Card Reader Cryptographic Verification Against Deep-Insert Skimmers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Deep insert skimmers pose a significant threat to retailers by allowing thieves to bypass existing security measures and insert skimmers into card readers, which cannot be detected without removing and inspecting the card reader.

Innovation Solution

A cryptographic token approach is implemented using an Encrypted Personal Identification Number (PIN) Pad (EPP) to generate, verify, and distribute cryptographic tokens to the card reader, ensuring its authenticity and preventing unauthorized operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware sensors are added to detect skimmers, then detection capability is improved, but device complexity and cost increase

Engineering Contradiction:
Improveskimmer detection capabilityVSAvoidcard reader complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces mechanical sensor-based detection systems with a cryptographic authentication system. Instead of using physical sensors to detect skimmers, the system uses cryptographic tokens and encryption to verify the authenticity of card readers, thereby eliminating the need for complex hardware modifications while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a cryptographic intermediary system that mediates between the terminal and card reader. The EPP (Encrypted PIN Pad) acts as an intermediary that generates and verifies cryptographic tokens, providing a layer of security without requiring direct physical interaction or complex sensor arrays.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If card readers are removed and inspected to detect deep insert skimmers, then detection accuracy is improved, but time loss and operational disruption increase

Engineering Contradiction:
Improveskimmer detection accuracyVSAvoidterminal downtime
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary cryptographic verification before the card reader is authorized to operate. By verifying the authenticity of the card reader through cryptographic tokens during the initialization phase, the system prevents skimmers from gaining access without requiring physical inspection after installation, thus avoiding operational disruption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes a feedback mechanism where the EPP continuously verifies the card reader's authenticity through cryptographic token validation. This ongoing verification provides immediate feedback on skimmer presence without requiring physical inspection, allowing for real-time detection and response.

Inventive Principle:
Principle #23Feedback

3Reliability

If skimmer detection requires physical inspection, then detection reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveskimmer detection reliabilityVSAvoidterminal operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical inspection process with an automated cryptographic verification system. The EPP automatically validates card reader authenticity using cryptographic tokens, eliminating the need for manual physical inspection while maintaining high detection reliability and improving operational simplicity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250292238A1Card reader verification
Publication Date: 2025.09.18 NCR VOYIX CORP
  • US20250292238A1 patent drawing
  • US20250292238A1 patent drawing
  • US20250292238A1 patent drawing

AI summary

A card reader of a terminal is cryptographically verified upon initialization, power up, connection, or start of day processing of the terminal. A cryptographic and signed token is provided from and verified by an Encrypted Personal Identification Number (PIN) pad (EPP) of the terminal. Each time the reader initializes, the token is verified by the EPP and a new token is generated and provided to the reader for use during a next initialization cycle of the reader. If the reader lacks a token when the EPP has record that is should have the token, the reader is not authorized to perform card transactions for the terminal. If a token provided by the reader during an initialization cycle is not verified, the reader is not authorized to perform card transactions for the terminal.