Secure World NFC Payment Data Masking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile payment systems using NFC technology on smartphones are vulnerable to data exposure due to unencoded data transmission and the open nature of smartphone platforms, which can lead to security risks from malicious applications accessing sensitive information like credit card details.

Innovation Solution

A mobile terminal with a secure world that encodes and decodes data within a secure environment, using a payment processor and NFC key manager to protect sensitive information, and a security server that encodes and decodes approval requests, ensuring secure data transmission and storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is transmitted unencoded through NFC for payment processing, then communication speed and simplicity are improved, but security is worsened due to potential data exposure to malicious applications

Engineering Contradiction:
Improvepayment process simplicityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system separates sensitive card information handling from the main application environment by creating a distinct secure element (SE) within the NFC controller. This segmentation ensures that card data is processed in an isolated, trusted environment, preventing malicious applications from accessing sensitive information while maintaining seamless payment functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure element acts as an intermediary between the contactless card and the mobile terminal's main processor. It mediates the authentication process by performing secure verification of card data without exposing the actual card information to the host system or applications, thus maintaining security while enabling payment operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If an open-type smartphone platform is used for NFC payments, then adaptability and ease of application development are improved, but security is worsened due to potential exposure of secure data to malicious codes

Engineering Contradiction:
Improveplatform compatibilityVSAvoidmalicious code exposure
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system creates a segmented architecture where the secure element operates as an independent, protected domain within the smartphone. This allows the open platform to maintain its versatility and application compatibility while the segmented secure element isolates sensitive payment operations from potential malicious code in the host system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different parts of the system have different security properties: the main Android platform maintains open accessibility for various applications, while the secure element implements restricted, high-security access controls. This local differentiation of quality allows the system to be both adaptable and secure.

Inventive Principle:
Principle #3Local quality

3Speed

If card information is stored and processed in the main application memory, then ease of access and processing speed are improved, but security is worsened due to potential data exposure

Engineering Contradiction:
Improvedata processing speedVSAvoidinformation security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system extracts sensitive card information processing from the main application memory and relocates it to the secure element. This extraction maintains fast processing speeds within the secure element while removing the security vulnerability of exposing card data in the main memory space accessible to all applications.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9710803B2Mobile terminal, security server and payment method thereof
Publication Date: 2017.07.18 SAMSUNG ELECTRONICS CO LTD
  • US9710803B2 patent drawing
  • US9710803B2 patent drawing
  • US9710803B2 patent drawing

AI summary

A mobile terminal is provided. The mobile terminal includes a short-range communicator, a security server and a payment method thereof, the mobile terminal including a short-range communicator which exchanges data by a predetermined short-range technology, a payment processor which performs a payment process corresponding to a preset standard in response to a user's request for payment, and a secure world which communicates with the payment processor, extracts secure information from data and stores the data therein and masks the secure information from the outside. Thus, the secure data may be masked at the time of communication with the outside.