Multi-path Back-end Payment System Key Redundancy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Networked computer environments face downtime and usability issues due to compromised encryption keys, network latency, and failures, with no efficient solutions to dynamically manage these factors for maintaining message security and processing transactions in real-time.
Innovation Solution
Implementing a system where card readers store multiple keys associated with key management systems, with a point of sale system dynamically selecting keys based on monitored conditions using a rule set, allowing for secure transaction message processing even if one key is compromised, and enabling redundancy, latency minimization, flexibility, and scalability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single encryption key is used for securing transaction messages, then the system is simple to operate, but the system becomes unavailable when the key is compromised
Solution Approach 1:
The system segments the key management by storing multiple encryption keys (first key, second key, third key) in separate key slots within the secure element. Each key is associated with a different key management system, allowing the card reader to switch between keys based on availability, thus preventing single-point failure while maintaining operational simplicity through automated key selection.
Solution Approach 2:
The system dynamically changes the encryption key parameter based on monitored conditions. When a key management system becomes unavailable or a key is compromised, the system automatically transitions from using one encryption key to another, maintaining security and availability without requiring manual intervention or system reconfiguration.
2Reliability
If multiple encryption keys are stored at card readers, then the system can switch to alternative keys when one is compromised, but the device complexity increases
Solution Approach 1:
The card reader system performs self-service key management by automatically monitoring the availability of key management systems and autonomously selecting appropriate encryption keys from stored keys. The system includes a monitor that detects unavailable key management systems and a selector that automatically chooses alternative keys, eliminating the need for manual key management intervention while handling multiple keys efficiently.
Solution Approach 2:
The system introduces an intermediary key management architecture where multiple key management systems (first, second, third key management systems) serve as mediators between the card reader and the transaction processing network. Each system has associated encryption keys, and the intermediary selector determines which key management system and corresponding key to use, distributing complexity across multiple independent components rather than concentrating it in a single system.
3Productivity
If the system monitors network conditions dynamically, then the usability and latency are improved, but the system complexity increases
Solution Approach 1:
The system implements feedback mechanisms where a monitor continuously observes the availability and performance of key management systems, and this information feeds back to the selector component. Based on this feedback, the system dynamically adjusts key selection and transaction routing decisions, optimizing transaction processing efficiency by avoiding unavailable or slow key management systems while maintaining a relatively simple overall architecture through rule-based automated responses.
Data Source
AI summary
Systems and methods for securing transaction messages are described. In an example, a transaction network may receive a transaction message. The transaction message may have been secured based on a key or an obfuscation process. They key or the obfuscation process may be associated with a management system of the transaction network. The transaction message may be received based on a rule set specifying a selection of the key from a plurality of keys or the obfuscation process from a plurality of obfuscation processes. The selection may be based on a condition associated with securing the transaction message. The keys or the obfuscation processes may be stored at least at a card reader. The management system may access the transaction message and may provide transaction data to an endpoint based at least in part on the transaction message being accessed.


