Payment Terminal Firmware Configuration for Multi-Crypto Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing payment terminals require multiple firmware versions and certification processes for different cryptographic methods, leading to increased complexity and manufacturing costs, and customers are reluctant to adopt new terminals due to the cost of new cryptographic tools.

Innovation Solution

Implementing a single firmware with multiple cryptographic methods in payment terminals, allowing customization through enabling or disabling specific methods using electronic certificates, and enabling flexible configuration and security updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple firmware versions with different cryptographic methods are maintained for different terminal ranges, then compatibility with various customer verification tools is improved, but device complexity and manufacturing costs increase

Engineering Contradiction:
Improvecompatibility with customer verification toolsVSAvoidfirmware version complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a single firmware version that contains multiple cryptographic methods (RSA, ECC, DH) and multiple certificate authorities, enabling the terminal to work with different customer verification tools without requiring multiple firmware versions. This universal approach allows one firmware to serve multiple cryptographic purposes and compatibility requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges multiple cryptographic methods and multiple certificate authorities into a single firmware image. Instead of maintaining separate firmware versions for RSA, ECC, and DH methods, all cryptographic methods are combined into one firmware that can be deployed universally across all terminals.

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If multiple firmware versions with different cryptographic methods are maintained for different terminal ranges, then compatibility with various customer verification tools is improved, but manufacturing costs increase

Engineering Contradiction:
Improvecompatibility with customer verification toolsVSAvoidmanufacturing cost
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The single universal firmware eliminates the need for multiple production lines to flash different firmware versions. Manufacturers can use one production line to deploy the same firmware to all terminals, significantly reducing manufacturing complexity and costs while maintaining compatibility with various customer verification tools through embedded cryptographic methods.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

By combining multiple cryptographic methods and certificate authorities into one firmware, the patent eliminates the need for separate firmware production and deployment processes for each cryptographic method, thereby reducing manufacturing costs and simplifying the supply chain.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If multiple certification processes are conducted for different firmware versions, then security compliance with PCI standards is ensured, but time and resource consumption increase

Engineering Contradiction:
Improvesecurity complianceVSAvoidcertification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines multiple cryptographic methods and multiple certificate authorities into a single firmware that undergoes a single certification process. This unified approach maintains security compliance by ensuring all cryptographic methods in the firmware are certified together, rather than requiring separate certification processes for each firmware version.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The universal firmware, once certified, can be deployed to all terminals regardless of which cryptographic method or customer verification tool is used. This eliminates the need for repeated certification processes while maintaining security compliance across all deployments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If customers acquire new terminals with different cryptographic methods, then access to new terminal ranges is enabled, but investment in new cryptographic tools is required

Engineering Contradiction:
Improveaccess to new terminal rangesVSAvoidcryptographic tool investment
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The universal firmware enables customers to deploy the same terminal model with different cryptographic methods depending on their needs. Customers can use their existing cryptographic tools (RSA, ECC, or DH verification tools) with the new terminals by selecting the appropriate cryptographic method in the firmware, eliminating the need to invest in new cryptographic tools when adopting new terminal ranges.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4256450B1Method for configuring a payment terminal, and associated payment terminal
Publication Date: 2026.04.22 BANKS & ACQUIRERS INT HLDG SAS
  • EP4256450B1 patent drawingFigure 1~2

AI summary

Method for configuring a payment terminal, and associated payment terminal. The proposed technique relates to a method for configuring a payment terminal. The method comprises a step (11) of loading, within a secure memory of the payment terminal, a firmware item comprising a plurality of different cryptographic methods, each cryptographic method of the plurality being intended to allow operations for verifying the authenticity and integrity of at least one application installed in the payment terminal to be subsequently carried out by a third party in possession of the cryptographic hardware suitable for the method in question.