Systems and methods for payment terminal skimmer disablement
The point-of-interaction device uses electrical signals and overvoltage to simulate fake transactions and disable rogue electronic devices, addressing vulnerabilities in smartcard data interception and enhancing security.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-18
- Publication Date
- 2026-03-26
AI Technical Summary
Existing point-of-interaction devices are vulnerable to tampering by rogue electronic devices that intercept smartcard data, lacking effective means to detect and neutralize these threats.
Implementing a point-of-interaction device with a smartcard interface module and a burnout circuit that generates electrical signals or increased voltage through the smartcard interface pins to simulate fake customer records or overvoltage, thereby obfuscating legitimate data and disabling rogue electronic devices.
Effectively neutralizes rogue electronic devices by filling their memory with fake data or damaging them with overvoltage, enhancing security and protecting cardholder information.
Smart Images

Figure US2024047234_26032026_PF_FP_ABST
Abstract
Description
PATENTDocket No.: VFI-1059-WOSYSTEMS AND METHODS FOR PAYMENT TERMINAL SKIMMER DISABLEMENTField of the Disclosure
[0001] The present disclosure relates generally to payment systems, and more specifically to systems and methods for securing payment terminals and point-of-interaction devices from cybersecurity threats related to smartcard data theft.Background
[0002] Point-of-interaction devices, such as point-of-sale devices, secure card readers, and / or the like, are used in a variety of environments to process payment transactions. While processing payment transactions, such point-of-interaction devices receive, process, and / or store a wide array of sensitive information, such as credit card information, debit card information, banking information, customer personal identification numbers (PINs), and more. This sensitive information makes these point-of-interaction devices a significant target for tampering. Existing point-of-interaction devices employ a number of tamper detection systems and methods. These systems and methods may be based on, for example, the breaking of electrical connections or using light-based detectors. However, new lines of attack are constantly being developed by bad actors which require additional modifications and improvements to strengthen and secure said point-of-interaction devices.Summary of the Disclosure
[0003] According to one embodiment of the present disclosure, a point-of-interaction device is provided. The point-of-interaction device can include: at least one processor; a smartcard interface module operatively connected to the at least one processor and comprising a pin set including at least a first pin configured to communicate electrical signals; and a memory storing machine-readable instructions. When the machine-readable instructions are executed by the at least one processor, they may cause the point-of-interaction device to perform the following operations: generate, via the at least one processor, an electrical signal across at least the first pin of the pin set of the smartcard interface module, wherein the electrical signal communicates either (i) at least one fake customer record, or (ii) an increased voltage through at least the first pin of the pin set.PATENTDocket No.: VFI-1059-WO
[0004] In an aspect, the point-of-interaction device further comprises a smartcard insertion switch configured to detect physical insertion of a customer smartcard into the smartcard interface module of the point-of-interaction device.
[0005] In an aspect, the memory further stores machine-readable instructions that, when executed by the at least one processor, causes the point-of-interaction device to perform the following operations: detect, via the smartcard insertion switch, whether a customer smartcard has been inserted into the smartcard interface module of the point-of-interaction device; and generate, via the at least one processor, the electrical signal across at least the first pin of the pin set only if the smartcard insertion switch indicates that a customer smartcard is not present within the smartcard interface module.
[0006] In an aspect, the electrical signal communicates a plurality of fake customer records across at least the first pin of the pin set of the smartcard interface module.
[0007] In an aspect, the electrical signal communicates the plurality of fake customer records at a rate of at least one fake customer record per second of terminal inactivity.
[0008] In an aspect, each fake customer record comprises a fake cardholder PIN, a fake cardholder PAN, a fake cardholder name, a fake cardholder address, and / or a fake cardholder zip code.
[0009] In an aspect, the electrical signal is generated across at least the first pin of the pin set of the smartcard interface module by simulating, via the at least one processor and the smartcard interface module, a transaction with a non-existent customer smartcard.
[0010] In an aspect, the electrical signal is directly generated across at least the first pin of the pin set of the smartcard interface module using an input / output (I / O) line connecting an I / O pin of the at least one processor with at least the first pin.
[0011] In an aspect, the point-of-interaction device can further include: a power management integrated circuit configured to provide a plurality of voltage rails for operating the point-of-interaction device; and a burnout circuit operatively connecting a high-voltage rail of the plurality of voltage rails with at least the first pin of the pin set of the smartcard interface module. The burnout circuit can receive the electrical signal from the at least one processor and generate an increased voltage through at least the first pin of the pin set using the power management integrated circuit.
[0012] In an aspect, the high-voltage rail provides an increased voltage that is greater than about 5V.PATENTDocket No.: VFI-1059-WO
[0013] In an aspect, the high-voltage rail provides an increased voltage that is at least about 12 V.
[0014] According to another embodiment of the present disclosure, a burnout device is provided. The burnout device can include: a smartcard interface module comprising a pin set including at least a first pin configured to communicate electrical signals; a power management integrated circuit configured to provide a plurality of voltage rails; and a burnout circuit operatively connecting a high-voltage rail of the plurality of voltage rails with at least the first pin of the pin set of the smartcard interface module. The burnout circuit is configured to receive an electrical signal from at least one processor of an associated point-of-interaction device and generate an increased voltage through at least the first pin of the pin set using the power management integrated circuit.
[0015] In an aspect, the high-voltage rail provides an increased voltage that is greater than about 5V.
[0016] In an aspect, the high-voltage rail provides an increased voltage that is at least about 12 V.
[0017] According to still another embodiment of the present disclosure, a computer- implemented method of obfuscating smartcard data from a payment card is provided. The method can include — in a point-of-interaction device comprising at least one processor operatively connected to a smartcard insertion switch and a smartcard interface module having a pin set that includes at least a first pin configured to communicate electrical signals — performing the following steps: detecting, via the smartcard insertion switch, whether a payment card has been inserted into the smartcard interface module; and if a payment card is not detected, generating, an electrical signal across at least the first pin of the pin set of the smartcard interface module, wherein the electrical signal communicates either (i) at least one fake customer record, or (ii) an increased voltage through at least the first pin of the pin set.
[0018] In an aspect, the electrical signal communicates a plurality of fake customer records across at least the first pin of the pin set of the smartcard interface module.
