Apparatus, system and method for secure operation management module for payment terminal

By designing a secure operation management (SOM) module in the payment terminal, using security pads, embedded safety nets and freeze-thaw mode, the problem of payment terminals being vulnerable to physical attacks is solved, and effective protection of sensitive data is achieved.

CN120239868APending Publication Date: 2025-07-01JABIL INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380080105.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-11-18
Filing Date
2023-11-17
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

Existing payment terminals are vulnerable to physical attacks, and attackers can read sensitive data, such as credit card numbers and PIN codes, resulting in data security being compromised.

Method used

A safety operation management (SOM) module is designed, including a motherboard, a top board and a middle board, with a safety pad and multiple connectors on the motherboard, a battery and auxiliary processing components on the top board, and an embedded safety net is provided through the middle board to prevent physical penetration.

Benefits of technology

Through freeze-thaw mode and embedded security network, we can effectively prevent physical attacks, protect sensitive data in payment terminals, ensure data security and physical protection of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120239868A_ABST
    Figure CN120239868A_ABST
Patent Text Reader

Abstract

Apparatus, systems, and methods are provided for a secure operation management (SOM) module for a payment system. Comprising a main board having a main processing component of the SOM module and having a first security feature for preventing physical penetration of an object to the main processing component; a top plate having, on a presentation face facing the first face, at least an auxiliary processing component and a battery of the SOM module for electrical connection to the main processing component, and having a second security feature; and an intermediate plate providing a channel between the main plate and the top plate to allow electrical connection of the main processing component with the battery and the auxiliary processing component, and including a third security feature for preventing physical penetration into the channel.
Need to check novelty before this filing date? Find Prior Art

Description

Cross - Reference to Related Applications

[0001] This disclosure claims the benefit of U.S. Patent Application No. 63 / 426,668, filed on November 18, 2022, the disclosure of which is incorporated herein by reference in its entirety. BACKGROUND OF THE INVENTION FIELD OF THE INVENTION

[0002] The present invention relates to a payment terminal, and more particularly to a security operation management module for a payment terminal. Background of the Invention

[0003] Points of sale are typically poorly protected against physical attacks. As a result, these points of sale often become targets for data hackers using such physical attacks.

[0004] An attacker can access sensitive data, such as credit card numbers and PINs, which are temporarily stored on and transmitted through the point of sale to prevent data loss in the event of a payment process interruption. The attacker can read this data by obtaining physical access to the secure data path (e.g., using a probe or a microdrill).

[0005] Accordingly, additional security measures are needed to protect the secure data paths in contactless and contact payment terminals. SUMMARY OF THE INVENTION

[0006] The disclosed exemplary apparatus, system, and method provide a Secure Operations Management (SOM) module for a payment system terminal. The SOM may include a main board having on its first face a main processing component of the SOM module and on a face opposite the first face a plurality of connectors arranged in a large grid array (LGA), the LGA further including a security pad at a central portion of the opposite face, the security pad preventing physical penetration of an object from the opposite face to the first face; a top board having on a presenting face facing the first face at least an auxiliary processing component of the SOM module and a battery, wherein at least some of the battery and the auxiliary processing components are electrically connected to the main processing component to provide power to the main processing component at least sometimes, and the top board having an outer top face including a securecap at least partially covering the battery, the securecap preventing physical penetration of an object from the securecap to the presenting face; and an intermediate board between the main board and the top board, the intermediate board providing a passthrough to allow electrical connection of the main processing component and the battery and the auxiliary processing components, and the intermediate board including at least one embedded security mesh for preventing physical penetration of an object through the intermediate board into the passthrough.

[0007] The main processing component included on the main board may execute various operation modes. One such mode may be a freeze-unfreeze mode. In this mode, the unfreeze operation is performed in a controlled environment, for example to restrict access to sensitive information. The freeze / thaw process includes the steps of: receiving a read of a unique serial number SN of the SOM module; sending an authenticated command containing a unique symmetric key derived from a symmetric master key using the unique SN; encrypting a first code using the unique symmetric key; storing the first code in a secure random access memory (RAM) and storing the encrypted first code in an internal flash memory; and resetting the secure RAM when the battery is physically disconnected, thereby deactivating the SOM module.

