POS Security Layer Intercepts Payment Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current payment systems at point of sale (POS) terminals are vulnerable to data theft due to insecure transmission and storage of payment data, with intermediaries and malicious software intercepting sensitive information such as PANs and PINs, leading to fraud.

Innovation Solution

Implementing a POS security layer (PSL) on the terminal and a server security application (SSA) to intercept and encrypt payment data, providing false data for processing, which reduces the need for storing actual payment data and enhances security by using a secure channel for transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If payment data is transmitted through intermediaries at POS terminals, then transaction processing capability is improved, but security against data theft deteriorates

Engineering Contradiction:
Improvetransaction processing capabilityVSAvoiddata theft vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a payment data encryption system as an intermediary layer between the POS terminal and processing networks. This encryption intermediary transforms sensitive payment data into encrypted form before transmission, allowing the data to pass through multiple intermediaries (processors, banks, networks) without exposing the actual payment information. The encryption acts as a protective mediator that enables transaction processing while preventing data theft.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates encrypted copies of payment data that can be transmitted and processed without revealing the original sensitive information. Instead of transmitting actual payment card numbers and personal information through vulnerable channels, the system transmits encrypted copies that maintain the necessary data structure for processing but cannot be deciphered by unauthorized parties intercepting the transmission.

Inventive Principle:
Principle #26Copying

2Speed

If payment data is stored at POS terminals for processing, then transaction speed is improved, but security risk increases

Engineering Contradiction:
Improvetransaction speedVSAvoidsecurity risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive payment data from the POS terminal environment and transmits it securely to remote processing systems. By taking out the actual payment information from the terminal's storage and processing environment, the system eliminates the security vulnerability of storing sensitive data at multiple terminal locations while maintaining transaction speed through efficient encrypted transmission and remote processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements preliminary encryption of payment data at the point of capture, converting sensitive information into secure encrypted form before it can be exposed to security risks. This preliminary security action ensures that even if data is stored temporarily during processing, it remains protected because the encryption is applied before the data enters the processing pipeline.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If encryption and security layers are added to POS terminals, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the encryption functionality into integrated security modules that are embedded within the existing POS terminal architecture. By combining encryption, decryption, and security management functions into unified modules, the system achieves enhanced security without proportionally increasing complexity. The merged security layer works seamlessly with existing terminal operations.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent designs the encryption system to serve multiple functions simultaneously: it encrypts payment data for security, maintains data structure for processing compatibility, enables secure storage, and facilitates efficient transmission. This multi-functionality reduces the need for separate dedicated security components, thereby limiting the increase in overall system complexity while achieving comprehensive security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10185956B2Secure payment card transactions
Publication Date: 2019.01.22 SHIFT4 CORP
  • US10185956B2 patent drawing
  • US10185956B2 patent drawing
  • US10185956B2 patent drawing

AI summary

Payment card transactions at a point of sale (POS) are secured in certain embodiments by intercepting, with a POS security layer installed on a POS terminal, payment data from the POS terminal, transmitting the payment data from the POS security layer to a server security application installed on a POS server, and providing false payment data from the POS security layer to a POS terminal application installed on the POS terminal. The false payment data in various embodiments is processed as if it were the payment data, such that the POS terminal transmits an authorization request to the POS server using the false payment data. In addition, the authorization request may be transmitted from the POS server to a payment gateway.