Mobile Payment Tokenization via Intermediary Substitution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing payment systems require specialized hardware for secure transactions, and there is a need for secure payment solutions using personal mobile communication devices without additional hardware modifications, while ensuring higher security measures compared to stand-alone POS devices.
Innovation Solution
A personal mobile communication device with secured storage and a processor runs a client to store private keys and encrypted device keys, reads contactless cards, and sends payment information to a payment gateway for processing, utilizing a method that includes generating and managing secure transaction tokens for authorization and encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If personal mobile communication devices are used for payments without additional hardware, then device complexity is reduced and ease of operation is improved, but security reliability deteriorates due to the need for higher security measures
Solution Approach 1:
The patent introduces a token as an intermediary element between the mobile device and the payment card. The token stores encrypted card data and transaction information, allowing the mobile device to perform payments without directly storing sensitive card information. This intermediary approach enables the device to operate securely without requiring additional hardware security modules, resolving the contradiction between ease of operation and security reliability.
Solution Approach 2:
The patent replaces traditional mechanical security measures (physical POS terminals with dedicated hardware) with cryptographic mechanisms. Encryption algorithms and token-based authentication systems substitute for physical security hardware, enabling mobile devices to achieve security levels previously only attainable through dedicated POS infrastructure. This substitution maintains ease of operation while improving security reliability.
2Reliability
If additional hardware is used for secure payments, then security reliability is improved, but device complexity and manufacturing cost increase
Solution Approach 1:
The patent extracts the security-critical functions from physical hardware and relocates them to software-based cryptographic systems. By taking out the need for dedicated security hardware and implementing security mechanisms through software tokens and encryption algorithms, the system achieves security reliability without increasing device complexity. The mobile device's existing processor and memory suffice to handle the cryptographic operations.
Solution Approach 2:
The patent makes the mobile device universally capable of performing payment functions through software-based token management. Instead of requiring specialized hardware for each payment function, a single multi-functional token system handles card data storage, encryption, and transaction processing. This universality reduces device complexity while maintaining security reliability across different payment scenarios.
3Reliability
If traditional POS hardware is used, then security measures are simplified, but adaptability to mobile devices and versatility are reduced
Solution Approach 1:
The patent implements a dynamic token system that adapts to different payment scenarios and device configurations. The token can be created, updated, and managed dynamically based on the specific payment transaction requirements, allowing the same mobile device to handle various payment methods and merchants. This dynamic approach provides both security reliability and high adaptability, eliminating the need for fixed POS hardware configurations.
Data Source
AI summary
A client comprising an application for secure payment transactions is provided. The application runs on a personal mobile communication device and the client accesses a service provided by a server, which includes a payment gateway. Various security measures are included in the client-server communication related to executing payment transactions in a secure environment.


