Secure POS Software Update via Merchant Device Relay
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Point-of-sale (POS) systems face security issues during software updates, particularly when connected to separate electronic devices, as they are vulnerable to data theft due to potential malicious software being loaded during updates.
Innovation Solution
A method for securely updating POS systems by using a cloud-based payment service to send encrypted software updates to merchant and customer devices, ensuring that only authorized updates are applied, and verifying the integrity of the updates through a secure enclave and verification processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software updates are applied to POS devices to improve functionality and security, then system reliability is improved, but the risk of data theft and security breaches increases during the update process
Solution Approach 1:
The system performs preliminary actions by obtaining cryptographic hashes of the current software and verifying them against expected hashes before applying updates. This pre-verification mechanism ensures software integrity is checked beforehand, preventing malicious software from being installed while maintaining system reliability improvements.
Solution Approach 2:
A secure communication channel with mutual authentication is established as an intermediary between the POS device and update server. This intermediary mechanism uses cryptographic protocols to verify identities and encrypt data transmission, allowing secure software updates while preventing data theft during the update process.
2Adaptability or versatility
If the POS device is connected to a separate electronic device for payment processing, then functionality and customer convenience are improved, but security vulnerabilities increase due to potential malicious software
Solution Approach 1:
The system implements continuous feedback mechanisms by verifying software integrity through cryptographic hashes after each update and before critical operations. This feedback loop ensures that any unauthorized modifications are detected, allowing the system to maintain enhanced payment processing capabilities while preventing security vulnerabilities from compromising the connected devices.
Solution Approach 2:
The system applies preliminary anti-action by establishing mutual authentication and encrypted communication channels before any data exchange between the POS device and separate electronic devices. This pre-established security framework prevents malicious software from exploiting connections, enabling versatile payment processing while countering security threats in advance.
3Reliability
If software updates are applied frequently to address security issues, then security posture is improved, but system stability may be compromised due to potential buggy updates
Solution Approach 1:
The system performs preliminary verification by computing and comparing cryptographic hashes of incoming software updates against expected values before installation. This pre-installation verification ensures that only authentic, uncorrupted updates are applied, allowing frequent security updates while preventing buggy or malicious updates from compromising system stability.
Solution Approach 2:
The POS device autonomously verifies software integrity through self-service mechanisms by checking cryptographic hashes and authentication credentials before applying updates. This self-verification capability enables the system to frequently update its security posture while maintaining stability through automated integrity checks that prevent installation of compromised software.
Data Source
AI summary
Techniques are described for securely updating a point-of-sale (POS) system that includes a merchant-facing device and a buyer-facing device. For instance, the merchant-facing device may execute first software that provides first POS functionality and the buyer-facing device may execute second software that provides second POS functionality. To update both devices, the merchant-facing device may receive a software update from a payment service via a network connection, and update the first software using the software update. The merchant-facing device can then cause, via a physical connection, the buyer-facing device to reboot in an update mode and send the software update to the buyer-facing device. In response, the buyer-facing device can update the second software using the software update and then reboot in a payments mode. In some instances, the buyer-facing device can then update a secure enclave on the buyer-facing device using the software update.


