Security Module Application Blocking via Transaction Thresholds

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing security measures for mobile terminals with secure modules are inadequate in preventing fraudulent use after loss or theft, as they rely on traditional connections that can be blocked by malicious users, and there is a delay in blocking contactless applications, allowing unauthorized access.

Innovation Solution

A method that increments a transaction value on the security module during each transaction, compares it with a predetermined value, and sends a connection command to the management server to block applications if the value reaches the threshold, ensuring that transactions are limited and unauthorized use is prevented until user rights are verified.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional connection methods are used to block applications, then the service provider can manage applications, but the connection can be blocked by fraudulent users preventing application blocking

Engineering Contradiction:
Improveapplication blocking reliabilityVSAvoidfraudulent use prevention
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by establishing multiple alternative communication paths (SMS, email, data messages) before the fraudulent user can block the primary connection. The security module proactively tries different communication channels to reach the service provider, ensuring that application blocking commands can be delivered even if one path is blocked by a fraudulent user.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional blocking methods are used, then applications can be blocked, but there is a long delay between theft/loss and blocking command delivery allowing fraudulent use

Engineering Contradiction:
Improveblocking effectivenessVSAvoidblocking response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements feedback mechanisms where the mobile terminal continuously monitors connection status and automatically retries alternative communication paths when the primary path fails. The service provider receives real-time notifications of theft/loss reports and can immediately send blocking commands through available channels, reducing the time delay between incident and blocking.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Multiple communication paths are pre-configured and ready to use before needed. When a blocking command is required, the system immediately attempts these pre-established alternative paths without delay, enabling rapid response to theft or loss incidents.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the security module connects to the management server, then application rights can be verified, but the connection may fail allowing unauthorized transactions

Engineering Contradiction:
Improveauthorization verificationVSAvoidconnection delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security module and mobile terminal pre-establish multiple communication paths to the management server before authorization verification is needed. When connection is required for rights verification, the system immediately attempts these pre-configured paths, reducing verification delay while ensuring reliability through alternative routes if the primary path fails.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2232815B1Method of controlling applications installed on a security module associated with a mobile terminal, associated security module, mobile terminal and server
Publication Date: 2020.02.26 ORANGE SA
  • EP2232815B1 patent drawingFigure 1~2
  • EP2232815B1 patent drawingFigure 3~4
  • EP2232815B1 patent drawingFigure 5

AI summary

The invention pertains to a method of controlling applications installed on a security module associated with a mobile terminal, adapted to increment, during a transaction carried out by an application, at least one transaction value, and, if this value reaches an associated predetermined value, to dispatch at least one command for connection to a management server and to disable at least one application in the event that the command fails. The invention also pertains to a method of managing such applications which is adapted to receive a connection command, to verify the user rights and to update at least one transaction value and/or to disable at least one application, as a function of the result of the verification. The invention also relates to a management server, a mobile terminal and a security module able to be used with a mobile terminal.