Secure Element Payment Mapping for Lost Device Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a security risk associated with lost electronic devices that can be used to conduct fraudulent financial transactions, as existing technologies do not effectively disable or re-enable the capability to perform financial transactions securely.
Innovation Solution
An electronic device and a management device communicate to disable or re-enable financial transactions by altering the mapping between a device primary account number and a financial primary account number, using authentication information such as personal identification numbers, passcodes, or biometric identifiers, and can request additional authentication information from the user to re-establish the mapping.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If financial transaction capability is enabled on electronic devices, then user convenience and productivity are improved, but security risk increases when devices are lost
Solution Approach 1:
The system performs preliminary actions by establishing secure authentication mechanisms and mapping relationships (DPAN to FPAN) before transactions occur. When a device is reported lost, the system proactively disables the mapping relationship in advance, preventing any potential fraudulent transactions before they can happen.
Solution Approach 2:
The patent introduces an intermediary management system that acts as a mediator between the electronic device and the payment network. This intermediary controls the mapping relationship between DPAN and FPAN, enabling or disabling transaction capability without requiring physical access to the device, thus resolving the security risk while maintaining convenience.
2Reliability
If authentication mechanisms are implemented to secure transactions, then security is improved, but device complexity increases
Solution Approach 1:
The patent extracts the complex authentication and security management functions from the electronic device itself and places them in a separate management system. The device only needs to store the DPAN and communicate with the management system, while the complex FPAN mapping and authentication logic reside externally, reducing device complexity while maintaining strong security.
Solution Approach 2:
The management system serves as an intermediary that handles all complex authentication and security decisions. The electronic device interacts with this intermediary through simple commands, avoiding the need for complex local authentication mechanisms while still achieving high security through the centralized control of the mapping relationship.
Data Source
AI summary
If a user loses an electronic device that has the capability to conduct financial transactions, the user may report that the electronic device is lost using a lost-device software application to a management electronic device associated with a provider of the electronic device. In response to receiving this information, a disabling command is sent to a payment network associated with the financial account of the user to temporarily disable use of the electronic device to conduct the financial transactions. In particular, the electronic device may include a secure element that stores a payment applet for a financial account, and the disabling command may disable a mapping from a virtual identifier for the financial account to a financial primary account number. Subsequently, if the user finds the electronic device, the user may re-enable the capability (and, thus, the mapping) by providing authentication information to the electronic device.


