Automated Pin Pad Key Provisioning via Asymmetric Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Automated banking machines require secure and efficient methods for transferring and managing terminal master keys, currently relying on manual two-person teams, which is inefficient and vulnerable to security risks such as man-in-the-middle attacks.
Innovation Solution
Implementing a system that uses asymmetric encryption to provision an input device with a terminal master key, followed by symmetric encryption to transfer a communication key, enabling secure remote key management and authentication between the automated banking machine and the host system, utilizing public key infrastructure and secure communication protocols to minimize interception risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual two-person team method is used for terminal master key installation, then security verification can be performed, but installation efficiency is low and operational complexity increases
Solution Approach 1:
The patent replaces the manual mechanical key installation process with an automated electronic system. The EPP automatically receives terminal master keys from the host system via communication, eliminating the need for manual physical key transfer and installation by two-person teams, thereby improving efficiency while maintaining security through electronic authentication protocols
Solution Approach 2:
The EPP performs self-installation of terminal master keys without requiring manual intervention. The system automatically authenticates with the host system, receives keys securely, and configures itself, reducing operational complexity and eliminating the need for specialized manual installation procedures
2Reliability
If manual key transfer is used, then physical security can be maintained, but vulnerability to man-in-the-middle attacks increases and interception risk is high
Solution Approach 1:
The patent introduces a secure communication channel as an intermediary between the host system and EPP. This intermediary channel uses encryption protocols to protect key transmission, preventing direct exposure to interception risks while maintaining the security benefits of controlled key distribution
Solution Approach 2:
The system changes the transmission parameter from physical manual transfer to encrypted electronic communication. By transforming the key transfer mechanism into a digital protocol-based system with authentication and encryption parameters, the system maintains security while eliminating physical vulnerability and man-in-the-middle attack risks
3Reliability
If asymmetric encryption is used for terminal master key provisioning, then security is enhanced, but computational complexity increases
Solution Approach 1:
The patent segments the encryption process into distinct phases: asymmetric encryption is used only for the initial terminal master key provisioning from host system to EPP, while subsequent communication keys use symmetric encryption. This segmentation reduces overall computational complexity by applying the more complex asymmetric encryption only where necessary for initial security establishment
Data Source
AI summary
Described in an example embodiment herein is an apparatus comprising an input device and a processor communicatively coupled with the input device. The processor employs asymmetric encryption to provision the input device with a terminal master key. The processor employs the terminal master key with a symmetric encryption algorithm to transfer a communication key to the input device. The processor obtains data representative of a financial account. The processor receives data representative of the personal identification number for authorizing a financial transaction with the financial account from the input device, the data representative of the personal identification number is encrypted with the communication key. The processor receives a request for a financial transaction associated with the financial account via the input device. The processor determines whether the financial transaction is authorized based on the data representative of the personal identification number received from the input device.


