Secure Element Payment Integration with Dynamic Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online credit card transactions are vulnerable to 'man-in-the-middle' attacks, where hackers steal payment information by installing malware on users' computers to intercept keystrokes and browser content, compromising security during online purchases.

Innovation Solution

Implementing a secure element in computers that stores and processes user-specific payment information, using a pseudo account number and dynamic payment information, which are unique and recognizable by payment processing networks, to prevent interception and ensure secure communication with merchants.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real payment information is transmitted during online transactions, then transaction functionality is enabled, but security is compromised due to man-in-the-middle attacks

Engineering Contradiction:
Improvetransaction securityVSAvoidpayment system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a validation entity as an intermediary between the secure element and the payment processing network. This intermediary receives requests from the secure element, validates them, and returns dynamic payment information. The validation entity acts as a mediator that enables secure transactions without exposing real payment information to potential attackers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses pseudo account numbers as copies of real payment information. These pseudo account numbers are generated by the validation entity and stored in the secure element. They function as substitutes for real account numbers, enabling transactions to proceed while protecting the actual payment information from exposure.

Inventive Principle:
Principle #26Copying

2Reliability

If payment information is stored in the secure element, then security is improved, but the ability to use payment information in other commerce channels is limited

Engineering Contradiction:
Improvepayment information securityVSAvoidcommerce channel flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic payment information that changes over time. The validation entity generates new pseudo account numbers and other payment details for each transaction or transaction period. This dynamic approach allows the secure element to provide secure payment capabilities while adapting to different transaction contexts and maintaining compatibility with various commerce channels.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes key parameters of the payment information, specifically the account number and other details, between transactions. By transforming static real payment information into dynamic pseudo information with changing parameters, the system maintains security while enabling versatile use across different commerce channels.

Inventive Principle:
Principle #35Parameter changes

3Difficulty of detecting and measuring

If malware is installed on the user's computer, then keystroke interception is enabled, but system integrity is compromised

Engineering Contradiction:
Improveattack detection difficultyVSAvoidsystem security impact
Core Design Contradiction:
Difficulty of detecting and measuringVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the payment information handling function from the vulnerable computer operating system environment and places it in a separate, secure hardware element. The secure element operates independently with its own processor and memory, isolating payment operations from malware that may be present in the host system. This extraction removes the attack surface that malware would otherwise exploit.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the payment system into distinct components: the secure element hardware, the validation entity server, and the host computer system. By dividing the payment functionality into separate segments with defined interfaces, the system prevents malware in the host system from accessing or compromising payment information stored and processed in the secure element.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10657528B2Integration of payment capability into secure elements of computers
Publication Date: 2020.05.19 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US10657528B2 patent drawing
  • US10657528B2 patent drawing
  • US10657528B2 patent drawing

AI summary

Methods, secure elements, validation entities, and computer program products for effecting secure communication of payment information to merchants for Internet-based purchases. Payment information for a user's real payment information is installed in a secure element of a computer, the payment information may comprise a pseudo PAN number for the portable consumer device provided by a validation entity. The secure element is shielded from the computer's operating system to thwart hacker attacks. The user accesses the secure element to make a purchase. In response, the secure element contacts the validation entity with the pseudo account number, and in response obtains dynamic payment information that the secure element can used to effect the payment. The dynamic payment information comprises an account number that is different from the pseudo PAN, and which has at least one difference which respect to the user's real payment information.