Virtual Payment Terminal Architecture for Secure Online Banking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for secure digital data transmission over communication networks, particularly in online banking transactions, face challenges in replicating the efficiency and security of physical payment terminals in an e-commerce or m-commerce context, where users are burdened with tedious authentication processes and risk of data interception.

Innovation Solution

A distributed architecture that simulates a physical payment terminal by separating the functionality between a user's personal terminal and a remote server, utilizing a secure memory element like a SIM card for storing EMV data, with a local software interface and a communication module that manages secure access and authentication through standardized protocols, effectively creating a virtual electronic payment terminal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional online banking authentication methods are used, then security against fraudulent use is improved, but user convenience and ease of operation deteriorates due to tedious authentication steps

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a virtual copy of the physical payment terminal environment within the personal terminal. The simulated payment terminal replicates the secure EMV card reading and authentication processes of a physical terminal, allowing users to perform secure banking transactions online without leaving their devices. This copying approach maintains the security protocols of physical terminals while eliminating the need for users to physically visit branches or use complex multi-step authentication procedures.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The personal terminal acts as an intermediary device between the user's physical bank card and the remote banking server. It simulates a payment terminal that can read EMV data from the physical card and transmit it securely to the bank, thereby mediating the authentication process. This intermediary role allows the system to maintain the security of physical card-based authentication while enabling convenient online transactions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If physical payment terminals with EMV card reading are used, then transaction security is improved, but device complexity and portability worsen

Engineering Contradiction:
Improvetransaction securityVSAvoidterminal complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The personal terminal is designed to perform multiple functions: it serves as both a secure storage device for banking credentials and a simulated payment terminal capable of reading EMV cards and communicating with banking servers. By combining these functions in a single portable device, the system eliminates the need for separate physical payment terminals while maintaining transaction security. The personal terminal universally handles authentication, data storage, and communication tasks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If bank data is transmitted over communication networks, then accessibility and ease of operation are improved, but security against data interception deteriorates

Engineering Contradiction:
ImproveaccessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Instead of transmitting actual sensitive banking data over the network, the system transmits a simulated representation of the payment terminal's output. The personal terminal reads the EMV card data locally, processes it through the simulated terminal logic, and transmits only the necessary transaction information to the bank server. This copying approach ensures that sensitive data never leaves the user's device in transmittable form, maintaining security while enabling network accessibility.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2867837B1System for the secure transmission of digital data
Publication Date: 2018.08.08 NEPTING
  • EP2867837B1 patent drawingFigure 1~2
  • EP2867837B1 patent drawingFigure 3

AI summary

The invention relates to a system (1) for the secure transmission of digital data between a server (4) and a personal terminal (3) via a communication network (2), said system comprising said server (4) provided with a module (8) for communication with said terminal (3) and a banking application module (8) that are stored and run on said server (4); and said personal terminal (3) provided with means for connection to said network (2) and to said communication module (8); said terminal (3) also comprising personal payment data (5) stored within a secure memory element (10) and at least one channel (100) for authenticated access to said data (5). It is characterised in that said terminal comprises an interface (7) that is stored and run on said terminal (3), said interface (7) being connected, via said connection means, to the banking application module (9) of said server (4) by means of said communication module (8); and in that said interface (7) consists in a router for access to said data (5) via said secure access channel (100) and for authentication of said banking application module (9).