Wireless Payment Terminal Authentication via Challenge-Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for securing electronic payment terminals against fraudulent substitution or introduction are inadequate, particularly in mobile settings, as they either rely on visible markings that can be reproduced by fraudsters or restrict mobility, and there is a need for a simple and inexpensive solution to ensure authenticity before transactions.
Innovation Solution
A method using a mobile terminal, such as a smartphone, to detect fraudulent payment terminals through message exchanges and Bluetooth Low Energy (BLE) technology, where a challenge-response verification is performed to generate an alarm if the terminal is fraudulent, and the location of the fraudulent terminal is determined using Bluetooth signal strength.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If visible markings are applied to terminals for fraud detection, then merchants can detect terminal substitution, but fraudsters can reproduce the markings making the technique ineffective
Solution Approach 1:
The patent extracts the authentication function from the physical terminal hardware and relocates it to a centralized cloud-based authentication server. The terminal itself no longer contains the secret authentication data, which exists only in the cloud. This extraction prevents fraudsters from reproducing authentication capabilities by copying terminal hardware, as the critical authentication logic resides externally in the cloud infrastructure.
Solution Approach 2:
The patent introduces a cloud-based authentication server as an intermediary between the terminal and the verification process. Instead of direct verification or physical markings on the terminal, the authentication server mediates the verification by receiving terminal identifiers, comparing them against authorized lists, and returning authentication results. This intermediary layer adds security complexity that fraudsters cannot easily reproduce.
2Reliability
If wired payment terminals are used to prevent fraud, then terminal authenticity can be ensured through physical connection, but mobility for merchants and customers is restricted
Solution Approach 1:
The patent replaces the mechanical wired connection system with a wireless communication system. Instead of requiring physical cable connections to verify terminal authenticity, the system uses wireless transmission of terminal identifiers to the cloud-based authentication server. This substitution maintains security verification while enabling mobile and contactless payment operations.
Solution Approach 2:
The cloud-based authentication server provides a universal authentication mechanism that works across multiple terminal types and communication methods (wired, wireless, contactless). This multi-functional approach allows the same authentication infrastructure to support both fixed and mobile payment scenarios, eliminating the need for separate wired systems.
3Reliability
If complex authentication protocols are implemented to detect fraudulent terminals, then security against fraud is improved, but implementation complexity and cost increase
Solution Approach 1:
The patent extracts the complex authentication logic from the terminal device and places it in the cloud-based authentication server. The terminal itself remains simple, only needing to transmit its identifier for verification. The computational complexity of maintaining authentication lists and performing verification resides in the cloud infrastructure, not in the terminal hardware or software.
Solution Approach 2:
The system implements automated authentication verification where the cloud server automatically checks terminal identifiers against authorized lists without requiring manual intervention. The process is self-service in that the terminal simply presents its identifier and receives immediate authentication results, eliminating the need for complex manual verification procedures or specialized authentication hardware.
Data Source
Figure 1
Figure 2A~2C
Figure 3A~3B
AI summary
The invention relates to a method for detecting a fraudulent electronic payment terminal comprising a step, implemented by a mobile terminal, of generating an alarm (ES5) indicating that said electronic payment terminal is fraudulent, said alarm generation step (ES5) being triggered: • when no message, from said electronic payment terminal, is received by said mobile terminal, before the expiry of a predetermined time; or • when a verification phase (PV) of a response, received from said electronic payment terminal, to a challenge issued by said mobile terminal, delivers a negative verification result, said verification step being implemented by said mobile terminal.