Dynamic Content Shredding for POS Financial Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing POS systems lack efficient and effective methods to protect financial data from unauthorized access and exploitation, particularly during transactions when data is vulnerable in non-persistent memory.

Innovation Solution

The system employs a combination of data level encryption and cryptographic bitsplitting using a keyed information dispersal algorithm (IDA) to break up data into multiple splits, ensuring that even if data is breached, it remains unusable to unauthorized users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If financial data is stored in non-persistent memory for processing, then transaction speed and efficiency are improved, but data security and protection from unauthorized access deteriorate

Engineering Contradiction:
Improvetransaction processing speedVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies segmentation by dividing financial data into multiple fragments or shards that are distributed across different memory locations or storage devices. This allows the data to be processed efficiently while requiring multiple fragments to be reassembled for unauthorized access to be successful, thereby maintaining both transaction speed and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cryptographic intermediaries such as encryption keys, digital signatures, and secure protocols that mediate between the data and access requests. These intermediaries enable fast processing through optimized cryptographic operations while ensuring that only authorized parties can access the actual financial data, thus resolving the contradiction between speed and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional encryption methods are used to protect financial data, then data security is improved, but processing efficiency and system complexity deteriorate

Engineering Contradiction:
Improvedata protectionVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-computing and caching cryptographic keys, digital signatures, and encryption parameters before they are needed for actual transactions. This allows the system to maintain high processing speeds during transactions while still providing strong cryptographic protection, as the heavy computational burden is performed in advance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent dynamically adjusts cryptographic parameters such as key lengths, algorithm selection, and security protocols based on the specific transaction context, risk assessment, and system load. This allows the system to provide strong security when needed while optimizing for processing efficiency during normal operations, thus resolving the contradiction between protection and efficiency.

Inventive Principle:
Principle #35Parameter changes

3Speed

If data is kept in plaintext for easy processing, then processing speed is improved, but vulnerability to memory scraping and unauthorized access increases

Engineering Contradiction:
Improvedata processing speedVSAvoidmemory scraping vulnerability
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic data protection where encryption and decryption operations are performed on-demand based on the processing stage and authorization level. Data transitions between encrypted and decrypted states dynamically throughout the transaction lifecycle, allowing fast processing of encrypted data when appropriate while minimizing the time plaintext data exists in memory, thus reducing vulnerability to memory scraping.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12217251B2System and method for the protection of consumer financial data utilizing dynamic content shredding
Publication Date: 2025.02.04 CYBER RELIANT CORP
  • US12217251B2 patent drawing
  • US12217251B2 patent drawing
  • US12217251B2 patent drawing

AI summary

Consumer Point-of-Sale (POS) systems are becoming a major target for financial data loss within the commerce ecosystem. Privileged information, such as account numbers, card information, and transaction data are the primary targets during these data breaches. This information, while resident on a point-of-sale system, can be in plain text and susceptible to theft. The intent of this document is to present a unique solution that reduces the attack surface for these types of “hacks”, and protects consumer data through specialized cryptographic operations including data level encryption with a cryptographic bitsplitting algorithm. This makes the data useless to those who would take the data unlawfully. The invention allows for the efficient and effective processing of financial data while converting the data to a useless state for those who would obtain it unlawfully.