Virtual Card Payment Gateway for Mobile NFC Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current payment systems using NFC-enabled mobile devices for contactless transactions are limited by the need for pre-arranged agreements between mobile phone carriers and funding card issuers, leading to restricted options for users and increased costs for issuers, as well as security risks due to the exposure of sensitive financial data.

Innovation Solution

A cloud-based wallet payment gateway server synchronizes with NFC-enabled mobile devices to facilitate contactless payments using a virtual card system, where a virtual card is generated with required data, allowing users to make payments without exposing actual funding card details, and enabling registration of multiple funding cards independently of carrier or issuer agreements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If NFC-enabled mobile devices are used for contactless payments with pre-arranged agreements between carriers and issuers, then payment transactions can be completed securely, but user flexibility is restricted and infrastructure costs increase

Engineering Contradiction:
Improvepayment securityVSAvoiduser flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a virtual card as an intermediary between the user's funding card and the payment terminal. The virtual card contains placeholder data that allows the transaction to proceed without exposing the actual funding card details. This intermediary layer enables users to load any funding card onto their mobile device independently, eliminating the need for pre-arranged carrier-issuer agreements while maintaining security through the virtual card gateway.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy of the funding card data in the form of a virtual card. This virtual copy contains the necessary payment data (card number, expiry date, CVV) but is decoupled from the actual funding card. Users can load multiple different funding cards onto the same mobile device by simply updating the virtual card data, providing flexibility without requiring physical card changes or carrier-specific configurations.

Inventive Principle:
Principle #26Copying

2Reliability

If pre-arranged agreements between carriers and issuers are required for NFC payments, then system reliability is maintained, but infrastructure costs and complexity increase

Engineering Contradiction:
Improvesystem reliabilityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the carrier-issuer agreement requirement from the payment system. By using a virtual card gateway, the system removes the need for pre-established technical agreements between carriers and card issuers. The virtual card acts as a universal interface that works with any funding card, simplifying the infrastructure to a single gateway approach rather than multiple carrier-specific integrations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The virtual card system provides universality by enabling the same mobile device to work with multiple different funding cards from different issuers. The virtual card gateway serves as a universal adapter that translates between the mobile device's payment system and various funding card formats, eliminating the need for separate infrastructure for each carrier-issuer combination.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If actual funding card details are stored on mobile devices for NFC payments, then transactions can be processed, but security risks increase due to data exposure

Engineering Contradiction:
Improvetransaction processingVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The virtual card serves as a mediator that prevents direct storage of actual funding card details on the mobile device. Instead, the device stores only the virtual card data which maps to the funding card through the gateway. This intermediary layer allows transaction processing to proceed while ensuring that sensitive funding card information never resides on the mobile device, eliminating the security risk of data exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The virtual card can be designed as a single-use or short-lived credential that is generated temporarily for each transaction. After use, the virtual card data is discarded, and a new virtual card is generated for the next transaction. This disposable approach ensures that even if the mobile device is compromised, the actual funding card details remain protected, as they were never stored on the device.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution reduces storage requirements on secure elements, lowers infrastructure costs, and enhances security by minimizing data exposure, while allowing users to load any funding cards onto their mobile devices for contactless payments, thus increasing user flexibility and reducing issuer burdens.

Implementation Method 1

A mobile device can be equipped with a near field communication (NFC) system which can be used to transfer the buyer's payment credential, such as credit card information, to a point of sale terminal that is also equipped with a NFC-compatible system

Methodology Applied
Scientific EffectNear field communication (NFC): Electromagnetic Induction

Data Source

PatentEP3848874B1Systems and methods for facilitating a transaction using a virtual card on a mobile device
Publication Date: 2024.04.17 STICKY IO INC
  • EP3848874B1 patent drawingFigure 1
  • EP3848874B1 patent drawingFigure 2
  • EP3848874B1 patent drawingFigure 3

AI summary

A method at a payment gateway server comprises receiving a card registration request from a mobile device, the card registration request including a device identifier of the mobile device, a PIN provided by a user of the mobile device, and funding card details of a payment card to be registered. The funding car details include a name printed on the funding card, a primary account number (PAN) printed on the funding card, an expiry date printed on the funding card, and a static security code printed on the funding card. In response to the card registration request, a card registration response is sent to the mobile device for storage at the mobile device, the card registration response containing a certificate, an Application Transaction Counter, a first key value, a secure element key value (Ksec), and a funding card identifier distinct from the PAN. In a memory of the payment gateway server, the contents of the card registration response, the PIN, the device ID, and the funding card details are stored. Subsequent to sending the card registration response, a virtual card request from the mobile device is received, the virtual card request including the device identifier, a virtual transaction type indicator, the funding card identifier, a received certificate, and a received Kpan. On response to the payment initiation, a second Kpan is sent to the mobile device for use in generating a virtual PAN. Using the second Kpan, the virtual PAN is generated; and the second Kpan and the virtual PAN are stored in the memory in association with the funding card identifier.