[0019] In an aspect, the electrical signal communicates the plurality of fake customer records at a rate of at least one fake customer record per second of terminal inactivity.
[0020] In an aspect, the electrical signal is generated across at least the first pin of the pin set of the smartcard interface module by simulating, via the at least one processor and the smartcard interface module, a transaction with a non-existent customer smartcard.PATENTDocket No.: VFI-1059-WO
[0021] In an aspect, the electrical signal is directly generated across at least the first pin of the pin set of the smartcard interface module using an input / output (I / O) line connecting an I / O pin of the at least one processor with at least the first pin.
[0022] In an aspect, the point-of-interaction device further comprises a burnout device, and the method further comprises: receiving, at a burnout circuit of the burnout device, an instruction to generate an increased voltage through at least the first pin of the pin set; and directing, via the burnout circuit of the burnout device, an increased voltage through at least the first pin of the pin set, wherein the increased voltage is greater than 5V.
[0023] These and other aspects of the various embodiments will be apparent from and elucidated with reference to the embodiments described hereinafter.Brief Description of the Drawings
[0024] In the drawings, like reference characters generally refer to the same parts throughout the different views. Also, the drawings are not necessarily to scale, emphasis instead generally being placed upon illustrating the principles of the various embodiments.
[0025] FIG. 1 is a diagram of a point-of-interaction device illustrated in accordance with aspects of the present disclosure.
[0026] FIG. 2 is a chip-enabled payment card illustrated in accordance with aspects of the present disclosure.
[0027] FIG. 3 is a functional block diagram of a point-of-interaction device illustrated in accordance with further aspects of the present disclosure.
[0028] FIG. 4 is another block diagram of a point-of-interaction device illustrated in accordance with still further aspects of the present disclosure.
[0029] FIG. 5 is a flowchart illustrating a method of obfuscating smartcard data in a point- of-interaction device in accordance with aspects of the present disclosure.
[0030] FIG. 6 is a block diagram of another embodiment of a point-of-interaction device illustrated in accordance with aspects of the present disclosure.
[0031] FIG. 7 is a circuit diagram illustrating portions of a burnout device in accordance with aspects of the present disclosure.Detailed Description of Embodiments
[0032] The present disclosure is directed to payment systems and methods for securing said payment systems against theft of smartcard data. As mentioned above, bad actors seek to obtainPATENTDocket No.: VFI-1059-WO cardholder information via several different attack vectors. By virtue of the design of existing smartcards and smartcard interface module, the smartcard input / output (I / O) pin is completely accessible assuming physical access to the payment system. According to a new payment system threat, bad actors target the flow of cardholder information between the smartcard and the smartcard interface using rogue electronic devices (sometimes referred to as a “shim”) made from a flexible printed circuit board material that slips into the smartcard interface module. These rogue electronic devices are typically designed with limited hardware, including limited memory capacity, so that they will go unnoticed by merchants and customers. As a result, these rogue electronic devices generally do not interrupt normal operations of the payment system, but allow bad actors to capture cardholder information as payment transactions are performed.
[0033] However, there is currently no commercially-available means available to electrically detect rogue electronic devices (e.g., shims) connected to the smartcard I / O pin. Customers and merchants are reluctant and / or ill -prepared to inspect their payment terminals visually and frequently enough to detect and deter fraud. Accordingly, it is desirable to provide systems and methods to obfuscate legitimate cardholder information transferred during legitimate payment transactions and / or otherwise disable rogue electronic devices targeting the smartcard interface module.
[0034] Turning to FIG. 1, an exemplary payment system 100 is illustrated in accordance with various aspects of the present disclosure. As shown, the payment system 100 may be a point-of-interaction terminal configured to accept payment cards for completing payment transactions. As described herein, the payment system 100 includes at least a smartcard interface module 102 configured to receive a smartcard 104. In particular embodiments, the payment system 100 may also include one or more additional card readers / payment interface modules, including but not limited to an NFC reader 106, a magnetic stripe reader 108, a barcode / QR code scanner 110, and / or the like. In further embodiments, the payment system 100 may include a user interface, such as a keypad 112, as well as a display 114, which may be a touchscreen display.
[0035] With reference to FIG. 2, it will be appreciated that a smartcard 104 according to the present disclosure comprises at least a smart chip 116 that is configured to provide cardholder information for completing a financial transaction when inserted into the smartcard interface module 102 of the payment system 100. In general, the smart chip 116 can include a microprocessor, random access memory (RAM), and data storage under a gold contact pad. InPATENTDocket No.: VFI-1059-WO particular embodiments, the smart chip 116 will have a plurality of contacts (sometimes referred to as pins), each of which may be dedicated for a specific purpose. According to various current standards, the smart chip 116 may include 6 or 8 pins, but the present disclosure is not limited to a particular number of pins / contacts. In specific embodiments, the smart chip 116 may comprise: (i) a VCC pin / contact 120 dedicated to receiving a power supply from a corresponding interface module 102; (ii) an RST pin / contact 122 dedicated to receiving a reset signal used to reset the card’s communications; (iii) a CLK pin / contact 124 dedicated to receiving a clock signal from which data communications timing can be derived; (iv) a GND pin / contact 126 dedicated to receiving a reference voltage / ground; (v) a VPP or SPU pin / contact 128 dedicated to receiving a programming voltage or for standard / proprietary use, respectively; (vi) an I / O pin / contact 130 dedicates for serial input and output; and (vii) one or more pins / contacts 132, 134 for auxiliary uses.
[0036] In some embodiments, the smart chip 116 may be a smart card chip according to ISO 7816. In specific embodiments, the smart chip 116 may be an EMV chip, i.e., a smart chip 116 according to EMV® Specifications, which are managed by EMVCo. However, the systems and methods described herein are not limited to the specific EMV chips or EMV® Specifications.
