Offline Payment Certificate Management via Trusted Execution Environment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing offline payment methods on consumer terminal devices are cumbersome and insecure, particularly when selecting a payment application from a third-party payment application, as they require invoking the payment client and generating an offline payment identity certificate directly, leading to low efficiency and security concerns.
Innovation Solution
The method involves the third-party payment application obtaining an offline payment certificate from the target payment application, which is then stored locally on the terminal device, allowing for quick and secure offline payments by interacting with the payment application through a trusted execution environment (TEE) for authentication and storage, ensuring only the authorized device can use the certificate.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the payment client is invoked to perform offline payment procedure when selecting a payment application from third-party payment application, then the offline payment can be completed, but the procedure processing becomes cumbersome and time-consuming
Solution Approach 1:
The payment certificate is pre-generated and stored in the TEE during the account binding phase. When offline payment is needed, the certificate is directly retrieved and used without invoking the payment client or regenerating the certificate, thus eliminating the cumbersome procedure and reducing time consumption.
Solution Approach 2:
The payment certificate generation and storage process is extracted from the payment execution flow. The certificate is generated in advance during account binding and stored securely in TEE, separating the certificate preparation from the actual payment operation, allowing direct use during offline payments.
2Ease of operation
If the offline payment identity certificate is directly obtained after receiving by the consumer terminal device, then the user can easily obtain the certificate, but the security is relatively low
Solution Approach 1:
The TEE acts as a secure intermediary between the payment application and the certificate. The certificate is generated and stored within the TEE's secure environment, and only the TEE can access and use the certificate. This intermediary mechanism maintains security while allowing easy certificate acquisition by the payment application through authorized requests.
Solution Approach 2:
The TEE provides a localized secure environment within the terminal device for certificate storage and management. The security properties are concentrated in the TEE region, where the certificate is protected by hardware-based security mechanisms, while the rest of the system can access it through controlled interfaces.
3Productivity
If the payment client performs offline payment procedure by invoking another payment application, then the payment transaction can be processed, but the procedure becomes cumbersome requiring multiple client interactions
Solution Approach 1:
The certificate generation, storage, and usage functions are merged into a unified TEE-based mechanism that serves all payment applications. Instead of having separate payment client procedures for each application, the TEE provides a common secure infrastructure that all applications can use, simplifying the overall system architecture.
Solution Approach 2:
The TEE-based certificate management system provides universal functionality for all payment applications integrated in the terminal device. A single certificate storage and retrieval mechanism serves multiple payment applications, eliminating the need for separate payment client procedures for each application.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
The present application provides an offline payment method and device. The method includes the following: obtaining, by a third-party payment application, an identity authentication identifier of a user that sends an offline payment request when the third-party payment application receives the request that corresponds to a target payment application; obtaining, by the third-party payment application, an offline payment certificate issued by the target payment application to the user and stored in the terminal device, when it is determined that the obtained identity authentication identifier is verified; and providing, by the third-party payment application, the offline payment certificate for an offline payment service party, so that the offline payment service party requests the target payment application to process offline payment of the user based on the offline payment certificate. The present application makes user's payment quicker and more secure when a payment application is selected from a third-party payment application integrated into a consumer terminal device to make offline payment.