Onboard Terminal Payment Authentication via Encrypted Device Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile payment technologies for onboard terminals suffer from poor payment security due to the transmission of Bluetooth device IDs in plain text, lacking secure storage, and requiring complex user interactions that distract drivers during transactions.

Innovation Solution

The method involves acquiring and encrypting user device and user identifiers on an onboard terminal, transmitting the encrypted files to a server to establish a binding relationship, and decrypting the private key certificate on the terminal for secure storage, ensuring all files are transmitted encrypted, simplifying the payment process and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If device IDs are transmitted in plain text for Bluetooth payment verification, then the payment process is simple and fast, but the payment security deteriorates due to risk of theft and tampering

Engineering Contradiction:
Improvepayment processing speedVSAvoidpayment security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-establishing binding relationships between device identifiers and user identifiers, and pre-configuring encrypted storage environments in Bluetooth devices. The device identifier is bound to user identifier in advance, and the encrypted storage environment is prepared beforehand to securely store private keys and authentication information, so that secure authentication can be performed without adding complexity to the actual payment process

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating and storing encrypted copies of authentication information in the Bluetooth device's trusted storage environment. The private key certificate and bound user identifier are stored in encrypted form in the device's secure storage, allowing the device to prove its identity without transmitting the actual device ID in plain text during payment verification

Inventive Principle:
Principle #26Copying

2Reliability

If complex authentication interactions are required for onboard terminal payment, then the payment security is improved, but the ease of operation deteriorates due to driver distraction

Engineering Contradiction:
Improvepayment securityVSAvoiddriver operation convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling the Bluetooth device to automatically perform authentication operations using pre-configured credentials. The device automatically transmits its bound user identifier and authentication information to the server without requiring driver intervention, allowing the payment process to complete itself while the driver remains undisturbed

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-establishing the binding relationship between device identifier and user identifier, and pre-configuring the encrypted storage environment with private keys. This preliminary setup allows the authentication process to proceed automatically without requiring complex real-time interactions from the driver during the actual payment

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3457344B1Payment authentication method, apparatus and system for onboard terminal
Publication Date: 2022.09.21 ALIBABA GROUP HOLDING LTD
  • EP3457344B1 patent drawingFigure 1
  • EP3457344B1 patent drawingFigure 2
  • EP3457344B1 patent drawingFigure 3

AI summary

The present application discloses a payment authentication method, apparatus and system for an onboard terminal. The method applied to an onboard terminal includes: receiving a payment authentication request sent by a server, and forwarding the payment authentication request to a user device having an established communication connection, the payment authentication request including a user identifier; receiving encrypted payment certification information responded by the user device and sending the encrypted payment certification information to the server, the encrypted payment certification information including the user identifier and a user device identifier; and receiving a certification result sent by the server and performing payment processing according to the certification result, the certification result indicating whether there is a binding relationship between the user identifier and the user device identifier. The present application solves a technical problem of poor payment security in an existing mobile payment technology applied to onboard terminals.