SIM-Integrated mPOS Frontend for Secure COTS Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile Point-of-Sales (mPOS) applications on COTS devices face issues such as user discomfort and anxiety due to the need to present sensitive data, high attack surfaces, complex monitoring systems, and cumbersome setup procedures, which hinder widespread acceptance.
Innovation Solution
A method utilizing a UICC card, such as a SIM card, integrated with a terminal device to provide a secure frontend, capturing transaction data through a human machine interface and reading further data via a machine-to-machine interface, generating and transmitting transaction authorizations through a secure connection to a backend server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a mPOS application is executed on a COTS device with extensive external monitoring system, then transaction security is improved, but device complexity and setup procedure complexity increase
Solution Approach 1:
The patent extracts the critical security functions from the complex external monitoring system and relocates them to the UICC card. The UICC card independently performs transaction data storage, encryption key generation, and cryptographic operations, removing the burden of extensive monitoring requirements from the COTS device while maintaining high security standards.
Solution Approach 2:
The UICC card serves as an intermediary security element between the COTS device and the transaction processing system. It mediates security-critical operations by securely storing transaction data and cryptographic keys, performing encryption/decryption operations, and validating transaction authenticity without requiring the COTS device to implement complex monitoring mechanisms.
2Reliability
If a mPOS application on a COTS device uses extensive external monitoring system, then transaction security is improved, but user comfort and acceptance decrease due to anxiety in presenting sensitive data
Solution Approach 1:
The patent extracts sensitive data (transaction data and cryptographic keys) from the COTS device interface and stores it securely within the UICC card. Users interact with the terminal device as usual without being exposed to or anxious about sensitive data handling, while the UICC card securely manages these sensitive elements in the background.
Solution Approach 2:
The UICC card performs self-service security functions by automatically generating cryptographic keys, encrypting transaction data, and validating transaction authenticity without requiring user intervention or awareness of the complex security processes. This maintains user comfort while ensuring robust security.
3Reliability
If a mPOS application requires complex setup and personalization procedure with remote verification, then security is improved, but ease of deployment and wide acceptance decrease
Solution Approach 1:
The UICC card performs preliminary security setup during manufacturing or activation, where cryptographic key pairs are generated and stored securely. This preliminary action eliminates the need for complex runtime setup procedures on COTS devices, as the security infrastructure is already in place and ready for immediate use.
Solution Approach 2:
The UICC card provides universal security functionality that works across different COTS devices and transaction scenarios. By implementing standardized security operations (encryption, decryption, digital signing) within the UICC card, the system achieves broad compatibility and simplified deployment without requiring device-specific security configurations.
Data Source
AI summary
A method for operating a mobile Point-of-Sales (mPOS) application for executing a transaction includes: a Universal Integrated Circuit Card (UICC) card connected to a terminal device executes in interaction with the terminal device an application frontend of the mPOS application that provides, upon launch, an I/O interface with a human machine interface displayed by a touchscreen of the terminal device and a machine-to-machine interface; and the application frontend, for starting a transaction, captures transaction data associated with the transaction to be started via the human machine interface, reads further transaction data via the machine-to-machine interface from a transaction device separate from the terminal device and arranged close to the terminal device, generates a transaction authorization authorizing the requested transaction, and transmits the transaction authorization, the transaction data and the further transaction data via a connection to a remote backend server for completing the transaction.
