Landing area tamper line routing in a credit card reader

The credit card reader's asymmetrical landing areas and conductive security mesh with tamper switches improve tamper-resistance, making it harder to penetrate and secure against unauthorized access.

WO2025239880A1PCT designated stage Publication Date: 2025-11-20SUMUP PAYMENTS LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/US2024/029203
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-05-14
Publication Date
2025-11-20

AI Technical Summary

Technical Problem

Existing credit card readers lack sufficient tamper-resistance, making them vulnerable to probe penetration and security breaches.

Method used

The credit card reader incorporates a design with asymmetrical landing areas and a security mesh with closely spaced electrical traces, along with tamper switches made of alternating conductive and non-conductive silicone rubber, to enhance security by making probe attacks more difficult.

Benefits of technology

The design significantly increases the difficulty of tampering by varying electrical resistance based on tamper switch compression and providing a secure electrical connection, thus enhancing the reader's tamper-resistance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2024029203_20112025_PF_FP_ABST
    Figure US2024029203_20112025_PF_FP_ABST
Patent Text Reader

Abstract

Various aspects of the disclosure generally relate to credit card processing readers and related security features. Part of those features include landing pads which may be vulnerable to certain attacks and tamper attempts. Some landing pads are more easily accessed (vulnerable) in a tamper attempt, than others. In one aspect, this disclosure recites a direct electrical connection between landing areas, where one of the landing areas is more accessible and the other is less accessible. This may reduce device vulnerability when both landing areas must be accessed in a tamper attempt.
Need to check novelty before this filing date? Find Prior Art

Description

LANDING AREA TAMPER LINE ROUTING IN A CREDIT CARD READERBACKGROUNDField of the Disclosure

[0001] The disclosure relates generally to credit card processing readers, and more specifically to security measures that increase tamper-resistance and makes probe penetration more challenging.Description of Related Art

[0002] Fundamental to the functioning of the economy is the exchange of payment for goods and services. Throughout modern commercial history, payment has typically been rendered with money in the form of currency or cash such as banknotes and coins. Cash continues to be used to purchase goods and services, but it is becoming increasingly less common. In the United States, a study by Tufts University concluded that the cost of using cash amounts to around $200 billion per year. This is primarily the costs associated with collecting, sorting and transporting the physical currency, but also includes expenses like automated teller machine (ATM) fees. The study also found that the average American wastes five and a half hours per year withdrawing cash from ATMs, which is just one of the many inconvenient aspects of physical currency. Physical currency is often unhealthy too. Researchers in Ohio spot-checked cash used in a supermarket and found 87% contained harmful bacteria.

[0003] Conventional financial transactions are fundamentally based on the value of currency, but often involve the transfer of funds that do not require the physical exchange of cash.

[0004] In the United States, the Federal Reserve Bank's Automated Clearing House (ACH) Network is a processing and delivery system that provides for the distribution and settlement of electronic credits and debits among financial institutions, and functions as an electronic alternative to paper checks. Unlike a check, which is always a debit instrument, an ACH entry may be either a credit or a debit entry. The ACH Network isalso widely used to settle consumer transactions made at ATMs and point-of-sale (POS) terminals.

[0005] Physical currency is already being replaced by cryptocurrencies like Bitcoin.Bitcoin allows for direct transfers of funds between parties, without the need for a third party. A wide range of startups are now developing products based on the Bitcoin protocols, in the hope that it will compete with other global payment systems. Cash transactions worldwide rose just 1.75% between 2008 and 2012, to $11.6 trillion.Meanwhile, non-traditional payment methods rose almost 14% to total $6.4 trillion. This group includes online and mobile payment systems including PayPal, Google Wallet, Apple Passbook, and other cashless alternatives.

[0006] Thrive Analytics 2014 Digital Wallet Usage Study revealed that, despite nearly 80% of consumers being aware of digital wallets, including major players like PayPal, Google Wallet, and Apple Passbook, security concerns remain the main barrier to adoption, followed by lack of usability versus credit cards / cash (37%) and not being top of mind as a form of payment at the time of purchase (32%). Meanwhile, MasterCard and Visa face obstacles as they try to become players in the digital wallet game.

[0007] Other companies produce a point-of-sale credit card reader and app that provides transparent pricing, reliable technology and is available for major credit cards plus Google Pay and Apple Pay. Contrasting this with a traditional credit card terminal, which contains the hardware and software for generating an authorization request, these card readers work in conjunction with online systems to generate that request. Security and ensuring the secrecy of user credit card information is paramount in any credit card reader and strict standards apply to the construction and operation of these POS readers. While meeting security standards, the makers of these readers must design a product that is rugged, reliable and long-living.

[0008] In line with that need for and expectation of security and reliability, a credit card reader is expected to be reliable and secure from tampering and intrusion attacks. What's needed is a credit card processing reader with enhanced security.SUMMARY

[0009] In one aspect, a point-of-sale credit card reader includes a case and a printed circuit board (PCB) coupled to the case. The PCB may have a first side and a second side, with the first and second sides parallel and opposite to one another. At least one via may extend through the PCB from the first side to the second side. A microcontroller may be coupled to the first side of the PCB and may be electrically coupled to the via. The microcontroller may have at least one input / output (I / O) pin within the microcontroller footprint and between the top of the microcontroller and the first side of the PCB. There may be a first pair of landing areas also coupled to the first side of the PCB. The first pair of landing areas may each have a plurality of exposed electrical pads. There may be a first plurality of tamper switches coupled to the first pair of landing areas. There may be a second pair of landing areas coupled to the first side of the PCB, where the second pair of landing areas each have a plurality of exposed electrical pads. There may be a second plurality of tamper switches coupled to the second pair of landing areas. The first pair of landing areas may have a first landing area and a second landing area, wherein an orientation of the first pair of landing areas with respect to the case and the PCB differentiates the first landing area from the second landing area. The second pair of landing areas may have a first landing area and a second landing area wherein the orientation, applied to the second pair of landing areas, differentiates the first landing area and the second landing area. There may be a direct electrical connection between the first landing area of the first pair of landing areas and the second landing area of the second pair of landing areas.

[0010] The point-of-sale credit card reader may include a direct electrical connection between the second landing area of the first pair of landing areas and the first landing area of the second pair of landing areas.

[0011] In the point-of-sale credit card reader, the electrical resistance across the first plurality of tamper switches and the second pair of tamper switches may vary depending on a degree of tamper switch compression.

[0012] In the point-of-sale credit card reader, the tamper switch material may include alternating layers of conductive and non-conductive silicone rubber.

[0013] The point-of-sale credit card reader may include a cover that is coupled to the second side of the PCB. The cover may include a non-conducting base and a security mesh with a plurality of electrical traces as part of an electrical circuit. The plurality of electrical traces of the security mesh may have a spacing between two immediately adjacent traces of no more than 150 micrometers throughout the security mesh. The security mesh may extend over a majority of the cover.

[0014] In the point-of-sale credit card reader, the first landing area of the first pair of landing areas may be coupled to the security mesh of the cover.

[0015] The point-of-sale credit card reader may further include a removable front assembly that may be coupled to the case and may be coupled to the first and second plurality of tamper switches.

[0016] In one aspect, a point-of-sale credit card reader may include a case and a printed circuit board (PCB) that is coupled to the case. The PCB may have a first side and a second side, where the first and second sides are parallel and opposite to one another. At least one via may extend through the PCB from the first side to the second side. There may be a microcontroller that is coupled to the first side of the PCB and is electrically coupled to the via. The microcontroller may have at least one input / output (I / O) pin within the microcontroller footprint, the I / O pin between the top of the microcontroller and the first side of the PCB. There may be a first pair of landing areas coupled to the first side of the PCB, where the first pair of landing areas may each have a plurality of exposed electrical pads. There may be a first plurality of tamper switches that are coupled to the first pair of landing areas. There may be a second pair of landing areas coupled to the first side of the PCB, where the second pair of landing areas each have a plurality of exposed electrical pads. There may be a second plurality of tamper switches that are coupled to the second pair of landing areas. The first pair of landing areas may have a first landing area and a second landing area, wherein the first landing area is further from the case than the second landing area. The second pair of landing areasmay have a first landing area and a second landing area, wherein the first landing area is further from the case than the second landing area. There may be a direct electrical connection between the first landing area of the first pair of landing areas and the second landing area of the second pair of landing areas.

