Virtual Payment Terminal for Secure Mobile Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile payment solutions using communications terminals rely on the 'card not present' mode, which limits transaction possibilities and raises security concerns due to the storage of sensitive data, making them vulnerable to misuse if the device is lost or stolen.
Innovation Solution
A method that creates a secured communications channel between a communications terminal and a transaction-processing server, instantiating a virtual payment terminal to process transactions using a secure element, mimicking the 'card present' mode by exchanging identifiers and data through APDU, ensuring enhanced security and authorization similar to physical card transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If sensitive transaction data is stored within the communications terminal to enable convenient transactions, then transaction convenience is improved, but security is worsened due to vulnerability to device loss or theft
Solution Approach 1:
The patent extracts sensitive transaction data from the communications terminal and stores it externally in a secure database. The terminal only retains minimal identification information (IMSI) to initiate transactions, while actual card data (PAN, CVV, expiry date) is stored remotely. This separation resolves the contradiction by maintaining transaction convenience through local initiation while eliminating security risks of local data storage.
Solution Approach 2:
The patent introduces a secure database and transaction processing server as intermediaries between the communications terminal and the transaction network. The terminal communicates with the server, which in turn accesses the secure database and interacts with the payment network. This intermediary architecture allows the terminal to function conveniently without directly storing sensitive data, resolving the security-convenience contradiction.
2Ease of operation
If all transaction data is stored in the communications terminal to avoid manual re-entry, then ease of operation is improved, but the device becomes a security risk if compromised
Solution Approach 1:
The patent extracts complete transaction data (card number, CVV, expiry date, holder name) from the communications terminal and stores it in an externally secured database. The terminal only stores an identification marker (IMSI) that enables automatic retrieval of full data from the server. This extraction eliminates the security vulnerability of storing sensitive data locally while maintaining the convenience of automatic data availability.
Solution Approach 2:
The patent creates a virtual representation of the payment card data stored in a secure database, accessible via the terminal's identification. Instead of storing actual card data in the terminal, the system maintains a secure copy remotely that can be instantly retrieved. This copying approach preserves data availability for convenient transactions while protecting the actual sensitive information from device compromise.
3Reliability
If a virtual payment terminal is instantiated to process transactions securely, then security is improved through centralized control, but system complexity increases
Solution Approach 1:
The patent implements a universal transaction processing server that handles multiple functions: authentication, data retrieval, secure communication establishment, and transaction routing. This single multi-functional server consolidates what could be multiple separate complex components, achieving enhanced security while managing system complexity through functional integration rather than proliferation of separate systems.
Data Source
AI summary
A method for the processing, by a transaction-processing server, of a transaction at least partially initiated from a communications terminal connectable to the server by using a communications network. This method includes: creating a secured communications channel with the communications terminal; instantiation, within an execution server on the communications network, of a virtual payment terminal capable of exchanging information with the communications terminal by using the secured communications channel; and processing a transaction between the communications terminal and the virtual payment terminal implementing at least one secure element of the communications terminal, the secure element being configured to exchange an identifier of the type of service.


