Smart Card Repayment Limit for Secure Bidirectional Payments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing payment systems using data carriers and communication facilities for debiting and crediting services allow unauthorized users to increase memory value units, leading to security issues and improper crediting.
Innovation Solution
Implementing a repayment limit set to the value of the last debited debit value unit, with the data carrier checking that any credited credit value unit does not exceed this limit, ensuring that only authorized users can increase memory value units, and providing different credit authorizations for secure environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If communication facilities are provided for both debiting and crediting sums of money, then the system enables bidirectional payment operations, but the security risk increases as unauthorized persons can steal key information and perform improper crediting
Solution Approach 1:
The system segments credit authorization into two distinct types: Type 1 for secure environments (banks) with maximum credit limits, and Type 2 for less secure environments (communication facilities) with repayment limits. This segmentation allows bidirectional operations while restricting unauthorized crediting capabilities based on environment security levels.
Solution Approach 2:
Different credit authorization types are assigned to different locations/environments. Secure environments (banks) receive Type 1 authorization with higher limits, while less secure environments (communication facilities) receive Type 2 authorization with repayment limits. This local differentiation maintains versatility while enhancing security where needed.
2Reliability
If a repayment limit is set to the debited amount and credited amount is restricted to this limit, then security is improved by preventing unauthorized crediting, but the system flexibility is reduced
Solution Approach 1:
The system dynamically adapts credit limits based on the type of communication facility and environment security. Type 1 facilities operate with maximum credit limits for high-value transactions, while Type 2 facilities use repayment limits for lower-risk operations. This dynamic approach maintains security while preserving necessary flexibility for different use cases.
Solution Approach 2:
The credit limit parameter is changed based on the authorization type: Type 1 uses maximum credit limit (ML), Type 2 uses repayment limit (RL). This parameter differentiation allows the system to maintain both security (through appropriate limiting) and flexibility (by selecting the appropriate parameter based on environment).
Data Source
AI summary
A payment method (BV) executed by a communication facility (1, 2, 8, N) and at least one data carrier (11, 12, K) for debiting a payment value unit (BW) from the data carrier (11, 12, K), in order to pay for a performed service, wherein the following steps are executed:debit from a memory value unit (SW) stored in the data carrier (11, 12, K), of a debit value unit (AW) sufficient for payment for the maximum service to be performed, wherein a repayment limit (RL) stored in the data carrier (11, 12, K) is set to the value in essence of the debited debit value unit (AW);calculation of a credit value unit (AWE) to be credited back, wherein the payment value unit (BW) to be paid for the actually performed service is subtracted from the debited debit value unit (AWE);check by the data carrier (11, 12, K), that the credit value unit (AWE) to be credited does not exceed the stored repayment limit (RL), wherein only in this case is the credit value unit (AWE) credited to the memory value unit (SW) stored in the data carrier (11, 12, K).