[0017] The point-of-sale credit card reader may include a direct electrical connection between the second landing area of the first pair of landing areas and the first landing area of the second pair of landing areas.

[0018] In the point-of-sale credit card reader the electrical resistance across the first plurality of tamper switches and the second pair of tamper switches may vary depending on a degree of tamper switch compression.

[0019] In the point-of-sale credit card reader the tamper switch material may include alternating layers of conductive and non-conductive silicone rubber.

[0020] The point-of-sale credit card reader may include a cover that is coupled to the second side of the PCB. The cover may include a non-conducting base and a security mesh, including a plurality of electrical traces as part of an electrical circuit. The plurality of electrical traces of the security mesh may have a spacing between two immediately adjacent traces of no more than 150 micrometers throughout the security mesh. The security mesh may extend over a majority of the cover.

[0021] In the point-of-sale credit card reader, the first landing area of the first pair of landing areas may be coupled to the security mesh of the cover.

[0022] The point-of-sale credit card reader may include a removable front assembly that is coupled to the case and is coupled to the first and second plurality of tamper switches.

[0023] In one aspect, a point-of-sale credit card reader may include a case and a printed circuit board (PCB) coupled to the case. The PCB may have a first side and a second side, where the first and second sides are parallel and opposite to one another. There may be at least one via that extends through the PCB from the first side to the second side. The PCB may have a center along the plane of the PCB. There may be a microcontroller coupled to the first side of the PCB that is electrically coupled to the via. The microcontroller may have at least one input / output (I / O) pin within the microcontrollerfootprint and the I / O pin may be between the top of the microcontroller and the first side of the PCB. A first pair of landing areas may be coupled to the first side of the PCB. The first pair of landing areas may each have a plurality of exposed electrical pads with a first plurality of tamper switches that are coupled to the first pair of landing areas. A second pair of landing areas may be coupled to the first side of the PCB. The second pair of landing areas may each have a plurality of exposed electrical pads with a second plurality of tamper switches that are coupled to the second pair of landing areas. The first pair of landing areas may have a first landing area and a second landing area, wherein the first landing area may be closer to the center than the second landing area. The second pair of landing areas may have a first landing area and a second landing area wherein the first landing area may be closer to the center than the second landing area. There may be a direct electrical connection between the first landing area of the first pair of landing areas and the second landing area of the second pair of landing areas.

[0024] The point-of-sale credit card reader may include a direct electrical connection between the second landing area of the first pair of landing areas and the first landing area of the second pair of landing areas.

[0025] In the point-of-sale credit card reader, the electrical resistance across the first plurality of tamper switches and the second pair of tamper switches may vary depending on a degree of tamper switch compression.

[0026] In the point-of-sale credit card reader, the tamper switch material may further include alternating layers of conductive and non-conductive silicone rubber.

[0027] The point-of-sale credit card reader may include a cover that is coupled to the second side of the PCB. The cover may include a non-conducting base and a security mesh that may include a plurality of electrical traces as part of an electrical circuit. The plurality of electrical traces of the security mesh may have a spacing between two immediately adjacent traces of no more than 150 micrometers throughout the security mesh. The security mesh may extend over a majority of the cover.

[0028] In the point-of-sale credit card reader, the first landing area of the first pair of landing areas may be coupled to the security mesh of the cover.

[0029] The point-of-sale credit card reader may include a removable front assembly that is coupled to the case and is coupled to the first and second plurality of tamper switches.

[0030] The foregoing has outlined rather broadly the gestures and technical advantages of examples according to the disclosure in order that the detailed description that follows may be better understood. Additional features and advantages will be described hereinafter. The conception and specific examples disclosed may be readily utilized as a basis for modifying or designing other structures for carrying out the same purposes of this disclosure. Such equivalent constructions do not depart from the scope of the appended claims. Characteristics of the concepts disclosed herein, both their organization and method of operation, together with associated advantages will be better understood from the following description when considered in connection with the accompanying figures. Each of the figures is provided for the purposes of illustration and description, and not as a definition of the limits of the claims.BRIEF DESCRIPTION OF THE DRAWINGS

[0031] So that the above-recited features of the disclosure can be understood in detail, a more particular description, briefly summarized above, may be had by reference to aspects, some of which are illustrated in the appended drawings. It is to be noted, however, that the appended drawings illustrate only certain typical aspects of this disclosure and are therefore not to be considered limiting of its scope, for the description may admit to other equally effective aspects. The same reference numbers in different drawings may identify the same or similar elements.

[0032] FIG. 1 is a top right perspective view illustrating one example of a credit card reader.

[0033] FIG. 2 is an exploded parts diagram illustrating one example of a credit card reader.

[0034] FIG. 3 is a partial exploded parts diagram illustrating one example of a front assembly from a credit card reader.

[0035] FIG. 4 is a partial exploded parts diagram illustrating one example of a secure circuit assembly from a credit card reader.

[0036] FIG. 5 is a partial exploded parts diagram illustrating one example of a rear assembly from a credit card reader.

[0037] FIG. 6 is a clamshell perspective diagram illustrating one example of a front assembly and a printed circuit board from a credit card reader.

[0038] FIG. 7 is a clamshell perspective diagram illustrating one example of a front assembly and a printed circuit board from a credit card reader.

[0039] FIG. 8 is a top-down perspective view illustrating one example of a printed circuit board from a credit card reader.DETAILED DESCRIPTION

[0040] Various aspects of the disclosure are described more fully herein with reference to the accompanying drawings. This disclosure may, however, be embodied in many different forms and should not be construed as limited to any specific structure or function presented throughout this disclosure. Rather, these aspects are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art. Based at least in part on the teachings herein, one skilled in the art should appreciate that the scope of the disclosure is intended to cover any aspect of the disclosure disclosed herein, whether implemented independently of or combined with any other aspect of the disclosure. For example, an apparatus may be implemented, or a method may be practiced using any number of the aspects set forth herein. In addition, the scope of the disclosure is intended to cover such an apparatus or method which is practiced using other structure, functionality, or structure and functionality in addition to or other than the various aspects of the disclosure set forth herein. Any aspect of the disclosure may be embodied by one or more elements of a claim.

[0041] A point-of-sale (POS) credit card reader may physically interact with payment instruments such as magnetic stripe payment cards, Europay, MasterCard and Visa(EMV) payment cards, and short-range communication (e.g., near field communication (NFC), radio frequency identification (RFID), Bluetooth, Bluetooth. RTM. low energy (BLE), etc.) payment instruments. The reader may provide a rich user interface through the display, communicate with the payment reader, and communicate with a payment processing service server, which may communicate with payment processing service provider server(s). In this manner, the reader may collectively process transaction(s) between a merchant and customer(s).

[0042] POS readers may be mobile, such that POS readers may process transactions in disparate locations across the world. For various reasons, a payment processing service provider may contract with a payment processing service regarding where the payment processing service is permitted to collectively process card-present transactions between merchants that utilize POS readers serviced by the payment processing service and customers. As a non-limiting example, a payment processing service provider may contract with a payment processing service such that the payment processing service is permitted to process card-present transactions on behalf of a merchant via a POS reader serviced by the payment processing service in one or more particular regions but is not permitted to process transactions on behalf of the merchant in any region that is not one of the one or more particular regions. For instance, a payment processing service provider may contract with a payment processing service such that the payment processing service is permitted to process card-present transactions on behalf of the merchant in the United States, Canada, and Australia, but is not permitted to process card-present transactions on behalf of the merchant in any other country. That is, if the merchant tries to transact with a customer in China via a card-present transaction using a POS reader serviced by the payment processing service and the payment processing service processes the card-present transaction, the payment processing service may breach its contract with the payment processing service provider. Accordingly, the payment processing service may refrain from processing the card-present transaction (i.e., the payment processing service may not transmit the card-present transaction tothe payment processing service provider) to avoid breaking its contract with the payment processing service provider.

