Mobile Payment Authentication via Simplex QR Code and Unpredictable Numbers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current payment systems, such as EMV transactions, require duplex communication and additional hardware like NFC-compatible terminals, which are costly and pose security risks, while QR code payments are not compliant with EMV protocols and rely on mobile data connections, leading to inconvenient and insecure transactions.
Innovation Solution
A method for authenticating transactions using a mobile payment application on a mobile device through a one-way communication system, where an image payment code, such as a QR code, is displayed on the device, allowing merchants to scan and verify transactions without needing NFC or additional hardware, using transaction unpredictable numbers stored securely on the device and server for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If EMV-compliant POS terminals with dual direction communication protocols are deployed, then transaction security and global interoperability are ensured, but hardware costs, deployment costs, and maintenance costs for merchants increase considerably
Solution Approach 1:
The patent extracts the complex dual-direction communication requirement from the transaction system and replaces it with a simplex (one-way) communication model. The mobile device generates and sends a payment code containing all necessary authentication data, eliminating the need for merchants to deploy EMV-compliant terminals with dual-direction communication capabilities.
Solution Approach 2:
The patent creates a copy of the payment authentication mechanism by generating a payment code that encapsulates transaction data, authentication information, and verification credentials. This code serves as a portable representation of the payment instrument, replacing the need for physical EMV cards and terminals.
2Ease of operation
If NFC-compatible payment terminals are deployed, then contactless payment functionality is enabled, but hardware, software, and support expenses associated with having NFC-enabled devices on site increase
Solution Approach 1:
The patent replaces the mechanical NFC communication system with an optical/digital code-based system. Instead of using electromagnetic fields for near-field communication, the system uses visual display of payment codes that can be captured by standard imaging devices, eliminating the need for specialized NFC hardware.
3Ease of operation
If sensitive information is stored on the customer's smart phone for NFC transactions, then NFC payment functionality is enabled, but the system becomes vulnerable to hacking and compromise if the smart phone is acquired or if a remote connection can be made
Solution Approach 1:
The patent performs preliminary actions by generating the payment code with embedded authentication data and transaction parameters before the actual transaction occurs. The code is displayed only when needed and contains time-limited or single-use credentials, reducing the window of vulnerability compared to continuously stored sensitive information.
4Ease of operation
If QR code or bar code payment systems are used with information flux between seller, buyer, and server, then customers have an easier way to pay, but the system occupies the server with many information exchanges which can be critical during high transaction periods
Solution Approach 1:
The patent segments the transaction information into distinct components within the payment code structure, allowing the server to process only essential authentication data rather than exchanging extensive information back and forth. The payment code contains pre-packaged transaction details that reduce server processing requirements.
Data Source
AI summary
The present invention generally relates to systems and methods for authenticating transactions through a simplex communication. To allow trusting the transaction with a payment by an image code such QR code, the invention proposes means to authenticate said transaction. For that, when the mobile payment application is loaded into preferably a secure element of the user mobile device a registration process is enabled. During this registration process on a server, an account of the user is created and a set of unpredictable numbers in quantity N is generated. This set of unpredictable numbers is transmitted to the mobile payment application for storage. The payment application uses the stored set of transaction unpredictable numbers for next N times transactions performed by the mobile payment application for transaction cryptogram calculation. The same transaction unpredictable number is recovered in the server side during the transaction authorization process.


