Secure Element Identifier Verification for Mobile Banking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In developing countries, mobile devices lack secure end-to-end encrypted communication capabilities, making it difficult to securely perform financial transactions due to vulnerabilities in existing secure elements, which can lead to fraudulent activities.
Innovation Solution
A method and system utilizing a secure element with a tamper-resistant cryptoprocessor and secure memory to verify mobile devices by comparing identifiers stored in non-volatile memory, ensuring only authorized interactions occur, and a cryptographic expansion device locked to specific SIM cards and mobile devices for secure operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional brick-and-mortar banks are established in rural areas, then banking services are provided, but the infrastructure cost is high and the bank cannot adequately support large numbers of customers
Solution Approach 1:
The patent replaces the mechanical/physical bank branch infrastructure with a software-based mobile banking system. Instead of building physical banks in rural areas, the invention uses mobile devices running banking applications to provide financial services, eliminating the need for complex physical infrastructure while maintaining service availability.
Solution Approach 2:
The patent creates virtual copies of banking functions through software applications on mobile devices. Rather than requiring physical bank branches, the system replicates banking services (transfers, payments, balance checks) through digital copies that can be accessed by any user with a mobile device, significantly reducing infrastructure requirements.
2Adaptability or versatility
If mobile devices are used for banking transactions, then access to financial services is improved, but security vulnerabilities arise due to lack of end-to-end encrypted communication
Solution Approach 1:
The patent introduces secure elements as intermediary components between the mobile device and the banking system. These secure elements (hardware security modules, smart cards, or cloud-based secure elements) act as trusted intermediaries that perform cryptographic operations and verify identities, enabling secure communication without requiring the mobile device itself to have strong encryption capabilities.
Solution Approach 2:
The patent segments the security functions from the mobile device by using separate secure elements. Instead of relying on the mobile device's inherent security (which is weak), the system divides security responsibilities: the mobile device handles basic communication, while dedicated secure elements handle cryptographic operations and sensitive data protection, thereby improving overall security without sacrificing mobile accessibility.
3Reliability
If secure elements are added to mobile devices, then security against fraudulent attacks is improved, but the device complexity and cost increase
Solution Approach 1:
The patent makes secure elements universal by designing them to work across multiple platforms and device types. The secure elements can be implemented as hardware security modules in smartphones, software-based solutions on tablets, or even cloud-based services accessible from any device. This multi-functionality approach improves security without requiring complex integration into specific device hardware, as the same secure element can serve multiple purposes and platforms.
Solution Approach 2:
The patent implements secure elements that perform security functions autonomously without requiring complex integration or configuration in the mobile device. The secure elements self-manage their cryptographic operations, key management, and communication protocols, thereby improving security while minimizing the complexity burden on the mobile device and its integration layers.
Data Source
AI summary
Systems and methods for verification conducted at a secure element are disclosed. In a method of verification conducted at a secure element interacting with a mobile device, the secure element receives at least one of an identifier of a universal integrated circuit card (UICC) and an identifier of the mobile device. The secure element then compares each of the received at least one identifiers against a registered identifier of corresponding form stored in a non-volatile memory of the secure element. If the received at least one identifiers match corresponding registered identifiers stored in the non-volatile memory, the secure element permits further interaction with the mobile device. If at least one of the received identifiers do not match corresponding registered identifiers stored in the non-volatile memory, the secure element denies further interaction with the mobile device.


