Secure Element Payment Credential Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote payment transactions lack sufficient security, as they are vulnerable to hacking and fraud due to the manual entry of sensitive information and the lack of verification of payment credentials, especially when conducted through untrusted merchant applications on mobile devices.

Innovation Solution

The implementation of a secure transaction processing system that uses a mobile device's secure memory to store and encrypt payment credentials, generating dynamic authentication data for remote transactions, and validating the authenticity of merchant applications through certificate authorities to ensure secure communication and protection of sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual entry of payment information is used in merchant applications, then ease of operation is improved, but security is worsened due to vulnerability to eavesdropping and hacking

Engineering Contradiction:
Improveease of payment entryVSAvoidsecurity of payment information
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts sensitive payment information from the merchant application environment and stores it in a secure element within the mobile device. The secure element is a separate, protected storage area that isolates payment credentials from potentially malicious applications, allowing manual entry convenience while preventing unauthorized access to the actual payment data.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a secure element as an intermediary between the merchant application and the payment information. This secure element acts as a mediator that provides controlled access to payment credentials, allowing the merchant application to use payment information without directly exposing it to potential security threats in the application environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If payment credentials are stored in unsecure memory on mobile devices, then ease of operation is improved, but security is worsened due to access by malicious applications

Engineering Contradiction:
Improveavailability of payment credentialsVSAvoidvulnerability to malicious applications
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the mobile device memory into separate secure and unsecure areas. The secure element is a distinct, isolated storage compartment that holds payment credentials, separated from the general application memory space. This segmentation allows payment information to be readily available to authorized applications while preventing access by malicious applications that cannot penetrate the secure boundary.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure element serves as an intermediary storage layer between the application ecosystem and sensitive payment data. It provides a controlled interface that allows legitimate applications to access payment credentials through proper authentication while blocking malicious applications from directly accessing or stealing the stored information.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If traditional remote transaction methods are used, then productivity is improved, but security is worsened due to lack of verification and higher fraud risk

Engineering Contradiction:
Improvetransaction processing speedVSAvoidsecurity against fraud
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent performs preliminary authentication actions by validating the merchant application's certificate authority credentials before the actual payment transaction occurs. This pre-verification step ensures that the merchant application is legitimate and authorized to process payments, preventing fraud while maintaining efficient transaction processing for authenticated merchants.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where the mobile device receives and validates certificate authority information from the merchant application, and based on this validation feedback, determines whether to proceed with the transaction. This feedback loop provides continuous security verification while allowing rapid transaction processing once authentication is established.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11847643B2Secure remote payment transaction processing using a secure element
Publication Date: 2023.12.19 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11847643B2 patent drawing
  • US11847643B2 patent drawing
  • US11847643B2 patent drawing

AI summary

Embodiments of the present invention are directed to methods, apparatuses, computer readable media and systems for securely processing remote transactions. One embodiment of the invention is directed to a method of processing a remote transaction initiated by a mobile device. The method comprises receiving, by a mobile payment application on a secure memory of the mobile device, transaction data from a transaction processor application on the mobile device. The method further comprises validating that the transaction processor application is authentic and in response to validating the transaction processor application, providing encrypted payment credentials to the transaction processor application. The transaction processor application further initiates a payment transaction with a transaction processor server computer using the encrypted payment credentials.