[0037] With reference to FIG. 3, a block diagram of an exemplary point-of-interaction device 100 is illustrated in accordance with further aspects of the present disclosure. As shown, the point-of-interaction device 100 can include one or more processors 202 and a machine- readable memory 204 interconnected and / or in communication via a system bus 206 containing conductive circuit pathways through which instructions (e.g., machine-readable signals) may travel to effectuate communication, tasks, storage, and the like. The point-of-interaction device 100 can be connected to a power source (not shown), which can include an internal power supply and / or an external power supply. As mentioned above, the point-of-interaction device 100 can also include one or more additional components, such as a user interface 112, a display 114, an input / output (VO) interface 212, a networking unit 214, one or more card readers 101, and the like, including combinations thereof. As shown, each of these components may be interconnected and / or in communication via the system bus 206, for example.
[0038] In embodiments, the one or more card readers 101 may include a magnetic stripe reader 108 for reading and processing magnetic stripe data (e.g., Track I and Track II data) of payment cards 104, a smartcard interface module 102 for reading and processing chip-enabledPATENTDocket No.: VFI-1059-WO payment card 104, a contactless reader 106 for reading and processing contactless data from a contactless-enabled payment card, and / or the like.
[0039] In particular embodiments, the point-of-interaction device 100 includes at least a smartcard interface module 102 comprising a pin set 401 configured to communicate electronically with the smart chip 116 of a smartcard 104. For example, with reference to FIG. 4, an embodiment of the point-of-interaction device 100 is illustrated, wherein a secure processor 230, an application processor 232, a memory 204, and a smartcard interface module 102 are connected via an I2C bus 206. As shown, the smartcard interface module 102 includes a pin set 401 configured to communicate electronically, i.e., send and receive electrical signals.
[0040] In embodiments, when a smartcard 104 is inserted into a smartcard interface module 102, the pin set 401 is configured to communicate electronically with the contacts 120, 122, 124, 126, 128, 130, 132, 134 of the smart chip 116 in order to exchange a set of security-related and / or transaction-related parameters between the smartcard 104 and the point-of-interaction device 100. In embodiments, this set of parameters may be referred to as a customer transaction record, which can include cardholder information such as the cardholder’s personal identification number (“PIN”), the cardholder’s primary account number (“PAN”), the cardholder’s card verification code (“CVC”), the cardholder’s name, the cardholder’s address, the cardholder’s zip code, and / or the like. As mentioned above, bad actors seek to steal and exploit this customer transaction record information in order to, for example, perform unauthorized transactions without the cardholder’s knowledge.
[0041] In specific embodiments, the pin set 401 includes at least one pin, such as an VO pin 430 that is configured to communicate electronic signals. In particular embodiments, the pin set 401 includes a plurality of pins corresponding to the pins / contacts of potential smart chips 116. For example, the pin set 401 may include (i) a VCC pin / contact 420 dedicated to supplying power to a smart chip 116 when the payment card 104 is inserted; (ii) an RST pin / contact 422 dedicated to providing a reset signal used to reset the card’s communications; (iii) a CLK pin / contact 424 dedicated to providing a clock signal from which data communications timing can be derived; (iv) a GND pin / contact 426 dedicated to providing a reference voltage / ground; (v) a VPP or SPU pin / contact 428 dedicated to providing a programming voltage or for standard / proprietary use, respectively; (vi) an I / O pin / contact 430 dedicates for serial input and output; and (vii) one or more pins / contacts 432, 434 for auxiliary uses.
[0042] As described herein, the one or more contacts of the pin set 401 may physical connection with the pins / contacts of the smart chip 116 when a payment card 104 is insertedPATENTDocket No.: VFI-1059-WO into the point-of-interaction device 100, such that the contacts of the pin set 401 are in electrical communication with the smart chip 116.
[0043] Returning to FIG. 3, the one or more processors 202 can include one or more highspeed data processors adequate to process payment card information, execute the program components described herein, and / or perform one or more operations of the methods described herein.
[0044] In particular embodiments, the one or more processors 202 can include at least a secure processor 230. The secure processor 230 may be a processor that is housed in a secured or fortified part of the point-of-interaction device 100, may be configured to control the high- security functions of the point-of-interaction device 100, including but not limited to, managing encryption keys and libraries 234 and / or protocols (e.g., VeriShield Crypto Library, AES, etc.), encrypting and decrypting sensitive cardholder information, managing card-reading interface modules 101 to receive and process sensitive cardholder information, receive and transmit sensitive cardholder information to external destinations, and / or the like.
[0045] In further embodiments, the one or more processors 202 can also include at least an application processor 232. The application processor 232 may be housed within the point-of- interaction device 100 and may be configured to control the less sensitive functions of the point-of-interaction device 100, including but not limited to controlling the display 114.
[0046] As described herein, the one or more processors 202 may include a microprocessor, a multi-core processor, a multithreaded processor, an ultra-low voltage processor, an embedded processor, and / or the like, including combinations thereof. The one or more processors 202 can include multiple processor cores on a single die and / or may be a part of a system on a chip (SoC) in which the processor 202 and other components are formed into a single integrated circuit, or a single package. That is, the one or more processors 202 may be a single processor, multiple independent processors, or multiple processor cores on a single die.
[0047] In embodiments, the user interface 112 may be configured to receive various forms of input from a user associated with the point-of-interaction device 100. The user interface 208 can include, but is not limited to, one or more of a keyboard, keypad, trackpad, trackball(s), capacitive keyboard, controller (e.g., a gaming controller), computer mouse, computer stylus / pen, a voice input device, and / or the like, including combinations thereof.
[0048] In embodiments, the display device 114 may be configured to display information, including text, graphs, and / or the like. In particular embodiments, the display device 114 may be configured to display transaction information related to one or more payment transactions.PATENTDocket No.: VFI-1059-WOThe display device 114 can include, but is not limited to, a liquid crystal display (LCD), a lightemitting diode (LED) display, a touch screen or other touch-enabled display, a foldable display, a projection display, and so on, or combinations thereof.
[0049] In embodiments, the input / output (I / O) interface 212 may be configured to connect and / or enable communication with one or more peripheral devices (not shown), including but not limited to additional machine-readable memory devices, diagnostic equipment, and other attachable devices. The EO interface 212 may include one or more EO ports that provide a physical connection to the one or more peripheral devices. In some embodiments, the EO interface 212 may include one or more serial ports.
