Provisioning Payment Credentials to Mobile Devices Without Secure Elements
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices without secure elements cannot conduct near field financial transactions, as they lack the necessary hardware to securely store and transmit payment information.
Innovation Solution
A method and system for provisioning payment credentials to mobile devices without secure elements, involving the generation of a card profile, single-use keys, and dynamic card validation codes, which allows for secure transmission of payment information via near field communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If mobile devices use secure elements to store payment credentials, then security and reliability of payment transactions are improved, but device compatibility and ease of operation deteriorate because not all mobile devices have secure elements
Solution Approach 1:
The patent introduces a remote secure element (RSE) system that acts as an intermediary between the mobile device and the payment network. The RSE stores payment credentials remotely in the cloud, allowing mobile devices without secure elements to access secure payment processing through this intermediary service. The system uses secure communication channels and authentication protocols to bridge the gap between devices lacking hardware security and the requirements for secure payment transactions.
Solution Approach 2:
The patent creates a virtual copy of the secure element functionality in the cloud. Instead of requiring physical secure element hardware in each device, the system provisions virtual payment credentials and security keys to the mobile device through secure provisioning protocols. This virtualized approach replicates the security functions of a physical secure element without requiring the hardware to be present in the device.
2Adaptability or versatility
If mobile devices provision payment credentials without secure elements, then device compatibility and ease of operation are improved, but security and reliability of payment transactions worsen
Solution Approach 1:
The remote secure element system serves as a trusted intermediary that manages security on behalf of the mobile device. The RSE holds the actual payment credentials and security keys, while the mobile device only contains application-layer software that communicates with the RSE through secure channels. This architecture allows insecure devices to perform secure transactions by delegating security functions to the intermediary RSE service.
Solution Approach 2:
The patent moves the security function from the physical hardware dimension (secure element chip in device) to the network/cloud dimension (remote secure element service). By transitioning security from a local hardware constraint to a remote service capability, the system enables devices without physical secure elements to access security functions through network-based provisioning and authentication mechanisms.
3Reliability
If traditional secure element hardware is required for NFC payments, then security is improved, but device complexity and manufacturing cost worsen
Solution Approach 1:
The patent extracts the secure element functionality from the mobile device hardware and relocates it to a remote cloud-based service. The mobile device retains only the NFC communication capability and application software, while the actual secure credential storage and management functions are taken out and hosted remotely. This separation allows devices to be manufactured without expensive secure element hardware while maintaining security through the remote service.
Solution Approach 2:
The patent replaces expensive, permanent secure element hardware with a software-based provisioning system that uses less costly components. The secure credentials are provisioned as virtual objects that can be remotely updated, revoked, or replaced without requiring hardware changes. This approach uses cheaper software-based security mechanisms that can be deployed and managed more flexibly than hardware secure elements.
Data Source
AI summary
A method for generating and provisioning payment credentials to a mobile device lacking a secure element includes: generating a card profile associated with a payment account, wherein the card profile includes at least payment credentials corresponding to the associated payment account and a profile identifier; provisioning, to a mobile device lacking a secure element, the generated card profile; receiving, from the mobile device, a key request, wherein the key request includes at least a mobile identification number (PIN) and the profile identifier; using the mobile PIN; generating a single use key, wherein the single use key includes at least the profile identifier, an application transaction counter, and a generating key for use in generating a payment cryptogram valid for a single financial transaction; and transmitting the generated single use key to the mobile device.


