Cryptographic Processor for Point-to-Point Encryption Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Point of interaction devices face security risks during payment transactions due to the potential transmission of unencrypted card data when the data is not compliant with ISO-7813 standards, which can violate PCI Security Standards Council's point-to-point encryption requirements.

Innovation Solution

A method and device for point-to-point encryption compliance that involves receiving card data, determining errors such as non-compliance with ISO-7813, generating substitute data to replace the erroneous data, and communicating this substitute data to a payment server, utilizing a cryptographic processor in a point of interaction device that includes card readers and a payment application.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If card data is transmitted without encryption when errors occur, then processing speed is improved, but security is worsened

Engineering Contradiction:
Improveprocessing speedVSAvoidsecurity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system performs preliminary validation of card data against ISO-7813 compliance standards before transmission. The cryptographic processor checks data integrity and compliance status in advance, determining whether encryption is required before the transmission occurs, thus preventing unencrypted transmission of non-compliant data

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A cryptographic processor acts as an intermediary between the payment application and the transmission channel. This intermediary component validates card data compliance, manages encryption requirements, and controls data flow based on compliance status, ensuring that only properly encrypted or validated data is transmitted

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If card data validation and substitution processes are implemented, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cryptographic processor combines multiple functions into a single component: card data validation, ISO-7813 compliance checking, error detection, and substitute data generation. This consolidation achieves security requirements without proportionally increasing device complexity, as one component performs what would otherwise require multiple separate systems

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The cryptographic processor autonomously validates card data compliance and generates appropriate substitute data when errors are detected, without requiring external intervention or complex control systems. The component self-manages the security validation process based on embedded compliance rules

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4187466A1Systems and methods for point-to-point encryption compliance
Publication Date: 2023.05.31 VERIFONE INC
  • EP4187466A1 patent drawingFigure 1
  • EP4187466A1 patent drawingFigure 2
  • EP4187466A1 patent drawing

AI summary

Systems and methods for point-to-point encryption compliance are disclosed. In one embodiment, in a point of interaction device comprising at least one computer processor, a method for point-to-point encryption compliance may include: (1) receiving card data from a card reading device; (2) determining an error with the card data; (3) generating substitute data by replacing at least a portion of the card data with substitute data; and (4) communicating the substitute data to a payment server. The card data may be received from a magnetic stripe reader, from an EMV card reader, or from a contactless card reader. The error may include comprises the card data not being compliant with ISO-7813.