[0043] For the purpose of this disclosure, a card-present transaction is a transaction where both a customer and their payment instrument are physically present at the time of the transaction. Card-present transactions may be processed by swipes, dips, and / or taps. A swipe is a card-present transaction where a customer slides a card having a magnetic strip through a payment reader that captures payment data contained in the magnetic strip. A dip is a card-present transaction where a customer inserts a card having an embedded microchip (i.e., chip) into a payment reader chip-side first. The card remains in the payment reader until the payment reader prompts the customer to remove the card. While the card is in the payment reader, the microchip creates a one-time code which is sent from the POS reader to a server associated with a payment processing service, a bank, and / or a card payment network (e.g., Mastercard, VISA, etc.) to be matched with an identical one-time code. A tap is a card-present transaction where a customer may tap or hover his or her electronic device such as a smart phone running a payment application over a payment reader to complete a transaction via short-range communication (e.g., NFC, RFID, Bluetooth. RTM., BLE, etc.). Short-range communication enables the electronic device to exchange information with the payment reader. A tap may also be called a contactless payment. In some countries, a customer may engage in a tap using a TAP card instead of an electronic device.

[0044] The phrases "in some examples," "according to various examples," "in the examples shown," "in one example," "in other examples," "various examples," "some examples," and the like generally mean the particular feature, structure, or characteristic following the phrase is included as at least one example, and may be included in more than one example without specifically being referred to as such. In addition, such phrases do not necessarily refer to the same examples or to different examples.

[0045] If the specification states a component or feature "may," "can," "could," or "might" be included or have a characteristic, that particular component or feature is not required to be included or have the characteristic.

[0046] The preceding summary is provided for the purposes of summarizing some examples to provide a basic understanding of aspects of the subject matter described herein. Accordingly, the above-described features are merely examples and should not be construed as limiting in any way. Other features, aspects, and advantages of the subject matter described herein will become apparent from the following description of Figures and Claims.

[0047] FIG. 1 illustrates one example of credit card processing reader or device 100 such as a point-of-sale (POS) reader for on-premises credit card payments. Such readers typically meet industry requirements if used for processing Visa, Mastercard, American Express, JCB or Discover payments. The security standards are set by the Payment Card Industry Security Standards Council (PCI SSC), which also sets standards for personal identification number (PIN) transaction security (PTS). One of the security standards set is the Payment Card Industry Data Security Standard (PCI DSS). Other security standards are set by a European subgroup of the Joint Interpretation Library (JI L) working group, called the JILTerminal Evaluation Methodology Subgroup, or JTEMS. The standards serve to protect against fraud and provide for secure entry and transmission of PIN and account data. POS terminals and readers are used in the retail, restaurant, entertainment, healthcare, and service industries, to name a few.

[0048] Reader 100 may be a standalone device, or it may be mounted within or on to a cradle, bracket or other holder (not illustrated) and interface through port 102. Port 102 may be any type of serial or parallel communication port, for example a universal serial bus (USB), or any other type of interface. In one example port 102 may be used to provide power to reader 100. In one example port 102 may be used for communication and power to reader 100. Other communication options for reader 100 are discussed below. On the side of reader 100 that is opposite port 102 is a slot (not visible in FIG. 1) into which a credit card may be inserted and read by a payment reader (not illustrated in FIG. 1). This describes a dip type transaction, but it should be understood that both a tap and a swipe are both included as potential transaction methods with an appropriately configured terminal, for example with near field communications(NFC). An NFC antenna(not shown in FIG. 1) may be located behind, for example, a display and enable interaction with other NFC devices. Display module 103 includes display 104 and pad 105. Display 104 may be any type of emissive or reflective display, or a combination thereof, for example LED, LCD, OLED, MEMS, ELD, QLED, etc. Additionally display 104 may be touch sensitive such that a user may interact with images present on display 104. Such interactions include viewing an amount to be charged to a card, transaction description, entry or selection of amounts for gratuity, signature input, transaction approval, and so on. Pad 105 may be an alternative to a touch sensitive screen, or in addition to a touch sensitive screen. Pad 105 may include number, menu, scroll, approve, decline, reverse, and other interface options with reader 100. Button 106 activates reader 100 and may be used to power down, power up, place reader 100 into a sleep / standby mode or awaken reader 100 from a sleep / standby mode.

[0049] FIG. 2 is an exploded parts diagram illustrating one example of credit card processing reader 100. The illustrated parts are broadly grouped into three groups plus a structural component. The groups are front assembly 202, secure circuit assembly 204 and rear assembly 206. Frame 208 is the structural component. The naming convention with respect to each group is in no way limiting to that group or any other group, for example front assembly 202 may also be a communications assembly that includes more than just communication components, or secure circuit assembly 204 does not mean or imply that other groups are not secure, or that communication functions may also be performed by rear assembly 206, to name a few examples.

[0050] The assembly of reader 100 may be completed by collapsing the parts illustrated in FIG. 2, with front assembly 202 attaching to the topmost section of frame 208 (in the perspective illustrated in FIG. 2), then secure circuit assembly 204 inserting within frame 208 and underneath front assembly 202, with rear assembly inserting within frame 208 and under secure circuit assembly 204. The orientation of reader 100 is the same in FIGS. 1, 2 and 3 (with display module 103 facing the top of the page), but the orientation is reversed in FIGS. 4 and 5 (with display module 103 facing the bottom of the page).

[0051] FIG. 3 is a partial exploded parts diagram illustrating front assembly 202 from FIG. 2 in a top-down orientation, as well as frame 208. front assembly 202 includes display module 103 as previously described with respect to FIG. 1. Also included in front assembly 202 is shield 300 and antennae 304. Shield 300 attenuates electromagnetic impulses between display 104 and antenna 304, as well as secure circuit assembly 204.

[0052] Shield 300 may be useful in reducing losses that occur from metal parts that are on the other side of shield 300 from display 104 (e.g. the PCB, the battery - conductive material that is near shield 300) reducing interference of communications and circuit processing by display 104. Shield 300 may be made from ferrite or other suitable shielding material for short range attenuation, for example NiZn, MnZn, etc. In one aspect shield 300 is an optional component in reader 100.

[0053] Antennae 304 in this example may be a near field communication (NFC) antenna. NFC is based on inductive coupling between two antennas present on NFC-enabled devices, for example a POS credit card processing reader and a credit card. An NFC system can be used for communicating in one or both directions, using a frequency of 13.56 MHz. One practice of providing a small form factor for a POS reader is by placing a communication coil used by the NFC system in close proximity to the readout display of the processing device. Because of the proximity of the coil and display, operating aspects of the display may cause distortion of the waveforms from the NFC system.

[0054] Frame 208 provides structural support and integrity to reader 100 and may be made from injection molded plastic or any other suitable material and manufacturing method. From the perspective shown in FIG. 3, front assembly 202 stack together near the top of frame 208 once in place.

[0055] FIG. 4 is a partial exploded parts diagram illustrating secure circuit assembly 204 from FIG. 2 as well as frame 208 and front assembly 202. FIG. 4 is in a reverse orientation of FIG. 3, such that front assembly 202 is pictured at the bottom of frame 208. Secure circuit assembly 204 includes printed circuit board (PCB) 400, seal tape card connector 408, tamper switches 410, cable 412, cover 414 and screws 416.

[0056] PCB 400 includes connector 418 (accessed through port 102) and seal tape card connector 408 to help reduce shorting issues. Cable 412 carries information between display 104, pad 105, antennae 304 and PCB 400.

