Mobile Device Secure Element Tokenization for Transaction Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional electronic transaction systems, particularly in financial and non-financial contexts, face security issues due to the transmission of sensitive information and lack of robust user authentication, leading to increased fraud risks both offline and online.

Innovation Solution

A method and system utilizing a mobile device to securely perform electronic transactions by receiving user identification and transaction information, determining payment information, and authenticating users, thereby reducing the need to transmit sensitive data and enhancing authentication through mobile channel security and geo-location verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If sensitive payment information is transmitted between POS terminal and payment backend, then electronic transactions can be processed, but security risks increase due to potential interception and misuse of data

Engineering Contradiction:
Improvetransaction securityVSAvoidfraud risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive payment information from the transmission path between POS terminal and payment backend. Instead of transmitting card numbers, CVV, and other sensitive data, the system uses a tokenized approach where only a transaction identifier is transmitted. The actual payment information remains stored securely in the mobile device's secure element, effectively removing it from the vulnerable transmission path.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a token as an intermediary element between the payment information and the transaction processing system. The token serves as a mediator that allows transaction authorization without exposing the actual payment credentials. This intermediary layer prevents direct access to sensitive information while enabling the transaction to proceed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If conventional authentication systems are used at POS terminals, then transaction processing is simple, but fraud detection capability is insufficient

Engineering Contradiction:
Improvetransaction simplicityVSAvoidauthentication strength
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges multiple authentication factors into a single unified process. The system combines device-based authentication (secure element in mobile device), transaction context verification, and optional biometric authentication into one integrated flow. This allows the system to maintain simplicity for the user while incorporating multiple layers of authentication strength.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs preliminary authentication actions before the actual transaction occurs. The mobile device authenticates the user and establishes security credentials in advance, so that when the transaction is initiated at the POS terminal, the authentication is already complete or can be quickly verified. This preliminary authentication strengthens security without adding complexity to the point-of-sale interaction.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If manual entry of payment information is required for online transactions, then transaction flexibility is maintained, but time consumption increases and error potential rises

Engineering Contradiction:
Improvetransaction flexibilityVSAvoidtransaction duration
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent performs preliminary setup of payment information in the mobile device's secure element before online transactions occur. During the initial configuration, payment credentials are stored securely and tokenized. When an online transaction is needed, the pre-configured token can be quickly deployed without requiring manual entry of card details, significantly reducing transaction time while maintaining flexibility through the ability to store multiple payment methods.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If payment information is stored in mobile device secure element, then security is enhanced, but device complexity increases

Engineering Contradiction:
Improveinformation securityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a simplified copy or representation of the payment system architecture that leverages the mobile device's existing secure element. Rather than building a completely new secure storage system, the patent copies and adapts the proven secure element technology already present in modern mobile devices. This approach enhances security by utilizing established secure hardware while avoiding the need to design and implement a new complex security architecture from scratch.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11127009B2Methods and systems for using a mobile device to effect a secure electronic transaction
Publication Date: 2021.09.21 ID-TX INC
  • US11127009B2 patent drawing
  • US11127009B2 patent drawing
  • US11127009B2 patent drawing

AI summary

According to one aspect, the subject matter described herein includes a method for using a mobile device to effect a secure electronic transaction. In one embodiment, the method includes, at a mobile backend server comprising one or more processors: receiving, from a mobile device of a user that is engaged in or desires to engage in an electronic transaction with an entity other than the user, first information that identifies the user and second information that directly or indirectly identifies the electronic transaction, wherein the second information does not contain payment information for the user; using the first information to identify the user; determining user payment information for the identified user; using the second information to identify a target for the payment information; and sending the user payment information to the identified target for use to initiate the electronic transaction.