[0008] Once the battery is reconnected, the steps performed by the processor include: receiving a re - read of the SN; based on the re - read of the SN, re - sending the authenticated command including the symmetric key; decrypting the encrypted first code from the internal flash memory; and restoring the decrypted encrypted first code to the secure RAM, thereby re - activating the SOM module for deployment. It should be noted that the SOM can use a similar process to protect the symmetric key at any point during the process where there is secret information to be protected. Thus, if the public key of the freeze / thaw tool is kept in the SOM firmware, the authentication command can occur at any time.

[0009] Accordingly, the present disclosure provides a secure operation management module for a payment terminal and / or a point of sale. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] The disclosure provided herein describes and includes drawings, where like reference numerals may represent like elements, and where:

[0011] Figure 1 An exemplary payment terminal is shown;

[0012] Figure 2 is a software architecture diagram;

[0013] Figure 3 An exemplary component assembly is shown;

[0014] Figures 4A - 4D An exemplary board stack in an embodiment is shown;

[0015] Figures 5A - 5D An exemplary board stack in an embodiment is shown; and

[0016] Figure 6 is a flowchart showing an exemplary process in an embodiment. DETAILED DESCRIPTION

[0017] The drawings and description provided herein may have been simplified to illustrate aspects relevant to a clear understanding of the devices, systems, and methods described herein, while eliminating other aspects that may be present in typical similar devices, systems, and methods for the sake of clarity. Thus, those skilled in the art may recognize that other elements and / or operations may be desirable and / or necessary for implementing the devices, systems, and methods described herein. However, because such elements and operations are well - known in the art and because they do not facilitate a better understanding of the present disclosure, no discussion of such elements and operations is provided here. However, the present disclosure is considered to inherently include all such elements, variations, and modifications of the described aspects that would be known to a person of ordinary skill in the art.

[0018] Descriptions are provided throughout the specification to make the present disclosure thorough and complete and to fully convey the scope of the disclosed embodiments to those skilled in the art. Numerous specific details are set forth, such as examples of specific components, devices, and methods, to provide a thorough understanding of the embodiments of the present disclosure. However, it will be apparent to those skilled in the art that some of the specific disclosed details need not be employed, and the embodiments may be implemented in different forms. Accordingly, the described embodiments are exemplary in nature and should not be construed as limiting the scope of the present disclosure.

[0019] The terms used herein are for the purpose of describing particular exemplary embodiments only and are not intended to be limiting. For example, as used herein, the singular forms "a", "an", and "the" may also be intended to include the plural forms, unless the context clearly indicates otherwise. The terms "comprising", "including", "containing", and "having" are inclusive and thus specify the presence of the stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. Method steps, processes, and operations described herein should not be construed as necessarily requiring them to be performed in the particular order discussed or illustrated, unless explicitly identified as an order of performance. It should also be understood that additional or alternative steps may be employed.

[0020] When an element or layer is referred to as being "on", "engaged to", "connected to", or "coupled to" another element or layer, it can be directly on, engaged directly to, connected directly to, or coupled directly to the other element or layer, or intervening elements or layers may be present. In contrast, when an element is referred to as being "directly on", "directly engaged to", "directly connected to", or "directly coupled to" another element or layer, intervening elements or layers may not be present. Other words used to describe the relationship between elements should be interpreted in a like manner (e.g., "between" relative to "directly between", "adjacent" relative to "directly adjacent", etc.). As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items.

[0021] Although the terms first, second, third, etc. may be used herein to describe various elements, components, regions, layers, and / or sections, these elements, components, regions, layers, and / or sections should not be limited by these terms. These terms are only used to distinguish one element, component, region, layer, or section from another. That is, unless the context clearly indicates otherwise, terms such as "first", "second", and other numerical terms do not imply an order or sequence when used herein. Thus, without departing from the teachings of the exemplary embodiments, the first element, component, region, layer, or section discussed below may be referred to as the second element, component, region, layer, or section.

