Mobile Payment Security via Universal SMS Protocol
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile payment systems face challenges due to rigidity in global deployment, compatibility with various mobile phone brands and models, complex user instructions, and the need for POS terminals, which limits their universality and increases transaction costs.
Innovation Solution
A method utilizing programmable mobile handsets with a specific application that employs up to 5 user verification elements, including debit/credit card data, mobile number, SIM card information, and an access key, for secure transactions, allowing for a single connection and flexible use across different mobile phones and countries without the need for additional hardware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a data call is used for communication with the user, then the transaction can be authorized, but the system becomes rigid and difficult to deploy worldwide
Solution Approach 1:
The patent uses the mobile phone's existing communication capabilities (SMS, voice calls, display, keypad) that are universally available across all mobile phones regardless of brand or model. This eliminates the need for proprietary data call protocols and enables worldwide deployment without requiring transaction servers in each country.
Solution Approach 2:
The patent introduces a standardized intermediary protocol that translates between the mobile phone's universal communication capabilities and the transaction authorization requirements. This intermediary layer allows the system to work with any mobile phone model while maintaining reliable transaction authorization.
2Reliability
If control of the mobile handset is implemented, then transaction authorization is achieved, but different modules are needed for each mobile phone brand and model
Solution Approach 1:
The patent leverages universal mobile phone functions (display, keypad, SMS, voice calls) that exist in all mobile phones regardless of brand or model. This approach eliminates the need for device-specific modules and handlers, achieving transaction authorization through standardized interactions with universal phone capabilities.
Solution Approach 2:
The mobile phone's existing interface elements (display, keypad, SMS system) are used to perform the authorization function without requiring additional proprietary software or hardware modules. The phone's own universal capabilities serve the transaction authorization need.
3Adaptability or versatility
If WAP protocol connection is used, then greater standardisation is achieved, but transaction costs increase and data entry becomes slower
Solution Approach 1:
The patent uses SMS messages instead of WAP protocol connections. SMS is a simpler, more efficient communication method that requires less data transmission and processing. The authorization is achieved through a brief SMS exchange rather than a lengthy WAP session, significantly reducing both cost and transaction time while maintaining standardization.
Solution Approach 2:
The patent extracts the essential authorization function from the complex WAP protocol framework and implements it through the simpler SMS protocol. This extraction removes unnecessary complexity and data transmission requirements while preserving the core authorization capability.
4Reliability
If POS terminals are used in shops, then transactions can be processed, but the system requires additional hardware infrastructure
Solution Approach 1:
The patent extracts the transaction processing capability from the POS terminal hardware and relocates it to the mobile phone. The mobile phone's universal communication capabilities and the SMS-based protocol enable transaction processing without requiring any specialized POS hardware, eliminating the need for additional infrastructure.
Solution Approach 2:
The mobile phone itself performs the transaction processing function that would traditionally require a POS terminal. The phone's existing capabilities (display, keypad, SMS, voice calls) are sufficient to handle the entire transaction process, making external hardware unnecessary.
Data Source
AI summary
A system, method and mobile application for conducting financial transactions wherein a mobile device operated by a user is operably coupled to a server over a mobile communication network. Both the server and the user's mobile device store a user encryption key (UEK) and a user access key (UAK). A software application stored on the user's mobile device and the server are configured to conduct a transaction wherein a session key (SK) specific to the transaction is exchanged in an encrypted form based upon the UEK. The software application is further configured to i) generate transaction data, ii) access the UAK stored on the mobile device, iii) encrypt the UAK and transaction data into an encrypted form based upon the SK, and iv) send the UAK and transaction data in encrypted form from the mobile device to the server over the mobile communication network in order to conduct the transaction.


