Encrypted PIN Block Creation for Secure COTS Payments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for software-based PIN entry on commercial off-the-shelf (COTS) devices face security concerns as they often compromise card data and PINs within a single device, lacking the protections of standard payment devices, and may not randomize data adequately, leading to potential security breaches.
Innovation Solution
A system that diversifies PIN and card data reception across different locations, using a consumer application on a user device and a card reading interface on a COTS device, with an encrypted PIN block (EPB) creation subsystem, ensuring secure PIN verification by transmitting encrypted data through a network, thereby minimizing the risk of compromise within a single device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If PIN and card data are processed within a single COTS device, then device cost is reduced, but security risk increases
Solution Approach 1:
The system divides the payment processing function into separate components: card data reception, PIN entry interface, and EPB creation subsystem. These components can be distributed across different devices or locations, allowing COTS devices to perform payment processing while maintaining security through spatial separation of sensitive operations.
Solution Approach 2:
An encrypted PIN block (EPB) creation subsystem acts as an intermediary between card data and PIN verification. This subsystem securely combines card data with PIN input to create encrypted blocks, preventing direct exposure of either data type and enabling secure processing on COTS devices.
2Ease of operation
If PIN entry interface is provided on COTS device, then ease of operation is improved, but privacy security deteriorates
Solution Approach 1:
The EPB creation subsystem serves as an intermediary that receives PIN input through the COTS device interface, combines it with card data, and produces encrypted output. This mediator architecture allows convenient PIN entry while protecting privacy by immediately encrypting the input before it can be exposed or mishandled.
Solution Approach 2:
The system replaces traditional secure PIN pad hardware with software-based PIN entry on COTS devices. By using the EPB creation subsystem to handle the cryptographic operations, the patent substitutes physical security mechanisms with cryptographic software solutions that maintain security while improving operational convenience.
Data Source
AI summary
A system for conducting a card transaction comprises an consumer application running on a user device, a card reading interface separate from the user device, a payment application residing on a COTS device, a PIN verification subsystem, an EPB creation subsystem located at an EPB creation location, and a server. The user device receives an entered PIN. The card reading interface receives a PAN from a payment card. Either the PIN or a first set of signals comprising the PIN is received by the EPB creation subsystem. The second set of signals comprising the PAN is generated and transmitted by the payment application via the network. An EPB is created by the EPB creation subsystem based on the PIN and PAN, and the EPB is transmitted by the EPB creation subsystem to either the PIN verification subsystem or the payment card for PIN verification.