[0022] Processor-implemented modules and systems are disclosed herein that can provide access to and conversion of multiple types of digital content (including but not limited to schedules and data streams), and the algorithms applied herein can track, deliver, manipulate, transform, transmit and receive, and report the accessed content. The embodiments of these modules, applications, systems, and methods are intended to be exemplary and not restrictive.

[0023] As a non-limiting example, an exemplary computing processing system for use in conjunction with the embodiments is capable of executing software, such as an operating system (OS), an application / app, a user interface, and / or one or more other computing algorithms, such as the algorithms, decisions, models, programs, and subroutines discussed herein. The operation of the exemplary processing system is mainly controlled by non-transitory computer-readable instructions / code, such as instructions stored in a computer-readable storage medium such as a hard disk drive (HDD), an optical disc, a solid-state drive, random access memory (RAM), flash memory, etc. These instructions can be executed within a central processing unit (CPU) to cause the system to perform the disclosed operations. In many known computer servers, workstations, mobile devices, personal computers, etc., the CPU is implemented in an integrated circuit referred to as a processor.

[0024] It should be understood that although the exemplary processing system may include a single CPU, such a description is merely illustrative since the processing system may include multiple CPUs. Thus, the disclosed system may utilize the resources of a remote CPU via a communication network or some other data communication means.

[0025] In operation, the CPU obtains, decodes, and executes instructions from the computer-readable storage medium. Information such as computer instructions and other computer-readable data is transmitted between the components of the computing system via the system's main data transmission path.

[0026] In addition, the processing system may include a peripheral communication controller and a bus, which are responsible for transmitting instructions from the CPU to peripheral devices and / or receiving data from peripheral devices, as discussed throughout this document. An example of a peripheral bus is the Peripheral Component Interconnect bus well known in the relevant art.

[0027] For example, in response to operations of the foregoing computing programs / applications, an operator display / graphical user interface (GUI) may be used to display visual outputs generated by the processing system or generated in response to requests from the processing system and / or to present data. Such visual outputs may include, for example, text, graphics, animated graphics, and / or video.

[0028] In addition, the processing system may include a network adapter, which may be used to couple to an external communication network, which may include or provide access to the Internet, an intranet, an extranet, etc. The communication network may provide access to the processing system in a manner that electronically communicates and transfers software and information. The network adapter may communicate with the network using any available wired or wireless technology. As a non-limiting example, such technologies may include cellular, Wi-Fi, Bluetooth, or infrared, etc.

[0029] The disclosed embodiments include a SOM (Secure Operations Management) module for payment components in a PCI (Payment Card Industry) payment system, such as may include EMV (Europay, Visa, MC), Apple Pay, Google Pay, PTS (PIN Transaction Security), and other similar contactless payments. The disclosed SOM is preferably a hardware, firmware, and software module that meets relevant PCI and DSS (Data Security Standard).

[0030] The disclosed SOM module may be used, for example, as the physical security core module of an EFTPOS (Electronic Funds Transfer at Point of Sale) (also referred to herein as a payment terminal) at a POI (Point of Interaction) (e.g., a retail POI). Together with the SOM, the EFTPOS may not only embed contactless payment hardware, software, and firmware, but may additionally embed contact payment hardware, software, and firmware, such as a keyboard for information such as PIN input from a payer.

[0031] The SOM module may be particularly associated with the disclosed printed circuit board (PCB) design as an aspect of an entire contactless-contact payment terminal and system. Thus, all authentication and security for such a payment terminal system may preferably be embedded in the SOM. The disclosed SOM module / component may form part of a known payment terminal, such as Figure 1 shown in the cross-sectional view.

[0032] As shown in the figure, the payment terminal 5 may include contact type 10 and non-contact type 12 reading hardware and firmware, computing features 14, and a SOM module 20. The SOM may include all components of such a payment terminal that require physical security, and those elements providing logical security may also be fully or partially embedded in the components of the SOM.

[0033] In this way, the SOM module enables self-authentication and / or minimal authentication in order to add secure EMV / payment capabilities to any payment system. Such systems include contactless or contactless payments without PIN entry, contactless or contactless payments with PIN entry, or any other CVM (Cardholder Verification Method).

