Payment Terminal Tamper Detection via Attestation Tickets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Payment terminals in electronic payment systems are vulnerable to fraudulent activities and tampering, with attackers attempting to access sensitive information or modify communications, and existing security measures can be bypassed by sophisticated attackers.

Innovation Solution

Implementing an augmented tamper and fraud detection methodology through a trust routine that includes hashing software code, scanning memory, and gathering metadata, with attestation tickets being generated and validated to ensure the integrity and security of payment platforms, and incorporating cryptographic processes to restrict access and protect data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures such as tamper switches or tamper meshes are implemented, then the payment terminal can detect physical tampering attempts, but these measures can be bypassed by sophisticated attackers who create counterfeit devices or modify communication signals

Engineering Contradiction:
Improvetamper detection capabilityVSAvoidfraudulent activities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces traditional mechanical tamper detection mechanisms (tamper switches, tamper meshes) with a logical validation system that uses software-based cryptographic verification. The system validates the logical integrity of payment devices through cryptographic hashes and digital signatures, making it immune to physical tampering attempts that bypass mechanical detectors.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a payment service as an intermediary that performs validation of payment devices before transactions. This intermediary system uses cryptographic verification to authenticate devices, replacing direct physical security measures with a layered security architecture where the payment service validates device integrity through logical means rather than physical detectors.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If payment terminals implement comprehensive security validation routines including hashing software code and scanning memory, then the integrity of payment platforms is enhanced, but the device complexity increases

Engineering Contradiction:
Improveintegrity of payment platformsVSAvoidsecurity validation system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary validation actions where the payment service validates payment devices before transactions occur. The system performs cryptographic verification of device integrity in advance, establishing trust before the actual payment processing. This preliminary validation reduces the complexity of real-time security checks by pre-establishing device authenticity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses cryptographic hashes and digital signatures to create virtual copies of device state information for validation purposes. Instead of directly analyzing the complex device architecture in real-time, the system works with condensed cryptographic representations (hashes) of device integrity, simplifying the validation process while maintaining comprehensive security.

Inventive Principle:
Principle #26Copying

3Reliability

If the payment terminal performs extensive validation of payment devices including checking for tampering and fraud, then fraudulent transactions are reduced, but the transaction processing time increases

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs extensive validation actions before transactions occur, establishing device integrity and authenticity in advance. By completing complex validation routines preliminarily rather than in real-time during transactions, the system reduces processing time during actual payment operations while maintaining high fraud detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where validation results are cached and reused for subsequent transactions. The payment service provides feedback about device validity status that can be referenced in future transactions, reducing the need for repeated comprehensive validation and thereby decreasing transaction processing time while maintaining security.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3479320B1Logical validation of devices against fraud and tampering
Publication Date: 2021.11.10 BLOCK INC
  • EP3479320B1 patent drawingFigure 1A
  • EP3479320B1 patent drawingFigure 1B
  • EP3479320B1 patent drawingFigure 1B

AI summary

Disclosed herein is a method and system to determine whether a payment terminal has been tampered with based on a comparison of attestation data received from the payment terminal. If the determination yields that the request has been approved, the terminal generates an attestation ticket having one or more validity conditions, wherein the validity conditions include expiration time that indicates the time after which the attestation ticket becomes invalid. The attestation ticket can be used as long as it is valid or until another trigger causes the ticket to be invalidated or regenerated.