Trusted Execution Environment Secure Payment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current electronic payment systems using mobile terminals are vulnerable to credit card fraud due to the potential for unauthorized access to credit card information, as data for millions of stolen credit cards is readily available on the black market, posing a significant risk of fraud and abuse.

Innovation Solution

An apparatus and method for secure electronic payment that includes a trusted execution environment in an electronic device, which authenticates users, generates credit card track data, and stores it securely, using a magnetic stripe swipe simulator to simulate a magnetic card swipe, thereby enhancing security and reducing power consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If credit card information is stored in mobile terminal using conventional methods, then electronic payment convenience is improved, but security against fraud deteriorates

Engineering Contradiction:
Improveelectronic payment convenienceVSAvoidsecurity against fraud
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments credit card data into multiple components (primary account number, service code, discrete data elements) and stores them separately in different memory locations within the trusted execution environment. This segmentation prevents criminals from obtaining complete card information even if they compromise part of the system, directly addressing the security vulnerability while maintaining payment convenience.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trusted execution environment as an intermediary layer between the user's credit card information and the payment processing system. This secure enclave acts as a mediator that handles authentication and data transmission without exposing sensitive information to the rest of the mobile terminal or external systems, thereby improving security while maintaining ease of use.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If magnetic stripe simulation is implemented for contactless payment, then transaction speed is improved, but power consumption increases

Engineering Contradiction:
Improvetransaction speedVSAvoidpower consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The patent implements magnetic stripe simulation using periodic electromagnetic field generation only during the brief moment when the mobile terminal is held near the card reader. The system activates the magnetic field intermittently and only when needed for data transmission, rather than maintaining continuous electromagnetic emission. This periodic action enables fast contactless transactions while significantly reducing overall power consumption compared to continuous transmission methods.

Inventive Principle:
Principle #19Periodic action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

The solution provides a secure and trusted method for electronic payments by preventing unauthorized access to sensitive financial information, reducing the risk of fraud, and improving user interface efficiency while minimizing power consumption.

Implementation Method 1

a magnetic stripe swipe simulator configured to generate a magnetic field capable of being read by a magnetic card reader

Methodology Applied
Scientific EffectMagnetic field generation: Electromagnet

Data Source

PatentUS10699274B2Apparatus and method for secure electronic payment
Publication Date: 2020.06.30 SAMSUNG ELECTRONICS CO LTD
  • US10699274B2 patent drawing
  • US10699274B2 patent drawing
  • US10699274B2 patent drawing

AI summary

An apparatus and method for secure electronic payment are provided. The method includes authenticating a user of an electronic device executing a trusted payment application in a trusted execution environment of the electronic device, receiving credit card data from the user, generating credit card track data based on the received credit card data, and storing the credit card track data.