Network-Based SIOM for POS Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy Point-Of-Sale (POS) terminals often lack integrated Secure Input/Output (I/O) Modules (SIOMs, necessitating new hardware deployment and limiting secure communication solutions, as existing SIOM deployments are localized and require individual installation on each terminal.

Innovation Solution

A network-based SIOM approach is introduced, where a single SIOM per store manages multiple POS terminals and peripheral devices over a Local-Area Network (LAN) or Wide-Area Network (WAN), establishing unique secure sessions using a secure protocol to ensure encryption and security policies are enforced across devices, allowing for secure communication without the need for physical SIOMs on each terminal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a localized SIOM is deployed within each POS terminal, then security and policy management for that terminal is improved, but hardware deployment complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidhardware deployment
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a virtual copy of the SIOM functionality that can be instantiated on any network-connected device rather than requiring physical SIOM hardware in each terminal. The virtual SIOM replicates security functions through software implementation, allowing multiple terminals to share a single physical SIOM instance.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent enables a single SIOM to serve multiple POS terminals and peripheral devices across different locations through network connectivity. The SIOM transitions from being terminal-specific to being system-wide, providing universal security management across the entire point-of-sale network infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a physical SIOM is installed in each POS terminal, then secure communication for that terminal is ensured, but the need for new hardware deployment increases

Engineering Contradiction:
Improvesecure communicationVSAvoidhardware deployment
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent replaces the mechanical/physical SIOM hardware with a virtual SIOM implementation that runs as software on standard network devices. This substitution eliminates the need for specialized hardware deployment while maintaining secure communication capabilities through virtualization.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the fundamental parameter of SIOM implementation from physical hardware to virtual software instance. This parameter change allows the system to leverage existing network infrastructure rather than requiring dedicated hardware installations at each terminal location.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If legacy POS terminals without integrated SIOM are used, then existing infrastructure is maintained, but security coverage is limited

Engineering Contradiction:
Improvelegacy system compatibilityVSAvoidsecurity coverage
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a network-based virtual SIOM as an intermediary between legacy terminals and the security infrastructure. This intermediary provides security services to terminals that lack integrated SIOMs, enabling secure communication without modifying the existing terminal hardware.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The virtual SIOM serves multiple functions including security policy enforcement, encrypted communication management, and device authentication across both legacy and modern terminals, providing universal security coverage regardless of terminal generation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10009376B2Network-based secure input/output (I/O) module (SIOM)
Publication Date: 2018.06.26 NCR VOYIX CORP
  • US10009376B2 patent drawing
  • US10009376B2 patent drawing
  • US10009376B2 patent drawing

AI summary

A Secure Input/Output (I/O) Module (SIOM) is networked-enabled providing secure communications with terminals and peripherals integrated into the terminals. Communications between devices are securely made through encrypted communication sessions provisioned, defined, and managed through a secure protocol using the network-based SIOM. In an embodiment, a single-tenant network-based SIOM is provided. In an embodiment, a hybrid dual single-tenant and multi-tenant network-based SIOM is provided. In an embodiment, a multi-tenant network-based SIOM is provided. In an embodiment, a cloud-based SIOM is provided.