Secure Payment Terminal Data Transmission via Near-Field Key Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data transmission methods from payment terminals to printers lack security, as they can be intercepted by malicious third parties, compromising sensitive information like banking details.
Innovation Solution
A method using a near-field connection to establish a shared cryptographic key, followed by a short-distance radio connection for secure data transmission, where data is encrypted and decrypted using this key, ensuring secure data exchange even if the near-field connection is compromised.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is transmitted through radio connections (Wi-Fi or Bluetooth) from payment terminal to printer, then communication flexibility and device pooling are improved, but security is worsened due to potential interception by malicious third parties
Solution Approach 1:
The transmission process is segmented into two distinct phases: a near-field key exchange phase and a radio connection data transmission phase. This segmentation allows the sensitive key establishment to occur through a secure near-field channel while data transmission uses the flexible radio channel, thereby resolving the contradiction between security and flexibility.
Solution Approach 2:
A shared cryptographic key is established preliminarily through near-field communication before the actual data transmission occurs. This preliminary action ensures that when data is transmitted over the radio connection, it is already protected by a pre-established secure key, thus maintaining security while allowing radio connection flexibility.
2Reliability
If encryption protocols are used to protect transmitted data, then data security is improved, but vulnerability to interception remains when the fraudster can identify the encryption protocol
Solution Approach 1:
Near-field communication serves as an intermediary channel for establishing the cryptographic key. This intermediary approach allows the key to be exchanged through a physically secure channel that is difficult to intercept, thereby protecting the encryption mechanism itself from being compromised even if the radio transmission is intercepted.
Solution Approach 2:
The cryptographic key is established preliminarily through near-field communication before any data transmission occurs. This preliminary key establishment ensures that even if the encryption protocol is identified during radio transmission, the actual decryption key remains secure because it was exchanged through a secure near-field channel that is resistant to interception.
3Reliability
If a shared cryptographic key is established through near-field connection, then security against interception is improved, but device placement flexibility may be limited by the near-field requirement
Solution Approach 1:
The communication process is segmented into two phases with different flexibility requirements: near-field key exchange (security-critical) and radio data transmission (flexibility-critical). This segmentation allows the system to prioritize security for key establishment while maintaining operational flexibility for the actual business transactions.
Solution Approach 2:
The near-field key exchange is performed preliminarily when devices are in close proximity, establishing a secure cryptographic foundation. After this preliminary secure setup, the radio connection enables flexible device placement for subsequent data transmission, thus resolving the contradiction between security requirements and operational flexibility.
Data Source
AI summary
Novel payment terminals can take the form of a touchpad screen that incorporates no printer. This makes it possible to pool a printer among several payment terminals. The editing of a receipt confirms to confirm the invoiced amount and justify it. The data indicated in a receipt are sensitive and they must be secured before they are transmitted to the printer. However, the techniques used to encrypt the data transmitted to the printer can suffer from a security defect. A payment terminal and data-reception device are provided, which exchange messages on negotiation of a shared cryptographic key through a first near-field connection. The data relating to a transaction made by the payment terminal are then encrypted by using the shared cryptographic key and transmitted to the data-reception device through a second radio connection.

