Provisioning Payment Credentials to Mobile Devices Without Secure Elements

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices without secure elements cannot conduct near field financial transactions, as they lack the necessary hardware to securely store and transmit payment information.

Innovation Solution

A method and system for provisioning payment credentials to mobile devices without secure elements, involving the generation of a card profile, single-use keys, and dynamic card validation codes, which allows for secure transmission of payment information via near field communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If mobile devices use secure elements to store payment credentials, then security and reliability of payment transactions are improved, but device compatibility and ease of operation deteriorate because not all mobile devices have secure elements

Engineering Contradiction:
Improvesecurity of payment transactionsVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a remote secure element (RSE) system that acts as an intermediary between the mobile device and the payment network. The RSE stores payment credentials remotely in the cloud, allowing mobile devices without secure elements to access secure payment processing through this intermediary service. The system uses secure communication channels and authentication protocols to bridge the gap between devices lacking hardware security and the requirements for secure payment transactions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a virtual copy of the secure element functionality in the cloud. Instead of requiring physical secure element hardware in each device, the system provisions virtual payment credentials and security keys to the mobile device through secure provisioning protocols. This virtualized approach replicates the security functions of a physical secure element without requiring the hardware to be present in the device.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If mobile devices provision payment credentials without secure elements, then device compatibility and ease of operation are improved, but security and reliability of payment transactions worsen

Engineering Contradiction:
Improvedevice compatibilityVSAvoidsecurity of payment transactions
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The remote secure element system serves as a trusted intermediary that manages security on behalf of the mobile device. The RSE holds the actual payment credentials and security keys, while the mobile device only contains application-layer software that communicates with the RSE through secure channels. This architecture allows insecure devices to perform secure transactions by delegating security functions to the intermediary RSE service.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent moves the security function from the physical hardware dimension (secure element chip in device) to the network/cloud dimension (remote secure element service). By transitioning security from a local hardware constraint to a remote service capability, the system enables devices without physical secure elements to access security functions through network-based provisioning and authentication mechanisms.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If traditional secure element hardware is required for NFC payments, then security is improved, but device complexity and manufacturing cost worsen

Engineering Contradiction:
Improvesecurity of payment transactionsVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the secure element functionality from the mobile device hardware and relocates it to a remote cloud-based service. The mobile device retains only the NFC communication capability and application software, while the actual secure credential storage and management functions are taken out and hosted remotely. This separation allows devices to be manufactured without expensive secure element hardware while maintaining security through the remote service.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces expensive, permanent secure element hardware with a software-based provisioning system that uses less costly components. The secure credentials are provisioned as virtual objects that can be remotely updated, revoked, or replaced without requiring hardware changes. This approach uses cheaper software-based security mechanisms that can be deployed and managed more flexibly than hardware secure elements.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS20240029062A1Systems and methods for processing mobile payments by provisoning credentials to mobile devices without secure elements
Publication Date: 2024.01.25 MASTERCARD INT INC
  • US20240029062A1 patent drawing
  • US20240029062A1 patent drawing
  • US20240029062A1 patent drawing

AI summary

A method for generating and provisioning payment credentials to a mobile device lacking a secure element includes: generating a card profile associated with a payment account, wherein the card profile includes at least payment credentials corresponding to the associated payment account and a profile identifier; provisioning, to a mobile device lacking a secure element, the generated card profile; receiving, from the mobile device, a key request, wherein the key request includes at least a mobile identification number (PIN) and the profile identifier; using the mobile PIN; generating a single use key, wherein the single use key includes at least the profile identifier, an application transaction counter, and a generating key for use in generating a payment cryptogram valid for a single financial transaction; and transmitting the generated single use key to the mobile device.