NFC Payment Card Tokenization for Secure Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current near-field communication (NFC) systems for payment transactions lack efficient user interface navigation and security features, particularly in processing transactions and managing account actions, leading to complexities and potential security vulnerabilities.
Innovation Solution
Implementing NFC-enabled payment cards with programmable NFC tags using NFC Data Exchange Format (NDEF) messages and custom applets that support context-based actions, encryption, and U2F protocol compliance, allowing for secure and streamlined transaction processing and account management through NFC-enabled devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If NFC systems use standard payment processing protocols, then transaction compatibility is improved, but user interface navigation complexity increases
Solution Approach 1:
The patent segments the payment system into multiple components: NFC-enabled cards with programmable tags, reader devices, and a payment network. Each component handles specific functions independently, allowing standard protocols to be implemented without complicating the overall user interface. The segmentation enables complex transactions to be broken down into simple user actions.
Solution Approach 2:
The patent introduces an intermediary layer in the form of a payment network that mediates between the NFC card and reader device. This intermediary handles the complex protocol negotiations and transaction processing, allowing the user interface to remain simple while maintaining compatibility with standard payment protocols.
2Adaptability or versatility
If NFC cards store more account information, then transaction functionality is improved, but security vulnerability increases
Solution Approach 1:
The patent implements preliminary security actions by requiring authentication and authorization before account information is accessed or transactions are processed. The system pre-establishes security credentials and permissions, ensuring that even though NFC cards store account information, unauthorized access is prevented through pre-configured security measures.
Solution Approach 2:
The patent uses disposable or single-use transaction codes and tokens that are generated for each transaction. Instead of storing sensitive account information in plain text, the system uses temporary credentials that become invalid after use, reducing security vulnerabilities while maintaining full transaction functionality.
3Productivity
If NFC transaction processing is automated, then transaction speed is improved, but authentication reliability decreases
Solution Approach 1:
The patent implements feedback mechanisms where the system continuously verifies authentication credentials during the automated transaction process. The NFC reader device receives feedback from the payment network about the validity of credentials, and the system adjusts the authentication process in real-time, maintaining both speed and reliability through continuous verification.
Solution Approach 2:
The system performs preliminary authentication checks before initiating automated transaction processing. By pre-verifying credentials and establishing authentication in advance, the system ensures that automated processing maintains high reliability while achieving fast transaction speeds.
Data Source
AI summary
In one embodiment, a method includes receiving, from a computing device of a first user, a request to transfer funds from a first account associated with the first user to a second account associated with a second user. The request to transfer funds may be generated by receiving a first token at the computing device of the first user through near-field communication with a first payment card and determining that the first token is associated with the second user. The method includes sending, in response to receiving the request to transfer funds, to the computing device of the first user, a request to authorize the transfer to the second account associated with the second user. The method includes receiving, from the device of the first user, an indication of authorization, wherein the indication of authorization is generated by receiving a second token at the device of the first user.


