Mobile POS Terminal Using Cryptogram-Secured Payment Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile payment systems face exposure risks during e-commerce transactions, leading to potential fraud and lack of nonrepudiation assurance, as they require consumers to input transaction account information directly, which can be vulnerable to data breaches.
Innovation Solution
A mobile payment system utilizing a personal POS terminal on a consumer's device, integrated with a virtual terminal system, allows for secure transactions by generating a device identifier, displaying transaction details, and accepting payment tokens through a payment instrument, ensuring low fraud risk and nonrepudiation assurance similar to in-person transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If consumers input transaction account information directly into a payment web page during e-commerce transactions, then the transaction process is simple and direct, but the information exposure risk increases and fraud vulnerability rises
Solution Approach 1:
The patent introduces a point-of-sale terminal as an intermediary device between the consumer and the payment system. Instead of directly inputting account information into a web page, the consumer uses the POS terminal which then communicates with the payment system. This intermediary approach maintains ease of operation while reducing information exposure risk by preventing direct transmission of sensitive account details through potentially vulnerable web interfaces.
2Speed
If traditional electronic wallet systems are used for online transactions, then transaction speed is maintained, but nonrepudiation assurance is lost and fraud risk increases
Solution Approach 1:
The patent segments the transaction system into distinct components: a point-of-sale terminal for authentication and a separate payment processing system. The terminal captures biometric data and device identifiers locally, creating a secure authentication layer that maintains transaction speed while providing strong nonrepudiation assurance through multi-factor verification (biometrics + device identifier + one-time password).
Solution Approach 2:
The system performs preliminary authentication actions through the POS terminal before the actual payment transaction occurs. The terminal verifies biometric data, captures device identifiers, and generates one-time passwords in advance, ensuring that when the transaction executes, nonrepudiation assurance is already established without compromising speed.
3Reliability
If physical payment instruments are used at POS terminals, then nonrepudiation assurance is achieved, but the system lacks adaptability for e-commerce transactions
Solution Approach 1:
The patent creates a universal point-of-sale terminal that can function in both physical and e-commerce transaction environments. The terminal uses biometric authentication and device identifier verification that work equally well whether the consumer is physically present or transacting online, providing nonrepudiation assurance across multiple transaction types without requiring separate systems.
Solution Approach 2:
The system creates a digital copy of the physical POS terminal authentication mechanism for use in e-commerce. The terminal's biometric verification and device identifier capture capabilities are replicated in software form that can operate on remote devices, maintaining the security properties of physical terminals while enabling e-commerce adaptability.
Data Source
AI summary
Disclosed are various embodiments for a point of sale application for a mobile device. In some embodiments, a system comprises a mobile device that is configured to receive a command from a service system to activate a personal point of sale (POS) application. The personal POS application is executed based at least in part on the command. A payment token is generated based at least in part on payment information. A cryptogram is generated for securing the payment token. The cryptogram is transmitted to the service system.


