Mobile Payment Security Token Management via Server Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for secure transactions using mobile devices face challenges in maintaining control and security, as the security system is not wholly under the bank's control and requires significant memory and processing power, making it difficult to manage and upgrade.

Innovation Solution

A method where a mobile device sends a token request to a server, which generates asymmetric key pairs and verifies user and device identity, allowing secure communication with a service provider device for transactions, with the server maintaining control over the security system and reducing processing requirements on the mobile device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the security system is implemented on the mobile device with full control, then security and reliability are improved, but device complexity and processing requirements increase significantly

Engineering Contradiction:
Improvesecurity controlVSAvoidprocessing requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security control functions from the mobile device and relocates them to a remote server. The mobile device only stores tokens and performs basic verification, while the server handles key generation, encryption, decryption, and security verification. This extraction resolves the contradiction by maintaining security control (improving reliability) while removing complex processing requirements from the mobile device (reducing device complexity).

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a server as an intermediary between the mobile device and service providers. The server mediates security operations by generating asymmetric key pairs, encrypting/decrypting data, and verifying tokens. This intermediary approach allows the mobile device to maintain security functionality without implementing complex security algorithms locally, thus improving reliability while reducing device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If memory and processing power are increased on the mobile device, then security functionality is improved, but device cost and power consumption increase

Engineering Contradiction:
Improvesecurity functionalityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts computationally intensive security operations (asymmetric encryption/decryption, token verification) from the mobile device and performs them on the server. The mobile device only needs to store tokens and send/receive encrypted data, dramatically reducing memory and processing requirements. This resolves the contradiction by maintaining full security functionality through server-based processing while minimizing power consumption on the mobile device.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If the bank maintains full control of the security system, then security management is improved, but system complexity and coordination requirements increase

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem coordination
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts security control functions from the mobile device and consolidates them on the server, which the bank can fully control. The server becomes the central authority for key management, encryption/decryption, and verification. This extraction resolves the contradiction by giving the bank complete control over security operations while simplifying the mobile device to a thin client that only stores tokens and communicates with the server.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11995630B2Method and apparatus for providing secure services using a mobile device
Publication Date: 2024.05.28 BELL IDENTIFICATION
  • US11995630B2 patent drawing
  • US11995630B2 patent drawing
  • US11995630B2 patent drawing

AI summary

This invention relates generally to methods and apparatus for providing secure services using a mobile device, and in particular for securely making transactions, such as payments, using mobile phones and smartphones.