Cloud-Based Transaction Security Using Limited-Use Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing secure element-based payment systems in portable communication devices are cumbersome and costly for financial institutions to manage, and they lack direct control, leading to security concerns when conducting transactions without a secure element.
Innovation Solution
Implementing cloud-based transactions that use limited-use account parameters with a limited lifespan, which are replenished from the cloud, allowing transactions to be conducted without relying on a secure element, and utilizing card emulation technology to access the contactless interface, reducing the need for secure element control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a secure element is used in a portable communication device, then transaction security is improved, but device complexity and manufacturing cost increase
Solution Approach 1:
The patent extracts the secure element from the portable communication device entirely, replacing it with cloud-based security infrastructure. The secure element functionality is removed from the device and relocated to remote servers, eliminating the hardware component while maintaining security through network-based authentication and encryption protocols.
Solution Approach 2:
The patent introduces an intermediary cloud-based authentication server that mediates between the portable communication device and the transaction processing system. This intermediary handles security verification, credential validation, and encrypted communication, replacing the need for embedded secure elements while maintaining transaction security through centralized authentication.
2Reliability
If a secure element is used in a portable communication device, then transaction security is improved, but manufacturing cost increases
Solution Approach 1:
The patent employs disposable, short-lived cryptographic credentials and session tokens that are generated, used, and discarded for each transaction or short time period. These ephemeral security credentials replace expensive, permanent secure elements, providing comparable security through temporary authentication mechanisms that are computationally generated and validated.
Solution Approach 2:
The patent replaces the mechanical/hardware-based secure element with software-based cryptographic protocols and cloud-based authentication services. This substitution eliminates the need for physical secure hardware components, reducing manufacturing costs while maintaining security through mathematical cryptography and network-based verification.
3Device complexity
If cloud-based transactions with limited-use account parameters are used, then device complexity is reduced, but transaction security may be compromised
Solution Approach 1:
The patent implements dynamic security credentials with limited usage parameters, where account parameters are configured with specific validity periods, transaction count limits, or monetary thresholds. These dynamic constraints are enforced by the cloud-based authentication system, allowing flexible security policies that adapt to different transaction types and risk levels without requiring complex device hardware.
Solution Approach 2:
The patent incorporates continuous feedback loops where the cloud-based authentication system monitors transaction patterns, validates limited-use parameter compliance, and dynamically adjusts security responses. The system provides real-time feedback on credential validity, transaction authorization status, and parameter compliance, enabling secure transactions without complex device-side security infrastructure.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Techniques for enhancing the security of a communication device when conducting a transaction using the communication device may include using a limited-use key (LUK) to generate a transaction cryptogram, and sending a token instead of a real account identifier and the transaction cryptogram to an access device to conduct the transaction. The LUK may be associated with a set of one or more limited-use thresholds that limits usage of the LUK, and the transaction can be authorized based on at least whether usage of the LUK has exceeded the set of one or more limited-use thresholds.