Terminal Management Server Application Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile payment systems face challenges in ensuring the authenticity and integrity of payment applications, preventing unauthorized usage of sensitive services, and efficiently distributing and maintaining applications across a large scale with high quality-of-service measures.

Innovation Solution

A system comprising an application store, a terminal management server (TMS), and a network that allows vendors to upload applications, which are then downloaded and authorized by the TMS for installation and running on terminals, ensuring authentication and classification into application class sandboxes based on authorization and type.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If payment applications are distributed through traditional Terminal-Management-Servers or custom application stores, then full control of security is achieved, but running costs increase significantly

Engineering Contradiction:
Improvesecurity controlVSAvoidrunning cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent introduces a dual-signature mechanism where both the terminal vendor and application vendor sign the application. This intermediary verification layer allows the system to use public application stores for distribution while maintaining security control through cryptographic verification, avoiding the need for expensive custom application store infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent enables payment applications to be distributed through universal public application stores alongside non-payment applications. The dual-signature system allows a single distribution infrastructure to serve multiple purposes (payment and non-payment apps) while maintaining differentiated security verification, reducing infrastructure costs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of energy

If payment applications are distributed through public application stores, then running costs are reduced, but security control and authentication requirements increase

Engineering Contradiction:
Improverunning costVSAvoidauthentication requirements
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The patent performs security verification in advance by requiring dual signatures from terminal vendor and application vendor before the application is made available in the public store. This preliminary authentication layer is embedded in the application packaging process, so that when the application is installed and executed, the security verification has already been completed, simplifying runtime authentication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses cryptographic hash values and digital signatures as copies of the application's identity and authenticity. Instead of complex runtime verification of the entire application, the system verifies a compact cryptographic copy (hash + signature) that proves the application's integrity and authorization, reducing authentication complexity.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If applications are allowed to run on smart devices for flexibility, then adaptability improves, but security risks from unauthorized applications increase

Engineering Contradiction:
Improveapplication compatibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies different quality standards to different applications based on their type. Payment applications require dual signatures from both terminal vendor and application vendor, while non-payment applications require only application vendor signature. This localized quality control allows flexible distribution of diverse applications while maintaining high security for sensitive payment functions.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the security verification parameter based on application type. For payment applications, the verification requires matching terminal vendor public key with the application's terminal vendor signature. For non-payment applications, only application vendor signature verification is needed. This parameter change enables adaptable security that matches the risk level of different application categories.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12210596B2Terminal hardware configuration system
Publication Date: 2025.01.28 STRIPE LLC
  • US12210596B2 patent drawing
  • US12210596B2 patent drawing
  • US12210596B2 patent drawing

AI summary

Methods and systems for installing and running an application for a terminal are described. The method may include uploading an application to an application store. The method may also include downloading, by a terminal, the application from the application store, wherein the terminal is connected to the application store by a network. Furthermore, the method may include authorizing, by a terminal management server (TMS) coupled to the terminal and the application store via the network, the terminal to install and run the downloaded application.