Portable Payment Terminal Peripheral Authentication via Server Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The ease of installation and low-cost hardware of portable payment terminals, such as detachable data acquisition peripherals (DAPs), has led to increased risks of fraudulent activities, particularly in environments where trust between nomadic merchants and their customers is a concern, as these terminals can be easily compromised to obtain confidential banking data or perform undue debits.

Innovation Solution

A method for verifying the authenticity of DAPs using an authentication server that receives and verifies an identifier associated with a referenced authentic peripheral, providing a decision on identification and detecting any damage or break-in, allowing users to ensure the peripheral's integrity before use, which can be initiated manually or automatically through a user's terminal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If DAPs are made easy to install and low-cost, then ease of operation and accessibility are improved, but reliability and security against fraud deteriorate

Engineering Contradiction:
Improveease of installationVSAvoidsecurity against fraud
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

An authentication server is introduced as an intermediary between the user and the DAP. The server receives an identifier from the DAP, verifies its authenticity against a database of registered peripherals, and returns an authentication result. This mediator enables secure verification without requiring complex hardware in the DAP itself, maintaining ease of installation while improving reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If DAPs are made low-cost with basic hardware functions, then ease of manufacture is improved, but reliability and susceptibility to fraud deteriorate

Engineering Contradiction:
Improveease of manufactureVSAvoidresistance to fraudulent activities
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The authentication system is segmented into two parts: a simple identifier generation component embedded in the DAP (easy to manufacture) and a complex verification component hosted on the authentication server. This segmentation allows the DAP to remain low-cost and simple to manufacture while the server handles the security-critical verification functions that resist fraud.

Inventive Principle:
Principle #1Segmentation

3Reliability

If manual verification of DAP authenticity is required, then reliability is improved, but ease of operation and user convenience deteriorate

Engineering Contradiction:
Improveauthentication accuracyVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The DAP automatically performs the authentication process by sending its identifier to the authentication server without requiring manual user intervention. The server processes the verification and returns the result automatically. This self-service approach maintains high reliability through accurate verification while improving ease of operation by eliminating manual steps for the user.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9536262B2Method for verifying authenticity, corresponding server, system and computer program
Publication Date: 2017.01.03 BANKS & ACQUIRERS INT HLDG SAS
  • US9536262B2 patent drawing
  • US9536262B2 patent drawing
  • US9536262B2 patent drawing

AI summary

A method and apparatus are provided for verifying authenticity of a data acquisition peripheral to be used, which has at least one identifier. The method includes: receiving the identifier by means of an authentication server, verifying, by the authentication server, an association of the identifier with a referenced authentic peripheral, delivering a decision of identification; and transmission, by the server, of the decision of identification.