[0034] The SOM module 20 may encapsulate the EMVCo L1 / L2, PCI PTS-certified security stack. Level 1 (contactless / contactless) authentication is the responsibility of the device hardware vendor, and level 2 (contactless / contactless) authentication is the responsibility of the device software vendor of the software within the SOM. Similarly, the disclosed SOM meets the authentication standards of PCI PTS as cited throughout.

[0035] The security stack(s) may operate on a known secure microcontroller unit (MCU), which is also referred to as a processor herein. The software architecture may also provide support for any of a variety of known payment schemes and may enable modification when new payment schemes emerge.

[0036] The SOM module is smoothly integrated with the necessary systems for contactless and contactless payments. For example, the integrated elements include: a communication interface for an external system controller; a peripheral interface for supporting wireless communication, such as cellular, wifi, Bluetooth, BLE, etc.; resources for supporting L3 integration; power delivery to the SOM; and partial or fully embedded software control.

[0037] Figure 2 The software architecture 100 of the SOM module 20 in an exemplary embodiment is shown. This architecture may be executed in accordance with ISO 14443A / B in combination with NFC (Near Field Communication), such as for contactless payments in accordance with EMVCo 3.1 and EMVCo L1 / L2.

[0038] Payment schemes supported by the architecture can include, but are not limited to: Contactless Visa; Contactless MasterCard; Contactless American Express (ExpressPay); Contactless Discover (D-PAS); Contactless JCB; ChinaPay; and Interac (Canada). Thus, at the POI, for example, with v6.x support (as of 6.1 in March 2022), contactless and contactless payments are supported via PCI and PTS in these various schemes.

[0039] Support can be provided for stack customization and flexible peripheral and protocol integration. This flexible integration (e.g., host control, L3 integration) is achieved through the application performance developed using the SDK (Software Development Kit). By way of non-limiting example, the above is provided in conjunction with a microcontroller-centric operating system such as RTOS, AZURE, or FreeRTOS.

[0040] The foregoing architecture can be provided as illustrated, having an insecure / untrusted architecture region 110 and a secure / trusted architecture region 112. The untrusted region contains features associated with the payment terminal hardware. For example, included in the untrusted region is the OS114 discussed above, as well as communication hardware / peripherals 116 and a hardware coordinator (HAL) 118. Also in the untrusted region is the firmware 120 associated with the payment terminal.

[0041] Additionally, in the untrusted region are those features corresponding to the above SDK 122 and, more specifically, for the interaction between the terminal and the API. The SDK can include features for interacting with data and device management (MDM) via the API, as well as features for contactless transactions, PCI operations, and pin entry (PED) transaction operations.

[0042] The trusted region then contains the various APIs for implementing the disclosed embodiments. More specifically, it includes an API 130 for PCI PED, an API 132 for encryption (Crypto), an API 134 for contactless L1 / L2 payments, and an API for PCI SRED.

[0043] Figure 3An exemplary complete SOM component assembly 20 is shown, which may include a plurality of secure PCBs. In this illustration, a security controller 150 may be provided, as discussed further below. For example, a security controller STM32U5 may be used, which may be embedded with a 160 MHz Cortex-M33. As part of a payment terminal package, a contactless reader, such as ST25R3917B / ST25R3916B, may also be provided.

[0044] The SOM may have any chip-to-board interface, such as an LGA interface or a standard interface. The chip package may address tamper signals for the keypad (such as using a mechanical keyboard or a touchscreen); may include interfaces such as for UART, USB, and SPI; and may include communication modules (e.g., cellular, wifi / ble, ble), a wiremesh (the SOM may generate a tamper signal that enables the wiremesh outside the SOM to protect a contactless smart card reader), LEDs, buzzers, and debug signaling; an NFC reader / coil; and may be within a secure housing.

