Secure Element Signed Blob for Mobile Financial Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless financial transaction technologies lack efficiency and security in establishing connections and transmitting sensitive information between electronic devices, particularly in scenarios where initial connections may not exist, and there is a need for enhanced user authentication and privacy protection.

Innovation Solution

An electronic device equipped with a secure element that generates a signed blob using an encryption key, establishes connections, and communicates transaction information via various protocols, including near-field communication, to facilitate secure financial transactions by authenticating users and encrypting sensitive data before transmission to a server for processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If near-field communication is used to transmit financial information wirelessly, then the convenience of mobile transactions is improved, but the security risk of data transmission is worsened

Engineering Contradiction:
Improveconvenience of mobile transactionsVSAvoidsecurity risk of data transmission
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the communication process into two distinct phases: (1) Near-field communication for establishing initial connection and exchanging connection information, and (2) Bluetooth communication for transmitting sensitive financial data. This segmentation allows each communication mode to be used for its optimal purpose - NFC for secure initial handshake and Bluetooth for reliable data transmission - thereby maintaining both convenience and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a server as an intermediary in the financial transaction process. The server acts as a trusted third party that receives connection information from the first electronic device, establishes Bluetooth connection with the second device, and coordinates the exchange of signed blobs and financial information. This intermediary architecture enhances security by centralizing authentication and data verification, reducing the security burden on the mobile devices themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If connection information is transmitted via near-field communication, then the speed of establishing connection is improved, but the reliability of connection establishment is worsened when initial connection does not exist

Engineering Contradiction:
Improvespeed of establishing connectionVSAvoidreliability of connection establishment
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent employs preliminary action by having the first electronic device generate and transmit a signed blob containing connection information via near-field communication before the actual Bluetooth connection is established. This signed blob serves as pre-authenticated connection credentials that the second device can use to reliably establish the Bluetooth connection without requiring prior connection history. The signing process ensures the connection information is authentic and has not been tampered with.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where the first device sends signed connection information to the second device via NFC, the second device attempts to establish Bluetooth connection using this information, and then both devices exchange signed blobs to confirm successful connection. This feedback loop ensures that connection establishment is both fast (through pre-generated connection info) and reliable (through verification steps).

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2993633B1Mobile-merchant proximity solution for financial transactions
Publication Date: 2023.11.01 APPLE INC
  • EP2993633B1 patent drawingFigure 1
  • EP2993633B1 patent drawingFigure 2
  • EP2993633B1 patent drawingFigure 3

AI summary

In order to facilitate conducting a financial transaction via wireless communication between an electronic device (such as a smartphone) and another electronic device (such as another smartphone), a secure element in the electronic device may generate, using an encryption key associated with the secure element, a signed blob based on a transaction amount and a merchant identifier. Then, the electronic device communicates connection information between the electronic device and the other electronic device. Moreover, the electronic device may establish a connection between the electronic device and the other electronic device based on the connection information, and may concurrently provide the signed blob to the other electronic device. After receiving a signed transaction blob from the other electronic device using the connection (which includes information needed to conduct the financial transaction), the electronic device provides the information to a server to conduct the financial transaction.