Cloud-Based Transaction System for Secure Mobile Payments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing secure element-based systems for portable communication devices are cumbersome and costly, requiring complex commercial and technical agreements for provisioning, and they do not allow direct access for issuers and payment processors, leading to security concerns when transactions are conducted without a secure element.

Innovation Solution

A cloud-based transaction system that uses card emulation technology to enable mobile applications on portable communication devices to conduct contactless transactions without relying on a secure element, by provisioning limited-use account parameters that can be replenished from the cloud, reducing reliance on tamper-resistant hardware for security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure element is used to store account information, then transaction security is improved, but device complexity and manufacturing cost increase

Engineering Contradiction:
Improvetransaction securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the secure element component from the portable communication device entirely. Instead of embedding tamper-resistant hardware, the system uses cloud-based account parameters that are provisioned to the device software, eliminating the physical secure element while maintaining security through limited-use credentials and cloud validation

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a software-based copy of the secure element functionality through virtualization. The account parameters are provisioned as software objects that emulate secure element behavior, allowing the device to perform secure transactions without physical tamper-resistant hardware

Inventive Principle:
Principle #26Copying

2Reliability

If a secure element is used to store account information, then transaction security is improved, but manufacturing cost increases

Engineering Contradiction:
Improvetransaction securityVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent removes the secure element hardware component from the device assembly process. By provisioning account parameters through software updates and cloud-based delivery, the manufacturing process is simplified and costs are reduced while security is maintained through cryptographic validation of limited-use credentials

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses disposable, short-lived account parameters that are provisioned software-based rather than embedded in expensive permanent hardware. These limited-use credentials can be rotated and replenished from the cloud, replacing the need for costly secure elements while maintaining security through frequent credential renewal

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Device complexity

If cloud-based provisioning is used without secure element, then device complexity is reduced, but transaction security deteriorates

Engineering Contradiction:
Improvedevice complexityVSAvoidtransaction security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent performs preliminary security actions by provisioning limited-use account parameters with embedded validity thresholds before transactions occur. The cloud system pre-validates and signs these credentials, so that during actual transactions, security verification is rapid and does not require complex device-side security hardware

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous feedback loops where the cloud system monitors account parameter usage, validates transaction requests, and replenishes credentials based on usage patterns. This creates a dynamic security system that adapts to threats and maintains security without requiring static tamper-resistant hardware in the device

Inventive Principle:
Principle #23Feedback

4Device complexity

If secure element is controlled by mobile network operator, then device complexity is reduced, but ease of operation deteriorates due to complex provisioning process

Engineering Contradiction:
Improvedevice complexityVSAvoidprovisioning process
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The patent creates a universal provisioning system where the cloud-based account parameter delivery mechanism can serve multiple functions: initial device setup, credential replenishment, security updates, and transaction validation. This multi-functional approach eliminates the need for separate secure element management infrastructure and simplifies the provisioning process for all parties involved

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11783061B2Embedding cloud-based functionalities in a communication device
Publication Date: 2023.10.10 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11783061B2 patent drawing
  • US11783061B2 patent drawing
  • US11783061B2 patent drawing

AI summary

Techniques for enhancing the security of a communication device may include providing an application agent and a transaction application that executes on a communication device. The application agent may receive, from the application, a cryptogram key generated by a remote computer, and store the cryptogram key on the communication device. When the application agent receives a request to conduct a transaction from the application, the application agent may generate a transaction cryptogram using the cryptogram key, and provides the transaction cryptogram to an access device.