[0050] In embodiments, the networking unit 214 may include one or more types of networking interfaces that facilitate wired and / or wireless communication between the point- of-interaction device 100 and one or more external devices. That is, the networking unit 214 may operatively connect the point-of-interaction device 100 to one or more types of communications networks, which can include a direction interconnection, the Internet, a local area network (“LAN”), a metropolitan area network (“MAN”), a wide area network (“WAN”), a wired or Ethernet connection, a wireless connection, a cellular network, and similar types of communications networks, including combinations thereof. In some embodiments, the point- of-interaction device 100 may communicate with one or more remote / cloud-based servers and / or cloud-based services, in order to verify payment card information and process financial transactions.
[0051] In embodiments, the memory 204 can be variously embodied in one or more forms of machine accessible and machine-readable memory. In some embodiments, the memory 204 includes a storage device (not shown), which can include, but is not limited to, a non-transitory storage medium, a magnetic disk storage, an optical disk storage, an array of storage devices, a solid-state memory device, and / or the like, as well as combinations thereof. The memory 204 may also include one or more other types of memory, such as dynamic random-access memory (DRAM), static random-access memory (SRAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), Flash memory, and / or the like, as well as combinations thereof. In embodiments, the memory 204 may include a combination of different types of memory, including different types of transitory memory and different types of non-transitory memory.
[0052] The point-of-interaction device 100 can be configured by software components stored in the memory 204 to perform one or more processes of the methods described herein.PATENTDocket No.: VFI-1059-WOMore specifically, the memory 204 can be configured to store data / information 220 and machine-readable instructions 222 that, when executed by the one or more processors 202, causes the point-of-interaction device 100 to enact countermeasures obfuscating or otherwise protecting the cardholder information transmitted to the smartcard interface module 102. Such data 220 and the machine-readable instructions 222 stored in the memory 204 may form a smartcard security package 224 that may be incorporated into, loaded from, loaded onto, or otherwise operatively available to and from the point-of-interaction device 100. Thus, in some embodiments, the smartcard security package 224 and / or one or more individual software packages may be stored in a local storage device of the memory 204. However, in other embodiments, the smartcard security package 224 and / or one or more individual software packages may be loaded onto and / or updated from a remote server or service via a communications network.
[0053] In particular embodiments, the memory 204 may be configured to store a cryptographic library 234, including the algorithms and keys necessary to support the secure encryption / decryption functions of the point-of-interaction device 100. In embodiments, the portion of the memory 204 storing the cryptographic library 234 may be disposed within a secured or fortified section of the point-of-interaction device 100 along with the secure processor 230.
[0054] In further embodiments, the memory 204 may include an application program interface (API) 236 configured to facilitate the low-security features of the point-of-interaction device 100, as described above. In certain embodiments, this may include operating the display device 114, generating / printing receipts, and / or the like. The API 236 may be based on or otherwise compatible with one or more types of operating systems 226, including but not limited to Verifone Secure OS, Engage VOS2, VAOS based on Android, and / or the like.
[0055] Accordingly, provided herein is a computer program product 224 comprising a non- transitory computer-readable storage medium 204 having stored thereon computer-readable instructions 222 that, when executed by one or more processors (such as processors 202), cause the one or more processors to perform one or more operations of the methods described below. For example, in specific embodiments, the computer-readable storage medium 204 may include computer-readable instructions 222 that, when executed by one or more processors (such as processors 202), cause the one or more processors to perform the following operations: (i) detecting whether a payment card 104 has been inserted into the smartcard interface module 102 of the point-of-interaction device 100; and (ii) if a payment card 104 is not detected,PATENTDocket No.: VFI-1059-WO generating an electrical signal across at least a first pin of the pin set (discussed in more detail below) of the smartcard interface module, wherein the electrical signal communicates either (a) at least one fake customer record, or (b) an increased voltage through at least the first pin of the pin set.
[0056] More particularly, the computer-readable storage medium 204 can include computer-readable instructions 222 that, when executed by one or more processors (such as processors 202), cause the one or more processors to perform a method for obfuscating smartcard data from a payment card in accordance with the various aspects described herein.
[0057] For example, with reference to FIG. 5, a method 500 for obfuscating smartcard data from a payment card is illustrated in accordance with certain aspects of the present disclosure. As shown, the method 500 can include performing the following operations within a point-of- interaction device (e.g., point-of-interaction device 100, etc.): in a step 510, detecting whether a payment card 104 has been inserted into the smartcard interface module 102 of the point-of- interaction device 100; and in a step 520, if a payment card 104 is not detected, generating an electrical signal across at least a first pin of the pin set of the smartcard interface module, wherein the electrical signal communicates either (a) at least one fake customer record, or (b) an increased voltage through at least the first pin of the pin set.
[0058] More specifically, in the step 510, the method 500 includes detecting whether a payment card 104 is presently inserted into the smartcard interface module 102 of the point-of- interaction device 100. If a payment card 104 is detected, that indicates that a transaction may be occurring and the method 500 should pause. In other words, the point-of-interaction device 100 is preferably configured to cryptographically verify smartcard data from a payment card 104 if the payment card 104 is detected in the step 510, such that point-of-interaction device 100 can complete a financial transaction.
[0059] In embodiments, the payment card 104 may be detected via one or more card insertion switches 240 as shown in the example of FIG. 3. In some embodiments, the card insertion switch 240 may be a physical device that is triggered when a payment card 104 is inserted into the smartcard interface module 102. However, other embodiments are contemplated.
[0060] According to the method 500, if a payment card 104 is not detected within the smartcard interface module 102, the point-of-interaction device 100 may proceed to the step 520, where an electrical signal is generated across at least one pin 420, 422, 424, 426, 428, 430, 432, 434 of the pin set 401 of the smartcard interface module 102. Put another way, the point-PATENTDocket No.: VFI-1059-WO of-interaction device 100 may only proceed to the step 520 when a payment card 104 is not detected and it is therefore safe to proceed without damaging a customer’s card.
[0061] As discussed in more detail below, the electrical signal generated across the one or more pins 420, 422, 424, 426, 428, 430, 432, 434 of the pin set 401 of the smartcard interface module 102 may communicate either: (i) at least one fake customer record; or (ii) an increased voltage through the one or more pins 420, 422, 424, 426, 428, 430, 432, 434 of the pin set 401.
