Virtual ICC Secure Zone for Payment Data Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic devices are vulnerable to security breaches during online transactions due to software-based attacks, and physical credit cards introduce flexibility and security issues.
Innovation Solution
A secure zone within electronic devices, comprising a supervisor, secure processor, and cryptographic engine, ensures secure storage and processing of payment information, isolating it from the operating system to prevent interception and manipulation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If payment information is stored and processed in the operating system of electronic devices, then online transactions can be conducted, but the system becomes vulnerable to software-based attacks such as viruses, backdoors, and keyloggers
Solution Approach 1:
The system is divided into two distinct segments: a secure zone with a secure processor for handling payment information, and a non-secure zone with the operating system for general computations. This segmentation isolates sensitive operations from software-based attacks while maintaining overall system functionality.
Solution Approach 2:
The critical payment information processing functions are extracted from the vulnerable operating system environment and placed into a dedicated secure zone. This extraction removes the security vulnerability from the payment processing path while preserving the operating system's other functions.
2Reliability
If physical credit cards are used for transactions, then payment information can be stored securely, but consumers must keep and manipulate physical cards which reduces flexibility
Solution Approach 1:
The system creates a digital copy of the payment card functionality within the secure zone, eliminating the need for physical card manipulation. The secure processor handles authentication and transaction processing digitally, providing the same security as physical cards with enhanced convenience and flexibility.
Solution Approach 2:
The mechanical system of physical card handling is replaced with an electronic/digital system. The secure processor performs cryptographic operations and authentication functions that previously required physical card presence, enabling contactless and more flexible transactions while maintaining security.
3Reliability
If a secure zone is implemented to protect against software attacks, then security is improved, but device complexity increases
Solution Approach 1:
The secure processor and cryptographic engine are merged into an integrated secure zone module that can be incorporated into existing electronic devices. This consolidation provides comprehensive security functions (encryption, authentication, key management) in a unified component, minimizing the increase in device complexity.
Solution Approach 2:
The secure zone is designed with multi-functionality, serving as a universal security platform that can protect various types of sensitive data and operations beyond just payment transactions. This includes authentication, digital signatures, and protection of other confidential information, amortizing the complexity overhead across multiple security functions.
Data Source
AI summary
The systems, methods and apparatuses described herein provide a virtual integrated circuit card (ICC). In one aspect, a method of creating a virtual ICC may be provided. The method may comprise obtaining executable code configured to run on a user device to facilitate financial transactions, preparing a first encryption key usable by the executable code, receiving a second encryption key associated with the user device, forming a virtual ICC comprising the executable code and the first encryption key, and encrypting the virtual ICC with the second encryption key. In another aspect, a virtual ICC may be embodied on a non-transitory computer-readable medium. The virtual ICC may comprise executable code configured to run on a user device to facilitate financial transactions and a first encryption key usable by the executable code. The virtual ICC may be encrypted using a second encryption key associated with the user device.


