Mobile Payment Gesture Verification via Sensor Intent Models
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The four-party transaction model in mobile computing devices is vulnerable to attacks where nefarious actors insert themselves between the mobile device and the terminal device, leading to unauthorized remuneration actions, such as relay attacks, due to the lack of user intent verification.
Innovation Solution
A security layer is added to the remuneration application on mobile computing devices using sensor data to identify user gestures and intentions through a user intention model, which detects remuneration trigger events, retrieves sensor data, determines user intent, generates remuneration credentials, and transmits them to the terminal device for secure transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If NFC communication is enabled for contactless payments, then payment convenience is improved, but vulnerability to relay attacks increases
Solution Approach 1:
The patent introduces sensor data and a user intention model as intermediary verification layers between the NFC communication and the payment execution. These intermediaries analyze sensor patterns to determine genuine user intent, thereby mediating the trust relationship and preventing relay attacks while maintaining NFC convenience
Solution Approach 2:
The system implements feedback loops where sensor data continuously monitors and validates user intent during the payment process. The user intention model receives feedback from multiple sensors and adjusts its assessment of genuine intent, creating a dynamic verification system that responds to real-time behavioral patterns
2Reliability
If user intent verification through sensor analysis is added, then security against relay attacks is improved, but device complexity increases
Solution Approach 1:
The patent leverages existing multi-functional sensors in mobile devices (accelerometers, gyroscopes, proximity sensors) that serve both traditional functions and payment verification purposes. By making these existing components serve multiple functions, the system adds security without requiring entirely new hardware systems
Solution Approach 2:
The device performs self-verification by using its own sensor data to authenticate user intent. The user intention model is executed locally on the device, allowing the system to verify its own operational state without requiring external verification infrastructure, thereby adding security while minimizing additional system complexity
3Measurement precision
If real-time sensor data analysis is performed, then accuracy of user intent detection is improved, but processing time increases
Solution Approach 1:
The system performs preliminary actions by continuously collecting and pre-processing sensor data even before a payment transaction is initiated. This allows the user intention model to have pre-analyzed data ready for rapid evaluation when a payment gesture occurs, thereby maintaining high accuracy while minimizing real-time processing delays
Solution Approach 2:
The patent applies partial action by selectively analyzing only the most relevant sensor data subsets that are most indicative of genuine user intent. Rather than processing all sensor data equally, the system focuses computational resources on the most discriminative features, achieving high accuracy with reduced processing overhead
Data Source
AI summary
In one embodiment, the present disclosure includes a mobile computing device. The mobile computing device includes a communication interface, one or more sensors, a memory, and an electronic processor. The electronic processor is configured to detect a remuneration trigger event, retrieve sensor data from a sensor data repository in response to detecting the remuneration trigger event, determine whether a user of the mobile computing device intended to perform a remuneration action by applying a user intention model to the sensor data, generate remuneration credentials in response to determining that the user of the mobile computing device intended to perform the remuneration action, and control the communication interface to transmit the remuneration credentials to the terminal device to complete the remuneration action.


