POS Terminal Key Provisioning via Smart Card Interface
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The maintenance of secure facilities for provisioning point of sale (POS) terminals with cryptographic keys is cumbersome and inefficient for computer hardware manufacturers, as it requires extensive physical security and safeguards to meet financial industry standards.
Innovation Solution
The method involves securely transporting cryptographic keys to a key injection facility using an interface on the POS terminal, such as the card reader, and provisioning the terminals through a multi-stage process involving a provisioning server, smart card, and initialization device, allowing secure communication and key injection without the need for a dedicated secure facility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic keys are provisioned using traditional secure facilities with physical security safeguards, then security compliance with EMV and PCI standards is achieved, but operational complexity and maintenance burden increase significantly
Solution Approach 1:
The patent replaces the mechanical/physical security system (secure facilities with physical safeguards) with a cryptographic/digital security system. The provisioning process uses cryptographic protocols, digital certificates, and secure key exchange mechanisms implemented through software and hardware modules, eliminating the need for physically secure facilities while maintaining security compliance.
Solution Approach 2:
The patent introduces a provisioning server as an intermediary that mediates the key provisioning process between the terminal and the key management system. This server handles secure communication, authentication, and key distribution, replacing the need for direct physical secure facility access while ensuring security compliance through controlled intermediary management.
2Reliability
If dedicated secure facilities are maintained for key provisioning, then security standards are met, but cost and resource requirements increase
Solution Approach 1:
The patent makes the provisioning server and key management system universal, capable of serving multiple terminals and locations through digital networks. Instead of maintaining separate secure facilities for each terminal, a single provisioning infrastructure can securely provision keys to numerous terminals globally, dramatically reducing resource requirements while maintaining security compliance.
Solution Approach 2:
The patent uses digital copying and distribution of cryptographic keys and certificates through secure channels. Rather than physically transporting or storing keys in secure facilities, the system creates and distributes digital copies through encrypted communications, reducing the need for physical security infrastructure and associated resources.
3Reliability
If multi-stage provisioning process is implemented, then unauthorized provisioning is prevented, but provisioning time and process complexity increase
Solution Approach 1:
The patent implements preliminary authentication and authorization actions during the provisioning process. The provisioning server verifies terminal identities, validates cryptographic credentials, and authorizes key distribution before actual key provisioning occurs. This preliminary security verification prevents unauthorized provisioning while streamlining the overall process by establishing trust early.
Solution Approach 2:
The patent establishes continuous secure communication channels and authentication sessions throughout the provisioning process. Rather than discrete, time-consuming security checks, the system maintains continuous authenticated sessions that allow multiple provisioning operations to proceed efficiently while maintaining security, reducing overall provisioning time.
Data Source
AI summary
A provisioning system is provided for terminals such as point of sale terminals. An interface device interfaces with a smart card and a provisioning server, providing initialization keys and security codes that are stored on the smart card. At a terminal, an initialization key from the smart card may be provided to the terminal if a correct security code is entered at the terminal. The terminal may then provide a terminal authorization package to the smart card. The terminal authorization package is stored on the smart card. At the interface device, the terminal authorization package is provided to the provisioning server. The terminal may then securely communicate transactions with an issuer server.