[0057] In a POS credit-card processing terminal or reader, secure covers and anti-tamper rubber switches are commonly used to pass penetration tests that verify the resistance of the reader against physical attack methods. Secure covers may have grabbers (also referred to as ribs)(not illustrated in FIG. 4) into which conductive blocks are pressed to form a bridge between electrical pads. In one example, the conductive blocks may be zebra connectors, or tamper switches 410, made from, for example, a conductive rubber, or alternating layers of conductive and non-conductive silicone rubber. Electrical pads (not illustrated in FIG. 4) are respectively connected to electrical traces (not illustrated in FIG. 4) and are located on PCB 400. When cover 414 is tightened onto PCB 400 with screws 416, the resistance of tamper switches 410 changes until it is within a determined range. Once reader 100 is in use, the anti-tamper sub-system (not illustrated in FIG. 4) asserts a pseudo-random digital pulse wave at an output and compares that signal with the signal received at an input. If a sufficient difference is observed between the two, a tamper alarm is triggered. The signal leaving the output pin may be routed through each security-relevant element of the system before being looped back to the input pin. One electrical mechanism by which a tamper attempt (or alert) would be triggered is either the formation of an open circuit between a single input / output pair, or formation of a short circuit between one input / output pair and another, carrying a different signal (or some other signal or voltage, for example ground). In one aspect, if a change in resistance outside a determined range is detected with respect to the circuit connected to tamper switches 410 then reader 100 registers that change as a tamper attempt and reader 100 may be blocked or disabled. Once reader 100 is activated, removing cover 414 may dislodge tamper switches 410 or cause a change in resistance across the electrical contacts and trigger a tamper attempt. Accessing a trace from one of the electrical pads and connecting it to a trace from another electrical pad (creating a short circuit), also causes a change in resistance andmay trigger a tamper attempt. This is one example of security for secure circuit assembly 204.

[0058] In one aspect, security for reader 100 includes tamper switches 410 sandwiched between PCB 400 and front assembly 202. Not illustrated in FIG. 4 are landing areas on each of PCB 400 and front assembly 202, on either side of the sandwiched tamper switches. Each landing area may have exposed electrical pads that contact the tamper switches. The electrical pads may be routed to circuits, a microcontroller or microprocessor, or electrical mesh (components not illustrated in FIG. 4) that is part of security for reader 100, etc. The electrical pads, or landing areas, may be connected to security mesh in cover 414 or other security mesh (for example, in the microcontroller). For a group of landing areas, one of which may be on PCB 400 and one of which may be on front assembly 202, instead of being symmetrical to one another the electrical pads may be asymmetrical. The asymmetry between the electrical pads from PCB 400 exists as compared to the electrical pads from front assembly 202. In one aspect, the electrical pads may be sized differently. In one aspect the electrical pads may have a different exposed surface area. In one aspect, the electrical pads may be shaped differently. In one aspect, the electrical pads may be positioned differently. In one aspect, the electrical pads may have a combination of size, surface area, shape and position that creates asymmetry. In one aspect, landing areas between other components may also have asymmetrical landing areas, for example between cover 414 and PCB 400.

[0059] One form of attack may be bridging the two points on PCB 400 where the tamper signal leaves PCB 400 to enter front assembly 202 and reenters PCB 400 from front assembly 202, respectively. Once such a bridge is made externally (for all involved tamper signals), front assembly 202 could be disconnected from reader 100 and even replaced with a false front assembly. In this example, the conductive material comprising tamper switches 410 is still continuous with the tamper signal coming from PCB 400, despite no longer being sandwiched between two conductive surfaces.

[0060] One form of attack may be a probe inserted into reader 100 and into tamper switch 410. The goal of inserting the probe is to find the signal within the tamper switchand use the probe to bridge the signal between, for example, PCB 400 and front assembly 202 while front assembly 202 is removed from reader 100. This could give an attacker access to the interior of reader 100 without triggering security measures. Using a probe to penetrate tamper switches 410 between PCB 400 and front assembly 202 may be easier than penetrating tamper switches 410 between cover 414 and PCB 400 due to other security measures in cover 414, for example electrical security mesh (not illustrated in FIG. 4). Cover 414 may include a non-conducting base, for example plastic, and a security mesh with electrical traces forming an electrical mesh circuit. In one aspect, the electrical traces may have a spacing between two immediately adjacent traces of no more than 150 micrometers throughout the security mesh. The security mesh may extend over a majority of cover 414. The spacing may be selected to make insertion of a probe through cover 414 difficult without contacting the security mesh. The spacing may be different depending on manufacturing capability of either the security mesh, probes, or other factors. In one aspect, cover 414 may be connected to a side of PCB 400 that is opposite a side of PCB 400 to which a microcontroller (not illustrated in FIG. 4) is connected. Although on opposite sides of PCB 400, the microcontroller, which if it is a security-enabled device, may fall within a "footprint" of PCB 400. From a plan-view or top / bottom view, the microcontroller includes as part of its security measures the mesh of cover 414. Additional mesh may be embedded within the microcontroller, for a security enabled device, for example a security-enabled microcontroller. The circuitry within the microcontroller may therefore be protected on one side by mesh within the cover of the microcontroller and on the other side of PCB 400 by mesh within cover 414.

[0061] With reader 100 fully assembled, an inserted probe may detect a signal through the tamper switch that it penetrated. One goal of inserting the probe is to determine where within the tamper switch the signal is traversing so that the signal may be provided to the landing area on front assembly 202 when front assembly 202 is removed from reader 100. In one aspect, the asymmetry of electrical pads between PCB 400 and front assembly 202 creates a signal with a "footprint" within tamper switch 410 thatdiffers depending on whether front assembly 202 is coupled to PCB 400 or not. Despite seeing the signal with the probe, an attacker may not be certain that the signal will persist when the front assembly 202 is removed. If the signal does not persist then security measures of reader 100 are enacted.

[0062] FIG. 5 is a partial exploded parts diagram illustrating rear assembly 206 from FIG. 2 with display module 103 (not illustrated in FIG. 5) oriented toward the bottom of FIG.5, as well as frame 208 and secure circuit assembly 204. FIG. 5 is in the reverse orientation of FIG. 3, such that front assembly 202 (not illustrated in FIG. 5) is at the bottom of frame 208, with secure circuit assembly 204 shown on top of front assembly 202 and inside of frame 208. Rear assembly 206 includes button 501, button support assembly 502, foam button support 504, battery 506, adhesive 510 and rear panel 516.

[0063] Button 501, button support assembly 502 and foam button support 504 assist a user in selecting power and sleep operations. Button support assembly 502 may include antennae and capability for wireless support, for example cellular, Bluetooth, Bluetooth LE, Wi-Fi, Zigbee, infrared, near field (NFC), etc. Button support assembly may connect to PCB 400. Battery 506 provides power to reader 100 and may be rechargeable or non-rechargeable. Examples of rechargeable battery types include lead-acid, nickel-cadmium (NiCd), nickel-metal hydride (NiMH), lithium-ion (Li-ion), lithium-ion polymer (LiPo), and rechargeable alkaline batteries. Battery 506 is attached to cover 414 with adhesive 510. Rear panel 516 may be pressed or snapped into place on frame 208 and held there by friction or catch / lock mechanisms, for example. Rear panel 516 may be made from any suitable material, for example metal, glass, plastic, etc.

[0064] FIG. 6 is a clamshell perspective diagram illustrating one example of a front assembly and a printed circuit board from a credit card reader. In one aspect, front assembly 202 is illustrated in FIG. 6 from the same perspective as illustrated in FIG. 4. In one aspect, PCB 400 is illustrated in FIG. 6 from the same perspective as illustrated in FIG. 1. Other components, for example tamper switches and support, may be between front assembly 202 and PCB 400 and are not illustrated in FIG. 6 for clarity.Microcontroller 610 may be a security-enabled microcontroller, having a security mesh(not illustrated) embedded within its cover. Microcontroller 610 may be within a footprint of cover 414 (see FIG. 4), which is located on the opposite side of PCB 400. Microcontroller 610 may have in I / O pin (not illustrated), within its footprint, between microcontroller 610 and PCB 400, which is connected to a via (not illustrated) going through PCB 400 to the side of PCB 400 on which cover 414 is attached.

[0065] In one aspect, front assembly 202 may have landing areas 600a, 600b, 600c and 600d, and PCB 400 may have landing areas 600e, 600f, 600g and 600h (collectively referred to as landing areas 600). Each landing area 600 may include one or more exposed electrical pads. The electrical pads are exposed in order to make an electrical connection with a tamper switch and there may be one or more signals carried across landing areas 600 connected by a tamper switch, as well as ground. In one aspect, there are one signal and one ground electrical pads per landing area (two electrical pads total). In one aspect there are one signal and two ground electrical pads per landing area (three electrical pads total). In one aspect there are two signal and two ground electrical pads per landing area (four electrical pads total, and illustrated in FIG. 6). There may be more signal, or more ground, or more of both electrical pads than have been described. In one aspect, exposed electrical pads include signal pads 615 and ground pads 620.

