Secure Element Virtual Keypad for Mobile Payment PIN Entry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile payment solutions for merchants lack security, particularly when entering PIN codes on unsecured communications terminals, as these devices are vulnerable to fraud and data theft due to their general-purpose nature and lack of secure processing capabilities.

Innovation Solution

A method where a card reader, connected to a communications terminal, generates and manages a virtual keypad for entering personal identification data, ensuring encryption and secure transmission, thereby isolating sensitive data entry from the potentially insecure communications terminal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a general-purpose communications terminal is used for mobile payments, then ease of operation and accessibility are improved, but security and reliability deteriorate due to vulnerability to fraud and data theft

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a card reader as an intermediary device between the user's card and the communications terminal. The card reader includes a secure element that acts as a trusted mediator, handling sensitive operations like PIN verification and cryptographic operations locally, thereby protecting the general-purpose terminal from direct exposure to security-critical data while still enabling convenient mobile payments

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a dedicated payment terminal is used, then security and reliability are improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the payment system into distinct functional components: a general-purpose communications terminal for user interface and basic processing, and a separate card reader with secure element for security-critical operations. This segmentation allows each component to be optimized independently, reducing overall system complexity while maintaining high security standards

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If the communications terminal handles PIN entry directly, then ease of operation is improved, but security deteriorates due to unauthorized access risks

Engineering Contradiction:
Improveease of operationVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The card reader's secure element serves as an intermediary that receives PIN input from the terminal's interface but processes and verifies it locally without exposing the PIN to the terminal's main processor. This intermediary architecture maintains user-friendly input while blocking unauthorized access pathways

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the security-critical PIN verification function from the general-purpose terminal and relocates it to the card reader's secure element. This extraction removes the harmful vulnerability from the terminal while preserving the convenient input interface

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11551220B2Method for processing transaction data, corresponding communications terminal, card reader and program
Publication Date: 2023.01.10 BANKS & ACQUIRERS INT HLDG SAS
  • US11551220B2 patent drawing
  • US11551220B2 patent drawing

AI summary

A method for processing transaction data, implemented by a communications terminal having a touch screen. The method includes: detecting a necessity of entering a piece of personal identification data; transmitting to a card reader connected to the communications terminal a request for supporting a display of a virtual keypad, the request comprising a piece of data representing a passage of the communications terminal from a “master” mode to a “slave” mode of operation, the slave mode leading to implementation of the method for processing transaction data under the exclusive control of the card reader; of entry, by the user on the virtual keypad, of the piece of personal identification data; and receiving, from the card reader, the piece of personal identification data.