Trust Token Verification for Secure NFC Payment Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for a solution that enables a payor or a payment application to ascertain the security, reliability, or trustworthiness of a merchant device before transmitting payment card information or other confidential information during a NFC-enabled contactless payment transaction.

Innovation Solution

A system and method that utilize a trust token server to assess the trustworthiness of a merchant device by generating and comparing displayable trust tokens, ensuring that payment information is only transmitted to validated, trustworthy merchant devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If contactless payment transactions are implemented between mobile communication device and merchant device, then payment convenience and transaction speed are improved, but security and reliability of payment information transmission deteriorate due to potential untrusted merchant devices

Engineering Contradiction:
Improvetransaction speedVSAvoidsecurity of payment information
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary trust verification by generating and validating trust tokens before actual payment information is transmitted. The mobile communication device obtains a trust token from the merchant device, verifies it against a trusted list, and only then proceeds with the payment transaction, ensuring security is established in advance

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Trust tokens act as an intermediary mechanism between the mobile communication device and merchant device. The tokens serve as a trusted third-party verification that mediates the interaction, allowing the system to establish confidence in the merchant device's authenticity without requiring direct trust between the two parties

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If trust verification mechanisms are implemented to assess merchant device reliability, then security and reliability of payment transactions are improved, but device complexity and operational overhead increase

Engineering Contradiction:
Improvetrustworthiness verificationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of implementing complex verification protocols directly in the mobile device, the system uses simplified trust tokens that copy or represent the merchant device's identity and trust attributes. These tokens can be easily generated, transmitted, and verified without requiring the mobile device to perform complex cryptographic operations or maintain extensive verification logic

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The trust token mechanism serves multiple functions: it verifies merchant device authenticity, establishes transaction legitimacy, and provides audit trail capability. This multi-functional approach consolidates what could be multiple separate verification systems into a single unified mechanism, reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12288213B2Systems, methods and computer program products for secure contactless payment transactions
Publication Date: 2025.04.29 MASTERCARD INT INC
  • US12288213B2 patent drawing
  • US12288213B2 patent drawing
  • US12288213B2 patent drawing

AI summary

The invention provides methods, systems and computer program products for implementing an electronic payment transaction between mobile communication device and a NFC enabled merchant device, both of which are configured to implement a defined communication protocol. The invention implements the required functionality by (i) receiving a request for a trust token from a merchant device, (ii) determining whether the merchant device is trustworthy, (iii) responsive to a determination that the merchant device is trustworthy, generating and transmitting a first displayable trust token to the merchant device, (iv) receiving a second displayable token from the mobile communication device, (v) comparing the received second displayable token against the first displayable token, and generating a merchant device validation message based on the comparison, and (vi) transmitting the merchant validation decision message to the mobile communication device.