Secure PIN Entry on Trusted Devices via Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current PIN On Glass specifications do not provide a method or infrastructure for cardholders to enter their personal identification number (PIN) on a device they trust, rather than a merchant-controlled device, and fail to mitigate risks of theft or damage to merchant devices.
Innovation Solution
A system and method where cardholders enter their PIN on a personal device they trust, with secure communication protocols to protect PIN and cardholder data, involving a merchant device, a cardholder-trusted device, and an acquirer application to establish a secure transmission connection for verifying electronic identity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If cardholders enter PIN on merchant-controlled devices, then transaction processing is simplified, but security risks and device theft/damage risks increase
Solution Approach 1:
The system segments the PIN entry function from the merchant device and relocates it to the cardholder's trusted device. The merchant device displays only a transaction identifier (QR code or alphanumeric), while the actual PIN entry occurs on the cardholder's mobile device through a trusted application, separating the sensitive input function from the potentially compromised merchant terminal.
Solution Approach 2:
The system introduces an intermediary trusted application on the cardholder's device that mediates the PIN entry process. This intermediary application securely captures the PIN locally and transmits it through encrypted channels to the payment processor, acting as a trusted mediator between the cardholder and the payment system without exposing the PIN to the merchant device.
2Reliability
If cardholders enter PIN on personal trusted devices, then security and theft risk mitigation improve, but system complexity and communication requirements increase
Solution Approach 1:
The trusted application on the cardholder's device serves multiple functions: it displays the transaction identifier, captures the PIN input, establishes secure communication with the payment processor, and manages the authentication flow. This multi-functional approach consolidates the complexity into a single trusted application rather than requiring separate dedicated hardware components.
Solution Approach 2:
The system implements a feedback mechanism where the merchant device displays a transaction identifier that the cardholder's trusted application must recognize and verify. This feedback loop ensures that the PIN entry is tied to a specific authorized transaction, providing real-time verification and preventing unauthorized use while maintaining system security.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
System, devices and methods of verifying an electronic identity provided. A cardholder device method comprises receiving an input of an element associated with a transaction identifier for a transaction, establishing with an acquirer application a secure transmission connection, receiving from the acquirer application a request for a secure cardholder identification, receiving an input comprising the secure cardholder identification, and sending the acquirer application the input comprising the secure cardholder identification. A merchant device method comprises displaying an element associated with a transaction identifier for a transaction, receiving from an acquirer application a secure cardholder identification, and transmitting to a payment transition security device the secure cardholder identification. An acquirer system method comprises sending to a cardholder device a request for a secure cardholder identification, receiving from the cardholder device the secure cardholder identification, and transmitting to a merchant device the secure cardholder identification.