Mobile Payment Security via Intermediary Authentication and Data Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for conducting online payment transactions through mobile communication devices lack secure and efficient mechanisms for authorizing payments, particularly in point-of-sale scenarios, which can lead to potential identity theft and fraudulent transactions.

Innovation Solution

A system and method that utilizes a mobile communication device to securely send payment authorizations from a point-of-sale device to a payment entity, reducing the risk of identity theft by minimizing the transmission of sensitive user information, and incorporating NFC technology for contactless payments, along with a mobile wallet application for managing transactions and storing payment information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If mobile communication devices are used to conduct online payment transactions, then convenience and accessibility are improved, but security risks and vulnerability to identity theft increase

Engineering Contradiction:
Improveconvenience of payment transactionsVSAvoidsecurity of payment transactions
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary authentication system that mediates between the mobile device and payment processors. The system uses authentication information (such as biometric data or security tokens) stored securely in the mobile device to verify user identity without transmitting sensitive payment information over networks, thus maintaining convenience while enhancing security through an additional verification layer

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the payment transaction process into distinct components: authentication verification, payment authorization, and transaction processing. By separating the authentication function from the payment processing function, the system allows mobile devices to provide convenient access while the segmented authentication module independently verifies user identity, reducing the risk of identity theft even if payment data is compromised

Inventive Principle:
Principle #1Segmentation

2Speed

If payment authorization is transmitted through mobile communication devices, then transaction speed is improved, but exposure to fraudulent transactions increases

Engineering Contradiction:
Improvetransaction processing speedVSAvoidfraudulent transactions
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication actions before payment authorization is transmitted. The system pre-verifies user identity and authenticates the transaction request using security credentials stored in the mobile device before initiating the payment transmission. This preliminary verification step occurs locally on the device, maintaining fast transaction speeds while preventing fraudulent transactions from being authorized in the first place

Inventive Principle:
Principle #10Preliminary action

3Productivity

If sensitive user information is transmitted for payment authorization, then payment processing is enabled, but risk of identity theft increases

Engineering Contradiction:
Improvepayment processing efficiencyVSAvoididentity theft risk
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The patent extracts and removes sensitive user information (such as full credit card numbers, CVV codes, and personal identifiers) from the transmission process. Instead of transmitting complete payment data, the system uses tokenized representations or authentication credentials that are insufficient for identity theft but sufficient for authorizing payments. This extraction of sensitive data maintains payment processing efficiency while eliminating the primary vector for identity theft

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20240029114A1Blaze remote delivery of advertisements to a non-browser based application
Publication Date: 2024.01.25 FISHER MICHELLE
  • US20240029114A1 patent drawing
  • US20240029114A1 patent drawing
  • US20240029114A1 patent drawing

AI summary

A method and system for receiving digital artifacts from a management server. The method includes sending a request for a digital artifact from a mobile application to the management server for display within a specific mobile application generated screen, receiving the digital artifact from the management server, and displaying the digital artifact with the specific mobile application generated screen.