Secure Element User Security Domain Mobile Transaction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current transaction systems using mobile devices lack adequate security measures, making them vulnerable to fraudulent activities, especially when used for financial transactions, as they often rely on insecure identification methods and are susceptible to hacking.

Innovation Solution

A secure element with a user security domain is integrated into mobile devices, providing advanced security features such as encryption, decryption, and a firewall functionality to protect sensitive information, and utilizing a pseudo-random number generator to enhance authentication processes, ensuring that only authorized parties can access and transmit data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If mobile devices use traditional identification methods for transactions, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the mobile device into two distinct domains: a secure element domain for storing sensitive data and performing secure operations, and a non-secure application domain for user interactions. This segmentation allows the device to maintain ease of operation through the application domain while ensuring security through the isolated secure element domain.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a secure element as an intermediary component between the user/application and the sensitive transaction data. This secure element acts as a mediator that handles authentication and cryptographic operations, protecting the main system from direct exposure to security-critical functions while maintaining operational convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If mobile devices integrate secure elements with user security domains, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the secure element functionality directly within the mobile device architecture, merging security functions with the existing device structure. This integration approach, while adding security capabilities, seeks to minimize overall complexity by consolidating security functions within the device rather than requiring external security hardware.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If mobile devices use contactless smart cards for transactions, then ease of operation is improved, but security is worsened due to susceptibility to reading by any nearby reader

Engineering Contradiction:
Improveease of operationVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies different security qualities to different parts of the transaction system. The secure element domain implements strong cryptographic protection and access control for sensitive operations, while the application domain provides user-friendly interfaces. This local differentiation of security qualities enables convenient contactless operation while protecting against unauthorized reading through targeted cryptographic safeguards in the secure element.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9886688B2System and method for secure transaction process via mobile device
Publication Date: 2018.02.06 PING IDENTITY CORP
  • US9886688B2 patent drawing
  • US9886688B2 patent drawing
  • US9886688B2 patent drawing

AI summary

A secure element with a user security domain thereon, the user security domain constituted of: a security domain control circuitry; an encoder/decoder functionality responsive to the security domain control circuitry; and a secured keys storage in communication with the security domain control circuitry, the encoder/decoder functionality arranged to: encode data responsive to at least one first key stored on the secured keys storage, and output an encoded data; and decode received data responsive to at least one second key stored on the secured keys storage, and output a decoded data.