Network-Based SIOM for POS Terminals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Legacy Point-Of-Sale (POS) terminals often lack integrated Secure Input/Output (I/O) Modules (SIOMs, necessitating new hardware deployment and limiting secure communication solutions, as existing SIOM deployments are localized and require individual installation on each terminal.
Innovation Solution
A network-based SIOM approach is introduced, where a single SIOM per store manages multiple POS terminals and peripheral devices over a Local-Area Network (LAN) or Wide-Area Network (WAN), establishing unique secure sessions using a secure protocol to ensure encryption and security policies are enforced across devices, allowing for secure communication without the need for physical SIOMs on each terminal.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a localized SIOM is deployed within each POS terminal, then security and policy management for that terminal is improved, but hardware deployment complexity and cost increase
Solution Approach 1:
The patent creates a virtual copy of the SIOM functionality that can be instantiated on any network-connected device rather than requiring physical SIOM hardware in each terminal. The virtual SIOM replicates security functions through software implementation, allowing multiple terminals to share a single physical SIOM instance.
Solution Approach 2:
The patent enables a single SIOM to serve multiple POS terminals and peripheral devices across different locations through network connectivity. The SIOM transitions from being terminal-specific to being system-wide, providing universal security management across the entire point-of-sale network infrastructure.
2Reliability
If a physical SIOM is installed in each POS terminal, then secure communication for that terminal is ensured, but the need for new hardware deployment increases
Solution Approach 1:
The patent replaces the mechanical/physical SIOM hardware with a virtual SIOM implementation that runs as software on standard network devices. This substitution eliminates the need for specialized hardware deployment while maintaining secure communication capabilities through virtualization.
Solution Approach 2:
The patent changes the fundamental parameter of SIOM implementation from physical hardware to virtual software instance. This parameter change allows the system to leverage existing network infrastructure rather than requiring dedicated hardware installations at each terminal location.
3Adaptability or versatility
If legacy POS terminals without integrated SIOM are used, then existing infrastructure is maintained, but security coverage is limited
Solution Approach 1:
The patent introduces a network-based virtual SIOM as an intermediary between legacy terminals and the security infrastructure. This intermediary provides security services to terminals that lack integrated SIOMs, enabling secure communication without modifying the existing terminal hardware.
Solution Approach 2:
The virtual SIOM serves multiple functions including security policy enforcement, encrypted communication management, and device authentication across both legacy and modern terminals, providing universal security coverage regardless of terminal generation.
Data Source
AI summary
A Secure Input/Output (I/O) Module (SIOM) is networked-enabled providing secure communications with terminals and peripherals integrated into the terminals. Communications between devices are securely made through encrypted communication sessions provisioned, defined, and managed through a secure protocol using the network-based SIOM. In an embodiment, a single-tenant network-based SIOM is provided. In an embodiment, a hybrid dual single-tenant and multi-tenant network-based SIOM is provided. In an embodiment, a multi-tenant network-based SIOM is provided. In an embodiment, a cloud-based SIOM is provided.


