Gateway Device Encryption for Secure Payment Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic payment systems face challenges in securing sensitive information during transactions, with data often being communicated in unencrypted form, making it vulnerable to unauthorized access and misuse.

Innovation Solution

Implementing an End to End Encryption Security Model that uses data encryption, Tamper Resistant Security Modules, Hardware Security Modules, and physical access protections to ensure that sensitive payment account and processing data are protected throughout the transaction process, from data entry to authorization and settlement, using encryption techniques and secure key management to maintain data integrity and confidentiality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If sensitive information is communicated in unencrypted form, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the encryption process into multiple stages: merchant device-specific encryption at the point of sale, gateway device decryption and re-encryption, and host device final processing. This segmentation allows sensitive information to be encrypted at the source while maintaining operational simplicity for end users, resolving the contradiction between ease of operation and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway device serves as an intermediary between the merchant device and the host device. It receives encrypted transaction data, decrypts it using gateway-specific keys, and re-encrypts it for transmission to the host. This intermediary approach maintains security while enabling seamless operation without requiring end users to understand or manage encryption processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption is implemented throughout the transaction process, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements local quality by assigning different encryption capabilities to different devices in the system. The merchant device has encryption capability for initial protection, the gateway device has decryption and re-encryption capability, and the host device has final processing capability. This distributed approach maintains high security while managing device complexity through specialized functions rather than requiring all devices to have full encryption suites.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs preliminary encryption at the merchant device before data leaves the point of sale. This preliminary action ensures security is established early in the transaction process, allowing subsequent devices to work with already-encrypted data and reducing their security implementation complexity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple encryption keys are used, then security is improved, but loss of time is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidloss of time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The gateway device performs decryption and re-encryption operations in advance before data is transmitted to the host device. This preliminary processing ensures that security transformations are completed proactively, minimizing delays during actual transaction processing and reducing perceived loss of time for end users.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements efficient key management that allows the gateway device to quickly switch between merchant device-specific keys and gateway-specific keys. This enables rapid decryption and re-encryption operations, rushing through the security transformation process to minimize time loss while maintaining multiple encryption layers.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS10748146B2Tamper-resistant secure methods, systems and apparatuses for credit and debit transactions
Publication Date: 2020.08.18 HEARTLAND PAYMENT SYST LLC
  • US10748146B2 patent drawing
  • US10748146B2 patent drawing
  • US10748146B2 patent drawing

AI summary

An electronic payment transaction involves operating a gateway device in an electronic payment system to receive first encrypted transaction data from a merchant device, wherein the first encrypted transaction data is encrypted by means of a merchant device-specific encrypting key. Decrypted transaction data is produced by using a merchant device-specific decrypting key to decrypt the first encrypted transaction data. Second encrypted transaction data is derived from the decrypted transaction data, wherein the second encrypted transaction data is encrypted by means of a gateway device-specific encrypting key. The gateway device communicates the second encrypted transaction data to another electronic payment system server. A key transmission block received from the merchant device includes information that enables the gateway device to derive the merchant device-specific decryption key.