[0045] For example, a security operation management (SOM) module used in a payment system terminal may include three PCBs 202, 204, 206. The first may be a main board 202, which has the main processing components of the SOM module on a first side, such as the aforementioned security controller 150 and memory 220, as well as a path 222 for secure data, and a contactless controller. On the opposite side, the main board may have a plurality of connectors arranged in a large grid array (LGA) 230. In addition to connectivity, the LGA may provide security 232 to prevent an attacker from physically penetrating to the first side.

[0046] The second top board 204 may include and / or integrate a battery 240 and auxiliary processing components 242. The battery and some of the auxiliary processing components are electrically connected to the main processing components. The battery may also enable a secure transfer between the manufacturing of the SOM and the integration of the SOM into a product. On the side opposite to the auxiliary processing components, the top board may include a safety cap 244 to prevent an attacker from physically penetrating to the battery and the auxiliary processing components.

[0047] The intermediate board 206 between the main board and the top board may provide a passage 250 to allow electrical connection between the main processing components, the battery, and the auxiliary processing components. The intermediate board may also include security features 252, such as an embedded security net, to prevent / deter an attacker from physically penetrating into the passage.

[0048] Figures 4A - 4DFigures 5A - 5D illustrate a specific exemplary SOM component assembly 20, which includes a physical security enclosure for key components configured by the above - mentioned three PCBs 202, 204, 206. The SOM module 20 can be of any of a variety of sizes or shapes and can be miniaturized. As a non - limiting example, such as being approximately 24 mm × 24 mm and having a thickness of approximately 2.5 mm, and can include multiple PCBs or similar components. Additionally, for example, the use of wafer - level chip - scale packaging (WLCSP) can further achieve the above - mentioned miniaturization.

[0049] The multiple PCBs can include a main PCB 202, for example, having an LGA 230 to allow for high - density connection. The underside of the main PCB can be as Figure 4D shown and can include any connection pattern, such as the LGA pattern with the aforementioned connection pad assignment, where some pads provide connections while some pads serve as "security pads" 232, especially in the middle of the PCB where physical security attacks are most likely. As used herein, pads can include shapes such as circular, rectangular, spherical, or hemispherical, etc., and can be or not be substantially uniform.

[0050] A supporting / protective intermediate PCB is also shown. The size and shape of the intermediate PCB can be designed to allow for connections between components on the top and bottom PCBs in the pathway and to provide physical security for interface components on the top and bottom PCBs. Thus, a fully secure physical enclosure is provided between the security components on the top side of the top PCB, the bottom side of the bottom PCB, and the sides provided by the intermediate PCB to protect the components of the SOM module from attacks.

[0051] The SOM component can thus include multiple (e.g., three) PCBs in a micro - stacked assembly, for example, providing significant physical security. That is, the components and structure of the disclosed SOM module prevent tampering with security signals or similar malicious access. For example, the above - mentioned two PCBs loading components can be located at the top and bottom of the assembly, and between these two PCBs and the intermediate board, support and physical security can be provided through a combination of security pads, safety caps, wires, and other security nets, plastic moldings, and similar physical security measures, which will be obvious to those skilled in the art based on the disclosure herein.

[0052] As a non - limiting example, the bottom PCB can include some or all of the components of the SOM and physical security protection. The physical security protection can be in the form of security pads, safety caps or covers, plastic (non - conductive) moldings, wiremesh, vias - mesh, or similar suitable substances or elements capable of preventing / deterring physical security attacks from below the SOM.

[0053] As described above, the top PCB may include auxiliary components, or supports for components of the bottom PCB, specifically, such as batteries, such as button batteries, printed batteries, and / or backup button batteries or printed batteries. When a printed battery is provided, the battery structure can be used to prevent / deter drilling attacks, for example, by including a protective grid pattern to prevent / deter drilling attacks.

[0054] A portion of the top PCB may also be a board-to-board (B2B) connector 500, and in place of or in addition to the security features of the battery itself, can be a security protection to prevent / deter attacks from the top of the SOM module, such as a multi-layer grid embedded in the top PCB, such as a wire grid or via grid. As mentioned, alternatively or also included is a protective cover on the top of the SOM, and the cover can be formed of plastic or a similar hard-to-penetrate material. The B2B connector can manage the top / bottom PCB removal detection discussed here (including detection regarding the freeze-thaw feature), as well as the wire grid transmission and inter-component communication between the bottom PCB and the top PCB.