[0062] For example, according to one embodiment of the present disclosure, the one or more processors 202 (e.g., the secure processor 230 and / or the application processor 232, etc.) may be configured to generate electrical signals on the system 206 that causes the smartcard interface module 102 to generate electrical activity on the one or more pins 420, 422, 424, 426, 428, 430, 432, 434 of the pin set 401. In some embodiments, only the secure processor 230 may be aware of whether a smartcard 104 is present within the POI device 100, and therefore the secure processor 230 may preferably generate this electrical activity. Alternatively, the application processor 232 may query the secure processor 230 regarding the smartcard insertion status, and if the secure processor 230 reports that no smartcard 104 is present, the application processor 232 may generate this electrical activity. In particular embodiments, the application processor 232 may preferably generate the electrical activity if the secure processor 230 is put into a low-power sleep mode, thereby enabling “bug” disablement even in a low- power configuration.
[0063] In particular embodiments, the electrical signal(s) generated by the one or more processors 202 would mimic a real transaction such that at least one fake customer record containing fake cardholder data is communicated through one or more pins 420, 422, 424, 426, 428, 430, 432, 434 of the pin set 401. In specific embodiments, the electrical signal(s) may be generated so as to create fake traffic across the I / O pin 430 of the pin set 401 of the smartcard interface module 102. In other embodiments, the electrical signal(s) generated by the one or more processors 202 may not simulate a real transaction, but instead contain invalid, random, or unexpected data and / or data types, thereby causing any rogue electronics to become nonoperative.
[0064] While the point-of-interaction device 100 remains in a state of inactivity (e.g., no payment cards 104 are detected), the one or more processors 202 may generate a plurality of fake customer records. In embodiments, the one or more processors 202 may generate fake customer records at random times while the point-of-interaction device 100 remains inactive, or may generate such customer records periodically or pseudo-periodically. In particularPATENTDocket No.: VFI-1059-WO embodiments, the one or more processors 202 can be configured to generate fake customer records at a rate of between 10 records per hour and 36,000 records per hour, including at least about 1 record per second, while the point-of-interaction device 100 remains inactive.
[0065] In embodiments, the fake customer record can include, but is not limited to, a fake cardholder PIN, a fake cardholder PAN, a fake cardholder CVC, a fake cardholder name, a fake cardholder address, a fake cardholder zip code, and / or the like, including combinations thereof. As such, the fake customer record may resemble an actual customer transaction record, but contains a set of fake transaction-related parameters that cannot be exploited. For example, the tables below illustrates an example of three fake customer records:PATENTDocket No.: VFI-1059-WO
[0066] As described herein, it will be appreciated that a rogue electronic device (e.g., a shim, etc.) that is attempting to monitor the traffic between a smart chip 116 of a payment card 104 and the pin set 401 of a smartcard interface module 102 will perceive the fake customer records as legitimate transaction information because the electrical signal(s) are communicated through the one or more pins 420, 422, 424, 426, 428, 430, 432, 434 of the pin set 401 of the smartcard interface module 102. Therefore, the rogue electronic device will store these fake customer records within its limited memory storage. As such, the limited memory of the rogue electronic device can be completely filled-up with useless data within minutes or hours. For example, if a rogue electronic device is configured to hold about 40,000 transaction records, the device’s memory can be filled in less than half a day by faking one transaction per second of terminal activity.
[0067] According to another embodiment of the present disclosure, the point-of-interaction device 100 may be configured to include a direct connection between the one or more processors 202 (e.g., the secure processor 230 and / or the application processor 232, etc.) and the one or more pins 420, 422, 424, 426, 428, 430, 432, 434 of the pin set 401 of the smartcard interface module 102. For example, the one or more processors 202 may include at least one or a plurality of unused general purpose input output (GPIO) pins that can be connected to, for example, the I / O pin 430 of the pin set 401, which can then be used to generate electrical signals on connected pin(s) of the pin set 401 as described above.
[0068] According to still another embodiment of the present disclosure, the point-of- interaction device 100 may be configured with a dedicated burnout device that is operatively connected to and controlled by the one or more processors 202 (e.g., the secure processor 230 and / or the application processor 232, etc.). In this embodiment, the one or more processors 202PATENTDocket No.: VFI-1059-WO can be configured to generate an electrical signal that is an increased voltage across one or more pins 420, 422, 424, 426, 428, 430, 432, 434 of the pin set 401 of the smartcard interface module 102.
[0069] As described herein, it will be appreciated that smartcards 104 can be configured to operate at particular DC voltages. For example, under certain industry standards, the smart chips 116 of a payment card 104 may be configured to operate one or more voltages, such as 5V, 3.3V (or 3V), or 1.8V. Generally, the point-of-interaction device 100 may determine the proper voltage to apply to a smart chip 116 when a payment card 104 is inserted. To achieve this, the point-of-interaction device 100 may first apply a 1.8V current and determines whether an appropriate response to a reset signal is received (e.g., via the RST pins 122, 422). If there is no answer to the reset signal sent by the smartcard interface module 102, then the voltage is switched up to the next pre-determined level (e.g., 3.0V or 3.3V), and the reset signal is tried again.
[0070] Importantly, like the smart chips 116 of various types of payment cards 104, rogue electronic devices also operate at particular DC voltages. If the power supply is incorrect, the circuit (e.g., the rogue electronic device, the smart chip 116, etc.) will be damaged. Thus, by providing an overvoltage, any rogue electronic device attached to the smartcard interface module 102 can be destroyed.
[0071] With reference to FIG. 6, a block diagram of a point-of-interaction device 100 comprising a dedicated burnout device 600 is illustrated according to certain aspects of the present disclosure. As shown, the burnout device 600 can include: (1) a power adapter 602 configured to receive a power supply from a power source; (2) a power management integrated circuit (PMIC) 604 configured to receive the power supply and generate different DC voltage rails, including at least one high-voltage rail; and (3) a burnout circuit 606 configured to receive a switch signal from the one or more processors 202 and facilitate the generation of an increased DC voltage across one or more pins 420, 422, 424, 426, 428, 430, 432, 434 of the pin set 401 of the smartcard interface module 102.
