Certificate Server Terminal Activation Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The security of payment terminals connected to a secure payment network can be compromised by rogue software installed on a central server, which acts as a trusted intermediary between the acquirer network and a second network, due to its third-party control.

Innovation Solution

A terminal configuration network that includes a communications terminal and a certificate server, where the communications terminal generates an activation request with terminal credentials, which are validated by the certificate server to ensure uniqueness, and a digital certificate is generated and used to establish an encrypted channel for secure payload download, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a central server acts as a trusted intermediary between the acquirer network and a second network, then the terminals can access computer servers on the second network through the acquirer network, but the security of the acquirer network can be compromised by rogue software installed on the central server

Engineering Contradiction:
Improveterminal access capabilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a certificate server as a new intermediary that issues digital certificates to terminals. This certificate server validates terminal credentials independently of the central server, creating a distributed trust model. The terminal uses the digital certificate to establish encrypted channels with both the acquirer network and the second network, preventing the central server from compromising security through rogue software.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication and encryption functions by separating the credential validation (performed by the certificate server) from the transaction processing (performed by the central server). The terminal's private key and digital certificate are stored locally, creating independent security modules that prevent a single point of compromise.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If the terminal application communicates with both the acquirer network and the central server, then the terminal can function on the second network, but the security can be compromised by third-party control of the central server

Engineering Contradiction:
Improvenetwork communication capabilityVSAvoidthird-party security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication by requiring the terminal to present a digital certificate issued by a trusted certificate server before establishing communication with the acquirer network. This pre-validation ensures that only authorized terminals can connect, preventing third-party compromises from affecting unauthorized devices.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the mechanical trust relationship (terminal trusting the central server) with a cryptographic trust relationship (terminal trusting its own digital certificate). The terminal uses asymmetric cryptography to establish secure channels without relying on the central server's security, substituting mathematical proofs for organizational trust.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If the central server is controlled by a third party, then the terminal can access the second network, but the acquirer network security becomes vulnerable to rogue software

Engineering Contradiction:
Improvecross-network accessVSAvoidrogue software impact
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The patent introduces a certificate server as an independent intermediary that issues digital certificates to terminals. This certificate server validates terminal credentials independently of the central server, creating a distributed trust model. The terminal uses the digital certificate to establish encrypted channels with both the acquirer network and the second network, preventing the central server from compromising security through rogue software.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the security parameter from trust-based (relying on the central server's integrity) to cryptography-based (relying on digital certificates and encrypted channels). This parameter change makes the system resistant to rogue software because the security depends on mathematical proofs rather than organizational trust.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20210192510A1Method and network for configuring a communications terminal
Publication Date: 2021.06.24 THE TORONTO DOMINION BANK
  • US20210192510A1 patent drawing
  • US20210192510A1 patent drawing
  • US20210192510A1 patent drawing

AI summary

A terminal configuration network includes a communications terminal and a certificate server. The certificate server is configured to receive, from the communications terminal, an activation request that includes at least one credential. The certificate server is configured to confirm that the credential was uniquely associated with the terminal in a database before the server received the activation request. The certificate server is also configured to generate an activation response that includes a digital certificate, and to transmit the response to the terminal. The terminal communications is configured to establish an encrypted channel with a computer server using the digital certificate, and to download a payload to the terminal via the encrypted channel. The computer server is distinct from the certificate server.