POS Output Device Switching for Tamper and Behavior Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Payment object reading devices face security risks due to unprotected circuitry that can be accessed by malicious parties, compromising sensitive information, and there is a need to securely share output devices between secured and unsecured processors.
Innovation Solution
Implementing a secure enclosure with tamper detection circuitry and a switch controlled by a secure processor to transfer control of output devices, ensuring secure processor dominance in specific scenarios like tampering detection or sensitive information handling.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If output devices are shared between secured and unsecured processors, then device versatility and functionality are improved, but security risks increase due to potential unauthorized access
Solution Approach 1:
A switch component is introduced as an intermediary between the processors and the output device. The switch is controlled by the secure processor to mediate access requests from both secure and unsecured processors, allowing legitimate sharing while blocking unauthorized access attempts.
Solution Approach 2:
The system dynamically changes the connectivity state of the switch based on security conditions. When tampering is detected or security violations occur, the switch dynamically reconfigures to disconnect the unsecured processor while maintaining connection for the secure processor, enabling adaptive security response.
2Reliability
If a switch is introduced to control output device access, then security control is improved, but device complexity increases
Solution Approach 1:
The secure processor itself performs the switching control function without requiring an external dedicated switch controller. The secure processor uses its existing control capabilities to manage the switch states, eliminating the need for additional control logic and reducing overall system complexity.
3Reliability
If the secure processor maintains dominance over output devices, then security protection is improved, but operational flexibility decreases
Solution Approach 1:
The switch connectivity states are dynamically adjusted based on operational context. During sensitive operations (e.g., PIN entry, secure data transmission), the switch maintains secure processor dominance. During normal operations, the switch allows unsecured processor access, providing contextual flexibility while maintaining security when needed.
Data Source
AI summary
A point of sale (POS) device includes an output device such as a speaker, a display screen, or a network interface. The POS device also includes a secure enclosure housing a secure processor and tamper detection circuitry for detecting attempts to tamper with the secure enclosure. Use of the output device is shared between the secure processor and a main processor via a switch that is controlled by the secure processor. The secure processor can switch control of the output device from the main processor to itself and can output an output dataset via the output device in a number of scenarios. These scenarios include the secure processor detecting an attempt to tamper with the secure enclosure, the secure processor recognizing that the main processor is behaving suspiciously, or the secure processor wanting to output sensitive information. The output dataset may include visual data, audio data, or network data.


