Automated Pin Pad Key Provisioning via Asymmetric Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Automated banking machines require secure and efficient methods for transferring and managing terminal master keys, currently relying on manual two-person teams, which is inefficient and vulnerable to security risks such as man-in-the-middle attacks.

Innovation Solution

Implementing a system that uses asymmetric encryption to provision an input device with a terminal master key, followed by symmetric encryption to transfer a communication key, enabling secure remote key management and authentication between the automated banking machine and the host system, utilizing public key infrastructure and secure communication protocols to minimize interception risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual two-person team method is used for terminal master key installation, then security verification can be performed, but installation efficiency is low and operational complexity increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidinstallation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces the manual mechanical key installation process with an automated electronic system. The EPP automatically receives terminal master keys from the host system via communication, eliminating the need for manual physical key transfer and installation by two-person teams, thereby improving efficiency while maintaining security through electronic authentication protocols

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The EPP performs self-installation of terminal master keys without requiring manual intervention. The system automatically authenticates with the host system, receives keys securely, and configures itself, reducing operational complexity and eliminating the need for specialized manual installation procedures

Inventive Principle:
Principle #25Self-service

2Reliability

If manual key transfer is used, then physical security can be maintained, but vulnerability to man-in-the-middle attacks increases and interception risk is high

Engineering Contradiction:
Improvephysical securityVSAvoidinterception risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a secure communication channel as an intermediary between the host system and EPP. This intermediary channel uses encryption protocols to protect key transmission, preventing direct exposure to interception risks while maintaining the security benefits of controlled key distribution

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the transmission parameter from physical manual transfer to encrypted electronic communication. By transforming the key transfer mechanism into a digital protocol-based system with authentication and encryption parameters, the system maintains security while eliminating physical vulnerability and man-in-the-middle attack risks

Inventive Principle:
Principle #35Parameter changes

3Reliability

If asymmetric encryption is used for terminal master key provisioning, then security is enhanced, but computational complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the encryption process into distinct phases: asymmetric encryption is used only for the initial terminal master key provisioning from host system to EPP, while subsequent communication keys use symmetric encryption. This segmentation reduces overall computational complexity by applying the more complex asymmetric encryption only where necessary for initial security establishment

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9224144B2Securing communications with a pin pad
Publication Date: 2015.12.29 DIEBOLD NIXDORF INCORPORATED
  • US9224144B2 patent drawing
  • US9224144B2 patent drawing
  • US9224144B2 patent drawing

AI summary

Described in an example embodiment herein is an apparatus comprising an input device and a processor communicatively coupled with the input device. The processor employs asymmetric encryption to provision the input device with a terminal master key. The processor employs the terminal master key with a symmetric encryption algorithm to transfer a communication key to the input device. The processor obtains data representative of a financial account. The processor receives data representative of the personal identification number for authorizing a financial transaction with the financial account from the input device, the data representative of the personal identification number is encrypted with the communication key. The processor receives a request for a financial transaction associated with the financial account via the input device. The processor determines whether the financial transaction is authorized based on the data representative of the personal identification number received from the input device.