[0066] Each one of landing areas 600 is part of the security features for reader 100 and may be connected to electrical mesh (whether in PCB 400 or elsewhere), secure cover 414, microcontroller 610, or other components that are not illustrated in FIG. 6. Tamper switches 410 (see FIG. 4) bridge one of landing areas 600 on front assembly 202 and a corresponding landing area 600 on PCB 400. For example, a tamper switch may bridge (or when reader 100 is assembled, be sandwiched between) landing area 600a and landing area 600f. Configured in this way, landing areas 600a and 600f, together with the sandwiched tamper switch (not illustrated in FIG. 6) may be part of the security features of reader 100. In one aspect, other sets of landing areas may include landing areas 600b and 600e, landing areas 600c and 600h, landing areas 600d and 600g, as examples.

[0067] In a conventional system, landing area 600f would have a direct electrical connection to landing area 600h. Landing area 600e would have a direct electricalconnection to landing area 600g, in the conventional system. One disadvantage of this in a conventional system is that a probe attack may attempt to reach two separate landing areas, which share a direct electrical connection. A probe (for example a wire, a line, a lead, a contact, a needle, etc.) inserted into reader 100 through frame 208 may be used to contact landing area 600f, with a separate probe contacting 600h in a conventional system. By contacting two separate landing areas with a direct electrical connection between them, an attacker may attempt to bypass the security measures for a reader.

[0068] In one aspect, there is a direct electrical connection between landing area 600e and landing area 600h. The electrical connection may be, for example, trace within or on the surface of PCB 400 and be a security feature for reader 100. Exposed electrical pads for landing area 600e may connect to exposed electrical pads for landing area 600h. Exposed electrical pads may include ground pads, for example ground pads 620, and signal pads, for example signal pads 615. As between landing area 600e and 600f, a probe inserted through case 208 may be able to more easily reach landing area 600f (or a connected tamper switch) than landing area 600e because of their relative positions (landing area 600f is between landing area 600e and the nearest edge of case 208 into which a probe might be inserted to attack reader 100, for example site A). Landing area 600f (or a tamper switch, not illustrated in FIG. 6, connected to landing area 600f) serves as a "shield" for landing area 600e (or a tamper switch, not illustrated in FIG. 6, connected to landing area 600e). A probe inserted from the other side, for example site C, must navigate more hardware and material to reach landing area 600e than a probe inserted from site A. A probe inserted from site B may have problems traversing the tamper switch (not illustrated in FIG. 6) in contact with landing area 600e (for example, to reach separate signal pads). As between landing areas with a direct electrical connection between them, one of the landing areas may be more exposed to a probe attack, for example landing area 600h (which is near an edge of case 208), than the other landing area, in this example landing area 600e. Landing area 600h is more vulnerable to a probe attack from site D than is landing area 600e to a probe attack from site A, site B, site C or site D, because landing area 600h is near site D with fewintervening structures, and a probe can access all of a tamper switch across landing area 600h. In one aspect, a more vulnerable landing area may be directly connected to a less vulnerable landing area because an attacker, trying to circumvent security features on a reader, may have a harder time probing a tamper switch at the less vulnerable landing area, and therefore make this type of probe attack more difficult than in a conventional system.

[0069] In one aspect, there is a direct electrical connection between landing area 600f and landing area 600g. The electrical connection may be, for example, trace within or on the surface of PCB 400 and be a security feature for reader 100. Exposed electrical pads for landing area 600e may connect to exposed electrical pads for landing area 600h. Exposed electrical pads may include ground pads, for example ground pads 620, and signal pads, for example signal pads 615. As between landing area 600g and 600h, a probe inserted into case 208 may be able to more easily reach landing area 600h (or a connected tamper switch) than landing area 600g because of their relative positions (landing area 600h is between landing area 600g and the nearest edge of case 208 through which a probe might be inserted to attack reader 100, for example site D). Landing area 600h (or a tamper switch, not illustrated in FIG. 6, connected to landing area 600h) serves as a "shield" for landing area 600g (or a tamper switch, not illustrated in FIG. 6, connected to landing area 600g). A probe inserted from the other side, for example site F, must navigate more hardware and material to reach landing area 600g than a probe inserted from site D. A probe inserted from site E may have problems traversing the tamper switch (not illustrated in FIG. 6) in contact with landing area 600g. As between landing areas with a direct electrical connection between them, one of the landing areas may be more exposed to a probe attack, for example landing area 600f (which is near an edge of case 208), than the other landing area, in this example landing area 600g. Landing area 600f is more vulnerable to a probe attack from site A than is landing area 600g to a probe attack from site A, site B, site C or site D, because landing area 600f is near site A with few intervening structures, and a probe can access all of a tamper switch across landing area 600f. In one aspect, a more vulnerable landing areamay be directly connected to a less vulnerable landing area because an attacker, trying to circumvent security features on a reader, may have a harder time probing a tamper switch at the less vulnerable landing area, and therefore make this type of probe attack more difficult than in a conventional system.

[0070] In one aspect, landing areas 600e and 600f are a first pair of landing areas. In one aspect, landing areas 600g and 600h are a second pair of landing areas. Within a pair of landing areas an orientation may be established, distinguishing a first landing area from a second landing area (within the pair). For example, landing area 600e may be first and landing area 600f may be second. In this example, the "upper" landing area is designated first in the orientation and the "lower" landing area is designated second. The terms "upper" and "lower" are being used only with respect to the relative position of landing areas, within a pair, and no other positional or geometric consideration."Upper" is closer to the top of the page upon which FIG. 6 is illustrated and "lower" is closer to the bottom of that page. Applying this orientation to another pair of landing areas, landing areas 600g and 600h, means landing area 600g is first and landing area 600h is second, within this second pair of landing areas, because landing area 600g is closer to the top of the page and landing area 600h is closer to the bottom of the page. From the orientation established with respect to landing areas 600e and 600f, landing area 600g is the "upper" landing area (and therefore first) and landing area 600h is the "lower" landing area (and therefore second).

[0071] Assignment of the first and second labels is arbitrary and may be reversed, but the orientation (and therefore assignment of first and second labels) is consistent as applied between pairs of landing areas. For example, in an orientation where landing area 600e may be second and landing area 600f may be first, applying that orientation to landing areas 600g and 600h makes landing area 600h first and landing area 600g second. Therefore, between pairs of landing areas, a first landing area from a first pair may have a direct electrical connection to a second landing area from a second pair. A second landing area from the first pair may have a direct electrical connection to a first landing area from the second pair. In one example and one orientation, landing areas600e and 600f, as a first pair of landing areas, and landing areas 600g and 600h, as a second pair of landing areas, have direct electrical connections between landing area 600f (first in this orientation) and landing area 600g (second in the same orientation), with a direct electrical connection between landing area 600e (second in the same orientation) and landing area 600h (first in the same orientation).

[0072] FIG. 7 is a clamshell perspective diagram illustrating one example of a front assembly and a printed circuit board from a credit card reader. FIG. 7 shares the same perspective view of front assembly 202 and PCB 400 as illustrated in FIG. 6. Other components, for example tamper switches and support, may be between front assembly 202 and PCB 400 and are not illustrated in FIG. 7 for clarity. Microcontroller 610 may be a security-enabled microcontroller, having a security mesh (not illustrated) embedded within its cover. Microcontroller 610 may be within a footprint of cover 414 (see FIG. 4), which is located on the opposite side of PCB 400. Microcontroller 610 may have in I / O pin (not illustrated), within its footprint, between microcontroller 610 and PCB 400, which is connected to a via (not illustrated) going through PCB 400 to the side of PCB 400 on which cover 414 is attached.

