Security Element Modules Embedding Tamper Data in Payment Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile applications face threats from attackers who can decompile and tamper with their source code, and existing binary protections are ineffective when attackers shut down cellular data connections, preventing security notifications from being reported.

Innovation Solution

A system that includes a portable communication device with security element modules that detect unauthorized access and generate security notification data, which is embedded in standard payment transaction data, allowing a remote security server and payment processing network to make transaction decisions and report security compromises without relying on cellular data connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If binary protections are used to obfuscate source code and notify remote servers of attacks, then security detection capability is improved, but reliability deteriorates when attackers shut down cellular data connections

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidattack reporting reliability
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent introduces an intermediary mechanism by embedding security notification data within standard payment transaction data. This allows security information to be transmitted through the payment network infrastructure rather than relying solely on cellular data connections. The payment transaction data serves as a carrier that can bypass network restrictions and deliver security notifications reliably even when cellular data is shut down by attackers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If security notification data is transmitted over cellular network, then security reporting is enabled, but vulnerability increases when data connection is shut down

Engineering Contradiction:
Improvesecurity reporting functionalityVSAvoidnetwork dependency vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies multi-functionality by using standard payment transaction data to serve dual purposes: its primary function for payment processing and a secondary function for carrying security notification data. This allows the same communication channel to be used for both legitimate payment operations and security reporting, eliminating the need for separate dedicated security communication channels that would be vulnerable to network shutdowns.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If mobile applications are protected with binary protections, then source code obfuscation is achieved, but security against determined attackers deteriorates

Engineering Contradiction:
Improvecode protection strengthVSAvoiddetermined attacker vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback by embedding security notification data that provides real-time information about attack attempts directly into the payment transaction flow. When tampering is detected, the security element modules generate notification data that is immediately transmitted through the payment network to remote servers. This feedback loop allows for rapid response to attacks, enabling the system to adapt and respond to determined attackers rather than relying solely on static binary protections.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3238415B1Software tampering detection and reporting process
Publication Date: 2020.04.01 VISA INTERNATIONAL SERVICE ASSOCIATION
  • EP3238415B1 patent drawingFigure 1
  • EP3238415B1 patent drawingFigure 2~3A
  • EP3238415B1 patent drawingFigure 3B

AI summary

A method is disclosed. The method includes determining, by a security software application on a communication device, that the communication device has been accessed by an unauthorized user. The communication device is configured to communicate with a telecommunications network over the air through a first communication channel. The method also includes generating, by the communication device, security notification data and providing the security notification data or a derivative of the security notification data to a host computer via a second communication channel.