Mobile Payment Terminal Mutual Authentication Session Key
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile payment systems are insecure and cumbersome, particularly in fueling environments, as they often transmit sensitive user data in cleartext and require user interaction, which can lead to security issues and inconvenience.
Innovation Solution
Implementing a mutual authentication process between a payment terminal and a mobile device to establish a session key for encrypting data, allowing secure and automatic transactions without user interaction, with the mobile device able to remain in a user's pocket or vehicle.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If sensitive user data is transmitted in cleartext for simplicity, then device complexity is reduced, but security is compromised
Solution Approach 1:
The system performs preliminary authentication and session key establishment before actual data transmission. The payment terminal and mobile device conduct mutual authentication and generate encrypted session keys in advance, so that when user data is transmitted, it is already protected by encryption without adding complexity to the transmission protocol itself.
2Reliability
If user interaction is required for transaction initiation, then security is improved through user confirmation, but transaction time increases
Solution Approach 1:
The system performs preliminary authentication and data exchange before the user needs to interact. User information is transmitted and authenticated in advance, and when the user provides authorization information, the transaction can be completed quickly using pre-validated data, reducing overall transaction time while maintaining security.
3Reliability
If the mobile device must be held up to the payment terminal, then authentication reliability is improved, but ease of operation deteriorates
Solution Approach 1:
The system replaces the mechanical requirement of physical proximity (holding device to terminal) with wireless communication protocols. The mobile device and payment terminal communicate wirelessly to exchange authentication data and session keys, eliminating the need for physical contact while maintaining authentication reliability through cryptographic verification.
4Adaptability or versatility
If cloud-to-cloud infrastructure integration is implemented, then system versatility is improved, but device complexity and cost increase
Solution Approach 1:
The system uses the wireless communication channel and standardized protocols as an intermediary between different payment infrastructures. By establishing mutual authentication and using session keys through this intermediary layer, the system can communicate between different cloud platforms without requiring complex direct integrations, reducing infrastructure complexity while maintaining versatility.
Data Source
AI summary
Systems and methods for conducting convenient and secure mobile transactions between a payment terminal and a mobile device, e.g., in a fueling environment, are disclosed herein. In some embodiments, the payment terminal and the mobile device conduct a mutual authentication process that, if successful, produces a session key which can be used to encrypt sensitive data to be exchanged between the payment terminal and the mobile device. Payment and loyalty information can be securely communicated from the mobile device to the payment terminal using the session key. This can be done automatically, without waiting for the user to initiate a transaction, to shorten the overall transaction time. The transaction can also be completed without any user interaction with the mobile device, increasing the user's convenience since the mobile device can be left in the user's pocket, purse, vehicle, etc.