[0073] In one aspect, front assembly 202 may have landing areas 700a, 700b, 700c and 700d, and PCB 400 may have landing areas 700e, 700f, 700g and 700h (collectively referred to as landing areas 700). Each landing area 700 may include one or more exposed electrical pads. The electrical pads are exposed in order to make an electrical connection with a tamper switch and there may be one or more signals carried across landing areas 700 connected by a tamper switch, as well as ground. In one aspect, there are one signal and one ground electrical pads per landing area (two electrical pads total). In one aspect there are one signal and two ground electrical pads per landing area (three electrical pads total). In one aspect there are two signal and two ground electrical pads per landing area (four electrical pads total, and illustrated in FIG. 7). There may be more signal, or more ground, or more of both electrical pads than have been described. In one aspect, exposed electrical pads include signal pads 715 and ground pads 720.

[0074] Each one of landing areas 700 is part of the security features for reader 100 and may be connected to electrical mesh (whether in PCB 400 or elsewhere), secure cover 414, microcontroller 610, or other components that are not illustrated in FIG. 7. Tamper switches 410 (see FIG. 4) bridge one of landing areas 700 on front assembly 202 and a corresponding landing area 700 on PCB 400. For example, a tamper switch may bridge (or when reader 100 is assembled, be sandwiched between) landing area 700a and landing area 700f. Configured in this way, landing areas 700a and 700f, together with the sandwiched tamper switch (not illustrated in FIG. 7) may be part of the security features of reader 100. In one aspect, other groups of landing areas may include landing areas 700b and 700e, landing areas 700c and 700h, landing areas 700d and 700g, as examples.

[0075] In one aspect, there is a direct electrical connection between landing area 700e and landing area 700g. The electrical connection may be, for example, trace within or on the surface of PCB 400 and be a security feature for reader 100. Exposed electrical pads for landing area 700e may connect to exposed electrical pads for landing area 700g. Exposed electrical pads may include ground pads, for example ground pads 720, and signal pads, for example signal pads 715. As between landing area 700e and 700f, a probe inserted through case 208 may be able to more easily reach landing area 700f (or a connected tamper switch) than landing area 700e because of their relative positions (landing area 700f is between landing area 700e and the nearest edge of case 208 into which a probe might be inserted to attack reader 100, for example site A). Landing area 700f (or a tamper switch, not illustrated in FIG. 7, connected to landing area 700f) serves as a "shield" for landing area 700e (or a tamper switch, not illustrated in FIG. 7, connected to landing area 700e). A probe inserted from the other side, for example site C, must navigate more hardware and material to reach landing area 700e than a probe inserted from site A. A probe inserted from site B may have problems traversing the tamper switch (not illustrated in FIG. 6) in contact with landing area 700e (for example, to reach separate signal pads). As between landing areas with a direct electrical connection between them, one of the landing areas may be more exposed to a probe attack, for example landing area 700g (which is near an edge of case 208), than theother landing area, in this example landing area 700e. Landing area 700g is more vulnerable to a probe attack from site E than is landing area 700e to a probe attack from site A, site B, site C or site D, because landing area 700g is near site E with few intervening structures, and a probe can access all of a tamper switch across landing area 700G. In one aspect, a more vulnerable landing area may be directly connected to a less vulnerable landing area because an attacker, trying to circumvent security features on a reader, may have a harder time probing a tamper switch at the less vulnerable landing area, and therefore make this type of probe attack more difficult than in a conventional system.

[0076] In one aspect, there is a direct electrical connection between landing area 700f and landing area 700h. The electrical connection may be, for example, trace within or on the surface of PCB 400 and be a security feature for reader 100. Exposed electrical pads for landing area 700e may connect to exposed electrical pads for landing area 700g. Exposed electrical pads may include ground pads, for example ground pads 720, and signal pads, for example signal pads 715. As between landing area 700g and 700h, a probe inserted into case 208 may be able to more easily reach landing area 700g (or a connected tamper switch) than landing area 700h because of their relative positions (landing area 700g is between landing area 700h and the nearest edge of case 208 through which a probe might be inserted to attack reader 100, for example site E). Landing area 700g serves as a "shield" for landing area 700h. A probe inserted from the other side, for example site B, must navigate more hardware and material to reach landing area 700h than a probe inserted from site E. A probe inserted from site D may have problems traversing the tamper switch (not illustrated in FIG. 7) in contact with landing area 700h. As between landing areas with a direct electrical connection between them, one of the landing areas may be more exposed to a probe attack, for example landing area 700f (which is near an edge of case 208), than the other landing area, in this example landing area 700h. Landing area 700f is more vulnerable to a probe attack from site A than is landing area 700h to a probe attack from site A, site B, site C or site D, because landing area 700f is near site A with few intervening structures, and a probe canaccess all of a tamper switch across landing area 700f. In one aspect, a more vulnerable landing area may be directly connected to a less vulnerable landing area because an attacker, trying to circumvent security features on a reader, may have a harder time probing a tamper switch at the less vulnerable landing area, and therefore make this type of probe attack more difficult than in a conventional system.

[0077] In one aspect, landing areas 700e and 700f may be a first pair of landing areas. In one aspect, landing areas 700g and 700h may be a second pair of landing areas. Within a pair of landing areas, one of the landing areas may be closer to the case, or side of a reader, or area from which an attacker would insert a probe into the reader during an attack, and the other landing area may be further away. As described above, the landing area closer to the case may be more vulnerable to attack than the landing area further from the case. In this example, from the first pair of landing areas (including landing areas 700e and 700f), landing area 700e may be further from the case, from where an attack may occur. Landing area 700f may be closer to the case, from where an attack may occur. In this example, an attack may occur from Site A. Landing areas 700e and 700f may be similar in distance from Site B (and that side of case 208, generally), but a probe attack from this side is more difficult because of probe access to the exposed electrodes through the tamper switch. Landing area 700e may be closer than landing area 700f to Site C (and that side of case 208, generally), but a probe attack from this side is more difficult because of the distance to traverse and intervening structures.

[0078] In one aspect, landing areas 700g and 700h are perpendicular in their orientation as compared to landing areas 700e and 700f. In a second pair of landing areas, for example landing areas 700g and 700h, one of the landing areas may be closer to the case, or side of a reader, or area from which an attacker would insert a probe into the reader during an attack, and the other landing area may be further away. As described above, the landing area closer to the nearest side of the case may be more vulnerable to attack than the landing area further from the case. In this example, from the second pair of landing areas (including landing areas 700g and 700h), landing area 700h may be further from a side of the case nearest to the second pair of landing areas, from wherean attack would most likely occur. Landing area 700g may be closer to the case, from where an attack would most likely occur. In this example, a probe attack would most likely occur from Site E. Landing areas 700h and 700g may be similar in distance from Site D (and that side of case 208, generally), but a probe attack from this side is more difficult because of probe access to the exposed electrodes through the tamper switch. Landing area 700h may be closer than landing area 700g to Site B (and that side of case 208, generally), but a probe attack from this side is more difficult because of the distance to traverse and intervening structures. Landing areas 700h and 700g may be similar in distance from Site F (and that side of case 208, generally), but a probe attack from this side is more difficult because of probe access to the exposed electrodes through the tamper switch, the distance to traverse and intervening structures. Sites A and C don't rectify the issues.

[0079] FIG. 8 is a top-down perspective view illustrating one example of a printed circuit board from a credit card reader. FIG. 8 shares the same perspective view of PCB 400 as illustrated in FIGS. 6 and 7. Structural components on PCB 400 and illustrated in FIGS. 6 and 7 have been removed from PCB 400 as illustrated in FIG. 8, for example microcontroller 610, for clarity, but may still be considered a part of PCB 400 as pertains to FIG. 8 (although not illustrated). Front assembly 202 is not illustrated in FIG. 8 for clarity. Aspects of front assembly 202, tamper switches 410, and PCB 400 as previously discussed also apply to PCB 400 in FIG. 8, as one of skill in the art will recognize.

