Payment Terminal Cryptographic Segregation for Multi-Operator Use
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current payment terminal systems lack efficient methods for cryptographic segregation and secure key management, making it difficult to share payment terminals among multiple operators while ensuring privacy and security in transactions.
Innovation Solution
The implementation of a method that configures payment terminals to use operator- and terminal-specific encryption keys, derived from master keys using terminal identification numbers, with symmetric encryption and tamper-resistant security modules to manage access and encrypt transactions, ensuring secure communication with payment providers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If payment terminals are shared by multiple operators, then device utilization and productivity improve, but security and transaction privacy deteriorate due to lack of cryptographic segregation
Solution Approach 1:
The patent applies segmentation by creating operator-specific encryption keys and cryptographic zones within the payment terminal. Each operator receives a unique key pair (public and private) that segments the transaction processing into isolated cryptographic domains, allowing multiple operators to use the same terminal while maintaining separate security boundaries for each operator's transactions.
Solution Approach 2:
The patent implements local quality by assigning different cryptographic properties to different operators within the same terminal. Each operator has localized access to their specific key material and encryption context, while other operators cannot access their data. This creates operator-specific security zones within the shared terminal environment.
2Adaptability or versatility
If multiple operators access the payment terminal, then adaptability and versatility improve, but key management complexity increases due to need for operator-selective control
Solution Approach 1:
The patent applies universality by creating a master key management system that can serve multiple operators through a single terminal. The controlling entity uses a master key to derive and manage individual operator keys, allowing one terminal to securely support multiple operators without requiring separate key management systems for each operator.
Solution Approach 2:
The patent introduces a controlling entity as an intermediary between the payment terminal and multiple operators. This controlling entity manages the key derivation and distribution process, acting as a mediator that simplifies key management by centralizing the derivation of operator-specific keys from a master key, thereby reducing the complexity of managing multiple operator keys.
3Reliability
If operator-specific encryption keys are implemented, then transaction privacy improves, but device complexity increases due to multiple encryption layers
Solution Approach 1:
The patent applies the nested doll principle by implementing nested encryption key structures where operator-specific keys are derived from and contained within the framework of master keys. The key hierarchy nests operator keys within the master key structure, and transaction data is encrypted with operator keys that are themselves derived from the master key, creating nested layers of encryption that maintain privacy while managing complexity through hierarchical organization.
Data Source
AI summary
Methods, systems, and computer program products for payment terminal sharing. A payment terminal is configured to become usable as a payment terminal shared by a plurality of operators with cryptographic segregation between the different operators of the payment terminal. An operator- and terminal-specific transport key is provided to the payment terminal. An operator- and terminal-specific initial-encryption key is derived, by the payment provider, from an operator-specific base-derivation key using the terminal-identification number, or an additional identification number of the payment terminal. The operator- and terminal-specific initial-encryption key is transmitted to the payment terminal, and is decrypted at the payment terminal. An operator- and transaction-specific encryption key is derived, both at the payment provider and the payment terminal, from the operator- and terminal-specific initial-encryption key using a transaction-specific number associated with this transaction, when performing a transaction with the payment terminal.


