Secure Element Payment Encryption for Fraud Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing remote payment transactions lack security, as they are vulnerable to hacking and fraud due to the manual entry of sensitive information and the lack of secure authentication, especially when conducted through untrusted merchant applications on mobile devices.
Innovation Solution
A method and system for securely processing remote transactions using a mobile device's secure element to generate and transmit encrypted payment information, incorporating dynamic authentication data, and utilizing a remote key manager or payment processing network to ensure secure communication and authentication, protecting against malicious applications and threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual entry of payment information is used in merchant applications, then consumers can conduct online payment transactions, but security risks such as vulnerability to eavesdropping and hacking increase
Solution Approach 1:
The patent extracts sensitive payment information from the merchant application environment and stores it in a secure element on the mobile device. The secure element acts as a separate, protected storage location that is inaccessible to merchant applications, thereby removing the security vulnerability while preserving payment functionality.
Solution Approach 2:
The patent introduces an intermediary component (the secure element with its dedicated interface) between the merchant application and the payment information. This intermediary allows the application to access payment data without exposing the actual sensitive information to potentially malicious software.
2Ease of operation
If payment credentials are stored on mobile device for remote transactions, then transaction convenience is improved, but vulnerability to malicious applications and hacking increases
Solution Approach 1:
The patent segments the mobile device into two distinct parts: a general-purpose area for merchant applications and a secured area (secure element) for storing payment credentials. This segmentation ensures that even if the general-purpose area is compromised, the sensitive payment information remains protected in the isolated secure element.
Solution Approach 2:
The patent creates a composite security architecture combining the mobile device's processing capabilities with the secure element's protected storage. This composite structure leverages the strengths of both components while mitigating their individual weaknesses, providing both convenience and security.
3Device complexity
If traditional remote transaction methods are used, then transaction simplicity is maintained, but fraud risk and chargeback vulnerability increase
Solution Approach 1:
The secure element performs self-service authentication by generating dynamic cryptograms and verifying payment credentials independently of the merchant application. This self-contained security mechanism provides fraud protection without requiring complex additional steps from the consumer, maintaining simplicity while enhancing security.
Data Source
AI summary
Embodiments of the present invention are directed to methods, apparatuses, computer readable media and systems for securely processing remote transactions. One embodiment of the invention is directed to a method of processing a remote transaction initiated by a mobile device comprising a server computer receiving a payment request including encrypted payment information. The encrypted payment information being generated by a mobile payment application of the mobile device and being encrypted using a third party key. The method further comprises decrypting the encrypted payment information using the third party key, determining a transaction processor public key associated with the payment information, and re-encrypting the payment information using the transaction processor public key. The method further comprises sending a payment response including the re-encrypted payment information to a transaction processor. The transaction processor decrypts the re-encrypted payment information using a transaction processor private key and initiates a payment transaction.


