Multiparty Computation Authentication for Contactless Payments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for contactless payments using Secure Elements (SEs) in mobile devices face high upfront investment costs, complex management due to technological evolution and multiple standards, and sensitivity issues related to customer ownership, leading to inefficient and secure authentication processes.

Innovation Solution

A method employing multiparty computation using elliptic curve cryptography, where multiple parties jointly generate and authenticate cryptographic results based on input data, with each party contributing intermediate data and performing authentication processes to ensure secure transaction processing without relying on SEs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Secure Elements (SEs) are used for contactless payments, then security level is improved, but device complexity and management complexity increase

Engineering Contradiction:
Improvesecurity levelVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the physical Secure Element hardware system with a software-based multiparty computation system. Instead of relying on SEs with hardware security modules, the invention uses cryptographic protocols where multiple parties jointly compute authentication results, eliminating the need for physical security elements while maintaining security through distributed cryptographic operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The authentication process is segmented into multiple independent parties (e.g., payment service provider, acquirer, issuer) that each hold portions of the cryptographic keys. No single party has complete control, and each party performs a portion of the computation, distributing the security function across multiple entities rather than concentrating it in a single Secure Element.

Inventive Principle:
Principle #1Segmentation

2Reliability

If Secure Elements (SEs) are deployed across multiple entities, then security is improved, but system complexity and synchronization requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The multiparty computation protocol serves multiple functions: it provides authentication, key management, and transaction verification across different entities. The same cryptographic framework works for various payment scenarios and can be implemented by different parties using standard protocols, reducing the need for entity-specific customizations and synchronization mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If SEs are used for payment processing, then transaction security is improved, but upfront investment cost and cost of ownership increase

Engineering Contradiction:
Improvetransaction securityVSAvoidcost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent replaces expensive, long-lived Secure Element hardware with software-based cryptographic operations that can be implemented using standard computing resources. The multiparty computation protocol uses conventional cryptographic libraries and algorithms that are already widely available, eliminating the need for specialized hardware investments while maintaining security through mathematical rather than physical means.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

4Reliability

If multiple standards bodies control SE technology, then security standards are improved, but adaptability and ease of operation decrease

Engineering Contradiction:
Improvesecurity standardsVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The invention changes the fundamental parameter of security implementation from hardware-based (SEs with fixed security properties) to software-based (cryptographic protocols with configurable parameters). This allows the system to adapt to different security requirements and standards by adjusting cryptographic parameters, key lengths, and protocol versions without requiring changes to physical hardware or compatibility with multiple SE standards.

Inventive Principle:
Principle #35Parameter changes

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach simplifies payment processing by reducing costs and complexity, enhancing security through distributed authentication, and maintaining customer ownership integrity, while eliminating the need for SEs in mobile devices.

Implementation Method 1

A method employing multiparty computation using elliptic curve cryptography, where multiple parties jointly generate and authenticate cryptographic results based on input data

Methodology Applied
Scientific EffectElliptic curve cryptography:

Data Source

PatentEP3089091B1Transaction authentication
Publication Date: 2020.03.11 BARCLAYS EXECUTION SERVICES LTD
  • EP3089091B1 patent drawingFigure 1
  • EP3089091B1 patent drawingFigure 2
  • EP3089091B1 patent drawingFigure 3

AI summary

The present disclosure relates to methods, apparatuses and systems relating to multiparty computation. The disclosure provides a method of performing multiparty computation to carry out an operation, wherein the multiparty computation uses a plurality of parties arranged to jointly generate a result for the operation based on input data, the method comprising: each party of the plurality of parties generating corresponding intermediate data for use in generating the result; and performing a first authentication process on first authentication data, the first authentication data being based on the intermediate data generated by a first party of the plurality of parties, and, if the first authentication data fails the first authentication process, performing a corresponding predetermined action indicative of failure of the operation.