[0055] The third or central / intermediate PCB can be soldered, epoxy-cured, or otherwise attached to the bottom PCB, the top PCB, or both. As an example, the side protection PCB can, but does not have to, include one or more layers of wire grids or grid patterns created by vias to provide side protection for the components of the top and bottom PCBs as mentioned herein.

[0056] The SOM module can additionally include pins and contact organizations to avoid tampering and enhance security. For example, tamper signal pins for switches and wire grids, such as those used when the SOM module is associated with a secure keyboard and / or a secure contactless smart card reader, can preferably be located at the center of the square formed by the aforementioned LGA. Thus, these pins are extremely difficult for an intended attacker to reach.

[0057] The disclosed SOM is preferably manufactured using approved / certified PCI / PTS hardware, firmware, and software. Additionally, a battery / backup battery can be added to one of the PCBs of the SOM before the SOM enters any secure manufacturing area.

[0058] Once in the secure area, firmware and any security / security / encryption information (such as key loading, key signing, and / or freeze / thaw information as described herein) can be injected into the SOM. The tamper-proofing and tamper-evidencing seals (when present) of the SOM can be activated to leave the secure manufacturing area to protect the SOM during shipment.

[0059] From the perspective of PCI / PTS, the customer receives the active SOM. At the customer's site, the SOM is placed in a frozen mode, for example, frozen using a Freeze Secure Tool / Key. The battery of the SOM can be removed to solder the SOM to the proprietary / product / customer PCB. If the battery is printed on the top PCB, the top PCB can be removed.

[0060] The SOM can be soldered or otherwise connected to the product PCB. The battery or the top PCB with the printed battery can be returned to the SOM. Then, the SOM can be thawed using an Unfreeze Secure Tool / Key.

[0061] After thawing, from the perspective of PCI / PTS, the product is active again. Then, the product can be shipped to the merchant, still protected by anti-tampering and leaving evidence of tampering. Once on-site with the merchant, remote key injection can be performed based on the initially loaded security information. It is worth noting that in some cases, key injection can also be performed before shipping to the merchant.

[0062] The freeze-thaw process can be executed by the main processing component (such as may include a security controller) discussed herein. More particularly, the main processing component can execute non-transitory computing code stored in an associated computing memory for providing freeze-thaw modes and various different operating modes.

[0063] Specifically for the freeze-thaw process, and as shown in the flowchart regarding Figure 6 the processor can receive a read of the unique serial number (SN) of the SOM module; can send an authenticated command including a unique symmetric key derived from the symmetric master key using the unique SN; can encrypt a first code using the unique symmetric key; can store the first code in a secure random access memory (RAM) and store the encrypted first code in the internal flash memory; and can reset the secure RAM when the battery is physically disconnected, thereby deactivating the SOM module during the manufacturing process, for example, in a secure area as described herein.

[0064] Then, once the battery is reconnected, the processor can receive a re-read of the SN; can re-send the authenticated command including the symmetric key based on the re-read of the SN; can decrypt the encrypted first code from the internal flash memory; and can restore the decrypted encrypted first code to the secure RAM, thereby reactivating the SOM module for deployment.

[0065] In a more specific embodiment of the freezing process, the freeze security tool receives the unique serial number (SN) of the SOM, for example, by reading. Then, the freeze security tool sends an authenticated command to the SOM, and the authenticated command provides a unique symmetric key derived from the symmetric freeze master key using the unique SN of the SOM, that is, the freeze key (FreezeKEY). Thus, a key pair is used.

[0066] The SOM encrypts its KPRIV (private key) using the FreezeKEY, and the KPRIV is associated with the KPUB (public key) allocated in the secure area. It is worth noting that the SOM can similarly encrypt any confidential information to be saved. The encrypted KPRIV is stored in the internal flash memory of the SOM, and the plaintext KPRIV is stored in the secure RAM of the SOM. The SOM is capable of encrypting any security / encryption key stored in its secure RAM. In addition, the removal of the battery / backup battery can erase or otherwise reset the secure RAM of the SOM.

