Memory Scanning System for Payment Terminal Fraud Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Payment terminals are vulnerable to fraudulent transactions and tampering due to limited access restrictions on memory, which hinders software-based fraud and tamper identification capabilities.
Innovation Solution
A memory scanning system with direct access to the payment terminal's general memory, allowing unrestricted access to determine security status and take corrective actions, communicates with a payment server to verify security and update detection criteria.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software-based fraud and tamper identification is used, then the payment terminal can process transactions, but the ability to detect security compromises is limited due to restricted memory access
Solution Approach 1:
A security coprocessor is introduced as an intermediary component between the main processor and memory. The coprocessor has direct memory access capability and performs security functions independently, allowing fraud detection without being constrained by the main processor's memory access restrictions. This mediator enables comprehensive security scanning while the main system continues normal operations.
Solution Approach 2:
The payment terminal's processing functions are segmented into two independent parts: the main processor handles transaction processing, while a separate security coprocessor handles security scanning and fraud detection. This segmentation allows the security function to operate with full memory access rights without affecting the main system's operation or requiring its memory access permissions.
2Loss of information
If the operating system limits software access to certain memory portions, then system security is maintained, but fraud identification software cannot access all necessary information to detect tampering
Solution Approach 1:
The security coprocessor acts as a privileged intermediary that can access any memory portion directly through its own memory interface. It bypasses the operating system's access control mechanisms that restrict software programs, enabling comprehensive memory scanning for security purposes while the OS maintains its protection rules for application software.
3Object-affected harmful factors
If attackers physically access communication lines or processors, then they can intercept or modify payment information, but existing software-based detection methods cannot identify these attacks
Solution Approach 1:
The security coprocessor monitors communication lines and processor operations independently from the main system. It can detect physical tampering attempts such as wiretapping or processor modification by analyzing memory contents and communication patterns, providing tamper detection capability that software-based methods alone cannot achieve.
Data Source
AI summary
A payment terminal can have an integrated memory scanning system that has direct access to the memory of the payment terminal. By having direct access to the memory of the payment terminal, the memory scanning system can access information about the operating system and the applications of the payment terminal to determine if the operating system or applications are performing unauthorized or forbidden actions, which may indicate that a fraudulent transaction or tamper attempt is occurring at the payment terminal. The memory scanning system can determine if an unauthorized action is occurring by comparing the information regarding the operating system or applications obtained from the memory to test criteria stored by the memory scanning system. In addition, the memory scanning system can also have a direct communications with a payment server using information from a network stack in memory that can be accessed directly by the memory scanning system.


