Multi-path Secure Element Data Communication for Online Payments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for secure online payments using portable electronic devices, such as cellular telephones, are inefficient due to the insecure communication of commerce credentials during contactless proximity-based transactions.

Innovation Solution

A method involving multi-path communication of electronic device secure element data, where a commercial entity derives a transaction key based on token and transaction information, and communicates this key to a financial institution via a merchant subsystem, while keeping sensitive crypto information separate from the merchant, ensuring secure validation of transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If commerce credentials are communicated during contactless proximity-based transactions, then transaction convenience is improved, but security is worsened due to insecure communication

Engineering Contradiction:
Improvetransaction convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The credential data is divided into multiple portions: first portion (token information) is communicated to the merchant subsystem, while second portion (crypto information) is kept separate and communicated directly to the financial institution. This segmentation ensures that no single entity, including the merchant, has access to the complete credential, thereby maintaining security while enabling convenient contactless transactions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The commercial entity acts as an intermediary that receives device transaction data, derives transaction keys, and facilitates multi-path communication between the electronic device, merchant subsystem, and financial institution. This intermediary manages the complex data routing and key derivation, enabling secure credential communication without requiring direct trust between all parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If complete credential data is shared with the merchant subsystem, then transaction processing is simplified, but security exposure increases

Engineering Contradiction:
Improvetransaction processing complexityVSAvoidsecurity exposure
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The credential data is segmented into first portion (token information) and second portion (crypto information). The merchant subsystem receives only the first portion for processing, while the second portion is communicated separately to the financial institution. This reduces the information exposure to merchants while maintaining processing capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The sensitive crypto information is extracted from the data shared with the merchant subsystem. Instead of sharing complete credential data, the system extracts and communicates only the necessary token information to the merchant, while retaining the crypto information separately for direct financial institution verification.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If crypto information is kept separate from merchant systems, then security is improved, but communication complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The commercial entity serves as an intermediary that manages the multi-path communication. It receives device transaction data, derives transaction keys using the segmented credential portions, and facilitates communication between the electronic device, merchant subsystem, and financial institution. This intermediary handles the communication complexity while maintaining security through separate crypto information paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the financial institution receives crypto information directly and can validate transactions. The commercial entity derives transaction keys based on received data and provides feedback on transaction status, enabling secure verification without requiring crypto information to pass through merchant systems.

Inventive Principle:
Principle #23Feedback

4Reliability

If multi-path communication is implemented, then security and data integrity are improved, but system complexity increases

Engineering Contradiction:
Improvedata integrityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The commercial entity acts as a central intermediary that coordinates the multi-path communication. It receives device transaction data, derives transaction keys, and manages data routing between the electronic device, merchant subsystem, and financial institution. This intermediary abstracts the complexity of multiple communication paths, presenting a simplified interface while maintaining data integrity through separate credential portions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments credential data into multiple portions that travel through different communication paths. The first portion goes to the merchant subsystem while the second portion goes directly to the financial institution. This segmentation provides data integrity and security while the commercial entity manages the overall system complexity through standardized key derivation and data handling protocols.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240265383A1Multi-path communication of electronic device secure element data for online payments
Publication Date: 2024.08.08 APPLE INC
  • US20240265383A1 patent drawing
  • US20240265383A1 patent drawing
  • US20240265383A1 patent drawing

AI summary

Systems, methods, and computer-readable media for communicating electronic device secure element data over multiple paths for online payments are provided. In one example embodiment, a method includes, inter alia, at a commercial entity subsystem, receiving, from an electronic device, device transaction data that includes credential data indicative of a payment credential on the electronic device for funding a transaction with a merchant subsystem, accessing a transaction identifier, deriving a transaction key based on transaction key data that includes the accessed transaction identifier, transmitting, to one of the merchant subsystem and the electronic device, merchant payment data that includes a first portion of the credential data and the accessed transaction identifier, and sharing, with a financial institution subsystem using the transaction key, commercial payment data that includes a second portion of the credential data that is different than the first portion of the credential data. Additional embodiments are also provided.