Secure Element Virtual Keypad for Mobile Payment PIN Entry
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile payment solutions for merchants lack security, particularly when entering PIN codes on unsecured communications terminals, as these devices are vulnerable to fraud and data theft due to their general-purpose nature and lack of secure processing capabilities.
Innovation Solution
A method where a card reader, connected to a communications terminal, generates and manages a virtual keypad for entering personal identification data, ensuring encryption and secure transmission, thereby isolating sensitive data entry from the potentially insecure communications terminal.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a general-purpose communications terminal is used for mobile payments, then ease of operation and accessibility are improved, but security and reliability deteriorate due to vulnerability to fraud and data theft
Solution Approach 1:
The patent introduces a card reader as an intermediary device between the user's card and the communications terminal. The card reader includes a secure element that acts as a trusted mediator, handling sensitive operations like PIN verification and cryptographic operations locally, thereby protecting the general-purpose terminal from direct exposure to security-critical data while still enabling convenient mobile payments
2Reliability
If a dedicated payment terminal is used, then security and reliability are improved, but device complexity and cost increase
Solution Approach 1:
The patent segments the payment system into distinct functional components: a general-purpose communications terminal for user interface and basic processing, and a separate card reader with secure element for security-critical operations. This segmentation allows each component to be optimized independently, reducing overall system complexity while maintaining high security standards
3Ease of operation
If the communications terminal handles PIN entry directly, then ease of operation is improved, but security deteriorates due to unauthorized access risks
Solution Approach 1:
The card reader's secure element serves as an intermediary that receives PIN input from the terminal's interface but processes and verifies it locally without exposing the PIN to the terminal's main processor. This intermediary architecture maintains user-friendly input while blocking unauthorized access pathways
Solution Approach 2:
The patent extracts the security-critical PIN verification function from the general-purpose terminal and relocates it to the card reader's secure element. This extraction removes the harmful vulnerability from the terminal while preserving the convenient input interface
Data Source
AI summary
A method for processing transaction data, implemented by a communications terminal having a touch screen. The method includes: detecting a necessity of entering a piece of personal identification data; transmitting to a card reader connected to the communications terminal a request for supporting a display of a virtual keypad, the request comprising a piece of data representing a passage of the communications terminal from a “master” mode to a “slave” mode of operation, the slave mode leading to implementation of the method for processing transaction data under the exclusive control of the card reader; of entry, by the user on the virtual keypad, of the piece of personal identification data; and receiving, from the card reader, the piece of personal identification data.

