Remote Secure Element for Contactless Payment Cryptogram Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing payment systems require physical possession of a card matching the authorization capabilities of a merchant's system, making transactions inconvenient and necessitating more flexible and convenient authorization methods.

Innovation Solution

A method for acquiring digital credential data by a point-of-sale terminal from a mobile device for authorization of a financial transaction, using a remote permanent cryptographic key to calculate an expected cryptogram, and performing an interrogation between the point-of-sale terminal and the mobile device to request and receive the digital credential data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If physical possession of a card is required for transactions, then security is maintained, but convenience and ease of operation deteriorate

Engineering Contradiction:
Improvetransaction convenienceVSAvoidauthorization security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent creates a virtual copy of the Secure Element's cryptographic functionality in a remote server environment. Instead of requiring physical possession of a card with an embedded SE, the system generates and transmits a virtual representation of the SE's cryptogram generation capability through remote servers, allowing transactions to be authorized without physical card presence while maintaining security through cryptographic verification

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces remote servers as intermediaries between the mobile device and the payment authorization system. These servers host the Secure Element representation and facilitate the generation and transmission of cryptograms, enabling the mobile device to perform transactions without direct physical card interaction while maintaining secure authorization through the intermediary server infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If a local permanent cryptographic key is stored on the mobile device, then transaction speed is improved, but security deteriorates due to potential key compromise

Engineering Contradiction:
Improvetransaction processing speedVSAvoidcryptographic security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent extracts the permanent cryptographic key from the mobile device and relocates it to a remote server environment. The mobile device no longer stores the permanent key but instead receives temporary session keys from the remote server for each transaction, eliminating the security risk of key compromise on the mobile device while maintaining efficient transaction processing through the remote key management system

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary key establishment actions by having the remote server generate and transmit temporary session keys before transactions occur. This preliminary action of key exchange occurs in advance of actual transactions, allowing the mobile device to perform rapid cryptographic operations without needing to store permanent keys locally, thus improving speed while maintaining security

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If physical card possession is required, then authorization reliability is maintained, but device complexity and operational burden increase

Engineering Contradiction:
Improvetransaction flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent makes the payment system universal by allowing any mobile device with network connectivity to perform transactions without requiring physical cards. The remote server infrastructure provides multi-functional support including cryptogram generation, card verification, and transaction authorization, enabling the same system to handle various transaction types and device configurations flexibly without increasing operational complexity for users

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250182126A1Systems and methods for authorizing a transaction with an unexpected cryptogram
Publication Date: 2025.06.05 OV LOOP INC
  • US20250182126A1 patent drawing
  • US20250182126A1 patent drawing
  • US20250182126A1 patent drawing

AI summary

Methods are described for performing a timely authorization of digital credential data delivered from a mobile device that is without access to a local persistently stored permanent cryptographic key. An application executable in the operating system of a mobile device receives a first non-permanent cryptographic key associated with the account from a remote computer system, stores the first non-permanent cryptographic key as a local cryptographic key associated with the account; generates a response cryptogram using the local cryptographic key and without accessing the permanent cryptographic key and sends a device response communication from the mobile device to an electronic reader of a POS terminal, the device response communication comprising an application data protocol unit containing the response cryptogram and an account identifier for the account.