Mobile Payment Security via Software Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing payment systems require additional hardware for secure transactions, and there is a need for secure payment solutions using personal mobile communication devices without the need for external hardware modifications.

Innovation Solution

A client application on personal mobile communication devices generates a public and private key pair for secure storage, sends an attestation request to a terminal management server, receives a device key for encryption, and processes payment information using a communication interface, ensuring secure transactions through encryption and token management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional external hardware (POS terminals) is used for secure payment transactions, then security and reliability are improved, but device complexity and cost increase

Engineering Contradiction:
Improvepayment transaction securityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the secure payment processing functionality from dedicated external POS hardware and relocates it to the mobile device's existing secure storage and communication interfaces. The mobile device itself becomes the secure terminal, eliminating the need for separate POS hardware while maintaining security through the device's built-in secure elements and encrypted communication channels.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent enables personal mobile communication devices to perform multiple functions: they serve as both the payment card (via contactless communication interfaces like NFC) and the payment terminal (via application-based processing). This universal usage eliminates the need for separate dedicated hardware for each function, reducing overall system complexity while maintaining security through software-based protections.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If personal mobile communication devices are used without additional hardware, then device complexity is reduced, but security measures must be significantly enhanced

Engineering Contradiction:
Improvehardware requirementsVSAvoidsecurity measures
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces an intermediary attestation mechanism where the mobile device's secure storage and communication interfaces verify the authenticity of payment applications and data before processing transactions. This intermediary layer of verification ensures that even without additional hardware, the device can securely handle payments through software-based trust validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the security parameters from hardware-based physical security to software-based cryptographic security. By using encrypted communication channels, digital certificates, and token-based authentication, the system achieves equivalent or superior security without requiring additional physical hardware components.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If contactless communication interfaces are used for card reading, then ease of operation is improved, but security risks increase without proper protection

Engineering Contradiction:
Improvecontactless payment convenienceVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary security actions by establishing encrypted communication channels and validating payment application authenticity before any contactless card reading occurs. The secure storage pre-provisions cryptographic keys and certificates that are activated only when needed, ensuring that convenience operations are always preceded by security verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent converts the potential security vulnerability of contactless communication into a benefit by using the same communication interface for both convenient card reading and secure data transmission. Through encrypted channels and protocol-level security, the system ensures that the convenience of contactless operation does not compromise security, and may even enhance it through faster, more secure wireless authentication.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS11397940B2Secure payment transactions
Publication Date: 2022.07.26 BANKS & ACQUIRERS INT HLDG SAS
  • US11397940B2 patent drawing
  • US11397940B2 patent drawing
  • US11397940B2 patent drawing

AI summary

A client comprising an application for secure payment transactions is provided. The application runs on a personal mobile communication device and the client accesses a service provided by a server, which includes a payment gateway. Various security measures are included in the client-server communication related to executing payment transactions in a secure environment.