Security Keyboard for Mobile Payment Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile payment security is compromised due to attacks from malicious software leading to the leak and loss of private user information and property, as existing technologies fail to adequately secure the information interaction process, particularly in verifying network access points and application signatures during transactions.

Innovation Solution

A method and device that monitor and verify the security of network access points and application signatures on mobile terminals, displaying a security keyboard for secure user input and transmitting data only when security parameters are met, ensuring secure information interaction by preventing malicious software interception and domain name hijacking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If mobile payment allows user information transmission, then payment convenience is improved, but security vulnerability to malicious software increases

Engineering Contradiction:
Improvepayment convenienceVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

A security application acts as an intermediary between the first application (payment app) and the user information transmission process. The security application monitors network access points, verifies application signatures, and controls the security keyboard to prevent malicious software from intercepting user information, thus resolving the contradiction between payment convenience and security vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security verification by checking network access point security and application signature authenticity before allowing user information transmission. The security application pre-establishes security parameters and validates them in advance, preventing malicious interference during the actual payment process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security verification is performed on network access points and application signatures, then information security is improved, but system complexity increases

Engineering Contradiction:
Improveinformation securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security application performs multiple security functions including network access point verification, application signature validation, and secure keyboard control within a single unified system. This multi-functional approach improves information security while avoiding the complexity that would result from implementing separate verification systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If a security keyboard from a second application is used, then user information protection is improved, but ease of operation decreases

Engineering Contradiction:
Improveuser information protectionVSAvoidease of input
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security application automatically manages the security keyboard, including its activation, deactivation, and switching between different applications. The system self-regulates the keyboard based on security parameter verification results, reducing the operational burden on users while maintaining strong information protection.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10055731B2Method and device for securing an information interaction process
Publication Date: 2018.08.21 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US10055731B2 patent drawing
  • US10055731B2 patent drawing
  • US10055731B2 patent drawing

AI summary

An electronic device with one or more processors, memory, and a display detects a user interaction with a user interface of a first application and, in response to detecting the user interaction with the user interface of the first application, determines whether one or more security parameters are satisfied, where a first security parameter is satisfied when a network access point being used by the electronic device satisfies predefined criteria. In accordance with a determination that the one or more security parameters are satisfied, the device: displays a security keyboard on the display corresponding to a second application different from the first application; and receives user information input via the security keyboard by a user of the electronic device. The device transmits the user information to a target terminal.