Secured Payment Token Generation via Nested Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Payment tokens derived from payment instruments, especially those hosted on mobile terminals without secure chips, remain vulnerable to theft due to lack of adequate security measures during provisioning and usage, exposing them to data interception and hacking.

Innovation Solution

A method that secures payment tokens by pairing a mobile terminal's identifier and personal cryptogram with the payment instrument, generating a second secured token through encryption of the first token, transaction data, terminal identifier, and personal cryptogram, using a successful authentication protocol and temporary encryption keys, ensuring only registered terminals and users can utilize the tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If payment tokens are hosted on mobile terminals without secure chips to enable software-based payment solutions, then ease of operation and adaptability are improved, but security and reliability deteriorate due to vulnerability to data theft and interception

Engineering Contradiction:
Improvesoftware-based payment solutionVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a nested security structure where multiple layers of protection are embedded within each other: the first token is encrypted to produce a second token, which is then encrypted again with additional parameters (terminal identifier, personal cryptogram, transaction data) to produce a third token. This nested encryption approach allows software-based payment solutions to achieve security comparable to hardware secure chips while maintaining ease of operation.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent applies preliminary pairing between the mobile terminal and payment instrument before token provisioning occurs. This preliminary authentication establishes security credentials (terminal identifier, personal cryptogram) that are used throughout subsequent transactions. By performing this security setup in advance, the system enables secure software-based payments without requiring physical secure chips in the mobile terminal.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If payment tokens are provisioned on mobile phones in batches for multiple payments, then productivity is improved, but security worsens because tokens remain vulnerable to theft between provisioning and usage

Engineering Contradiction:
Improvebatch token provisioningVSAvoidsecurity during transmission and storage
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements dynamic token generation where the final token (third token) is not created until the moment of transaction execution. Instead, the system stores only the second token along with security parameters, and generates the final encrypted token dynamically when transaction data becomes available. This dynamic approach allows batch provisioning of base tokens for efficiency while ensuring security by only creating the final usable token when actually needed, eliminating the security gap during storage.

Inventive Principle:
Principle #15Dynamics

3Reliability

If encryption of payment tokens is implemented using temporary keys from payment token generation servers, then security is improved, but device complexity increases due to additional authentication protocols and key management

Engineering Contradiction:
Improveencryption securityVSAvoidauthentication protocol
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary pairing between the mobile terminal and payment instrument before token provisioning, establishing security credentials (terminal identifier, personal cryptogram) in advance. This preliminary action consolidates the authentication complexity into a one-time setup process, allowing subsequent transactions to use these pre-established credentials for encryption without repeating complex authentication protocols, thus improving security while managing device complexity.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If pairing of terminal identifier and personal cryptogram with payment instrument is performed through authentication protocol, then security against unauthorized access is improved, but ease of operation deteriorates due to additional authentication steps

Engineering Contradiction:
Improveauthorization securityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent performs the pairing and authentication protocol as a preliminary action during the initial setup phase, establishing security credentials before the user needs to make payments. Once this preliminary authentication is complete, subsequent transactions can proceed using the pre-established credentials without requiring the user to repeat complex authentication steps, thus maintaining strong authorization security while improving ease of operation for actual payment transactions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3221815B1Method for securing a payment token
Publication Date: 2021.05.19 IDEMIA FRANCE SAS
  • EP3221815B1 patent drawingFigure 1~2
  • EP3221815B1 patent drawingFigure 3
  • EP3221815B1 patent drawingFigure 4

AI summary

The invention relates to a method for securing a payment token, a mobile terminal (12), and a server (11) for generating a payment token. The method comprises a first step of pairing a subscriber terminal identifier and a personal password to a payment instrument (17), followed by a step of generating a payment token (104) secured by the identifier and personal password. The pairing and generating of the secured payment token (104) allow verification that the token (103) is used by the subscriber and by the mobile terminal (12) of same. The invention is applicable to payment systems based on payment tokens with restrictions of use.