Secure Cashless Transaction System Using PKI and 802.11
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cashless payment systems rely on trusted third parties for validation and mediation, which can be insecure and require physical credit or debit cards, limiting the convenience and security of transactions.
Innovation Solution
Implementing a method for secure communication between an end user device and a point-of-sale device using a public key infrastructure (PKI) and certificates to establish a secure 802.11 connection, allowing for automatic authentication and encryption, thereby eliminating the need for physical cards and enhancing transaction security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical credit or debit cards are used for cashless transactions, then transaction validation can be performed, but security risks increase and convenience decreases
Solution Approach 1:
The patent replaces the mechanical card-swiping system with a wireless communication system using 802.11 protocols. The end user device communicates directly with the point-of-sale device through wireless authentication and encryption, eliminating the need for physical cards while maintaining transaction validation and security.
Solution Approach 2:
The patent introduces trusted third party certificates and public key infrastructure as intermediaries to enable secure direct communication between the end user device and point-of-sale device. These digital certificates mediate the authentication process, providing security without requiring physical card presence.
2Reliability
If trusted third parties mediate cashless transactions, then transaction validation is possible, but system complexity and security vulnerabilities increase
Solution Approach 1:
The patent implements preliminary authentication and capability exchange between the end user device and point-of-sale device before the actual transaction occurs. The devices verify each other's credentials and establish encryption keys in advance, enabling secure direct communication without requiring complex ongoing mediation by trusted third parties during the transaction itself.
3Reliability
If manual card insertion is required at point-of-sale, then transaction authentication can be performed, but transaction time increases
Solution Approach 1:
The patent enables the end user device to perform self-authentication with the point-of-sale device using stored credentials and cryptographic keys. The device automatically initiates the authentication process, exchanges capabilities, and establishes secure communication without requiring manual card insertion or operator intervention, significantly reducing transaction time while maintaining security.
Data Source
AI summary
Embodiments of the present invention provide a system and method for an access point providing client to point-of-sale communication over a network, comprising: receiving credentials from the point-of-sale; sending at least one beacon message; receiving a probe request from a client; sending a probe response to the client; authenticating a connection with the client; exchanging capabilities with the client; performing a security handshake with the client; assigning at least one dynamic IP address to the client; and establishing an https session between the client and the point-of-sale over the network.


