Merchant-Associated Device Validation Using Public-Key Registries
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile transactions and payments lack enhanced convenience, security, and experiences for merchants, consumers, and payment service providers due to limited interactions between smart devices and contactless terminals.
Innovation Solution
Implementing a mobile payment system that allows for non-standard processing of transactions, provides enhanced merchant experiences, utilizes rendezvous requests for multi-step transactions, and secures data exchange with public key registries, enabling flexible and secure mobile transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If basic interaction between smart device and contactless terminal is used, then device complexity is reduced, but transaction security and user experience are insufficient
Solution Approach 1:
The patent segments the transaction validation process into multiple independent components: device identifier extraction, public key retrieval from registry, cryptographic validation, and transaction approval. This modular approach enhances security through comprehensive verification while maintaining manageable system complexity by organizing validation steps as separate, reusable modules.
Solution Approach 2:
The patent implements preliminary action by pre-registering public keys in a centralized registry before transactions occur. The mobile device retrieves and validates the terminal's public key in advance during the transaction flow, enabling security verification to be performed proactively rather than reactively, thus enhancing transaction security without adding significant operational complexity.
2Adaptability or versatility
If standardized processing is used, then ease of operation is improved, but flexibility for non-standard transactions is limited
Solution Approach 1:
The patent applies dynamics by making the transaction processing system adaptable to different transaction types and requirements. The system can dynamically select between standardized processing paths for routine transactions and customized validation sequences for non-standard cases, allowing flexibility in processing approaches while maintaining ease of operation through automated route selection based on transaction characteristics.
Solution Approach 2:
The patent implements universality through a multi-functional validation framework that handles both standard and non-standard transactions using a common infrastructure. The same public key registry and validation mechanisms serve multiple transaction types (payments, ticketing, access control), providing flexible adaptability across different use cases while maintaining operational simplicity through a unified processing architecture.
3Reliability
If public key validation is implemented, then transaction security is enhanced, but processing time increases
Solution Approach 1:
The patent reduces validation time by performing preliminary actions: public keys are pre-registered in a centralized registry and cached in the mobile device. During transactions, the system retrieves pre-stored keys locally rather than performing full cryptographic validation from scratch, significantly reducing processing time while maintaining security through the pre-established trust framework.
Solution Approach 2:
The patent applies local quality by implementing a hierarchical validation approach where frequently accessed public keys are stored locally in the mobile device's secure storage. This local caching eliminates the need for repeated network queries and complex remote validation for routine transactions, reducing processing time while maintaining high security through localized cryptographic verification of trusted merchants.
Data Source
AI summary
Methods, systems, and computer program products for providing enhanced mobile transactions and payments are disclosed. A computer-implemented method may include providing a registry of public keys to allow users to securely exchange mobile payment data with respective trusted merchants, sending a request from a computing device of a user to validate a merchant, storing a public key for the merchant from the registry, receiving a merchant identifier from a terminal during a mobile transaction indicating that the terminal is associated with the merchant, receiving a request for information from the terminal as part of the mobile transaction, determining whether the terminal requesting the information is trusted, providing the requested information encrypted using the public key to the terminal when the terminal is trusted, and providing decoy response information to the terminal when the terminal is determined to be untrusted.


