Card Reading Terminal Secure Channel Key Derivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current card reading terminals lack secure processing of communication data between the terminal and the card, making it vulnerable to interception and tampering, resulting in a low security level.
Innovation Solution
A card reading terminal method and apparatus that establishes a secure channel by determining instruction types, acquiring card parameters, deriving keys, generating random data packages, and obtaining session keys to encrypt and decrypt communication data, ensuring secure transmission and reception of data between the terminal and the card.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure channel establishment and encryption processes are implemented, then communication security is improved, but device complexity increases
Solution Approach 1:
The patent implements preliminary action by establishing secure channels and deriving encryption keys before actual card communication begins. The terminal performs key derivation from card data, establishes authenticated secure channels, and prepares encryption/decryption mechanisms in advance, so that when communication occurs, security processing is already in place and can operate efficiently without adding complexity to the communication flow.
Solution Approach 2:
The patent uses an intermediary approach by introducing a secure channel as a mediator between the terminal and card. This secure channel, established through authentication and key exchange, acts as an intermediate layer that handles encryption and decryption of communication data, thereby protecting security without requiring the terminal's main processing logic to be complex.
2Reliability
If secure channel establishment with multiple authentication steps is performed, then communication security is improved, but communication time increases
Solution Approach 1:
The patent applies preliminary action by completing the time-consuming authentication and key derivation processes before actual card reading operations. The secure channel is established once, and subsequent communications use this pre-established channel with cached session keys, avoiding repeated authentication overhead for each card operation.
Solution Approach 2:
The patent implements partial action by performing full authentication and key derivation only when needed (e.g., when card data changes or secure channel needs refresh), rather than for every single communication. The system balances security with efficiency by selectively applying the complete authentication sequence only when necessary.
Data Source
AI summary
A card reading terminal. The card reading terminal comprises a receiving module, a first determining module, a first judging module, a first acquiring module, a second determining module, a second acquiring module, a third acquiring module, a first obtaining module, a fourth acquiring module, a first decrypting module, a generating module, a second obtaining module, an updating module, a third obtaining module, a fourth obtaining module, a reading module, a second judging module, an identifying module, a fifth obtaining module, a third judging module, an executing module, a fifth acquiring module, a sixth acquiring module, an encrypting module, a second decrypting module, and a sending module. According to the present invention, communication data between the card reading terminal and a card is secured, and is thus difficult to be intercepted, leaked, or tampered with, such that security is great improved.


