Intermediate Service Organization for Secure Payment Infrastructure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing mobile USB key payment solution lacks service abstraction, resulting in a less open technical framework, limiting the security and flexibility of payment infrastructure in scenarios like mobile banking transfers.
Innovation Solution
A method and device for establishing a secure infrastructure by using intermediate service organizations to encrypt and decrypt organization secret keys and terminal public keys, ensuring secure storage and communication between terminals and third-party service organizations, while providing better openness through asymmetric key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If mobile USB key uses direct business between mobile phone manufacturers and banks, then payment security is achieved, but service abstraction is lacking and technical framework openness is reduced
Solution Approach 1:
The patent introduces a service provider as an intermediary layer between the terminal and the bank. The service provider obtains the terminal's public key and uses it to encrypt data before transmitting to the bank, while the bank's private key decrypts and signs responses. This intermediary mechanism enables service abstraction and improves technical framework openness without compromising security, as the cryptographic key exchange ensures reliable authentication and data protection.
2Adaptability or versatility
If asymmetric key management is implemented through intermediate service organization, then technical framework openness is improved, but system complexity increases
Solution Approach 1:
The service provider acts as a mediator that simplifies the complexity for end users. While the underlying asymmetric key management system is sophisticated, the service provider handles key exchange, encryption, and signature verification transparently. The terminal only needs to store its public key and verify signatures, while the service provider manages the cryptographic operations with the bank, thus hiding the system complexity from users.
Solution Approach 2:
The system is segmented into distinct functional components: the terminal generates and stores its public key, the service provider handles key exchange and data encryption, and the bank performs decryption and signature verification. This segmentation allows each component to be optimized independently and simplifies the overall system architecture by distributing complexity across multiple specialized modules.
3Reliability
If organization secret key is encrypted and transmitted through intermediate service organization, then communication security is enhanced, but transmission time increases
Solution Approach 1:
The terminal generates its public key in advance and stores it locally before any communication with the bank. When establishing a secure connection, the terminal immediately sends this pre-generated public key to the service provider, which then uses it to encrypt data. This preliminary key generation eliminates the need for time-consuming key exchange protocols during actual communication, reducing transmission time while maintaining security through the encrypted channel.
Data Source
AI summary
A method, terminal and device for establishing security infrastructure, comprising: an intermediate service organization receives an organization secret key sent by a third-party service organization; the intermediate service organization encrypts the organization secret key by a first encryption means and sends the encrypted organization secret key to a security storage region of a terminal; the intermediate service organization receives a first terminal public key encrypted by the terminal using a second encryption means; and the intermediate service organization sends the first terminal public key obtained by decryption to the third-party service organization. The organization secret key of the third-party service organization may be sent to the terminal through the intermediate service organization, and the first terminal public key of the terminal may be sent to the third-party service organization, thus a universal security infrastructure and a technical frame work having good openness may be provided by the intermediate service organization.