[0080] In one aspect, PCB 400 may have landing areas 800a, 800b, 800c and 800d (collectively referred to as landing areas 800). Each landing area 800 may include one or more exposed electrical pads. The electrical pads are exposed in order to make an electrical connection with a tamper switch (not illustrated in FIG. 8) and there may be one or more signals carried across landing areas 800 connected by a tamper switch, as well as ground. In one aspect, there are one signal and one ground electrical pads per landing area (two electrical pads total). In one aspect there are one signal and two ground electrical pads per landing area (three electrical pads total). In one aspect there are two signal and two ground electrical pads per landing area (four electrical pads total,and illustrated in FIG. 8). There may be more signal, or more ground, or more of both electrical pads than have been described. In one aspect, exposed electrical pads include signal pads 815 and ground pads 820.

[0081] Each one of landing areas 800 is part of the security features for reader 100 and may be connected to electrical mesh (whether in PCB 400 or elsewhere), secure cover 414, microcontroller 610, or other components that are not illustrated in FIG. 8. Tamper switches 410 (see FIG. 4) bridge one of the landing areas on front assembly 202 (not illustrated in FIG. 8) and a corresponding landing area 800 on PCB 400. For example, a tamper switch may bridge (or when reader 100 is assembled, be sandwiched between) landing area 800a and a corresponding landing area on the front assembly (not illustrated in FIG. 8, see FIGS. 6 and 7). Configured in this way, landing areas 800a together with the sandwiched tamper switch and corresponding landing area (neither illustrated in FIG. 8), may be part of the security features of reader 100. In one aspect, landing areas 800b, 800c, and 800d may have corresponding tamper switches and landing areas that may be part of the security features of reader 100, as explained in the description.

[0082] PCB 400 may have a center, as viewed from a top-down (or bottom-up) perspective. PCB 400 may be coplanar with the plane of FIG. 8, with a center of PCB 400 determined, for example, from corner-to-corner, or edge-to-edge (or otherwise as warranted by a shape of the printed circuit board, for example with a circular circuit board, the radius may be the center). In one aspect, center 830 may be determined by measuring from corner-to-corner along lines 832 and 834, with the meeting point of each of lines 832 and 834 being a center for PCB 400.

[0083] In one aspect, center 840 may be determined by measuring edge-to-edge of PCB 400. For example, line 842 extends from an edge of PCB 400 to an opposite, parallel edge. For example, line 844 extends from an edge of PCB 400 to an opposite, parallel edge. The middle of lines 842 and 844 may define center 840. Including the example of a circular printed circuit board, three examples of determining a center are provided. Oneof skill in the art will recognize that other methods may be used to determine a center of a printed circuit board depending on shape, with many different shapes possible.

[0084] In one aspect, there is a direct electrical connection between landing area 800a and landing area 800d. The electrical connection may be, for example, trace within or on the surface of PCB 400 and be a security feature for reader 100. Exposed electrical pads for landing area 800a may connect to exposed electrical pads for landing area 800d. Exposed electrical pads may include ground pads, for example ground pads 820, and signal pads, for example signal pads 815. Within a pair of landing areas, for example landing areas 800a and 800b, a probe inserted through case 208 may be able to more easily reach landing area 800b (or a connected tamper switch, not illustrated in FIG. 8) than landing area 800a because of their relative positions (landing area 800a is closer to either center 830 or 840 than is landing area 800b). Landing area 800b (or a connected tamper switch, not illustrated in FIG. 8) serves as a "shield" for landing area 800a, protecting it from probe attacks from one direction. In this example, within a pair of landing areas (as above, landing areas 800a and 800b), the landing area closer to a center of the printed circuit board may be harder to attack by probe than the landing area further from the center. The landing area closer to the center, in this example landing area 800a, is shielded from probe attacks by the landing area further from the center, in this example landing area 800b. From the opposite direction, a probe attack to a landing area closer to a center of PCB 400 may have a harder time with the distance and potential intervening structures, than a probe attack to a landing area further from a center of PCB 400.

[0085] In one aspect, there is a direct electrical connection between landing area 800b and landing area 800c. The electrical connection may be, for example, trace within or on the surface of PCB 400 and be a security feature for reader 100. Exposed electrical pads for landing area 800b may connect to exposed electrical pads for landing area 800c. Exposed electrical pads may include ground pads, for example ground pads 820, and signal pads, for example signal pads 815. Within a pair of landing areas, for example landing areas 800c and 800d, a probe inserted through case 208 may be able to moreeasily reach landing area 800d (or a connected tamper switch, not illustrated in FIG. 8) than landing area 800c because of their relative positions (landing area 800c is closer to either center 830 or 840 than is landing area 800d). Landing area 800d (or a connected tamper switch, not illustrated in FIG. 8) serves as a "shield" for landing area 800c, protecting it from probe attacks from one direction. In this example, within a pair of landing areas (as above, landing areas 800c and 800d), the landing area closer to a center of the printed circuit board may be harder to attack by probe than the landing area further from the center. The landing area closer to the center, in this example landing area 800c, is shielded from probe attacks by the landing area further from the center, in this example landing area 800d. From the opposite direction, a probe attack to a landing area closer to a center of PCB 400 may have a harder time with the distance and potential intervening structures, than a probe attack to a landing area further from a center of PCB 400.

[0086] A pair of landing areas may be located in close proximity to one another. A pair of landing areas may have interconnected ground pads. A pair of landing areas do not have a direct electrical connection between their signal pads. A pair of landing areas do not share a tamper switch.

[0087] This disclosure refers to the term "reader" throughout, and while specifically directed towards a credit card reader, the disclosure applies equally well to a traditional credit card terminal. Nothing in the disclosure should be taken as limiting to a reader over a terminal. Moreover, many aspects of the disclosure apply equally well to any electronic device, as would be recognized by one skilled in the art.

[0088] The aspects and features mentioned and described together with one or more of the previously detailed examples and figures, may as well be combined with one or more of the other examples in order to replace a like feature of the other example or in order to additionally introduce the feature to the other example.

[0089] Examples may further be or relate to a computer program having a program code for performing one or more of the above methods, when the computer program is executed on a computer or processor. Steps, operations or processes of variousabove-described methods may be performed by programmed computers or processors. Examples may also cover program storage devices such as digital data storage media, which are machine, processor or computer readable and encode machine-executable, processor-executable or computer-executable programs of instructions. The instructions perform or cause performing some or all of the acts of the above-described methods. The program storage devices may comprise or be, for instance, digital memories, magnetic storage media such as magnetic disks and magnetic tapes, hard drives, or optically readable digital data storage media. Further examples may also cover computers, processors or control units programmed to perform the acts of the above-described methods or (field) programmable logic arrays ((F)PLAs) or (field) programmable gate arrays ((F)PGAs), programmed to perform the acts of the above-described methods.

[0090] The description and drawings merely illustrate the principles of the disclosure. Furthermore, all examples recited herein are principally intended expressly to be only for pedagogical purposes to aid the reader in understanding the principles of the disclosure and the concepts contributed by the inventor(s) to furthering the art. All statements herein reciting principles, aspects, and examples of the disclosure, as well as specific examples thereof, are intended to encompass equivalents thereof.

[0091] A functional block denoted as "means for . . . " performing a certain function may refer to a circuit that is configured to perform a certain function. Hence, a "means for s.th." may be implemented as a "means configured to or suited for s.th.", such as a device or a circuit configured to or suited for the respective task.

[0092] Functions of various elements shown in the figures or described in the specification, including any functional blocks labeled as "means", "means for providing a sensor signal", "means for generating a transmit signal.", etc., may be implemented in the form of dedicated hardware, such as "a signal provider", "a signal processing unit", "a processor", "a controller", etc. as well as hardware capable of executing software in association with appropriate software. When provided by a processor, the functions may be provided by a single dedicated processor, by a single shared processor, or by aplurality of individual processors, some of which or all of which may be shared. However, the term "processor" or "controller" is by far not limited to hardware exclusively capable of executing software (and is intended to be used interchangeably within this specification, including "microprocessor" and "microcontroller") but may include digital signal processor (DSP) hardware, network processor, application specific integrated circuit (ASIC), field programmable gate array (FPGA), read only memory (ROM) for storing software, random access memory (RAM), and non-volatile storage. Other hardware, conventional and / or custom, may also be included.

