POS PIN Pad Remote Key Injection via Asymmetric Cryptography

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing point of sale (POS) systems face challenges in securely expanding capabilities to accommodate additional acquirers or acquirer processors without the need for costly and inconvenient key injection processes, which often require transporting PIN pads to secure rooms.

Innovation Solution

Implementing remote key injection using asymmetric or public key cryptography, allowing a public key to be injected into PIN pads in their usual operating environment, enabling secure encryption and decryption of PINs without hardware or software changes, and incorporating additional data elements like time stamps and random data to defend against attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If symmetric cryptography with DUKPT is used for PIN encryption, then security is provided, but key management becomes complex and costly when expanding to additional acquirers

Engineering Contradiction:
Improvecapability to accommodate additional acquirersVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces asymmetric cryptography as an intermediary layer between the PIN pad and acquirer processors. A public key is injected into the PIN pad, which serves as a mediator that enables multiple acquirers to securely receive encrypted PINs without requiring separate symmetric keys for each acquirer. The private key remains securely stored in the acquirer processor, creating a trusted intermediary relationship that simplifies key management while expanding adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If PIN pads are transported to secure rooms for key injection, then security is maintained, but operational efficiency and cost are reduced

Engineering Contradiction:
Improvesecurity of key injectionVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces the mechanical process of physically transporting PIN pads to secure rooms with an electronic key injection process. The public key is transmitted electronically to the PIN pad through communication interfaces, eliminating the need for physical secure room facilities and transportation logistics. This substitution maintains security through cryptographic protocols while dramatically improving operational efficiency and reducing costs.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If additional PIN pads are provided for each merchant, then security is maintained, but cost and consumer confusion increase

Engineering Contradiction:
Improvesecurity for multiple acquirersVSAvoidcost and simplicity of deployment
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements universality by enabling a single PIN pad to serve multiple acquirers through the injection of a public key. The PIN pad becomes a multi-functional device that can securely communicate with different acquirer processors using the same public key infrastructure. This eliminates the need for separate PIN pads for each acquirer, reducing costs and simplifying deployment while maintaining security through the asymmetric cryptographic system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If remote key injection is implemented, then operational efficiency is improved, but vulnerability to unauthorized key injection increases

Engineering Contradiction:
Improveoperational efficiency of key injectionVSAvoidrisk of unauthorized key injection
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing verification mechanisms that prevent unauthorized key injection before it can compromise the system. The PIN pad verifies the authenticity of the injected public key through digital signatures or certificates from trusted authorities. This preliminary verification creates a defensive barrier that blocks unauthorized keys from being injected, thereby mitigating the security risks associated with remote key injection while maintaining operational efficiency.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10796306B2Point of sale (POS) personal identification number (PIN) security
Publication Date: 2020.10.06 PAYPAL INC
  • US10796306B2 patent drawing
  • US10796306B2 patent drawing
  • US10796306B2 patent drawing

AI summary

A key is securely injected into a POS PIN pad processor in its usual operating environment. In response to entry of a personal identification number (PIN) into a PIN pad, the processor puts the PIN into a PIN block; puts additional random data into the PIN block; and encrypts the entire PIN block using asymmetric cryptography with a public key derived from the injected key residing in the PIN pad processor. The corresponding private key may be held securely and secretly by an acquirer processor for decrypting the PIN block to retrieve the PIN. The encrypted random data defends the PIN against dictionary attacks. Time stamp data and constant data encrypted with the PIN block enables a defense of the PIN against replay attacks and tampering. The method may also include accepting the PIN from a mobile phone in communication with the processor.