Secure Cashless Transaction System Using PKI and 802.11

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cashless payment systems rely on trusted third parties for validation and mediation, which can be insecure and require physical credit or debit cards, limiting the convenience and security of transactions.

Innovation Solution

Implementing a method for secure communication between an end user device and a point-of-sale device using a public key infrastructure (PKI) and certificates to establish a secure 802.11 connection, allowing for automatic authentication and encryption, thereby eliminating the need for physical cards and enhancing transaction security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical credit or debit cards are used for cashless transactions, then transaction validation can be performed, but security risks increase and convenience decreases

Engineering Contradiction:
Improvetransaction securityVSAvoidtransaction convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical card-swiping system with a wireless communication system using 802.11 protocols. The end user device communicates directly with the point-of-sale device through wireless authentication and encryption, eliminating the need for physical cards while maintaining transaction validation and security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces trusted third party certificates and public key infrastructure as intermediaries to enable secure direct communication between the end user device and point-of-sale device. These digital certificates mediate the authentication process, providing security without requiring physical card presence.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If trusted third parties mediate cashless transactions, then transaction validation is possible, but system complexity and security vulnerabilities increase

Engineering Contradiction:
Improvetransaction validationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary authentication and capability exchange between the end user device and point-of-sale device before the actual transaction occurs. The devices verify each other's credentials and establish encryption keys in advance, enabling secure direct communication without requiring complex ongoing mediation by trusted third parties during the transaction itself.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If manual card insertion is required at point-of-sale, then transaction authentication can be performed, but transaction time increases

Engineering Contradiction:
Improveauthentication securityVSAvoidtransaction time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent enables the end user device to perform self-authentication with the point-of-sale device using stored credentials and cryptographic keys. The device automatically initiates the authentication process, exchanges capabilities, and establishes secure communication without requiring manual card insertion or operator intervention, significantly reducing transaction time while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10380570B2System and method for secure communication for cashless transactions
Publication Date: 2019.08.13 ONDOT SYSTEMS INC
  • US10380570B2 patent drawing
  • US10380570B2 patent drawing
  • US10380570B2 patent drawing

AI summary

Embodiments of the present invention provide a system and method for an access point providing client to point-of-sale communication over a network, comprising: receiving credentials from the point-of-sale; sending at least one beacon message; receiving a probe request from a client; sending a probe response to the client; authenticating a connection with the client; exchanging capabilities with the client; performing a security handshake with the client; assigning at least one dynamic IP address to the client; and establishing an https session between the client and the point-of-sale over the network.