Secure Virtual Point of Service for Wireless Transaction Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 3G wireless network payment systems, such as Vodafone 'm-pay' and DoCoMo, have limitations in enabling transactions between subscribers and merchants without pre-established relationships, and they raise concerns about privacy and security, with limited purchase amounts and restricted applications.
Innovation Solution
A secure virtual point of service (SVPOS) that coordinates authentication, authorization, and identity management within a 3G network, transforming a mobile device into a credit/debt payment device, ensuring privacy and anonymity, and includes a non-repudiation mechanism to prevent fraud, allowing transactions with any merchant and managing settlements through a Bootstrapping Server, Home Subscriber Server, and Parlay server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a wallet full of credit cards is carried for transactions, then payment capability is improved, but convenience deteriorates and risks of loss, theft, and fraud increase
Solution Approach 1:
The mobile device is transformed into a multi-functional electronic wallet that combines payment, authentication, and transaction management capabilities in a single device, eliminating the need to carry multiple credit cards while maintaining payment versatility
2Adaptability or versatility
If personal credentials and payment information are transmitted over the network for online transactions, then transaction capability is improved, but security and privacy deteriorate due to information being shared with merchants and business partners
Solution Approach 1:
The operator's network serves as a trusted intermediary between the subscriber and merchant, handling authentication and payment information transmission securely. The subscriber's personal credentials never leave the mobile device, and the operator mediates the exchange of payment tokens and authorization codes without exposing sensitive information
Solution Approach 2:
Sensitive personal identification information and payment credentials are extracted from the transaction flow entirely. Instead of transmitting actual credit card numbers and personal details, the system uses anonymized tokens and authorization codes that carry payment value without exposing underlying sensitive data
3Reliability
If pre-established business relationships are required between phone operators and merchants for mobile payment, then security is improved, but adaptability deteriorates limiting transactions to official sites only
Solution Approach 1:
The system provides universal payment capability that works with any merchant regardless of pre-established relationships. The operator's authentication infrastructure serves multiple purposes: securing transactions, enabling payments, and providing fraud protection without requiring exclusive partnerships
Solution Approach 2:
The system enables self-service transactions where the subscriber's mobile device independently handles authentication and payment authorization without requiring merchant integration with the operator's systems. Any merchant accepting mobile payments can process transactions using the standardized protocol
4Ease of operation
If mobile phone payment systems are implemented, then payment convenience is improved, but purchase amount limits and application restrictions worsen the versatility
Solution Approach 1:
The system provides dynamic payment capabilities where transaction limits and authorization levels can be adjusted in real-time based on subscriber preferences, merchant agreements, and risk assessments. The electronic wallet can handle both small impulsive purchases and large planned transactions without fixed limits
Data Source
AI summary
A Secure Virtual Point of Service (SVPOS) that coordinates the authentication, authorization, and identity, settlement, arbitration and non-repudiation for an electronic commercial transaction. For each commercial transaction, both the buyer and merchant authenticate itself to the SVPOS and create two unique transaction encryption keys, one for the buyer and one for the merchant. The merchant uses both encryption keys to encrypt a package that include at least product identification. The merchant and buyer calculate a hash of the package and transmit the calculated hash to the SVPOS for comparison to prevent repudiation. If the calculated hash is identical the buyer receives the merchants encryption key and decrypts the package. Payment is released by the SVPOS if the buyer is satisfied with the package via a Parlay system. If the buyer is not satisfied, said SVPOS performs arbitration between the buyer and merchant to determine if the package is correct.


