Secure Element Payment Credential Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing remote payment transactions lack sufficient security, as they are vulnerable to hacking and fraud due to the manual entry of sensitive information and the lack of verification of payment credentials, especially when conducted through untrusted merchant applications on mobile devices.
Innovation Solution
The implementation of a secure transaction processing system that uses a mobile device's secure memory to store and encrypt payment credentials, generating dynamic authentication data for remote transactions, and validating the authenticity of merchant applications through certificate authorities to ensure secure communication and protection of sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual entry of payment information is used in merchant applications, then ease of operation is improved, but security is worsened due to vulnerability to eavesdropping and hacking
Solution Approach 1:
The patent extracts sensitive payment information from the merchant application environment and stores it in a secure element within the mobile device. The secure element is a separate, protected storage area that isolates payment credentials from potentially malicious applications, allowing manual entry convenience while preventing unauthorized access to the actual payment data.
Solution Approach 2:
The patent introduces a secure element as an intermediary between the merchant application and the payment information. This secure element acts as a mediator that provides controlled access to payment credentials, allowing the merchant application to use payment information without directly exposing it to potential security threats in the application environment.
2Ease of operation
If payment credentials are stored in unsecure memory on mobile devices, then ease of operation is improved, but security is worsened due to access by malicious applications
Solution Approach 1:
The patent segments the mobile device memory into separate secure and unsecure areas. The secure element is a distinct, isolated storage compartment that holds payment credentials, separated from the general application memory space. This segmentation allows payment information to be readily available to authorized applications while preventing access by malicious applications that cannot penetrate the secure boundary.
Solution Approach 2:
The secure element serves as an intermediary storage layer between the application ecosystem and sensitive payment data. It provides a controlled interface that allows legitimate applications to access payment credentials through proper authentication while blocking malicious applications from directly accessing or stealing the stored information.
3Productivity
If traditional remote transaction methods are used, then productivity is improved, but security is worsened due to lack of verification and higher fraud risk
Solution Approach 1:
The patent performs preliminary authentication actions by validating the merchant application's certificate authority credentials before the actual payment transaction occurs. This pre-verification step ensures that the merchant application is legitimate and authorized to process payments, preventing fraud while maintaining efficient transaction processing for authenticated merchants.
Solution Approach 2:
The patent implements a feedback mechanism where the mobile device receives and validates certificate authority information from the merchant application, and based on this validation feedback, determines whether to proceed with the transaction. This feedback loop provides continuous security verification while allowing rapid transaction processing once authentication is established.
Data Source
AI summary
Embodiments of the present invention are directed to methods, apparatuses, computer readable media and systems for securely processing remote transactions. One embodiment of the invention is directed to a method of processing a remote transaction initiated by a mobile device. The method comprises receiving, by a mobile payment application on a secure memory of the mobile device, transaction data from a transaction processor application on the mobile device. The method further comprises validating that the transaction processor application is authentic and in response to validating the transaction processor application, providing encrypted payment credentials to the transaction processor application. The transaction processor application further initiates a payment transaction with a transaction processor server computer using the encrypted payment credentials.


