Cloud POS Transaction Data Security via Key Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Point of Sale (POS) terminals face high operation and maintenance costs, difficulty in promoting new services, and inadequate security for transaction data, as they often rely on outdated technical architectures and insecure communication channels.

Innovation Solution

A secure transfer method for cloud-based POS transaction data involves exchanging a transaction process key between a cloud POS terminal and background system, encrypting and decrypting sensitive data using this key, and uploading it to a financial acquiring platform through secure channels, ensuring the security of the access channel and data integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing POS terminals employ dial-in approaches, then the terminal can communicate with financial acquiring platform, but the security of transaction data is completely dependent on private network channels without additional secure measures

Engineering Contradiction:
Improvetransaction data securityVSAvoidsecurity architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security layers (public key infrastructure, private network channels, and encryption algorithms) to create a composite security architecture. The terminal uses both RSA public-key cryptography for key exchange and symmetric encryption for data transmission, creating a multi-layered security structure that addresses the weakness of relying on a single security mechanism.

Inventive Principle:
Principle #40Composite materials

Solution Approach 2:

The patent introduces a cloud-based security server as an intermediary between the POS terminal and the financial acquiring platform. This server manages key distribution, validates transaction requests, and provides security certificates, thereby enhancing transaction data security without requiring the terminal to implement complex security measures independently.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If existing POS terminals employ Internet access approaches, then the terminal can access financial platforms through public networks, but the security of transaction data is completely dependent on secure network channels such as 3G without additional secure measures

Engineering Contradiction:
Improvenetwork access flexibilityVSAvoidtransaction data security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The cloud security server acts as an intermediary that establishes secure communication channels between the terminal and financial platforms. It implements SSL/TLS encryption for Internet access and 3G secure channels, providing adaptability for different network types while maintaining consistent security standards through centralized certificate management and encryption protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically adjusts security parameters based on the network type being used. For Internet access, it applies stronger encryption protocols and additional validation steps, while for 3G networks it utilizes the inherent security features of the network while adding complementary encryption layers, thereby adapting security measures to the specific communication channel.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If POS terminals use backward technical architectures, then the terminal can perform basic bankcard consumption functions, but operation and maintenance cost is too high and difficulty of promoting new services arises

Engineering Contradiction:
Improvebasic transaction functionVSAvoidservice update efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent divides the POS system into two segments: a lightweight terminal component that handles basic transaction functions and a cloud-based platform that manages service logic, updates, and new features. This allows the terminal to remain simple and cost-effective while the cloud platform enables rapid deployment of new services without requiring terminal hardware upgrades.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cloud-based platform provides universal service management capabilities that can serve multiple terminal types and implement various banking services through software updates. This multi-functional approach allows a single terminal design to support multiple services (bankcard consumption, mobile payments, online banking) by downloading service modules from the cloud, thereby reducing terminal complexity while maintaining service versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3029880B1Method and system for safely transmitting transaction sensitive data based on cloud POS
Publication Date: 2022.11.09 CHINA UNIONPAY
  • EP3029880B1 patent drawingFigure 1

AI summary

The present application discloses a secure transfer method for cloud-based POS transaction sensitive data, comprising steps of: (a) exchanging a transaction process key with the cloud POS terminal; (b) receiving, from the cloud POS terminal, the transaction request packet encrypted by using the transaction process key; and (c) obtaining the transaction sensitive data from the transaction request packet, and using the transaction process key to operate on the transaction sensitive data so as to upload to the financial acquiring platform. The present invention also discloses a secure transfer system for cloud-based POS transaction sensitive data.