Mobile Device Secure Element Tokenization for Transaction Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional electronic transaction systems, particularly in financial and non-financial contexts, face security issues due to the transmission of sensitive information and lack of robust user authentication, leading to increased fraud risks both offline and online.
Innovation Solution
A method and system utilizing a mobile device to securely perform electronic transactions by receiving user identification and transaction information, determining payment information, and authenticating users, thereby reducing the need to transmit sensitive data and enhancing authentication through mobile channel security and geo-location verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If sensitive payment information is transmitted between POS terminal and payment backend, then electronic transactions can be processed, but security risks increase due to potential interception and misuse of data
Solution Approach 1:
The patent extracts sensitive payment information from the transmission path between POS terminal and payment backend. Instead of transmitting card numbers, CVV, and other sensitive data, the system uses a tokenized approach where only a transaction identifier is transmitted. The actual payment information remains stored securely in the mobile device's secure element, effectively removing it from the vulnerable transmission path.
Solution Approach 2:
The patent introduces a token as an intermediary element between the payment information and the transaction processing system. The token serves as a mediator that allows transaction authorization without exposing the actual payment credentials. This intermediary layer prevents direct access to sensitive information while enabling the transaction to proceed.
2Ease of operation
If conventional authentication systems are used at POS terminals, then transaction processing is simple, but fraud detection capability is insufficient
Solution Approach 1:
The patent merges multiple authentication factors into a single unified process. The system combines device-based authentication (secure element in mobile device), transaction context verification, and optional biometric authentication into one integrated flow. This allows the system to maintain simplicity for the user while incorporating multiple layers of authentication strength.
Solution Approach 2:
The patent performs preliminary authentication actions before the actual transaction occurs. The mobile device authenticates the user and establishes security credentials in advance, so that when the transaction is initiated at the POS terminal, the authentication is already complete or can be quickly verified. This preliminary authentication strengthens security without adding complexity to the point-of-sale interaction.
3Adaptability or versatility
If manual entry of payment information is required for online transactions, then transaction flexibility is maintained, but time consumption increases and error potential rises
Solution Approach 1:
The patent performs preliminary setup of payment information in the mobile device's secure element before online transactions occur. During the initial configuration, payment credentials are stored securely and tokenized. When an online transaction is needed, the pre-configured token can be quickly deployed without requiring manual entry of card details, significantly reducing transaction time while maintaining flexibility through the ability to store multiple payment methods.
4Reliability
If payment information is stored in mobile device secure element, then security is enhanced, but device complexity increases
Solution Approach 1:
The patent creates a simplified copy or representation of the payment system architecture that leverages the mobile device's existing secure element. Rather than building a completely new secure storage system, the patent copies and adapts the proven secure element technology already present in modern mobile devices. This approach enhances security by utilizing established secure hardware while avoiding the need to design and implement a new complex security architecture from scratch.
Data Source
AI summary
According to one aspect, the subject matter described herein includes a method for using a mobile device to effect a secure electronic transaction. In one embodiment, the method includes, at a mobile backend server comprising one or more processors: receiving, from a mobile device of a user that is engaged in or desires to engage in an electronic transaction with an entity other than the user, first information that identifies the user and second information that directly or indirectly identifies the electronic transaction, wherein the second information does not contain payment information for the user; using the first information to identify the user; determining user payment information for the identified user; using the second information to identify a target for the payment information; and sending the user payment information to the identified target for use to initiate the electronic transaction.


