Application Package Signing for Secure Transaction Terminal Installation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing platforms for managing and distributing application software on transaction terminals lack robust security measures to prevent malicious downloads and ensure the integrity and reliability of the software installation process.

Innovation Solution

A service platform that provides online application signing, combining signature data from manufacturers and agents with transaction terminals to verify and package applications securely, ensuring only authorized installations occur.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If application software is provided through web technology platforms, then accessibility and distribution are improved, but security and reliability against attacks deteriorate

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by signing the application package before distribution and verifying the signature before installation. The service platform signs the application package with its private key, and the terminal device verifies the signature using the platform's public key, ensuring security is established in advance rather than during installation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The service platform acts as an intermediary between the application developer and the terminal device. It provides certification services by signing application packages, creating a trusted connection that allows widespread distribution while maintaining security through digital signatures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional installation processes are used, then ease of installation is maintained, but security verification and protection against malicious software deteriorate

Engineering Contradiction:
Improveease of installationVSAvoidsecurity verification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The terminal device performs self-service security verification by automatically checking the digital signature of the application package against the service platform's public key before installation. This automated verification process maintains ease of installation while ensuring security, as the device itself performs the verification without requiring user intervention.

Inventive Principle:
Principle #25Self-service

3Reliability

If digital signature verification is implemented, then security and reliability are improved, but installation time and processing overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidinstallation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The digital signature is applied in advance during the application packaging stage by the service platform, so that when the application is installed, the verification process is already prepared. This preliminary signing action reduces the time required during installation, as the verification can proceed efficiently without requiring complex real-time analysis.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12626248B2Method for signing application, and service platform
Publication Date: 2026.05.12 SHENZHEN ZOLON TECH CO LTD
  • US12626248B2 patent drawing
  • US12626248B2 patent drawing
  • US12626248B2 patent drawing

AI summary

The present application provides a method for signing an application, and a transaction terminal. The method includes receiving a download request that is sent by a transaction terminal, and the download request comprising an identification of an application to be installed, and determining an installation package of the application to be installed corresponding to the download request according to the identification, and obtaining signature data associated with the installation package and sending the installation package and the signature data to the transaction terminal, the installation package and the signature data indicating that the transaction terminal obtains a signed application package by combining the installation package and the signature data and installs the installation package after the signed application package is verified.