[0072] In embodiments, the power adapter 602 can be a 12V power connection that is configured to receive a 12V DC power supply from an external power source. However, other power connections are possible, including, for example, a 24V DC power supply.
[0073] In embodiments, the PMIC 604 is configured to generate a plurality of DC voltage rails, including but not limited to a 1.8V power rail, a 3.0V power rail, a 3.3V power rail, aPATENTDocket No.: VFI-1059-WO5.0V power rail, and a high-voltage power rail. In particular embodiments, the high-voltage power rail is greater than 5 V, including at least about 12V.
[0074] In embodiments, the burnout circuit 606 is configured to receive a signal (‘ZAP’) from the one or more processors 202 that triggers the burnout circuit 606 to connect the high- voltage power rail to one or more pins 420, 422, 424, 426, 428, 430, 432, 434 of the pin set 401 of the smartcard interface module 102. In particular embodiments, the burnout circuit 606 may be connected to the one or more processors 202 via a dedicated GPIO line, and may include a relay and / or a field effect transistor (FET) that, when turned on, applies the increased voltage to one or more pins 420, 422, 424, 426, 428, 430, 432, 434 of the pin set 401 of the smartcard interface module 102.
[0075] With reference to FIG. 7, a circuit diagram showing an exemplary embodiment of a burnout device 600 is illustrated in accordance with these and further aspects of the present disclosure. As shown, the burnout device 600 includes a power adapter 602 operatively connected to a PMIC 604 that is configured to provide a plurality of power rails having different voltages. During normal operation of a point-of-interaction device 100 comprising the burnout device 600, the power adapter 602 and PMIC 604 will provide the appropriate voltage for each payment card 104 presented for transaction using the switch ‘SI’, which may be controlled by the one or more processors 202. When a payment card is not present (as described above with respect to the method 500), a burnout circuit 606 is controlled to connect a high-voltage power rail 700 to one or more pins 420, 422, 424, 426, 428, 430, 432, 434 (illustrated in FIG. 7 as channels Cl through C8) of the pin set 401 of the smartcard interface module 102.
[0076] In particular embodiments, the burnout circuit 606 may be operated such that the high-voltage rail 700 remains connected to the one or more pins 420, 422, 424, 426, 428, 430, 432, 434 for a period of time, such as between 1 and 5 seconds. In further embodiments, the burnout circuit 606 may be operated to provide the increased voltage one or more times at periodic, pseudo-periodic intervals, or random intervals.
[0077] As shown in the example of FIG. 7, the burnout device 600 may also include a burnout circuit 702 that blocks the increased voltage from harming other components of the smartcard interface module 102. In embodiments, the burnout circuit 702 can include at least one diode and / or transient voltage suppressor (TVS). As also shown in the example of FIG. 7, it should be appreciated that the high-voltage rail 700 may be connected to different pins 420, 422, 424, 426, 428, 430, 432, 434. In particular embodiments, the high-voltage rail 700 may be connected to the VO pin 430.PATENTDocket No.: VFI-1059-WO
[0078] In addition to neutralizing a rogue electronic device by providing an overvoltage of direct current, it should be appreciated that certain rogue electronic devices may also be neutralized by providing an alternating current. That is, rogue electronic devices are commonly designed to tolerate certain DC voltages, but may not support an AC voltage. Accordingly, in certain embodiments, a dedicated burnout device may be configured to deliver an AC voltage across one or more 420, 422, 424, 426, 428, 430, 432, 434 of the pin set 401 of the smartcard interface module 102. In such embodiments, the dedicated burnout device may include: (1) a power adapter (e.g., power adapter 602) configured to receive a power supply from a power source; (2) a PMIC (e.g., PMIC 604) configured to receive the power supply and generate different DC voltage rails; and (3) a burnout circuit configured to receive a switch signal from the one or more processors 202 and facilitate the supply of an alternating current to one or more pins 420, 422, 424, 426, 428, 430, 432, 434 of the pin set 401 of the smartcard interface module 102. In particular embodiments, the burnout circuit comprises a switch circuit responsive to the switch signal and a DC-to-AC circuit operatively connected to the switch circuit, wherein the DC-to-AC circuit is configured to take one of the DC power rails, generate an alternating current from the DC power rail, and apply the alternating current to one or more 420, 422, 424, 426, 428, 430, 432, 434 of the pin set 401 of the smartcard interface module 102 based on the switch signal.
[0079] It should be appreciated that all combinations of the foregoing concepts and additional concepts discussed in greater detail below (provided such concepts are not mutually inconsistent) are contemplated as being part of the inventive subject matter disclosed herein. In particular, all combinations of claimed subject matter appearing at the end of this disclosure are contemplated as being part of the inventive subject matter disclosed herein. It should also be appreciated that terminology explicitly employed herein that also may appear in any disclosure incorporated by reference should be accorded a meaning most consistent with the particular concepts disclosed herein.
[0080] All definitions, as defined and used herein, should be understood to control over dictionary definitions, definitions in documents incorporated by reference, and / or ordinary meanings of the defined terms.
[0081] The indefinite articles “a” and “an,” as used herein in the specification and in the claims, unless clearly indicated to the contrary, should be understood to mean “at least one.”
[0082] The phrase “and / or,” as used herein in the specification and in the claims, should be understood to mean “either or both” of the elements so conjoined, i.e., elements that arePATENTDocket No.: VFI-1059-WO conjunctively present in some cases and disjunctively present in other cases. Multiple elements listed with “and / or” should be construed in the same fashion, i.e., “one or more” of the elements so conjoined. Other elements may optionally be present other than the elements specifically identified by the “and / or” clause, whether related or unrelated to those elements specifically identified.
[0083] As used herein in the specification and in the claims, “or” should be understood to have the same meaning as “and / or” as defined above. For example, when separating items in a list, “or” or “and / or” shall be interpreted as being inclusive, i.e., the inclusion of at least one, but also including more than one, of a number or list of elements, and, optionally, additional unlisted items. Only terms clearly indicated to the contrary, such as “only one of’ or “exactly one of,” or, when used in the claims, “consisting of,” will refer to the inclusion of exactly one element of a number or list of elements. In general, the term “or” as used herein shall only be interpreted as indicating exclusive alternatives (i.e., “one or the other but not both”) when preceded by terms of exclusivity, such as “either,” “one of,” “only one of,” or “exactly one of.”
