Secure Electronic Entity for Mobile Payment Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing payment solutions using mobile devices lack security and require merchants to equip themselves with new technology, while existing systems for mobile payments often have low security levels and are not compatible with standard mobile phones.
Innovation Solution
A system comprising a remote transaction verification server, a portable electronic device, and a secure electronic entity, such as a SIM card or on-board secure module, with a communication interface that authenticates and secures transactions using Access Control mechanisms and secure connections via telecommunications networks, allowing for secure payment processing without requiring new equipment for merchants.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a mobile phone is used as a payment terminal without special developments, then ease of operation is improved, but security is worsened
Solution Approach 1:
The system segments the payment functionality by separating the payment terminal application (on the merchant's mobile device) from the secure verification server (remote server). The mobile device handles user interaction and transaction initiation, while the remote server performs secure verification of transaction data, thus maintaining security without requiring the mobile phone itself to be a secure payment terminal.
2Adaptability or versatility
If a payment terminal is incorporated into a mobile phone, then adaptability is improved, but security is worsened
Solution Approach 1:
The remote verification server acts as an intermediary between the mobile payment application and the transaction authorization process. The server receives transaction data from the mobile device, verifies its authenticity and validity according to established rules, and provides authorization decisions. This intermediary approach enables adaptability of mobile phones as payment terminals while maintaining security through centralized verification.
3Reliability
If remote payment verification is implemented, then transaction security is improved, but device complexity is worsened
Solution Approach 1:
The system extracts the complex verification logic and security processing from the mobile device and relocates it to a remote verification server. The mobile device only needs to implement a relatively simple payment application that can communicate with the server, while the server handles the complex tasks of verifying transaction data authenticity, checking authorization rules, and making authorization decisions. This extraction reduces device complexity while maintaining high transaction security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention pertains to a secure electronic entity (100) comprising a communication interface (105), characterized in that it comprises means, for, when it is connected by said communication interface (105) to a portable electronic device (200) having means of connection to a telecommunications network (300), - authenticating a remote transaction verification server (310) in the telecommunications network (300) and authenticating itself with said remote server (310), - then establishing a secure connection (1000), via the telecommunications network, with said remote server (310), - and receiving, via said communication interface (105), data relating to a transaction envisaged (2000) with a third-party device (400) and transmitting said data, via the secure connection (1000), to the remote server (310) so that it analyses said data with a view to taking a decision as to a possible authorization of the transaction.