[0067] In a more specific embodiment of the thawing process, the SOM battery backup is restored. The thawing security tool reads the unique serial number of the SOM and sends an authenticated command providing the unique symmetric FreezeKEY. Then the SOM decrypts the KPRIV from the flash memory and restores it to the secure RAM (the KPUB allocated in the secure area is still stored in the flash memory because it has never been erased). The SOM can also decrypt all other keys and restore them to the secure RAM of the SOM. Then the SOM components are active in the customer product and can be deployed.

[0068] As mentioned, the disclosed SOM meets the PCI PTS certification when used as a contactless reader. Therefore, a customer integrating the disclosed SOM into their product does not need to implement separate security features and achieve PCI PTS certification, because the customer product can simply adopt the PCI / PTS certification of the integrated SOM.

[0069] Similarly, if a customer integrates the SOM into a product including a secure keyboard and a secure contact smart card reader, the customer can utilize the PCI PTS security features of the SOM. This reuse of the PCI PTS certification of the SOM not only greatly simplifies the PCI / PTS certification of the payment terminal incorporating the SOM, but also will significantly reduce the PCI PTS certification time of the final product, for example, by up to or more than half.

[0070] In the above detailed description, for the sake of brevity of the present disclosure, various features may be combined together in various embodiments. This method of disclosure should not be construed as reflecting an intention that any subsequently claimed embodiment requires more features than those explicitly recited.

[0071] In addition, the present disclosure is provided to enable any person skilled in the art to make or use the disclosed embodiments. Various modifications to the invention will be readily apparent to those skilled in the art, and the general principles defined herein can be applied to other variations without departing from the spirit or scope of the invention. Thus, the present disclosure is not intended to be limited to the descriptions and designs set forth herein, but is to be accorded the widest scope consistent with the principles and novel features as claimed in the following claims.

Claims

1. A security operation management (SOM) module for a payment system terminal, comprising: A main board having, on its first surface, the main processing component of the SOM module, and on the surface opposite the first surface, a plurality of connectors arranged in a large grid array (LGA), the LGA further including a security pad at the central portion of the opposite surface, the security pad preventing physical penetration of an object from the opposite surface to the first surface; A top board having, on its presentation surface facing the first surface, at least the auxiliary processing component and the battery of the SOM module, wherein at least some of the battery and the auxiliary processing components are electrically connected to the main processing component to provide power to the main processing component at least sometimes, and the top board has an outer top surface including a safety cap at least partially covering the battery, the safety cap preventing physical penetration of an object from the safety cap to the presentation surface; And An intermediate board between the main board and the top board, the intermediate board providing a path to allow electrical connection between the main processing component and the battery and the auxiliary processing components, and the intermediate board includes at least one embedded security net for preventing physical penetration of an object through the intermediate board into the path.

2. The module according to claim 1, wherein each of the top board, the main board, and the intermediate board is 24 mm × 24 mm.

3. The module according to claim 1, wherein the main processing component includes a wafer-level chip scale package.

4. The module according to claim 1, wherein the main processing component includes a secure data path.

5. The module according to claim 4, wherein The prevented physical penetration is to the interface of the secure data path.

6. The module according to claim 1, wherein The safety cap includes a plastic molded part.

7. The module according to claim 1, wherein, The safety cap includes a security net.

8. The module according to claim 7, wherein the security net includes one of a through-hole net and a wire net.

9. The module according to claim 1, wherein The embedded security net includes one of a through-hole net and a wire net.

10. The module according to claim 1, wherein the battery is a button battery.

11. The module according to claim 1, wherein the battery is a printed battery.

12. The module according to claim 11, wherein the printed battery includes a printed protection net.

13. The module according to claim 1, wherein, The intermediate board is welded or cured with epoxy resin to at least one of the top board and the main board.

