Mobile Gateway Authentication for Secure Payment Channels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices used for payments lack secure issuer update solutions and face security concerns due to the risk of intercepted sensitive information during transactions, especially when lost or stolen, and there is a need to protect both information sent from and to the device.
Innovation Solution
A method and system that authenticate mobile devices via a third-party mobile gateway before information transmission, using challenge-response messages and a key management center to establish a secure channel for communication, ensuring the integrity and confidentiality of data exchanged.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If mobile devices are used for contactless payments, then payment convenience is improved, but security against interception and unauthorized use is worsened
Solution Approach 1:
A mobile gateway acts as an intermediary between the consumer device and the payment network. The gateway receives payment requests from the mobile device, forwards them to the payment network, and relays responses back. This intermediary layer protects the mobile device from direct exposure to potential security threats while maintaining contactless payment functionality.
Solution Approach 2:
Challenge-response authentication is performed before the actual payment transaction. The mobile gateway sends a challenge to the consumer device, which must respond correctly using stored authentication data. This preliminary authentication ensures that only authorized devices can initiate payments, preventing unauthorized use of lost or stolen devices.
2Reliability
If issuer updates are implemented for chip cards, then transaction security is improved, but device compatibility is worsened when using mobile devices
Solution Approach 1:
The mobile gateway serves as a mediator that enables issuer updates for mobile devices without requiring physical contact. Instead of inserting the device into a POS terminal, the gateway communicates with the consumer device wirelessly to deliver update data from the payment network, maintaining security while adapting to mobile form factors.
Solution Approach 2:
The physical contact mechanism (inserting chip card into POS terminal) is replaced with wireless communication through the mobile gateway. The gateway transmits update data to the consumer device via mobile networks, eliminating the need for mechanical contact while achieving the same security update objective.
3Reliability
If authentication protocols are added to mobile payments, then information security is improved, but system complexity is worsened
Solution Approach 1:
The mobile gateway consolidates authentication logic in a centralized location rather than requiring complex authentication code in every mobile device. The gateway manages challenge-response protocols and coordinates with the payment network, reducing the complexity burden on consumer devices while maintaining strong security.
Solution Approach 2:
Complex authentication management functions are extracted from the consumer device and placed in the mobile gateway. The device only needs to store authentication data and respond to challenges, while the gateway handles protocol coordination, message formatting, and communication with the payment network.
Data Source
AI summary
A system, method, and server computer configured to authenticate a consumer device. The consumer device is authenticated via a mobile gateway using challenge-response authentication. If the consumer device is successfully authenticated, a secure channel is established between the consumer device and a first entity. The secure channel allows for secure communication between the consumer device and the first entity.


