Secure Payment Module Transaction Process
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for managing credits and entitlements between payment and security modules in Pay-TV applications lack secure and real-time transaction capabilities, often leading to fraud and inefficient communication processes.
Innovation Solution
A process that securely transfers credits or entitlements between a payment module and a security module by establishing communication between the two modules, either directly or through a management centre, using protocols like APDU, ensuring that a corresponding debit is made on the payment module before crediting the security module, and utilizing unlocking codes for authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a credit is transferred from a payment module to a security module in Pay-TV applications, then the user can access conditional access data, but the transaction security is compromised and fraud can occur
Solution Approach 1:
The patent applies preliminary action by requiring the debit operation to be executed and verified on the payment module before the credit operation is performed on the security module. This ensures that the payment is confirmed prior to granting access rights, preventing fraud where credits could be issued without corresponding payments. The system verifies the debit result and only then proceeds with crediting the security module.
Solution Approach 2:
The patent implements feedback by establishing a communication link between the payment module and security module that allows the payment module to verify transaction results and send confirmation messages. The system receives feedback about the debit operation success and uses this information to control whether the credit operation should proceed, creating a closed-loop verification system that enhances transaction security.
2Reliability
If a management centre mediates all transactions between payment and security modules, then transaction control is centralized, but communication efficiency decreases and real-time processing is delayed
Solution Approach 1:
The patent applies segmentation by dividing the transaction process into two distinct communication phases: a setup phase where the management centre establishes authorization rules and parameters, and an execution phase where direct peer-to-peer communication occurs between the payment module and security module. This segmentation allows centralized control for security-critical setup operations while enabling efficient decentralized execution for actual transactions.
Solution Approach 2:
The patent uses the management centre as an intermediary only for the initial authorization setup, not for every transaction. The management centre mediates the establishment of transaction parameters and authorization rules, after which the payment module and security module can communicate directly. This reduces the management centre's role from a bottleneck in every transaction to a one-time setup authority, improving processing speed while maintaining control.
3Reliability
If multiple messages are sent to the management centre for each transaction, then transaction authorization is verified, but communication overhead increases and system load increases
Solution Approach 1:
The patent applies preliminary action by having the management centre pre-authorize transaction parameters and rules before actual transactions occur. Once authorized, these parameters are cached and reused for multiple transactions without requiring repeated communication with the management centre. This reduces the number of messages needed while maintaining authorization verification, as the preliminary authorization covers subsequent transactions.
Solution Approach 2:
The patent uses copying by having the payment module and security module store and reuse authorized transaction parameters locally after initial management centre approval. Instead of sending unique authorization requests for every transaction, the system copies and reuses the pre-validated transaction templates and parameters, significantly reducing communication overhead while maintaining security through the original authorization verification.
4Reliability
If the payment module and security module are linked securely with real-time verification, then fraud is prevented, but device complexity increases
Solution Approach 1:
The patent applies merging by combining the payment module and security module into a single user unit with integrated communication capabilities. This integration allows direct peer-to-peer messaging between the modules without requiring external verification infrastructure, reducing system complexity while maintaining security through the inherent linkage of modules under common user control. The fraud prevention mechanism becomes part of the integrated unit rather than requiring separate complex verification systems.
Data Source
AI summary
This invention relates to a process for carrying out a transaction between a payment module and a security module connected to a user's unit, this process being characterized in that it comprises the following steps: entering an identifier representative of the transaction to be carried out by means of an input device; generating by the user's unit, a control message containing at least a representative code of said transaction and an identifier of the security module requiring the transaction; sending said control message to said payment module (PP); verifying in said payment module whether it is entitled to carry out the desired transaction; if the payment module is entitled to carry out this transaction, execution of the transaction, storage of the result of the transaction in said payment module and generation by the payment module, of a receipt relating to the desired transaction and to the related security module; sending said receipt to a management center; sending an unlocking code to the security module (SC) by the management center; registering the transaction in said security module.


