Secure Electronic Entity for Mobile Payment Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing payment solutions using mobile devices lack security and require merchants to equip themselves with new technology, while existing systems for mobile payments often have low security levels and are not compatible with standard mobile phones.

Innovation Solution

A system comprising a remote transaction verification server, a portable electronic device, and a secure electronic entity, such as a SIM card or on-board secure module, with a communication interface that authenticates and secures transactions using Access Control mechanisms and secure connections via telecommunications networks, allowing for secure payment processing without requiring new equipment for merchants.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a mobile phone is used as a payment terminal without special developments, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the payment functionality by separating the payment terminal application (on the merchant's mobile device) from the secure verification server (remote server). The mobile device handles user interaction and transaction initiation, while the remote server performs secure verification of transaction data, thus maintaining security without requiring the mobile phone itself to be a secure payment terminal.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If a payment terminal is incorporated into a mobile phone, then adaptability is improved, but security is worsened

Engineering Contradiction:
ImproveadaptabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The remote verification server acts as an intermediary between the mobile payment application and the transaction authorization process. The server receives transaction data from the mobile device, verifies its authenticity and validity according to established rules, and provides authorization decisions. This intermediary approach enables adaptability of mobile phones as payment terminals while maintaining security through centralized verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If remote payment verification is implemented, then transaction security is improved, but device complexity is worsened

Engineering Contradiction:
Improvetransaction securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts the complex verification logic and security processing from the mobile device and relocates it to a remote verification server. The mobile device only needs to implement a relatively simple payment application that can communicate with the server, while the server handles the complex tasks of verifying transaction data authenticity, checking authorization rules, and making authorization decisions. This extraction reduces device complexity while maintaining high transaction security.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2873045B1Secure electronic entity for authorizing a transaction
Publication Date: 2024.01.24 IDEMIA FRANCE SAS
  • EP2873045B1 patent drawingFigure 1
  • EP2873045B1 patent drawingFigure 2
  • EP2873045B1 patent drawingFigure 3

AI summary

The invention pertains to a secure electronic entity (100) comprising a communication interface (105), characterized in that it comprises means, for, when it is connected by said communication interface (105) to a portable electronic device (200) having means of connection to a telecommunications network (300), - authenticating a remote transaction verification server (310) in the telecommunications network (300) and authenticating itself with said remote server (310), - then establishing a secure connection (1000), via the telecommunications network, with said remote server (310), - and receiving, via said communication interface (105), data relating to a transaction envisaged (2000) with a third-party device (400) and transmitting said data, via the secure connection (1000), to the remote server (310) so that it analyses said data with a view to taking a decision as to a possible authorization of the transaction.