Payment Cloud Server Authentication for Secure Mobile Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional electronic payment transactions using mobile devices are vulnerable to fraud due to the potential security weaknesses in cash register applications, which may send inaccurate information to payment control applications, compromising the transaction process.

Innovation Solution

A payment cloud server is introduced to authenticate cash register cloud servers and establish secure channels for processing electronic payments, using authentication information such as digital signatures and symmetric keys to verify the authenticity of cash register servers and protect payment data, ensuring secure communication through TLS tunnels and NFC interfaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a mobile phone is used to process payment transactions instead of a POS terminal, then the ease of operation is improved, but the security of the transaction is worsened due to potential vulnerabilities in cash register applications

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a payment cloud server as an intermediary between the mobile merchant device and the payment network. This server authenticates the cash register application and establishes secure communication channels, thereby maintaining security while enabling the use of mobile devices for payments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication of the cash register application and establishment of secure communication channels before the actual payment transaction occurs. This ensures that security measures are in place beforehand, preventing potential attacks during the transaction process.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If multiple applications from different providers are used in a mobile payment system, then the adaptability is improved, but the security is worsened due to potential weak points in third-party applications

Engineering Contradiction:
ImproveadaptabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The payment cloud server acts as a central intermediary that authenticates and manages multiple third-party applications. By verifying each application's credentials and establishing secure channels, the server enables diverse applications to participate in payments while maintaining overall system security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements authentication feedback mechanisms where the payment cloud server verifies the credentials of cash register applications and provides authentication responses. This feedback loop ensures that only authorized applications can process payments, maintaining security across multiple providers.

Inventive Principle:
Principle #23Feedback

3Reliability

If authentication mechanisms are added to verify cash register servers, then the security is improved, but the device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The payment cloud server centralizes the authentication functionality, so the mobile merchant device itself remains relatively simple. The complex authentication logic resides on the server, which mediates between the mobile device and the payment network, reducing the complexity burden on the endpoint device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is designed to operate automatically without requiring manual intervention from the merchant or customer. The payment cloud server autonomously verifies credentials and establishes secure channels, making the security process transparent and eliminating the need for complex user-side authentication mechanisms.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4191497A1Devices, methods and a system for secure electronic payment transactions
Publication Date: 2023.06.07 RUBEAN AG
  • EP4191497A1 patent drawingFigure 1
  • EP4191497A1 patent drawingFigure 2
  • EP4191497A1 patent drawingFigure 3

AI summary

A payment cloud server (140) for processing an electronic payment based on an interaction between a mobile merchant communication device (120) and a customer payment device (110) is disclosed. The payment cloud server (140) comprises a communication interface (143) configured to receive an authentication request from a cash register cloud server (150), wherein the authentication request comprises authentication information. Moreover, the payment cloud server (140) comprises a processing circuitry (141) configured to authenticate the cash register cloud server (150) based on the authentication information. The communication interface (143) is further configured to receive a payment authorization request via a secure channel from the mobile merchant communication device (120). The processing circuitry (141) is configured to, in response to the payment authorization request, authorize the electronic payment transaction, if the authentication of the cash register cloud server (150) based on the authentication information is successful.