Mobile Payment Security Token Management via Server Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for secure transactions using mobile devices face challenges in maintaining control and security, as the security system is not wholly under the bank's control and requires significant memory and processing power, making it difficult to manage and upgrade.
Innovation Solution
A method where a mobile device sends a token request to a server, which generates asymmetric key pairs and verifies user and device identity, allowing secure communication with a service provider device for transactions, with the server maintaining control over the security system and reducing processing requirements on the mobile device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the security system is implemented on the mobile device with full control, then security and reliability are improved, but device complexity and processing requirements increase significantly
Solution Approach 1:
The patent extracts the security control functions from the mobile device and relocates them to a remote server. The mobile device only stores tokens and performs basic verification, while the server handles key generation, encryption, decryption, and security verification. This extraction resolves the contradiction by maintaining security control (improving reliability) while removing complex processing requirements from the mobile device (reducing device complexity).
Solution Approach 2:
The patent introduces a server as an intermediary between the mobile device and service providers. The server mediates security operations by generating asymmetric key pairs, encrypting/decrypting data, and verifying tokens. This intermediary approach allows the mobile device to maintain security functionality without implementing complex security algorithms locally, thus improving reliability while reducing device complexity.
2Reliability
If memory and processing power are increased on the mobile device, then security functionality is improved, but device cost and power consumption increase
Solution Approach 1:
The patent extracts computationally intensive security operations (asymmetric encryption/decryption, token verification) from the mobile device and performs them on the server. The mobile device only needs to store tokens and send/receive encrypted data, dramatically reducing memory and processing requirements. This resolves the contradiction by maintaining full security functionality through server-based processing while minimizing power consumption on the mobile device.
3Reliability
If the bank maintains full control of the security system, then security management is improved, but system complexity and coordination requirements increase
Solution Approach 1:
The patent extracts security control functions from the mobile device and consolidates them on the server, which the bank can fully control. The server becomes the central authority for key management, encryption/decryption, and verification. This extraction resolves the contradiction by giving the bank complete control over security operations while simplifying the mobile device to a thin client that only stores tokens and communicates with the server.
Data Source
AI summary
This invention relates generally to methods and apparatus for providing secure services using a mobile device, and in particular for securely making transactions, such as payments, using mobile phones and smartphones.


