Wireless Payment Terminal Authentication via Challenge-Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securing electronic payment terminals against fraudulent substitution or introduction are inadequate, particularly in mobile settings, as they either rely on visible markings that can be reproduced by fraudsters or restrict mobility, and there is a need for a simple and inexpensive solution to ensure authenticity before transactions.

Innovation Solution

A method using a mobile terminal, such as a smartphone, to detect fraudulent payment terminals through message exchanges and Bluetooth Low Energy (BLE) technology, where a challenge-response verification is performed to generate an alarm if the terminal is fraudulent, and the location of the fraudulent terminal is determined using Bluetooth signal strength.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If visible markings are applied to terminals for fraud detection, then merchants can detect terminal substitution, but fraudsters can reproduce the markings making the technique ineffective

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidreproducibility of marking
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent extracts the authentication function from the physical terminal hardware and relocates it to a centralized cloud-based authentication server. The terminal itself no longer contains the secret authentication data, which exists only in the cloud. This extraction prevents fraudsters from reproducing authentication capabilities by copying terminal hardware, as the critical authentication logic resides externally in the cloud infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a cloud-based authentication server as an intermediary between the terminal and the verification process. Instead of direct verification or physical markings on the terminal, the authentication server mediates the verification by receiving terminal identifiers, comparing them against authorized lists, and returning authentication results. This intermediary layer adds security complexity that fraudsters cannot easily reproduce.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If wired payment terminals are used to prevent fraud, then terminal authenticity can be ensured through physical connection, but mobility for merchants and customers is restricted

Engineering Contradiction:
Improveterminal authenticity verificationVSAvoidmobility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical wired connection system with a wireless communication system. Instead of requiring physical cable connections to verify terminal authenticity, the system uses wireless transmission of terminal identifiers to the cloud-based authentication server. This substitution maintains security verification while enabling mobile and contactless payment operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The cloud-based authentication server provides a universal authentication mechanism that works across multiple terminal types and communication methods (wired, wireless, contactless). This multi-functional approach allows the same authentication infrastructure to support both fixed and mobile payment scenarios, eliminating the need for separate wired systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If complex authentication protocols are implemented to detect fraudulent terminals, then security against fraud is improved, but implementation complexity and cost increase

Engineering Contradiction:
Improvefraud preventionVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex authentication logic from the terminal device and places it in the cloud-based authentication server. The terminal itself remains simple, only needing to transmit its identifier for verification. The computational complexity of maintaining authentication lists and performing verification resides in the cloud infrastructure, not in the terminal hardware or software.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements automated authentication verification where the cloud server automatically checks terminal identifiers against authorized lists without requiring manual intervention. The process is self-service in that the terminal simply presents its identifier and receives immediate authentication results, eliminating the need for complex manual verification procedures or specialized authentication hardware.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3107023B1Method, device and program for wireless payment terminal authentication
Publication Date: 2019.05.01 COMPAGNIE INDUSTRIELLE ET FINANCIERE D INGENIERIE INGENICO SA
  • EP3107023B1 patent drawingFigure 1
  • EP3107023B1 patent drawingFigure 2A~2C
  • EP3107023B1 patent drawingFigure 3A~3B

AI summary

The invention relates to a method for detecting a fraudulent electronic payment terminal comprising a step, implemented by a mobile terminal, of generating an alarm (ES5) indicating that said electronic payment terminal is fraudulent, said alarm generation step (ES5) being triggered: • when no message, from said electronic payment terminal, is received by said mobile terminal, before the expiry of a predetermined time; or • when a verification phase (PV) of a response, received from said electronic payment terminal, to a challenge issued by said mobile terminal, delivers a negative verification result, said verification step being implemented by said mobile terminal.