Card Reader Cryptographic Verification Against Deep-Insert Skimmers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Deep insert skimmers pose a significant threat to retailers by allowing thieves to bypass existing security measures and insert skimmers into card readers, which cannot be detected without removing and inspecting the card reader.
Innovation Solution
A cryptographic token approach is implemented using an Encrypted Personal Identification Number (PIN) Pad (EPP) to generate, verify, and distribute cryptographic tokens to the card reader, ensuring its authenticity and preventing unauthorized operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware sensors are added to detect skimmers, then detection capability is improved, but device complexity and cost increase
Solution Approach 1:
The patent replaces mechanical sensor-based detection systems with a cryptographic authentication system. Instead of using physical sensors to detect skimmers, the system uses cryptographic tokens and encryption to verify the authenticity of card readers, thereby eliminating the need for complex hardware modifications while maintaining security.
Solution Approach 2:
The patent introduces a cryptographic intermediary system that mediates between the terminal and card reader. The EPP (Encrypted PIN Pad) acts as an intermediary that generates and verifies cryptographic tokens, providing a layer of security without requiring direct physical interaction or complex sensor arrays.
2Measurement precision
If card readers are removed and inspected to detect deep insert skimmers, then detection accuracy is improved, but time loss and operational disruption increase
Solution Approach 1:
The patent implements preliminary cryptographic verification before the card reader is authorized to operate. By verifying the authenticity of the card reader through cryptographic tokens during the initialization phase, the system prevents skimmers from gaining access without requiring physical inspection after installation, thus avoiding operational disruption.
Solution Approach 2:
The system establishes a feedback mechanism where the EPP continuously verifies the card reader's authenticity through cryptographic token validation. This ongoing verification provides immediate feedback on skimmer presence without requiring physical inspection, allowing for real-time detection and response.
3Reliability
If skimmer detection requires physical inspection, then detection reliability is improved, but ease of operation deteriorates
Solution Approach 1:
The patent replaces the mechanical inspection process with an automated cryptographic verification system. The EPP automatically validates card reader authenticity using cryptographic tokens, eliminating the need for manual physical inspection while maintaining high detection reliability and improving operational simplicity.
Data Source
AI summary
A card reader of a terminal is cryptographically verified upon initialization, power up, connection, or start of day processing of the terminal. A cryptographic and signed token is provided from and verified by an Encrypted Personal Identification Number (PIN) pad (EPP) of the terminal. Each time the reader initializes, the token is verified by the EPP and a new token is generated and provided to the reader for use during a next initialization cycle of the reader. If the reader lacks a token when the EPP has record that is should have the token, the reader is not authorized to perform card transactions for the terminal. If a token provided by the reader during an initialization cycle is not verified, the reader is not authorized to perform card transactions for the terminal.


