Payment Terminal Authentication Using Asymmetric Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for payment terminals lack robustness and security, particularly in ensuring the legitimacy of payment transactions and terminal authenticity within communication networks.

Innovation Solution

The implementation of asymmetric cryptographic key pairs for terminal authentication, where payment terminals generate activation requests using private keys and receive digital authentication certificates from a certificate server, enabling secure authentication within the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used for payment terminals, then the system is simpler to implement, but security and legitimacy of transactions are insufficient

Engineering Contradiction:
Improvetransaction securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A certificate server is introduced as an intermediary component that issues digital authentication certificates to payment terminals. This mediator enables secure authentication without requiring complex direct verification mechanisms between terminals and the payment processing system, thereby improving security while managing complexity through a dedicated authentication authority.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Traditional mechanical or basic network-based authentication is replaced with cryptographic authentication mechanisms. Payment terminals use asymmetric key pairs (private keys for signing, public keys for verification) and digital certificates to authenticate their identity, substituting simple network login mechanisms with robust cryptographic proof of authenticity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If asymmetric cryptographic key pairs are implemented for terminal authentication, then terminal authenticity and transaction legitimacy are enhanced, but the complexity of key management and authentication processes increases

Engineering Contradiction:
Improveterminal authenticityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Payment terminals autonomously generate their own asymmetric key pairs and securely store their private keys. The terminals independently manage their authentication credentials without requiring manual intervention, thereby reducing operational complexity while maintaining strong security through self-contained cryptographic identity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Payment terminals perform preliminary authentication with the certificate server before actual payment transactions occur. The terminal obtains a digital authentication certificate in advance, which is then used for subsequent authentication steps. This preliminary authentication action establishes trust before the main transaction, simplifying the overall flow by separating authentication from payment processing.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9152957B2System and method for downloading an electronic product to a pin-pad terminal after validating an electronic shopping basket entry
Publication Date: 2015.10.06 THE TORONTO DOMINION BANK
  • US9152957B2 patent drawing
  • US9152957B2 patent drawing
  • US9152957B2 patent drawing

AI summary

A method of downloading an electronic product to a pin-pad terminal involves the terminal transmitting to a network gateway a transaction proposal for an electronic product from a network device, and receiving from the gateway a transaction proposal response generated by the gateway in response to the transaction proposal. The transaction proposal response includes a transaction pointer associated with the electronic product. An electronic cash register receives an indication of a proposed payment amount for the electronic product. The pin-pad terminal receives from the electronic cash register confirmation of entry of the electronic product in an electronic shopping basket maintained by the electronic cash register. The terminal validates the confirmation of entry of the electronic product from a comparison with the transaction proposal response, and transmits the transaction pointer to the network device via the gateway. The terminal receives the electronic product from the network device via the gateway.