Mobile POS Terminal Registration Using NFC Credential Retrieval
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face vulnerabilities in storing payment credentials across multiple resource provider applications, leading to data theft risks and inefficient transaction experiences due to manual input errors.
Innovation Solution
A mobile device is registered as a POS terminal with resource providers, using near-field communication to retrieve payment credentials directly from a credential-storing device, bypassing application storage and enabling secure, seamless transactions through a server computer authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If users store credentials for payment in each resource provider application, then transaction efficiency is improved, but security vulnerability increases due to multiple storage points
Solution Approach 1:
The patent extracts payment credentials from multiple resource provider applications and consolidates them into a single credential storing device (secure element). This eliminates the security vulnerability of storing credentials in multiple locations while maintaining fast access through the device's NFC capability, resolving the contradiction between transaction efficiency and security.
Solution Approach 2:
The patent introduces a credential storing device (secure element) as an intermediary between the user's payment information and resource provider applications. This mediator securely holds credentials and enables access without manual input, improving both security by centralizing storage and efficiency through automated NFC-based retrieval.
2Object-affected harmful factors
If users manually input credentials for payment, then security is improved by avoiding stored credentials, but user experience deteriorates due to input errors and inefficiency
Solution Approach 1:
The patent implements self-service by enabling the credential storing device to automatically provide payment credentials through NFC communication when the resource provider application is activated. This eliminates manual input requirements while maintaining security, as the device autonomously retrieves and transmits credentials without user exposure or typing errors.
3Object-affected harmful factors
If smart devices are registered as POS terminals, then transaction security is improved by bypassing resource provider systems, but system complexity increases
Solution Approach 1:
The patent applies universality by enabling standard smartphone hardware (NFC reader, processor, communication interfaces) to function as a POS terminal. The existing smartphone components are repurposed for secure credential storage and transaction processing, achieving enhanced security without adding specialized hardware or significantly increasing system complexity.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enhances security by reducing credential storage points and improves user experience by eliminating manual input, while mitigating fraud risks and ensuring efficient transactions.
Implementation Method 1
receiving, by the first instance of the resource provider application using the set of platform-specific scripts, the first account credentials from a credential storing device via near field communication capability of the first user device
Data Source
AI summary
Methods and systems for using a mobile device as a point-of-sale (POS) terminal provisioned by a resource provider are provided. A server computer can transmit, to a resource provider computer, a set of platform-specific scripts to be incorporated into a resource provider application provisioned on a user device. The server computer can register each instance of the resource provider application provisioned on any user device as an access terminal associated with the resource provider computer. The server computer can receive, directly from an instance of the resource provider application on a user device, a processing request message to perform a transaction. The server computer can obtain an authorization decision on behalf of the resource provider computer and transmit the authorization decision to the user device and the resource provider computer.