14. A security operation management SOM module for a payment system, comprising: A main board having, on its first surface, the main processing component of the SOM module, and on the opposite surface, a first security feature for preventing physical penetration of an object from the opposite surface to the first surface; A top board having, on its presentation surface facing the first surface, at least the auxiliary processing component and the battery of the SOM module for electrical connection to the main processing component, and having a second security feature for preventing physical penetration of an object to the presentation surface; An intermediate board that provides a channel between the main board and the top board to allow electrical connection of the main processing component to the battery and the auxiliary processing component, and includes a third security feature for preventing physical penetration of an object into the channel; The main processing component executes non-transitory computing code stored in an associated computing memory to provide a plurality of operating modes including a freeze-thaw mode, the freeze-thaw mode including the steps of: Receiving a read of the unique serial number (SN) of the SOM module; Sending an authenticated command including a unique symmetric key derived from a symmetric master key using the unique SN; Encrypting a first code using the unique symmetric key; Storing the first code in a secure random access memory (RAM) and storing the encrypted first code in an internal flash memory; Resetting the secure RAM once the battery is physically disconnected; and Once the battery is reconnected: Receiving a re-read of the SN; Based on the re-read of the SN, re-sending the authenticated command including the symmetric key; Decrypting the encrypted first code from the internal flash memory; and Restoring the decrypted encrypted first code to the secure RAM, thereby activating the SOM module for deployment.

15. The module according to claim 14, wherein each of the top board, the main board, and the intermediate board is approximately 24 mm × 24 mm.

16. The module according to claim 14, wherein the main processing component includes a secure data path.

17. The module according to claim 16, wherein, The blocked physical penetration is to the interface of the secure data path.

18. The module according to claim 14, wherein, The embedded security net includes one of a via net and a wire net.

19. The module according to claim 14, wherein the battery is a button battery.

20. The module according to claim 14, wherein the battery is a printed battery including a printed protection net.

21. A secure operation management (SOM) module for a payment terminal, comprising: A main board having a main processing component for protecting data on its first surface and a first security feature on the opposite surface for preventing an object from physically penetrating from the opposite surface to the first surface; A top board having at least one battery on a presentation surface facing the first surface for powering the main processing component and having a second security feature for preventing physical penetration of an object into the presentation surface; An intermediate board that provides a channel for electrical connection between the main board and the top board between the main board and the top board and includes a third security feature for preventing physical penetration of an object into the channel; The main processing component executes non-transitory computing code stored in an associated computing memory to provide a plurality of operating modes, the plurality of operating modes including a thaw mode that occurs after the battery is disconnected and when the battery is reconnected, including the steps of: Receiving a read of the serial number (SN) of the SOM module; Sending an authenticated command including a unique symmetric key derived from a symmetric master key using the unique SN before the battery is disconnected; Decrypt a first code encrypted with the unique symmetric key when the battery is disconnected from the internal flash memory; and Restore the decrypted first code to the secure RAM, thereby activating the SOM module for deployment.

22. The module according to claim 21, wherein each of the top plate, the main board, and the intermediate plate is approximately 24 mm × 24 mm.

23. The module according to claim 21, wherein, The embedded security net includes one of a through-hole net and a wire net.

24. The module according to claim 21, wherein the battery is a button battery.

25. The module according to claim 21, wherein the battery is a printed battery including a printed protection net.

26. A secure operation management SOM module for a payment terminal, comprising: A main board having a main processing component for secure data and including security features above, below, and beside the main processing component to prevent physical penetration of the secure data by an object; The main processing component executes non-transitory computing code stored in an associated computing memory to provide a plurality of operation modes, including a thaw mode that occurs after the battery is disconnected and upon reconnection, including the steps of: Receiving a read of the serial number (SN) of the SOM module; Sending an authenticated command including a unique symmetric key derived from a symmetric master key using the unique SN before the battery is disconnected; Decrypting a first code encrypted with the unique symmetric key when the battery is disconnected from the internal flash memory; and Restoring the decrypted first code to the secure RAM, thereby activating the SOM module for deployment.

27. The module according to claim 26, wherein the security feature includes at least one of a through-hole net, a wire net, and a plastic cover.

28. The module according to claim 26, further comprising a battery electrically connectable to the main board for occasionally powering the main processing component, the battery including at least one of the security features.