Secure Element for EMV Chip and PIN Payment Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile devices face challenges in securely processing chip and PIN payments due to insecurity issues, such as malware that can capture PIN information from IC chip readers, and merchants must undergo costly certification processes to accept chip and PIN payments.

Innovation Solution

A software development kit (SDK) is provided that allows merchants to integrate chip and PIN payment functionality into their own POS systems, enabling secure PIN entry through mobile devices without requiring certification, using abstraction layers and secure PIN entry methods like touch screen interfaces or sketch PIN entry, keeping PIN information away from the merchant's device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobile devices are used as POS terminals with IC chip readers, then payment processing capability is improved, but security risk increases due to malware that can capture PIN information

Engineering Contradiction:
Improvepayment processing capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a secure element as an intermediary component between the IC chip reader and the mobile device's main processor. This secure element acts as a trusted mediator that handles PIN verification securely, preventing malware on the mobile device from accessing PIN information while still enabling payment processing functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into distinct security zones: the secure element contains sensitive PIN verification functions isolated from the mobile device's main operating system. This segmentation ensures that even if the mobile device is compromised by malware, the core security functions remain protected in the isolated secure element.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If merchants use third-party POS systems, then ease of operation is improved, but device complexity increases due to integration requirements

Engineering Contradiction:
Improveease of operationVSAvoidintegration requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The mobile device is designed to function as a universal POS terminal that can process both traditional magnetic stripe cards and EMV chip cards with PIN verification. This multi-functionality is achieved through the secure element that provides standardized security interfaces, allowing merchants to use a single device for multiple payment types without complex integration of separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If chip and PIN payment processing is implemented, then payment security is improved, but device complexity increases due to certification requirements

Engineering Contradiction:
Improvepayment securityVSAvoidcertification requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure element is pre-certified and embedded in the mobile device, providing self-service security functionality. The secure element contains all necessary security credentials and certification, allowing the mobile device to process chip and PIN payments without requiring the merchant to undergo separate certification processes for each device.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10535066B2Systems and methods for securing pins during EMV chip and pin payments
Publication Date: 2020.01.14 PAYPAL INC
  • US10535066B2 patent drawing
  • US10535066B2 patent drawing
  • US10535066B2 patent drawing

AI summary

In transactions between a consumer and a merchant (or other third party) using services of a payment provider (e.g., credit card company, or financial services provider), methods and systems are provided for enabling any third party to accept chip and PIN payment and payment provider services using a payment provider device that is enabled using the third party's own application (referred to herein as “app”) and not the app of the payment provider. Enabling a merchant to accept chip and PIN payments usually requires the merchant to certify (accredit) their application (e.g., a point-of-sale (POS) system) end to end with the payment providers (e.g., Visa, MasterCard). A software development kit (SDK) modification to the application allows the merchant to accept chip and PIN cards the without the need to certify the application. The SDK includes the functionality that needs to be certified, and certifies it once with a service provider.