E-Purse Manager Security for Open Network Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing single functional cards, such as MIFARE, face challenges in expanding to open environments like e-commerce and m-commerce due to security concerns related to key delivery over public networks, making it difficult to conduct secure transactions over open networks.
Innovation Solution
A three-tier security model is implemented, comprising physical security, e-purse security, and card manager security, with personalized symmetric or asymmetric security keys to establish a secured channel between an embedded e-purse and a Security Authentication Module or payment server, enabling secure transactions over wired or wireless networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If single functional cards like MIFARE are used in enclosed environments, then transaction security is maintained through protected data storage with keys, but the system cannot be expanded to open environments such as e-commerce and m-commerce due to security concerns about key delivery over public networks
Solution Approach 1:
The patent introduces a card manager as an intermediary component that mediates between the e-purse and external systems. The card manager handles key management and authentication operations, allowing secure communication over open networks without exposing the underlying card's data storage structure. This intermediary layer enables expansion to open environments while maintaining security through proper authentication protocols.
Solution Approach 2:
The patent segments the security architecture into distinct functional layers: physical security at the card level, e-purse security for transaction processing, and card manager security for key management. This segmentation allows each layer to be optimized independently and facilitates secure operation over open networks by distributing security functions across multiple protected boundaries.
2Reliability
If keys are delivered to the card for authentication before data access, then data protection is ensured, but the system becomes difficult to expand to open networks because key delivery over public domain networks causes security concerns
Solution Approach 1:
The card manager serves as a secure intermediary that manages key delivery and authentication without requiring direct key exposure over public networks. It establishes secure channels with remote servers and handles authentication operations, enabling data access while maintaining protection even when communicating through open network environments.
Solution Approach 2:
The system performs preliminary authentication actions through the card manager before allowing any data access operations. Security keys are pre-loaded into the card manager in a secure manner, and authentication is performed in advance before data retrieval, ensuring that even if key delivery occurs over open networks, the data remains protected through prior security establishment.
3Reliability
If a three-tier security model with personalized security keys is implemented, then secure transactions over open networks are enabled, but the device complexity increases due to multiple security layers and key management requirements
Solution Approach 1:
The card manager is designed as a universal component that performs multiple security-related functions: key management, authentication, authorization, and secure communication. By consolidating these diverse security operations into a single multi-functional module, the patent reduces the practical complexity of implementing the three-tier security model while maintaining comprehensive security coverage.
Solution Approach 2:
The patent merges the security management functions into a unified card manager component that handles all security operations for the e-purse. This consolidation combines key storage, authentication protocols, and access control into a single integrated system, reducing the complexity that would otherwise arise from managing separate security layers and components.
Data Source
AI summary
Techniques for funding an electronic purse (e-purse) are disclosed. According to one aspect of the invention, a mechanism is provided to enable a portable device to conduct transactions over an open network with a payment server without compromising security. In one embodiment, a device is loaded with an e-purse manager. The e-purse manager is configured to manage various transactions and functions as a mechanism to access an e-purse therein. The e-purse is funded by interactions among the e-purse manager, a payment server and a financial institution (its server) that maintains an account therefor.


