Secure Element Payment Encryption for Fraud Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote payment transactions lack security, as they are vulnerable to hacking and fraud due to the manual entry of sensitive information and the lack of secure authentication, especially when conducted through untrusted merchant applications on mobile devices.

Innovation Solution

A method and system for securely processing remote transactions using a mobile device's secure element to generate and transmit encrypted payment information, incorporating dynamic authentication data, and utilizing a remote key manager or payment processing network to ensure secure communication and authentication, protecting against malicious applications and threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual entry of payment information is used in merchant applications, then consumers can conduct online payment transactions, but security risks such as vulnerability to eavesdropping and hacking increase

Engineering Contradiction:
Improveonline payment transaction capabilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive payment information from the merchant application environment and stores it in a secure element on the mobile device. The secure element acts as a separate, protected storage location that is inaccessible to merchant applications, thereby removing the security vulnerability while preserving payment functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary component (the secure element with its dedicated interface) between the merchant application and the payment information. This intermediary allows the application to access payment data without exposing the actual sensitive information to potentially malicious software.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If payment credentials are stored on mobile device for remote transactions, then transaction convenience is improved, but vulnerability to malicious applications and hacking increases

Engineering Contradiction:
Improveremote transaction convenienceVSAvoidprotection against malicious applications
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the mobile device into two distinct parts: a general-purpose area for merchant applications and a secured area (secure element) for storing payment credentials. This segmentation ensures that even if the general-purpose area is compromised, the sensitive payment information remains protected in the isolated secure element.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a composite security architecture combining the mobile device's processing capabilities with the secure element's protected storage. This composite structure leverages the strengths of both components while mitigating their individual weaknesses, providing both convenience and security.

Inventive Principle:
Principle #40Composite materials

3Device complexity

If traditional remote transaction methods are used, then transaction simplicity is maintained, but fraud risk and chargeback vulnerability increase

Engineering Contradiction:
Improvetransaction process simplicityVSAvoidfraud risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The secure element performs self-service authentication by generating dynamic cryptograms and verifying payment credentials independently of the merchant application. This self-contained security mechanism provides fraud protection without requiring complex additional steps from the consumer, maintaining simplicity while enhancing security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12198124B2Secure remote payment transaction processing
Publication Date: 2025.01.14 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US12198124B2 patent drawing
  • US12198124B2 patent drawing
  • US12198124B2 patent drawing

AI summary

Embodiments of the present invention are directed to methods, apparatuses, computer readable media and systems for securely processing remote transactions. One embodiment of the invention is directed to a method of processing a remote transaction initiated by a mobile device comprising a server computer receiving a payment request including encrypted payment information. The encrypted payment information being generated by a mobile payment application of the mobile device and being encrypted using a third party key. The method further comprises decrypting the encrypted payment information using the third party key, determining a transaction processor public key associated with the payment information, and re-encrypting the payment information using the transaction processor public key. The method further comprises sending a payment response including the re-encrypted payment information to a transaction processor. The transaction processor decrypts the re-encrypted payment information using a transaction processor private key and initiates a payment transaction.