Mobile Payment Authentication Using Dual Cryptograms Without Secure Elements

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile devices lacking secure elements face challenges in conducting secure payment transactions due to security concerns, limiting their use in contactless and remote payment methods.

Innovation Solution

A method and system for generating and transmitting dual application cryptograms using session keys and personal identification numbers, stored securely in a mobile device without a secure element, to authenticate both the device and user, enhancing transaction security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure elements are used in mobile devices, then security of payment transactions is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity of payment transactionsVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a virtual copy of the secure element functionality through software-based cryptographic operations. Instead of relying on physical secure element hardware, the system uses virtualization to replicate security functions in the software layer, allowing standard mobile devices to achieve secure payment capabilities without additional hardware components.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical/hardware-based secure element with a software-based cryptographic system. The physical secure element chip is substituted with virtual cryptographic operations including key generation, encryption, and authentication protocols that run on the device's standard processor, eliminating the need for specialized hardware while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Device complexity

If secure elements are not used in mobile devices, then device complexity is reduced, but security of payment transactions deteriorates

Engineering Contradiction:
Improvedevice complexityVSAvoidsecurity of payment transactions
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent changes the fundamental parameters of security implementation by transitioning from hardware-based security to software-based cryptographic security. This involves changing the security model from physical isolation to mathematical protection, using cryptographic keys, encryption algorithms, and protocol-based authentication to achieve security without secure elements.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces cryptographic intermediaries including virtual secure environments, trusted execution environments, and cryptographic protocol layers that mediate between the application and the underlying hardware. These intermediaries provide security functions without requiring direct access to or physical secure element hardware.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If cryptographic operations are performed without secure elements, then ease of operation is improved, but security concerns increase

Engineering Contradiction:
Improveease of operationVSAvoidsecurity concerns
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements self-service security where the mobile device autonomously performs cryptographic operations including key generation, encryption, and authentication without requiring external secure element hardware. The device's standard components handle security functions independently, making the system both easier to operate and deploy while maintaining security through software-based protection.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12499445B2Method and system for secure authentication of user and mobile device without secure elements
Publication Date: 2025.12.16 MASTERCARD INT INC
  • US12499445B2 patent drawing
  • US12499445B2 patent drawing
  • US12499445B2 patent drawing

AI summary

A method for generating payment credentials in a payment transaction includes storing, in a memory, at least a card master key associated with a transaction account. The method also includes generating, by a processing device, a first session key based on at least the stored card master key; generating, by the processing device, a second session key; generating, by the processing device, a first application cryptogram based on at least the first session key; generating, by the processing device, a second application cryptogram based on at least the second session key; and transmitting, by a transmitting device, at least the first application cryptogram and second application cryptogram for use in a payment transaction.