Virtual Card Security via Dynamic Transaction Identifiers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is an increasing need to protect sensitive information on smart cards from nefarious parties as cyber security threats rise, particularly with the increasing use of credit cards, identification cards, and access cards that store more secure data.
Innovation Solution
A method is implemented where a processing entity receives a smart card identifier from a virtual card on a mobile device, which is then converted into an executable application using a security object, allowing the virtual card to provide the functionality of a predefined physical electronic card while maintaining security by hiding sensitive information from vendors and ensuring only authorized transactions occur.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If sensitive information is stored on smart cards to enable secure transactions, then transaction security is improved, but vulnerability to cyber security threats increases
Solution Approach 1:
The patent segments sensitive information into multiple components: a static portion stored on the smart card and a dynamic portion generated during transactions. This segmentation ensures that no single component contains all sensitive data, reducing the impact of potential breaches while maintaining transaction security.
Solution Approach 2:
The patent implements dynamic transaction-specific identifiers that change with each transaction, replacing static card information. This dynamic approach ensures that even if one transaction identifier is compromised, it cannot be reused for future transactions, effectively countering cyber security threats while maintaining reliable transaction verification.
2Ease of operation
If virtual cards are implemented on mobile devices, then convenience and accessibility are improved, but security risks from unauthorized access increase
Solution Approach 1:
The patent introduces a secure element or trusted execution environment within the mobile device as an intermediary layer between the virtual card application and the operating system. This intermediary isolates sensitive card operations from the general system, allowing convenient mobile access while preventing unauthorized access by malicious applications or system compromises.
Solution Approach 2:
The patent changes the state of card information from static to dynamic, generating unique transaction-specific identifiers for each use. This parameter change ensures that even if the virtual card data is accessed unauthorizedly, the stolen information cannot be reused for fraudulent transactions, maintaining security while enabling convenient mobile card usage.
Data Source
AI summary
A method securely manages smart card transactions. A processing entity receives a smart card identifier from a smart card, where the smart card is a virtual card on a mobile computing device that comprises a processor, where the smart card identifier is a transaction-specific identifier for a transaction. A protected application is received at the mobile computing device, where a received protected application initially cannot be utilized by an operating system for execution by the processor. A security object is received at the mobile computing device, where the security object is used to convert the received protected application into an executable application that can be utilized by the operating system for execution by the processor. The processor executes the executable application to act as the virtual card, where the virtual card provides a functionality of a predefined physical electronic card.


