Mobile Payment Security via Token Extraction and Remote Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing payment methods using payment cards are vulnerable to data theft and fraud, as they require physical card handling and storage of personal information, which can lead to risks of card cloning and unauthorized transactions.
Innovation Solution
A method and system utilizing a mobile device to initiate payments by receiving merchant data, transmitting payment requests to a remote server, verifying customer identity, and implementing transactions between bank accounts, with features such as visual token capture, PIN verification, and encryption of transaction IDs to enhance security and reduce physical handling of sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a payment card is physically handled and inserted into a card reader, then the payment transaction can be completed, but the risk of data theft and fraud increases
Solution Approach 1:
The patent extracts the sensitive payment information from the physical payment card and stores it remotely on a server. The mobile device only contains a token or identifier, while the actual card details (card number, expiry date, CVV) are stored securely on the remote server. This extraction eliminates the risk of physical card data theft while maintaining transaction functionality.
Solution Approach 2:
The patent introduces a remote server as an intermediary between the mobile device and the payment network. The server acts as a mediator that securely stores payment information, verifies transactions, and communicates with the payment network on behalf of the user. This intermediary layer protects users from directly exposing sensitive card information to merchants or card readers.
2Ease of operation
If vendors retain card information for repeat orders, then convenience is improved, but the risk of information theft increases
Solution Approach 1:
The patent extracts and removes sensitive card information from the vendor's systems. Instead of storing actual card details, the vendor's system only retains a token or reference identifier. When a repeat order is placed, the system retrieves the full card information from the secure remote server using this token, eliminating the need for vendors to store sensitive data locally.
Solution Approach 2:
The patent uses a token or identifier as a copy/reference to the actual card information. This copy allows the system to reference and process payment information without exposing or storing the sensitive original data. The token serves as a safe placeholder that can be stored and transmitted without security risks.
3Reliability
If a mobile device is used to initiate payments remotely, then security is improved, but the device complexity increases
Solution Approach 1:
The patent leverages the mobile device's existing universal capabilities (camera, communication interfaces, processing power) to perform payment functions. The same device that users already use for communication and information access is also used for secure payment initiation, eliminating the need for separate dedicated payment hardware and reducing overall system complexity.
Solution Approach 2:
The mobile device autonomously performs multiple functions in the payment process: capturing merchant data via camera, communicating with the remote server, verifying transaction details, and initiating payments. This self-service capability eliminates the need for complex intermediary hardware and simplifies the overall system architecture.
Data Source
AI summary
The invention concerns a method of making a payment transaction by a customer including steps of receiving, by a mobile device (402) of the customer, merchant data; transmitting, by the mobile device to a remote server (408), a payment transaction request including the merchant data; determining, by the remote server; the identity of the customer based on the request and the identity of the merchant based on the data; and implementing the payment transaction between bank accounts of the customer and the merchant.