[0084] As used herein in the specification and in the claims, the phrase “at least one,” in reference to a list of one or more elements, should be understood to mean at least one element selected from any one or more of the elements in the list of elements, but not necessarily including at least one of each and every element specifically listed within the list of elements and not excluding any combinations of elements in the list of elements. This definition also allows that elements may optionally be present other than the elements specifically identified within the list of elements to which the phrase “at least one” refers, whether related or unrelated to those elements specifically identified.
[0085] As used herein, although the terms first, second, third, etc. may be used herein to describe various elements or components, these elements or components should not be limited by these terms. These terms are only used to distinguish one element or component from another element or component. Thus, a first element or component discussed below could be termed a second element or component without departing from the teachings of the inventive concept.
[0086] Unless otherwise noted, when an element or component is said to be “connected to,” “coupled to,” or “adjacent to” another element or component, it will be understood that the element or component can be directly connected or coupled to the other element or component, or intervening elements or components may be present. That is, these and similar terms encompass cases where one or more intermediate elements or components may be employedPATENTDocket No.: VFI-1059-WO to connect two elements or components. However, when an element or component is said to be “directly connected” to another element or component, this encompasses only cases where the two elements or components are connected to each other without any intermediate or intervening elements or components.
[0087] In the claims, as well as in the specification above, all transitional phrases such as “comprising,” “including,” “carrying,” “having,” “containing,” “involving,” “holding,” “composed of,” and the like are to be understood to be open-ended, i.e., to mean including but not limited to. Only the transitional phrases “consisting of’ and “consisting essentially of’ shall be closed or semi -closed transitional phrases, respectively.
[0088] It should also be understood that, unless clearly indicated to the contrary, in any methods claimed herein that include more than one step or act, the order of the steps or acts of the method is not necessarily limited to the order in which the steps or acts of the method are recited.
[0089] The above-described examples of the described subject matter can be implemented in any of numerous ways. For example, some aspects can be implemented using hardware, software or a combination thereof. When any aspect is implemented at least in part in software, the software code can be executed on any suitable processor or collection of processors, whether provided in a single device or computer or distributed among multiple devices / computers.
[0090] The present disclosure can be implemented as a system, a method, and / or a computer program product at any possible technical detail level of integration. The computer program product can include a computer readable storage medium (or media) having computer readable program instructions thereon for causing a processor to carry out aspects of the present disclosure.
[0091] The computer readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device. The computer readable storage medium can be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of the computer readable storage medium comprises the following: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), aPATENTDocket No.: VFI-1059-WO digital versatile disk (DVD), a memory stick, a floppy disk, a mechanically encoded device such as punch-cards or raised structures in a groove having instructions recorded thereon, and any suitable combination of the foregoing. A computer readable storage medium, as used herein, is not to be construed as being transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission media (e.g., light pulses passing through a fiber-optic cable), or electrical signals transmitted through a wire.
[0092] Computer readable program instructions described herein can be downloaded to respective computing / processing devices from a computer readable storage medium or to an external computer or external storage device via a network, for example, the Internet, a local area network, a wide area network and / or a wireless network. The network can comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and / or edge servers. A network adapter card or network interface in each computing / processing device receives computer readable program instructions from the network and forwards the computer readable program instructions for storage in a computer readable storage medium within the respective computing / processing device.
[0093] Computer readable program instructions for carrying out operations of the present disclosure can be assembler instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine dependent instructions, microcode, firmware instructions, statesetting data, configuration data for integrated circuitry, or either source code or object code written in any combination of one or more programming languages, comprising an object oriented programming language such as Smalltalk, C++, or the like, and procedural programming languages, such as the “C” programming language or similar programming languages. The computer readable program instructions can execute entirely on the user’s computer, partly on the user’s computer, as a stand-alone software package, partly on the user’s computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, comprising a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider). In some examples, electronic circuitry comprising, for example, programmable logic circuitry, field-programmable gate arrays (FPGA), or programmable logic arrays (PLA) can execute the computer readable program instructions by utilizing statePATENTDocket No.: VFI-1059-WO information of the computer readable program instructions to personalize the electronic circuitry, in order to perform aspects of the present disclosure.
[0094] Aspects of the present disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to examples of the disclosure. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer readable program instructions.
[0095] The computer readable program instructions can be provided to a processor of a, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. These computer readable program instructions can also be stored in a computer readable storage medium that can direct a computer, a programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer readable storage medium having instructions stored therein comprises an article of manufacture comprising instructions which implement aspects of the function / act specified in the flowchart and / or block diagram or blocks.
[0096] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process, such that the instructions which execute on the computer, other programmable apparatus, or other device implement the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0097] The flowchart and block diagrams in the Figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various examples of the present disclosure. In this regard, each block in the flowchart or block diagrams can represent a module, segment, or portion of instructions, which comprises one or more executable instructions for implementing the specified logical function(s). In some alternative implementations, the functions noted in the blocks can occur out of the order noted in the Figures. For example, two blocks shown in succession can, in fact, be executed substantially concurrently, or the blocks can sometimes be executed in the reverse order, depending upon the functionality involved. It will also be notedPATENTDocket No.: VFI-1059-WO that each block of the block diagrams and / or flowchart illustration, and combinations of blocks in the block diagrams and / or flowchart illustration, can be implemented by special purpose hardware-based systems that perform the specified functions or acts or carry out combinations of special purpose hardware and computer instructions.
[0098] Other implementations are within the scope of the following claims and other claims to which the applicant can be entitled.
[0099] While several inventive embodiments have been described and illustrated herein, those of ordinary skill in the art will readily envision a variety of other means and / or structures for performing the function and / or obtaining the results and / or one or more of the advantages described herein, and each of such variations and / or modifications is deemed to be within the scope of the inventive embodiments described herein. More generally, those skilled in the art will readily appreciate that all parameters, dimensions, materials, and configurations described herein are meant to be exemplary and that the actual parameters, dimensions, materials, and / or configurations will depend upon the specific application or applications for which the inventive teachings is / are used. Those skilled in the art will recognize, or be able to ascertain using no more than routine experimentation, many equivalents to the specific inventive embodiments described herein. It is, therefore, to be understood that the foregoing embodiments are presented by way of example only and that, within the scope of the appended claims and equivalents thereto, inventive embodiments may be practiced otherwise than as specifically described and claimed. Inventive embodiments of the present disclosure are directed to each individual feature, system, article, material, kit, and / or method described herein. In addition, any combination of two or more such features, systems, articles, materials, kits, and / or methods, if such features, systems, articles, materials, kits, and / or methods are not mutually inconsistent, is included within the inventive scope of the present disclosure.