[0093] A block diagram may, for instance, illustrate a high-level circuit diagram implementing the principles of the disclosure. Similarly, a flow chart, a flow diagram, a state transition diagram, a pseudo code, and the like may represent various processes, operations or steps, which may, for instance, be substantially represented in computer readable medium and so executed by a computer or processor, whether or not such computer or processor is explicitly shown. Methods disclosed in the specification or in the claims may be implemented by a device having means for performing each of the respective acts of these methods.

[0094] It is to be understood that the disclosure of multiple acts, processes, operations, steps, or functions disclosed in the specification or claims may not be construed as to be within the specific order, unless explicitly or implicitly stated otherwise, for instance for technical reasons. Therefore, the disclosure of multiple acts or functions will not limit these to a particular order unless such acts or functions are not interchangeable for technical reasons. Furthermore, in some examples a single act, function, process, operation or step may include or may be broken into multiple sub-acts, -functions, -processes, -operations or -steps, respectively. Such sub acts may be included and part of the disclosure of this single act unless explicitly excluded.

[0095] Furthermore, the following claims are hereby incorporated into the detailed description, where each claim may stand on its own as a separate example. While each claim may stand on its own as a separate example, it is to be noted that--although a dependent claim may refer in the claims to a specific combination with one or moreother claims-other examples may also include a combination of the dependent claim with the subject matter of each other dependent or independent claim. Such combinations are explicitly proposed herein unless it is stated that a specific combination is not intended. Furthermore, it is intended to include features of a claim to any other independent claim even if this claim is not directly made dependent on the independent claim.

Claims

CLAIMSWhat is claimed is:

1. A point-of-sale credit card reader comprising: a case; a printed circuit board (PCB) coupled to the case, the PCB with a first side and a second side, the first and second sides parallel and opposite to one another, wherein at least one via extends through the PCB from the first side to the second side; a microcontroller coupled to the first side of the PCB and electrically coupled to the via, the microcontroller having at least one input / output (I / O) pin within the microcontroller footprint and between the top of the microcontroller and the first side of the PCB; a first pair of landing areas coupled to the first side of the PCB, the first pair of landing areas each having a plurality of exposed electrical pads; a first plurality of tamper switches coupled to the first pair of landing areas; a second pair of landing areas coupled to the first side of the PCB, the second pair of landing areas each having a plurality of exposed electrical pads; a second plurality of tamper switches coupled to the second pair of landing areas; the first pair of landing areas having a first landing area and a second landing area wherein an orientation of the first pair of landing areas with respect to the case and the PCB differentiates the first landing area from the second landing area, the second pair of landing areas having a first landing area and a second landing area wherein the orientation, applied to the second pair of landing areas, differentiates the first landing area and the second landing area; and a direct electrical connection between the first landing area of the first pair of landing areas and the second landing area of the second pair of landing areas.

2. The reader of claim 1 further comprising: a direct electrical connection between the second landing area of the first pair of landing areas and the first landing area of the second pair of landing areas.

3. The reader of claim 2 wherein the electrical resistance across the first plurality of tamper switches and the second pair of tamper switches varies depending on a degree of tamper switch compression.

4. The reader of claim 2, the tamper switch material further comprising: alternating layers of conductive and non-conductive silicone rubber.

5. The reader of claim 2, further comprising: a cover coupled to the second side of the PCB, the cover including a non-conducting base and a security mesh including a plurality of electrical traces as part of an electrical circuit, the plurality of electrical traces of the security mesh having a spacing between two immediately adjacent traces of no more than 150 micrometers throughout the security mesh, the security mesh extending over a majority of the cover.

6. The reader of claim 5 wherein the first landing area of the first pair of landing areas is coupled to the security mesh of the cover.

7. The reader of claim 6, further comprising: a removable front assembly coupled to the case and coupled to the first and second plurality of tamper switches.

8. A point-of-sale credit card reader comprising: a case; a printed circuit board (PCB) coupled to the case, the PCB with a first sideand a second side, the first and second sides parallel and opposite to one another, wherein at least one via extends through the PCB from the first side to the second side; a microcontroller coupled to the first side of the PCB and electrically coupled to the via, the microcontroller having at least one input / output (I / O) pin within the microcontroller footprint and between the top of the microcontroller and the first side of the PCB; a first pair of landing areas coupled to the first side of the PCB, the first pair of landing areas each having a plurality of exposed electrical pads; a first plurality of tamper switches coupled to the first pair of landing areas; a second pair of landing areas coupled to the first side of the PCB, the second pair of landing areas each having a plurality of exposed electrical pads; a second plurality of tamper switches coupled to the second pair of landing areas; the first pair of landing areas having a first landing area and a second landing area wherein the first landing area is further from the case than the second landing area, the second pair of landing areas having a first landing area and a second landing area wherein the first landing area is further from the case than the second landing area; and a direct electrical connection between the first landing area of the first pair of landing areas and the second landing area of the second pair of landing areas.

9. The reader of claim 8 further comprising: a direct electrical connection between the second landing area of the first pair of landing areas and the first landing area of the second pair of landing areas.

10. The reader of claim 9 wherein the electrical resistance across the first plurality of tamper switches and the second pair of tamper switches varies depending on a degree of tamper switch compression.

11. The reader of claim 9, the tamper switch material further comprising: alternating layers of conductive and non-conductive silicone rubber.

12. The reader of claim 9, further comprising: a cover coupled to the second side of the PCB, the cover including a non-conducting base and a security mesh including a plurality of electrical traces as part of an electrical circuit, the plurality of electrical traces of the security mesh having a spacing between two immediately adjacent traces of no more than 150 micrometers throughout the security mesh, the security mesh extending over a majority of the cover.

13. The reader of claim 12 wherein the first landing area of the first pair of landing areas is coupled to the security mesh of the cover.

14. The reader of claim 13, further comprising: a removable front assembly coupled to the case and coupled to the first and second plurality of tamper switches.

15. A point-of-sale credit card reader comprising: a case; a printed circuit board (PCB) coupled to the case, the PCB with a first side and a second side, the first and second sides parallel and opposite to one another, wherein at least one via extends through the PCB from the first side to the second side, the PCB having a center along the plane of the PCB; a microcontroller coupled to the first side of the PCB and electrically coupled to the via, the microcontroller having at least one input / output (I / O) pin within the microcontroller footprint and between the top of the microcontroller and the first side of the PCB;a first pair of landing areas coupled to the first side of the PCB, the first pair of landing areas each having a plurality of exposed electrical pads; a first plurality of tamper switches coupled to the first pair of landing areas; a second pair of landing areas coupled to the first side of the PCB, the second pair of landing areas each having a plurality of exposed electrical pads; a second plurality of tamper switches coupled to the second pair of landing areas; the first pair of landing areas having a first landing area and a second landing area wherein the first landing area is closer to the center than the second landing area, the second pair of landing areas having a first landing area and a second landing area wherein the first landing area is closer to the center than the second landing area; and a direct electrical connection between the first landing area of the first pair of landing areas and the second landing area of the second pair of landing areas.

16. The reader of claim 15 further comprising: a direct electrical connection between the second landing area of the first pair of landing areas and the first landing area of the second pair of landing areas.

17. The reader of claim 16 wherein the electrical resistance across the first plurality of tamper switches and the second pair of tamper switches varies depending on a degree of tamper switch compression.

18. The reader of claim 16, the tamper switch material further comprising: alternating layers of conductive and non-conductive silicone rubber.

19. The reader of claim 16, further comprising: a cover coupled to the second side of the PCB, the cover including anon-conducting base and a security mesh including a plurality of electrical traces as part of an electrical circuit, the plurality of electrical traces of the security mesh having a spacing between two immediately adjacent traces of no more than 150 micrometers throughout the security mesh, the security mesh extending over a majority of the cover.

20. The reader of claim 19 wherein the first landing area of the first pair of landing areas is coupled to the security mesh of the cover.

21. The reader of claim 20, further comprising: a removable front assembly coupled to the case and coupled to the first and second plurality of tamper switches.

Citation Information

Patent Citations

  • Tamper detection system

    US10595400B1

  • Secure Card Reader

    US20080164320A1

  • Protection for circuit boards

    US20080278217A1

  • Fuel dispenser input device tamper detection arrangement

    US20120286760A1