integrityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The intelligent cipher token pre-stores cryptographic authentication data and certificates before actual transactions occur. During payment operations, the pre-configured authentication mechanisms are activated immediately, allowing for rapid mutual authentication between the terminal and server without requiring time-consuming key generation or certificate verification setup during the transaction itself.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If cryptographic techniques are used for secure channels, then confidentiality is improved, but computational overhead increases

Engineering Contradiction:
Improvedata confidentialityVSAvoidterminal energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The intelligent cipher token acts as a dedicated cryptographic processing intermediary that handles the computationally intensive encryption and decryption operations. By offloading these cryptographic tasks from the terminal's main processor to the specialized cipher token, the terminal's energy consumption is reduced while maintaining strong data confidentiality through robust cryptographic protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3136646B1Secure data interaction method and system
Publication Date: 2021.03.03 TENDYRON CORP
  • EP3136646B1 patent drawingFigure 1
  • EP3136646B1 patent drawingFigure 2

AI summary

Provided are a secure data interaction method and system, the method comprising: a terminal scans an intelligent cryptographic device within signal coverage, and acquires the identifier information of the scanned intelligent cryptographic device; the terminal and a background system server authenticate each other, and/or the terminal and the intelligent cryptographic device authenticate each other; the terminal acquires user information corresponding to the intelligent cryptographic device according to the identifier information of the scanned intelligent cryptographic device; and the terminal stores the user information in a pre-established current user list. Thus, the present invention constructs a method system of mutually authenticating the background system server, the terminal and the intelligent cryptographic device, and establishes security channels there between to prevent phishing risks and transaction risks such as transaction information tampering, remote hijacking and middle-man attacks, thus effectively ensuring fund security of a user possessing the intelligent cryptographic device and a merchant possessing the terminal.