Mobile Payment Code Segmentation for Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile payment systems lack security and efficiency in transactions, and do not provide 100% protection against common attacks, especially when using QR codes, barcodes, or additional hardware and software for communication with merchants.

Innovation Solution

A method for generating a secure code using encryption and encoding techniques, involving a client, a first server, and a second server, where the code is split into public and private parts, with the public part displayed as a QR code and the private part stored on the second server, ensuring only authorized entities can decrypt and complete transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional mobile payment systems use QR codes, barcodes, or additional hardware for transactions, then communication with merchants is enabled, but security against attacks is compromised and 100% protection cannot be assured

Engineering Contradiction:
Improvemobile payment operationVSAvoidtransaction security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authorization code is segmented into two distinct parts: a public part that can be displayed to the user and a private part that remains securely stored on the server. This segmentation allows the system to maintain ease of operation by displaying readable information while ensuring security by keeping the sensitive private component separate and protected from exposure during the transaction process

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary encoding mechanism that transforms sensitive authorization data into a secure format. The encoding method acts as a mediator between the private data and its display representation, ensuring that even if the public part is exposed, the underlying sensitive information remains protected through the one-way encoding transformation

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If sensitive information is displayed during transaction for user verification, then user authorization is enabled, but information exposure creates security vulnerabilities

Engineering Contradiction:
Improveuser authorizationVSAvoidinformation exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The authorization information is divided into public and private components, allowing the public part to be safely displayed for user verification while the private part remains hidden on the server, thus enabling user authorization without exposing sensitive information

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The sensitive private information is extracted from the displayable content and stored separately on the server. Only the non-sensitive public part is extracted for display purposes, eliminating the harmful factor of information exposure while maintaining the functionality of user verification

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2693687B1Method for generating a code, authorization method and authorization system for authorizing an operation
Publication Date: 2016.10.05 BANCO BILBAO VIZCAYA ARGENTARIA
  • EP2693687B1 patent drawingFigure 1
  • EP2693687B1 patent drawingFigure 2
  • EP2693687B1 patent drawingFigure 3

AI summary

The present invention relates to a method for generating a code and a method comprising the authorization of an operation carried out by a client on a first server. A second server generating an authorization code according to an encoding method is involved in the authorization. The operations can be transactions, access to a web page, user-to-user payments, user-to-business payments, online user-to-business payments, cash withdrawal in automated teller machines, etc.