Secure PIN Entry Application for Mobile EMV Payments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems cannot securely facilitate EMV-approved debit and credit card payments using mobile phones due to security concerns, particularly the interception of personal identification numbers (PINs) by malicious software.

Innovation Solution

A method and system that employs a secure PIN entry application on a mobile device, utilizing encryption and secure communication protocols, including standard Secure Socket Layer (SSL) for secure PIN input and verification, involving a card reader, payment server, and bank server, to ensure secure EMV-approved transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If PIN entry is implemented on mobile phone, then payment convenience is improved, but security is worsened due to potential interception by malicious software

Engineering Contradiction:
Improvepayment convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a payment server as an intermediary between the mobile device and the banking system. The server receives encrypted PIN data from the mobile device, decrypts it securely, and processes the authentication. This mediator architecture allows PIN entry on convenient mobile devices while maintaining security through server-side verification, resolving the contradiction between operational ease and security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If standard mobile phone is used for EMV payment, then device accessibility is improved, but security compliance is worsened as mobile phones are not considered secure devices

Engineering Contradiction:
Improvedevice accessibilityVSAvoidsecurity compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent replaces the traditional mechanical EMV chip verification system with a software-based alternative. Instead of requiring specialized secure hardware, the system uses encrypted data transmission and server-side PIN verification to achieve the same security objectives. This substitution enables standard mobile phones to perform EMV-compliant payments while maintaining security through cryptographic methods rather than physical security mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If encryption is applied to PIN data, then security is improved, but processing complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the security processing into two distinct segments: encryption/decryption operations performed on the mobile device, and verification/authentication operations performed on the payment server. This segmentation allows each component to handle only its designated security function, reducing the complexity burden on individual devices while maintaining overall system security through coordinated encrypted communication.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2622585B1Hub and spokes pin verification
Publication Date: 2015.08.05 IZETTLE MERCHANT SERVICES
  • EP2622585B1 patent drawingFigure 1
  • EP2622585B1 patent drawingFigure 2
  • EP2622585B1 patent drawingFigure 3a

AI summary

A method for conducting PIN authorized EMV payments using an ordinary mobile phone. The credit card payment is conducted using a merchant's device comprising a card reader and a mobile phone a payment server and a buyer's mobile phone. A PIN entry request is sent from the merchant's device to the buyer's device via the payment server. A secure application in the buyer's device is executed and a PIN code may be entered securely. The entered PIN code is either verified, via the payment server, against the credit card in said merchant's device or against a bank server. Thus, secure credit card payments can be performed using an ordinary unsecure mobile device's.