Remote Key Downloading for POS Terminals via Bidirectional Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for downloading terminal master keys (TMK) in bank card payment systems are inefficient, requiring physical movement of devices to a security machine room for key distribution, leading to high labor costs, long maintenance cycles, and risks of key leakage due to manual input errors or interception.

Innovation Solution

A remote key downloading method using a device sequence number and identity authentication to securely download keys from a Remote Key Server (RKS) to POS terminals, employing cryptographic techniques like digital signatures, non-symmetric key pairs, and XOR operations to ensure secure and efficient key distribution without physical concentration of devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual text clear input solution is used for TMK downloading, then the key can be directly input into the POS terminal, but the security is compromised due to operator interception and manual input errors

Engineering Contradiction:
Improvekey input convenienceVSAvoidkey security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the manual mechanical input process with an automated electronic key downloading system. The TMK is automatically downloaded from the TMS to the POS terminal through encrypted communication channels, eliminating the need for manual text input and thereby removing the security vulnerabilities associated with human operators handling clear text keys.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary key downloading mechanism that acts as a secure bridge between the TMS and POS terminal. This intermediary system uses cryptographic protocols to transmit the TMK through encrypted channels, preventing direct exposure of the key to potential interceptors while maintaining automated delivery.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If IC card cipher text import solution is used for TMK downloading, then the key can be protected during storage, but huge management costs and workloads are generated due to manual IC card insertion and PIN setting

Engineering Contradiction:
Improvekey protectionVSAvoidkey distribution efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces the manual mechanical process of IC card insertion, PIN setting, and key import with an automated electronic downloading system. The TMK is directly downloaded to the POS terminal's internal secure storage through encrypted communication, eliminating all manual operations and thereby removing the associated management costs and workloads while maintaining key protection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The POS terminal performs self-service key downloading by automatically receiving and storing the TMK through encrypted channels. The terminal's built-in security module handles the key storage and protection automatically without requiring external manual intervention, thereby eliminating the need for operators to insert IC cards or set PINs.

Inventive Principle:
Principle #25Self-service

3Reliability

If local key parent POS solution is used for TMK downloading, then the key can be securely downloaded to financial POS terminals, but the devices need to be physically moved to the security machine room, leading to high transport costs and long maintenance cycles

Engineering Contradiction:
Improvesecure key downloadingVSAvoidmaintenance cycle
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces the mechanical process of physically moving devices to a security machine room with an electronic key downloading system. The TMK is transmitted through encrypted network channels directly to the POS terminal at its deployment location, eliminating the need for physical transport and thereby removing the associated time loss and transport costs while maintaining secure key delivery.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a network-based intermediary key distribution system that acts as a secure mediator between the key management center and POS terminals. This intermediary system enables remote key downloading through encrypted communication channels, allowing terminals to receive keys at their deployment locations without physical movement to centralized security facilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If remote key downloading is implemented without proper authentication, then the key distribution becomes efficient, but the system is vulnerable to fake terminals and fake TMS backgrounds

Engineering Contradiction:
Improvekey distribution efficiencyVSAvoidauthentication security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements bidirectional authentication with feedback mechanisms. The POS terminal authenticates the TMS background by verifying digital signatures on the downloaded key, while the TMS authenticates the POS terminal through device identity verification. This mutual authentication process with feedback ensures that both parties are legitimate before completing the key distribution, thereby preventing fake terminals and fake TMS backgrounds while maintaining efficient remote downloading.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9806889B2Key downloading method, management method, downloading management method, device and system
Publication Date: 2017.10.31 INGENICO (FUJIAN) TECHNOLOGY CO LTD
  • US9806889B2 patent drawing
  • US9806889B2 patent drawing
  • US9806889B2 patent drawing

AI summary

Disclosed is a key downloading management method, comprising: a device end authorizing the validity of an RKS server by checking a digital signature of a work certificate public key of the RKS server, and the RKS server generating an authentication token (AT); encrypting by using an identity authentication secondary key DK2 of the device end, and sending the ciphertext to the device end; the device end decrypting the ciphertext by using the identity authentication secondary key DK2 saved thereby, encrypting the ciphertext by using the work certificate public key and then returning same to the RKS server; the RKS server decrypting same by using a work certificate private key thereof and then comparing whether the authentication token (AT) is the same as the generated authentication token (AT) or not, and if so, it is indicated that the device end is valid, thereby achieving bidirectional identity authentication.