Secure PIN Entry Application for Mobile EMV Payments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems cannot securely facilitate EMV-approved debit and credit card payments using mobile phones due to security concerns, particularly the interception of personal identification numbers (PINs) by malicious software.
Innovation Solution
A method and system that employs a secure PIN entry application on a mobile device, utilizing encryption and secure communication protocols, including standard Secure Socket Layer (SSL) for secure PIN input and verification, involving a card reader, payment server, and bank server, to ensure secure EMV-approved transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If PIN entry is implemented on mobile phone, then payment convenience is improved, but security is worsened due to potential interception by malicious software
Solution Approach 1:
The patent introduces a payment server as an intermediary between the mobile device and the banking system. The server receives encrypted PIN data from the mobile device, decrypts it securely, and processes the authentication. This mediator architecture allows PIN entry on convenient mobile devices while maintaining security through server-side verification, resolving the contradiction between operational ease and security reliability.
2Adaptability or versatility
If standard mobile phone is used for EMV payment, then device accessibility is improved, but security compliance is worsened as mobile phones are not considered secure devices
Solution Approach 1:
The patent replaces the traditional mechanical EMV chip verification system with a software-based alternative. Instead of requiring specialized secure hardware, the system uses encrypted data transmission and server-side PIN verification to achieve the same security objectives. This substitution enables standard mobile phones to perform EMV-compliant payments while maintaining security through cryptographic methods rather than physical security mechanisms.
3Reliability
If encryption is applied to PIN data, then security is improved, but processing complexity is worsened
Solution Approach 1:
The patent divides the security processing into two distinct segments: encryption/decryption operations performed on the mobile device, and verification/authentication operations performed on the payment server. This segmentation allows each component to handle only its designated security function, reducing the complexity burden on individual devices while maintaining overall system security through coordinated encrypted communication.
Data Source
Figure 1
Figure 2
Figure 3a
AI summary
A method for conducting PIN authorized EMV payments using an ordinary mobile phone. The credit card payment is conducted using a merchant's device comprising a card reader and a mobile phone a payment server and a buyer's mobile phone. A PIN entry request is sent from the merchant's device to the buyer's device via the payment server. A secure application in the buyer's device is executed and a PIN code may be entered securely. The entered PIN code is either verified, via the payment server, against the credit card in said merchant's device or against a bank server. Thus, secure credit card payments can be performed using an ordinary unsecure mobile device's.