Claims
PATENTDocket No.: VFI-1059-WOClaimsWhat is claimed is:
1. A point-of-interaction device comprising: at least one processor; a smartcard interface module operatively connected to the at least one processor and comprising a pin set including at least a first pin configured to communicate electrical signals; and a memory storing machine-readable instructions that, when executed by the at least one processor, causes the point-of-interaction device to perform the following operations: generate, via the at least one processor, an electrical signal across at least the first pin of the pin set of the smartcard interface module, wherein the electrical signal communicates either (i) at least one fake customer record, or (ii) an increased voltage through at least the first pin of the pin set.
2. The point-of-interaction device of claim 1, further comprising a smartcard insertion switch configured to detect physical insertion of a customer smartcard into the smartcard interface module of the point-of-interaction device.
3. The point-of-interaction device of claim 2, wherein the memory further stores machine-readable instructions that, when executed by the at least one processor, causes the point-of-interaction device to perform the following operations: detecting, via the smartcard insertion switch, whether a customer smartcard has been inserted into the smartcard interface module of the point-of-interaction device; and generate, via the at least one processor, the electrical signal across at least the first pin of the pin set only if the smartcard insertion switch indicates that a customer smartcard is not present within the smartcard interface module.
4. The point-of-interaction device of claim 1, wherein the electrical signal communicates a plurality of fake customer records across at least the first pin of the pin set of the smartcard interface module.PATENTDocket No.: VFI-1059-WO5. The point-of-interaction device of claim 4, wherein the electrical signal communicates the plurality of fake customer records at a rate of at least one fake customer record per second of terminal inactivity.
6. The point-of-interaction device of claim 1, wherein each fake customer record comprises a fake cardholder PIN, a fake cardholder PAN, a fake cardholder CVC, a fake cardholder name, a fake cardholder address, and / or a fake cardholder zip code.
7. The point-of-interaction device of claim 1, wherein the electrical signal is generated across at least the first pin of the pin set of the smartcard interface module by simulating, via the at least one processor and the smartcard interface module, a transaction with a non-existent customer smartcard.
8. The point-of-interaction device of claim 1, wherein the electrical signal is directly generated across at least the first pin of the pin set of the smartcard interface module using an input / output (I / O) line connecting an I / O pin of the at least one processor with at least the first pin.
9. The point-of-interaction device of claim 1, further comprising: a power management integrated circuit configured to provide a plurality of voltage rails for operating the point-of-interaction device; and a burnout circuit operatively connecting a high-voltage rail of the plurality of voltage rails with at least the first pin of the pin set of the smartcard interface module; wherein the burnout circuit receives the electrical signal from the at least one processor and generates an increased voltage through at least the first pin of the pin set using the power management integrated circuit.
10. The point-of-interaction device of claim 9, wherein the high-voltage rail provides an increased voltage that is greater than about 5 volts.
11. The point-of-interaction device of claim 10, wherein the high-voltage rail provides an increased voltage that is about 12 volts.PATENTDocket No.: VFI-1059-WO12. A burnout device comprising: a smartcard interface module comprising a pin set including at least a first pin configured to communicate electrical signals; a power management integrated circuit configured to provide a plurality of voltage rails; and a burnout circuit operatively connecting a high-voltage rail of the plurality of voltage rails with at least the first pin of the pin set of the smartcard interface module; wherein the burnout circuit is configured to receive an electrical signal from at least one processor of an associated point-of-interaction device and generate an increased voltage through at least the first pin of the pin set using the power management integrated circuit.
13. The burnout device of claim 12, wherein the high-voltage rail provides an increased voltage that is greater than about 5 V.
14. The burnout device of claim 13, wherein the high-voltage rail provides an increased voltage that is at least about 12V.
15. A computer-implemented method of obfuscating smartcard data from a payment card, the method comprising: in a point-of-interaction device comprising at least one processor operatively connected to a smartcard insertion switch and a smartcard interface module having a pin set that includes at least a first pin configured to communicate electrical signals: detecting, via the smartcard insertion switch, whether a payment card has been inserted into the smartcard interface module; and if a payment card is not detected, generating, an electrical signal across at least the first pin of the pin set of the smartcard interface module, wherein the electrical signal communicates either (i) at least one fake customer record, or (ii) an increased voltage through at least the first pin of the pin set.
16. The computer-implemented method of claim 15, wherein the electrical signal communicates a plurality of fake customer records across at least the first pin of the pin set of the smartcard interface module.PATENTDocket No.: VFI-1059-WO17. The computer-implemented method of claim 16, wherein the electrical signal communicates the plurality of fake customer records at a rate of at least one fake customer record per second of terminal inactivity.
18. The computer-implemented method of claim 15, wherein the electrical signal is generated across at least the first pin of the pin set of the smartcard interface module by simulating, via the at least one processor and the smartcard interface module, a transaction with a non-existent customer smartcard.
19. The computer-implemented method of claim 15, the electrical signal is directly generated across at least the first pin of the pin set of the smartcard interface module using an input / output (I / O) line connecting an I / O pin of the at least one processor with at least the first pin.
20. The computer-implemented method of claim 15, wherein the point-of- interaction device further comprises a burnout device, and the method further comprises: receiving, at a burnout circuit of the burnout device, an instruction to generate an increased voltage through at least the first pin of the pin set; and directing, via the burnout circuit of the burnout device, an increased voltage through at least the first pin of the pin set; wherein the increased voltage is greater than 5 V.
Citation Information
Patent Citations
Automated banking machine that outputs interference signals to jam reading ability of unauthorized card reader devices
US20140158768A1
Tamper detection system
US9892293B1
Line-based chip card tamper detection
WO2018156742A1