EMV Payment System Using Limited-Use Session Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic payment systems face challenges in providing secure payment card functionality on user devices without a secure element, such as mobile phones, due to the need for secure elements to store and process secret data, and the limitations of existing EMV infrastructure and POS hardware.

Innovation Solution

A method for authorizing EMV transactions using a user device that does not store the ICC Master Key locally, instead deriving session keys from it, allowing the payment application to generate application cryptograms based on these keys, and communicating with the issuing bank to manage key provisioning, thus reducing the risk of attacks and eliminating the need for a secure element.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure element is used to store and process secret data, then security is improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the secure storage and processing function from a dedicated secure element (hardware component) and relocates it to a software-based trusted execution environment. This allows the same security function to be achieved without requiring specialized hardware, thereby reducing device complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the mechanical/hardware-based secure element with a software-based trusted execution environment. This substitution eliminates the need for dedicated secure hardware while providing equivalent security through software-enforced isolation and protection mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If a secure element is required for EMV transactions, then transaction security is improved, but adaptability to devices without secure elements deteriorates

Engineering Contradiction:
Improvetransaction securityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal payment solution that works on both devices with secure elements and devices without secure elements. The trusted execution environment provides the same security functionality across different device types, enabling EMV transactions to be performed universally regardless of hardware capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If the ICC Master Key is stored locally on the user device, then ease of operation is improved, but security against attacks deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity against attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted execution environment as an intermediary layer between the payment application and the stored key material. This intermediary provides a secure context for key storage and usage while maintaining ease of operation through automated key management, effectively isolating the system from attack vectors.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250272677A1Payment system
Publication Date: 2025.08.28 VISA EUROPE
  • US20250272677A1 patent drawing
  • US20250272677A1 patent drawing
  • US20250272677A1 patent drawing

AI summary

A method is disclosed. The method includes receiving a first session key different from a Master Key from a remote entity, the first session key based on the Master Key. The first session key is usable for a limited number of transactions. In response to receiving the first session key, the method includes provisioning a payment application in the user device with the first session key. The method includes receiving, at the payment application, a request for an application cryptogram from a point-of-sale terminal. In response to the receiving the request for the application cryptogram, the method includes generating the application cryptogram using the first session key, transmitting the application cryptogram to the point-of-sale terminal, and receiving a second session key from the remote entity. The second session key is based on the Master Key.