System and method of multiple closed-loop secured transaction
The present invention relates to a system and a method for performing a closed-loop secured transactions using NFC. The method comprises of receiving a payment selection comprising of instrument selection at a secure element of a first user device. The instrument selection is used to automatically select the closed-loop kernel. The invention further encompasses using symmetric key encryption for the payment selection data which can only be decrypted inside the HSM for quick and hassle-free peer to peer (P2P) or peer to merchant (P2M) closed-loop transactions.
1 . A method for performing a closed-loop transaction, comprising:
receiving a payment selection for at least one service at a secure element of a first user device, the payment selection comprising at least one of payment information, a service token, an instrument selection, or a service identifier for the at least one service;
transmitting, from the first user device, via a wireless interface, first data to a second user device, the first data comprising at least an encrypted payment selection, wherein the first data is transmitted in response to a Near Field Communication (NFC) tap between the first user device and the second user device, and wherein transmitting the first data to the second user device further comprises:
generating a session key for the payment selection received at the secure element of the first user device; and
encrypting the payment selection based on the generated session key and a message authentication code; and
wherein a symmetric session key for the first data is generated at a secure element of the second user device,
wherein the first data is processed at the second user device to generate second data by encrypting the first data based on the symmetric session key, a second user device identifier, the message authentication code, or the payment information to generate second data;
transmitting, by the second user device, the second data to a payment server;
wherein the payment server comprises a hardware security module (HSM) configured to decrypt the second data based on the message authentication code, and to route the decrypted second data to at least one closed-loop service provider selected based on the instrument selection included in the payment selection,
wherein the at least one closed-loop service provider is onboarded at the secure element of the first user device and the second user device respectively, wherein the secure element of the first user device is configured to automatically select a closed-loop kernel for transaction processing based on the instrument selected by the user, and
wherein a closed-loop transaction is performed by the at least one closed-loop service provider based on the decrypted second data.
2 . The method as claimed in claim 1 , further comprising:
receiving a status of the closed-loop transaction from the at least one closed-loop service provider at least at one of the first user device and the second user device; and
displaying the status of the closed-loop transaction on at least one of the first user device and the second user device.
3 . The method as claimed in claim 1 , wherein the second user device is a merchant user device, and wherein the second user device transmits the second data to a merchant payment server.
4 . A system for performing a closed-loop transaction, the system comprising:
a first user device configured to:
receive a payment selection for at least one service at a secure element of the first user device, the payment selection comprises at least one of payment information, a service token, an instrument selection, and a service identifier for the at least one service, and
transmit first data to a second user device via a wireless interface, wherein the first data is transmitted in response to a Near Field Communication (NFC) tap between the first user device and the second user device,
wherein the first data comprises at least an encrypted payment selection, and wherein the first user device is configured to:
generate a session key for the payment selection received at the secure element of the first user device, and
encrypt the payment selection based on the generated session key and a message authentication code;
wherein the first user device is further configured to enable the second user device to:
generate a symmetric session key for the first data received at a secure element of the second user device,
process the first data to generate second data by encrypting the first data based on the symmetric session key, a second user device identifier, the message authentication code, and the payment information to generate second data, and
transmit the second data to a payment server;
wherein the payment server comprises a hardware security module (HSM) configured to decrypt the second data based on the message authentication code, and to route the decrypted second data to at least one closed-loop service provider selected based on the instrument selection included in the payment selection, wherein the at least one closed-loop service provider is onboarded at the secure element of the first user device and the second user device respectively, wherein the secure element of the first user device is configured to automatically select a closed-loop kernel for transaction processing based on the instrument selected by the user; and
wherein the at least one closed-loop service provider performs a closed-loop transaction based on the decrypted second data.
5 . The system as claimed in claim 4 , wherein the first user device and the second user device are further configured to:
receive a status of the closed-loop transaction from the at least one closed-loop service provider, and
display the status of the closed-loop transaction.
6 . The system as claimed in claim 4 , wherein the second user device is a merchant user device, and wherein the second user device transmits the second data to a merchant payment server.