On-boarding Server for Secure Payment Terminal Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for configuring pin-pad terminals for secure electronic payments are cumbersome and time-consuming, requiring direct connection to a hardware security module for cryptographic key configuration and storage in a secure environment.
Innovation Solution
A method and system that utilize an on-boarding server to remotely authorize entities for electronic payments by validating identities, associating cryptographic keys, and transmitting merchant identifiers to acquirer servers, enabling secure configuration of pin-pad terminals via communications devices without physical access to a hardware security module.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If direct connection to hardware security module is used for cryptographic key configuration, then security of payment-related data is improved, but configuration time and complexity increase
Solution Approach 1:
The patent introduces an on-boarding server as an intermediary between the pin-pad terminal and the acquirer network. This server remotely provisions cryptographic keys and configuration data to the terminal, eliminating the need for direct physical connection to hardware security modules during configuration. The intermediary enables secure key distribution over networks while maintaining security requirements.
Solution Approach 2:
The patent replaces the mechanical/physical connection method (direct wiring to hardware security module) with an electronic/digital method (network-based remote provisioning). The configuration process transitions from physical access to secure rooms and direct connections to wireless or networked remote configuration, significantly reducing configuration time while maintaining security through cryptographic protocols.
2Reliability
If direct connection to hardware security module is used for cryptographic key configuration, then cryptographic integrity is maintained, but device complexity and operational difficulty increase
Solution Approach 1:
The on-boarding server acts as a trusted intermediary that manages the complexity of cryptographic key generation, storage, and distribution. Instead of requiring operators to directly interface with hardware security modules and manage cryptographic protocols manually, the server automates these complex processes and delivers pre-configured keys and certificates to the terminal, simplifying the operational process while maintaining cryptographic integrity.
Solution Approach 2:
The patent applies preliminary action by pre-generating and securing cryptographic keys on the on-boarding server before provisioning them to the pin-pad terminal. The server prepares all necessary cryptographic materials (keys, certificates, configuration data) in advance through secure processes, then delivers them remotely to the terminal, eliminating the need for complex real-time cryptographic operations during the configuration phase.
3Reliability
If secure restricted-access room is used for storing pin-pad terminals during configuration, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The on-boarding server enables configuration to occur remotely over networks, eliminating the requirement for secure restricted-access physical rooms. The intermediary server handles all secure communications and key deliveries digitally, allowing configuration personnel to work from standard offices or remote locations without needing specialized secure facilities, thereby greatly improving ease of operation while maintaining security through cryptographic protocols.
Solution Approach 2:
The patent replaces the physical security infrastructure (secure rooms, controlled access, physical monitoring) with digital security mechanisms (cryptographic authentication, encrypted communications, secure protocols). This substitution eliminates the operational constraints of physical secure facilities while maintaining or enhancing security through modern cryptographic methods, significantly improving ease of configuration and deployment.
Data Source
AI summary
An on-boarding server is configured to receive a data set and a manufacturer identifier from a communications device, validate an identity of an entity from the data set, and locate a first terminal cryptographic key associated with the manufacturer identifier in a terminal database. The on-boarding server is configured to confirm, using the located first terminal cryptographic key, that the manufacturer identifier received from the communications device was signed with a second terminal cryptographic key. The located first terminal cryptographic key and the second terminal cryptographic key are an asymmetric cryptographic key pair. The on-boarding server is configured to determine an acquirer server from the data set, and authorize the entity to effect electronic payments by providing the communications device with a merchant identifier and transmitting the merchant identifier to the acquirer server.


