Checkout System Security Monitoring via Code Hashing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Self-checkout systems in businesses are vulnerable to malicious activity, making it difficult for businesses to determine if a system has been compromised or if user accounts have been tampered with, leading to potential data breaches and loss of sensitive information.

Innovation Solution

A compromise determination system that monitors the execution of code on checkout systems, compares processes to known valid processes, and identifies anomalous user behavior, providing alerts and insights to quickly identify and flag compromised systems and accounts, thereby enhancing network security and protecting sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If businesses deploy numerous checkout systems to reduce labor costs and improve service, then productivity increases, but the risk of security compromise and difficulty in monitoring increases

Engineering Contradiction:
Improvecheckout efficiencyVSAvoidsystem security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments the large-scale checkout network into individually monitorable units by implementing lightweight agents on each checkout system. Each agent independently collects and reports security data, enabling granular monitoring of hundreds or thousands of checkout systems without overwhelming central infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A centralized security monitoring system acts as an intermediary between checkout systems and businesses. This intermediary aggregates security data from multiple checkout systems, performs centralized analysis, and provides unified security management, reducing the burden on individual checkout systems while maintaining comprehensive oversight.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If businesses rely on manufacturers to secure checkout systems, then ease of operation is improved, but the ability to detect compromise deteriorates

Engineering Contradiction:
Improvesystem deploymentVSAvoidcompromise detection
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary security configuration by pre-installing monitoring agents and establishing baseline security profiles during checkout system deployment. Valid processes and configurations are identified and recorded before potential compromise occurs, enabling rapid detection of deviations from expected behavior.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where security data from checkout systems is constantly monitored, analyzed, and compared against known good states. When anomalies are detected, the system provides immediate feedback through alerts and notifications, enabling rapid response to potential compromises.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If the system monitors all checkout systems for compromise, then security detection capability improves, but system complexity increases

Engineering Contradiction:
Improvecompromise detection accuracyVSAvoidmonitoring infrastructure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts only essential security-relevant data from checkout systems, such as process lists, running services, and configuration states, rather than monitoring all system activities. This selective extraction reduces data volume and processing requirements while maintaining effective compromise detection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes monitoring parameters dynamically based on risk levels and system states. Low-risk systems receive minimal monitoring with lower resource consumption, while systems showing signs of potential compromise receive intensified monitoring. This adaptive parameter adjustment optimizes the balance between detection accuracy and system complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3133523B1System security monitoring
Publication Date: 2021.05.12 PALANTIR TECHNOLOGIES INC
  • EP3133523B1 patent drawingFigure 1
  • EP3133523B1 patent drawingFigure 2
  • EP3133523B1 patent drawingFigure 3

AI summary

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for a checkout system executable code monitoring, and user account compromise determination system. The system monitors executable code initiating and executing on checkout systems, including determining hashes of the executable code. The system determines whether the executable code is malicious based on the hash, and associated information of the executable code. Additionally, the system monitors user access to checkout systems, and determines user accounts associated with being compromised. User interfaces are generated describing checkout systems associated with a risk of being compromised, and are configured for user interaction, which cause generation of updated user interfaces and access to electronic data stores to determine information relevant to the user interaction.