Mobile Terminal Payment Application Security Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile terminals, such as mobile phones used as points of sale, face security risks due to hosting various applications that may compromise payment transactions, especially in contactless communication scenarios, where it is essential to ensure the authenticity and security of payment applications.
Innovation Solution
A method is implemented to control the execution of payment applications by verifying the application identifier against a list of authorized applications, where the execution is blocked by default and only authorized if the request originates from a secure element, ensuring secure transactions by transmitting an application selection request and verifying the identifier received from a payment device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a mobile terminal hosts various applications to enable versatile functionality, then the adaptability and versatility of the device is improved, but the security risk of payment transactions deteriorates due to potential malicious applications
Solution Approach 1:
The patent segments the application execution control into two distinct paths: a default blocked path for all applications and an authorized path for whitelisted payment applications. This segmentation is implemented through a verification mechanism that checks application identifiers against an authorized list, creating separate execution channels that isolate secure payment operations from potentially malicious applications.
Solution Approach 2:
The patent introduces an intermediary verification mechanism that acts as a mediator between the application selection request and the actual execution. This intermediary checks the application identifier against an authorized list and verifies that requests originate from secure elements, thereby mediating between the need for application execution and the requirement for transaction security.
2Reliability
If all applications are blocked by default to ensure security, then the security of payment transactions is improved, but the ease of operation deteriorates due to restricted application execution
Solution Approach 1:
The patent inverts the traditional approach by blocking all applications by default and allowing execution only for authorized applications. Instead of allowing all applications and blocking specific malicious ones, the system reverses the default state to 'blocked' and uses a whitelist approach, making the secure path the exception rather than the rule.
Solution Approach 2:
The patent performs preliminary verification of application identifiers against an authorized list before allowing execution. This preliminary action ensures that only pre-authorized payment applications can execute, preventing malicious applications from running while maintaining ease of operation for legitimate applications through automated verification.
3Ease of operation
If application execution is freely allowed to maintain ease of operation, then the ease of operation is improved, but the object-generated harmful factors worsen due to potential malicious applications pirating transactions
Solution Approach 1:
The patent applies preliminary anti-action by blocking all application execution by default and requiring explicit authorization for payment applications. This preemptive measure counteracts potential malicious actions before they can occur, preventing fraudulent transactions while maintaining ease of operation for authorized applications through automated verification.
Solution Approach 2:
The verification mechanism acts as an intermediary that filters application execution requests, allowing only authorized payment applications to proceed while blocking malicious ones. This intermediary layer prevents harmful factors from manifesting while maintaining operational ease for legitimate applications.
Data Source
AI summary
A method of controlling the execution of a payment application by a mobile terminal, in near field communication with a payment device. The method includes transmitting an application selection request to the payment device, and verifying the application identifier received from the payment device against a list of authorized applications. The verification is performed by the circuit having the application selection request transiting therethrough.


