Mobile Payment Authentication via Remote Key Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile payment systems face challenges in maintaining control, security, and reliability due to the need for cooperation among multiple parties and high memory or processing power requirements on mobile devices, making secure transactions difficult to manage.

Innovation Solution

A method and apparatus that process secure transactions using a mobile device and a virtual payment gateway server, where a mobile device transport key and session key are established for secure communication, and confidential data is not stored on the mobile device or POS, ensuring secure authentication and transaction processing without exposing card information to merchants or mobile devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If mobile payment systems use multiple parties cooperation for secure transactions, then security is improved, but control and reliability deteriorate due to distributed trust issues

Engineering Contradiction:
ImprovesecurityVSAvoidcontrol
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the secure element and cryptographic key storage from the mobile device to a remote server. The mobile device only stores a device identifier, while all sensitive authentication data and cryptographic operations are performed remotely, eliminating the need for complex multi-party key management on the device itself.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a remote server as an intermediary that mediates all authentication and cryptographic operations. This server acts as a trusted third party that the mobile device and POS terminal both communicate with, simplifying the trust model compared to direct peer-to-peer cryptographic verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If mobile devices store cryptographic keys and secure data locally, then authentication capability is improved, but memory and processing power requirements increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidmemory
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent removes cryptographic keys and secure authentication data from local mobile device storage. Only a minimal device identifier is stored locally, while all cryptographic material is maintained and managed on the remote server, dramatically reducing mobile device memory requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If mobile devices perform cryptographic operations locally, then authentication speed is improved, but processing power requirements increase

Engineering Contradiction:
Improveauthentication speedVSAvoidprocessing power
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent extracts cryptographic processing from the mobile device to the remote server. The mobile device only performs lightweight operations like generating random numbers and communicating with the server, while all computationally intensive cryptographic key generation, signing, and verification is performed on the server with superior processing resources.

Inventive Principle:
Principle #2Taking out (Extraction)

4Ease of operation

If card information is stored on mobile devices or POS terminals, then transaction processing is simplified, but security and compliance requirements increase

Engineering Contradiction:
Improvetransaction processingVSAvoidcompliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts all card information storage from both mobile devices and POS terminals to a centralized remote server. This eliminates the need for PCI-DSS compliance on distributed devices while maintaining secure transaction processing, as no sensitive card data resides on devices that would be vulnerable to theft or compromise.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3731164B1Method and apparatus for authenticating and processing secure transactions using a mobile device
Publication Date: 2025.01.01 BELL IDENTIFICATION
  • EP3731164B1 patent drawingFigure 1~3
  • EP3731164B1 patent drawingFigure 4~5
  • EP3731164B1 patent drawingFigure 6

AI summary

A method and apparatus for processing secure transactions of a requested service at a merchant point of sale (POS) using a customer mobile device and a virtual payment gateway (VPG) server, the method comprising an authentication and a transaction. The activation establishes a mobile device transport key (mTK) at the mobile device and a server, and assigns a mobile application identifier (MAID) to a mobile application of the mobile device. The transaction is based on generating a mobile device transport session key (msTK) derived from a server generated session ID and the mobile device transport key (mTK) generated during activation. The transaction of the requested service is initiated by the customer mobile device and is processed without storing confidential data such as financial account data or financial account identification data at the POS and/or the customer mobile.